Latest News

    • Home
    • Global
    • Google’s Project Zero is now being more considerate with how it discloses security vulnerabilities
    Google’s Project Zero is now being more considerate with how it discloses security vulnerabilities
    Thursday, January 9, 2020 IST
    Google’s Project Zero is now being more considerate with how it discloses security vulnerabilities

    ‘Full 90 days by default, regardless of when the bug is fixed’

     
     

    Google’s Project Zero cybersecurity team is trialling a new policy where it won’t make security vulnerabilities public early after a fix has been issued. “Full 90 days by default, regardless of when the bug is fixed,” is the team’s new policy, which it will trial for a year before deciding whether to adopt it permanently.
     
    Under the old system, Project Zero’s researchers would give vendors 90 days to fix an issue before making the problem public. However, if a patch was issued within that 90 day window, it would disclose the vulnerability early. This can be a problem, because it means users have to rush to patch a vulnerability before hackers can exploit it. A vulnerability might be fixed by the company, but that doesn’t matter if the patch hasn’t been widely adopted.
     
    USERS ARE ONLY SECURE ONCE THEY’VE INSTALLED THE PATCH
     
    So now, regardless of whether a patch is issued 20 days or 90 days after Project Zero makes a vendor aware of the problem, it will still wait 90 days to make the issue public. There are a couple of exceptions, though. One is when there’s “mutual agreement” between the two companies to disclose early, and Project Zero may also extend the deadline by 14 days if it’s taking longer for a vendor to put together a patch. The seven day deadline for vulnerabilities that are being exploited in the wild will remain unchanged.
     
    As well as giving patches more time to be adopted, Project Zero says it hopes the new policy will improve consistency, giving vendors a better idea of when a vulnerability will be made public. It also says it’s eager to see more iterative and thorough patches issued, thanks to the time vendors will now have between a patch initially being issued and the vulnerability it addresses being made public.
     
    Despite the changes, the Project Zero team says it’s broadly happy with how its disclosure period has worked until now. In 2014, when the team started its work, it says that bugs were sometimes not fixed six months after being discovered. Now, of the issues it’s identified (of which there have been many), it says 97.7 percent are patched within its 90 day window.
     

     
     

     
     
     
     
     

    Related Topics

     
     
     

    Trending News & Articles

     

    More in Global

     Article
    ICC World Cup 2019: India’s all-time World Cup XI - Virat Kohli misses out

    As the country gets ready to cheer for the ‘Men in Blue’ in the upcoming World Cup, we bring to you India’s all-time World Cup XI, comprising play...

    Recently posted. 734 views . 1 min read
     

     Article
    MS Dhoni, Gautam Gambhir likely to contest on BJP ticket in 2019 Lok Sabha elections - Report

    Ruling party BJP is in talks with Gautam Gambhir and MS Dhoni to rope them in as their star campaigners for the 2019 elections. Dhoni and Gambhir may likely conte...

    Recently posted. 694 views . 1 min read
     

     Article
    Eugenie Bouchard’s poor form continues, exits Miami Open first round

    Eugenie Bouchard lost to Australia’s Ashleigh Barty int he first round of the Miami Open. Barty will next face Samantha Stosur Eugenie Bouchard&rsq...

    Recently posted. 591 views . 16 min read
     

     Video
    How train change the track



    Recently posted . 977 views
     

     Article
    ‘At 17, my family sent me to see a psychologist’: Roger Federer reveals angry teenage phase

    The 19-time Grand Slam champion said that as a teenager he was so angry on court that he would throw his racket every time a match was slipping out of his hand.

    Recently posted. 488 views . 1 min read
     

     Article
    IPL Auction | How the Teams Stack Up After Reinforcing Squads

    351 players were in contention for 70 possible vacant spots at the IPL 2019 Auctions in Jaipur on Tuesday. When the process was completed, a total of 60 were sold...

    Recently posted. 618 views . 1 min read
     

     
     
     

       Prashnavali

      Thought of the Day

    "Inspiration Exists But It Has To Find You Working."
    Pablo Picasso

    Be the first one to comment on this story

    Close
    Post Comment
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST


    ads
    Back To Top