4 ms·
And here is EP004 BUG HUNTERS: https://www.youtube.com/watch?v=IoXiXlCNoXg https://www.youtube.com/watch?v=IoXiXlCNoXg
by markoman 4y ago
And here is EP004 BUG HUNTERS: https://www.youtube.com/watch?v=IoXiXlCNoXg https://www.youtube.com/watch?v=IoXiXlCNoXg
- O__________O 4y agoHmmm... page loads, but clicking play results in an error; 76 views, 5 likes. ________ EDIT: Able to access the videos via the direct non-web links, but any of the ones with audio baked in are not accessible; the ones without audio do play. Assuming it’s glitch and will fix it itself.
- deleted 4y ago[deleted]
- O__________O 4y agoSummary: Covers Google Bug Bounty program including interviews with staff and the top bounty hunters. Response: As mentioned in the video, Knuth’s bounty program was largely to help him feel better about publishing a book with errors; checks are largely symbolic and rarely cashed, since they’re only worth few dollars. Similarly, black market for bugs continues to offer higher payouts than white hat markets. It’s an issue and building communities alone around bug bounties will neither fix it, nor stop true adversaries from developing talent and technology that exceeds current capacities, capabilities, etc. Obviously, complex problem, but if Google is going to market and position themselves as a community resource for protecting people, they need to be direct and honest about the limits of reality and the constraints they’re forced to work within; for example, that their interests, nation states, etc - frequently have security concerns that conflict with user security. _______________________ Links related to video: - https://wikipedia.org/wiki/Bounty_(reward) https://wikipedia.org/wiki/Bounty_(reward) - https://wikipedia.org/wiki/The_Art_of_Computer_Programming https://wikipedia.org/wiki/The_Art_of_Computer_Programming - https://wikipedia.org/wiki/Knuth_reward_check https://wikipedia.org/wiki/Knuth_reward_check - https://securitymagazine.com/articles/95726-google-launches-bug-hunters-community https://securitymagazine.com/articles/95726-google-launches-... - https://wikipedia.org/wiki/Market_for_zero-day_exploits https://wikipedia.org/wiki/Market_for_zero-day_exploits _______________________ Meta: YouTube bug to playing video with audio is fixed. Also, appears this is last full episode in the series; full playlist is now up here: https://m.youtube.com/playlist?list=PL590L5WQmH8dsxxz7ooJAgmijwOz0lh2H https://m.youtube.com/playlist?list=PL590L5WQmH8dsxxz7ooJAgm...
- O__________O 4y ago(Oops, Google posted another one to play list.) _________________________ EP005: Project Zero | HACKING GOOGLE - https://youtube.com/watch?v=My_13FXODdU https://youtube.com/watch?v=My_13FXODdU Summary: Covers Google’s Project Zero team, which is tasked hunting zero day exploits across the internet in software, hardware, and Google products. Response: Beyond basic information and covering already publicly disclosed zero-days Project Zero has discovered, there was not much incite into how they prioritize research or hope to bring zero days down longer even as technology changes. _________________________ Related links from video: - https://en.m.wikipedia.org/wiki/Siege_of_Château_Gaillard https://en.m.wikipedia.org/wiki/Siege_of_Château_Gaillard - https://googleprojectzero.blogspot.com/?m=1 https://googleprojectzero.blogspot.com/?m=1 - https://en.m.wikipedia.org/wiki/Project_Zero https://en.m.wikipedia.org/wiki/Project_Zero - https://en.m.wikipedia.org/wiki/Zero-day_(computing) https://en.m.wikipedia.org/wiki/Zero-day_(computing) - https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Can-You-Hear-Me-Now-Remote-Eavesdropping-Vulnerabilities-In-Mobile-Messaging-Applications.pdf https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Can-Yo... - https://en.m.wikipedia.org/wiki/L0pht https://en.m.wikipedia.org/wiki/L0pht - https://googleprojectzero.blogspot.com/p/vulnerability-disclosure-policy.html?m=1 https://googleprojectzero.blogspot.com/p/vulnerability-discl... - https://googleprojectzero.blogspot.com/2019/08/a-very-deep-dive-into-ios-exploit.html?m=1 https://googleprojectzero.blogspot.com/2019/08/a-very-deep-d...
- O__________O 4y agoHacking Google to Defend Enterprises - YouTube - https://m.youtube.com/watch?v=dhdz5VZ4S88 https://m.youtube.com/watch?v=dhdz5VZ4S88 _________________ Summary: Chief Information Security Officer of Google Cloud, Phil Venables, covers all the teams listed in prior videos and describes how Google Cloud helps secure its customers. Response: As an outsider watching video series, while it is possible I misunderstood, appears the Google Cloud CISO is the highest-level security leadership role within Google, which might be confusing to random outsider, since generally the public thinks of Google being Google, not Google Cloud. Lastly, as evident by my posts, really wish this had been accompanied by blog posts with links. These videos are obviously targeting general public and potential hires, but Google neither links to job opportunities or submit security issues, nor provides a way generally speaking to engage them with feedback, questions, etc - of the series or Google Security in general. _________________ Related links from video: - https://www.google.com/search?q=google.cloud+ciso+phil+venables https://www.google.com/search?q=google.cloud+ciso+phil+venab... - https://cloud.google.com/security https://cloud.google.com/security - https://www.google.com/appserve/security-bugs/m2/new https://www.google.com/appserve/security-bugs/m2/new - https://bughunters.google.com/ https://bughunters.google.com/