Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

241–250 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#241
post #225

Earlier quoted context omitted.

Does anyone else get rubbed the wrong way by this sort of irreverent infringement? Even if you have zero concern for journalists’ copyrights, it puts this forum at risk.

WSJ deserves zero respect.

Then don't read their articles

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#242
I think the these three passages really sum up where Google's moral compass is these days:

>"A memo reviewed by the Journal prepared by Google’s legal and policy staff and shared with senior executives warned that disclosing the incident would likely trigger “immediate regulatory interest” and invite comparisons to Facebook’s leak of user information to data firm Cambridge Analytica."

>"The document shows Google officials felt that disclosure could have serious ramifications. Revealing the incident would likely result “in us coming into the spotlight alongside or even instead of Facebook despite having stayed under the radar throughout the Cambridge Analytica scandal,” the memo said. It “almost guarantees Sundar will testify before Congress.”"

>"Internal lawyers advised that Google wasn’t legally required to disclose the incident to the public, the people said. Because the company didn’t know what developers may have what data, the group also didn’t believe notifying users would give any actionable benefit to the end users, the people said."

These statements and tactics seem to be taken from the same playbook that Big Pharma, Big Tobacco or any other soulless Mega Corp uses. As long as it it's legal they don't care if it's right. Did their arrogance prevent them from entertaining the idea that disclosure would have provided users with the "actionable benefit" of considering whether or not they wanted to delete their Google accounts?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#243
post #4

Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…

What did Google do to piss off Murdoch? Fox News spends most nights railing on Google also.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#245
post #233
post #213

Nowadays I tend to trust a company that had a security vulnerability or data breach once and handled it gracefully, rather than a company that says they had no security breach. Making a mistake is only human; Your true test is what you do after you found it.

So is this an example of a company handling it gracefully? They couldn't tell what the impact was but kept it a secret for 6 months.

Pretty sure he is saying the opposite.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#246

Earlier quoted context omitted.

I get a TLS problem: An error occurred during a connection to archive.is. Cannot communicate securely with peer: no common encryption algorithm(s). Error code: SSL_ERROR_NO_CYPHER_OVERLAP SSLLabs probably has the same problem: https://www.ssllabs.com/ssltest/analyze.html?d=archive.is

For some reason, this only happens with Cloudflare DNS. I had to revert to Google because all archive.is links didn’t work.

Jeez, just run your own resolver instead of dumping all your internet access data on $AntiPrivacyCo.'s reception desk.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#247
post #221

Earlier quoted context omitted.

Does anyone else get rubbed the wrong way by this sort of irreverent infringement? Even if you have zero concern for journalists’ copyrights, it puts this forum at risk.

While I think posting paywalled links is basically advertisements and I therefore have no problem with people posting accessible versions, I am curious about the same question. I think the question about the legality is legit and shouldn't be downvoted (unless I'm misinterpreting the guidelines). Not sure I'll like the answer and potential new rule, though.

In the United States I imagine WSJ would have to send a DMCA takedown request to archive.is.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#248

Earlier quoted context omitted.

I get a TLS problem: An error occurred during a connection to archive.is. Cannot communicate securely with peer: no common encryption algorithm(s). Error code: SSL_ERROR_NO_CYPHER_OVERLAP SSLLabs probably has the same problem: https://www.ssllabs.com/ssltest/analyze.html?d=archive.is

For some reason, this only happens with Cloudflare DNS. I had to revert to Google because all archive.is links didn’t work.

That explains why I kept having these errors.. switched back to Quad9 and I'm good.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#249
post #213

Nowadays I tend to trust a company that had a security vulnerability or data breach once and handled it gracefully, rather than a company that says they had no security breach. Making a mistake is only human; Your true test is what you do after you found it.

This!

It's not about the mistake that led to the breach. It's about what you do once you become aware of it as a company, as a team, and as an individual.

I am quite confused about how poor this has been handled by Facebook recently and now Google follows suit.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#250
post #105
post #98

>We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug. Wait, so they only keep two weeks worth of logs and within these logs they did not find anyone abusing this flaw. How can they be certain for any time period from two week prior ?

Wow. “We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks.” The wording of this is really pushing the boundary of plausibility. I fail to understand the logic of how this would protect privacy? Access logs with no profile data logged would not compromise privacy would it? Can anyone confirm the timing of the google blog post? It seems the WSJ article was posted at a similar…

>Goog is trying to avoid using the words Data breach as they may get into hot water in EU.

As far as GDPR goes technically this breach happened right before they would have faced large repercussions from it.

Post reply on HN