Live data from Hacker News

Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

zdnet.com

41–50 of 52 posts

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#41
post #12
post #3

I have never worked at any company that publishes every security bug discovered internally. This is ridiculous.

Same. But the users whose data was emitted should have been immediately notified. That's (a) law in some places, (b) common decency if one party holds another's PII and then fails to keep it private.

You're right! There are laws in some places requiring notification in the event of a breach. California has one of these, and some provisions of GDPR are similar.

With that said, I don't think any of these require notification in the event of the abstract possibility, unsupported by any evidence, of a data breach. This is because there is a substantial difference between data that was emitted (factually sent somewhere) and exposed (could have been sent somewhere), and laws tend to trigger on the former.

If you're aware of relevant laws I have missed, I would love to know!

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#42
post #38
post #34

Earlier quoted context omitted.

Your first point is actually the main problem here- according to Google's internal memo they didn't have the logging data to support a full investigation and have no way of knowing whether a breach occurred or not. If you find a vulnerability and there's no way to prove it hasn't been exploited then the responsible thing to do is treat it as if it had been.

Rarely is it ever the case that you can conclusively rule out exploitation ( ever ) of a discovered vulnerability. Most of the time, companies don't even check; they fix the problem and get on with their lives. That Google even bothered to figure out the limits of what they could conclude about the vulnerability is already above the standard response in the industry.

How do you feel about the log retention period?

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#43
post #3

I have never worked at any company that publishes every security bug discovered internally. This is ridiculous.

It's disappointing to see people defending Google on this.

Whether the vulnerability was discovered internally or not, they were leaking people's data, and the responsible thing to do is tell them. Even if it's only a possibility, people have the right to know.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#44
post #38

Earlier quoted context omitted.

Rarely is it ever the case that you can conclusively rule out exploitation ( ever ) of a discovered vulnerability. Most of the time, companies don't even check; they fix the problem and get on with their lives. That Google even bothered to figure out the limits of what they could conclude about the vulnerability is already above the standard response in the industry.

How do you feel about the log retention period?

I don't care about the log retention period. My assumption is that Google does a better job of real-time log monitoring than most other tech firms, and that they are between a rock and a hard place with respect to retention owing to privacy concerns. Either way: it's simply not a real-world norm to conduct a forensics investigation after the internal discovery a vulnerability, so any work they did in that regard easily clears the industry bar.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#46
post #3

I have never worked at any company that publishes every security bug discovered internally. This is ridiculous.

Depends on the industry. E.g. if you're working in defense or healthcare, then just the possibility of a data leak might be something you're obligated to report on. And a Google- or Facebook-size company might easily fall into the category where even "near miss" events should be disclosed. Basically you have to conduct an internal risk evaluation and depending on the overall risk assessment, you need or don't need to…

With respect to just the possibility of a data leak might be something you're obligated to report on, I haven't heard of this being a real requirement. I would be curious to see links or evidence to the contrary.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#47
post #3

I have never worked at any company that publishes every security bug discovered internally. This is ridiculous.

It's disappointing to see people defending Google on this. Whether the vulnerability was discovered internally or not, they were leaking people's data, and the responsible thing to do is tell them. Even if it's only a possibility, people have the right to know.

There is no evidence that they were leaking people's data.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#48
post #47

Earlier quoted context omitted.

It's disappointing to see people defending Google on this. Whether the vulnerability was discovered internally or not, they were leaking people's data, and the responsible thing to do is tell them. Even if it's only a possibility, people have the right to know.

There is no evidence that they were leaking people's data .

I don't think that's up for debate. Both the WSJ and Google's own engineers came to the conclusion that they were. If the data wasn't leaking there wouldn't be anything for Google to cover up in their memo.

The only question left is who was affected, and Google doesn't know because they deleted the logs. The responsible thing to do would be notify everybody using that part of the service.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#49
post #47

Earlier quoted context omitted.

There is no evidence that they were leaking people's data .

I don't think that's up for debate. Both the WSJ and Google's own engineers came to the conclusion that they were. If the data wasn't leaking there wouldn't be anything for Google to cover up in their memo. The only question left is who was affected, and Google doesn't know because they deleted the logs. The responsible thing to do would be notify everybody using that part of the service.

I agree that it is not up for debate. They did not lose any information. The google announcement here https://www.blog.google/technology/safety-security/project-s... says that they looked for leakages and We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any Profile data was misused.

The difference is between data being exposed and data being leaked. The difference is quite critical.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#50

Earlier quoted context omitted.

Google was able to finger a specific number of accounts that had data marked as private that may have been shared with third parties. The thing that makes this issue unique and interesting is that Google is claiming is that they deleted all the relevant logs, so they can't confirm whether the private information was indeed shared or not. This is a big problem since if this becomes a valid way of deferring responsibil…

That doesn’t sound especially unique or interesting, I would expect API access logs to expire after a time and without more knowledge of the specifics, two weeks seems reasonable to me. I would assume that the logs themselves contain PII so increasing the retention has a risk, too. Speaking of retention, given GDPR I would expect the logs to be expired after some known amount of time just for regulatory compliance re…

Logs with personal information anonymized are still just as useful for security and other system audits. You would be able to clearly see unauthorized access of A from B, even if A and B could no longer be identified.

And you're ignoring the biggest risk here. If this defense of claiming 'we see there was a trivially exploited issue to allow unauthorized access to data users had marked as private, but we threw away all logs so we can't be expected to see if it was exploited, or be held to any level of accountability' passes for acceptable, it's going to set a far worse precedent than any sort of legal action. Get hacked? Worried about regulatory requirements? No problem, just migrate to a two week cycle of completely deleting all logs, patch it, and stall for 2 weeks. There, you can now hoenstly say you have 'no evidence this attack ever happened.'

Post reply on HN