Live data from Hacker News

A walk through Project Zero metrics

googleprojectzero.blogspot.com

31–40 of 62 posts

Re: A walk through Project Zero metrics

#31
post #22

Earlier quoted context omitted.

> [P0] has greatly improve the overall security of the industry. What is the argument for this?

Project Zero's argument is: > For nearly ten years, Google’s Project Zero has been working to make it more difficult for bad actors to find and exploit security vulnerabilities, significantly improving the security of the Internet for everyone. In that time, we have partnered with folks across industry to transform the way organizations prioritize and approach fixing security vulnerabilities and updating people’s sof…

Is “the security of the Internet” just a proxy for, “the number of vulns in the wild”?

Re: A walk through Project Zero metrics

#32

that iOS vs Android table kinda makes no sense as they said iOS 76, Android Samsung 10, Android Pixel 6 >The first thing to note is that it appears that iOS received remarkably more bug reports from Project Zero than any flavor of Android did during this time period, but rather than an imbalance in research target selection, this is more a reflection of how Apple ships software. Security updates for "apps" such as iM…

I would argue that Android is safer, specifically from 0days.

Anyone with Android 6.0 or later (a 2015 OS) gets Chrome updates. Those updates are fast, automatic, and transparently happen in the background, with no user input or downtime (e.g. need to restart). They're also not arbitrarily delayed to fit into with some rigid OS update release schedule, like iOS or macOS.

That's especially important in this era where people are skeptical of updates, or just too busy, and keep delaying and skipping updates. Every time I use a family member's device, and check the version, I see they haven't updated in months. Many aren't even aware there are updates available.

I told the story before, but my grandma only has 4G, no Wi-Fi, and only has an iPhone, no laptop to download IPSWs from (and obviously average users can't do that); therefore she only gets iOS updates when I visit once or twice a year. Is Apple happy with that? Provocatively: is that the best they can do? Google proves it's not.

Sure, the Android OS update situation isn't great, but your biggest 0day exposures will be apps exposed to the internet (Chrome, chat apps) and those all get regular, transparent background updates with no user input; and Android users are much safer for it, than they'd be if Google imitated Apple's OS update strategy.

This is an Apple-wide problem, not just iOS. Anyone with OS X El Capitan 10.11 or later (again, a 2015 OS) is running the latest Google Chrome. Yet their Safari version is riddled with catastrophic 0day bugs (which can now be called 1,314-day bugs, since there have been 1,314 days since the last El Capitan security update).

Add to that the fact that Apple doesn't really support "n-2" OSes with security updates, as tech people say, since their unstated policy seems to be that only bugs which Apple thinks are "exploited in the wild" will be backported to any OS that isn't the very latest; most (not all) other known security patches are never backported.[0]

Apple's security stance is much worse than Microsoft's or Google's when comparing Apples to Apples.

[0]: https://www.intego.com/mac-security-blog/apples-poor-patchin...

Re: A walk through Project Zero metrics

#33
post #14

Earlier quoted context omitted.

I guess I'd start by saying I don't see the advantage to P0 operating independently. Threads about P0 often devolve into debates about conflicts of interest, but there's no conflict here; every vendor has in principle the right to conduct lawful vulnerability research against other vendors, including competitors, and there's no ethical standard that dictates what those vendors should choose to target. Google is, of c…

I don't think they are ethically obligated, but adds credibility to the idea that P0 is trying to improve security across the industry as a whole. Perhaps that makes their work easier because people are more receptive knowing that they are being treated "fairly" (at least in the same manner as the organization sponsoring the work).

See, this is my problem, because it should be self-evident just from their output, no matter who the vendor targets are, that they're improving security across the industry as a whole. It shouldn't even be a question.

Re: A walk through Project Zero metrics

#34
post #8

This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…

I imagine it might be a legal thing? Could their competitors file suits claiming they're being targeted/treated unfairly through the disclosure timelines and whatnot? This would seem to mitigate that.

Nope, there's no law that says you can't do independent vulnerability research.

Re: A walk through Project Zero metrics

#35
post #34

Earlier quoted context omitted.

I imagine it might be a legal thing? Could their competitors file suits claiming they're being targeted/treated unfairly through the disclosure timelines and whatnot? This would seem to mitigate that.

Nope, there's no law that says you can't do independent vulnerability research.

Is publicly revealing vulnerabilities/exploits that can damage a competitor considered part of what you're referring to as "research"?

Re: A walk through Project Zero metrics

#36

What was the most serious vulnerability or set of vulnerabilities identified by Project Zero?

I'm partial to the watering hole attack they found with TAG that had a bunch of browser 0days in it, personally:

https://googleprojectzero.blogspot.com/2021/01/introducing-i...

Re: A walk through Project Zero metrics

#37
post #14

Earlier quoted context omitted.

I guess I'd start by saying I don't see the advantage to P0 operating independently. Threads about P0 often devolve into debates about conflicts of interest, but there's no conflict here; every vendor has in principle the right to conduct lawful vulnerability research against other vendors, including competitors, and there's no ethical standard that dictates what those vendors should choose to target. Google is, of c…

I don't think they are ethically obligated, but adds credibility to the idea that P0 is trying to improve security across the industry as a whole. Perhaps that makes their work easier because people are more receptive knowing that they are being treated "fairly" (at least in the same manner as the organization sponsoring the work).

If you ever get a chance to sit down with someone from Google security, ask them if P0 is buddy buddy with product. Just make sure they aren’t talking a sip of anything at the time.

Re: A walk through Project Zero metrics

#38
post #34

Earlier quoted context omitted.

Nope, there's no law that says you can't do independent vulnerability research.

Is publicly revealing vulnerabilities/exploits that can damage a competitor considered part of what you're referring to as "research"?

It is considered that, because that is what it is. There is no law dictating how (or why) vulnerabilities are disclosed, and the disclosure of vulnerabilities is a public service.

Re: A walk through Project Zero metrics

#39
post #9
post #8

This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…

Why not? It really strengthens the message.

What’s the value of the public’s opinion of their objectivity in this context? Let’s say that my mom thinks P0 are a bunch of bullies and blowhards. So what?

I’m not saying there’s absolutely no brand damage to Google, but in the grand scheme it seems negligible outside of HN and similar venues.

Re: A walk through Project Zero metrics

#40
post #8

This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…

I wonder if part of it is providing a way around internal politics/prioritization to force the teams to actually take action, to make delaying a fix a complete non-option.
Post reply on HN