Google is spending millions of their own dollars to freely help other companies (and themselves!) enhance their security and close holes malicious actors can exploit.
Now replace "Google" with any other company or independent researcher of your choice. If you're no longer angry, you're being biased solely because its Google and not someone you like.
Really, I don't get peoples hatred for Project Zero. Sure, hate the companies, but can you seriously argue that companies spending money on security research is a bad thing? Even if gasp they might get some good publicity from that research?
And if you rule out "all companies like Google", you've basically ruled out everyone with enough capital to donate to research, depending on your definition of "like Google".
And really, it absolutely is a donation. The ROI on Project Zero is likely 50x or more less than if that money went to the marketing team.
And I am not going try to convince you in a popularity based forum, but that is generally the objection.
You are saying that this gives more power to google and someone asked if you could elaborate on why you think that. Not everyone has the same background and what may be obvious power to you may not be to others. This forum is supposed to be participated in with good faith.
But on the other hand meta isn't that interesting either. If large companies wanted to do security research that wasn't objectionable to people they could do so by consensus, standards and agreements. No one could really question that. Instead the idea is largely that "the ends justify the means". That is what people tend to disagree with. That large companies can unilaterally decide how things are done, not just for themselves but in a way that affects other companies or their users. It doesn't really matter if it is for good or best practice because it is about them, especially as large companies in the industry, having that influence.
That being said, I think the same behavior is to be expected from any company large enough to need a dedicated security research team.
Agreed, and I don't think for a second Google as a whole is any different in this regard.
But who cares? Security issues are being found, Security issues are being publicized, Security issues are being fixed.
Project Zero, as a small part of Google, is finding bugs in everyones software - including Google's - and holding them to the same standards, standards which are widely regarded as being acceptable standards for disclosure.
The rest of Google, should they discover an issue without Project Zero's help, presumably behave just as most of other companies do - so hate them all equally, that's fine - and I agree, but Project Zero is different to Google as a whole, and just is not something to hate IMO.
How does fixing vulnerabilities in your iPhone make you feel unsafe?
> apple blamed for issues
Apple is being blamed for the issues because Apple is to blame for the issues. They made the product. Who is to blame about the security issues in an Apple product, if not Apple?
As soon as a company slighted Google, it was immediately a Project Zero target, and that should tell you everything you need to know about why people are annoyed with them.
> with a constructed story about how Epic is compromising everyone's security
Did Epic compromise everyone's (or, at least their users) security? My memory of that incident is, yes - they did. If that's true, if the code was buggy and had a path to a security exploit, how is it a "constructed story"?
It's a pretty big vulnerability when you allow the malicious intent of one app to escalate to an actual malicious capability so I don't think you're accurately recalling the issue in question.
Which is to say, there's the possibility for minor problems that should be fixed, but it's far from the "Epic is terribly insecure, trust the malware-ridden Play Store instead" rhetoric we got from this particularly aggressive media campaign.
Did p0 say that anywhere?
Given that if I search fortnite on the play store, I get a special warning message that it can't be downloaded on play (which was added specifically to prevent fortnite clones), I'm less than convinced that there was a unified campaign by Google to undermine epic, as you seem to be suggesting.
So, yes is what your saying. It was vulnerable code discovered by Project Zero.
And when discovered, did Project Zero follow their published process for disclosure to both Epic and the general public?
I don't think it's all that sudden and they've talked about it:
Plenty of uncovered and disclosed vulnerabilities for Android and Chrome there.
130.
Even Microsoft released a patch recently to a security vulnerability found in Windows XP.
But that “pretty small portion” doesn’t matter if you can’t patch it.
There is a large difference. One is an automatic app update while the user continues working. The other requires the user to stop everything they're doing and reboot their device.
With the benefit that all necessary components are updated together and that Apple can push out any updates world wide without waiting on the carriers....,
This is how devices stay vulnerable.
> With the benefit that all necessary components are updated together
The whole app is already updated atomically. There is no benefit here.
> and that Apple can push out any updates world wide without waiting on the carriers
The same as a Pixel or Android One device. The only difference is that app security updates are artificially slower on iOS due to poor design, and for apps like browsers, this is a fatal flaw.
As opposed to most Android phones that never get system updates? As opposed to Apple releasing an update two weeks ago for all iOS devices back to 2011?
The whole app is already updated atomically. There is no benefit here.
The Safari app is also used as an out of process web view for other apps as is the messenger app...
The same as a Pixel or Android One device. The only difference is that app security updates are artificially slower on iOS due to poor design, and for apps like browsers, this is a fatal flaw.
It’s estimated that Google may sell 1-2 million phones a year and Android One phones are not much more ubiquitous. Even then Google only promises updates for two years.
Don't buy them. Problem solved. Do you avoid Linux entirely because there exist Linux-based routers that are never updated? No, you buy Linux-based routers that are updated.
In this case, the choice is between properly updated Android phones, poorly updated userspace iOS phones, and poorly updated base system Android phones. The obvious choice is a phone from the first group.
> The Safari app is also used as an out of process web view for other apps as is the messenger app...
As is Chrome on Android. Since Android is designed in a way that apps can gracefully recover from arbitrary processes being killed, this does not matter. Chrome gets updated, the process restarts, and the page the user was viewing in the web view reappears. If the app wasn't in the foreground, the user won't even notice.
But yet every single Windows PC sold by any vendor can still get updates directly from Microsoft.
In this case, the choice is between properly updated Android phones, poorly updated userspace iOS phones, and poorly updated base system Android phones. The obvious choice is a phone from the first group.
You are really claiming that Android has a better update strategy than iOS and is more secure? Which Android phones from 2011 are still getting updates? 2013? 2015? Heck 2017?
It's a problem, just like the routers that aren't getting updated. It's not my problem.
> You are really claiming that Android has a better update strategy than iOS and is more secure?
Yes. I've already explained why, and you haven't refuted it.
> Which Android phones from 2011 are still getting updates?
I don't use eight year old phones, so this doesn't matter to me. If you use old phones, you could argue that iOS is marginally more secure than the Android options; but that argument is irrelevant to the purchase decisions of 99% of the people here who do upgrade devices regularly for whom there are Android options that are much more secure than iOS phones.
The average replacement time for cell phones in the US is 32 months.
https://www.npd.com/wps/portal/npd/us/news/press-releases/20...
8 months longer than Google has promised updates.
https://www.digitaltrends.com/mobile/what-is-android-one/
And that’s only with Android One phones. Most Android phones never get updates or are rolled out slowly waiting on the OEM and carrier.
That is not my replacement cycle nor the replacement cycle for most of the readers of this forum. It has no bearing on my purchase decisions nor the purchase decisions of most of the readers of this forum. For people who upgrade regularly, which is a group that includes me and most of the people on this forum, Android One and Pixel devices are more secure than iOS devices, and you appear to agree.
> 8 months longer than Google has promised updates.
Android One phones get security updates at least three years after release.
Well as long as it caters to you and the rest of the people on HN (have you done a survey?), I guess that’s all that matters - not the other 2 billion people in the world....
Android One and Pixel devices are more secure than iOS devices, and you appear to agree.
Android One phones still have to wait on the manufacturer to update their phones. Yes, but they pinky promise they will. From the article I posted.
I’ve never had to wait on a manufacturer to get updates from my Windows PCs. Heck I still get updates for my Mac Mini running Windows 7 and Apple definitely had nothing to do with it. Why is the Android architecture so piss poor that they can’t figure this out? This- an OS vendor licensing to OEMs and providing update - has been a solved problem for PCs for well over 30 years.
From the earlier article I posted.
While updates do still have to go through each phone’s manufacturer, there’s much less to check and update, so updates will generally arrive much faster. It won’t be a day one patch like you’d expect on the Google Pixel range
Each Android One phone is guaranteed to get at least three years worth of security updates from its release date, and up to two years of major Android releases, too.
Android One phones get security updates at least three years after release.
The iPhone 5s (2013) received 5 years worth of OS updates.
The 4s (2011) just received a bug fix earlier this month.
The 6s (2015) is still a more performant phone than any midrange Android phone released this year and can hold its own against high end Android phones that are two years newer. It would be a pity to replace it if it were an Android phone just because Google couldn’t figure out how to update third party devices. My son is still using it.
I already explained the choices. For us, the obvious choice is a properly updating Android device. Any user who chose an iPhone or non-updating Android phone made a poor security choice. Any user who has a longer than three year upgrade cycle has no good options unless they use a community-maintained Android build.
> Android One phones still have to wait on the manufacturer to update their phones. Yes, but they pinky promise they will.
They are guaranteed monthly security updates. If you have an example of one that hasn't had monthly security updates, that would be a breach of contract with at least the user and possibly with Google who certified the device as Android One.
Windows updates aren't guaranteed to work with arbitrary device manufacturers' custom drivers.
> [Irrelevant stuff about how long iOS devices are updated]
The comment you replied to was a correction to your claim about how long Android One devices are updated. That is the maximum period a user can get a secure device for because we have already established that all alternatives have non-working security update systems.
>The 6s (2015) is still a more performant phone than any midrange Android phone released this year and can hold its own against high end Android phones that are two years newer.
You have conceded that iOS is worse for security, so now you want to argue about performance. Android has iOS beat there, too. Here is a midrange Android phone one generation older than the iPhone 6 beating it at the most common task for phone users — opening apps: https://youtu.be/hPhkPXVxISY
Here is a midrange Android phone of the same generation as the iPhone 6s beating it in the same test: https://youtu.be/B5ZT9z9Bt4M
Of course if you want to get off topic, a more interesting discussion than performance is usability, and Android is multiple generations ahead of iOS for what you can do with it and has been since at least the Verizon Droid, which came with driving navigation and voice control.
I’m not arguing performance for performance sake. I’m arguing that a four year phone is still performant compared to many newer Android phones and it is getting both* security updates and os upgrades 24 months and 12 months longer than the tiny percentage of Android phones that get either. It also doesn’t have to wait for a third party OEM to decide to push updates.
I’m also criticizing Google for not knowing how to push updates to phones running its operating system without OEM intervention - something Microsoft figured out 30 years ago with PCs.
But you don’t need to speculate how fast iOS users update their phones.
There are plenty of sites showing how many iOS users have updated operating systems compared to Android users:
https://www.forbes.com/sites/ianmorris/2018/04/13/android-is...
So do have a cite showing that a larger percentage of Android users are running an up to date OS?
You keep coming back to this irrelevant point. Many Android phones are insecure, just as all iPhones are. Don't buy them.
> I’m also criticizing Google for not knowing how to push updates to phones running its operating system without OEM intervention - something Microsoft figured out 30 years ago with PCs.
Who cares? Don't buy them. Besides, I already pointed out in my previous post that Microsoft didn't solve this problem. Do you blame Linus for all the routers that don't get updated, or do you just not buy them?
> I’m arguing that a four year phone is still performant compared to many newer Android phones and it is getting both*
So is a five year old midrange Android phone, which is also as insecure as any iPhone. Don't buy them.
Seeing that the latest iPhones you can get that hasn’t received a recent patch is the iPhone 4 from 2010, where are “all of the insecure iPhones” - especially seeing that both Google and Apple routinely publish the percentage of devices running older OS’s, there is no conjecture needed on which one is running a greater percentage of OS’s with unpatched vulnerabilities - we have numbers straight from the source.
Who cares? Don't buy them. Besides, I already pointed out in my previous post that Microsoft didn't solve this problem.
Seeing that I have a Mac Mini from 2006 running Windows 7 that is still getting security updates and a Dell from 2009 running Windows 10, I think Microsoft solved the problem a lot better than Google. The other 2.7 billion Android users probably would care if they knew any better.
you blame Linus for all the routers that don't get updated, or do you just not buy them?
Linux is free open source software that anyone can use, no one pays Linus for using it, and Linus doesn’t have much of any criteria about how it’s used. None of that is true about Android. What makes Android Android is Google Play Services that is licensed by a commercial entity.
So is a five year old midrange Android phone, which is also as insecure as any iPhone. Don't buy them
There is no five year old iPhone that isn’t supported and receiving security patches. Right now, there isn’t any 8 year iPhone that hasn’t received a security patch recently.
We already discussed this. iOS has a huge attack surface that can only be patched via system updates, which is horribly bad design and terrible for security.
> The other 2.7 billion Android users probably would care if they knew any better.
If those billions knew better, they would get an Android One or Pixel instead of an instead of an iOS or other Android device. We already established that there is only one set of devices that is good for security, and the vast majority of people, including you it seems, do not have them. It's not my problem to fix their security. I don't buy them myself.
> I have a Mac Mini from 2006 running Windows 7 that is still getting security updates and a Dell
In exactly the same way, updates work fine for those of us on properly updated Android devices, and Windows updates don't work for people with hardware that has poorly supported drivers. You didn't address my point. Also, you still haven't addressed why this matters.
> Linux is free open source software that anyone can use, no one pays Linus for using it, and Linus doesn’t have much of any criteria about how it’s used.
So exactly the same as Android.
> There is no five year old iPhone that isn’t supported and receiving security patches.
And all of them have poorly updated userspace. There is no five year old Android phone that has poorly updated userspace. All of those are insecure except for the subset of Android devices that have properly updated base system.
And your theory isn’t supported by facts on the ground - we have statistics about the percentage of iOS devices running the latest version of iOS versus the number of Android devices.
Since iOS annoying asks you to upgrade when there is one available and you are given a choice to automatically update when you’re not using, do you have a reliable citation showing the number of iOS devices without the latest version compared to the number of Android devices? Or do you just have a hunch?
> you're being biased solely because its Google and not someone you like.
We should be biased against Google, in everything.
>On the surface it appears
This implies an ulterior motive.
>expose flaws
As mentioned, "expose" is an emotionally charged word with negative connotation.
>in competitor's products.
P0 does not just focus on competitors products, by any stretch.
Your statement also fails to convey that they notified Apple with industry accepted disclosure practices in order to fix the vulnerabilities, rather than just "expose flaws".
I'm not a fan of Google at all and don't use their products unless I absolutely have to, but everything I've seen so far about P0 has been stellar technically and ethically.
There is no reason to assume project zero is biased if one considers second order effects of this security research.
What kind of press releases get picked up by the media 9 out of 10 times? Not the ones about google finding flaws in google products. Google just makes clever use of the medias' bias for conflict.
Hopefully Apple does the same thing and obliges Google to operate with a whole lot more security. (Not that anyone should use Google in any case because of the industry leading flagrance of their privacy issues. But I digress.)