{"id":253,"date":"2015-01-15T01:25:07","date_gmt":"2015-01-15T01:25:07","guid":{"rendered":"http:\/\/outworx.com\/blog\/?p=253"},"modified":"2015-02-17T22:02:02","modified_gmt":"2015-02-17T22:02:02","slug":"chill-google-project-zero","status":"publish","type":"post","link":"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/","title":{"rendered":"Chill Out, Google Project Zero!"},"content":{"rendered":"<p>On October 13, 2014, Google notified Microsoft that they had found a security bug in their software. Google&#8217;s Project Zero gives vendors 90 days before publicly disclosing the bug. \u00a0Microsoft fixed the bug, and asked Google for a bit more time so they could release the fix on their customary Patch Tuesday. \u00a0Google ignored Microsoft&#8217;s request, and released details of the vulnerability\u00a0on Sunday, January 11, 2015 &#8212; a mere two days before Patch Tuesday.<\/p>\n<p>Google acted poorly.<\/p>\n<p>By pedantically following their 90 day policy, Google made sure that that the security bug was publicly known before a fix that they knew was coming just a few days later. \u00a0This doesn&#8217;t benefit anyone. \u00a0And by publishing the vulnerability on a Sunday, they made sure that Microsoft could not respond to it as effectively as on a work day. \u00a0Again, how does this benefit the community at large?<\/p>\n<p>Behind Google&#8217;s actions is the raging debate between <em>full disclosure<\/em> and <em>responsible disclosure<\/em>. \u00a0Full disclosure involves publishing vulnerabilities as soon as discovered, or more commonly after some time has passed and the vendor has not fixed them. \u00a0At first glance, full disclosure may seem irresponsible. \u00a0Why inform the bad guys when there is no fix? \u00a0But full disclosure does have an important use. \u00a0Often, a security researcher notifies the company of a bug, and\u00a0the company does not do anything. \u00a0But when the bug is published, companies typically take it much more seriously and fix it. \u00a0So full disclosure, used judiciously, does make software more secure.<\/p>\n<p>Responsible disclosure involves notifying the company of the bug, and keeping it under wraps until the company fixes it. \u00a0This\u00a0can make it easier for the company to respond and schedule the fix. \u00a0The downside is that if the company is slow, then a bad guy may discover it on his own and exploit it while customers have no idea about the vulnerability.<\/p>\n<p>Google leans toward full disclosure, but after a 90 day period. \u00a0Microsoft leans toward responsible disclosure.<\/p>\n<p>That said, Google should have waited two more days before disclosing the bug. \u00a0In this case, their disclosure had little value and did more harm than good. \u00a0It did not force Microsoft into fixing the bug. \u00a0Microsoft had already done that. \u00a0But it did give the hackers a two day window of opportunity.<\/p>\n<p>Google needs to amend their policy. \u00a0They should do two things:<\/p>\n<p>1.) When a vendor notifies them that a fix is coming in a short period after the 90 day period, they should wait. \u00a0They should also talk with the vendor so both sides know what the other intends &#8212; even if they disagree.<\/p>\n<p>2.) Google should never publish vulnerabilities on non-work days unless there is a compelling (and not pedantic) reason for doing so. \u00a0This places the vendor in a better situation to respond to the disclosure, and that benefits everyone.<\/p>\n<p>&nbsp;<\/p>\n<p><em>\u00a02\/17\/2015 Update. \u00a0Google has announced that they will\u00a0now disclose bugs on business days. \u00a0If a company contacts Google and asks for a two week extension for the patch, Google will now grant that.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On October 13, 2014, Google notified Microsoft that they had found a security bug in their software. Google&#8217;s Project Zero gives vendors 90 days before publicly disclosing the bug. \u00a0Microsoft fixed the bug, and asked Google for a bit more time so they could release the fix on their customary Patch Tuesday. \u00a0Google ignored Microsoft&#8217;s &hellip; <a href=\"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Chill Out, Google Project Zero!&#8221;<\/span><\/a><\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"xn-wppe-expiration":[],"xn-wppe-expiration-action":[],"xn-wppe-expiration-prefix":[],"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0},"categories":[13],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Chill Out, Google Project Zero! | OutworX<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Chill Out, Google Project Zero! | OutworX\" \/>\n<meta property=\"og:description\" content=\"On October 13, 2014, Google notified Microsoft that they had found a security bug in their software. Google&#8217;s Project Zero gives vendors 90 days before publicly disclosing the bug. \u00a0Microsoft fixed the bug, and asked Google for a bit more time so they could release the fix on their customary Patch Tuesday. \u00a0Google ignored Microsoft&#8217;s &hellip; Continue reading &quot;Chill Out, Google Project Zero!&quot;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/\" \/>\n<meta property=\"og:site_name\" content=\"OutworX\" \/>\n<meta property=\"article:published_time\" content=\"2015-01-15T01:25:07+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2015-02-17T22:02:02+00:00\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Outworx\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.outworx.com\/blog\/#website\",\"url\":\"https:\/\/www.outworx.com\/blog\/\",\"name\":\"OutworX\",\"description\":\"Blogs, News and Updates of IT Industry | OutworX\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.outworx.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/#webpage\",\"url\":\"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/\",\"name\":\"Chill Out, Google Project Zero! | OutworX\",\"isPartOf\":{\"@id\":\"https:\/\/www.outworx.com\/blog\/#website\"},\"datePublished\":\"2015-01-15T01:25:07+00:00\",\"dateModified\":\"2015-02-17T22:02:02+00:00\",\"author\":{\"@id\":\"https:\/\/www.outworx.com\/blog\/#\/schema\/person\/e305dc141a7e95d5a79eb095ac1f1461\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.outworx.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Chill Out, Google Project Zero!\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.outworx.com\/blog\/#\/schema\/person\/e305dc141a7e95d5a79eb095ac1f1461\",\"name\":\"Outworx\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.outworx.com\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/01a175d14b9fd311bc14945e82e36b1d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/01a175d14b9fd311bc14945e82e36b1d?s=96&d=mm&r=g\",\"caption\":\"Outworx\"},\"sameAs\":[\"http:\/\/www.outworx.com\"],\"url\":\"https:\/\/www.outworx.com\/blog\/author\/outworx\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Chill Out, Google Project Zero! | OutworX","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/","og_locale":"en_US","og_type":"article","og_title":"Chill Out, Google Project Zero! | OutworX","og_description":"On October 13, 2014, Google notified Microsoft that they had found a security bug in their software. Google&#8217;s Project Zero gives vendors 90 days before publicly disclosing the bug. \u00a0Microsoft fixed the bug, and asked Google for a bit more time so they could release the fix on their customary Patch Tuesday. \u00a0Google ignored Microsoft&#8217;s &hellip; Continue reading \"Chill Out, Google Project Zero!\"","og_url":"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/","og_site_name":"OutworX","article_published_time":"2015-01-15T01:25:07+00:00","article_modified_time":"2015-02-17T22:02:02+00:00","twitter_misc":{"Written by":"Outworx","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/www.outworx.com\/blog\/#website","url":"https:\/\/www.outworx.com\/blog\/","name":"OutworX","description":"Blogs, News and Updates of IT Industry | OutworX","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.outworx.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/#webpage","url":"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/","name":"Chill Out, Google Project Zero! | OutworX","isPartOf":{"@id":"https:\/\/www.outworx.com\/blog\/#website"},"datePublished":"2015-01-15T01:25:07+00:00","dateModified":"2015-02-17T22:02:02+00:00","author":{"@id":"https:\/\/www.outworx.com\/blog\/#\/schema\/person\/e305dc141a7e95d5a79eb095ac1f1461"},"breadcrumb":{"@id":"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.outworx.com\/blog\/chill-google-project-zero\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.outworx.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Chill Out, Google Project Zero!"}]},{"@type":"Person","@id":"https:\/\/www.outworx.com\/blog\/#\/schema\/person\/e305dc141a7e95d5a79eb095ac1f1461","name":"Outworx","image":{"@type":"ImageObject","@id":"https:\/\/www.outworx.com\/blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/01a175d14b9fd311bc14945e82e36b1d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/01a175d14b9fd311bc14945e82e36b1d?s=96&d=mm&r=g","caption":"Outworx"},"sameAs":["http:\/\/www.outworx.com"],"url":"https:\/\/www.outworx.com\/blog\/author\/outworx\/"}]}},"_links":{"self":[{"href":"https:\/\/www.outworx.com\/blog\/wp-json\/wp\/v2\/posts\/253"}],"collection":[{"href":"https:\/\/www.outworx.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.outworx.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.outworx.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.outworx.com\/blog\/wp-json\/wp\/v2\/comments?post=253"}],"version-history":[{"count":3,"href":"https:\/\/www.outworx.com\/blog\/wp-json\/wp\/v2\/posts\/253\/revisions"}],"predecessor-version":[{"id":280,"href":"https:\/\/www.outworx.com\/blog\/wp-json\/wp\/v2\/posts\/253\/revisions\/280"}],"wp:attachment":[{"href":"https:\/\/www.outworx.com\/blog\/wp-json\/wp\/v2\/media?parent=253"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.outworx.com\/blog\/wp-json\/wp\/v2\/categories?post=253"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.outworx.com\/blog\/wp-json\/wp\/v2\/tags?post=253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}