All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Google Project Zero Addresses the 'Patch Gap' in Vulnerability Disclosure

By

esnard

10mo ago· 4 min readenInsight

Summary

The article discusses Google Project Zero's updated vulnerability disclosure policy, the '90+30' model, introduced in 2021 to accelerate patch development and adoption. It highlights the persistent challenge of the 'patch gap,' the delay between a security fix release and its installation on end-user devices. The piece emphasizes the complexity of this issue and its implications for cybersecurity.

Key quotes

· 3 pulled
Our goals were to drive faster yet thorough patch development, and improve patch adoption.
The time it takes for a fix to actually reach an end-user's device is a significant challenge.
Many consider the patch gap to be the time between a fix being released for a security vulnerability and the user installing the relevant update.
Snippet from the RSS feed
Posted by Tim Willis, Google Project Zero In 2021, we updated our vulnerability disclosure policy to the current "90+30" model. Our goals we...

You might also wanna read