Hacker News new | past | comments | ask | show | jobs | submit login

> If you find a bug in their product you are expected to follow their policy.

Is their policy more than 90 days? Yes? Fuck 'em; post everything everywhere.




It's not; from parent's own links: "We of course expect to be held to the same standards ourselves."


* impolitecough *

Great, then they should start pushing OS security patches out to devices instead of handing them to manufacturers and carriers and washing their hands of them.


They have started that. That's why more and more of Android has been moved to Google Play Services.

Coincidentally, that's one of the reasons why being denied use of Android is such an obstacle for Huawei, even though it's "open source".


You forgot to include "with pre-built exploit tooling built around what he explicitly said he spent a lot of time on."

Project Zero has done some great things and improved a lot of security, but this feels like a spiteful slap at a competitor. It's not Google is really vulnerable to the same kind of thing, they've long since shown that the security of older versions of their only real public OS is not their concern.


> You forgot to include "with pre-built exploit tooling built around what he explicitly said he spent a lot of time on."

No I didn't; I said everything and I meant everything. If anything, 90 days is overly generous to Google. If they can't get their shit together in three bloody months, fuck them. Of course, this is Google, so fuck them regardless, but this way you have obvious moral high ground.




Applications are open for YC Winter 2020

Guidelines | FAQ | Support | API | Security | Lists | Bookmarklet | Legal | Apply to YC | Contact

Search: