[0] Their secondary goals are to protect Google products and services, and to provide excellent PR in line with what we're discussing right here.
[0] Their secondary goals are to protect Google products and services, and to provide excellent PR in line with what we're discussing right here.
edit: I'm sure everyone involved acted responsibly. I'm just curious as how far apart these independent discoveries were made.
The bug has been around forever, but it must have been discovered relatively recently since it's not fixed in hardware yet.
I've always been baffled by the concept of simultaneous discovery.
> We would like to thank Intel for their professional handling of this issue through communicating a clear timeline and connecting all involved researchers.
1) Have any of them ended up in Project Zero or working on stuff like this
2) Wonder if NSA knew about this vulnerability and now someone there in a windowless office is sighing saying to themselves "Welp, another backdoor we can't use".
Which is, at the same time, highly rational: to secure their entire market.
It's nice to have big corp's incentives aligned with the public good. Too bad it happens so rarely.
Sure, Google could just patch themselves, but the information to recreate the issue would surely be leaked by a xoogler, since it only takes a single sentence describing the vuln for a competent sec team to recreate it
Suppose your company also has a team that inspects public bridges to make sure they don't collapse.
Is it really altruistic, or given your market share is it a cost of business?