Earlier quoted context omitted.
> It's the norm in healthcare (HIPAA), disclosure is required for breaches that affect 500+ persons, and even > https://www.cms.gov/Outreach-and-Education/Medicare-Learning... > edit: less-than sign wrong way* Breaches, not vulnerabilities. The discussion is not whether or not breaches should be disclosed[0], but whether newly discovered and believed-to-be-unexploited vulnerabilities should be disclosed. [0]: They sh…
Easy fix, just design your system so that you can’t confirm whether there ever was a breach because you deleted all the old data
Google Exposed User Data, Feared Repercussions of Disclosing to Public
191–200 of 277 posts
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#192Just this weekend, I setup a domain name, setup email, and setup apps and accounts to replace Google with open-source software and servers I control, generally (I use some 3rd party services that I feel I can trust, like Fastmail and Namecheap). I then turned off and deleted all of my data from Google that I could without deleting my Google account (I need to forward this long-standing email to my new email and I don…
Every time I read comments like this, I shake my head. Despite recent breaches, I still trust the big players--Google, FB, Microsoft, etc.--with my data from a security perspective far more than I'd trust myself to be able to manage security properly on my own servers or trust a smaller shop. Security is hard . There are many, many more compromises of small firms and self-maintained servers than of these big players,…
Take 100 people, and suppose 1 of them decides to stop using Gmail, replacing it with a custom setup. 99 decide to stick with Gmail. The 1 person who spent hours on a custom setup is more likely to leave a comment sharing their experience, tips and tricks, etc. The 99 won't have something noteworthy to post about.
End result is you see disproportionally more comments from people who do something drastic and unusual compared to ones who don't.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#193Earlier quoted context omitted.
I don't know if it should or it shouldn't, but it absolutely is not the norm for companies to announce those vulnerabilities publicly. Every year, most moderate-and-up-sized tech companies (really, a pretty big swathe of the Fortune 500 outside tech, as well) contract multiple penetration tests, and those tests turn up thousands upon thousands of sev:hi vulnerabilities, none of which are ever announced. An obligation…
While that is true, it's worth pointing out that Google's Project Zero has a "disclose by default" approach to vulnerabilities they find, even if there is no proof that they were exploited. The default P0 timeline is 90 days... do we know when Google found this vulnerability in Google+? Does Google apply the P0 deadline to their own vulnerabilities? Is it fair to expect them to?
This wasn't a Project Zero bug, was it? Project Zero is a very special team with a distinct and notable charter. They aren't "Google's Security Folks". Certainly Project Zero has discovered and disclosed bugs in Google products in the past.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#194Earlier quoted context omitted.
Every time I read comments like this, I shake my head. Despite recent breaches, I still trust the big players--Google, FB, Microsoft, etc.--with my data from a security perspective far more than I'd trust myself to be able to manage security properly on my own servers or trust a smaller shop. Security is hard . There are many, many more compromises of small firms and self-maintained servers than of these big players,…
I would explain it with sampling bias. Take 100 people, and suppose 1 of them decides to stop using Gmail, replacing it with a custom setup. 99 decide to stick with Gmail. The 1 person who spent hours on a custom setup is more likely to leave a comment sharing their experience, tips and tricks, etc. The 99 won't have something noteworthy to post about. End result is you see disproportionally more comments from people…
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#195Earlier quoted context omitted.
Ah yes, the perennial story of the lone inventor or two, with a world changing invention, who has their idea stolen by a big company. Did it ever occur to you that the idea of syncing video or audio playback across devices or people is not a new idea and is continually reinvented? I've been on the net since '86, and every brilliant idea I had in secret, I was surprised to learn had been thought of by others too. The…
Well your employer was granted patents for what we met them for and emphatically said to us the race is on. So your saying it held no value to your employer and they have every right to treat the little guy dreamer inventors who do not have the right connections like dogs? Also it wasn't nor isn't an idea rather algorithms we created in 2013 (have improved since) that just worked and work now... demo videos below...…
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#196Companies internally find and fix security bugs all the time and dont talk about it if no known breach occured. Is there a requirement to do this? Maybe there should be a requirement to document that due diligence occurred to understand if it was exploited?
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#197Earlier quoted context omitted.
While that is true, it's worth pointing out that Google's Project Zero has a "disclose by default" approach to vulnerabilities they find, even if there is no proof that they were exploited. The default P0 timeline is 90 days... do we know when Google found this vulnerability in Google+? Does Google apply the P0 deadline to their own vulnerabilities? Is it fair to expect them to?
No, it's not reasonable to apply P0's public vulnerability research norms to internal security research. P0 "competes" on an even playing field with everyone else doing public vulnerability research and, to a reasonable approximation, has access to the same information that everyone else does. Internal security assessment teams have privileged information not available to public researchers, and rely on that informat…
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#198non-paywall version: http://archive.is/rpuA1
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#199Earlier quoted context omitted.
The regulatory costs of GDPR mean that for every piece of log data, you want to think about whether or not you really want to keep it. If you don't have a good business case for keeping it, you're often better off erring on the side of deletion.
Both the breach and the fix happened months before GDPR went into effect, though.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#200Earlier quoted context omitted.
Well your employer was granted patents for what we met them for and emphatically said to us the race is on. So your saying it held no value to your employer and they have every right to treat the little guy dreamer inventors who do not have the right connections like dogs? Also it wasn't nor isn't an idea rather algorithms we created in 2013 (have improved since) that just worked and work now... demo videos below...…
I'm not aware of any Google product that has this functionality. What is preventing you from selling your apps?
We'd love to find those connections who sincerely want to guide us (are well connected) so our next big meeting with a FANNG or another tech company is a win for all! I believe if we went in the meeting well connected in the Valley things would have been different! Not treated like dogs!