Live data from Hacker News

A walk through Project Zero metrics

googleprojectzero.blogspot.com

21–30 of 62 posts

Re: A walk through Project Zero metrics

#21
post #14
post #10

Earlier quoted context omitted.

Could you expand more on why? At least to me, it seems like there's no downside to publicly tracking responses from Google itself. Ideally P0 should operate mostly independently. Agreed that there should be more P0 like efforts from other companies though. The more the merrier.

I guess I'd start by saying I don't see the advantage to P0 operating independently. Threads about P0 often devolve into debates about conflicts of interest, but there's no conflict here; every vendor has in principle the right to conduct lawful vulnerability research against other vendors, including competitors, and there's no ethical standard that dictates what those vendors should choose to target. Google is, of c…

Maybe think of it as Dog Fooding ?

Re: A walk through Project Zero metrics

#22
post #2

I dislike many aspects of google, but project zero is not one of them and has greatly improve the overall security of the industry. Also their blogs describing how security exploits work are always super interesting

> [P0] has greatly improve the overall security of the industry.

What is the argument for this?

Re: A walk through Project Zero metrics

#23
post #8

This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…

Gosh, why? From any outsider's perspective, this gives Google P0 much more credibility to show that they are operating on equal terms and not playing a game favoring Google itself.

This trust is the foundation of industry cooperation, otherwise Google P0 would be perceived as a weapon of Google focusing on attacking and disclosing bugs in other companies, most of which are their direct and top competitors.

Re: A walk through Project Zero metrics

#24
post #22
post #2

I dislike many aspects of google, but project zero is not one of them and has greatly improve the overall security of the industry. Also their blogs describing how security exploits work are always super interesting

> [P0] has greatly improve the overall security of the industry. What is the argument for this?

They've been very effective at getting many large companies to actually fix security bugs, and release updates with those fixes in an actually reasonable time frame. They've been very strict about their "we will publish the details of this security bug in 90 days unless you can provide a very good reason not to".

Re: A walk through Project Zero metrics

#25
post #22
post #2

I dislike many aspects of google, but project zero is not one of them and has greatly improve the overall security of the industry. Also their blogs describing how security exploits work are always super interesting

> [P0] has greatly improve the overall security of the industry. What is the argument for this?

Like the number of critical bugs they found and pushed the vendors to fix? Like finding bugs like Spectre that forever changed the chip industry's understanding of side channel attacks and subsequent designs?

Re: A walk through Project Zero metrics

#26
post #22
post #2

I dislike many aspects of google, but project zero is not one of them and has greatly improve the overall security of the industry. Also their blogs describing how security exploits work are always super interesting

> [P0] has greatly improve the overall security of the industry. What is the argument for this?

Project Zero's argument is:

> For nearly ten years, Google’s Project Zero has been working to make it more difficult for bad actors to find and exploit security vulnerabilities, significantly improving the security of the Internet for everyone. In that time, we have partnered with folks across industry to transform the way organizations prioritize and approach fixing security vulnerabilities and updating people’s software.

This feels pretty reasonable, we don't have a spare universe to act as our control, but their intervention does seem likely to have made us more secure overall than otherwise.

Re: A walk through Project Zero metrics

#27
post #8

This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…

I imagine it might be a legal thing? Could their competitors file suits claiming they're being targeted/treated unfairly through the disclosure timelines and whatnot? This would seem to mitigate that.

Re: A walk through Project Zero metrics

#28
post #8

This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…

> I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from.

Why? This is just dog food. They should be testing that bugs can be submitted through normal channels. Then they can know how their own system compares to others from a user standpoint.

> if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under the fiction that it's OK for Google to be the only major vendor doing this work.

I mean shouldn't they? If you have a trillion dollar tech business that depends on software built out-of-house then I would imagine your security highly depends on such a team. I don't understand why all big tech doesn't have their own project zero.

Re: A walk through Project Zero metrics

#29
post #8

This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…

> fiction that it's OK for Google to be the only major vendor doing this work.

Do any of the other major vendors have the same incentives that lead Google to create P0? I expect most of them don't.

Re: A walk through Project Zero metrics

#30
post #29
post #8

This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…

> fiction that it's OK for Google to be the only major vendor doing this work. Do any of the other major vendors have the same incentives that lead Google to create P0? I expect most of them don't.

Maybe IBM, but that's where engineering orgs go to die these days, so I don't really expect it of them.
Post reply on HN