Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

51–60 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#51
post #14
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

I don't know if it should or it shouldn't, but it absolutely is not the norm for companies to announce those vulnerabilities publicly. Every year, most moderate-and-up-sized tech companies (really, a pretty big swathe of the Fortune 500 outside tech, as well) contract multiple penetration tests, and those tests turn up thousands upon thousands of sev:hi vulnerabilities, none of which are ever announced. An obligation…

It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even https://www.cms.gov/Outreach-and-Education/Medicare-Learning...

edit: less-than sign wrong way

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#52
post #14
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

I don't know if it should or it shouldn't, but it absolutely is not the norm for companies to announce those vulnerabilities publicly. Every year, most moderate-and-up-sized tech companies (really, a pretty big swathe of the Fortune 500 outside tech, as well) contract multiple penetration tests, and those tests turn up thousands upon thousands of sev:hi vulnerabilities, none of which are ever announced. An obligation…

An obligation to announce findings would create a moral hazard as well, since the incentives would suddenly tilt sharply towards not looking for security vulnerabilities.

If it became routine for companies to report these kinds of vulns, the moral hazard might dry up.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#53

Just this weekend, I setup a domain name, setup email, and setup apps and accounts to replace Google with open-source software and servers I control, generally (I use some 3rd party services that I feel I can trust, like Fastmail and Namecheap). I then turned off and deleted all of my data from Google that I could without deleting my Google account (I need to forward this long-standing email to my new email and I don…

Your security is only guaranteed by your obscurity. The moment this becomes standard practice and people start using popular software to handle personal services, this version of security will become laughable again.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#54
post #33

Earlier quoted context omitted.

Unless they are 100% certain it hasn't been exploited, yes. The reputational and legal risk to appearing to not disclose / cover up an issue is far larger than the issue itself. That changes if they are absolutely certain it was not exploited: then it's just a bug that they fixed and there's no impact beyond that.

How many vulns do you think companies find internally daily? Should every vuln be publicized?

If they potentially expose sensitive data, yes. Again, if an organization is certain that it hasn't then I'd say no. Sure, certain is a high bar but there's absolutely no way for people to make informed decisions and/or mitigate issues otherwise.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#55

Just this weekend, I setup a domain name, setup email, and setup apps and accounts to replace Google with open-source software and servers I control, generally (I use some 3rd party services that I feel I can trust, like Fastmail and Namecheap). I then turned off and deleted all of my data from Google that I could without deleting my Google account (I need to forward this long-standing email to my new email and I don…

Every time I read comments like this, I shake my head. Despite recent breaches, I still trust the big players--Google, FB, Microsoft, etc.--with my data from a security perspective far more than I'd trust myself to be able to manage security properly on my own servers or trust a smaller shop.

Security is hard. There are many, many more compromises of small firms and self-maintained servers than of these big players, it's just that they don't get major media coverage in 99% of cases.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#56
post #41
post #23

Earlier quoted context omitted.

What data was breached? If the answer is none, there is no GDPR action to be taken.

I don't know, but Google doesn't either: >Because the company kept a limited set of activity logs, it was unable to determine which users were affected and what types of data may potentially have been improperly collected, the two people briefed on the matter said. The bug existed since 2015, and it is unclear whether a larger number of users may have been affected over that time.

Then, to be clear, is your position that companies should be punished (fined) if there has ever been the possibility that user data was compromised? It's possible that a time-traveling quantum-powered encryption-breaking mind-reader from the future has seen your personal data. Should we fine everybody who knows anything about you?

Reckless endangerment deals with the possibility of something bad happening, but notice that word "reckless."

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#58
post #14

Earlier quoted context omitted.

I don't know if it should or it shouldn't, but it absolutely is not the norm for companies to announce those vulnerabilities publicly. Every year, most moderate-and-up-sized tech companies (really, a pretty big swathe of the Fortune 500 outside tech, as well) contract multiple penetration tests, and those tests turn up thousands upon thousands of sev:hi vulnerabilities, none of which are ever announced. An obligation…

It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even https://www.cms.gov/Outreach-and-Education/Medicare-Learning... edit: less-than sign wrong way

IANAL but it doesn't seem that the way they define a breach (https://www.hhs.gov/hipaa/for-professionals/breach-notificat...) includes issues that provably haven't been exploited.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#59
post #14

Earlier quoted context omitted.

I don't know if it should or it shouldn't, but it absolutely is not the norm for companies to announce those vulnerabilities publicly. Every year, most moderate-and-up-sized tech companies (really, a pretty big swathe of the Fortune 500 outside tech, as well) contract multiple penetration tests, and those tests turn up thousands upon thousands of sev:hi vulnerabilities, none of which are ever announced. An obligation…

It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even https://www.cms.gov/Outreach-and-Education/Medicare-Learning... edit: less-than sign wrong way

That's a requirement in general for CA.

https://www.oag.ca.gov/privacy/databreach/reporting

If there is a reasonable belief that data was exposed, all of the exposed CA residents need to be notified, and if > 500, the Atty General of CA needs to additionally be notified.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#60
post #14

Earlier quoted context omitted.

I don't know if it should or it shouldn't, but it absolutely is not the norm for companies to announce those vulnerabilities publicly. Every year, most moderate-and-up-sized tech companies (really, a pretty big swathe of the Fortune 500 outside tech, as well) contract multiple penetration tests, and those tests turn up thousands upon thousands of sev:hi vulnerabilities, none of which are ever announced. An obligation…

It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even https://www.cms.gov/Outreach-and-Education/Medicare-Learning... edit: less-than sign wrong way

> It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even

> https://www.cms.gov/Outreach-and-Education/Medicare-Learning...

> edit: less-than sign wrong way*

Breaches, not vulnerabilities. The discussion is not whether or not breaches should be disclosed[0], but whether newly discovered and believed-to-be-unexploited vulnerabilities should be disclosed.

[0]: They should of course, after a reasonable period in which to patch the vulnerability used.

Post reply on HN