Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

261–270 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#261

Earlier quoted context omitted.

I don't think you're making it up, it sounds like you had a bad experience, and someone from Motorola biz-dev/m&a was being a jerk, but without knowing how the interaction went, it's not really my place to pass judgement. In a company of 88,000 employees, there's a non-zero probability of getting a bad interviewer. I'm sorry to hear you had that experience. Where I part company is the added interpretation. If I was i…

I agree ideas are a dime a dozen and are not patentable... syncing audio between devices on the same network or separate networks as an idea is not novel. It's all about the steps taken and if they are unique enough to be strong IP, as well you the inventor have access to capital for the patents and the right connections to truly make things happen. Stuff my friends and I are working on to better amidst daily life. A…

Well, I came to Google via an acquisition in 2010, I worked for years on the GWT (Google Web Toolkit) compiler, and related web compilation tooling. Then I switched to the Apps team (Inbox and Gmail) for a few years. Now I work in Research and Machine Intelligence.

I'm not on the Chrome audio team, but I have had experience with Chrome Audio, as I implemented an OpenAL layer for GwtQuake and the web version of Angry Birds for Chrome using it. See https://www.youtube.com/watch?v=F_sbusEUz5w for example PlayN, a cross-platform (Web, Android, iOS, Flash) library I worked on in 20% time, and https://www.youtube.com/watch?v=aW--Wlf9EFs which details some early experiments with image processing, and the porting of Quake to Chrome in 2010.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#262

Earlier quoted context omitted.

Does anyone else get rubbed the wrong way by this sort of irreverent infringement? Even if you have zero concern for journalists’ copyrights, it puts this forum at risk.

The other way of looking at it is that it can boost publication revenue and journalist income by driving more traffic to the publication than it would otherwise get, of which some may convert to subscriptions (if the publication can offer sufficient incentive). Obviously, no user would be able to justify buying subscriptions to every publication linked from HN. And if there was no paywall bypass, then HN couldn't lin…

  The other way of looking at it is that it can boost publication revenue... by driving more traffic
The same argument has been made in defense of software piracy for over a generation.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#263
post #105
post #98

>We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug. Wait, so they only keep two weeks worth of logs and within these logs they did not find anyone abusing this flaw. How can they be certain for any time period from two week prior ?

Wow. “We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks.” The wording of this is really pushing the boundary of plausibility. I fail to understand the logic of how this would protect privacy? Access logs with no profile data logged would not compromise privacy would it? Can anyone confirm the timing of the google blog post? It seems the WSJ article was posted at a similar…

  The wording of this is really pushing the boundary of plausibility.
Maybe Google is running short of disk space.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#264

Earlier quoted context omitted.

The other way of looking at it is that it can boost publication revenue and journalist income by driving more traffic to the publication than it would otherwise get, of which some may convert to subscriptions (if the publication can offer sufficient incentive). Obviously, no user would be able to justify buying subscriptions to every publication linked from HN. And if there was no paywall bypass, then HN couldn't lin…

The other way of looking at it is that it can boost publication revenue... by driving more traffic The same argument has been made in defense of software piracy for over a generation.

Which is why the freemium model evolved.

But we’re not talking about piracy here. If the publishers thought of it that way they’d block all access to archive sites.

Anyway, rather than a snarky dismissal like this, do you have a constructive suggestion for a solution that works well for everyone?

If the answer is “no paywalled sites on HN ever” please say so.

But if you have a more nuanced suggestion that would be a huge help!

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#265

I’m surprised Google’s own Project Zero did not caught this one.

When your purview is as wide as theirs, you can't catch every single vulnerability; I'm sure there are plenty of things in openssl, linux, etc. that they (or anyone else) haven't caught yet too :)

Yes but is it damn right that they should start in their own backyards.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#266

Earlier quoted context omitted.

I agree ideas are a dime a dozen and are not patentable... syncing audio between devices on the same network or separate networks as an idea is not novel. It's all about the steps taken and if they are unique enough to be strong IP, as well you the inventor have access to capital for the patents and the right connections to truly make things happen. Stuff my friends and I are working on to better amidst daily life. A…

Well, I came to Google via an acquisition in 2010, I worked for years on the GWT (Google Web Toolkit) compiler, and related web compilation tooling. Then I switched to the Apps team (Inbox and Gmail) for a few years. Now I work in Research and Machine Intelligence. I'm not on the Chrome audio team, but I have had experience with Chrome Audio, as I implemented an OpenAL layer for GwtQuake and the web version of Angry…

Thanks for sharing.

Looks like you lived in Maryland too at one time. I grew up in Towson(now in Bel Air in Harford County) and all my family is here. I’d move out there for a dream job; inventing/building/designing interesting tech for a FANNG company. The road to there looks to be thru an acquisition.

Well it was nice chatting with you!

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#267

A lot of the time I feel Google gets a bad rep on HN as the comments are so often filled with hyperbole. In this case however Google did a very poor job of disclosing this leak in their sunsetting Google+ announcement post. I would have much preferred an incident report explaining what really happened, even if they couldn't find any examples of abuse.

Conveniently for them, they only kept 2 weeks of logs (this is a 3 year old bug). I might implement that at my company. Take two weeks to patch and test the security hole, then review my two weeks of logs for any evidence of a breach. Then tell customers we haven't found any evidence of illicit access.

Not only that but does anyone actually believe they only kept two weeks of logs? I find it very suspect that the company known for amassing data only keeps some data for two weeks. How convienent for them.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#268

Earlier quoted context omitted.

Does this limit things like Zapier integrations as well? Surely they can't confirm the end security of every usage?

> Surely they can't confirm the end security of every usage? If attachments are going from Gmail to Google Docs then they're probably fine, I'd imagine one audit could cover all those types of apps. For things that send email to Slack or whatever I'd expect that Slack would need to pay to have that audited.

I used to work in a place where we had Trello boards, database integrations, and spreadsheets all triggering emails through Gmail (via Zapier) - it was startup-hacky, but it worked.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#269

non-paywall version: http://archive.is/rpuA1

Does anyone else get rubbed the wrong way by this sort of irreverent infringement? Even if you have zero concern for journalists’ copyrights, it puts this forum at risk.

Nope.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#270

Earlier quoted context omitted.

The other way of looking at it is that it can boost publication revenue and journalist income by driving more traffic to the publication than it would otherwise get, of which some may convert to subscriptions (if the publication can offer sufficient incentive). Obviously, no user would be able to justify buying subscriptions to every publication linked from HN. And if there was no paywall bypass, then HN couldn't lin…

The other way of looking at it is that it can boost publication revenue... by driving more traffic The same argument has been made in defense of software piracy for over a generation.

Pirates of all media types tend to also buy legal media far, far more than people who never pirate.
Post reply on HN