Google Project Zero Changes Its Disclosure Policy
Google的Project Zero团队将继续执行90+30天的漏洞披露政策,并从7月29日起,在向厂商披露后一周内发布有限信息。此举旨在加快修复速度但可能引发恐慌。作者认为Google并非中立的漏洞猎手。 2025-8-8 11:1:14 Author: www.schneier.com(查看原文) 阅读量:29 收藏

Google’s vulnerability finding team is again pushing the envelope of responsible disclosure:

Google’s Project Zero team will retain its existing 90+30 policy regarding vulnerability disclosures, in which it provides vendors with 90 days before full disclosure takes place, with a 30-day period allowed for patch adoption if the bug is fixed before the deadline.

However, as of July 29, Project Zero will also release limited details about any discovery they make within one week of vendor disclosure. This information will encompass:

  • The vendor or open-source project that received the report
  • The affected product
  • The date the report was filed and when the 90-day disclosure deadline expires

I have mixed feelings about this. On the one hand, I like that it puts more pressure on vendors to patch quickly. On the other hand, if no indication is provided regarding how severe a vulnerability is, it could easily cause unnecessary panic.

The problem is that Google is not a neutral vulnerability hunting party. To the extent that it finds, publishes, and reduces confidence in competitors’ products, Google benefits as a company.

Tags: , , ,

Posted on August 8, 2025 at 7:01 AM0 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2025/08/google-project-zero-changes-its-disclosure-policy.html
如有侵权请联系:admin#unsafe.sh