Latest News

    • Home
    • Global
    • Google’s Project Zero is now being more considerate with how it discloses security vulnerabilities
    Google’s Project Zero is now being more considerate with how it discloses security vulnerabilities
    Thursday, January 9, 2020 IST
    Google’s Project Zero is now being more considerate with how it discloses security vulnerabilities

    ‘Full 90 days by default, regardless of when the bug is fixed’

     
     

    Google’s Project Zero cybersecurity team is trialling a new policy where it won’t make security vulnerabilities public early after a fix has been issued. “Full 90 days by default, regardless of when the bug is fixed,” is the team’s new policy, which it will trial for a year before deciding whether to adopt it permanently.
     
    Under the old system, Project Zero’s researchers would give vendors 90 days to fix an issue before making the problem public. However, if a patch was issued within that 90 day window, it would disclose the vulnerability early. This can be a problem, because it means users have to rush to patch a vulnerability before hackers can exploit it. A vulnerability might be fixed by the company, but that doesn’t matter if the patch hasn’t been widely adopted.
     
    USERS ARE ONLY SECURE ONCE THEY’VE INSTALLED THE PATCH
     
    So now, regardless of whether a patch is issued 20 days or 90 days after Project Zero makes a vendor aware of the problem, it will still wait 90 days to make the issue public. There are a couple of exceptions, though. One is when there’s “mutual agreement” between the two companies to disclose early, and Project Zero may also extend the deadline by 14 days if it’s taking longer for a vendor to put together a patch. The seven day deadline for vulnerabilities that are being exploited in the wild will remain unchanged.
     
    As well as giving patches more time to be adopted, Project Zero says it hopes the new policy will improve consistency, giving vendors a better idea of when a vulnerability will be made public. It also says it’s eager to see more iterative and thorough patches issued, thanks to the time vendors will now have between a patch initially being issued and the vulnerability it addresses being made public.
     
    Despite the changes, the Project Zero team says it’s broadly happy with how its disclosure period has worked until now. In 2014, when the team started its work, it says that bugs were sometimes not fixed six months after being discovered. Now, of the issues it’s identified (of which there have been many), it says 97.7 percent are patched within its 90 day window.
     

     
     

     
     
     
     
     

    Related Topics

     
     
     

    Trending News & Articles

     

    More in Global

     Article
    6 Things That Happen To Your Body When You Eat Probiotics Every Day

    Many people make the mistake of believing that all microorganisms are inherently bad, but that’s far from the truth! There are good microorganisms and bad one...

    Recently posted. 852 views . 1 min read
     

     Article
    Second hand smoke can be dangerous, one of the biggest reasons for still birth

    Exposure to secondhand smoke during pregnancy increases the risk of stillbirth, congenital malformations, low birth-weight and respiratory illnesses.

    Recently posted. 741 views . 1 min read
     

     Article
    Weightlifting helps improve brain health, muscle strength in adults over 55

    Australian researchers have found even more evidence for exercising into older age, finding humans over fifty-five with mild Cognitive Impairment can improve their ...

    Recently posted. 690 views . 18 min read
     

     Video
    10,000 YEARS INTO THE FUTURE IN 10 MINUTES



    Recently posted . 829 views
     

     Video
    Who is a MAN?



    Recently posted . 479 views
     

     Photo
    Top Honeymoon Destinations in India



    Recently posted . 1K views
     

     Photo
    10 Rare and Beautiful Birds



    Recently posted . 2K views
     

     Article
    Relieve Sciatica Lower Back And Hip Pain Using These 11 Piriformis Stretches!

    Sciatic nerve pain can be extremely difficult to handle. Sciatica appears because of many reasons: body injury, ruptured disk, spinal stenosis etc. ...

    Recently posted. 1K views . 1 min read
     

     Article
    What’s the most unexpected way to use garlic in a dish?

    Many of us lunge for garlic frequently in the usual ways in our kitchens: garlic bread, pasta sauces, a topping on pizza. But in honor of our favorite flavorful mem...

    Recently posted. 972 views . 2 min read
     

     
     
     

       Prashnavali

      Thought of the Day

    "Forgive others, not because they deserve forgiveness, but because you deserve peace."
    Anonymous

    Be the first one to comment on this story

    Close
    Post Comment
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST


    ads
    Back To Top