Live data from Hacker News

A walk through Project Zero metrics

googleprojectzero.blogspot.com

51–60 of 62 posts

Re: A walk through Project Zero metrics

#51
post #3

Is it meaningful to include "Linux" as a discrete vendor? How would you compare an OSS project to a company like Microsoft or Google?

The Linux Kernel is a product and the Linux Foundation is it‘s vendor. I would assume they mean Them. Especially when they had Red Hat and Cannonical in „other“

The Linux Foundation is not the vendor for Linux. "Vendor" here refers to the Linux kernel community and how it acts when security issues are discovered. That is, if you want to be pedantic, it's Linus Torvalds and everyone under him.

It doesn't really matter that it's not a legal entity, just "whoever is responsible for fixing the bug and releasing the fix officially". In security we call open source projects vendors because they act as such just like Apple would.

Re: A walk through Project Zero metrics

#52
post #38

Earlier quoted context omitted.

It is considered that, because that is what it is. There is no law dictating how (or why) vulnerabilities are disclosed, and the disclosure of vulnerabilities is a public service.

Has there been any court case where this interpretation has been sufficient defense?

Thousands of vulnerabilities are disclosed every year. Nobody has ever been successfully sued. The burden is on your argument, not mine.

Re: A walk through Project Zero metrics

#53

Earlier quoted context omitted.

The Linux Kernel is a product and the Linux Foundation is it‘s vendor. I would assume they mean Them. Especially when they had Red Hat and Cannonical in „other“

The Linux Foundation is not the vendor for Linux. "Vendor" here refers to the Linux kernel community and how it acts when security issues are discovered. That is, if you want to be pedantic, it's Linus Torvalds and everyone under him. It doesn't really matter that it's not a legal entity, just "whoever is responsible for fixing the bug and releasing the fix officially". In security we call open source projects vendor…

Linus Trovalds works for the Linux Foundation? So if we're being pedantic, which I think you are, then If it's Linux Torvalds in his professional capcitiy then it is for Linux Foundation.

Re: A walk through Project Zero metrics

#54
post #52

Earlier quoted context omitted.

Has there been any court case where this interpretation has been sufficient defense?

Thousands of vulnerabilities are disclosed every year. Nobody has ever been successfully sued. The burden is on your argument, not mine.

Yeah I understand that part. But to my understanding this is just due to a lack of clear court rulings on this (cases often settle/drop before court?), not due to the law being interpreted explicitly in favor of this by a court. e.g., https://securityboulevard.com/2021/07/what-the-van-buren-cas...

So if a case came up against Google, I imagine they would very much prefer to have this available as a defense, and draw analogies to the real world if necessary (like the home trespassing example in the link above).

Re: A walk through Project Zero metrics

#55
post #52

Earlier quoted context omitted.

Thousands of vulnerabilities are disclosed every year. Nobody has ever been successfully sued. The burden is on your argument, not mine.

Yeah I understand that part. But to my understanding this is just due to a lack of clear court rulings on this (cases often settle/drop before court?), not due to the law being interpreted explicitly in favor of this by a court. e.g., https://securityboulevard.com/2021/07/what-the-van-buren-cas... So if a case came up against Google, I imagine they would very much prefer to have this available as a defense, and draw…

You haven't even presented a theory of law that would make this work unlawful. It can't be on me to come up with such a thing just to knock it down.

Re: A walk through Project Zero metrics

#56

Earlier quoted context omitted.

You've got things reversed here: what would you sue someone for that anyone would need to mount a defense?

Well, Sony tried to sue me for disclosing a vulnerability in the PS3. This is what they claimed: > Violations of the Digital Millennium Copyright Act; violations of the Computer Fraud and Abuse Act; contributory copyright infringement; violations of the California Comprehensive Computer Data Access and Fraud Act; breach of contract; tortious interference with contractual relations; common law misappropriation; and tr…

Journalists have tried to put stories together on vulnerability researchers being threatened (and, hey, I'll raise my hand here: I've been threatened several times). But if you look at the actual instances where things have gotten far enough along to report, the fact patterns break down. It tends to turn out that people are getting threatened for:

* "Researching" serverside apps --- software running on computers the researcher doesn't own --- which is widely understood to fall afoul of CFAA and categorically isn't the kind of work P0 does.

* Breaching contracts, which happens commonly when vuln research firms take on pentest vendor assessment contracts for companies considering purchases, where the pentester access to the target was explicitly arranged under NDA.

* Stuff that isn't vulnerability research under any sane definition, as when people find open S3 buckets, grab all the files off them, and then try to "conduct research" based on the contents of the stolen files.

None of this is at play in the kind of work P0 does, and there are basically no modern stories about straight vulnerability research done under P0 terms where meaningful legal threats have been made. There was a time around the turn of the last century where it was briefly believed that the DMCA might be wielded against vuln researchers, but that didn't pan out.

Re: A walk through Project Zero metrics

#57
post #55

Earlier quoted context omitted.

Yeah I understand that part. But to my understanding this is just due to a lack of clear court rulings on this (cases often settle/drop before court?), not due to the law being interpreted explicitly in favor of this by a court. e.g., https://securityboulevard.com/2021/07/what-the-van-buren-cas... So if a case came up against Google, I imagine they would very much prefer to have this available as a defense, and draw…

You haven't even presented a theory of law that would make this work unlawful. It can't be on me to come up with such a thing just to knock it down.

> You haven't even presented a theory of law that would make this work unlawful.

I did in fact link to 2 entire pages of what might apply, based on my layman understanding:

- https://news.ycombinator.com/item?id=30310902 (which is one potential "theory of law" that might apply)

- https://news.ycombinator.com/item?id=30316448 (a lot of actual cases against actual individuals, each based on different legal theories)

Obviously I don't know if any of theory would make it unlawful (again, I'm not a judge or a lawyer). I just know security researchers have been sued in the past, and so far it seems to me that they have been either (a) settled out of court, (b) dropped, or (c) been scoped too narrowly to set much of a general precedent.

You don't have to feel compelled to knock anything down if you don't know; I don't really expect anyone to know at this point to be honest. (The second website I linked to also mentions this dearth of court rulings.)

Re: A walk through Project Zero metrics

#58
post #55

Earlier quoted context omitted.

You haven't even presented a theory of law that would make this work unlawful. It can't be on me to come up with such a thing just to knock it down.

> You haven't even presented a theory of law that would make this work unlawful. I did in fact link to 2 entire pages of what might apply, based on my layman understanding: - https://news.ycombinator.com/item?id=30310902 (which is one potential "theory of law" that might apply) - https://news.ycombinator.com/item?id=30316448 (a lot of actual cases against actual individuals, each based on different legal theories) Ob…

Every case in the article you cited involved someone conducting "research" on computers they did not themselves own, as happens when you portscan a remote host, or look for XSS vulnerabilities on someone's SAAS app, or try to pentest the media system on an airliner.

Project Zero doesn't do any of this kind of research.

Nobody is going to be able to sue Project Zero for finding iOS bugs. You have an almost unlimited right to conduct security research on a phone you buy, or a piece of software you install based on a click-through license.

What you need to be very careful about is, again, testing other people's computing devices. There, you have almost no rights at all (save for services that publicly waive their own rights by standing up bounty programs --- and, don't be confused, Project Zero doesn't depend on Apple's bounty programs to conduct iOS research).

These distinctions are super-clear to people who actually work in this field, but clearly unclear to people outside it, because we end up having the same picky debates about them every time vulnerability research comes up. I get it, it looks fuzzy on the outside. But it is not fuzzy to practitioners; the rules you have to be aware of to conduct research are actually fairly straightforward. Don't mess with other people's machines.

Re: A walk through Project Zero metrics

#59

Earlier quoted context omitted.

The Linux Foundation is not the vendor for Linux. "Vendor" here refers to the Linux kernel community and how it acts when security issues are discovered. That is, if you want to be pedantic, it's Linus Torvalds and everyone under him. It doesn't really matter that it's not a legal entity, just "whoever is responsible for fixing the bug and releasing the fix officially". In security we call open source projects vendor…

Linus Trovalds works for the Linux Foundation? So if we're being pedantic, which I think you are, then If it's Linux Torvalds in his professional capcitiy then it is for Linux Foundation.

Linus Torvalds does not answer to the Linux Foundation, and the Linux Foundation has little to do with how the Linux kernel handles security reports. It doesn't matter that they sponsor him; they aren't the "vendor" for Linux in any meaningful sense. They are just a nonprofit entity established to support Linux development in various ways.

Re: A walk through Project Zero metrics

#60
post #58

Earlier quoted context omitted.

> You haven't even presented a theory of law that would make this work unlawful. I did in fact link to 2 entire pages of what might apply, based on my layman understanding: - https://news.ycombinator.com/item?id=30310902 (which is one potential "theory of law" that might apply) - https://news.ycombinator.com/item?id=30316448 (a lot of actual cases against actual individuals, each based on different legal theories) Ob…

Every case in the article you cited involved someone conducting "research" on computers they did not themselves own, as happens when you portscan a remote host, or look for XSS vulnerabilities on someone's SAAS app, or try to pentest the media system on an airliner. Project Zero doesn't do any of this kind of research. Nobody is going to be able to sue Project Zero for finding iOS bugs. You have an almost unlimited r…

Thanks for clarifying that.
Post reply on HN