Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

41–50 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#41
post #23
post #6

GDPR proving to be great once again. The case for a US equivalent gets stronger. And more importantly, all these fuck ups will ensure that whatever bill gets drafted isn't just what the Facebook/Google lobbyists find acceptable.

What data was breached? If the answer is none, there is no GDPR action to be taken.

I don't know, but Google doesn't either:

>Because the company kept a limited set of activity logs, it was unable to determine which users were affected and what types of data may potentially have been improperly collected, the two people briefed on the matter said. The bug existed since 2015, and it is unclear whether a larger number of users may have been affected over that time.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#42

Earlier quoted context omitted.

Technically it's shutting down all consumer functionality for Google+.

This is a fair clarification per Google's followup: https://www.blog.google/technology/safety-security/project-s... > At the same time, we have many enterprise customers who are finding great value in using Google+ within their companies. Our review showed that Google+ is better suited as an enterprise product where co-workers can engage in internal discussions on a secure corporate social network. Enterprise custome…

What's the point, then? Google will (or should) spend just about as much effort keeping it live for enterprise users as it would for the rest of us.

I don't use it often, but occasionally find useful communities there, especially concerning technical subjects. Now all of that is going to disappear.

It's annoying that Google apparently prizes the opinion of enterprise customers enough to half-abort the plan to shut down Google+, while for some reason maintaining a stubborn insistence on removing its access for the rest of us. Yes, this will be another point to add on the list of reasons to never become invested in a new Google product.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#45
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

"We made Google+ with privacy in mind and therefore keep this API's log data for only two weeks"

Does anyone read the article anymore? Or do they just read it for what they want to see and ignore the rest?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#46
post #33
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

Unless they are 100% certain it hasn't been exploited, yes. The reputational and legal risk to appearing to not disclose / cover up an issue is far larger than the issue itself. That changes if they are absolutely certain it was not exploited: then it's just a bug that they fixed and there's no impact beyond that.

How many vulns do you think companies find internally daily? Should every vuln be publicized?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#47
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

That didn't stop them so far from making everybody else look bad. The latest in Google's unfair competitive practices:

"Google discloses Microsoft Edge security flaw before a patch is ready" https://www.theverge.com/2018/2/19/17027138/google-microsoft...

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#48
post #41
post #23

Earlier quoted context omitted.

What data was breached? If the answer is none, there is no GDPR action to be taken.

I don't know, but Google doesn't either: >Because the company kept a limited set of activity logs, it was unable to determine which users were affected and what types of data may potentially have been improperly collected, the two people briefed on the matter said. The bug existed since 2015, and it is unclear whether a larger number of users may have been affected over that time.

Looks like "we don't know if data was leaked" is now a standard language that accompanies every security bug disclosure to avoid GDPR fines.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#49

Just this weekend, I setup a domain name, setup email, and setup apps and accounts to replace Google with open-source software and servers I control, generally (I use some 3rd party services that I feel I can trust, like Fastmail and Namecheap). I then turned off and deleted all of my data from Google that I could without deleting my Google account (I need to forward this long-standing email to my new email and I don…

I've been working my way down this path. Fastmail for email and CalDAV/CardDAV, DavDroid to sync, K9 as my email client, OsmAnd for maps, Firefox instead of Chrome. I try and remember to use SkyTube not YouTube but it isn't flawless. I use KISS as my launcher on Android.

I still haven't eliminated Google Photos, I do appreciate the free sync on my Pixel 2 XL for peace of mind, Google Translate is still super useful for offline translate and the camera translate feature and I haven't yet been able to replace Google Maps for transit instructions. I still use a Chromecast which I guess is next to go, maybe I'll actually setup a HTPC of sorts, or perhaps just use Kodi on my Xbox One S as that seems to work well enough.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#50
A few years ago, I had an Google account. My account got disabled because I’ve tried to buy an app from Android Store. Besides the fact that I never managed to get my account back something funny happened a few years after.

I had teo Blogger blogs connected to the account and my Twitter was connected to my Blogger as well. I’ve lost those blogs too, and I couldn’t get them back. At some point, I’ve realized some suspicious tweets in my timeline and realized that they are from my blogs! So, Google freed my blogs but didn’t removed its connected accounts. Whoever got the account probably didn’t have any idea that these addresses are connected to a Twitter account as well! But the share to Twitter was on, and whatever she/he was positing were ending up in my twitter account!

Point being, Google is leaking from strange places! Add Google+ to your Blogger and you’ll risk much more I guess!

Post reply on HN