Live data from Hacker News

Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

zdnet.com

21–30 of 52 posts

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#21
post #19

Google admitted that they don't keep any logs around. So in the absence of logs, I am not sure how they are making the claim that their API was not abused. So there is definitely more transparency required about their internal investigation and how they are so certain. Just because Google has a great security team, I would not put my blind faith on them.

I don't believe they made that claim? They said they didn't have evidence that the API was abused.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#22
post #14
post #4

> Three Republican senators have sent a letter to Google today demanding the company hand over an internal memo based on which Google decided to cover up a Google+ data leak instead of going public as most companies do. That's a loaded first sentence. Here's another way of writing it: "Three Republican senators have sent a letter to Google today asking the company to please provide internal memo based on which Google…

> out yourself as biased garbage? Biased based on your opinion. I personally think this is a very big deal and I don't see anything wrong in that sentence. If you think Google is innocent, just look at the facts. 1) They had an internal memo discouraging public disclosure. 2) They only came clean with the leak after WSJ reached out for comment before the publication of a story. 3) They buried the "leak" announcement…

> I personally think this is a very big deal [...] Yeah, I'd say the article[...]'s tone is just about right.

That an article needs a "tone", and that it's right/wrong based on how big of a deal the reader thinks it is, is the issue. I await robot news that is a bulleted list of facts. We could argue about fact selection/placement, but I'll take that over arguing a particular organization's collective side of the bed they wake up on.

To your point, we disagree there wrt internal discussions of disclosure. What will be real scary is when there is a chilling effect to even performing rational discussion around these things. There is no such thing as disclose all, and when there is no such thing as talking about it either, you'll wish these rules were codified in law instead of applied selectively to issues you are ok with.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#23
post #3

I have never worked at any company that publishes every security bug discovered internally. This is ridiculous.

Depends on the industry. E.g. if you're working in defense or healthcare, then just the possibility of a data leak might be something you're obligated to report on. And a Google- or Facebook-size company might easily fall into the category where even "near miss" events should be disclosed. Basically you have to conduct an internal risk evaluation and depending on the overall risk assessment, you need or don't need to…

I have worked in healthcare related systems before that needs to be HIPAA compliant, even for those systems public disclosure of a vulnerability is not a requirement. No software is bug free, and many seemingly benign bugs are security vulnerabilities.

Try and name one company that reports all their bugs (security/non security) discovered internally.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#24
post #4

> Three Republican senators have sent a letter to Google today demanding the company hand over an internal memo based on which Google decided to cover up a Google+ data leak instead of going public as most companies do. That's a loaded first sentence. Here's another way of writing it: "Three Republican senators have sent a letter to Google today asking the company to please provide internal memo based on which Google…

Anyone want to take bets that those senators are using OS/email systems that have security vulnerabilities bugs that will be fixed (announced or not) over the next 12 months? Do they have sufficient logging/security that they will be able to demonstrate that their communications were not compromised?

I don't have confidence that their staff don't have direct access to their accounts, their passwords are remotely strong, or they have any real OpSec. Hopefully, they have been forced to use something resembling 2FA.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#25
post #14
post #4

> Three Republican senators have sent a letter to Google today demanding the company hand over an internal memo based on which Google decided to cover up a Google+ data leak instead of going public as most companies do. That's a loaded first sentence. Here's another way of writing it: "Three Republican senators have sent a letter to Google today asking the company to please provide internal memo based on which Google…

> out yourself as biased garbage? Biased based on your opinion. I personally think this is a very big deal and I don't see anything wrong in that sentence. If you think Google is innocent, just look at the facts. 1) They had an internal memo discouraging public disclosure. 2) They only came clean with the leak after WSJ reached out for comment before the publication of a story. 3) They buried the "leak" announcement…

>Biased based on your opinion...

All bias is based on opinion.

It's possible for everyone making a comment, including you and I, to be biased. In fact, in any political argument the chances that a commenter is unbiased are vanishingly small.

You have your bias. Kodablah has his/her own bias. There's nothing wrong with that. It certainly doesn't negate either of your arguments. Kodablah's point remains just as valid to consider.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#26
post #8

Earlier quoted context omitted.

Would you be surprised by legislation or insurance regulations that required such disclosures?

Yes. E.g. did you find a whiteboard facing an open window? Did leave a confidential document sitting on their desk? Did someone forget to close the filing cabinet to sensitive documents? Has anyone ever been able to access confidential information at your company without permission? Of course we can pick and choose analogies (hint: we'll never get it right, but that's what happens when comparisons are asked for). But…

None of those examples remotely resemble the G+ issues and subsequent shuttering.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#27
post #12

Earlier quoted context omitted.

Same. But the users whose data was emitted should have been immediately notified. That's (a) law in some places, (b) common decency if one party holds another's PII and then fails to keep it private.

> But the users whose data was emitted should have been immediately notified. If we’re still talking about the same bug… I thought that there was no evidence that anybody’s data was exfiltrated through this vulnerability? Granted, absence of evidence is not evidence of absence, but who, exactly, are you saying should be notified? I would say yes, if some person’s PII data was improperly disclosed, yes, disclose the b…

Google was able to finger a specific number of accounts that had data marked as private that may have been shared with third parties. The thing that makes this issue unique and interesting is that Google is claiming is that they deleted all the relevant logs, so they can't confirm whether the private information was indeed shared or not. This is a big problem since if this becomes a valid way of deferring responsibility or accountability, it creates a major incentive for companies to copy Google's claim here.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#28

Earlier quoted context omitted.

Depends on the industry. E.g. if you're working in defense or healthcare, then just the possibility of a data leak might be something you're obligated to report on. And a Google- or Facebook-size company might easily fall into the category where even "near miss" events should be disclosed. Basically you have to conduct an internal risk evaluation and depending on the overall risk assessment, you need or don't need to…

I have worked in healthcare related systems before that needs to be HIPAA compliant, even for those systems public disclosure of a vulnerability is not a requirement. No software is bug free, and many seemingly benign bugs are security vulnerabilities. Try and name one company that reports all their bugs (security/non security) discovered internally.

"all their bugs (security/non security) discovered internally"

No one. And no one is asking this of G+. Congratulations on this apparently successful straw man.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#30
post #14
post #4

> Three Republican senators have sent a letter to Google today demanding the company hand over an internal memo based on which Google decided to cover up a Google+ data leak instead of going public as most companies do. That's a loaded first sentence. Here's another way of writing it: "Three Republican senators have sent a letter to Google today asking the company to please provide internal memo based on which Google…

> out yourself as biased garbage? Biased based on your opinion. I personally think this is a very big deal and I don't see anything wrong in that sentence. If you think Google is innocent, just look at the facts. 1) They had an internal memo discouraging public disclosure. 2) They only came clean with the leak after WSJ reached out for comment before the publication of a story. 3) They buried the "leak" announcement…

There are two separate items, just in the first sentence quoted, that can reasonably be challenged as unfair.

First, there's no evidence to date that the vulnerability in question actually resulted in a data breach. This is distinct from there being actual, affirmative evidence supporting the idea that there was a breach. Here, I am using "vulnerability" to mean there was potential for exploitation and "breach" to mean an actual exploitation and exfiltration of data. I understand that some might opt regard this as a distinction without difference.

Second, it is not a common practice to make a loud media-friendly disclosure of every potentially-exploitable vulnerability. I've personally closed dozens of vulnerabilities, potentially exploitable vulnerabilities, in a variety of software packages for a variety of companies over the past decade. Of these, exactly one turned into a public notification of any sort. Hosted service companies in particular are unlikely to create what they would view as an undue media circus around bugs they find and fix internally.

With these items in mind, I submit that some people might find it reasonable that the phrasing of the article and the factual claims it makes might be at the very least unfair and potentially possessed of an opportunity to come into greater alignment with evidence-based reality.

Post reply on HN