Earlier quoted context omitted.
a vulnerability that allows some unauthorized access to user data via the API and a vulnerability that allows edting logs are very different types of vulnerabilities.
Well, the comment I was responding to didn't specify: > Company finds a security vulnerability caused by a bug Remote execution vulnerabilities do exist..
Google Exposed User Data, Feared Repercussions of Disclosing to Public
101–110 of 277 posts
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#102Earlier quoted context omitted.
It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even https://www.cms.gov/Outreach-and-Education/Medicare-Learning... edit: less-than sign wrong way
> It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even > https://www.cms.gov/Outreach-and-Education/Medicare-Learning... > edit: less-than sign wrong way* Breaches, not vulnerabilities. The discussion is not whether or not breaches should be disclosed[0], but whether newly discovered and believed-to-be-unexploited vulnerabilities should be disclosed. [0]: They sh…
you cannot prove the negative (realistically). If you have a vulnerability, you must treat it as though it has been exploited.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#103Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…
"Logs show that it has never been used by anyone" Is it 100% confirmed that the logs would show it? What they said was "We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any Profile data was misused." That seems only to say they couldn't find anything. Not that it absolutely didn't happen.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#104Earlier quoted context omitted.
Well, the comment I was responding to didn't specify: > Company finds a security vulnerability caused by a bug Remote execution vulnerabilities do exist..
The logs live somewhere else. If you had some magic exploit that let you run code on Google systems AND delete logs, you could do much more damaging things than just reading G+ data.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#105>We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug. Wait, so they only keep two weeks worth of logs and within these logs they did not find anyone abusing this flaw. How can they be certain for any time period from two week prior ?
The wording of this is really pushing the boundary of plausibility.
I fail to understand the logic of how this would protect privacy? Access logs with no profile data logged would not compromise privacy would it?
Can anyone confirm the timing of the google blog post? It seems the WSJ article was posted at a similar time.
This leads me to believe that the most likely reason we are hearing about this now is due to comment requests from the WSJ. WHEN Goog realised it was out they published.
Goog is trying to avoid using the words Data breach as they may get into hot water in EU.
Love how it is buried in the article.
My guess is a similar thing has been happening with android permissions. Data has been leaking through that they have just not admitted to it.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#106What would the EU fine for Google be now GDPR is enforced? 2.2 billion dollars?
GDPR enforcement would come into effect only if there was a breach and it was not handled. From what is in the story and from what we know, there has been no breach. As 'tptacek has noted, it is very unusual to announce a security bug without a resultant breach.
'We don't know who was affected and what data may have been collected' is way different than what you're saying. It also opens up lots of questions, such as why a company with the resources of Google would not persist security critical logs indefinitely.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#107Earlier quoted context omitted.
> It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even > https://www.cms.gov/Outreach-and-Education/Medicare-Learning... > edit: less-than sign wrong way* Breaches, not vulnerabilities. The discussion is not whether or not breaches should be disclosed[0], but whether newly discovered and believed-to-be-unexploited vulnerabilities should be disclosed. [0]: They sh…
> believed-to-be-unexploited vulnerabilities you cannot prove the negative (realistically). If you have a vulnerability, you must treat it as though it has been exploited.
edit: Within reason, anyway. Obviously if your vulnerability includes write access to logs or something then you're poked.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#108Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…
I don't know if it should or it shouldn't, but it absolutely is not the norm for companies to announce those vulnerabilities publicly. Every year, most moderate-and-up-sized tech companies (really, a pretty big swathe of the Fortune 500 outside tech, as well) contract multiple penetration tests, and those tests turn up thousands upon thousands of sev:hi vulnerabilities, none of which are ever announced. An obligation…
The default P0 timeline is 90 days... do we know when Google found this vulnerability in Google+? Does Google apply the P0 deadline to their own vulnerabilities? Is it fair to expect them to?
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#109>We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug. Wait, so they only keep two weeks worth of logs and within these logs they did not find anyone abusing this flaw. How can they be certain for any time period from two week prior ?
Wow. “We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks.” The wording of this is really pushing the boundary of plausibility. I fail to understand the logic of how this would protect privacy? Access logs with no profile data logged would not compromise privacy would it? Can anyone confirm the timing of the google blog post? It seems the WSJ article was posted at a similar…
True, but access logs without profile data would prevent you know _which_ profiles were accessed. This matches with the actual claim in the article that they would be "unable to determine which users were affected"
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#110Earlier quoted context omitted.
No, they would have to issue like 10 reports a day. Bugs that are never exploited in web sites are rarely published for multiple reasons. Definitely not something to blame Google for.
If it wasn't exploited makes it even better...shows that you are being aggressive in identifying issues and applying corrections. Take advantage of opportunities to show transparency in a good light as well as meet your commitments to be transparent when events have not gone your way. This shouldn't be about how many reports you have to issue. Google can afford the staff to make that happen.