Depending on who you ask, Google’s Project Zero is either the thing that’s going to singlehandedly save the internet, or the bane of many companies’ existence. It’s easy to see both sides of the argument.
On one hand, by uncovering previously undiscovered bugs in all manner of software and handing that information over to the authors, Google is undeniably performing a valued public service. The problem has never been with the “carrot” side of the equation, always with the stick.
The stick is this: Google gives each company 90 days in which to address the bug. If they take no action during that time, then Google will announce the existence of the bug to the world, which of course, means that hackers everywhere immediately have access to a new exploit.
This approach often accomplishes what contacting the vendor privately does not. Once the bug becomes common knowledge, the company in question is essentially forced to fix the problem, thus making the internet safer.
It should be noted that Google does allow exemptions to the 90-day rule. If a company is hard at work on a fix and needs more time, Google has been known to delay their announcement. In a similar vein, if a bug is simply catastrophic in scope and scale, the company has been known to make the announcement to help deploy resources of multiple companies toward addressing the issue.
More than 90 days ago, the Project Zero team discovered a pair of security flaws in Microsoft products. One in their Edge browser, and the other in the Windows 10 OS. One of the two got fixed. The other did not, and Google called them out for it.
Needless to say, Microsoft is not pleased, and they have hit Google back for such behavior in the past. They scored a PR victory last year when Microsoft engineers discovered a flaw in Google’s Chrome browser, and contacted the company privately so they could fix the issue and then bragged about their more responsible approach after the fact.
It will be interesting to see what Microsoft does in this instance.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
AT&T has big plans for their future and yours. If they’re your carrier of choice, and if you live in the cities of Dallas, Atlanta, or Waco, then you stand to be on the cutting edge of the changes the company has in store. Those locations have been selected to be the first to receive AT&T’s 5G network upgrade.
Android users have a reason to cheer. According to the latest report by ESET, the number of ransomware attacks targeting Android devices declined in 2017. The decline represents a bit of an anomaly, given that in 2017, the most common type of malware attack (by a wide margin) was ransomware. Given that security researchers can’t name a particular reason for the decline, it’s important not to read too much into the data. Whether there are declining figures or not, ransomware attacks still played a prominent role in last year’s threat landscape across a whole spectrum of devices. This year is shaping up to be no different.
Do you own a Mac? Do you use APFS “sparse disk images?” If so, be aware that under certain conditions, your trusty computer may allow you to copy important data into the void where it will be lost forever, without giving you a heads up first.
Hackers are picky about their victims. They’ll target just about any group or organization, including the 2018 Olympics.
Image theft is one of the biggest problems on the internet. If you’re a photographer, you’ve almost certainly lost money because people find your work online and make a copy of it rather than paying for the right to use it.
The latest Brand Finance Global 500 report out and contains some surprises this year.
That smartwatch you’re wearing might save your life. Literally.
Microsoft is getting tough on so-called “registry cleaners”, and it’s about time. The company recently announced a planned change to Windows Defender (the anti-malware program that comes standard with every Windows installation). The change will see to the deletion of an increasing number of these registry cleaners. It’s a great move, and the company deserves credit for it, but there’s a catch. This type of software has been around for decades. So the move, as welcome as it is, comes very late in the game.
Security researchers from around the web are reporting finding an increasing number of instances of proof of concept (PoC) code that incorporates the recently discovered Spectre and Meltdown vulnerabilities.