

EP109 How Google Does Vulnerability Management: The Not So Secret Secrets!
11 snips Feb 20, 2023
AI Snips
Chapters
Transcript
Episode notes
Google's Vulnerability Coordination Center
- Google's Vulnerability Coordination Center (VCC) handles vulnerabilities across OS, applications, firmware, and hardware.
- The VCC coordinates fixes, informs customers, and partners with internal teams and the industry.
Vulnerability Prioritization
- Google prioritizes vulnerabilities based on severity, system applicability, and active exploitation.
- No "magic AI" exists; they use similar metrics as other companies, emphasizing practical considerations.
Google's Monorepo
- Google's large monorepo, while complex, offers control over software and dependencies through code reviews and visibility rules.
- Calculating dependencies across billions of lines of code can be time-consuming, reminiscent of XKCD's "compiling" comic.