6 ms·
Project Zero has always been disguised marketing, and IMHO an extremely nasty form of it. I have no doubt they plan coordinated releases like this on a regular
by d2mw 7y ago
Project Zero has always been disguised marketing, and IMHO an extremely nasty form of it. I have no doubt they plan coordinated releases like this on a regular basis
(these downvotes are confusing. Do you disagree that it is marketing? That their approach is brutal? That they plan this regularly?)
- zerocrates 7y agoWhat's nasty about what they're doing here?
- d2mw 7y agoThey pay a team to embarrass competitors. The technical aspect is a small part of what is happening here.
- grenoire 7y agoCompetitors should be embarrassed when it concerns security flaws. It's one of the best ways to generate media buzz and inform customers about the flaws, and also their consequences.
- angulardementia 7y agoSo you don't view this as Apple getting free whitehat testing and a chance to not get hacked? I think there are two viewpoints you could take here and I think the truth is directly in the middle.
- ChrisSD 7y agoI wish my competitors "embarrassed" me by helping to improve my software for free.
- kps 7y ago… and to embarrass themselves? https://bugs.chromium.org/p/project-zero/issues/list?q=vendor%3AGoogle&can=1 https://bugs.chromium.org/p/project-zero/issues/list?q=vendo...
- jcims 7y agoThere are many possible motivations for Project Zero, and the reality is that more than one is likely responsible for the inception and ongoing sponsorship of the team's membership and activity. What made you settle on this specific one?
- Wowfunhappy 7y agoI agree that it's basically marketing, but what is the societal harm? That it makes Apple look bad? Remember, it's not like others would stop looking for these exploits if Google did.
- cptskippy 7y agoYou're assuming they're exposing the bugs for everyone's benefit when that might just be a side effect. Does Google harming the reputation of a competitor for it's own advantage not cause some societal harm? Or are we still pretending that some businesses are working in our best interests?
- Wowfunhappy 7y ago> Does Google harming the reputation of a competitor for it's own advantage not cause some societal harm? If they're harming the competitor's reputation by exposing a legitimate flaw in the competitor's product, I don't think that causes societal harm, no. Apple could open up their own Project Zero, if they wanted to. Then you'd have two competing companies making each other better, which sounds to me like the ideal of the free market.
- cptskippy 7y ago> If they're harming the competitor's reputation by exposing a legitimate flaw in the competitor's product, I don't think that causes societal harm, no. The act of rapid public disclosure compels the target to shift resources and focus to respond to those potential dumps. This can negatively impact the company's strategically and put them in damage control mode. In the case of Apple, they're not the dominant platform and are trying to pivot to be seen as the the secure and private platform. Google is damaging their credibility with that pivot by investing in finding vulnerabilities in their products and rapidly disclosing them. Short term this could improve the product but long term it could damage Apple's reputation and further diminish their market share and solidifying Google's. If Google were funding an independent research team tasked with securing the internet and platforms for the greater good that would be fine. But that isn't Project Zero. Project Zero is a weapon wielded by a company trying to protect it's monopoly.
- VikingCoder 7y agoGiving a company 90 days to fix a problem that may be currently exploited, harming end users, seems nasty to you? We should all be so lucky as to have Project Zero handing us free bug reports like that. Responsible companies PAY for bug reports on their products. Google is handing them over for free.
- rootusrootus 7y agoApple has a bug bounty program, yes? Are they paying Google for these?
- bobviolier 7y agoProbably not. I think that most of those bounties can only be redeemed when you sign an NDA.
- jefftk 7y agoWho requires an NDA? I don't believe Google does: https://www.google.com/about/appsecurity/reward-program/ https://www.google.com/about/appsecurity/reward-program/ (Disclosure: I work for Google)
- bobviolier 7y agoI meant the NDA from the party where the bug is reported, Apple in this case.
- devrand 7y agoProject Zero does not accept bounties. They generally ask for the money to be donated.
- rootusrootus 7y agoMakes sense. The bug bounty is meaningful money to an individual but it's just a pittance to Google.
- cameronbrown 7y agoSo what. I don't personally care if a company's marketing is affected - we as consumers have the right to know if iMessage or other protocols aren't secure. This is in the public interest and I'm glad Google's doing this. Apple can start their own Project Zero investigating Android if they want.
- pvg 7y agothese downvotes are confusing. You should check out https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html for some answers.
- computerex 7y agoWhy are the downvotes confusing? You are making completely unsubstantiated claims.
- tangue 7y ago90 days is enough to divert your next sprint from "Build new 3d Emojis" to "fix critical bugs". Of course it's not the same thing, but in the end : same company, same budget : just a question of priorities ... Project Zero is the stick. I still don't know what the carrot is.
- UncleMeat 7y agoBrutal? 90 days is unbelievably conservative. It's frankly ridiculous. Imagine you found weaknesses in a bridge. 90 days to disclose would be insane.
- lawnchair_larry 7y agoIt isn’t marketing and it isn’t brutal. It’s closer to charity.