5 ms·
"And what does Google get out of paying top-notch salaries to fix flaws in other companies’ code? Evans insists Project Zero is “primarily altruistic.”" I thin
by cliveowen 12y ago
"And what does Google get out of paying top-notch salaries to fix flaws in other companies’ code? Evans insists Project Zero is “primarily altruistic.”"
I think it's great that Google is trying to make software more secure, but I don't believe there's an altruistic spirit behind it. I think these researchers do search for bugs in software other than Google's, sure, but it's software that Google uses to run its services, so in the end the aim is still to make their products secure.
- ZeroGravitas 12y agoI think it's slightly wider than that, a web with a reputation for being insecure drives people away from the web, and therefore away from Google services. There's a few Google projects where the basic aim seems to be "improve the internet/web". Still selfish from Google's perspective, but it's still something I can get behind.
- btilly 12y agoJust think of the potential PR fallout if someone important clicks on an ad on a Google site and their computer gets exploited. What is mitigating that risk worth to Google?
- DCKing 12y agoObviously Google makes more money when the web and 'software' has a better reputation. Even 'altruism' itself can be a business model for a company the size of Google if this improves their image and therefore their product sales. The amount of money they hypothetically make from this initiative is so hard to quantify that at least it doesn't seem to be a business-driven decision. It seems to qualify as 'altruistic' to me.
- tptacek 12y agoNo. Google already does that, better than any other company on the Internet. From the announcement, this project is different: We're not placing any particular bounds on this project and will work to improve the security of any software depended upon by large numbers of people, paying careful attention to the techniques, targets and motivations of attackers. We'll use standard approaches such as locating and reporting large numbers of vulnerabilities. In addition, we'll be conducting new research into mitigations, exploitation, program analysis—and anything else that our researchers decide is a worthwhile investment. Unless the word "any" means something different to Chris.