Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

141–150 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#141
Google's Project Zero is always taking others to task for security yet not a peep from them on this. Their front page today is focused on bugs in Safari, Linux and Windows. Perhaps they should focus on their own products.

Its complete hypocrisy to affect commitment and then slink away when it comes to your own products. That raises questions about conflict of interest and credibility.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#142
post #90

Related discussion here: https://news.ycombinator.com/item?id=18169243 . Normally we'd treat these as dupes of each other (and initially we did that), but there seem to be two stories here: one about the data breach and one about Google+. So I guess we'll leave both of them up.

It's a fancy bit of PR-fu right here from Google, like releasing a jobs report right after a big hurricane hits so people don't notice it. A data breach is one thing, but the cover-up should put the nail in coffin of Google's image as benevolent good guys. They are basically Comcast now.

No, I get surprisingly decent service from Comcast plus I'm obviously their customer not their product. How about "more weaselly than Facebook"?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#143
post #128
post #57

Now that Google+ is going away, can we have the +string operator back in Google Search, to force inclusion of a single string (instead of having to use double quotes)?

is that why that was changed???

one can say it was used more

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#144

Wow the Wall St. Journal and Murdoch really does not like Google. This article makes this sound like this is something that it appears to not be. Did this all start when Google fired Damore? Or does it date further back?

Goes way back:

http://allthingsd.com/20091124/whats-really-behind-the-rupe-...

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#145

Earlier quoted context omitted.

It's a fancy bit of PR-fu right here from Google, like releasing a jobs report right after a big hurricane hits so people don't notice it. A data breach is one thing, but the cover-up should put the nail in coffin of Google's image as benevolent good guys. They are basically Comcast now.

No, I get surprisingly decent service from Comcast plus I'm obviously their customer not their product. How about "more weaselly than Facebook"?

> surprisingly decent

Ay, there's the rub, innit?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#146
post #140

Earlier quoted context omitted.

I too find Google only keeping 2 weeks of logs unbelievable.

The regulatory costs of GDPR mean that for every piece of log data, you want to think about whether or not you really want to keep it. If you don't have a good business case for keeping it, you're often better off erring on the side of deletion.

Both the breach and the fix happened months before GDPR went into effect, though.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#147
post #31

Companies internally find and fix security bugs all the time and dont talk about it if no known breach occured. Is there a requirement to do this? Maybe there should be a requirement to document that due diligence occurred to understand if it was exploited?

I would think it should be required to report. Just because you don’t know if a vulnerability was exploited does not mean it was not.

I assume cloud providers have hundreds of security issues that are found internally over the course of a year. Requiring reporting would certainly be a step forward and testing in production for software would maybe be seen as what it is, an engineering anomaly and failure to perform due diligence.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#148

Earlier quoted context omitted.

It's a fancy bit of PR-fu right here from Google, like releasing a jobs report right after a big hurricane hits so people don't notice it. A data breach is one thing, but the cover-up should put the nail in coffin of Google's image as benevolent good guys. They are basically Comcast now.

No, I get surprisingly decent service from Comcast plus I'm obviously their customer not their product. How about "more weaselly than Facebook"?

> I'm obviously their customer not their product

This is the same comcast we're talking about right? The one that's spent millions lobbying for the right to monitor what their customers do online and sell it to advertisers?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#149

Earlier quoted context omitted.

It's a fancy bit of PR-fu right here from Google, like releasing a jobs report right after a big hurricane hits so people don't notice it. A data breach is one thing, but the cover-up should put the nail in coffin of Google's image as benevolent good guys. They are basically Comcast now.

No, I get surprisingly decent service from Comcast plus I'm obviously their customer not their product. How about "more weaselly than Facebook"?

> I'm obviously their customer not their product

Are you sure you are not both? ATT gives you a discount on your monthly fee if you allow them to inject their own ads. It was opt-in, but it would not surprise me if they don't just do it to all users. Plus, if you are using their DNS, I'd assume they are slurping in all of that data.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#150

Earlier quoted context omitted.

> Access logs with no profile data logged would not compromise privacy would it? True, but access logs without profile data would prevent you know _which_ profiles were accessed. This matches with the actual claim in the article that they would be "unable to determine which users were affected"

Right, but the only "profile data" they would need to add to the logs to know, would be a user ID. Not really any private info.

User IDs are definitely private info, since they'd allow you to follow a user's behaviour etc.
Post reply on HN