Live data from Hacker News

A walk through Project Zero metrics

googleprojectzero.blogspot.com

41–50 of 62 posts

Re: A walk through Project Zero metrics

#41
post #31

Earlier quoted context omitted.

Project Zero's argument is: > For nearly ten years, Google’s Project Zero has been working to make it more difficult for bad actors to find and exploit security vulnerabilities, significantly improving the security of the Internet for everyone. In that time, we have partnered with folks across industry to transform the way organizations prioritize and approach fixing security vulnerabilities and updating people’s sof…

Is “the security of the Internet” just a proxy for, “the number of vulns in the wild”?

Sure, you could also phrase that sentence a hundred other ways.

Re: A walk through Project Zero metrics

#42
post #38

Earlier quoted context omitted.

Is publicly revealing vulnerabilities/exploits that can damage a competitor considered part of what you're referring to as "research"?

It is considered that, because that is what it is. There is no law dictating how (or why) vulnerabilities are disclosed, and the disclosure of vulnerabilities is a public service.

Has there been any court case where this interpretation has been sufficient defense?

Re: A walk through Project Zero metrics

#43
post #33

Earlier quoted context omitted.

I don't think they are ethically obligated, but adds credibility to the idea that P0 is trying to improve security across the industry as a whole. Perhaps that makes their work easier because people are more receptive knowing that they are being treated "fairly" (at least in the same manner as the organization sponsoring the work).

See, this is my problem, because it should be self-evident just from their output, no matter who the vendor targets are, that they're improving security across the industry as a whole. It shouldn't even be a question.

Disclaimer: I work at Google, but this is just my opinion.

There’s another reason I can think of: Google has a great security culture, but like every company, it’s made up of people who may come and go. It takes constant investment to maintain and improve this culture. Project Zero helps to set standards and raise the bar across the industry, including for Google. So it’s not just setting an example; it also actively forces Google Product teams to exercise their security muscles (which includes reacting, communicating, patching, etc.). I imagine that Google would be happy having other friendly actors doing the same and sees it as a positive. (Obviously, this isn’t the only thing you’re doing to invest in the security culture, but it’s one thing.)

Re: A walk through Project Zero metrics

#44
post #38

Earlier quoted context omitted.

It is considered that, because that is what it is. There is no law dictating how (or why) vulnerabilities are disclosed, and the disclosure of vulnerabilities is a public service.

Has there been any court case where this interpretation has been sufficient defense?

You've got things reversed here: what would you sue someone for that anyone would need to mount a defense?

Re: A walk through Project Zero metrics

#45

Earlier quoted context omitted.

Has there been any court case where this interpretation has been sufficient defense?

You've got things reversed here: what would you sue someone for that anyone would need to mount a defense?

I don't know, I'm not a lawyer. But I imagine it wouldn't be hard to find some kind of vague basis to sue someone who intentionally causes you harm. Quick Googling suggests business torts are a thing; maybe there's more beyond that: https://www.findlaw.com/smallbusiness/business-laws-and-regu...

And if one has accepted a license agreement to use the product, there's often breach of contract available as a possible basis too.

Are you saying no one has ever been sued over publishing vulnerabilities in competitors' products?

Re: A walk through Project Zero metrics

#47
post #8

This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…

> if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under the fiction that it's OK for Google to be the only major vendor doing this work.

What's stopping them? Google started this team, stated it's goals publicly and engaged with third parties. They're free to ignore this, or to start their own teams and do the same.

Re: A walk through Project Zero metrics

#49

Earlier quoted context omitted.

Has there been any court case where this interpretation has been sufficient defense?

You've got things reversed here: what would you sue someone for that anyone would need to mount a defense?

Well, Sony tried to sue me for disclosing a vulnerability in the PS3. This is what they claimed:

> Violations of the Digital Millennium Copyright Act; violations of the Computer Fraud and Abuse Act; contributory copyright infringement; violations of the California Comprehensive Computer Data Access and Fraud Act; breach of contract; tortious interference with contractual relations; common law misappropriation; and trespass.

Yes. Trespass.

So yes, companies have tried to sue over disclosure of security vulnerabilities in the past. In this one they even ended up settling with one of the other defendants (whom they may have had a bit more of a case against, thanks to the DMCA if nothing else), but I think they realized they had no case against me and most of the others and dropped the lawsuit. They still filed it, though, and I had to get a lawyer, which was not a fun few months.

Re: A walk through Project Zero metrics

#50
post #3

Is it meaningful to include "Linux" as a discrete vendor? How would you compare an OSS project to a company like Microsoft or Google?

In the context of security policy, open source projects are "vendors". It doesn't matter that it's not a company. You only care about the result (when things are patched and released), not how it happens.

Of course with open source you can fix it yourself, but in this context the stats are about how upstream behaves.

Post reply on HN