Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

81–90 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#81

Earlier quoted context omitted.

Having a security disclosure policy and following it to the letter for everyone (including Google) is suddenly an "unfair competitive process".

Is the security disclosure policy 3 business days? https://www.theverge.com/2013/5/23/4358400/google-engineer-b... Do you think Google acted in a fair or unfair matter?

It's interesting you have to go back to 2013 to find something.

1. There's actually nothing here to suggest this was done as part of project zero or any part of tavis's job. In fact, this was before project zero even existed, AFAIK.

2. He published details about it in march (O(60) days), as he said. It was still a security bug then, just missing a working exploit.

3. This thread produced a working exploit.

I'm gonna go with "either unrelated or fair".

Unrelated if it wasn't done by Tavis as part of his job, and fair if it was given the timeline and disclosure policies that existed at the time.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#82
post #54

Earlier quoted context omitted.

How many vulns do you think companies find internally daily? Should every vuln be publicized?

If they potentially expose sensitive data, yes. Again, if an organization is certain that it hasn't then I'd say no. Sure, certain is a high bar but there's absolutely no way for people to make informed decisions and/or mitigate issues otherwise.

Okay ... and how to enforce this ?

Because reality is that this would essentially require policing every commit that ever makes it to public serving in every company.

To call that unreasonable is vastly understating matters.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#83
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

> Logs show that it has never been used by anyone.

Citation needed. Google's blog post wasn't very clear, but it sounds like an API that more than 400 developers use returned more data than was intended. Google thinks the developers didn't use this information, but logs wouldn't help Google come to this conclusion.

Murdoch has a vendetta, but Google isn't being transparent here either.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#84
post #55

Just this weekend, I setup a domain name, setup email, and setup apps and accounts to replace Google with open-source software and servers I control, generally (I use some 3rd party services that I feel I can trust, like Fastmail and Namecheap). I then turned off and deleted all of my data from Google that I could without deleting my Google account (I need to forward this long-standing email to my new email and I don…

Every time I read comments like this, I shake my head. Despite recent breaches, I still trust the big players--Google, FB, Microsoft, etc.--with my data from a security perspective far more than I'd trust myself to be able to manage security properly on my own servers or trust a smaller shop. Security is hard . There are many, many more compromises of small firms and self-maintained servers than of these big players,…

The problem is that you need to trust a lot more than just Google.

1) Google

2) Every government that has the power to compel Google to release your private information, from Chile's to the Cayman Islands

3) Every agent empowered by any of the governments from 2)

4) Every person and/or organisation that could be furnished with your data as part of some sort of "discovery" process by any of the agents listed in 3

(for the US: essentially anyone and everyone you've ever had any sort of commercial relationship with)

This means that if you, say, have a divorce case, expect your entire Gmail contents to be used against you by your significant other.

The problem is well explained here:

https://www.stangelawfirm.com/Articles/Facebook-Evidence-and...

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#85

Just this weekend, I setup a domain name, setup email, and setup apps and accounts to replace Google with open-source software and servers I control, generally (I use some 3rd party services that I feel I can trust, like Fastmail and Namecheap). I then turned off and deleted all of my data from Google that I could without deleting my Google account (I need to forward this long-standing email to my new email and I don…

Your security is only guaranteed by your obscurity. The moment this becomes standard practice and people start using popular software to handle personal services, this version of security will become laughable again.

[deleted]

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#86
post #54

Earlier quoted context omitted.

If they potentially expose sensitive data, yes. Again, if an organization is certain that it hasn't then I'd say no. Sure, certain is a high bar but there's absolutely no way for people to make informed decisions and/or mitigate issues otherwise.

Okay ... and how to enforce this ? Because reality is that this would essentially require policing every commit that ever makes it to public serving in every company. To call that unreasonable is vastly understating matters.

I'm not advocating any external enforcement action. Merely taking the position that if there's an internal conversation which goes along the lines of 'that vulnerability could have been really bad but based on what information we have it doesn't look like it's been exploited... should we tell anyone?' then the answer should be yes, it should be disclosed. That sounds like pretty much the conversation that happened inside Google only they decided 'no, better not... we might get in trouble'. That's a red flag right there.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#87

Just this weekend, I setup a domain name, setup email, and setup apps and accounts to replace Google with open-source software and servers I control, generally (I use some 3rd party services that I feel I can trust, like Fastmail and Namecheap). I then turned off and deleted all of my data from Google that I could without deleting my Google account (I need to forward this long-standing email to my new email and I don…

Your security is only guaranteed by your obscurity. The moment this becomes standard practice and people start using popular software to handle personal services, this version of security will become laughable again.

I can understand this position, but I'd be curious what your thoughts are on how to best (I realize there is no perfect) keep your data private from snooping employees, hackers, or law enforcement.

I've thought about this over and over, and it's hard to come to a solid conclusion about keeping personal data safe (in this context I mean emails and files you may store in the cloud, not browsing history, social media posts, etc.). There are so many options with downfalls for each, and I'm not a security expert. So every time I get excited about trying a new service geared towards privacy, or setting up my own instances, inevitably somebody points out the terrible pitfall in it and I get discouraged.

1. Don't use the internet or internet services, period. 2. Use services who market themselves as geared towards privacy. 3. Use regular cloud options, but stack stuff on top - VeraCrypt volumes or Cryptomator with Google drive, GPG for email, etc. 4. Host your own services - i.e. a Nextcloud 14 instance on EC2 with an S3 backend, then use client-side E2E 5. Spread what you do out over multiple services - FastMail for email, DropBox for cloud storage, Standard Notes for notes, etc. I know there will never be a consensus on this, but I'd love to hear what your thoughts are on the best way to keep my personal files and notes personal to me. Let's assume I'm not a target of any spy agencies or whatnot, but I want to make it very, very difficult for anyone to read my person notes and files but me.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#88

Huh why did this post get removed from the front page? It's less than 1 hour old, had acquired a lot of points + comments in the meantime. Yet I can't find it in the first 100 pages as of now.

It was buried as a dupe of https://news.ycombinator.com/item?id=18169243. We're just trying to figure out which URL is the best one for this story. It's a bit harder than usual. In the meantime, I've restored the current thread.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#89
post #31

Companies internally find and fix security bugs all the time and dont talk about it if no known breach occured. Is there a requirement to do this? Maybe there should be a requirement to document that due diligence occurred to understand if it was exploited?

I don't see the benefit. We'd all just end up with a barrage of emails we don't really care about.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#90
Related discussion here: https://news.ycombinator.com/item?id=18169243.

Normally we'd treat these as dupes of each other (and initially we did that), but there seem to be two stories here: one about the data breach and one about Google+. So I guess we'll leave both of them up.

Post reply on HN