10 ms·
Apparently unpopular opinion: an internally-discovered vulnerability with no evidence of abuse is not a breach and does not require public disclosure.
by rwestergren 8y ago
Apparently unpopular opinion: an internally-discovered vulnerability with no evidence of abuse is not a breach and does not require public disclosure.
- mannykannot 8y ago'No evidence of abuse' is not acceptable grounds for treating it as if there were no abuse. Personally, I consider all three points as being irrelevant.
- rwestergren 8y agoHow is this different than any other internal/private bug found every day at orgs?
- mannykannot 8y agoIf it was exploitable from outside then it was not internal, by definition.
- Kalium 8y agoOK. What do you find to be acceptable grounds for treating a situation as if there were no abuse? Bear in mind that proving no abuse is impossible, as it's always possible that the hypothetical abuser got one step further than your investigation and covered their tracks.
- dleslie 8y agoNever not inform. When such a vulnerability is discovered the right thing to do is to inform the users of its possible severity and the duration during which it was available. Always.
- reificator 8y agoSo then all security audits just become you paying someone large amounts of money to get really bad press for yourself. Regardless of whether you've actually lost customer information or not. At which point why not just stop being proactive? Hardline stances sell great on forums, that doesn't make them right.
- mannykannot 8y ago> At which point why not just stop being proactive? The attitude that absence of evidence should be treated as if it didn't happen leads to exactly that conclusion - that it's better to not be able to tell what's happening.
- buzer 8y agoIf that ever becomes standard, every actually relevant notification would be lost in the noise. Multiple local privilege escalation vulnerabilities are discovered yearly in both Linux and Windows (along with many other OSes and userland applications). Do you really want that every single company releases notifications that roughly every single of their systems were vulnerable since the day they were created until date X each time that happens? After all, there is no way to prove no one abused that before their systems were patched (including the period between system creation and vulnerability being publicly released).
- CaptSpify 8y ago> Do you really want that every single company releases notifications that roughly every single of their systems were vulnerable since the day... I'd love for that to happen. Maybe then everyone will start to pick up on the fact that all of our computer systems are insanely insecure.
- davidcbc 8y agoIt is much more likely in my opinion that people would become desensitized to data breaches and stop taking any of them seriously. Equifax or Cambridge Analytica would have been just another in a deluge of notifications.
- UncleMeat 8y agoDoes your place of business inform for every closed xss bug? Sqli? Every buffer overrun? Directory traversal? The bar for "bug that could potentially lead to access to user data" is so low that I'd say that any business that isn't finding hundreds of these bugs a year isn't doing a serious job on security.
- dleslie 8y agoWe try to, yes.
- Kalium 8y agoAre you familiar with California's Proposition 65? It was based on the same concept - never not inform. Some might opine that the consequences might have failed to meet hopes.
- dleslie 8y agoNope, am Canadian. Canada is going to require disclosure of breaches starting November 1. That may allow for companies to still fail to disclose the _possibility_ of breaches, however. https://globalnews.ca/news/4122202/data-breach-canada-privacy-commissioner/ https://globalnews.ca/news/4122202/data-breach-canada-privac...
- Kalium 8y agohttps://en.wikipedia.org/wiki/California_Proposition_65_(1986) https://en.wikipedia.org/wiki/California_Proposition_65_(198... Long story short, California requires labeling of things that may contain chemicals hazardous for a variety of reasons. The idea was simple - never not inform. The intentions were pure. The result is that basically everything has a vague and uninformative label about how it may contain chemicals that could be hazardous. The labels are spectacularly uninformative and incredibly numerous. They are universally ignored by everyone, as they constitute a sea of noise. The net result is that a wonderful, laudable, pure, kind, and compassionate idea - never not inform - has led to a deluge of useless informational notices in which actual useful notices are impossible to find. It might be worth considering that there could be a lesson in there.
- dleslie 8y agoLabeling is slightly different than simply informing, in that it is a specific method of informing. It would be like requiring Google to display information regarding this security issue on all of its pages. Warning labels have dubious efficacy, as evidenced by decades of grotesque warnings upon cigarette packaging and their limited success at reducing consumption; but that's not to say we ought not be able to know about the potential harms of a product or service, just that product labels sort of suck as a method of informing users. OTOH, Canada requires nutritional information on all food, and that's reasonably useful and successful _because_ the content of that label is strictly defined and reasonably useful.
- spdionis 8y agoYou are hereby informed that all technology systems may have vulnerabilities that may be exploited. Duh.
- mjw1007 8y agoThere's a scale from "there's no evidence of abuse and if there had been abuse we're certain we would have seen evidence" to "there's no evidence of abuse but there's no reason to suppose if there had been abuse we'd see any evidence". Companies tend not to be terribly good at articulating where we are on that sort of scale.
- Kalium 8y agoYou're absolutely right! There very much is such a scale. Even the companies who are the very best at communications will tend to struggle to communicate clearly when filtered through a press that have strong incentives to construe everything as a data breach. Lay people reading either of your statements will tend to stop at "there's no evidence" and go "What do you mean, 'no evidence'!? I want certainty!". Witness how readily and widely this whole G+ event has been mis-reported as MASSIVE DATA BREACH. While you're completely correct, perhaps there's room for subtlety here.
- s73v3r_ 8y agoExactly. There must always be an assumption that abuse happened.
- tyingq 8y agoRead Google's response carefully. They say they only had 2 weeks of api logs. They never say if the logs even had enough context to detect abuse. After reading it, I got the impression they have no idea what did, or did not happen.
- UncleMeat 8y agoGood luck demanding that every xss bug ever closed from any business gets publicized.
- emn13 8y agoSo if you were to write software or publish it, or deploy it, or even merely use it as part of your process to provide some other service to users, do you think it's reasonable to report each and every vulnerability? Keep in might that effectively means you'd need to report a potential breach every patch tuesday if you're running on windows, and similarly frequently for most linux distros. Oh, and you'd need to report all vulnerabilities in any dependencies of any software you build on, such as webframeworks, libraries, other apps... everything. Oh, and svn had a sha1 collision vulnerability, so any software that ever used SVN, and anything that depended on it might need to report a breach. With meltdown and spectre... OK, we've basically arrived at the point that if your business was somehow in nebulous proximity to a computing device it may well have posed the risk of a breach. Where does it stop? I mean - I'd love to live in a world where that were a realistic strategy, but in the I WANT MOAR DEPENDENCIES world we live in, which is just waking up to dealing with security issues, I'm not sure this is realistic, nor helpful. So it's a shame that the best we have is the absence of evidence - but for all my frustration about the cavalier risks google took here, I do actually believe that's pretty plausible evidence of actual absence. After all, if this had been discovered and meaningfully exploited, I really doubt the exploiter would have stopped. Reporting this kind of stuff as a breach is basically FUD. Essentially: You're distracting from real security issues, of which there are legion. No need to get all hypothetical about it - yet. Google made a shameful bug, but this isn't breach, not by any useful definition of breach.
- rectang 8y agoIt would probably be useful to explore the distinction between how vulnerabilities are handled in Open Source software, where disclosure is commonplace, versus non-source-available proprietary software, where the opposite is true. We need disclosure in Open Source because if attention is not drawn to the vuln downstream users won't upgrade, but highly motivated attackers will have what they need. With non-source-available software, there are fewer opportunities for attackers to learn of any vulns.
- leereeves 8y agoAccording to the announcement, Google can only say that no one abused the vulnerability in the two weeks prior to discovery. > We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug. However, we ran a detailed analysis over the two weeks prior to patching the bug, and from that analysis, the Profiles of up to 500,000 Google+ accounts were potentially affected. Our analysis showed that up to 438 applications may have used this API.
- puzzle 8y agoHow about attempts to abuse the vulnerability in the months since?
- zelon88 8y agoWhen some medical contractor misconfigures an AWS bucket and exposes 15,000 medical records we all lose our minds. It doesn't matter if the first bloke to find it was the researcher who disclosed it... We still go nuts. We make fun of the companies who come back and say "There was no evidence that the data was accessed by unauthorized parties." We know full well there's no evidence that the data WASN'T accessed by unauthorized parties. Please stop pretending this isn't a big deal just because of a hard-on for Google. If you'll put a 10 man company out of business for their complacency and ignorance you should be lining up at Google HQ with pitchforks over this. They're supposed to be above this. They are hailed as a gold standard.
- rwestergren 8y agoI think there is a difference between a vulnerability in an internal system, and blatantly exposing data to the public requiring little technical acumen to obtain.
- ArchTypical 8y agoIt wasn't an internal system. It was discovered within Google (internal as it was used originally). The wording is accidentally confusing.
- quaunaut 8y agoSo what do you say about the idea that it creates a disincentive to find security issues, because you'll be hit for them one way or the other? Also, I fundamentally disagree with your example. If they did an adequate investigation, using a 3rd party service, and found no evidence of my data being accessed by a 3rd party, and then fixed it- I'd say, "Good job checking up on yourselves" and move on. Security is still incredibly hard to get right. I'm willing to bet your service has security holes in it, right now- and that's not a hit against you. We haven't mastered these systems and anyone who thinks they have is just waiting to get bit in the ass. Every security professional knows: It's never, ever, a question of "if", but of "when".
- zelon88 8y ago
- mtgx 8y ago> no evidence of abuse is not a breach 400 third-party apps had access to this info. It's not that "Google knows that there wasn't any abuse" but that "Google doesn't know whether there was any abuse, because it didn't have the proper systems in place to check for that anyway." It's kind of like you saw no crime happening because you didn't look. But that says nothing about whether or not the crime actually happened.
- daveFNbuck 8y agoGoogle deleted most of the logs that could have contained any evidence. Would you feel the same way if Google employees manually deleted the logs after discovering the breach?
- spdionis 8y agoWould you prefer google keeping all access logs to your account forever?
- daveFNbuck 8y agoYes, I don't want them to delete records of third-party access to my account unless I explicitly ask them to. Even if I didn't want that, there are a lot of options in the space between deleting after two weeks and storing them forever.
- ForHackernews 8y agoThere's "no evidence" of abuse because they apparently only kept a short timeframe of logs. So we don't really know, and neither do they. Put another way, "no evidence of abuse" is not the same thing as "evidence of no abuse".
- chubot 8y agoNo, because it incentivizes the company "not to look very hard" for evidence of abuse. A company can claim EVERY bug was never exploited, and nobody can disprove them. There is an inherent conflict of interest there.
- ArchTypical 8y agoIt's not an unpopular opinion, it's the opposite of disclosure. It's not an opinion, but a different ethic in the vein of "no-disclosure". Who discovers it or if you can prove it was abused, is not relevant to the security issue.
- rwestergren 8y agoDo you disclose every vulnerability or bug internally-discovered at your org?
- dbllxr 8y agoLet's just assume there wasn't any abuse.. say a bug compromised my bank account, but no money was stolen (someone may have looked my balance and decided I was too poor to be robbed), do I expect to be made aware? yes of course and I feel data privacy deserves the same level of diligence because this is still a breach in trust, So ethically, they could and should have at least made a statement and apologized. We should not equate "no evidence of abuse" to "evidence of zero abuse", that type of plausible deniability is not going to push improvement in protecting user privacy. Especially in this case, no evidence was really a lack of evidence (probably worse), because logs were only kept for a short period of time. In the legal sense, or based on "industry practice", they might not be _required_ to disclose to the public. But can they, and should they? because we have all witnessed Google gone above and beyond, and done amazing things over the years. I'm a google fan, and I'm very disappointed by how this was handled.
- grandmczeb 8y agoAn attacker accessing your balance would be considered abuse. The analogy doesn’t fit.
- throwaway5250 8y agoThe fact that we have not (at least, not yet) observed evidence of abuse is little comfort, from an ethical perspective. https://en.wikipedia.org/wiki/Moral_luck#The_problem_of_moral_luck https://en.wikipedia.org/wiki/Moral_luck#The_problem_of_mora...
- foobiekr 8y agoI wonder if “Strategic Lack of Log Retention” would make a good conference topic. The problem with what Google is doing is that they are insinuating that a lack of evidence is evidence of lack. This is not unlike when companies like Equifax claim “we have no evidence...” We should not be rewarding companies for strategically avoiding culpability.
- tdb7893 8y agoI feel like lack of logs can increase apparent culpability (as this scenario shows). It seems a little silly they don't store anything after two weeks but I was explained elsewhere that a lot of the reason was that those logs can contain user data and they can't lose it or turn it over to the feds if it doesn't exist.
- foobiekr 8y agoIt can, however it also makes it harder to really pin them on anything. I think that's a net win. I understand the position that excessive log retention can itself create a high-risk metadata pool, but there are ways to mitigate that by tokenizing them or removing PII data without having zero usage information.
- endymi0n 8y agoPicking the nits here: They did not have any evidence of abuse, because they threw the logs away after 14 days... I'd consider that at least a disingenious reading of "we have no evidence that bad things happened".
- tyingq 8y agoBut..."no evidence of abuse" can mean a lot of things. The original WSJ article shared this version of "no evidence of abuse", and it's not very reassuring. "Because the company kept a limited set of activity logs, it was unable to determine which users were affected and what types of data may potentially have been improperly collected, the two people briefed on the matter said. The bug existed since 2015, and it is unclear whether a larger number of users may have been affected over that time." It's also not clear that the activity logs would even have the context to distinguish normal access from unauthorized access.
- deleted 8y ago[deleted]