Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

151–160 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#151

Earlier quoted context omitted.

No, I get surprisingly decent service from Comcast plus I'm obviously their customer not their product. How about "more weaselly than Facebook"?

> I'm obviously their customer not their product This is the same comcast we're talking about right? The one that's spent millions lobbying for the right to monitor what their customers do online and sell it to advertisers?

It's a rigged game for sure. Would Comcast and the other ISPs be fighting so hard for these rights if they didn't have Google and Facebook as models of success using them?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#152
post #144

Wow the Wall St. Journal and Murdoch really does not like Google. This article makes this sound like this is something that it appears to not be. Did this all start when Google fired Damore? Or does it date further back?

Goes way back: http://allthingsd.com/20091124/whats-really-behind-the-rupe-...

No mention of the Google-Murdoch spate is complete without a link to this classic: https://europe.googleblog.com/2014/09/dear-rupert_25.html

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#153
post #90

Related discussion here: https://news.ycombinator.com/item?id=18169243 . Normally we'd treat these as dupes of each other (and initially we did that), but there seem to be two stories here: one about the data breach and one about Google+. So I guess we'll leave both of them up.

It's a fancy bit of PR-fu right here from Google, like releasing a jobs report right after a big hurricane hits so people don't notice it. A data breach is one thing, but the cover-up should put the nail in coffin of Google's image as benevolent good guys. They are basically Comcast now.

HA... Google is definitely doing Evil.

I for one experienced personally when they invited my friend & I to discuss buying our app. They just wanted our secret sauce & after baiting us with promise of working together they us kicked us out and said the race is on.

Now there was no guarantees we’d be working together but two guys with no connections is tricked by Google and told the race is on? Us vs. Google who later is granted patents for what we met them about.

Now everyone says that’s just how Silicon Valley is...its expected. Hmmm things change!

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#154
post #116
post #98

>We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug. Wait, so they only keep two weeks worth of logs and within these logs they did not find anyone abusing this flaw. How can they be certain for any time period from two week prior ?

The company which consider every single bit of data as "gold" decided not to keep their API's access log > 2 weeks? wow!

It's not like they don't have the storage space for more. Heck, the full logs for all Google+ usage probably fit on a USB stick. :)

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#155

Google's Project Zero is always taking others to task for security yet not a peep from them on this. Their front page today is focused on bugs in Safari, Linux and Windows. Perhaps they should focus on their own products. Its complete hypocrisy to affect commitment and then slink away when it comes to your own products. That raises questions about conflict of interest and credibility.

The Project Zero team is specifically supposed to find Zero Days in other products to make everyone more safe. Google has other security teams for finding bugs in their own products. This isn't Project Zero's fault, nor does it really have anything to do with them. Project Zero is one of the decent teams at google trying to do good by everyone; they can't find every single bug, and if they changed their mission to just focus on Google products we might not have found all sorts of big bugs (eg. heartbleed) for a lot longer. Probably best to leave them alone and let them get on with their business.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#156

I’m surprised Google’s own Project Zero did not caught this one.

When your purview is as wide as theirs, you can't catch every single vulnerability; I'm sure there are plenty of things in openssl, linux, etc. that they (or anyone else) haven't caught yet too :)

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#157

Earlier quoted context omitted.

> I'm obviously their customer not their product This is the same comcast we're talking about right? The one that's spent millions lobbying for the right to monitor what their customers do online and sell it to advertisers?

It's a rigged game for sure. Would Comcast and the other ISPs be fighting so hard for these rights if they didn't have Google and Facebook as models of success using them?

Probably not; but regardless of "why", you're definitely also one of their products :)

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#158
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

Yes, it's been part of the regulations in the EU, even before GDPR. Being forced to disclose in a timely manner ensures it can't be swept under the rug because they squint at the logs just right.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#159
post #90

Related discussion here: https://news.ycombinator.com/item?id=18169243 . Normally we'd treat these as dupes of each other (and initially we did that), but there seem to be two stories here: one about the data breach and one about Google+. So I guess we'll leave both of them up.

It's a fancy bit of PR-fu right here from Google, like releasing a jobs report right after a big hurricane hits so people don't notice it. A data breach is one thing, but the cover-up should put the nail in coffin of Google's image as benevolent good guys. They are basically Comcast now.

Is it a data breach if they know that nobody used it?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#160
post #116

Earlier quoted context omitted.

The company which consider every single bit of data as "gold" decided not to keep their API's access log > 2 weeks? wow!

I too find Google only keeping 2 weeks of logs unbelievable.

You might find it surprising, but at Google it's common to do things like not returning anything when aggregating data from a small number of users. That's before even looking at projects like RAPPOR or ESA. Source: I had access to sensitive data many years ago.
Post reply on HN