Incomplete disclosures by Apple and Google regarding a vulnerability, the reasons behind hard drives not being physically bigger, and setting up a distributed backup system with friends.
Incomplete disclosures by Apple and Google create blind spots for 0-day hunters and delay the patching process for vulnerabilities.
Apple and Google's approach to responsible disclosure contradicts expectations and hampers vulnerability management efforts.
Deep dives
Open Source.net is Back
After the demise of open source.com, open source.net has emerged as a community-focused news and documentation site for open source enthusiasts. The platform offers opportunities for aspiring writers to contribute articles and build their portfolios. It serves as a hub for sharing experiences, challenges, and insights related to open source projects.
Incomplete Disclosures of Vulnerability in LibWebP
Both Apple and Google handled a vulnerability in libwebp poorly, resulting in incomplete disclosures. Rather than identifying the vulnerability in the widely used library, Apple labeled it as an image IO bug, while Google attributed it to Chrome. The failure to communicate that libwebp was the actual source of the vulnerability delayed the patching process, leaving many applications at risk.
Lack of Responsible Disclosure
Apple and Google's approach to responsible disclosure was called into question. Instead of coordinating with other developers and disclosing the vulnerability on private mailing lists, both companies focused on patching their own applications without considering the wider impact. This approach contradicts expectations for responsible disclosure and hampers efforts to address vulnerabilities effectively.
Implications for Vulnerability Scanners
The limited scope of the CVE registration by Google hinders vulnerability scanners from accurately identifying the vulnerability's presence in various products. The scanners primarily check for patches in specific applications like Chrome and image IO, disregarding the fact that vulnerabilities may exist in other software relying on libwebp. This creates blind spots for organizations relying solely on vulnerability scanning for protection.
Google and Apple do a bad job of disclosing a pretty serious vulnerability, why hard drives aren’t physically bigger, and setting up a distributed backup system with a group of friends.
We were asked about setting up a distributed backup system with a group of friends.
Kolide
Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today to see how it works at kolide.com/25a