Live data from Hacker News

Announcing Project Zero

googleonlinesecurity.blogspot.com

71–80 of 87 posts

Re: Announcing Project Zero

#71
post #67
post #43

Earlier quoted context omitted.

I'm entirely self taught. I have a single semester of college. I took psych and political science. :) Here's two starting points: - a reading list: http://amzn.to/cthr46 - how we hire: http://matasano.com/careers/

Thank you for doing the crypto challenge by the way. Was a lot of fun, and I'm looking forward to the next set :). Has anyone else finished it in c# yet?

Yes. There is, to my knowledge, no popular language people haven't finished in.

We'll have solutions in most of the languages on a public website in a couple weeks. :)

Re: Announcing Project Zero

#72

Earlier quoted context omitted.

Did you ever look at "Violent Python"? Any opinion as an alternative? http://www.amazon.com/Violent-Python-Cookbook-Penetration-En...

I'm not tptacek, but... After lightly reading through both books, I think Gray Hat Python is a great book for more advanced security concepts, especially on the reverse engineering and exploit dev side of things, but isn't a very good book for learning Python or programming. Violent Python on the other hand is a great book for beginners to Python and programming, and it teaches both pretty well, but it only goes into…

Thanks for your thoughts. I liked violent python- but you've convinced me to check out gray hat based on your commentary.

Re: Announcing Project Zero

#73
> Every bug we discover will be filed in an external database.

https://code.google.com/p/google-security-research/issues/li...

I am surprised that they didn't use something (other than Google Code) where one could more easily search by vendor or product, or other kinds of tags like "privilege escalation possible", "CVE-2014-0160", or "stack overflow" (as far as I know Google Code Issues doesn't support tags of any kind; maybe I'm wrong?), but I can see the appeal of using off-the-shelf code from somewhere else in Google.

Re: Announcing Project Zero

#74
post #73

> Every bug we discover will be filed in an external database. https://code.google.com/p/google-security-research/issues/li... I am surprised that they didn't use something (other than Google Code) where one could more easily search by vendor or product, or other kinds of tags like "privilege escalation possible", "CVE-2014-0160", or "stack overflow" (as far as I know Google Code Issues doesn't support tags of any ki…

Google Code really needs a bit of an overhaul these days.

Re: Announcing Project Zero

#75

Earlier quoted context omitted.

It's rather arrogant to say "everyone should have known". No, it isn't. http://en.wikipedia.org/wiki/DCSNet http://en.wikipedia.org/wiki/ECHELON http://en.wikipedia.org/wiki/Clipper_chip http://en.wikipedia.org/wiki/Room_641A http://en.wikipedia.org/wiki/Project_SHAMROCK http://en.wikipedia.org/wiki/President%27s_Surveillance_Prog... etc. Of course, no one listened. It was much easier to just decry everyone as a "cra…

This. And thanks to everyone for the down-vote, much love from Google these days, eh?

Jesus, the Google puppets are out strong on this one.

Amazing.

Re: Announcing Project Zero

#76
Another article or comment I read about this (or maybe an interview, IDK) highlighted the main reason behind this endeavour: more bugs squashed means a safer internet, a safer internet means people will be more likely to click on ads. Because ads have a bit of a trust issue; ad networks have been used to distribute malware via legitimate sites, and sites behind ads have frequently been serving malware themselves.

So basically similar to other of Google's 'free' endeavours (Chrome, SPDY), this is another project intended to make the web safer, faster, more trusted, which by extension leads to more ad impressions / clicks.

Re: Announcing Project Zero

#77
post #60
post #59

Earlier quoted context omitted.

haha not to drag this conversation out but just a hypothetical scenario: I download and install Drupal on my web server. I find an SQL Injection vulnerability in the login form. I post on a public forum the vulnerability where someone proceeds on their own to deface a government website using that knowledge. You don't think they would charge you in assisting?

No, they would not. The equivalent of this scenario happens all the time . In the one case I'm aware of where the developer of exploit code was found criminally liable for its use, that developer had a direct relationship with the person who actually did the exploiting (for commercial gain).

> I'm aware of [one case] where the developer of exploit code was found criminally liable

You're probably referring to Stephen Watt (a.k.a. "Unix Terrorist"), who wrote the POS sniffer. His friend, Albert Gonzalez, then used it to steal 170 million credit cards from TJ Maxx and other vendors back in 2006-2007.

Re: Announcing Project Zero

#79
post #73

> Every bug we discover will be filed in an external database. https://code.google.com/p/google-security-research/issues/li... I am surprised that they didn't use something (other than Google Code) where one could more easily search by vendor or product, or other kinds of tags like "privilege escalation possible", "CVE-2014-0160", or "stack overflow" (as far as I know Google Code Issues doesn't support tags of any ki…

As of now, this database contains some strange entries. Probably they have issues with access permissions?

  01 | Invalid | This is a test
  49 | Invalid | 
  50 | Invalid | 
  51 | Invalid | Random Guy Has Access To File Bugs
  52 | Invalid | Google PR doesn't respond to press inquiries
  53 | Invalid | The issue is the blog
  54 | Invalid | FR
  55 | Invalid | 
  56 | Invalid | hello

Re: Announcing Project Zero

#80
post #25
post #17

Earlier quoted context omitted.

http://america.aljazeera.com/articles/2014/5/6/nsa-chief-goo... There's also the fact that Google only started challenging the FISA court post-Snowden. To my knowledge, they're not even challenging the unconstitutional spying, just the gag order preventing Google from telling you how frequently Google turns over your data to the feds. This isn't just some theoretical, might be spying on "those people" sort of thing e…

You may want to look at an article I wrote in May 2013, which was the first to disclose that Google was challenging two secret National Security Letters in court. This was before anyone except Glenn and Laura had heard of some guy named Edward Snowden: http://www.cnet.com/news/justice-department-tries-to-force-g... There are other examples as well, like the Feds' subpoena for search logs that Google fought in court a…

>You may recall that Yahoo, AOL, Microsoft received the same subpoena but did not fight the Feds in court; they instead quietly complied.

Correction: Microsoft did not turn over the requested information.

http://bokardo.com/archives/microsoft-didnt-give-user-data-t...

“Today, Mehdi added some detail concerning what actually happened when the request from the Government was made. First, the Government had asked for information that could identify people on an individual basis (most likely, an IP address). Microsoft declined this request, and instead handed the Government a watered down version of data, which Mehdi made clear did not include personal information. The information provided by Microsoft, Mehdi said, consisted only of a sample of search terms and their frequency, as well as a random sample of pages in the MSN Search Index.

Just a minute of research would have led you to this, but of course, that would run counter to your pro-Google bias.

Post reply on HN