Earlier quoted context omitted.
Would you be surprised by legislation or insurance regulations that required such disclosures?
Yes. E.g. did you find a whiteboard facing an open window? Did leave a confidential document sitting on their desk? Did someone forget to close the filing cabinet to sensitive documents? Has anyone ever been able to access confidential information at your company without permission? Of course we can pick and choose analogies (hint: we'll never get it right, but that's what happens when comparisons are asked for). But…
Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up
11–20 of 52 posts
Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up
#12I have never worked at any company that publishes every security bug discovered internally. This is ridiculous.
But the users whose data was emitted should have been immediately notified. That's (a) law in some places, (b) common decency if one party holds another's PII and then fails to keep it private.
Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up
#13Earlier quoted context omitted.
I have found over and over and over that when I read "memos" or "screeds" or whathaveyou coming from the tech industry I inevitably find that a huge portion of the media is pushing a narrative that is so uniform and so disjoint from the actual content I have a hard time imagining how it wasn't coordinated journo-pros-style.
James Damore?
Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up
#14> Three Republican senators have sent a letter to Google today demanding the company hand over an internal memo based on which Google decided to cover up a Google+ data leak instead of going public as most companies do. That's a loaded first sentence. Here's another way of writing it: "Three Republican senators have sent a letter to Google today asking the company to please provide internal memo based on which Google…
Biased based on your opinion.
I personally think this is a very big deal and I don't see anything wrong in that sentence. If you think Google is innocent, just look at the facts.
1) They had an internal memo discouraging public disclosure. 2) They only came clean with the leak after WSJ reached out for comment before the publication of a story. 3) They buried the "leak" announcement in a gigantic blog post. The blog post was meant to announce a new project, but about halfway through the middle they disclosed a data-leaking bug. I'd say the tone of the article is in response to Google's observed and recorded actions.
Yeah, I'd say the article and letter's tone is just about right.
Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up
#15> Three Republican senators have sent a letter to Google today demanding the company hand over an internal memo based on which Google decided to cover up a Google+ data leak instead of going public as most companies do. That's a loaded first sentence. Here's another way of writing it: "Three Republican senators have sent a letter to Google today asking the company to please provide internal memo based on which Google…
Any other topic or company: the wording or journalistic techniques are an unimportant aside, if they get mentioned at all.
Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up
#16Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up
#17I have never worked at any company that publishes every security bug discovered internally. This is ridiculous.
Same. But the users whose data was emitted should have been immediately notified. That's (a) law in some places, (b) common decency if one party holds another's PII and then fails to keep it private.
If we’re still talking about the same bug… I thought that there was no evidence that anybody’s data was exfiltrated through this vulnerability? Granted, absence of evidence is not evidence of absence, but who, exactly, are you saying should be notified?
I would say yes, if some person’s PII data was improperly disclosed, yes, disclose the breach to that person. But if there is not any evidence that some particular person’s data was exposed here, do you go around telling people that their data “could have” been accessed, “if”?
Physical security analogy—let’s say I found out that the window was unlocked. It’s been unlocked for three years, and I pull security tapes. Nobody is on tape coming in through the window, but the old tapes have been erased. I don’t have any evidence that anybody came in through the window, and yet I can’t disprove it either.
Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up
#18I have never worked at any company that publishes every security bug discovered internally. This is ridiculous.
Basically you have to conduct an internal risk evaluation and depending on the overall risk assessment, you need or don't need to publicly report on it. Of course the bar is much lower than 'certain data leak'.
Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up
#19Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up
#20> Three Republican senators have sent a letter to Google today demanding the company hand over an internal memo based on which Google decided to cover up a Google+ data leak instead of going public as most companies do. That's a loaded first sentence. Here's another way of writing it: "Three Republican senators have sent a letter to Google today asking the company to please provide internal memo based on which Google…
It's funny how picky and particular HN gets over the wording or sources whenever the story is about Google. In nearly every article you see comments like this upvoted to the top within 10 minutes of posting. Any other topic or company: the wording or journalistic techniques are an unimportant aside, if they get mentioned at all.