Earlier quoted context omitted.
Does anyone else get rubbed the wrong way by this sort of irreverent infringement? Even if you have zero concern for journalists’ copyrights, it puts this forum at risk.
WSJ deserves zero respect.
Google Exposed User Data, Feared Repercussions of Disclosing to Public
241–250 of 277 posts
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#242>"A memo reviewed by the Journal prepared by Google’s legal and policy staff and shared with senior executives warned that disclosing the incident would likely trigger “immediate regulatory interest” and invite comparisons to Facebook’s leak of user information to data firm Cambridge Analytica."
>"The document shows Google officials felt that disclosure could have serious ramifications. Revealing the incident would likely result “in us coming into the spotlight alongside or even instead of Facebook despite having stayed under the radar throughout the Cambridge Analytica scandal,” the memo said. It “almost guarantees Sundar will testify before Congress.”"
>"Internal lawyers advised that Google wasn’t legally required to disclose the incident to the public, the people said. Because the company didn’t know what developers may have what data, the group also didn’t believe notifying users would give any actionable benefit to the end users, the people said."
These statements and tactics seem to be taken from the same playbook that Big Pharma, Big Tobacco or any other soulless Mega Corp uses. As long as it it's legal they don't care if it's right. Did their arrogance prevent them from entertaining the idea that disclosure would have provided users with the "actionable benefit" of considering whether or not they wanted to delete their Google accounts?
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#243Company finds a security vulnerability caused by a bug. Logs show that it has never been used by anyone. It patches the vulnerability. [Honest question] Should the company announce it publicly? PS: Keeping in mind that this is part of the Murdoch vs. Google war going on for about 10 years: https://www.npr.org/sections/money/2009/11/murdoch_vs_google... https://www.thedrum.com/news/2017/03/28/timing-everything-ru... h…
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#244non-paywall version: http://archive.is/rpuA1
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#245Nowadays I tend to trust a company that had a security vulnerability or data breach once and handled it gracefully, rather than a company that says they had no security breach. Making a mistake is only human; Your true test is what you do after you found it.
So is this an example of a company handling it gracefully? They couldn't tell what the impact was but kept it a secret for 6 months.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#246Earlier quoted context omitted.
I get a TLS problem: An error occurred during a connection to archive.is. Cannot communicate securely with peer: no common encryption algorithm(s). Error code: SSL_ERROR_NO_CYPHER_OVERLAP SSLLabs probably has the same problem: https://www.ssllabs.com/ssltest/analyze.html?d=archive.is
For some reason, this only happens with Cloudflare DNS. I had to revert to Google because all archive.is links didn’t work.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#247Earlier quoted context omitted.
Does anyone else get rubbed the wrong way by this sort of irreverent infringement? Even if you have zero concern for journalists’ copyrights, it puts this forum at risk.
While I think posting paywalled links is basically advertisements and I therefore have no problem with people posting accessible versions, I am curious about the same question. I think the question about the legality is legit and shouldn't be downvoted (unless I'm misinterpreting the guidelines). Not sure I'll like the answer and potential new rule, though.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#248Earlier quoted context omitted.
I get a TLS problem: An error occurred during a connection to archive.is. Cannot communicate securely with peer: no common encryption algorithm(s). Error code: SSL_ERROR_NO_CYPHER_OVERLAP SSLLabs probably has the same problem: https://www.ssllabs.com/ssltest/analyze.html?d=archive.is
For some reason, this only happens with Cloudflare DNS. I had to revert to Google because all archive.is links didn’t work.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#249Nowadays I tend to trust a company that had a security vulnerability or data breach once and handled it gracefully, rather than a company that says they had no security breach. Making a mistake is only human; Your true test is what you do after you found it.
It's not about the mistake that led to the breach. It's about what you do once you become aware of it as a company, as a team, and as an individual.
I am quite confused about how poor this has been handled by Facebook recently and now Google follows suit.
Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public
#250>We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug. Wait, so they only keep two weeks worth of logs and within these logs they did not find anyone abusing this flaw. How can they be certain for any time period from two week prior ?
Wow. “We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks.” The wording of this is really pushing the boundary of plausibility. I fail to understand the logic of how this would protect privacy? Access logs with no profile data logged would not compromise privacy would it? Can anyone confirm the timing of the google blog post? It seems the WSJ article was posted at a similar…
As far as GDPR goes technically this breach happened right before they would have faced large repercussions from it.