Google Exposed User Data, Feared Repercussions of Disclosing to Public
91–100 of 277 posts
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#92Earlier quoted context omitted.
Then, to be clear, is your position that companies should be punished (fined) if there has ever been the possibility that user data was compromised? It's possible that a time-traveling quantum-powered encryption-breaking mind-reader from the future has seen your personal data. Should we fine everybody who knows anything about you? Reckless endangerment deals with the possibility of something bad happening, but notice…
I didn't say GDPR would apply in this situation, and the WSJ story suggests it wouldn't because of when it was discovered. All I said was that GDPR was great (obviously we'd only see the benefits from it after it had gone into effect), and this latest scoop bodes well for the political movement to enact equivalent legislation in the US.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#93Earlier quoted context omitted.
Every time I read comments like this, I shake my head. Despite recent breaches, I still trust the big players--Google, FB, Microsoft, etc.--with my data from a security perspective far more than I'd trust myself to be able to manage security properly on my own servers or trust a smaller shop. Security is hard . There are many, many more compromises of small firms and self-maintained servers than of these big players,…
The problem is that you need to trust a lot more than just Google. 1) Google 2) Every government that has the power to compel Google to release your private information, from Chile's to the Cayman Islands 3) Every agent empowered by any of the governments from 2) 4) Every person and/or organisation that could be furnished with your data as part of some sort of "discovery" process by any of the agents listed in 3 (for…
This has nothing to do with Google. In a divorce case, you would be compelled to disclose your email, not Google, so using another provider wouldn't matter, because you would be compelled to turn over any emails there too.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#94Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…
Is it 100% confirmed that the logs would show it?
What they said was "We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any Profile data was misused."
That seems only to say they couldn't find anything. Not that it absolutely didn't happen.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#95Earlier quoted context omitted.
Unless they are 100% certain it hasn't been exploited, yes. The reputational and legal risk to appearing to not disclose / cover up an issue is far larger than the issue itself. That changes if they are absolutely certain it was not exploited: then it's just a bug that they fixed and there's no impact beyond that.
How many vulns do you think companies find internally daily? Should every vuln be publicized?
So does that mean that every single time you patch a remote-exploitable hole, in your web server, et.al, you have to file a report with every single government saying that there might have been a leak of all our data from all of our users, but we're not sure? It will be like the California proposition 65 warning where there will be so many "could be potentially harmful to a fetus" warnings that they all fade into the noise.
Just think of all of the CVE's reported by Microsoft, Red hat, etc. Anyone of those _could_ be a vulnerability leading to the loss of user data, and there is no guarantees that you would be able to detect it via logs.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#96Companies internally find and fix security bugs all the time and dont talk about it if no known breach occured. Is there a requirement to do this? Maybe there should be a requirement to document that due diligence occurred to understand if it was exploited?
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#97Related discussion here: https://news.ycombinator.com/item?id=18169243 . Normally we'd treat these as dupes of each other (and initially we did that), but there seem to be two stories here: one about the data breach and one about Google+. So I guess we'll leave both of them up.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#98Wait, so they only keep two weeks worth of logs and within these logs they did not find anyone abusing this flaw. How can they be certain for any time period from two week prior ?
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#99Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#100Just this weekend, I setup a domain name, setup email, and setup apps and accounts to replace Google with open-source software and servers I control, generally (I use some 3rd party services that I feel I can trust, like Fastmail and Namecheap). I then turned off and deleted all of my data from Google that I could without deleting my Google account (I need to forward this long-standing email to my new email and I don…
Your security is only guaranteed by your obscurity. The moment this becomes standard practice and people start using popular software to handle personal services, this version of security will become laughable again.
Centralization does have drawbacks, but it in terms of security it is a major step up from homerun servers in many ways.