Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

251–260 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#251
post #97

Earlier quoted context omitted.

Maybe even three stories; there's another bit in that Google blog post about Google making their API permission prompts for Gmail, Drive, Calendar, and contacts more fine-grained and locking them down with policy measures.

This is extremely problematic for us. We're bootstrapped and now Google is suddenly asking for up to $75,000 (or more) for a security audit. This despite the fact that we've been publicly asking for more limited OAuth scopes for years (c.f. my HN posting history and my tickets on the Google issue tracker), and the fact that we've had zero security incidents in over three years. All to ensure that we're not risking ex…

Does this limit things like Zapier integrations as well? Surely they can't confirm the end security of every usage?

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#252

Earlier quoted context omitted.

For some reason, this only happens with Cloudflare DNS. I had to revert to Google because all archive.is links didn’t work.

Jeez, just run your own resolver instead of dumping all your internet access data on $AntiPrivacyCo.'s reception desk.

They anticipated this reaction and have made some significant privacy promises about the data they receive via Google Public DNS:

"We delete [the] temporary logs [which include your full IP address to identify things like DDoS attacks and debug problems] within 24 to 48 hours."

"In the permanent logs, we don't keep personally identifiable information or IP information. After keeping [the data we do keep] for two weeks, we randomly sample a small subset for permanent storage."

And importantly:

"We don't correlate or combine information from our temporary or permanent logs with any personal information that you have provided Google for other services."

Source: https://developers.google.com/speed/public-dns/privacy

Unless you think they're lying or unable to enforce this policy, this addresses most of the common privacy concerns I've heard in this context.

(I have worked for Google in the past, but I have never been involved at all with Google Public DNS or its privacy promises.)

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#253
post #213

Nowadays I tend to trust a company that had a security vulnerability or data breach once and handled it gracefully, rather than a company that says they had no security breach. Making a mistake is only human; Your true test is what you do after you found it.

This! It's not about the mistake that led to the breach. It's about what you do once you become aware of it as a company, as a team, and as an individual. I am quite confused about how poor this has been handled by Facebook recently and now Google follows suit.

I agree. I think it is more important when a company is forthright about a breach quickly than the history of breaches. Both Sony and Equifax had large security breaches prior to the large hacks.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#254

Yes they should have announced it no matter what the logs said. Depending on the logs is the worst idea ever in terms of breach determination. I don’t know how many times we’ve had 40 IoCs, but just because there isn’t a log file (often because no one splurged for the SIEM and the syslog collector broke beyond repair months ago) management acts like they’ve won the legal liability / cyber security lottery. Obviously…

Wait, was this a vulnerability or a breach? Because if every vulnerability is now a breach, there are millions more than we know about.

Microsoft sends out monthly security patches. Each fix is in there is fixing a vulnerability. Every Windows server has multiple vulnerabilities fixed every month. Is every company that uses Windows now required to determine if any of those vulnerabilities were actually used? This seems like a bottomless hole.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#255

Earlier quoted context omitted.

This is extremely problematic for us. We're bootstrapped and now Google is suddenly asking for up to $75,000 (or more) for a security audit. This despite the fact that we've been publicly asking for more limited OAuth scopes for years (c.f. my HN posting history and my tickets on the Google issue tracker), and the fact that we've had zero security incidents in over three years. All to ensure that we're not risking ex…

Does this limit things like Zapier integrations as well? Surely they can't confirm the end security of every usage?

> Surely they can't confirm the end security of every usage?

If attachments are going from Gmail to Google Docs then they're probably fine, I'd imagine one audit could cover all those types of apps. For things that send email to Slack or whatever I'd expect that Slack would need to pay to have that audited.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#256

This is the data that could potentially have been exposed for each person [1]. In their release about shutting down Google+ they made it seem like a lot less. [1] https://developers.google.com/+/web/api/rest/latest/people

Thanks for this. I hadn't been able to track down a clear statement of what was exposed, which is an awfully important question in a case like this. It's frustrating that "someone on HN dug up the API" is the most reliable way to get information like this, and speaks ill of how this was handled even after it was disclosed.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#257

Earlier quoted context omitted.

Are you saying I was not pursued/invited and met with Motorola ATAP(Google had bought them in Jan 2013) now Google ATAP in April 2013? I am making this up? I made up this NDA I signed https://ryanspahn.com/motorola-google-Expired-NDA2013.pdf and this letter when Google absorbed ATAP https://ryanspahn.com/google.JPG . Ive got emails from the jerk who invited us out there .. who baited us then said here is the door and…

I don't think you're making it up, it sounds like you had a bad experience, and someone from Motorola biz-dev/m&a was being a jerk, but without knowing how the interaction went, it's not really my place to pass judgement. In a company of 88,000 employees, there's a non-zero probability of getting a bad interviewer. I'm sorry to hear you had that experience. Where I part company is the added interpretation. If I was i…

I agree ideas are a dime a dozen and are not patentable... syncing audio between devices on the same network or separate networks as an idea is not novel. It's all about the steps taken and if they are unique enough to be strong IP, as well you the inventor have access to capital for the patents and the right connections to truly make things happen. Stuff my friends and I are working on to better amidst daily life. Access to capital & more importantly those who can help here in Baltimore for audio syncing technology isn't easy to come by. Though more importantly we have reached out to those in our network who have sold companies yet none have had any experience in making deals with Google, Samsung and others(what strategy to use when all just want to know your algorithmic steps & if they are unique). It's been a crap-shoot for us and our meeting with Google was a learning experience, but a very unnecessary harsh one and worse compared to meetings with others like Samsung; all very professional and respectful!

Indeed we have not given up and the recent news that Google was awarded patents for SpeakerBlast type technology has lit a fire under us even more.

Well I'd enjoy learning what you do at Google. Are you on the Chrome Audio team ;-)

*Edit: weird your first post here was flagged.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#258
post #180

So, I couldn't understand what "exposed" means in that article. Was any user's data obtained by someone not authorized to do so, or merely access to the data was possible?

Just possible. Similarly, the recent FB hack didn't actually penetrate 50 million accounts -- that was just an upper bound estimate based how many accounts were "exposed to the risk" of being compromised, probably because they were noted as being touched by the buggy "view as" function.

Update: It looks like on October 2nd, Facebook clarified that 50 million users actually had their login credentials stolen, and an additional 40 million were unconfirmed but known to have been touched by the buggy "view as" feature:

https://newsroom.fb.com/news/2018/10/facebook-login-update/

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#259
post #116
post #98

>We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug. Wait, so they only keep two weeks worth of logs and within these logs they did not find anyone abusing this flaw. How can they be certain for any time period from two week prior ?

The company which consider every single bit of data as "gold" decided not to keep their API's access log > 2 weeks? wow!

Such policy existed since the very beginning of Google APIs, and is well documented within the company. Anyone who worked at Google should be aware of it.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#260
post #140

Earlier quoted context omitted.

I too find Google only keeping 2 weeks of logs unbelievable.

The regulatory costs of GDPR mean that for every piece of log data, you want to think about whether or not you really want to keep it. If you don't have a good business case for keeping it, you're often better off erring on the side of deletion.

Even before the GDPR, Google had to contend with the NSA / GCHQ illicit access events and the China hack.

They had plenty of experience to suggest to them that keeping highly-detailed logs around indefinitely could do more harm to their users than good.

Post reply on HN