5 ms·
Technically interesting and also interesting that this comes from Tencent. > Tencent Holdings Limited is a Chinese multinational conglomerate holding company f
by explorigin 7y ago
Technically interesting and also interesting that this comes from Tencent.
> Tencent Holdings Limited is a Chinese multinational conglomerate holding company founded in 1998, whose subsidiaries specialise in various Internet-related services and products, entertainment, artificial intelligence and technology both in China and globally.
- netsharc 7y agoI'd say it's no different to Google Project Zero. Of course since it's China, there'd be worries. I'd guess the Chinese government also employs crack hackers, like the NSA probably does?
- monocasa 7y agoYeah, but they don't share 0 days like this, just like the NSA doesn't.
- close04 7y agoFrom the article: > Responsible disclosure > All the two vulnerabilities we presented above are reported to Tesla in March 2019. Tesla already fixed them in version 2019.36.2, and the Marvell also has deployed a fix and published a security advisory[4] to the issue. The disclosure of the vulnerability research report had been communicated to Tesla, and Tesla is aware of our release.
- monocasa 7y agoRight... They shared the 0 day. NSA and Comment Crew just sit on them like a dragon hording gold.
- rrdharan 7y agoI believe it’s less black and white than that - all of these organizations have both offensive and defensive priorities and sometimes choose to disclose exploits publicly after calculating their remaining value. See e.g. https://foreignpolicy.com/2017/09/25/is-the-nsa-doing-more-harm-than-good-in-not-disclosing-exploits-zero-days/ https://foreignpolicy.com/2017/09/25/is-the-nsa-doing-more-h... https://www.npr.org/sections/alltechconsidered/2017/11/17/564755961/government-outlines-when-it-will-disclose-or-exploit-software-vulnerabilities https://www.npr.org/sections/alltechconsidered/2017/11/17/56...
- solarkraft 7y ago> Of course since it's China, there'd be worries. I could imagine the government siphoning off the more valuable exploits.
- deleted 7y ago[deleted]
- kccqzy 7y agoIf you read the Apple product security announcements you'll find that they (as well as Qihoo 360) has been finding security vulnerabilities in unaffiliated companies' products for a long time. It's not unusual. They probably got the inspiration from Project Zero though.
- saagarjha 7y agoTencent has a number of security teams in addition to Keen Lab that have been around for a while: Xuanwu for example. I believe Keen Lab itself is some sort of acquisition of Keen Team, which did independent security research.