7 ms·
The more concerning security finding here is that Google sat on this for 9 months. Assuming the claims hold, this is a serious problem for any security-consciou
by cle 5y ago
The more concerning security finding here is that Google sat on this for 9 months. Assuming the claims hold, this is a serious problem for any security-conscious GCP customers. What other vulnerabilities are they sitting on? Do they have processes in place to promptly handle new ones? Doesn’t look like it…
- saghm 5y agoThis is especially questionable given the much shorter deadline that Project Zero gives other companies to fix bugs before publishing their vulnerabilities (regardless of whether there's been a fix). It only seems fair that Google should hold itself to the same standard.
- VWWHFSfQ 5y agoGoogle doesn't hold itself to any standard. At least, not anymore.
- sirdarckcat 5y agohttp://g.co/appsecurity http://g.co/appsecurity has more details but TL;DR is that Google is supportive of people disclosing unfixed bugs after 90 days, which is what happened here.
- dataflow 5y agoProject Zero gives Google the same timeline. This had nothing to do with Project Zero from what I understand.
- breakingcups 5y agoProject Zero is a (very public) Google project though. If they stand behind their choices and policies, they should live by them.
- joshuamorton 5y agoIn what way is Google not standing by their policies (for example, have they criticized or tried to prevent this person from disclosing publicly)?
- e40 5y agoThe clear implication is by not fixing the bug in the same time frame.
- joshuamorton 5y agoWhat is the thing being implied? Like as far as I can tell, Google's position seems to be that "it is best if vuln researchers have the freedom to disclose unfixed issues, especially after reporting them". People criticize P0 for publishing issues despite companies asking for extensions. But we're criticizing Google here for...what? They didn't ask for an extension, they didn't try to prevent this person from disclosing. Where is the hypocritical thing?
- staticassertion 5y agoThey didn't fix it within that timeline. I don't know why everyone is saying "well they didn't stop disclosure in 90 days", but they didn't fix it in the timeline that they have allocated as being reasonable for all vulns they report.
- jsnell 5y agoAt the limit, what you're saying would mean that vendors should feel obligated to fix issues they don't consider to be vulnerabilities, as long as they're reported as such. That'd clearly be absurd. Is there maybe some additional qualifying factor that's required to trigger this obligation that you've left implicit?
- staticassertion 5y ago
- kerng 5y agoBoth are Google - from an outside view we shouldn't distinguish. Google should hold itself to a consistent bar. It highlights how divisions operate in silos at Google, and just because Project Zero causes a lot of positive security marketing for Google, it doesn't seem that the quality bar is consistently high across the company. Also, please don't forget this is still not fixed.
- dataflow 5y agoFunny thing is I agree with you that Google should hold itself to that bar, but I don't agree as to Project Zero being the reason. I think we very much should distinguish Google from P0, and that P0's policy should be irrelevant here; their entire purpose is to be an independent team of security researchers finding vulnerability in software, indiscriminately. It seems a number of others here feel similarly (judging by the responses), and ironically their support for the position is probably being lost by dragging P0 into the conversation. The reason I think Google should hold itself to that bar is something else: Google itself claims to use that bar. From the horse's mouth [1]: > This is why Google adheres to a 90-day disclosure deadline. We notify vendors of vulnerabilities immediately, with details shared in public with the defensive community after 90 days, or sooner if the vendor releases a fix. If they're going to do this to others as general company policy, they need to do this to themselves. [1] https://www.google.com/about/appsecurity/ https://www.google.com/about/appsecurity/
- sirdarckcat 5y agoAre you suggesting Google to make all unfixed vulnerabilities public after 90 days? Would that be even if the finder does not want them to become public? Or just as an opt-out type of thing.
- dataflow 5y agoI'm only suggesting Google needs to fix everything in 90 days (and reveal them afterward as they consider that standard practice) so they don't have unfixed vulnerabilities past that. I don't really have opinions on what policies they should have for cases where that isn't followed, though I think of thing even having a policy for that case encourages it not to be followed to begin with.
- tptacek 5y agoIf the people who reported this vulnerability had wanted to disclose it on P0's timeline, they were presumably free to do so.
- ajklsdhfniuwehf 5y agothat's fine and all, but what would they gain? Companies who use that response are even worse because they know very well there is no wining move from the researcher. The company have all the responsibility no matter what.
- staticassertion 5y agoI agree - they've been really strict about this too, and have even talked about reducing this window. To go 3x over the window is a bad look.
- kerng 5y agoAgreed, especially Google's comment early December about "holiday seasons" seems strange after not having done anything for 2 months already... When it comes to others (like Microsoft) Google is always quick to publish their findings, regardless of other circumstances.