Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

71–80 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#72

Earlier quoted context omitted.

That didn't stop them so far from making everybody else look bad. The latest in Google's unfair competitive practices: "Google discloses Microsoft Edge security flaw before a patch is ready" https://www.theverge.com/2018/2/19/17027138/google-microsoft...

Having a security disclosure policy and following it to the letter for everyone (including Google) is suddenly an "unfair competitive process".

[deleted]

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#73
post #55

Just this weekend, I setup a domain name, setup email, and setup apps and accounts to replace Google with open-source software and servers I control, generally (I use some 3rd party services that I feel I can trust, like Fastmail and Namecheap). I then turned off and deleted all of my data from Google that I could without deleting my Google account (I need to forward this long-standing email to my new email and I don…

Every time I read comments like this, I shake my head. Despite recent breaches, I still trust the big players--Google, FB, Microsoft, etc.--with my data from a security perspective far more than I'd trust myself to be able to manage security properly on my own servers or trust a smaller shop. Security is hard . There are many, many more compromises of small firms and self-maintained servers than of these big players,…

Yes, I trust Google, Microsoft, Apple, etc with data reasonably. I would however like one breach to not be catastrophic. Also Google discontinuing Inbox made my Fastmail experiement permanent.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#74

Earlier quoted context omitted.

> Logs show that it has never been used by anyone Yes, because the #1 thing on the mind of someone who gained unauthorized access (e.g. a remote execution vulnerability) to a system is to cover their tracks, which includes things like doctoring logs.

a vulnerability that allows some unauthorized access to user data via the API and a vulnerability that allows edting logs are very different types of vulnerabilities.

Well, the comment I was responding to didn't specify:

> Company finds a security vulnerability caused by a bug

Remote execution vulnerabilities do exist..

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#75
post #14

Earlier quoted context omitted.

I don't know if it should or it shouldn't, but it absolutely is not the norm for companies to announce those vulnerabilities publicly. Every year, most moderate-and-up-sized tech companies (really, a pretty big swathe of the Fortune 500 outside tech, as well) contract multiple penetration tests, and those tests turn up thousands upon thousands of sev:hi vulnerabilities, none of which are ever announced. An obligation…

It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even https://www.cms.gov/Outreach-and-Education/Medicare-Learning... edit: less-than sign wrong way

> It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even It is required by law to report breaches of data, though I can assure you that in practice, this does not happen nearly as often as you'd expect or hope.

There is, however, no requirement to disclose vulnerabilities for which there is no evidence of exploitation or data breach, or to disclose vulnerabilities that were provably never exploited.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#77

Earlier quoted context omitted.

That didn't stop them so far from making everybody else look bad. The latest in Google's unfair competitive practices: "Google discloses Microsoft Edge security flaw before a patch is ready" https://www.theverge.com/2018/2/19/17027138/google-microsoft...

Having a security disclosure policy and following it to the letter for everyone (including Google) is suddenly an "unfair competitive process".

Is the security disclosure policy 3 business days?

https://www.theverge.com/2013/5/23/4358400/google-engineer-b...

Do you think Google acted in a fair or unfair matter?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#78
post #59

Earlier quoted context omitted.

It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even https://www.cms.gov/Outreach-and-Education/Medicare-Learning... edit: less-than sign wrong way

That's a requirement in general for CA. https://www.oag.ca.gov/privacy/databreach/reporting If there is a reasonable belief that data was exposed, all of the exposed CA residents need to be notified, and if > 500, the Atty General of CA needs to additionally be notified.

Again, that's breaches, not vulnerabilities. Literally every company has vulnerabilities.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#79
post #78
post #59

Earlier quoted context omitted.

That's a requirement in general for CA. https://www.oag.ca.gov/privacy/databreach/reporting If there is a reasonable belief that data was exposed, all of the exposed CA residents need to be notified, and if > 500, the Atty General of CA needs to additionally be notified.

Again, that's breaches, not vulnerabilities. Literally every company has vulnerabilities.

Agreed! Apologies, as I think my use of the term "exposed" left that ambiguous. I should have used the original term "acquired". The first line from the link says the following:

> California law requires a business or state agency to notify any California resident whose unencrypted personal information, as defined, was acquired, or reasonably believed to have been acquired, by an unauthorized person.

With links to more specifics in the CA Civil code.

Post reply on HN