Google Project Zero changes the 90 day deadline

The Zero will change the deadline of 90 days in a new model that incorporates a new 30-day grace period to give users time to install updates before the technical details of a vulnerability are revealed.

Project maintains a 90-day disclosure period for vulnerabilities that have not been fixed; however, if an update occurs within this disclosure period, the technical details will be displayed 30 days after the release of the update.

For which are already online, the reveal will take place one week after , along with the technical details if not fixed.

In very rare cases the has given developers a fifteen-day grace period after disclosure, or a 3-day period for very dangerous exploits. This period will now be part of the 30 day grace period before the technical details are released.

“Moving to a '90+30' model allows us to fix update adoption time while supporting the reduction of time users are vulnerable to known attacks.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.095 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).