NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Budget 2025
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Google riles Silicon Valley, threatens to expose others' security flaws

Bloomberg
12 Feb, 2015 07:30 PM8 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Google is annoying Silicon Valley rivals by exposing IT security flaws. Photo / AP

Google is annoying Silicon Valley rivals by exposing IT security flaws. Photo / AP

Google has given fellow tech companies an ultimatum: patch your software vulnerabilities within 90 days or we'll make them public.

An elite team of Google hackers and programmers scrub their own and competitors' software for security flaws, giving companies a deadline to issue a fix. Google says it wants software makers to move fast because cybercriminals act with lightning speed when they spot bugs.

It's a sensitive topic - rivals Microsoft and Apple declined to talk about the tactic - though others in the industry say the help isn't always welcome, usurps a role best left to government and can jeopardise security.

"I'm not sure who made Google the official referee of the marketplace for vulnerability notification," said John Dickson, a principal with software security company Denim Group in San Antonio. He said pressuring companies to fix flaws is a good idea, but "what noble motives they had in mind could be called into question given the fact that they essentially outed vulnerabilities for two of their biggest rivals."

Read also:
• 2014: Technological let-downs: From Sony hack to 'Heartbleed', security flaws are always with us
• Google plays catch-up on cybercrime with Project Zero

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Google established the team in July, calling it Project Zero after the much-feared "zero day" security flaws that are exploited before developers learn of them. It says it is trying to help everyone as well as protect its own products that run on others' devices and software.

That's an activity some security experts say is more appropriate for a government agency. The respective roles of the private and public sectors is on the agenda at a cybersecurity summit Friday in Palo Alto, California, where President Barack Obama will call on technology leaders to improve cooperation and share more information.

Some researchers are wondering aloud, however, how much cooperation can be expected if the biggest internet companies can't play nice together.

Advertisement
Advertise with NZME.

If these companies can't even get along, that's just bad for security for the whole ecosystem Jake Kouns, chief information security officer for Risk Based Security

Jake Kouns, chief information security officer, Risk Based Security

"We support a variety of efforts, including Project Zero and our Security Reward Programs, to find and fix online threats," Aaron Stein, spokesman for the Mountain View, California-based Google said in an email.

Apple declined to comment while Microsoft would only refer to a previous statement in which it said Google's tactics felt like a game of "gotcha," illustrating how divisive the issue is.

"If these companies can't even get along, that's just bad for security for the whole ecosystem," said Jake Kouns, chief information security officer for Risk Based Security Inc. in Richmond, Virginia.

Opponents of Google's practice say it puts online security at risk by revealing gaps before they can be plugged.

Discover more

World

Ruling means rethink on net use

01 Jun 05:00 PM
Energy

Why tech giants are buying up wind energy

09 Nov 07:00 PM
Business

Google's moonshot that missed

20 Nov 08:14 PM
Telecommunications

Google gets serious in taking on the telcos

09 Feb 01:00 AM

Hackers work fast to exploit problems when they become known. Chinese-backed intruders exploited a Web-security flaw known as Heartbleed last year to attack Community Health Systems Inc. more than a week after the hole was publicised.

In January, Apple pleaded with Google to wait about a week before going public so it could fix three flaws in the Mac OS X operating system, according to a person familiar with the request who wasn't authorised to speak publicly.

Google knew the fix was coming and had possession of the updated software because it serves as a developer for Apple, the person said. Regardless, Google refused and released details of the flaws.

The decision feels less like principles and more like a 'gotcha,' with customers the ones who may suffer as a result

Chris Betz, senior director of Microsoft's Security Response Center

Microsoft, meanwhile, requested two additional days to fix a flaw in Windows. Google refused and publicised the bug.

"The decision feels less like principles and more like a 'gotcha,' with customers the ones who may suffer as a result," wrote Chris Betz, senior director of Microsoft's Security Response Center, in a January 11 blog post, which has remained the company's only public comment on the issue to date. "What's right for Google is not always right for customers."

App users: Tap here to view the 'Fighting Cybercrime: A New Era of Collaboration' video

Advertisement
Advertise with NZME.

Microsoft asks that researchers privately disclose flaws to software providers, working with them until a fix is made available, Betz said. "Policies and approaches that limit or ignore that partnership do not benefit the researchers, the software vendors, or our customers. It is a zero sum game where all parties end up injured," he wrote.

Google supporters say the hard-line approach may fundamentally alter software industry practices in which companies can take months or years to patch bugs.

According to an analysis by Risk Based Security, Project Zero has identified 39 vulnerabilities in Apple products and 20 in Microsoft products. The team also has found 37 flaws in Adobe Systems software and 22 in the FreeType software development library for rendering fonts.

Project Zero publicly released details before a fix became available about Apple flaws 16 times, Microsoft three times and Adobe once, Kouns said in a phone interview.

Google's "strict policy is good for the industry," and the company should be praised because they "stuck to their guns," said Tom Gorup, a manager with Rook Security based in Indianapolis.

"A regular Joe on the street doesn't have the clout that Google does," Gorup said in a phone interview. "If we have huge companies like Microsoft, Apple and Google going at each other and pushing for better security, it's a win across the board."

Advertisement
Advertise with NZME.

Google created Project Zero after revelations about the Heartbleed bug and spying by the National Security Agency and other governments.

"You should be able to use the Web without fear that a criminal or state-sponsored actor is exploiting software bugs to infect your computer, steal secrets or monitor your communications," according to a July 15 blog post announcing Project Zero. "Our objective is to significantly reduce the number of people harmed by targeted attacks."

Read also:
• How the Heartbleed bug reveals a flaw in online security
• Internet Explorer 'security hole' leaves a quarter of web browsers vulnerable

Google also is helping to spur the market for managing and patching software vulnerabilities, which is expected to grow to $1 billion in value by 2018 from about $600 million in 2014, said Christopher Kissel, a network security industry analyst with research company Frost & Sullivan Inc.

We've had a lot of experiences where vendors will seemingly not care about something unless it's in the headlines or unless there's something out there that people see as an immediate threat

Craig Young, senior security researcher with Tripwire

Companies that provide vulnerability management services like Hewlett-Packard, Tenable Network Security Inc. and Qualys Inc. stand to gain from the increased spending, Kissel said in a phone interview.

The number of internet flaws being found surged to 7,903 in 2014 from 5,174 in 2013, he said. It took companies 205 days on average in 2014 to learn that hackers had infiltrated their networks, according to cybersecurity company FireEye Inc.

Advertisement
Advertise with NZME.

"While a few adversaries use zero-day exploits to target victims, many adversaries still target known vulnerabilities for which patches have been released, capitalising on slow patch processes and risk decisions by network owners not to patch certain vulnerabilities or systems," the FBI said in an alert at the end of January obtained by Bloomberg News.

A 90-day deadline might not be practical for large companies that have to search through thousands lines of code and make sure patches don't negatively affect other software, said Craig Young, a senior security researcher with Tripwire Inc. based in Portland, Oregon, in a phone interview.

Other times, however, a company may be negligent. "We've had a lot of experiences where vendors will seemingly not care about something unless it's in the headlines or unless there's something out there that people see as an immediate threat," Young said.

Young reported a bug to Apple in October 2012 that could let hackers attack a file server in OS X. Although the flaw wasn't critical, Apple didn't issue a final patch until Jan. 27 of this year, Young said.

The flaws exposed by Project Zero without fixes so far haven't been very serious, Young said. He said he would have more concerns if Google published details about a critical vulnerability that put users at a high risk.

"Microsoft is using this opportunity to kick some sand up in Google's face and attack their mantra of 'Do no evil'," said Gorup with Rook Security. "If it was a government entity, Microsoft wouldn't be able to make the case."

Advertisement
Advertise with NZME.
Save

    Share this article

Latest from Business

Business

Syos wins company of the year crown, Beck named Flying Kiwi

23 May 11:00 AM
Premium
Media Insider

Breakfast battle: Hosking v Barnett ratings and Bridge is back; RNZ cuts: What's in line?

23 May 08:10 AM
Premium
Shares

Market close: NZ sharemarket falls as interest rates take centre stage

23 May 06:11 AM

Deposit scheme reduces risk, boosts trust – General Finance

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Syos wins company of the year crown, Beck named Flying Kiwi

Syos wins company of the year crown, Beck named Flying Kiwi

23 May 11:00 AM

Deep Dive Division was also among the big winners at the annual Hi-Tech Awards.

Premium
Breakfast battle: Hosking v Barnett ratings and Bridge is back; RNZ cuts: What's in line?

Breakfast battle: Hosking v Barnett ratings and Bridge is back; RNZ cuts: What's in line?

23 May 08:10 AM
Premium
Market close: NZ sharemarket falls as interest rates take centre stage

Market close: NZ sharemarket falls as interest rates take centre stage

23 May 06:11 AM
Agritech leaders say Budget offers tax relief but lacks bold vision

Agritech leaders say Budget offers tax relief but lacks bold vision

23 May 04:01 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP