A network-related or instance-specific error occurred while establishing a connection to SQL Server. The server was not found or was not accessible. Verify that the instance name is correct and that SQL Server is configured to allow remote connections. (provider: Named Pipes Provider, error: 40 - Could not open a connection to SQL Server) Twitter Is Shocked To See The Amount Of Money Found After An IT Raid On A Pharma Company In Hyderabad, Others : Today Indya

Latest News

  • Home
  • Global
  • Google’s Project Zero is now being more considerate with how it discloses security vulnerabilities
Google’s Project Zero is now being more considerate with how it discloses security vulnerabilities
Thursday, January 9, 2020 IST
Google’s Project Zero is now being more considerate with how it discloses security vulnerabilities

‘Full 90 days by default, regardless of when the bug is fixed’

 
 

Google’s Project Zero cybersecurity team is trialling a new policy where it won’t make security vulnerabilities public early after a fix has been issued. “Full 90 days by default, regardless of when the bug is fixed,” is the team’s new policy, which it will trial for a year before deciding whether to adopt it permanently.
 
Under the old system, Project Zero’s researchers would give vendors 90 days to fix an issue before making the problem public. However, if a patch was issued within that 90 day window, it would disclose the vulnerability early. This can be a problem, because it means users have to rush to patch a vulnerability before hackers can exploit it. A vulnerability might be fixed by the company, but that doesn’t matter if the patch hasn’t been widely adopted.
 
USERS ARE ONLY SECURE ONCE THEY’VE INSTALLED THE PATCH
 
So now, regardless of whether a patch is issued 20 days or 90 days after Project Zero makes a vendor aware of the problem, it will still wait 90 days to make the issue public. There are a couple of exceptions, though. One is when there’s “mutual agreement” between the two companies to disclose early, and Project Zero may also extend the deadline by 14 days if it’s taking longer for a vendor to put together a patch. The seven day deadline for vulnerabilities that are being exploited in the wild will remain unchanged.
 
As well as giving patches more time to be adopted, Project Zero says it hopes the new policy will improve consistency, giving vendors a better idea of when a vulnerability will be made public. It also says it’s eager to see more iterative and thorough patches issued, thanks to the time vendors will now have between a patch initially being issued and the vulnerability it addresses being made public.
 
Despite the changes, the Project Zero team says it’s broadly happy with how its disclosure period has worked until now. In 2014, when the team started its work, it says that bugs were sometimes not fixed six months after being discovered. Now, of the issues it’s identified (of which there have been many), it says 97.7 percent are patched within its 90 day window.
 

 
 

 
 
 
 
 

Related Topics

 
 
 

Trending News & Articles

 Article
Five ways to refresh your kitchen in under Rs 3 lakh

Simple tips to help you design your kitchen on a budget while avoiding any structural changes.

Recently posted . 3K views . 0 min read
 

 Article
Travellers Who Dumped Pizza Boxes On Karnataka Road Made To Go Back 80 Kms To Pick Up Trash

Have you seen or been one of those people who toss garbage out of your car window on the roads? Well, if you're travelling to Karnataka then you're going to...

Recently posted . 3K views . 1 min read
 

 Article
Twitter Is Shocked To See The Amount Of Money Found After An IT Raid On A Pharma Company In Hyderabad

However, a picture apparently from this raid is doing the rounds and it has caught a lot of attention. The picture shows a cupboard filled with wads of cash.

Recently posted . 2K views . 1 min read
 

 Article
When do upper middle-class urban youngsters start thinking of themselves as poor?

When do upper middle-class urban youngsters start thinking of themselves as poor?

Recently posted . 2K views . 0 min read
 

 
 

More in Global

 Article
Man Who Captured Three Bear Cubs Dancing & Playing Like Human Kids, Thought He Was Imagining It

There is no way to know what goes on inside the depths of the forests, how some animals behave when they are…not seen. However, a few years ago, a physical e...

Recently posted. 1K views . 2 min read
 

 Article
Spooky 'Blood Snow' Spotted In Antarctica. See Viral Pics

The photographs show white snow with streaks of blood red.

Recently posted. 1K views . 0 min read
 

 Article
Burj Khalifa, Eiffel Tower: What Indians Can ‘See’ From Noida, Indore as Pollution is Less

With automobiles and industrial work shut down, pollution levels across India have witnessed a drastic fall.

Recently posted. 1K views . 0 min read
 

 Video
This $2,000.00 mask is so Realastic!!



Recently posted . 2K views
 

 Article
Engineer-Turned-Farmer’s Way of Growing Yellow Watermelons Takes Goa By Storm

250 delicious organic watermelons in just 4X4 square metres. Nitesh spent only Rs 4,000 to grow them and earned more than Rs 30,000 on selling them! #FarmersFirst...

Recently posted. 1K views . 1 min read
 

 Article
Ratan Tata's New Campaign Helps Those Working A Job Nobody Wants. See His Powerful Post

"Mission Garima, for our brave sanitation workers," wrote Ratan Tata.

Recently posted. 1K views . 0 min read
 

 
 
 

   Prashnavali

  Thought of the Day

“Your thoughts shape your vision. You see what you choose to see.”
Anonymous

Be the first one to comment on this story

Close
Post Comment
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST


ads
Back To Top