A network-related or instance-specific error occurred while establishing a connection to SQL Server. The server was not found or was not accessible. Verify that the instance name is correct and that SQL Server is configured to allow remote connections. (provider: Named Pipes Provider, error: 40 - Could not open a connection to SQL Server) Google’s Project Zero is now being more considerate with how it discloses security vulnerabilities, Global : Today Indya

Latest News

  • Home
  • Global
  • Google’s Project Zero is now being more considerate with how it discloses security vulnerabilities
Google’s Project Zero is now being more considerate with how it discloses security vulnerabilities
Thursday, January 9, 2020 IST
Google’s Project Zero is now being more considerate with how it discloses security vulnerabilities

‘Full 90 days by default, regardless of when the bug is fixed’

 
 

Google’s Project Zero cybersecurity team is trialling a new policy where it won’t make security vulnerabilities public early after a fix has been issued. “Full 90 days by default, regardless of when the bug is fixed,” is the team’s new policy, which it will trial for a year before deciding whether to adopt it permanently.
 
Under the old system, Project Zero’s researchers would give vendors 90 days to fix an issue before making the problem public. However, if a patch was issued within that 90 day window, it would disclose the vulnerability early. This can be a problem, because it means users have to rush to patch a vulnerability before hackers can exploit it. A vulnerability might be fixed by the company, but that doesn’t matter if the patch hasn’t been widely adopted.
 
USERS ARE ONLY SECURE ONCE THEY’VE INSTALLED THE PATCH
 
So now, regardless of whether a patch is issued 20 days or 90 days after Project Zero makes a vendor aware of the problem, it will still wait 90 days to make the issue public. There are a couple of exceptions, though. One is when there’s “mutual agreement” between the two companies to disclose early, and Project Zero may also extend the deadline by 14 days if it’s taking longer for a vendor to put together a patch. The seven day deadline for vulnerabilities that are being exploited in the wild will remain unchanged.
 
As well as giving patches more time to be adopted, Project Zero says it hopes the new policy will improve consistency, giving vendors a better idea of when a vulnerability will be made public. It also says it’s eager to see more iterative and thorough patches issued, thanks to the time vendors will now have between a patch initially being issued and the vulnerability it addresses being made public.
 
Despite the changes, the Project Zero team says it’s broadly happy with how its disclosure period has worked until now. In 2014, when the team started its work, it says that bugs were sometimes not fixed six months after being discovered. Now, of the issues it’s identified (of which there have been many), it says 97.7 percent are patched within its 90 day window.
 

 
 
 
 
 

Related Topics

 
 
 

Trending News & Articles

 Article
'Worse than prison': A rare look inside China's detention camps to 'brainwash' Muslims

ALMATY: Hour upon hour, day upon day, Omir Bekali and other detainees in far western China's new indoctrination camps had to disavow the...

Recently posted . 219K views . 1 min read
 

 Article
What The Shape Of Your Belly Button Says About Your Health

If you have payed attention to the belly buttons of people on the beach or the members of your family, you have probably noticed that they have different shapes and...

Recently posted . 10K views . 2 min read
 

 Article
New ‘Langya’ virus hits China as 35 people found infected: How deadly is it?

The Langya henipavirus has a place with a similar group of infections, including Nipah, which is known to kill up to 3/4 of people in extreme cases.

Recently posted . 6K views . 1 min read
 

 Article
Queen Elizabeth Dies At 96: The New Royal Line Of Succession

Queen's death: The eldest of her four children, Charles, Prince of Wales, who at 73 was the oldest heir apparent in British history, became king immediately...

Recently posted . 5K views . 1 min read
 

 
 

More in Global

 Article
India begins countdown to launch 31 satellites on Friday

The spaceport Sriharikota High Altitude Range (SHAR) is located about 80 km northeast of Chennai off the Bay of Bengal coast

Recently posted. 732 views . 0 min read
 

 Article
China worried ban on Azhar will make Jaish target CPEC

China is worried an action at the UN will make CPEC a target of the Jaish-e-Mohammad.

Recently posted. 755 views . 0 min read
 

 Article
Virgin Atlantic Flight Reaches Speed of 1300 Kilometers Per Hour; Sets New Record

It should be noted that the erstwhile Concorde flight service, which flew between New York and London, typically flew at 2140 km/h or 1334 mph), more than twice the...

Recently posted. 879 views . 1 min read
 

 Video
Top10Linch - World's smallest baby 2015



Recently posted . 1K views
 

 Photo
World's 10 most expensive cities in 2018



Recently posted . 2K views
 

 Reviews
Leaseweb hosting review



Recently posted . 4K views . 67 min read
 

 Reviews
The Best 5 Camping Tents in India 2018 – Reviews & Buying Guide



Recently posted . 4K views . 99 min read
 

 Article
North Korea Fires Missile Over Japan; US Confirms Launch

North Korea pink-slipped a missile that skipped over Japan on Tues. The us confirmed the missile launch by the nuclear-armed country. South Korea's J...

Recently posted. 1K views . 16 min read
 

 Article
Parents Taught Us Slow and Steady Wins the Race, They Weren’t Wrong!

We all have that sweet childhood memory of saving every rupee in our little piggy bank either to buy that favourite video game or a dress or shoes. Also, while grow...

Recently posted. 1K views . 2 min read
 

 
 
 

   Prashnavali

  Thought of the Day

"If you're going through hell keep going."
Winston Churchill

Be the first one to comment on this story

Close
Post Comment
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST


ads
Back To Top