Results 1 to 11 of 11

Thread: News - Google's 'Project Zero' - a hacker squad hunting for vulnerabilities

  1. #1
    HEXUS.admin
    Join Date
    Apr 2005
    Posts
    31,709
    Thanks
    0
    Thanked
    2,073 times in 719 posts

    News - Google's 'Project Zero' - a hacker squad hunting for vulnerabilities

    The team was put together to help cut down targeted attacks across the Internet.
    Read more.

  2. #2
    Senior Member
    Join Date
    May 2014
    Posts
    2,385
    Thanks
    181
    Thanked
    304 times in 221 posts

    Re: News - Google's 'Project Zero' - a hacker squad hunting for vulnerabilities

    Google are one of the better bad companies out there. Anything positive is good, anything negative is bad. Same old same old

  3. #3
    Senior Member
    Join Date
    Jul 2013
    Location
    Dorset
    Posts
    477
    Thanks
    4
    Thanked
    22 times in 19 posts
    • LeetyMcLeet's system
      • Motherboard:
      • Gigabyte Auros X570 Master 1.2
      • CPU:
      • AMD Ryzen 9 5900X
      • Memory:
      • 64 GB 3600 DDR3 (G.Skill Trident Z)
      • Storage:
      • 250GB Samsung 980 Pro PCIe NVMe, 2 x 2TB Samsung 870 EVO SATA3, 2 x 6TB WD Black 3.5'' HDDs
      • Graphics card(s):
      • Nvidia RTX 3070Ti (MSI SUPRIM)
      • PSU:
      • Fractal Design ION Gold 750W
      • Case:
      • Fractal Design 7 Dark with TG Window
      • Operating System:
      • Windows 10 Pro x64
      • Monitor(s):
      • BenQ/Zowie XL @ 1080p, 240Hz
      • Internet:
      • BT Business FTTC/VDSL ~ 50Mbps

    Re: News - Google's 'Project Zero' - a hacker squad hunting for vulnerabilities

    This can only be good.... can't it?

  4. #4
    Senior Member
    Join Date
    May 2014
    Posts
    2,385
    Thanks
    181
    Thanked
    304 times in 221 posts

    Re: News - Google's 'Project Zero' - a hacker squad hunting for vulnerabilities

    Depends on how much flak they get for penetration testing other companies software. They can be accused of outright black hat hacking if a contract is not in place dictating it's being done grey hat for the greater good.

  5. #5
    Anthropomorphic Personification shaithis's Avatar
    Join Date
    Apr 2004
    Location
    The Last Aerie
    Posts
    10,857
    Thanks
    645
    Thanked
    872 times in 736 posts
    • shaithis's system
      • Motherboard:
      • Asus P8Z77 WS
      • CPU:
      • i7 3770k @ 4.5GHz
      • Memory:
      • 32GB HyperX 1866
      • Storage:
      • Lots!
      • Graphics card(s):
      • Sapphire Fury X
      • PSU:
      • Corsair HX850
      • Case:
      • Corsair 600T (White)
      • Operating System:
      • Windows 10 x64
      • Monitor(s):
      • 2 x Dell 3007
      • Internet:
      • Zen 80Mb Fibre

    Re: News - Google's 'Project Zero' - a hacker squad hunting for vulnerabilities

    Quote Originally Posted by Tabbykatze View Post
    Depends on how much flak they get for penetration testing other companies software. They can be accused of outright black hat hacking if a contract is not in place dictating it's being done grey hat for the greater good.
    Especially with the likes of Geohot on the team....

    I am sure though that companies will see the benefits once they start providing important security info to a few companies.
    Main PC: Asus Rampage IV Extreme / 3960X@4.5GHz / Antec H1200 Pro / 32GB DDR3-1866 Quad Channel / Sapphire Fury X / Areca 1680 / 850W EVGA SuperNOVA Gold 2 / Corsair 600T / 2x Dell 3007 / 4 x 250GB SSD + 2 x 80GB SSD / 4 x 1TB HDD (RAID 10) / Windows 10 Pro, Yosemite & Ubuntu
    HTPC: AsRock Z77 Pro 4 / 3770K@4.2GHz / 24GB / GTX 1080 / SST-LC20 / Antec TP-550 / Hisense 65k5510 4K TV / HTC Vive / 2 x 240GB SSD + 12TB HDD Space / Race Seat / Logitech G29 / Win 10 Pro
    HTPC2: Asus AM1I-A / 5150 / 4GB / Corsair Force 3 240GB / Silverstone SST-ML05B + ST30SF / Samsung UE60H6200 TV / Windows 10 Pro
    Spare/Loaner: Gigabyte EX58-UD5 / i950 / 12GB / HD7870 / Corsair 300R / Silverpower 700W modular
    NAS 1: HP N40L / 12GB ECC RAM / 2 x 3TB Arrays || NAS 2: Dell PowerEdge T110 II / 24GB ECC RAM / 2 x 3TB Hybrid arrays || Network:Buffalo WZR-1166DHP w/DD-WRT + HP ProCurve 1800-24G
    Laptop: Dell Precision 5510 Printer: HP CP1515n || Phone: Huawei P30 || Other: Samsung Galaxy Tab 4 Pro 10.1 CM14 / Playstation 4 + G29 + 2TB Hybrid drive

  6. #6
    Senior Member
    Join Date
    May 2014
    Posts
    2,385
    Thanks
    181
    Thanked
    304 times in 221 posts

    Re: News - Google's 'Project Zero' - a hacker squad hunting for vulnerabilities

    Quote Originally Posted by shaithis View Post
    I am sure though that companies will see the benefits once they start providing important security info to a few companies.
    You would hope so...but you know what these large companies are like: "You found a flaw in our system and told us so we could fix it and prevent major issues to our customer base. You could have been stealing data (or enter other stupid reason here) so prepare to be sued". C'est la vie.

  7. #7
    Admin (Ret'd)
    Join Date
    Jul 2003
    Posts
    18,481
    Thanks
    1,016
    Thanked
    3,208 times in 2,281 posts

    Re: News - Google's 'Project Zero' - a hacker squad hunting for vulnerabilities

    Quote Originally Posted by Tabbykatze View Post
    Depends on how much flak they get for penetration testing other companies software. They can be accused of outright black hat hacking if a contract is not in place dictating it's being done grey hat for the greater good.
    I doubt that.

    If they are penetration-testing someone else's system or software on machines belonging to those other people, yeah sure, get a contract to do it.

    If they nuy a copy of XYZ software, install it on thir own (Google) lab machines and test it, I can't see why they need either permission from, or even knowledge of, the software developers to do it.

    And, as pointed out, vulnerabilities found will only be reported to the developer, and not made public until a patch is available.

    In theory at least, the more legitimate people that probe and test, the better chance we all stand of problems being fixed before those that would exploit them find out.

    This SEEMS like a good idea, but personally, I have a very low opinion of Google and I'm just a bit reluctant to trust them on anything.

  8. #8
    Senior Member
    Join Date
    May 2014
    Posts
    2,385
    Thanks
    181
    Thanked
    304 times in 221 posts

    Re: News - Google's 'Project Zero' - a hacker squad hunting for vulnerabilities

    Ha ha, from what I've seen Saracen, you barely even trust yourself on the internet
    Well, you have to remember those little Ts & Cs when you install the software in addition to how far it broaches into the computer misuse act or the equivalent in each country

  9. #9
    ZaO
    Guest

    Re: News - Google's 'Project Zero' - a hacker squad hunting for vulnerabilities

    Quote Originally Posted by Tabbykatze View Post
    Google are one of the better bad companies out there.
    Haha yeh I think I would probably agree with that

    I never gave google my real name. And because of that, I haven't been able to comment on youtube videos for ages now! I hope this change means I'll be able to again. It sucks not being able to leave people feedback!

  10. #10
    Admin (Ret'd)
    Join Date
    Jul 2003
    Posts
    18,481
    Thanks
    1,016
    Thanked
    3,208 times in 2,281 posts

    Re: News - Google's 'Project Zero' - a hacker squad hunting for vulnerabilities

    Quote Originally Posted by Tabbykatze View Post
    Ha ha, from what I've seen Saracen, you barely even trust yourself on the internet
    Well, you have to remember those little Ts & Cs when you install the software in addition to how far it broaches into the computer misuse act or the equivalent in each country
    I trust myself. Just not much of anybody else.

    Computer Misuse Act isn't relevant, if you're testing on your own PC, because it's about unauthorised access.

    Got any examples of T&Cs that preclude you testing software on your own PCs for vulnerabilities? I'd love to do an article about software vendors so unsure of their own product they try to prevent users testing their security.

  11. #11
    Senior Member
    Join Date
    May 2014
    Posts
    2,385
    Thanks
    181
    Thanked
    304 times in 221 posts

    Re: News - Google's 'Project Zero' - a hacker squad hunting for vulnerabilities

    Microsoft's Services agreement for Office 365 :

    7.3. Are there things I can't do with the software or Services? Yes. In addition to the other restrictions in this Agreement, you may not circumvent or bypass any technological protection measures in or relating to the software or Services or disassemble, decompile, or reverse engineer any software or other aspect of the Services that's included in or accessible through the Services, except and only to the extent that the applicable copyright law expressly permits doing so; separate components of the software or Services for use on different devices; publish, copy, rent, lease, or lend the software or the Services; or transfer the software, any software licenses, or any rights to access or use the Services. You may not use the Services in any unauthorized way that could interfere with anyone else’s use of them or gain access to any service, data, account, or network. You may not enable access to the Services by unauthorized third-party applications.
    There are very similar entries on other software I use, Section 4.5 on Adobe's Licenses and Terms of use for example.

    So these are gerneralistically to do with decompiling or reverse engineering but unless they just sit there poking it with a stick, they're going to take a very long time to find the issues they want to find. If Google can prove all they're doing is poking then they might get away with it....any thing else and they're putting themselves out for a suit.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •