5 ms·
This is the equivalent of a negative research result that looked into whether there's anything more to explore here to produce the really juicy result like a tr
by snoshy 6y ago
This is the equivalent of a negative research result that looked into whether there's anything more to explore here to produce the really juicy result like a true compromise, but instead shows that there's nothing that a set of highly qualified researchers can prove, at least. I applaud more of this, although it is not an infrequent practice among the top security engineers, I feel it sets a precedent for research broadly.
Nothing to be found here as far as we know, is still a result that deserves publishing. Let's make it more of the norm.
- rat9988 6y agoI feel like you are claiming researchers do not do it.
- ksml 6y agoI read it as GP arguing we don't do enough of it.
- rat9988 6y agoMy english may be failing me here, but doesn't > I feel it sets a precedent for research broadly imply it's some sort of first time?
- vulcan01 6y agoGenerally, precedent means first "well-known" time, or first time by a respected person/institution/company. I don't know enough about this field to know if this is the first time Google has published a negative result.
- snoshy 6y agoThis is a fair point to consider. Perhaps my claim was a bit overbroad.
- snoshy 6y agoYes, this was my intent. It's not that security researchers don't publish this kind of thing... it's just that there are a million rabbit holes to explore, and probably only like 0.1% of those dead ends get written about.
- philshem 6y agoAcademic research is starting to address publication bias: https://en.wikipedia.org/wiki/Series_of_Unsurprising_Results_in_Economics https://en.wikipedia.org/wiki/Series_of_Unsurprising_Results... https://www.cbc.ca/radio/asithappens/as-it-happens-thursday-edition-1.5146761/new-academic-journal-only-publishes-unsurprising-research-rejected-by-others-1.5146765 https://www.cbc.ca/radio/asithappens/as-it-happens-thursday-... discussed on HN (2019): https://news.ycombinator.com/item?id=19968679 https://news.ycombinator.com/item?id=19968679
- saagarjha 6y agoSecurity researchers sometime publish informative blog posts from time to time that don't deal with a specific vulnerability; this is one of them. Of course, being Project Zero usually these deep dives often turn up a bug or two (for example, this document on Apple's PAC implementation, which is probably one of the best resources describing it, stumbles upon a bug fixed by Apple while it was being written: https://googleprojectzero.blogspot.com/2019/02/examining-pointer-authentication-on.html https://googleprojectzero.blogspot.com/2019/02/examining-poi...), but this case it does seem like they just happened to not find anything. Whether that is because they couldn't probe very deeply due to the complete rewrite, or because the new architecture and use of a memory safe language upped the bar a bit (or a combination of both) is not clear but the thing I wanted to say here is that these blog posts are useful regardless of whether there is an exploit PoC attached. People may not want to write them, but they certainly stand on their own as good reference material.
- IncludeSecurity 6y agoHaving been in this silly industry of hacking for 20yrs, I really wish publishing negative results became more normalized. There are orders of magnitude more unpublished info regarding stories of not finding vulns there are about finding vulns. It just goes to show how much the industry really is flashy/stunt hacking. p.s. Samuel who published the research OP posted is one of the best hackers I've ever met, he helped me code our interview challenge test that we still use (it's that good!)
- ogre_codes 6y ago> Nothing to be found here as far as we know I disagree, it's a fantastic, approachable disection of what Apple did to mitigate some nasty security holes. Worth the price of entry by far.
- draw_down 6y agoLet's not be disingenuous, friend