Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Project Zero and Wiz and have very little in common. It's wrong to bring these two up together as if they are comparable. Project Zero focuses on discovering and analysis of new (including zero-day) vulnerabilities. I do not believe Wiz uncovers new vulnerabilities. The skillset of someone working on Project Zero looks very different from someone working on Wiz.

The field of security is huge. It's unhelpful to lump unrelated things together.



> I do not believe Wiz uncovers new vulnerabilities

Oh they do. https://www.wiz.io/blog/tag/research

A few fun ones are the multiple cross-tenant security exploits they found in Azure (which is why, among the tons of other reasons, Azure is just the worst possible choice for a cloud vendor from the big 3 - their security is a joke, and none of the vulnerabilities below should have passed even a cursory security review, but they did, which means the whole org doesn't take security seriously. Add in the fact that it's slow as hell, and has the UX worthy of an Enterprise vendor, the only reason to choose it is because you're getting a good deal on the golf course for it):

https://www.wiz.io/blog/azure-active-directory-bing-misconfi...

https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-o...

https://www.wiz.io/blog/secret-agent-exposes-azure-customers...

https://www.wiz.io/blog/chaosdb-how-we-hacked-thousands-of-a...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: