Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

211–220 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#211

non-paywall version: http://archive.is/rpuA1

Does anyone else get rubbed the wrong way by this sort of irreverent infringement? Even if you have zero concern for journalists’ copyrights, it puts this forum at risk.

Not I

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#212
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

>Logs show that it has never been used by anyone. It patches the vulnerability.

>We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug.

They have no idea if it has been used.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#213
Nowadays I tend to trust a company that had a security vulnerability or data breach once and handled it gracefully, rather than a company that says they had no security breach. Making a mistake is only human; Your true test is what you do after you found it.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#214
post #205

Earlier quoted context omitted.

Our default policy is to keep generic RPC server logs for O(weeks). It's best practice as we log a lot of structured data that can be large -- especially at our QPS. Furthermore, we have data retention timelines to keep.

> Our default policy is to keep generic RPC server logs for O(weeks). Out of curiosity, when was this policy adopted? After these security holes were discovered?

Doesn't the statement "That means we cannot confirm which users were impacted by this bug" indicate it was adopted before the hole was discovered?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#215
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

> Logs show that it has never been used by anyone.

They don't have log coverage for 90%+ of the time period, so that's not something their logs could even possibly show.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#217

Earlier quoted context omitted.

Ah yes, the perennial story of the lone inventor or two, with a world changing invention, who has their idea stolen by a big company. Did it ever occur to you that the idea of syncing video or audio playback across devices or people is not a new idea and is continually reinvented? I've been on the net since '86, and every brilliant idea I had in secret, I was surprised to learn had been thought of by others too. The…

Why do so many Googlers on HN have such unpleasant personalities? "Did it ever occur to you" that you make your employer look even more awful?

Isn't making accusations of theft and industrial espionage is unpleasant? This kind of accusation in the industry crops up time and time again and I don't think it should be accepted unchallenged, neither between small companies, or large ones.

I've seen this claims so many times, people claiming some investors took their deck and gave it to their portfolio companies, people claiming another company copied them. The instances where this actually happens usually occurs when an already proven market product is copied (e.g. look at FB copying Snapchat recently), I've never seen it with a pre-success product.

Think of it this way, if I had the idea for capacitive touch smart screen phone in 2004 and met with Apple, could I claim they stole the iPhone from me? There is so much more to an iPhone than just the 'idea'.

Now, if you have some non-obvious algorithm, which if you asked a senior engineer to design, could not come up with it in a few weeks, my opinion would be different. Like if you invented a fundamental new type of homomorphic encryption, which, could be explained on a single page, but enables a fundamentally new type of distributed computing.

There are indeed, some ideas which are very 'dense' in value purely by their description alone, but they're few and far between.

In any case, online forums are rife with people making conspiratorial claims, in economics, in politics, everywhere, and I think a technical community like HN should demand a higher degree of evidence.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#218

non-paywall version: http://archive.is/rpuA1

Does anyone else get rubbed the wrong way by this sort of irreverent infringement? Even if you have zero concern for journalists’ copyrights, it puts this forum at risk.

If it put the forum at risk, they wouldn’t put the “web” link after the title of the post, which basically accomplishes the same thing. This kind of thing is officially sanctioned.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#219

Earlier quoted context omitted.

Why do so many Googlers on HN have such unpleasant personalities? "Did it ever occur to you" that you make your employer look even more awful?

Isn't making accusations of theft and industrial espionage is unpleasant? This kind of accusation in the industry crops up time and time again and I don't think it should be accepted unchallenged, neither between small companies, or large ones. I've seen this claims so many times, people claiming some investors took their deck and gave it to their portfolio companies, people claiming another company copied them. The…

Are you saying I was not pursued/invited and met with Motorola ATAP(Google had bought them in Jan 2013) now Google ATAP in April 2013? I am making this up?

I made up this NDA I signed https://ryanspahn.com/motorola-google-Expired-NDA2013.pdf and this letter when Google absorbed ATAP https://ryanspahn.com/google.JPG .

Ive got emails from the jerk who invited us out there .. who baited us then said here is the door and by the way the race is on..goodbye.

I met with many others too ..like Samsung and that guy was an upstanding gentleman. Google was awful... treated us like dogs!

I have no reason to lie only to tell my story to warn others and highlight that Google no longer follows it's motto "Don't be evil."

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#220

Earlier quoted context omitted.

Does anyone else get rubbed the wrong way by this sort of irreverent infringement? Even if you have zero concern for journalists’ copyrights, it puts this forum at risk.

Websites like WSJ manage to get listed high in the Google rankings by presenting the actual article, instead of a paywall, to the Googlebot and to requests with Google in the Referer field (as I understand it). I gather that they do the same thing to the Archive scraper. As far as I'm concerned, that's a cheap trick the website performs, and using a cheap trick to get around it seems fine to me.

[deleted]
Post reply on HN