pwshub.com

Google highlights seven key security goals in new ‘Secure by Design’ white paper

A new white paper released today by Google LLC highlights its ongoing efforts to incorporate security across its products through a “Secure by Design” approach.

The paper “An Overview of Google’s Commitment to Secure by Design” covers how Google has continued to deliver on seven goals as part of the Security by Design pledge. The pledge, one made by Google and other companies, is a voluntary commitment to specific security goals as spearheaded by the U.S. Cybersecurity and Infrastructure Security Agency.

The first goal, the implementation of multifactor authentication, focuses on enhancing user security by requiring multiple verification steps during sign-in.

Google has long been a leader in this area, having launched Google Authenticator and 2-Step Verification for Google Workspace back in 2010. Since then, the company has expanded its MFA offerings through initiatives such as the Advanced Protection Program and collaborations with the FIDO Alliance. All that has culminated in the introduction of passkeys, a passwordless authentication method that has been used more than a billion times, providing a simpler yet more secure alternative to traditional passwords.

The second goal, tackling default passwords, addresses the security risks they pose by treating them as vulnerabilities. Google has implemented measures across its products to eliminate their use, such as requiring users to log in with their Google Accounts instead. The approach has also been applied to devices such as Nest and Pixel, as well as services such as Workspace and Google Cloud, to ensure stronger security without relying on preconfigured passwords.

Reducing entire classes of vulnerability, the third goal, has seen Google adopt a safe coding framework and secure development environment to address issues at scale. By evolving its methods, Google has mitigated threats such as cross-site scripting, SQL injection, memory safety problems and insecure cryptography to ensure more robust software security across its products.

For security patches, the fourth goal, Google has focused on making software updates seamless and easy for users to apply. Through the prioritization of quick deployment fixes, Google reduces the risk of exploitation with ChromeOS serving as an example through its automatic updates and multiple layers of protection that help keep it ransomware and virus-free.

The fifth goal, vulnerability disclosure, emphasizes collaboration within the industry to identify and report security issues. Google has long been a champion for transparency and proactively seeks external reports through its Vulnerability Rewards Program, which has distributed nearly $59 million in rewards across 18,500 instances, contributing to the security of its products.

The next goal, addressing common vulnerabilities and exposures, focuses on ensuring that critical fixes are applied. Google prioritizes issuing CVEs for products that require updates and provides detailed security bulletins for Android, Chrome, ChromeOS and Google Cloud while also offering users guidance on addressing vulnerabilities and mitigating risks.

The last goal, providing evidence of intrusions, ensures users are informed about security incidents without unnecessary noise. Google achieves this through personalized security alerts for Google Accounts and tools such as Security Checkup. In Google Cloud, audit logs provide visibility into activities and Workspace administrators can review user actions using audit tools, helping enterprises detect potential intrusions efficiently.

The white paper today is planned by Google to be the first of a series of insights it will publish in the coming months.

Source: siliconangle.com

Related stories
3 weeks ago - We believe the artificial intelligence center of gravity for enterprise value creation is shifting from large language models to small language models, where the S not only stands for small but encompasses a system of small, specialized,...
1 month ago - Oracle Corp. is seeing renewed business momentum powered by a combination of an entrenched database business, years of investment in cloud infrastructure, an integrated application suite and artificial intelligence technologies that are...
1 month ago - Input from theCUBE and data practitioner communities suggests that acceleration in compute performance and the sophistication of the modern data stack is outpacing the needs of many traditional analytic workloads. Most analytics workloads...
1 month ago - As digital transformation redefines the business landscape, cybersecurity is becoming increasingly complex and urgent. So it was timely that the mWISE 2024 conference, hosted by Google LLC’s Mandiant, brought together industry leaders...
1 month ago - Technology generally and big tech specifically are regularly cited by politicians, media and governments around the world as the root of many societal problems today. Accusations such as privacy invaders, fake news amplifiers, job...
Other stories
2 minutes ago - The Greenlight Capital founder said the PC market could se a stronger upgrade cycle as a result of AI in the future.
2 minutes ago - (Bloomberg) -- Defaults in an opaque corner of China’s local debt market have surged to a record high, ensnaring investors who’d assumed the securities had an implicit guarantee from the state.Most Read from BloombergRobotaxis Are No...
1 hour ago - Prominent economist Peter Schiff cautioned investors against holding cash as a long-term strategy, warning of significant purchasing power erosion amid growing inflation concerns. What Happened: The outspoken financial commentator and...
1 hour ago - A suit filed in federal court marks the third time in recent months that Charles Schwab and its affiliates have been accused of failing to prevent elderly clients from being swindled out of their life savings.
2 hours ago - The Microsoft Corp.-owned professional networking platform LinkedIn has been ordered to pay €310 million ($334 million) by the European Union’s privacy regulator over targeted advertising practices, one the biggest fines to hit American...