4 ms·
Fun fact, there was a universal XSS vulnerability on google (including search, support, accounts, cloud, etc) found just last week [0]. I'd say it's always just
by lowpro 7y ago
Fun fact, there was a universal XSS vulnerability on google (including search, support, accounts, cloud, etc) found just last week [0]. I'd say it's always just a matter of time. That doesn't mean they don't have everything in order, but securing everything as much as possible is half the battle. The other half is a solid response when things do happen, which we will now see in how Docker handles this situation.
[0] https://twitter.com/WHHackersBR/status/1118393568656334850 https://twitter.com/WHHackersBR/status/1118393568656334850
- acct1771 7y agoAnd do we ever find out how much that was being exploited "in the wild"?
- simondedalus 7y agowe grit our teeth and "believe" that anyone traceably affected got an email directly from the company or something :D (that said, google main page vulnerable to xss is kind of like... what, we're afraid someone will take over google and put some cryptominers on the google.com main page?)
- WrtCdEvrydy 7y agoThe Microsoft Approach... 'people totally didn't access your email body... except we eventually owned up to it after it got leaked'
- mehrdadn 7y agoWhere did they deny that anybody's email bodies were read? I'm looking for it and I can't find it. I only see that they told the other 94%(?) of people that unauthorized access did not reveal the contents of their messages in particular, which seems to be truthful?
- WrtCdEvrydy 7y agoInitial email said the body wasn't affected, and motherboard asked for a confirmation, so they said 'Yes'. 6% of the people received a specific email saying the body of their email was accessed and they had to backtrack.
- mehrdadn 7y agoWell the email said: > This unauthorized access could have allowed unauthorized parties to access and/or view information related to your email account (such as your e-mail address, folder names, the subject lines of e-mails, and the names of other e-mail addresses you communicate with), but not the content of any e-mails or attachments, between January 1st 2019 and March 28th 2019. Notice it says your email account. The whole email is about the account of the recipient, not those of other recipients. Given that they explicitly worded it this way and people clearly misinterpreted it to mean something else, I hope you can forgive me for being a little skeptical of third-party anecdotes that suggest Microsoft claimed nobody's email contents were accessed...
- dlitz 7y agoWell, a compromised google.com main page could return malicious search results for certain queries. How many Windows sysadmins install PuTTY by googling "putty", and then installing an executable from whatever site shows up in the first couple of results?...
- Piskvorrr 7y agoIf the primary install method is "search and download whatever manually from the internet," you have bigger issues than a potential Google compromise: create a site with better ranking than the canonical HTTP (!) download page, MITM the HTTP download, whatever.
- bartimus 7y agoYou'd want the XSS vulnerability to be on accounts.google.com. Much more to do before you can successfully exploit it. You still need to get people to come to your malicious page that exploits it. Then it's the question if your attack won't show up on Google's radars for abnormal behavior. Most likely for Google's security - since their landscape is so big - XSS vulnerabilities are considered a given. Then as soon as abnormal behavior is detected Google gets to discover the XSS vulnerability.
- azinman2 7y ago“We are enhancing our overall security processes and reviewing our policies. Additional monitoring tools are now in place.” Why wasn’t that the case before?!
- mfatica 7y agoSometimes you don't know what to monitor until you know the attack vector. We are only human
- k_sze 7y ago1. Because humans aren’t perfect. 2. Because mistakes happen. 3. Because there’s a cost to everything: if you want better security, it’s going to cost you more, immediately. And we don’t always estimate trade-offs correctly (see points 1 and 2).
- joshbaptiste 7y agoExactly.. life in general is about constant refinement.. if today's hacker could time travel to 1999, she would be in a nirvana of Bind, SSHv1, Apache, IIS etc.. vulnerabilities. Hacks happen and we learn and improve, even down to the language being used.. a la Rust.
- DCoder 7y agoBecause "Security is a journey, not a destination". There's always a way to enhance your processes, monitor more indicators, etc. or otherwise improve your security.