This is a perfect counterexample of a really nasty privilege escalation in Google's own OS.
This is a perfect counterexample of a really nasty privilege escalation in Google's own OS.
Security research is inherently adversarial in nature, and it seems fitting to have competiting parties doing security research on one another's products.
Presumably, Android development involves some measure of security assessment?
If project zero never spent a day looking at Android, but all their competitors did, I don't see the issue.
If there aren't any/enough competitors, that seems very unlikely to be a security or security research related problem.
I basically stopped reading Peter Bright's articles on ArsTechnica because of how he spent a couple weeks writing uninformed articles about how responsible disclosure in general and P0 specifically were terrible.
Interesting. My perception is it's often based on bragging rights. Which is more about ego than about an adversary. According to that theory, what matters is how deeply you understand systems or how determined you are to go the extra mile to find issues.
This extends to organizations which want to bolster their image by being at the leading edge of research.
Anyway, having an adversary is part of the picture, but what you really care about is not the victory over that adversary but your superiority on the battlefield
https://www.schneier.com/blog/archives/2008/03/the_security_...
And this is not how I see the motivation and attitude of most security people. For them it is mostly about the satisfaction of (or other inclination toward) understanding how and where something might be vulnerable to exploit. It is a particular type of thinking related to creativity, thinking outside the box, and seeing things from a different perspective. (So basically what Schneier's essay says. Which fits with my point.)
There is nothing sophisticated or clever about a neighbor calling the homeowners' association. What they're interested in is the effect their actions will have on their adversary. But a security researcher doesn't usually care to actually exploit vulnerabilities. Or if they do, it is only to prove that the vulnerability exists, not to gain from it.
So, getting back to the original point, I just don't follow the reasoning that security researchers would prefer to avoid finding holes in their own employer's systems. If they viewed everything as us vs. them, then yes, they would want to take sides and protect their employer. Instead, I think that because what they really care about is understanding vulnerabilities, they would want to understand them wherever they see them, own employer's systems included.
But writing up an exploit that was basically handed to them is pretty weak evidence against the angry narrative.
https://bugs.chromium.org/p/project-zero/issues/list?q=Produ...
You can dispute their intentions, but I'm not all that interested in debating those. What you can't do is debate the effect, which is positive.
This is the same general point that the original comment you had replied to was making which itself was an explanation of why people are distrustful of P0 even if the brass tax is positive for the end user. It's fine if you don't find that political side of it interesting but it's not as simple as just being a donation.