Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Does anyone know if they only research os and os environment bugs or also cisco juniper os bugs as well for example?


This is from the Project Zero announcement post:

"We're not placing any particular bounds on this project and will work to improve the security of any software depended upon by large numbers of people, paying careful attention to the techniques, targets and motivations of attackers."

http://googleonlinesecurity.blogspot.com/2014/07/announcing-...


I also wonder if they publish proof of concepts for security bugs they refuse to fix (e.g. in Android 4.3).


They said they also investigate on Android, but they haven't yet published a single vulnerability for it, as far as I can tell.


Right on their blog, though it's a guest post but they don't seem to have anything against it: http://googleprojectzero.blogspot.com/2015/01/exploiting-nvm...


Yes, it's a guest post. What I said is that, while in theory they said they will research all major OSs (including Android, which is by far the most common mobile OS), they have yet to publish a single vulnerability as a result of their research.


Maybe they do publish them but they are all fixed before the 90 windows passes so they don't have to be disclosed their. You still go to git.chromium.org and aosp's git see the daily security/improvement patches that go there.


The disclosure window is typically for fixes released to end-users, not just fixed by vendors. This is also what was enforced with MS last round, where they had a fix ready but couldn't get it to pass QA and being released before the 90-days window expired.


These bugs appear to be for Yosemite, so they might only look at bugs present in the latest version of the software.


I doubt they're wasting time with bugs in OS X 10.5 either.


Was the security bug discovered by Project Zero team?


https://code.google.com/p/google-security-research/issues/li...

They haven't published Cisco bugs, but they do have a pretty broad scope.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: