5 ms·
Sadly the strategy is working. not seeing much mention of breach on HN
by oculusthrift 8y ago
Sadly the strategy is working. not seeing much mention of breach on HN
- lucb1e 8y agoI must have skimmed over it in the article, I only know because it's in the comments. That should have been the headline, imo. Own up to it like other vendors do. I thought Google was good with security, this is a good way to get one of the few positive points about this monolith changed.
- jacquesm 8y agoNice they spent so much time on keeping Microsoft honest. Would have been better if they aimed their sights on their own products a bit longer.
- staticassertion 8y agoWhen did "there was a vulnerability" become "there was a breach" ? I don't understand why it's being reported as a breach.
- gandutraveler 8y agoGoogle's official statement also doesn't rule out the possibility of a breach. I think the bigger issue here us that Google did not report the vulnerability/breach when they discovered it. This could be looked into by SEC.
- dangerface 8y agoBecause breaches come from public vulnerabilities, unless you can prove there was no breach, you should treat it as a breach. This is common information security practice. Google are unable to prove there was no breach because they didn't keep sufficient logs, which is also not acceptable in modern security practice.
- staticassertion 8y ago> This is common information security practice. No it isn't. If every vulnerability in every product turned into a "We've been breached" disclosure the industry would be a disaster. Yeah, they didn't keep sufficient logs and they fucked up really badly there. Still silly to call it a breach.
- dangerface 8y agoThe industry is a disaster because companies don't disclose potential breaches.