Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

121–130 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#121
post #114
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

> Logs show that it has never been used by anyone Some other article I saw quoted somewhere said that they only kept logs for a short time for this service. I wonder how they ruled out exploits older than the logs?

Seems likely they actually didn't. Apparently the further down this comment thread you go, the more times this has already been mentioned. (I read the top comment in the thread having already understood this, and thus interpreted it as a hypothetical question. But in this case, it wasn't provable at all, according to Google themselves' own statement.)

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#122
post #105

Earlier quoted context omitted.

Wow. “We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks.” The wording of this is really pushing the boundary of plausibility. I fail to understand the logic of how this would protect privacy? Access logs with no profile data logged would not compromise privacy would it? Can anyone confirm the timing of the google blog post? It seems the WSJ article was posted at a similar…

> Access logs with no profile data logged would not compromise privacy would it? True, but access logs without profile data would prevent you know _which_ profiles were accessed. This matches with the actual claim in the article that they would be "unable to determine which users were affected"

Right, but the only "profile data" they would need to add to the logs to know, would be a user ID. Not really any private info.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#124
post #94

Earlier quoted context omitted.

"Logs show that it has never been used by anyone" Is it 100% confirmed that the logs would show it? What they said was "We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any Profile data was misused." That seems only to say they couldn't find anything. Not that it absolutely didn't happen.

You can't prove a negative. All you can do is hope that your logs are not tampered with and that they show that nobody used the hole that you are aware of .

I don't know how you could prove whether anyone exploited this or not, unless you found a breach list posted on the open internet... even if you had the access logs:

> This data is limited to static, optional Google+ Profile fields including name, email address, occupation, gender and age. (See the full list on our developer site.) It does not include any other data

This is such a bogus statement out front. The first time I read it, I didn't even see "the full list" mentioned. The full list is much longer than this seemingly innocuous list of properties of a person. It includes such gems as:

> A list of places where this person has lived.

> A list of email addresses that this person has,

> The hosted domain name for the user's Google Apps account.

It's a little worse than they painted it to be, maybe not much, but at least they're being transparent, I guess...

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#125
post #124

Earlier quoted context omitted.

You can't prove a negative. All you can do is hope that your logs are not tampered with and that they show that nobody used the hole that you are aware of .

I don't know how you could prove whether anyone exploited this or not, unless you found a breach list posted on the open internet... even if you had the access logs: > This data is limited to static, optional Google+ Profile fields including name, email address, occupation, gender and age. (See the full list on our developer site.) It does not include any other data This is such a bogus statement out front. The first…

That's sort of the point. You can only prove positively that a breach has been exploited because there can be proof of that. But there can never be 100% ironclad proof that it wasn't exploited.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#126
post #102

Earlier quoted context omitted.

> It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even > https://www.cms.gov/Outreach-and-Education/Medicare-Learning... > edit: less-than sign wrong way* Breaches, not vulnerabilities. The discussion is not whether or not breaches should be disclosed[0], but whether newly discovered and believed-to-be-unexploited vulnerabilities should be disclosed. [0]: They sh…

> believed-to-be-unexploited vulnerabilities you cannot prove the negative (realistically). If you have a vulnerability, you must treat it as though it has been exploited.

That is the kind of argument that carries a lot of force on a message board, but is not at all lined up with how the world actually works. In reality, almost nobody operates under the norm of "any vulnerability found must have been exploited", and even fewer organizations disclose as if they were.

You can want the world to work differently, but to do so coherently I think you should explicitly engage with the unintended consequences of such a policy.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#127
post #114
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

> Logs show that it has never been used by anyone Some other article I saw quoted somewhere said that they only kept logs for a short time for this service. I wonder how they ruled out exploits older than the logs?

I have no idea, but another thing to consider is that they probably have longer-term access to the binaries of all the applications that ever used this API, and they certainly have tools for automated/large-scale inspection of applications.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#129

What would the EU fine for Google be now GDPR is enforced? 2.2 billion dollars?

A company in my country got fined recently for not protecting data of ~735k users (7% of the country's population) (leaked email, password, phone, full name ...) they failed to disclose properly to the regulator and the users. They got ~$60,000 fine. GDPR was part of the reasoning for the fine.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#130

Earlier quoted context omitted.

> Access logs with no profile data logged would not compromise privacy would it? True, but access logs without profile data would prevent you know _which_ profiles were accessed. This matches with the actual claim in the article that they would be "unable to determine which users were affected"

Right, but the only "profile data" they would need to add to the logs to know, would be a user ID. Not really any private info.

[deleted]
Post reply on HN