Tag Archive for: Google

Google scraps annual Pwnium bug-hunting contest

Google is scrapping Pwnium, its annual bug hunting event, and folding it into an existing year-round program in part to reduce security risks.

The company held Pwnium annually at CanSecWest, a security conference in Vancouver, to find security problems in its Chrome OS, Chrome browser and affiliated applications.

But Tim Willis of the Chrome Security Team wrote in a blog post that the annual event isn’t best for either researchers or the company.

To read this article in full or to leave a comment, please click here

Network World Security

Google updates disclosure policy after Windows, OS X zero-day controversy

In a blog post today, the Google Security team announced changes to policies on full disclosure of bugs found by Project Zero, the security research team that uncovered zero-day vulnerabilities recently revealed in Microsoft’s Windows 8.1 and Apple’s OS X operating systems. Those disclosures, which were made 90 days after Google alerted Microsoft and Apple in accordance with Project Zero’s strict release policy, stirred controversy because they had not yet been patched—and gave attackers time to leverage them before Microsoft and Apple distributed fixes.

The announcement, authored by Project Zero’s Chris Evans and Ben Hawkes, Google Security’s Heather Adkins, Matt Moore, and Michal Zalewski, and Google Security Vice President Gerhard Eschelbeck noted, “Disclosure deadlines have long been an industry standard practice,” citing the disclosure policies of the Carnegie-Mellon CERT, Yahoo, and TippingPoint’s Zero Day Initiative. Deadline policies for vendor disclosure “improve end-user security by getting security patches to users faster,” the Google team stated.

Project Zero set a 90-day deadline, and since Project Zero’s launch, Google’s team claimed, “of the 154 Project Zero bugs fixed so far, 85% were fixed within 90 days. Restrict this to the 73 issues filed and fixed after Oct 1st, 2014, and 95% were fixed within 90 days.” The Microsoft and Apple bugs disclosed and other deadline misses by vendors, they noted, “were typically fixed very quickly after 90 days. Looking ahead, we’re not going to have any deadline misses for at least the rest of February.”

Read 5 remaining paragraphs | Comments


Ars Technica » Technology Lab

Why Google won’t fix Android security flaw – whnt.com


Forbes

Why Google won't fix Android security flaw
whnt.com
(CBS News) – Google has admitted that there is a security issue that can leave phones and tablets running older versions of Android open to hacking. And the company says it's not planning to do anything about it. Unlike Apple, which makes a big deal of …
"No Longer Practical" For Google To Update Android's Critical Security FlawForbes
Android WebView exploits: Google explains lack of patches and advises users to The Guardian
Google to Android Owners: You're on Your OwnTop Tech News
Computerworld –ZDNet
all 63 news articles »

“android security” – read more

​Why Google won’t fix Android security flaw – CBS News


Forbes

​Why Google won't fix Android security flaw
CBS News
Google has admitted that there is a security issue that can leave phones and tablets running older versions of Android open to hacking. And the company says it's not planning to do anything about it. Unlike Apple, which makes a big deal of releasing
​Google: Why we won't patch pre-KitKat Android WebViewZDNet
"No Longer Practical" For Google To Update Android's Critical Security FlawForbes
Google to Android Owners: You're on Your OwnCIO Today
The Guardian –Computerworld –International Business Times, India Edition
all 49 news articles »

“android security” – read more