Live data from Hacker News

Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

zdnet.com

31–40 of 52 posts

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#31
post #14

Earlier quoted context omitted.

> out yourself as biased garbage? Biased based on your opinion. I personally think this is a very big deal and I don't see anything wrong in that sentence. If you think Google is innocent, just look at the facts. 1) They had an internal memo discouraging public disclosure. 2) They only came clean with the leak after WSJ reached out for comment before the publication of a story. 3) They buried the "leak" announcement…

> I personally think this is a very big deal [...] Yeah, I'd say the article[...]'s tone is just about right. That an article needs a "tone", and that it's right/wrong based on how big of a deal the reader thinks it is, is the issue. I await robot news that is a bulleted list of facts. We could argue about fact selection/placement, but I'll take that over arguing a particular organization's collective side of the bed…

>I await robot news that is a bulleted list of facts.

Interesting that you mention this, I'm not convinced that this will be a silver bullet. A couple of concerns that come to mind:

1. Something must bridge the robot to the physical world. The selection of which facts to include and exclude in this data source can create bias.

2. From the data source, the robot then would make its own decision about to to present facts, presumably performing some filtration of its own. Such a robot can have bias [0].

To be clear, I definitely agree that robojournalism could be an improvement. But we can't forget how it works and how it could be manipulated.

[0] - For example http://blog.conceptnet.io/posts/2017/how-to-make-a-racist-ai...

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#32
post #14

Earlier quoted context omitted.

> out yourself as biased garbage? Biased based on your opinion. I personally think this is a very big deal and I don't see anything wrong in that sentence. If you think Google is innocent, just look at the facts. 1) They had an internal memo discouraging public disclosure. 2) They only came clean with the leak after WSJ reached out for comment before the publication of a story. 3) They buried the "leak" announcement…

> I personally think this is a very big deal [...] Yeah, I'd say the article[...]'s tone is just about right. That an article needs a "tone", and that it's right/wrong based on how big of a deal the reader thinks it is, is the issue. I await robot news that is a bulleted list of facts. We could argue about fact selection/placement, but I'll take that over arguing a particular organization's collective side of the bed…

  I await robot news that is a bulleted list of facts.
I've got just the thing for you:

  cat news.txt | sed 's/\. /.\n * Reportedly, /'

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#33

Earlier quoted context omitted.

> But the users whose data was emitted should have been immediately notified. If we’re still talking about the same bug… I thought that there was no evidence that anybody’s data was exfiltrated through this vulnerability? Granted, absence of evidence is not evidence of absence, but who, exactly, are you saying should be notified? I would say yes, if some person’s PII data was improperly disclosed, yes, disclose the b…

Google was able to finger a specific number of accounts that had data marked as private that may have been shared with third parties. The thing that makes this issue unique and interesting is that Google is claiming is that they deleted all the relevant logs, so they can't confirm whether the private information was indeed shared or not. This is a big problem since if this becomes a valid way of deferring responsibil…

That doesn’t sound especially unique or interesting, I would expect API access logs to expire after a time and without more knowledge of the specifics, two weeks seems reasonable to me. I would assume that the logs themselves contain PII so increasing the retention has a risk, too. Speaking of retention, given GDPR I would expect the logs to be expired after some known amount of time just for regulatory compliance reasons.

If you go too hard towards forcing disclosures you get pathological incentives to not retain the logs in the first place, the same way people at large companies these days will keep some discussions out of email so they can’t get subpoenaed. That’s not an excuse for bad behavior, but if you force companies to retain more logs for audit purposes, and you force companies to have PII retention policies that limit the retention period, you can easily force a company into a position where the cheapest way out is to reduce the detail in the logs to the point where they’re not useful for security audits any more (if this has the primary purpose of PII retention compliance).

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#34
post #30
post #14

Earlier quoted context omitted.

> out yourself as biased garbage? Biased based on your opinion. I personally think this is a very big deal and I don't see anything wrong in that sentence. If you think Google is innocent, just look at the facts. 1) They had an internal memo discouraging public disclosure. 2) They only came clean with the leak after WSJ reached out for comment before the publication of a story. 3) They buried the "leak" announcement…

There are two separate items, just in the first sentence quoted, that can reasonably be challenged as unfair. First, there's no evidence to date that the vulnerability in question actually resulted in a data breach. This is distinct from there being actual, affirmative evidence supporting the idea that there was a breach. Here, I am using "vulnerability" to mean there was potential for exploitation and "breach" to me…

Your first point is actually the main problem here- according to Google's internal memo they didn't have the logging data to support a full investigation and have no way of knowing whether a breach occurred or not. If you find a vulnerability and there's no way to prove it hasn't been exploited then the responsible thing to do is treat it as if it had been.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#35
post #19

Google admitted that they don't keep any logs around. So in the absence of logs, I am not sure how they are making the claim that their API was not abused. So there is definitely more transparency required about their internal investigation and how they are so certain. Just because Google has a great security team, I would not put my blind faith on them.

I don't believe they made that claim? They said they didn't have evidence that the API was abused.

They said that they kept logs for only two weeks, because the logs themselves contained private information. Those logs contained no evidence of abuse.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#36
post #3

I have never worked at any company that publishes every security bug discovered internally. This is ridiculous.

Depends on the industry. E.g. if you're working in defense or healthcare, then just the possibility of a data leak might be something you're obligated to report on. And a Google- or Facebook-size company might easily fall into the category where even "near miss" events should be disclosed. Basically you have to conduct an internal risk evaluation and depending on the overall risk assessment, you need or don't need to…

I won't do work for the Federal government, but I've worked with companies of all sizes in healthcare, manufacturing, finance, and utilities, and at none of them was it a norm that internal vulnerabilities be disclosed publicly.

People keep saying that there are certain kinds of companies where you have to disclose, and I have come to the conclusion that they are simply making that up because it sounds good to them.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#37
post #34
post #30

Earlier quoted context omitted.

There are two separate items, just in the first sentence quoted, that can reasonably be challenged as unfair. First, there's no evidence to date that the vulnerability in question actually resulted in a data breach. This is distinct from there being actual, affirmative evidence supporting the idea that there was a breach. Here, I am using "vulnerability" to mean there was potential for exploitation and "breach" to me…

Your first point is actually the main problem here- according to Google's internal memo they didn't have the logging data to support a full investigation and have no way of knowing whether a breach occurred or not. If you find a vulnerability and there's no way to prove it hasn't been exploited then the responsible thing to do is treat it as if it had been.

You're absolutely right! That's very much the responsible thing to do for internal purposes.

That said, it might be slightly less than maximally honest for press outlets to claim that the one scenario is factually identical to the other to a public that is ill-equipped to appreciate the point you have so wisely made.

At this juncture, I think it's fair to say that Google's internal worries about public response were well-founded. They're being publicly crucified for going above and beyond the common standards of responsible behavior here.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#38
post #34
post #30

Earlier quoted context omitted.

There are two separate items, just in the first sentence quoted, that can reasonably be challenged as unfair. First, there's no evidence to date that the vulnerability in question actually resulted in a data breach. This is distinct from there being actual, affirmative evidence supporting the idea that there was a breach. Here, I am using "vulnerability" to mean there was potential for exploitation and "breach" to me…

Your first point is actually the main problem here- according to Google's internal memo they didn't have the logging data to support a full investigation and have no way of knowing whether a breach occurred or not. If you find a vulnerability and there's no way to prove it hasn't been exploited then the responsible thing to do is treat it as if it had been.

Rarely is it ever the case that you can conclusively rule out exploitation (ever) of a discovered vulnerability. Most of the time, companies don't even check; they fix the problem and get on with their lives. That Google even bothered to figure out the limits of what they could conclude about the vulnerability is already above the standard response in the industry.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#39
post #8

Earlier quoted context omitted.

Yes. E.g. did you find a whiteboard facing an open window? Did leave a confidential document sitting on their desk? Did someone forget to close the filing cabinet to sensitive documents? Has anyone ever been able to access confidential information at your company without permission? Of course we can pick and choose analogies (hint: we'll never get it right, but that's what happens when comparisons are asked for). But…

None of those examples remotely resemble the G+ issues and subsequent shuttering.

No, they don't: they're all more severe than what happened at G+ with this vulnerability. Vulnerabilities of the kind we're discussing are utterly routine, and would probably merit a sev:low in an external assessment.

Re: Senators Demand Google Hand Over Internal Memo Urging Google+ Cover-Up

#40
post #19

Google admitted that they don't keep any logs around. So in the absence of logs, I am not sure how they are making the claim that their API was not abused. So there is definitely more transparency required about their internal investigation and how they are so certain. Just because Google has a great security team, I would not put my blind faith on them.

>Google admitted that they don't keep any logs around.

They didn't say that, they stated that in the logs they had, which were not fully comprehensive, there was no evidence of abuse.

> am not sure how they are making the claim that their API was not abused.

They didn't claim this.

But one could, for example, set up a honeypot and monitor any suspicious activity going forward, then if anyone attempted to abuse the vulnerability before it was publicized, they would know it might have been abused, but lack of use over a long timescale could give reasonable certainty that no one took advantage of the vuln.

(I work at Google, but not on G+ and not on security).

Post reply on HN