Earlier quoted context omitted.
Project Zero's argument is: > For nearly ten years, Google’s Project Zero has been working to make it more difficult for bad actors to find and exploit security vulnerabilities, significantly improving the security of the Internet for everyone. In that time, we have partnered with folks across industry to transform the way organizations prioritize and approach fixing security vulnerabilities and updating people’s sof…
Is “the security of the Internet” just a proxy for, “the number of vulns in the wild”?
A walk through Project Zero metrics
41–50 of 62 posts
Re: A walk through Project Zero metrics
#42Earlier quoted context omitted.
Is publicly revealing vulnerabilities/exploits that can damage a competitor considered part of what you're referring to as "research"?
It is considered that, because that is what it is. There is no law dictating how (or why) vulnerabilities are disclosed, and the disclosure of vulnerabilities is a public service.
Re: A walk through Project Zero metrics
#43Earlier quoted context omitted.
I don't think they are ethically obligated, but adds credibility to the idea that P0 is trying to improve security across the industry as a whole. Perhaps that makes their work easier because people are more receptive knowing that they are being treated "fairly" (at least in the same manner as the organization sponsoring the work).
See, this is my problem, because it should be self-evident just from their output, no matter who the vendor targets are, that they're improving security across the industry as a whole. It shouldn't even be a question.
There’s another reason I can think of: Google has a great security culture, but like every company, it’s made up of people who may come and go. It takes constant investment to maintain and improve this culture. Project Zero helps to set standards and raise the bar across the industry, including for Google. So it’s not just setting an example; it also actively forces Google Product teams to exercise their security muscles (which includes reacting, communicating, patching, etc.). I imagine that Google would be happy having other friendly actors doing the same and sees it as a positive. (Obviously, this isn’t the only thing you’re doing to invest in the security culture, but it’s one thing.)
Re: A walk through Project Zero metrics
#44Earlier quoted context omitted.
It is considered that, because that is what it is. There is no law dictating how (or why) vulnerabilities are disclosed, and the disclosure of vulnerabilities is a public service.
Has there been any court case where this interpretation has been sufficient defense?
Re: A walk through Project Zero metrics
#45Earlier quoted context omitted.
Has there been any court case where this interpretation has been sufficient defense?
You've got things reversed here: what would you sue someone for that anyone would need to mount a defense?
And if one has accepted a license agreement to use the product, there's often breach of contract available as a possible basis too.
Are you saying no one has ever been sued over publishing vulnerabilities in competitors' products?
Re: A walk through Project Zero metrics
#46Re: A walk through Project Zero metrics
#47This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…
What's stopping them? Google started this team, stated it's goals publicly and engaged with third parties. They're free to ignore this, or to start their own teams and do the same.
Re: A walk through Project Zero metrics
#48Why am I not surprised?
Re: A walk through Project Zero metrics
#49Earlier quoted context omitted.
Has there been any court case where this interpretation has been sufficient defense?
You've got things reversed here: what would you sue someone for that anyone would need to mount a defense?
> Violations of the Digital Millennium Copyright Act; violations of the Computer Fraud and Abuse Act; contributory copyright infringement; violations of the California Comprehensive Computer Data Access and Fraud Act; breach of contract; tortious interference with contractual relations; common law misappropriation; and trespass.
Yes. Trespass.
So yes, companies have tried to sue over disclosure of security vulnerabilities in the past. In this one they even ended up settling with one of the other defendants (whom they may have had a bit more of a case against, thanks to the DMCA if nothing else), but I think they realized they had no case against me and most of the others and dropped the lawsuit. They still filed it, though, and I had to get a lawyer, which was not a fun few months.
Re: A walk through Project Zero metrics
#50Is it meaningful to include "Linux" as a discrete vendor? How would you compare an OSS project to a company like Microsoft or Google?
Of course with open source you can fix it yourself, but in this context the stats are about how upstream behaves.