Live data from Hacker News

Google Calendar Unexpectedly Leaks Private Information

shkspr.mobi

41–50 of 138 posts

Re: Google Calendar Unexpectedly Leaks Private Information

#42
post #15

Earlier quoted context omitted.

It's mine, I just signed up to join the discussion, but evidently new users get rate-limited to only a few comments, so I've incremented the username by 1 to indicate it's still me.

Since you've been busily doing PR for Google lately, I assume you're paid for it. Care to be honest about it?

No I'm not paid by anyone, can't I just have a different opinion that yours with it being paid PR work?!

Re: Google Calendar Unexpectedly Leaks Private Information

#43
post #18
post #10

Earlier quoted context omitted.

It's evidently not 'expected' behaviour from the point of view of the user. Just because you happen to put an email address in the title of a calendar event doesn't imply that I expect the software to go and send messages on my behalf.

Then we disagree. Especially if it's in the title it indicates you want to coordinate with the email you just entered. A proper way to do it is, Title: "Email Alice", Description: "alice@example.com".

When the user gets unexpected behaviour doing something that many believe to be reasonable, telling them they're doing it wrong is really bad user interaction.

You can't change the behaviour of users, but you can make your software easier to use and more predictable in its behaviour.

Re: Google Calendar Unexpectedly Leaks Private Information

#44

Privacy, where it exists, creates impedance in Google's cash flow because it requires designing for some n sigma tail where n does not entail statistical significance and the case analysis must be very fine grained. Google doesn't have a category labeled "private" information". It never has and creating one is not planned. Privacy is not amenable to computer science. It is a social concept not a technical one. The cl…

Generally speaking you might be right, but I fail to see the profit motive behind this specific case. It's just a UX disagreement it seems.

Re: Google Calendar Unexpectedly Leaks Private Information

#45
post #20

Earlier quoted context omitted.

If you're aware of the feature, it's not a privacy leak. If you aren't, it could be very damaging. It would have been nice if the first time the Calendar parsed and sent emails on behalf of a user, it would ask if this is what they wanted. It doesn't have to bug them ever again, but that's a single instance of training that would minimize confusion.

https://support.google.com/calendar/answer/36604

Except that says: 'Who: This should begin with 'with' followed by a list of email addresses; these are added to the guest list.'

'Email alice@example.com' does not match this spec.

Re: Google Calendar Unexpectedly Leaks Private Information

#46
post #34

This article has pretty much the same content as my article from March, 2010: http://lee-phillips.org/gcaldisaster/ Even the titles are similar: this one's called "Another Google Privacy Flaw"; mine was called "Another Google Privacy Disaster Brewing". So people have been complaining about this since at least 2010, and Google by now has pretty firmly established that they don't care.

Hi Lee, Although I did search for information about this issue, I didn't come across your blog. I'll update mine with a link to yours. T

No worries - I didn't mean to imply that you copied me, but just to point out persistent this problem has been, and to underline the fact that Google doesn't consider it an issue.

Re: Google Calendar Unexpectedly Leaks Private Information

#47
post #27
post #11

Earlier quoted context omitted.

well, you had a problem with a badly written wordpress plugin ,not PHP. or are you saying PHP is insecure and no insecure code can be written in other plateforms ? for a project to be popular amongs developers and hobbyists , it has to be written in PHP, because PHP is easy to deploy even if you dont know PHP. By the way, most CMSes on other plateforms assume you know the language , PHP CMSes dont, so maybe there is…

> you had a problem with a badly written wordpress plugin The plugin is top 10 popular one > because PHP is easy to deploy even if you dont know PHP. Wordpress has clean URL, but under the hood many .php files are directly accessible via URL, so hacker found a exploit, crafted a parameter aginst one particular .php, and got in. The solution? Limit URL entry to only one .php file (like index.php), more rewrite configs…

* > > you had a problem with a badly written wordpress plugin > The plugin is top 10 popular one*

Popular !== Good (where in this case good is in the context of being well written)

> so hacker found a exploit, crafted a parameter aginst one particular .php, and got in

That could happen with almost any laguage/framework though. While PHP makes it easy to write bad code (as do other options) it doesn't make it impossible to write secure code and you can't blame PHP and/or Wordpress for every bad plugin out there, even the massively popular ones.

Re: Google Calendar Unexpectedly Leaks Private Information

#48
post #42

Earlier quoted context omitted.

Since you've been busily doing PR for Google lately, I assume you're paid for it. Care to be honest about it?

No I'm not paid by anyone, can't I just have a different opinion that yours with it being paid PR work?!

Your persistence, repeating the same point, and use of multiple accounts suggest otherwise.

Re: Google Calendar Unexpectedly Leaks Private Information

#49
post #5
post #2

Btw. ownCloud 6.0.1 was released yesterday: http://owncloud.org/releases/Changelog

God I love the idea of ownCloud so much but secretly hope it's not written in PHP. I run a wordpress site for 3 years, and one day a hacker took my site over with a bug from a plugin.

I hate PHP as a language, I really do, but bugs can happen in any language (eg C++ bugs are exploited all the time to gain machine access). Plus when you get a platform as popular as Wordpress, you'll find that it will constantly be under attack from 'hackers' who bank on people being slow to update their plugins.

With regards to ownCloud, that is PHP by the way.

Re: Google Calendar Unexpectedly Leaks Private Information

#50
post #4

A couple of things: That is expected behaviour, email address in reminders applies coordination. It's basically parsing your command correctly 'email this address'. Second, the zdnet post you link to towards the end is full of inaccuracies: https://news.ycombinator.com/item?id=7107554

Read this guy's history (and the same usernames with lower numbers on the end (edit: ...and now he's onto 4)) for some comedy. Google employee, or rabid google fan? I can't decide.

I would guess rabid fan, or maybe Google employee off the meter, who's about to get in trouble. Google's HN gardening is rather more sophisticated than this, but it does leave signals.
Post reply on HN