Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

21–30 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#21

What would the EU fine for Google be now GDPR is enforced? 2.2 billion dollars?

GDPR enforcement would come into effect only if there was a breach and it was not handled.

From what is in the story and from what we know, there has been no breach.

As 'tptacek has noted, it is very unusual to announce a security bug without a resultant breach.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#22

The buried lede is that Google is shutting down Google+. (EDIT: for consumers: Google is keeping it as an enterprise product)

Technically it's shutting down all consumer functionality for Google+.

And from this day forth, Google+ will sit along with Google Reader as part of the pantheon of betrayals that HN commenters will bring up every single time Google announces a new product.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#23
post #6

GDPR proving to be great once again. The case for a US equivalent gets stronger. And more importantly, all these fuck ups will ensure that whatever bill gets drafted isn't just what the Facebook/Google lobbyists find acceptable.

What data was breached? If the answer is none, there is no GDPR action to be taken.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#24

The buried lede is that Google is shutting down Google+. (EDIT: for consumers: Google is keeping it as an enterprise product)

Technically it's shutting down all consumer functionality for Google+.

This is a fair clarification per Google's followup: https://www.blog.google/technology/safety-security/project-s...

> At the same time, we have many enterprise customers who are finding great value in using Google+ within their companies. Our review showed that Google+ is better suited as an enterprise product where co-workers can engage in internal discussions on a secure corporate social network. Enterprise customers can set common access rules, and use central controls, for their entire organization. We’ve decided to focus on our enterprise efforts and will be launching new features purpose-built for businesses.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#25
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

>PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: Changes the facts of the story 0%

Given that nobody here knows the full facts, only the subset of the interpretations published by the WSJ, this is very relevant.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#26
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

Your statement: "Logs show that it has never been used by anyone." The Wall Street Journal: "Because the company kept a limited set of activity logs, it was unable to determine which users were affected and what types of data may potentially have been improperly collected, the two people briefed on the matter said. The bug existed since 2015, and it is unclear whether a larger number of users may have been affected o…

“We don’t know of any misuse” is very different from “we know it was not misused”. Thank you for being clear about which statement is true.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#27

Earlier quoted context omitted.

Technically it's shutting down all consumer functionality for Google+.

What does "consumer" mean in that context?

Corporate/internal use of Google+ for G Suite customers will probably continue. Google uses G+ internally, so it's unsurprising they intend to hang onto the corporate side of it for now, at least.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#28
post #12
post #8

Earlier quoted context omitted.

Yes, because when you go public with the issue you are able to control the narrative. Bad judgement to assume that these issues will never reach the public eye. Especially knowing that a patched was successfully applied...instead Google looks like it is having trouble living up to it's Don't Be Evil motto.

No, they would have to issue like 10 reports a day. Bugs that are never exploited in web sites are rarely published for multiple reasons. Definitely not something to blame Google for.

If it wasn't exploited makes it even better...shows that you are being aggressive in identifying issues and applying corrections. Take advantage of opportunities to show transparency in a good light as well as meet your commitments to be transparent when events have not gone your way. This shouldn't be about how many reports you have to issue. Google can afford the staff to make that happen.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#29
post #21

What would the EU fine for Google be now GDPR is enforced? 2.2 billion dollars?

GDPR enforcement would come into effect only if there was a breach and it was not handled. From what is in the story and from what we know, there has been no breach. As 'tptacek has noted, it is very unusual to announce a security bug without a resultant breach.

What in the story indicates that there was no breach. The story says that they didn't keep a large enough set of activity logs to determine whether data was improperly accessed, not that there was no breach.

> Because the company kept a limited set of activity logs, it was unable to determine which users were affected and what types of data may potentially have been improperly collected, the two people briefed on the matter said.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#30
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

I think they should announce it. It seems pretty optimistic to have an application with buggy code that exposes user data, yet claim that there is no chance that an error or oversight prevented it from being logged. Saying "if we didn't detect the hack then it didn't happen" doesn't inspire confidence.
Post reply on HN