4 ms·
> It is not and never has been a norm for SAAS vendors to disclose internal vulnerabilities that have not been discovered independently by third parties. The b
by Rafert 8y ago
> It is not and never has been a norm for SAAS vendors to disclose internal vulnerabilities that have not been discovered independently by third parties.
The bug sounds like it would need reporting to a data protection authority under the GDPR, which doesn't make a distinction on who discovered the breach. But I'm not sure if the fact that there is no evidence of the bug being abused means they didn't need to report after all.
- tptacek 8y agoSomeone claimed this on Twitter, so I took the time to finally read through the GDPR to validate the claim, and I don't find anything anywhere that requires the discovery of a vulnerability --- at all, by anyone --- to prompt a report to an external authority. I didn't look very hard, but maybe you can point me at it? GDPR is clear about breach reporting, that is true. But a vulnerability is not a breach.
- buckminster 8y agoIn plain English a breach is the hole in ones defenses. To breach is to take advantage of a breach or to create a breach. So "breach reporting" could be read either way. Like you, I've only ever seen it read in the verbal sense, but that isn't obviously correct. Edit: expanded definition of breach.
- tptacek 8y agoSorry, but you can't simply change the definition of "breach" to include "all vulnerabilities" and then charge Google with covering up your new supposed "breach". By that definition, practically every company in the world is constantly covering up breaches. You can say, "yes, they are", but at that point in the discussion the GDPR is out the window.
- buckminster 8y agoI didn't change anything. I pointed out a fact.
- wglb 8y agoNo. A breach is when data actually escapes.
- asdfasgasdgasdg 8y agoIn common English, a breach is the damage left be an attack (often a hole in the case of penetrating ordinance, as in "a breach in the hull of a ship"). Breach definitely does not, in common English, refer to a theoretical, unexploited hole in one's defenses. I would be interested if you could point out any instance in literature or professional writing where it is used that way. Also common English is notoriously unimportant when arguing over legal definitions, so this is all beside the point.
- Isinlor 8y agoAccording to UK Data Protection Authority: > A personal data breach can be broadly defined as a security incident that has affected the confidentiality, integrity or availability of personal data. In short, there will be a personal data breach whenever any personal data is lost, destroyed, corrupted or disclosed; if someone accesses the data or passes it on without proper authorisation; or if the data is made unavailable, for example, when it has been encrypted by ransomware, or accidentally lost or destroyed. https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/personal-data-breaches/ https://ico.org.uk/for-organisations/guide-to-the-general-da... The wording around data breach is quite specific i.e. "security incident that has affected ...". They also give 6 examples: - access by an unauthorised third party; - deliberate or accidental action (or inaction) by a controller or processor; - sending personal data to an incorrect recipient; - computing devices containing personal data being lost or stolen; - alteration of personal data without permission; and - loss of availability of personal data. Quite obviously enforcing disclosing security vulnerabilities was not the main goal of the authority or they would mention it explicitly. Also, if they would want to process all security vulnerabilities they would need way, way more stuff. Just reporting CVEs (Common Vulnerabilities and Exposures) from products used by all companies would lead to hundreds of millions of reports. CVE list more than 100 000 vulnerabilities * all companies that use these products. Note that DPAs have issues with processing actual data breaches where numbers are in thousands.
- Rafert 8y agoWith a bit of searching I found "Guidelines on Personal data breach notification under Regulation 2016/679"[1] which states: > Although the GDPR introduces the obligation to notify a breach, it is not a requirement to do so in all circumstances: > - Notification to the competent supervisory authority is only triggered where a breach is likely to result in a risk to the rights and freedoms of individuals. > - Communication of a breach to the individual is only triggered where it is likely to result in a high risk to their rights and freedoms. After some clarification, it also states: > Regardless of whether or not a breach needs to be notified to the supervisory authority, the controller must keep documentation of all breaches, as Article 33(5) explains: > “The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.” > This is linked to the accountability principle of the GDPR, contained in Article 5(2). Controllers are therefore encouraged to establish an internal register of breaches, regardless of whether they are required to notify or not. So the answer seems to be "it depends". But when Google says "We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug." I'd argue it's better to err on the side of caution and report it. [1]: http://ec.europa.eu/newsroom/document.cfm?doc_id=47741 http://ec.europa.eu/newsroom/document.cfm?doc_id=47741
- tptacek 8y agoAll of those excerpts refer to breaches, not vulnerabilities. Vulnerabilities aren't breaches, either in common parlance or as a term of art. The distinction the GDPR is making here is between intrusions that don't include exfiltration of data (ie, what happens when most teenager hackers break into something for the sport of it) and those that do.
- Rafert 8y agoIn this case nobody can surely say it was only a vulnerability, which IMO warrants treating as a breach.
- 8y ago