Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

61–70 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#61
post #22

Earlier quoted context omitted.

Technically it's shutting down all consumer functionality for Google+.

And from this day forth, Google+ will sit along with Google Reader as part of the pantheon of betrayals that HN commenters will bring up every single time Google announces a new product.

I doubt anybody cares about Google+, honestly. In fact I'm happy to see it die, after all the pain it's caused me (YouTube integration)

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#63
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

That didn't stop them so far from making everybody else look bad. The latest in Google's unfair competitive practices: "Google discloses Microsoft Edge security flaw before a patch is ready" https://www.theverge.com/2018/2/19/17027138/google-microsoft...

Having a security disclosure policy and following it to the letter for everyone (including Google) is suddenly an "unfair competitive process".

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#65
post #56
post #41

Earlier quoted context omitted.

I don't know, but Google doesn't either: >Because the company kept a limited set of activity logs, it was unable to determine which users were affected and what types of data may potentially have been improperly collected, the two people briefed on the matter said. The bug existed since 2015, and it is unclear whether a larger number of users may have been affected over that time.

Then, to be clear, is your position that companies should be punished (fined) if there has ever been the possibility that user data was compromised? It's possible that a time-traveling quantum-powered encryption-breaking mind-reader from the future has seen your personal data. Should we fine everybody who knows anything about you? Reckless endangerment deals with the possibility of something bad happening, but notice…

I didn't say GDPR would apply in this situation, and the WSJ story suggests it wouldn't because of when it was discovered. All I said was that GDPR was great (obviously we'd only see the benefits from it after it had gone into effect), and this latest scoop bodes well for the political movement to enact equivalent legislation in the US.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#66
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

> Logs show that it has never been used by anyone

Yes, because the #1 thing on the mind of someone who gained unauthorized access (e.g. a remote execution vulnerability) to a system is to cover their tracks, which includes things like doctoring logs.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#67
post #42

Earlier quoted context omitted.

This is a fair clarification per Google's followup: https://www.blog.google/technology/safety-security/project-s... > At the same time, we have many enterprise customers who are finding great value in using Google+ within their companies. Our review showed that Google+ is better suited as an enterprise product where co-workers can engage in internal discussions on a secure corporate social network. Enterprise custome…

What's the point, then? Google will (or should) spend just about as much effort keeping it live for enterprise users as it would for the rest of us. I don't use it often, but occasionally find useful communities there, especially concerning technical subjects. Now all of that is going to disappear. It's annoying that Google apparently prizes the opinion of enterprise customers enough to half-abort the plan to shut do…

> 90 percent of Google+ user sessions are less than five seconds.

If most people are visiting by accident and immediately leaving, it's probably actively causing usability problems and should be shut down.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#68
post #59

Earlier quoted context omitted.

It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even https://www.cms.gov/Outreach-and-Education/Medicare-Learning... edit: less-than sign wrong way

That's a requirement in general for CA. https://www.oag.ca.gov/privacy/databreach/reporting If there is a reasonable belief that data was exposed, all of the exposed CA residents need to be notified, and if > 500, the Atty General of CA needs to additionally be notified.

Is there a required timeframe for doing so?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#69
post #38

Earlier quoted context omitted.

This is a fair clarification per Google's followup: https://www.blog.google/technology/safety-security/project-s... > At the same time, we have many enterprise customers who are finding great value in using Google+ within their companies. Our review showed that Google+ is better suited as an enterprise product where co-workers can engage in internal discussions on a secure corporate social network. Enterprise custome…

So, pivot to Slack-alike. I'm sure it'll last.

They could have cornered that market with Google Wave, but killed the project before it took off.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#70
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

> Logs show that it has never been used by anyone Yes, because the #1 thing on the mind of someone who gained unauthorized access (e.g. a remote execution vulnerability) to a system is to cover their tracks, which includes things like doctoring logs.

a vulnerability that allows some unauthorized access to user data via the API and a vulnerability that allows edting logs are very different types of vulnerabilities.
Post reply on HN