5 ms·
Looks like they took it down for everyone [0]; maybe not the most elegant approach but at least it seems they're taking it more serious now. [0]: https://stack
by pred_ 8y ago
Looks like they took it down for everyone [0]; maybe not the most elegant approach but at least it seems they're taking it more serious now.
[0]: https://stackoverflow.com/questions/50289065/google-yolo-stop-working-the-client-origin-is-not-permitted-to-use-this-api https://stackoverflow.com/questions/50289065/google-yolo-sto...
- jacquesm 8y agoIt would be very interesting to see a split second exact timeline on this.
- pred_ 8y agoIndeed. A Google engineer stated on Twitter [0] that the shutdown of the service happened because apparently YOLO is only supposed to be accessible to whitelisted partners. [0]: https://twitter.com/sirdarckcat/status/994867632355577862 https://twitter.com/sirdarckcat/status/994867632355577862
- jacquesm 8y agoSo, whitelisted partners get the ability to rip your data? I'm sure that will go down just fine. FB just got into a lot of trouble over something like that (arguably a lot more serious, but still).
- pred_ 8y agoThey also state in the same Twitter thread that they were aware of the issue before the blog post was written. IANAL but even if the shutdown was intentional (as opposed to being the example of terrible damage control it looks like), willfully leaving a bug in production that allows a set of whitelisted partners to deanonymize their visitors without their consent seems like something that shouldn't fly in countries with data protection laws?
- jacquesm 8y agoI just received a message back on Twitter saying that the whitelist wasn't the fix and they are still making more changes. This is seriously denting my continued belief in Google's security chops. I know they have some of the finest security researchers on the planet but this was handled in a ham-fisted and ineffective way so far. And best of all: without 'partner' status you won't be able to check if has been fixed.
- pathseeker 8y ago>This is seriously denting my continued belief in Google's security chops. I know they have some of the finest security researchers on the planet but this was handled in a ham-fisted and ineffective way so far. This is a great demonstration how a company can have all of the right talent but still manage to become incompetent through poor organizational policies.
- sharcerer 8y agoLets hope it doesn't happen again.
- NightlyDev 8y agoJust wait a couple of weeks until GDPR takes effect
- true_religion 8y agoIt would be fine if they only gave whitelist access to people who could already simply access your data by request. But GDPR would only require that they know who could access, and that the access list be less than "the entire world".