Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…
> Logs show that it has never been used by anyone Some other article I saw quoted somewhere said that they only kept logs for a short time for this service. I wonder how they ruled out exploits older than the logs?
Google Exposed User Data, Feared Repercussions of Disclosing to Public
121–130 of 277 posts
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#122Earlier quoted context omitted.
Wow. “We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks.” The wording of this is really pushing the boundary of plausibility. I fail to understand the logic of how this would protect privacy? Access logs with no profile data logged would not compromise privacy would it? Can anyone confirm the timing of the google blog post? It seems the WSJ article was posted at a similar…
> Access logs with no profile data logged would not compromise privacy would it? True, but access logs without profile data would prevent you know _which_ profiles were accessed. This matches with the actual claim in the article that they would be "unable to determine which users were affected"
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#123Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#124Earlier quoted context omitted.
"Logs show that it has never been used by anyone" Is it 100% confirmed that the logs would show it? What they said was "We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any Profile data was misused." That seems only to say they couldn't find anything. Not that it absolutely didn't happen.
You can't prove a negative. All you can do is hope that your logs are not tampered with and that they show that nobody used the hole that you are aware of .
> This data is limited to static, optional Google+ Profile fields including name, email address, occupation, gender and age. (See the full list on our developer site.) It does not include any other data
This is such a bogus statement out front. The first time I read it, I didn't even see "the full list" mentioned. The full list is much longer than this seemingly innocuous list of properties of a person. It includes such gems as:
> A list of places where this person has lived.
> A list of email addresses that this person has,
> The hosted domain name for the user's Google Apps account.
It's a little worse than they painted it to be, maybe not much, but at least they're being transparent, I guess...
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#125Earlier quoted context omitted.
You can't prove a negative. All you can do is hope that your logs are not tampered with and that they show that nobody used the hole that you are aware of .
I don't know how you could prove whether anyone exploited this or not, unless you found a breach list posted on the open internet... even if you had the access logs: > This data is limited to static, optional Google+ Profile fields including name, email address, occupation, gender and age. (See the full list on our developer site.) It does not include any other data This is such a bogus statement out front. The first…
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#126Earlier quoted context omitted.
> It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even > https://www.cms.gov/Outreach-and-Education/Medicare-Learning... > edit: less-than sign wrong way* Breaches, not vulnerabilities. The discussion is not whether or not breaches should be disclosed[0], but whether newly discovered and believed-to-be-unexploited vulnerabilities should be disclosed. [0]: They sh…
> believed-to-be-unexploited vulnerabilities you cannot prove the negative (realistically). If you have a vulnerability, you must treat it as though it has been exploited.
You can want the world to work differently, but to do so coherently I think you should explicitly engage with the unintended consequences of such a policy.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#127Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…
> Logs show that it has never been used by anyone Some other article I saw quoted somewhere said that they only kept logs for a short time for this service. I wonder how they ruled out exploits older than the logs?
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#128Now that Google+ is going away, can we have the +string operator back in Google Search, to force inclusion of a single string (instead of having to use double quotes)?
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#129What would the EU fine for Google be now GDPR is enforced? 2.2 billion dollars?
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#130Earlier quoted context omitted.
> Access logs with no profile data logged would not compromise privacy would it? True, but access logs without profile data would prevent you know _which_ profiles were accessed. This matches with the actual claim in the article that they would be "unable to determine which users were affected"
Right, but the only "profile data" they would need to add to the logs to know, would be a user ID. Not really any private info.