We just published an update to the Chrome VRP. Blog post is at https://t.co/SF4sW5ncxZ. The gist: we are restructuring based on the AI advancements to allow for more automated triage and easier to predict payment amounts.
We are looking for an Android security expert to join our team and work on securing Chrome on Andoird. Job posting is available at https://t.co/QFXfQnQpTD, but also feel free to reach out to me directly.
@jduck@amyexp Have you tried maybe doing the same with "Rust" as the search term? Grepping for just one specific term might not reveal the full picture.
@jduck@argvee@ivansprundel We would all love to have protections! We can't always have them. Mitigations which increase attacker cost or significantly decrease probability of successful exploitation are worthwhile deploying when you don't have luxury of rewriting all the code in reasonable time.
@jduck@argvee@ivansprundel If a JS engine security bug is in the JIT code it produces, what difference does it make what language the engine is written in?
Entire process written in memory safe language is an awesome goal, but with millions lines of code, it does not happen overnight.
@jduck@amyexp Just because press rooms have more time and incentive to write about the bugs than engineers have time to write about their work, does not mean it is not happening. Have you seen our quarterly updates? https://t.co/SgDU1J5oYq
@jduck@amyexp Are you suggesting that our VRP is the only security strategy we have in our arsenal? I wonder what gives the impression that we aren't serious about security. Happy to chat more if you are up for a constructive conversation.
📢 Chrome VRP reward updates! 💰 Bigger payouts (up to 5x higher, $250,000+) and clearer guidelines, all designed to incentivize high-quality Chrome security research. Let's work together to make Chrome even safer! 🔐
https://t.co/40Jz6ZFAMf
This morning, I read about Satya Nadella’s latest memo, which emphasizes Microsoft’s new priority: security above all. The memo introduces a policy linking senior leadership compensation to the achievement of "security plans and milestones." I see this as a commendable step forward for Microsoft but more will be needed if they are to get back to being a security leader. Some thoughts here: https://t.co/JjgfJGlI5B
I published a step by step guide on using Windows event logs to hunt for malware trying to steal sensitive data from browsers e.g. cookies, passwords etc. https://t.co/9a3l56dDJo #DFIR Hope it's useful!