Saturday, March 31, 2007

Google Security and Product Safety

Google's Security Philosophy
As a provider of software, services and monetization for users, advertisers and publishers on the Internet, we feel a responsibility to protect your privacy and security. We recognize that secure products are instrumental in maintaining the trust you place in us and strive to create innovative products that both serve your needs and operate in your best interest.

We've learned that when security is done right, it's done best as a community, and this includes everybody: the people who use Google services (thank you all!), the software developers who make our applications, and the external security enthusiasts who keep us on our toes. These combined efforts go a long way in making the Internet more safe and secure.

Reporting Security Issues
If you are a Google user and have a security issue to report regarding your personal Google account, please visit our contact page. This includes password problems, login issues, spam reports, suspected fraud and account abuse issues.

If you have discovered a vulnerability in a Google product or have a security incident to report, please email security@google.com. Please include a detailed summary of the issue including the name of the product (e.g., Gmail) and the nature of the issue you believe you've discovered. Be sure to include an email address where we can reach you in case we need more information.

This process of notifying a vendor before publicly releasing information is an industry-standard best practice known as responsible disclosure. Responsible disclosure is important to the ecology of the Internet. It allows companies like Google to keep users safe by fixing vulnerabilities and resolving security concerns before they are brought to the attention of the bad guys. We strongly encourage anyone who is interested in researching and reporting security issues to observe the simple courtesies and protocols of responsible disclosure.

Working together helps make the online experience safer for everyone.

Google takes security issues very seriously and will respond swiftly to fix verifiable security issues. Some of our products are complex and take time to update. When properly notified of legitimate issues, we'll do our best to acknowledge your emailed report, assign resources to investigate the issue, and fix potential problems as quickly as possible.

Google Thanks You
People and organizations with an interest in security issues have made a tremendous contribution to the quality of the online experience. We are grateful for the responsible disclosure of security vulnerabilities in our software. On behalf of our millions of users, would like to thank the following individuals and organizations for going out of their way to improve the Google experience for everyone:
  • Alex Shipp, Messagelabs
  • Bryan Jeffries
  • Castlecops
  • H D Moore
  • Jeremiah Grossman
  • Johannes Fahrenkrug
  • Martin Straka
  • Team Cymru
  • Yahoo! Paranoids
  • Wayne Porter & Chris Boyd, FaceTime Communications
  • Alex Eckelberry, Sunbelt Software
  • Richard Forand
  • Fraser Howard, Sophos

No comments: