Earlier quoted context omitted.
Maybe even three stories; there's another bit in that Google blog post about Google making their API permission prompts for Gmail, Drive, Calendar, and contacts more fine-grained and locking them down with policy measures.
This is extremely problematic for us. We're bootstrapped and now Google is suddenly asking for up to $75,000 (or more) for a security audit. This despite the fact that we've been publicly asking for more limited OAuth scopes for years (c.f. my HN posting history and my tickets on the Google issue tracker), and the fact that we've had zero security incidents in over three years. All to ensure that we're not risking ex…
Google Exposed User Data, Feared Repercussions of Disclosing to Public
251–260 of 277 posts
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#252Earlier quoted context omitted.
For some reason, this only happens with Cloudflare DNS. I had to revert to Google because all archive.is links didn’t work.
Jeez, just run your own resolver instead of dumping all your internet access data on $AntiPrivacyCo.'s reception desk.
"We delete [the] temporary logs [which include your full IP address to identify things like DDoS attacks and debug problems] within 24 to 48 hours."
"In the permanent logs, we don't keep personally identifiable information or IP information. After keeping [the data we do keep] for two weeks, we randomly sample a small subset for permanent storage."
And importantly:
"We don't correlate or combine information from our temporary or permanent logs with any personal information that you have provided Google for other services."
Source: https://developers.google.com/speed/public-dns/privacy
Unless you think they're lying or unable to enforce this policy, this addresses most of the common privacy concerns I've heard in this context.
(I have worked for Google in the past, but I have never been involved at all with Google Public DNS or its privacy promises.)
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#253Nowadays I tend to trust a company that had a security vulnerability or data breach once and handled it gracefully, rather than a company that says they had no security breach. Making a mistake is only human; Your true test is what you do after you found it.
This! It's not about the mistake that led to the breach. It's about what you do once you become aware of it as a company, as a team, and as an individual. I am quite confused about how poor this has been handled by Facebook recently and now Google follows suit.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#254Yes they should have announced it no matter what the logs said. Depending on the logs is the worst idea ever in terms of breach determination. I don’t know how many times we’ve had 40 IoCs, but just because there isn’t a log file (often because no one splurged for the SIEM and the syslog collector broke beyond repair months ago) management acts like they’ve won the legal liability / cyber security lottery. Obviously…
Microsoft sends out monthly security patches. Each fix is in there is fixing a vulnerability. Every Windows server has multiple vulnerabilities fixed every month. Is every company that uses Windows now required to determine if any of those vulnerabilities were actually used? This seems like a bottomless hole.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#255Earlier quoted context omitted.
This is extremely problematic for us. We're bootstrapped and now Google is suddenly asking for up to $75,000 (or more) for a security audit. This despite the fact that we've been publicly asking for more limited OAuth scopes for years (c.f. my HN posting history and my tickets on the Google issue tracker), and the fact that we've had zero security incidents in over three years. All to ensure that we're not risking ex…
Does this limit things like Zapier integrations as well? Surely they can't confirm the end security of every usage?
If attachments are going from Gmail to Google Docs then they're probably fine, I'd imagine one audit could cover all those types of apps. For things that send email to Slack or whatever I'd expect that Slack would need to pay to have that audited.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#256This is the data that could potentially have been exposed for each person [1]. In their release about shutting down Google+ they made it seem like a lot less. [1] https://developers.google.com/+/web/api/rest/latest/people
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#257Earlier quoted context omitted.
Are you saying I was not pursued/invited and met with Motorola ATAP(Google had bought them in Jan 2013) now Google ATAP in April 2013? I am making this up? I made up this NDA I signed https://ryanspahn.com/motorola-google-Expired-NDA2013.pdf and this letter when Google absorbed ATAP https://ryanspahn.com/google.JPG . Ive got emails from the jerk who invited us out there .. who baited us then said here is the door and…
I don't think you're making it up, it sounds like you had a bad experience, and someone from Motorola biz-dev/m&a was being a jerk, but without knowing how the interaction went, it's not really my place to pass judgement. In a company of 88,000 employees, there's a non-zero probability of getting a bad interviewer. I'm sorry to hear you had that experience. Where I part company is the added interpretation. If I was i…
Indeed we have not given up and the recent news that Google was awarded patents for SpeakerBlast type technology has lit a fire under us even more.
Well I'd enjoy learning what you do at Google. Are you on the Chrome Audio team ;-)
*Edit: weird your first post here was flagged.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#258So, I couldn't understand what "exposed" means in that article. Was any user's data obtained by someone not authorized to do so, or merely access to the data was possible?
Just possible. Similarly, the recent FB hack didn't actually penetrate 50 million accounts -- that was just an upper bound estimate based how many accounts were "exposed to the risk" of being compromised, probably because they were noted as being touched by the buggy "view as" function.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#259>We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug. Wait, so they only keep two weeks worth of logs and within these logs they did not find anyone abusing this flaw. How can they be certain for any time period from two week prior ?
The company which consider every single bit of data as "gold" decided not to keep their API's access log > 2 weeks? wow!
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#260Earlier quoted context omitted.
I too find Google only keeping 2 weeks of logs unbelievable.
The regulatory costs of GDPR mean that for every piece of log data, you want to think about whether or not you really want to keep it. If you don't have a good business case for keeping it, you're often better off erring on the side of deletion.
They had plenty of experience to suggest to them that keeping highly-detailed logs around indefinitely could do more harm to their users than good.