Google Project Zero changes the approach to disclosing vulnerability data

According to network sources, this year the Google Project Zero research team, which focuses on information security, will change its rules regarding how data about discovered vulnerabilities becomes public knowledge.

Under the new rules, information about identified vulnerabilities will not be made public until after a 90-day period. Regardless of when developers resolve the issue, Project Zero representatives will not disclose information about it publicly. The new rules will be in effect this year, after which researchers will assess the feasibility of implementing them on a permanent basis.

Google Project Zero changes the approach to disclosing vulnerability data

In the past, Project Zero researchers granted software developers 90 days to fix identified vulnerabilities. If a patch addressing the issues was released before this deadline, the information about the vulnerability became publicly available. Researchers felt this was inappropriate, as in many cases users are rushed to install updates to avoid becoming victims of malicious actors. A developer might fix a vulnerability, but it doesn’t matter if the patch hasn’t been widely distributed.   

Therefore, now, regardless of whether a fix is released 20 or 90 days after Project Zero informs the developer of the issue, information about the vulnerability will only be made public after 90 days. There are certain exceptions in the rules. For example, if researchers and developers reach an agreement, the time to address the problem may be extended by 14 days. This is possible if developers need more time to create a patch. The seven-day deadline for fixing vulnerabilities that are already being exploited by attackers will remain unchanged.

Project Zero researchers note that since the beginning of their activities, there has been a significant improvement in addressing discovered vulnerabilities. For instance, in 2014, when the project was first established, vulnerabilities sometimes remained unaddressed for even six months after their discovery. Currently, 97.7% of the identified vulnerabilities are fixed by developers within the 90-day period.



Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster