3 ms·
It sounds like the idea that it's a donation is the part where we fundamentally disagree then. If you expose an unpatched exploit and the number of people using
by 2804t3qwp 7y ago
It sounds like the idea that it's a donation is the part where we fundamentally disagree then. If you expose an unpatched exploit and the number of people using that exploit goes up because of your publication then you've contributed to worsening the security landscape for whoever the relevant user is. If an exploit is years old, or if there's some other relevant context, then sure exposing a vulnerability mainly means that the parent company doesn't have to pay for the research. But it's not a favor they asked you to perform and if you have a competing product with that company then the question becomes "Why aren't you publishing more about yourself?" since surely no one is in a better position to do security research on your products than yourself or a contractor you hired. It's basically PR motivated research and when there's also a lack of transparency it leads to easy speculation that maybe you're holding back research on yourself purposefully or even simply not publishing the more damning research you discover about your own products.
- tptacek 7y agoThere's no "agreement" or "disagreement" to be had here. Vulnerability researchers don't create vulnerabilities, they find and ultimately eliminate them. Vulnerability research at the level practiced by P0 commands huge daily rates, and Google's competitors actively pay those rates to other researchers. It is simply a fact that what Google is doing is a donation to other vendors and their users. You can dispute their intentions, but I'm not all that interested in debating those. What you can't do is debate the effect, which is positive.
- 2804t3qwp 7y agoIf you're not interested in debating their intentions then why frame it as a donation? That by itself is a normative judgement in this context, and the reason I brought up framing, since normally two primary characteristics of a donation are that it can be refused and that it is being offered in good faith. This is the same general point that the original comment you had replied to was making which itself was an explanation of why people are distrustful of P0 even if the brass tax is positive for the end user. It's fine if you don't find that political side of it interesting but it's not as simple as just being a donation.
- tptacek 7y agoGoogle's competitors are getting a thing of great value at no cost. That's what a donation is.
- 2804t3qwp 7y agoIf it's a great value then why isn't that effort being directed entirely towards google products? I get the argument you're making I think, that it's free valuable labor. But if that's true then what explanation is there for primarily publishing about competing products? Even if the argument was purely user safety then surely there would be no reason to publish unpatched problems publicly which has happened in the past and seems like the sort of thing that group like P0 could have chosen to handle in a more graceful fashion. Somewhere in the chain of command is a reason for why P0 focuses where it does and it doesn't seem likely that the reason is "Because we're rolling in gold and Apple and Microsoft could use the money."
- tptacek 7y agoThere's no amount of axiomatic reasoning you're going to be able to generate to make your argument work. Vulnerability research is expensive. Google is giving it away to its competitors. Those competitors and, much more importantly and to a greater extent, their customers, benefit directly. Those aren't so much statements of opinion so much as they are simple facts.