Google Cuts Down Zero-Day Disclosure Period To 7 Days

Google has reduced the period between disclosing vulnerabilities to relevant third-party software developers and announcing them to the wider world.

For unknown and unpatched ‘zero-day’ vulnerabilities under active attack, Google will keep its discovery quiet for seven days only, instead of the usual two months.

Over the years, Google has disclosed dozens of actively exploited zero-day vulnerabilities to affected vendors, including XML parsing vulnerabilities, universal cross-site scripting bugs and targeted web application attacks.

Zero-day threat

Google said that in the past, it has uncovered zero-day vulnerabilities that were exploited to target small groups of people, such as political activists in less stable parts of the world. And in these cases, timely action could literally mean the difference between life and death.

Google’s standard period for keeping exploits under wraps is 60 days, but based on its experience, exploited critical vulnerabilities can and will be disclosed by its researchers in just seven days.

“The reason for this special designation is that each day an actively exploited vulnerability remains undisclosed to the public and unpatched, more computers will be compromised,” wrote Chris Evans and Drew Hintz, security engineers at Google.

“Seven days is an aggressive timeline and may be too short for some vendors to update their products, but it should be enough time to publish advice about possible mitigations, such as temporarily disabling a service, restricting access, or contacting the vendor for more information.”

If seven days pass, and the responsible organisations haven’t issued a patch or advisory, Google will take matters into its own hands and inform the community so users can protect themselves. The company has promised to hold itself to the same standard.

But not everyone thinks Google is doing the right thing, at least from the business perspective. “I think the stance of Chris Evans and Drew Hintz over at Google …  is rather naïve and devoid of commercial reality. As a web services company it is much easier for Google to develop and roll out fixes promptly – but for 95+ percent of the rest of the world’s software development companies making thick-client, server and device-specific software this is unrealistic,” told TechWeekEurope Gunter Ollmann, CTO of IOActive.

Are you a Google expert? Take our quiz!

Originally published on eWeek.

Max Smolaks

Max 'Beast from the East' Smolaks covers open source, public sector, startups and technology of the future at TechWeekEurope. If you find him looking lost on the streets of London, feed him coffee and sugar.

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

2 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

2 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

2 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

3 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

3 days ago