Live data from Hacker News

Announcing Project Zero

googleonlinesecurity.blogspot.com

21–30 of 87 posts

Re: Announcing Project Zero

#21

Earlier quoted context omitted.

Don't forget the part where they make significantly more money than working for a federal acronym.

The NSA pays quite well, and has excellent benefits. Also, if you want to work on really seriously challenging mathematics outside of academia, the NSA is close to being the only game in town.

The NSA pays government salaries, if you want real money you need to be at an outside vendor (a la Snowden). I'm sure the benefits are great, but so are Google's.

http://www.glassdoor.com/Salary/NSA-Salaries-E41534.htm

http://www.opm.gov/policy-data-oversight/pay-leave/salaries-...

Re: Announcing Project Zero

#22
post #17

Earlier quoted context omitted.

"unpleasant discovery that NSA has been up in that Google, and Google willingly accepted." [citation needed] Specifically for the willingly accepted part.

http://america.aljazeera.com/articles/2014/5/6/nsa-chief-goo... There's also the fact that Google only started challenging the FISA court post-Snowden. To my knowledge, they're not even challenging the unconstitutional spying, just the gag order preventing Google from telling you how frequently Google turns over your data to the feds. This isn't just some theoretical, might be spying on "those people" sort of thing e…

Many strawmen, but nothing relating to my comment, which was "do we know Google knew about the taps". I'm not aware of any article proving that was the case.

Re. the first link - companies of the size of Google will meet with the NSA at some point. They have to comply with many regulations and will have private chats at high level. They even willingly run NSA's software (selinux). This doesn't prove or disprove cooperation in communication taping.

Just one of your points I wanted to address.

> Google never really deletes anything from gmail and other services (disk is cheap)

Also, data invalidation is hard - probably every company that's big enough should have it in their ToC, unless they assign a full drive to each customer and do hardware wipe on it when something is deleted. Deleting a file is essentially just setting a "this is deleted" flag, until other data overwrites this. I'm willing to bet none of the companies you interact with guarantees your data is physically deleted. Everyone should be aware of that.

Re: Announcing Project Zero

#23

> Security is a top priority for Google Can't take this seriously any more. Used to like Google, not any more. Remember this was a company co-operating with the NSA.

Cooperating when they had a court order compelling them to. The alternative would be to shut down all services and see people go to jail. They didn't have a choice.

Re: Announcing Project Zero

#24
post #9

This sounds like a new name (and possibly more executive support) for what those guys have been doing for years now. The guys in that article have been working on finding bugs in non-Google products for a little over two years and you can see their past results through the advisory credits they've received at Microsoft and Adobe as well as from open source projects like FFmpeg. For example see Ben Hawkes on this list…

That's how PR works. You give a new brand name to something old to make it sexy.

Re: Announcing Project Zero

#25
post #17

Earlier quoted context omitted.

"unpleasant discovery that NSA has been up in that Google, and Google willingly accepted." [citation needed] Specifically for the willingly accepted part.

http://america.aljazeera.com/articles/2014/5/6/nsa-chief-goo... There's also the fact that Google only started challenging the FISA court post-Snowden. To my knowledge, they're not even challenging the unconstitutional spying, just the gag order preventing Google from telling you how frequently Google turns over your data to the feds. This isn't just some theoretical, might be spying on "those people" sort of thing e…

You may want to look at an article I wrote in May 2013, which was the first to disclose that Google was challenging two secret National Security Letters in court. This was before anyone except Glenn and Laura had heard of some guy named Edward Snowden: http://www.cnet.com/news/justice-department-tries-to-force-g...

There are other examples as well, like the Feds' subpoena for search logs that Google fought in court and mostly won. You may recall that Yahoo, AOL, Microsoft received the same subpoena but did not fight the Feds in court; they instead quietly complied.

My article on that: http://news.cnet.com/FAQ-What-does-the-Google-subpoena-mean/...

Re: Announcing Project Zero

#26
post #6

It reads a bit like they're trying to recruit NSA employees to come work for Google...

Hmmm... job-for-life with enforced zealous national patriotism, vs five-year job with enforced zealous corporate patriotism (and everything is so god-damned colourful). They'd have a tough sell to get the NSA employees I would think.

A lot of these people are not American and thus not eligible to be NSA employees, assuming they'd even want to be (obviously not).

Re: Announcing Project Zero

#27

Earlier quoted context omitted.

"unpleasant discovery that NSA has been up in that Google, and Google willingly accepted." [citation needed] Specifically for the willingly accepted part.

That fibers have been tapped by state actors was well known pre-Snowden (I recall reading a story about how subs were used in Russia etc), yet Google only completed encrypting their private fibers post-Swnoden.

The assumption pre-Snowden was that only "hostile states" did that kind of thing, e.g fibres in and out of China were probably tapped, but most of the internet wasn't. Because, you know, search warrants do exist.

It's rather arrogant to say "everyone should have known". Snowden's leaks have been making waves for a year solid now exactly because he showed that reality was the worst case scenario only the most extreme of the extreme postulated previously.

Re: Announcing Project Zero

#28
post #18

1) What steps will Google be taking to ensure timely vendor acknowledgement and fixing of issues? It often seems a public disclosure is the only thing which will trigger them to finally act (and then they like to fire back with litigation). If a vendor simply ignores Google, will the bug go unannounced indefinitely? Is there a reasonable timeline in which all bugs - fixed or not - are made public? 2) Will Google take…

The answer to #1 is in the wired article about Project Zero:

"When Project Zero’s hacker-hunters find a bug, they say they’ll alert the company responsible for a fix and give it between 60 and 90 days to issue a patch before publicly revealing the flaw on the Google Project Zero blog. In cases where the bug is being actively exploited by hackers, Google says it will move much faster, pressuring the vulnerable software’s creator to fix the problem or find a workaround in as little as seven days."

http://www.wired.com/2014/07/google-project-zero/

Re: Announcing Project Zero

#29
post #9

This sounds like a new name (and possibly more executive support) for what those guys have been doing for years now. The guys in that article have been working on finding bugs in non-Google products for a little over two years and you can see their past results through the advisory credits they've received at Microsoft and Adobe as well as from open source projects like FFmpeg. For example see Ben Hawkes on this list…

My read of the announcement is that they are now hiring vulnerability researchers to work on arbitrary targets, the way security product companies do to staff their research labs.

Starting back in the 1990s, companies like ISS and McAfee staffed teams of bugfinders to comb through high-profile software for vulnerabilities, and kept score with advisories (and with IDS/IPS signatures and scanner checks for those bugs, which they'd have a semi-proprietary interest in, since they found them). They'd use this to market their expensive products. The researchers generally had a long leash so long as they were (a) looking at software that customers might care about and (b) were actually finding things.

What Google seems to be doing is starting a lab like that, but without the hooks into products and marketing; instead: Google has cash, wants to retain security researchers, and so will throw money at a vulnerability lab run for the common good, partially for the PR win, partially for the knock-on benefits to Google of having lots of good security people, and yes, partially for the good of humanity.

(FWIW: I worked at what I think was the industry's first vulnerability lab, at SNI, which eventually became McAfee's vulnerability team).

Re: Announcing Project Zero

#30
post #18

1) What steps will Google be taking to ensure timely vendor acknowledgement and fixing of issues? It often seems a public disclosure is the only thing which will trigger them to finally act (and then they like to fire back with litigation). If a vendor simply ignores Google, will the bug go unannounced indefinitely? Is there a reasonable timeline in which all bugs - fixed or not - are made public? 2) Will Google take…

Regarding point (2): if you're thinking about things like SQLI and XSS vulnerabilities in websites, that's not the kind of research Google is likely to be doing. But if you're thinking about finding memory corruption flaws in software you install on your own machines: you have very little to worry about from the CFAA to begin with.
Post reply on HN