Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

181–190 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#181
post #42

Earlier quoted context omitted.

What's the point, then? Google will (or should) spend just about as much effort keeping it live for enterprise users as it would for the rest of us. I don't use it often, but occasionally find useful communities there, especially concerning technical subjects. Now all of that is going to disappear. It's annoying that Google apparently prizes the opinion of enterprise customers enough to half-abort the plan to shut do…

> 90 percent of Google+ user sessions are less than five seconds. If most people are visiting by accident and immediately leaving, it's probably actively causing usability problems and should be shut down.

I don't understand how that follows. Google doesn't need to fix its purported usability problems.

It can let the non-corporate users enjoy the fruit of their labors at keeping Google+ running for corporate users at almost no additional cost.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#182
post #180

So, I couldn't understand what "exposed" means in that article. Was any user's data obtained by someone not authorized to do so, or merely access to the data was possible?

Just possible. Similarly, the recent FB hack didn't actually penetrate 50 million accounts -- that was just an upper bound estimate based how many accounts were "exposed to the risk" of being compromised, probably because they were noted as being touched by the buggy "view as" function.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#183
post #180

So, I couldn't understand what "exposed" means in that article. Was any user's data obtained by someone not authorized to do so, or merely access to the data was possible?

They don’t quite know:

> We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug. However, we ran a detailed analysis over the two weeks prior to patching the bug, and from that analysis, the Profiles of up to 500,000 Google+ accounts were potentially affected. Our analysis showed that up to 438 applications may have used this API. We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any Profile data was misused.

https://www.blog.google/technology/safety-security/project-s...

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#184
post #116
post #98

>We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug. Wait, so they only keep two weeks worth of logs and within these logs they did not find anyone abusing this flaw. How can they be certain for any time period from two week prior ?

The company which consider every single bit of data as "gold" decided not to keep their API's access log > 2 weeks? wow!

Is it possible that your impression of the company is (was?) off?

I'm not surprised. They (claim to) do something similar with the logs of their DNS service: two weeks of anonymized logs after which they "randomly sample a small subset for permanent storage".

https://developers.google.com/speed/public-dns/privacy

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#186

Earlier quoted context omitted.

It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even https://www.cms.gov/Outreach-and-Education/Medicare-Learning... edit: less-than sign wrong way

> It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even > https://www.cms.gov/Outreach-and-Education/Medicare-Learning... > edit: less-than sign wrong way* Breaches, not vulnerabilities. The discussion is not whether or not breaches should be disclosed[0], but whether newly discovered and believed-to-be-unexploited vulnerabilities should be disclosed. [0]: They sh…

Easy fix, just design your system so that you can’t confirm whether there ever was a breach because you deleted all the old data

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#187
post #147

Earlier quoted context omitted.

I would think it should be required to report. Just because you don’t know if a vulnerability was exploited does not mean it was not.

I assume cloud providers have hundreds of security issues that are found internally over the course of a year. Requiring reporting would certainly be a step forward and testing in production for software would maybe be seen as what it is, an engineering anomaly and failure to perform due diligence.

That’s fair. I suppose I would aim for a distinction between minor and major flaws. What would be a reasonable threshold?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#188
post #98

>We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug. Wait, so they only keep two weeks worth of logs and within these logs they did not find anyone abusing this flaw. How can they be certain for any time period from two week prior ?

Developers have a natural, and understandable, urge to include data in the logs that they need for debugging. If you purge logs, it is simpler and easier to have higher confidence that you are retaining only the data you intended to retain.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#189
post #102

Earlier quoted context omitted.

> It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even > https://www.cms.gov/Outreach-and-Education/Medicare-Learning... > edit: less-than sign wrong way* Breaches, not vulnerabilities. The discussion is not whether or not breaches should be disclosed[0], but whether newly discovered and believed-to-be-unexploited vulnerabilities should be disclosed. [0]: They sh…

> believed-to-be-unexploited vulnerabilities you cannot prove the negative (realistically). If you have a vulnerability, you must treat it as though it has been exploited.

I wasn't arguing one way or the other on the issue, just reframing it so everyone's on the same page.

Devil's advocate: Do you believe that proactive security assessments would still be performed if each vulnerability found was required to be disclosed as though it had been exploited?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#190
post #14

Earlier quoted context omitted.

I don't know if it should or it shouldn't, but it absolutely is not the norm for companies to announce those vulnerabilities publicly. Every year, most moderate-and-up-sized tech companies (really, a pretty big swathe of the Fortune 500 outside tech, as well) contract multiple penetration tests, and those tests turn up thousands upon thousands of sev:hi vulnerabilities, none of which are ever announced. An obligation…

It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even https://www.cms.gov/Outreach-and-Education/Medicare-Learning... edit: less-than sign wrong way

I used to write those letters when I worked in insurance. They had to be reviewed by legal, needed to make it clear what level of threat was involved without divulging certain kinds of info and only occurred when an actual breach of some sort had happened.

In my case, it was usually not a computer issue. It was usually a case of "We sent a check or letter to the wrong address" and it was weirdly common for the reason to be "Because your dad, brother or cousin with a similar name and address also has a policy with us and you people are nigh impossible to tell apart."

And we couldn't say anything like that.

Point being that divulging the issue comes with risks of making the problem worse. So it's not as simple and straight forward as it seems.

Post reply on HN