Live data from Hacker News

Announcing Project Zero

googleonlinesecurity.blogspot.com

31–40 of 87 posts

Re: Announcing Project Zero

#31
post #29
post #9

This sounds like a new name (and possibly more executive support) for what those guys have been doing for years now. The guys in that article have been working on finding bugs in non-Google products for a little over two years and you can see their past results through the advisory credits they've received at Microsoft and Adobe as well as from open source projects like FFmpeg. For example see Ben Hawkes on this list…

My read of the announcement is that they are now hiring vulnerability researchers to work on arbitrary targets, the way security product companies do to staff their research labs. Starting back in the 1990s, companies like ISS and McAfee staffed teams of bugfinders to comb through high-profile software for vulnerabilities, and kept score with advisories (and with IDS/IPS signatures and scanner checks for those bugs,…

It could also be that their semi-formal third party security team is now a formal team. Previously it was less than a full time project but more than a 20% project for many of Google's vulnerability researchers.

I guess that'd have the same net result though since it's much more feasible to hire for if it's been formalized.

Re: Announcing Project Zero

#32
post #30
post #18

1) What steps will Google be taking to ensure timely vendor acknowledgement and fixing of issues? It often seems a public disclosure is the only thing which will trigger them to finally act (and then they like to fire back with litigation). If a vendor simply ignores Google, will the bug go unannounced indefinitely? Is there a reasonable timeline in which all bugs - fixed or not - are made public? 2) Will Google take…

Regarding point (2): if you're thinking about things like SQLI and XSS vulnerabilities in websites, that's not the kind of research Google is likely to be doing. But if you're thinking about finding memory corruption flaws in software you install on your own machines: you have very little to worry about from the CFAA to begin with.

Good to know, thank you. What in your opinion is the best way for someone to submit a security vulnerability (the sort which could land them into legal trouble, they don't have permission to be penetration-testing, could be viewed as malicious, etc) or is it simply not worth the risk?

Re: Announcing Project Zero

#34
post #32
post #30

Earlier quoted context omitted.

Regarding point (2): if you're thinking about things like SQLI and XSS vulnerabilities in websites, that's not the kind of research Google is likely to be doing. But if you're thinking about finding memory corruption flaws in software you install on your own machines: you have very little to worry about from the CFAA to begin with.

Good to know, thank you. What in your opinion is the best way for someone to submit a security vulnerability (the sort which could land them into legal trouble, they don't have permission to be penetration-testing, could be viewed as malicious, etc) or is it simply not worth the risk?

You need to clarify. Are you talking about submitting a vulnerability in someone else's website, or in a product you installed on your own computer?

In the latter case, it's pretty straightforward. Your legal liabilities in that situation are (so long as you don't demand money) civil (you many have violated a click-wrap that will probably prove toothless against security research). You can tell the vendor directly if you like (from experience, this isn't fun; you'll probably spend a couple hours in tier 1-2-3 tech support hell). If it's an important target, you can also talk to bug bounty programs.

In the former case: it's not not straightforward. Start by scouring the target's website to see if they have a disclosure program, which will probably equate to permission for looking for flaws in their site. If they don't, it's very possible that you've broken the law in whatever process you used to find the vulnerability. Submit anonymously and carefully. If they prove themselves to be cool, you can always take credit later.

Re: Announcing Project Zero

#35

Earlier quoted context omitted.

That fibers have been tapped by state actors was well known pre-Snowden (I recall reading a story about how subs were used in Russia etc), yet Google only completed encrypting their private fibers post-Swnoden.

The assumption pre-Snowden was that only "hostile states" did that kind of thing, e.g fibres in and out of China were probably tapped, but most of the internet wasn't. Because, you know, search warrants do exist. It's rather arrogant to say "everyone should have known". Snowden's leaks have been making waves for a year solid now exactly because he showed that reality was the worst case scenario only the most extreme…

It's rather arrogant to say "everyone should have known".

No, it isn't.

http://en.wikipedia.org/wiki/DCSNet

http://en.wikipedia.org/wiki/ECHELON

http://en.wikipedia.org/wiki/Clipper_chip

http://en.wikipedia.org/wiki/Room_641A

http://en.wikipedia.org/wiki/Project_SHAMROCK

http://en.wikipedia.org/wiki/President%27s_Surveillance_Prog...

etc.

Of course, no one listened. It was much easier to just decry everyone as a "crazy conspiracy theorist", wasn't it?

Re: Announcing Project Zero

#36
post #18

1) What steps will Google be taking to ensure timely vendor acknowledgement and fixing of issues? It often seems a public disclosure is the only thing which will trigger them to finally act (and then they like to fire back with litigation). If a vendor simply ignores Google, will the bug go unannounced indefinitely? Is there a reasonable timeline in which all bugs - fixed or not - are made public? 2) Will Google take…

For point 1, The Hacker News podcast (not related to this site, but Space Rogue's much older Hacker News Network) ran a list of all unresolved advisories in the Zero-Day Initiative older than 30 days. Apparently just being on the list, plus the popularity boost from Space Rogue's podcast, was enough to shame some companies into closing old vulnerabilities.

Re: Announcing Project Zero

#37
post #34
post #32

Earlier quoted context omitted.

Good to know, thank you. What in your opinion is the best way for someone to submit a security vulnerability (the sort which could land them into legal trouble, they don't have permission to be penetration-testing, could be viewed as malicious, etc) or is it simply not worth the risk?

You need to clarify. Are you talking about submitting a vulnerability in someone else's website, or in a product you installed on your own computer? In the latter case, it's pretty straightforward. Your legal liabilities in that situation are (so long as you don't demand money) civil (you many have violated a click-wrap that will probably prove toothless against security research). You can tell the vendor directly if…

Sorry I should have been more clear - I meant the former case of finding vulnerabilities in a website/API/web-service/etc. Your answer was comprehensive in either direction though, and thank you

Re: Announcing Project Zero

#38
post #29
post #9

This sounds like a new name (and possibly more executive support) for what those guys have been doing for years now. The guys in that article have been working on finding bugs in non-Google products for a little over two years and you can see their past results through the advisory credits they've received at Microsoft and Adobe as well as from open source projects like FFmpeg. For example see Ben Hawkes on this list…

My read of the announcement is that they are now hiring vulnerability researchers to work on arbitrary targets, the way security product companies do to staff their research labs. Starting back in the 1990s, companies like ISS and McAfee staffed teams of bugfinders to comb through high-profile software for vulnerabilities, and kept score with advisories (and with IDS/IPS signatures and scanner checks for those bugs,…

Is working at one of those labs as much fun as it sounds?

Re: Announcing Project Zero

#39

Earlier quoted context omitted.

The assumption pre-Snowden was that only "hostile states" did that kind of thing, e.g fibres in and out of China were probably tapped, but most of the internet wasn't. Because, you know, search warrants do exist. It's rather arrogant to say "everyone should have known". Snowden's leaks have been making waves for a year solid now exactly because he showed that reality was the worst case scenario only the most extreme…

It's rather arrogant to say "everyone should have known". No, it isn't. http://en.wikipedia.org/wiki/DCSNet http://en.wikipedia.org/wiki/ECHELON http://en.wikipedia.org/wiki/Clipper_chip http://en.wikipedia.org/wiki/Room_641A http://en.wikipedia.org/wiki/Project_SHAMROCK http://en.wikipedia.org/wiki/President%27s_Surveillance_Prog... etc. Of course, no one listened. It was much easier to just decry everyone as a "cra…

This. And thanks to everyone for the down-vote, much love from Google these days, eh?

Re: Announcing Project Zero

#40
post #38
post #29

Earlier quoted context omitted.

My read of the announcement is that they are now hiring vulnerability researchers to work on arbitrary targets, the way security product companies do to staff their research labs. Starting back in the 1990s, companies like ISS and McAfee staffed teams of bugfinders to comb through high-profile software for vulnerabilities, and kept score with advisories (and with IDS/IPS signatures and scanner checks for those bugs,…

Is working at one of those labs as much fun as it sounds?

Yes. Tim and I got something like 8 months to do this:

http://cs.unc.edu/~fabian/course_papers/PtacekNewsham98.pdf

... where we discovered (or were at least first to publish) two whole new attack classes, tracked down something like 6 different super expensive security products and got them up in a lab, designed and implemented a new programming language, and succeeded in giving a giant middle finger to surveillance software.

It's the most fun I've had in my whole career.

Not for nothing, but working at a software security consultancy is a close second; you lose the freedom to choose your targets (at least 80% of the time), but the work is the same.

Post reply on HN