Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

91–100 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#92
post #65
post #56

Earlier quoted context omitted.

Then, to be clear, is your position that companies should be punished (fined) if there has ever been the possibility that user data was compromised? It's possible that a time-traveling quantum-powered encryption-breaking mind-reader from the future has seen your personal data. Should we fine everybody who knows anything about you? Reckless endangerment deals with the possibility of something bad happening, but notice…

I didn't say GDPR would apply in this situation, and the WSJ story suggests it wouldn't because of when it was discovered. All I said was that GDPR was great (obviously we'd only see the benefits from it after it had gone into effect), and this latest scoop bodes well for the political movement to enact equivalent legislation in the US.

[deleted]

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#93
post #55

Earlier quoted context omitted.

Every time I read comments like this, I shake my head. Despite recent breaches, I still trust the big players--Google, FB, Microsoft, etc.--with my data from a security perspective far more than I'd trust myself to be able to manage security properly on my own servers or trust a smaller shop. Security is hard . There are many, many more compromises of small firms and self-maintained servers than of these big players,…

The problem is that you need to trust a lot more than just Google. 1) Google 2) Every government that has the power to compel Google to release your private information, from Chile's to the Cayman Islands 3) Every agent empowered by any of the governments from 2) 4) Every person and/or organisation that could be furnished with your data as part of some sort of "discovery" process by any of the agents listed in 3 (for…

>This means that if you, say, have a divorce case, expect your entire Gmail contents to be used against you by your significant other.

This has nothing to do with Google. In a divorce case, you would be compelled to disclose your email, not Google, so using another provider wouldn't matter, because you would be compelled to turn over any emails there too.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#94
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

"Logs show that it has never been used by anyone"

Is it 100% confirmed that the logs would show it?

What they said was "We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any Profile data was misused."

That seems only to say they couldn't find anything. Not that it absolutely didn't happen.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#95
post #33

Earlier quoted context omitted.

Unless they are 100% certain it hasn't been exploited, yes. The reputational and legal risk to appearing to not disclose / cover up an issue is far larger than the issue itself. That changes if they are absolutely certain it was not exploited: then it's just a bug that they fixed and there's no impact beyond that.

How many vulns do you think companies find internally daily? Should every vuln be publicized?

Every single root escalation bug could potentially leak huge amounts of data. And the definition of a successful exploit is one where you don't find out for a long time, or perhaps, not ever.

So does that mean that every single time you patch a remote-exploitable hole, in your web server, et.al, you have to file a report with every single government saying that there might have been a leak of all our data from all of our users, but we're not sure? It will be like the California proposition 65 warning where there will be so many "could be potentially harmful to a fetus" warnings that they all fade into the noise.

Just think of all of the CVE's reported by Microsoft, Red hat, etc. Anyone of those _could_ be a vulnerability leading to the loss of user data, and there is no guarantees that you would be able to detect it via logs.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#96
post #31

Companies internally find and fix security bugs all the time and dont talk about it if no known breach occured. Is there a requirement to do this? Maybe there should be a requirement to document that due diligence occurred to understand if it was exploited?

I would think it should be required to report. Just because you don’t know if a vulnerability was exploited does not mean it was not.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#97
post #90

Related discussion here: https://news.ycombinator.com/item?id=18169243 . Normally we'd treat these as dupes of each other (and initially we did that), but there seem to be two stories here: one about the data breach and one about Google+. So I guess we'll leave both of them up.

Maybe even three stories; there's another bit in that Google blog post about Google making their API permission prompts for Gmail, Drive, Calendar, and contacts more fine-grained and locking them down with policy measures.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#98
>We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug.

Wait, so they only keep two weeks worth of logs and within these logs they did not find anyone abusing this flaw. How can they be certain for any time period from two week prior ?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#99
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

Isn’t the news section of the Journal walled off from the editorial section? As a regular reader of the Journal’s news section (but not the editorial), I find its reporting to be quite solid usually.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#100

Just this weekend, I setup a domain name, setup email, and setup apps and accounts to replace Google with open-source software and servers I control, generally (I use some 3rd party services that I feel I can trust, like Fastmail and Namecheap). I then turned off and deleted all of my data from Google that I could without deleting my Google account (I need to forward this long-standing email to my new email and I don…

Your security is only guaranteed by your obscurity. The moment this becomes standard practice and people start using popular software to handle personal services, this version of security will become laughable again.

I think even that is being too generous. If you’ve ever set up any kind of public-facing server, no matter how obscure, you know that scans for vulnerabilities are constant. Whoops, you didn’t install that urgent Apache update because you were on vacation with no SSL access? You’re pwned.

Centralization does have drawbacks, but it in terms of security it is a major step up from homerun servers in many ways.

Post reply on HN