Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

131–140 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#131

Earlier quoted context omitted.

Is the security disclosure policy 3 business days? https://www.theverge.com/2013/5/23/4358400/google-engineer-b... Do you think Google acted in a fair or unfair matter?

It's interesting you have to go back to 2013 to find something. 1. There's actually nothing here to suggest this was done as part of project zero or any part of tavis's job. In fact, this was before project zero even existed, AFAIK. 2. He published details about it in march (O(60) days), as he said. It was still a security bug then, just missing a working exploit. 3. This thread produced a working exploit. I'm gonna…

I wasn't going down some reverse chronological timeline. It was in the first page of many of results.

About 1,2 and 3, if you would zoom a bit out, you have an advertising company that is, by it's intentional actions, making the rest look bad. Outside of contacting the relevant companies, they don't have to push the exploits to the world, yet they do.

The rest is just how one spins the story depending on the size of the paycheck received from Google.

There is nothing left to conclude, I am out of this thread.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#132
post #116
post #98

>We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug. Wait, so they only keep two weeks worth of logs and within these logs they did not find anyone abusing this flaw. How can they be certain for any time period from two week prior ?

The company which consider every single bit of data as "gold" decided not to keep their API's access log > 2 weeks? wow!

I too find Google only keeping 2 weeks of logs unbelievable.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#134
post #14
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

I don't know if it should or it shouldn't, but it absolutely is not the norm for companies to announce those vulnerabilities publicly. Every year, most moderate-and-up-sized tech companies (really, a pretty big swathe of the Fortune 500 outside tech, as well) contract multiple penetration tests, and those tests turn up thousands upon thousands of sev:hi vulnerabilities, none of which are ever announced. An obligation…

>An obligation to announce findings would create a moral hazard as well, since the incentives would suddenly tilt sharply towards not looking for security vulnerabilities.

A good point. There is also the fact that the average Internet user has no clue what things like a vulnerability, or a bug, or even a log is or what it means. Data mining, web scraping or data harvesting--no clue.

I just saw a TV report this weekend that stated CA hacked FB. Well on second thought, maybe that's better than trying to explain that even though "thisisyourdigitallife" you really need to spend some time and effort to understand what it all actually means.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#135
post #97
post #90

Related discussion here: https://news.ycombinator.com/item?id=18169243 . Normally we'd treat these as dupes of each other (and initially we did that), but there seem to be two stories here: one about the data breach and one about Google+. So I guess we'll leave both of them up.

Maybe even three stories; there's another bit in that Google blog post about Google making their API permission prompts for Gmail, Drive, Calendar, and contacts more fine-grained and locking them down with policy measures.

This is extremely problematic for us. We're bootstrapped and now Google is suddenly asking for up to $75,000 (or more) for a security audit.

This despite the fact that we've been publicly asking for more limited OAuth scopes for years (c.f. my HN posting history and my tickets on the Google issue tracker), and the fact that we've had zero security incidents in over three years. All to ensure that we're not risking exposing user data that we don't even have, have never accessed, and shouldn't need access to in the first place.

https://cloud.google.com/blog/products/g-suite/elevating-use...

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#137

Earlier quoted context omitted.

The problem is that you need to trust a lot more than just Google. 1) Google 2) Every government that has the power to compel Google to release your private information, from Chile's to the Cayman Islands 3) Every agent empowered by any of the governments from 2) 4) Every person and/or organisation that could be furnished with your data as part of some sort of "discovery" process by any of the agents listed in 3 (for…

>This means that if you, say, have a divorce case, expect your entire Gmail contents to be used against you by your significant other. This has nothing to do with Google. In a divorce case, you would be compelled to disclose your email, not Google, so using another provider wouldn't matter, because you would be compelled to turn over any emails there too.

Sure but you have a lot of options if you control your own emails that you don't have if someone else does. For instance, you can actually delete your emails, and know they are deleted (obviously I'm saying before any such case). The same option does not exist on the cloud.

(incidentally this is exactly why most corporations these days have a pretty short email retention policy, something like 3-6 months. As long as you delete the mails before a complaint, or at least before discovery is granted, there's nothing wrong with deleting them, even if it is to avoid them being used against you later. But there's other advantages too: it helps me get organized, and it prevents me from obsessing over things that have slipped so far down the priority list they'll never happen. Which is very soothing. Plus it breeds the good habit of not storing important things in your inbox)

I would like to point out that often the criticism is leveled that you'd only do this if you're guilty. Aside from that that is the "if you've got nothing to hide ..." argument against privacy, it comes with a lot of false assumptions. For instance, that such information will not spread, that laws won't change in bad ways you can't control, that you can trust law enforcement infinitely and indefinitely, and so on and so forth.

Also, a wise man once said: "In theory, theory and practice are the same. In practice however, ...". What you control is yours, and with proper security measures no power the police or justice system has can break that control. That's as it should be.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#138
post #94

Earlier quoted context omitted.

"Logs show that it has never been used by anyone" Is it 100% confirmed that the logs would show it? What they said was "We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any Profile data was misused." That seems only to say they couldn't find anything. Not that it absolutely didn't happen.

You can't prove a negative. All you can do is hope that your logs are not tampered with and that they show that nobody used the hole that you are aware of .

Well a little bit of detail as to whether exploiting this bug even creates a log entry might be interesting.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#139
post #69
post #38

Earlier quoted context omitted.

So, pivot to Slack-alike. I'm sure it'll last.

They could have cornered that market with Google Wave, but killed the project before it took off.

If it makes you feel any better, whether something is popular or not has never been a barrier to Google killing stuff.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#140
post #116

Earlier quoted context omitted.

The company which consider every single bit of data as "gold" decided not to keep their API's access log > 2 weeks? wow!

I too find Google only keeping 2 weeks of logs unbelievable.

The regulatory costs of GDPR mean that for every piece of log data, you want to think about whether or not you really want to keep it.

If you don't have a good business case for keeping it, you're often better off erring on the side of deletion.

Post reply on HN