11 ms·
Some Google Photos videos in backups were sent to strangers in November
- w0m 7y agoaaaaaahhhhhhhhh
- TheCapn 7y agoNow that's spicy. Were people receiving random videos? Was this being targeted to retrieve videos of specific users through an exploit?
- Mindwipe 7y agoThe wording suggests random, or at least from the end user pov. This is a catastrophic issue and it's terrible Google have sat on this for so long.
- SnowingXIV 7y agoHow does this happen? I realize it's a small percentage, but this is one of the first tests you build. Even 1 photo (not to mention this is regarding videos) should never make it to another non-authenticated user. This is a massive mistake.
- beamatronic 7y agoThey had one job!
- whatisthiseven 7y agoI think, when discussing software, the phrase "should never" just doesn't belong. I have only a short software career, but of all the bugs and unintentional behavior I have read about failures small and big companies make, I am no longer surprised. For that matter, software itself is full of surprising and undefined behavior, so it really shouldn't be a surprise that large corporations sometimes have "simple" mistakes that appear really big. That is just software in motion.
- jrowley 7y agoUnintended software behavior exists on a spectrum and a great deal of it is preventable by learning from past mistakes. It’s unfortunate we don’t have more information about the nature of the underlying this issue.
- thedance 7y agoI don't work at Google (any more) but I have seen bugs in large-scale production that served one user's data to another user, and both times it had the same cause: a developer stored user-specific data into a process-global singleton because the consequence of some java decorator was non-obvious. When the next user request came along they were served the previous user's information.
- dehrmann 7y agoOne way I've seen this happen is images have UUIDs (or just incrementing), they're base-64 encoded somewhere after security checks, and someone accidentally called `toLower()` on the id.
- KMag 7y agoGoing from 22 base-64 characters to 22 base-36 characters still only drops you to about 113 bits of entropy. Unless we're talking significantly more than a quadrillion images in the system, getting a collision on a 113-bit random ID is exceedingly unlikely. I strongly suspect there were more problems in the system than just toLower(), or else the system was hosting significantly more than a quadrillion images. Your mention of "or just incrementing" sounds much closer to the mark.
- gwbas1c 7y agoI once witnessed a very similar bug. The story was a comedy of errors: 1: I interviewed a HORRIBLE candidate and told my boss in no uncertain terms not to hire the bozo. Then, I look at my colleagues and explain how poorly the interview went. 2: I go away for two weeks to have surgery 3: I come back and learn that we're hiring the bozo 4: My boss asks me to do some pair programming with the bozo, and he doesn't understand some very basic concepts 5: I hear the bozo is debugging webservice code in production 6: We had a data leak from one of the bozo's bugs From what I remember, it was a very dumb bug based on clear misunderstanding of fundamentals.
- bouke 7y agoI once witnessed something similar. Deep down in the repository code there was a field marked `static`, which should've been an instance property. The value would be overwritten by the last user to access the repository; so this resulted in a race condition where one user might see the other's data.
- kerng 7y agoThis is big, and has GDPR fine written all over it. And I'm sure this will not be the last time we hear about this. Also, very curious to learn more of the technical details down the road?
- dsd 7y agoDoes gdpr forbid mistakes?
- agos 7y agono, but it does mandate to notify the people affected by the error/breach/fudge up. I wonder if they would have notified anyone if it wasn't for GDPR.
- gmac 7y agoWell, it wouldn't do a lot of good otherwise, since I'm pretty sure most data breaches aren't committed deliberately. The point is you should have measures in place that prevent those sorts of mistakes.
- progval 7y agono, but "In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55"
- captainbland 7y agoNot mistakes as such, but it'll probably invite an audit wherein they'll assess what strategies they took to mitigate a potential issue like this. If they're found to be inadequate and it also impacted a resident of the EU then maybe they'll slap them with a fine.
- kerng 7y agoWell, at least they will have to make sure they performed due diligence with testing- because a test would reveal this pretty quickly. You know real testing, not using customers as Guinea pigs
- friendly_fren 7y agoDon't store your private information in the cloud unencrypted. Caching bugs frequently leak unintended data.
- dehrmann 7y agoThis makes sense for backups, but for something like photos, there's a lot of value-add you're missing out on. Something like sharing a photo with a friend becomes an ordeal.
- sneak 7y agoThis is a nice platitude, but frequently most b2c client apps that use cloud storage (eg Google Photos) give no option to encrypt data clientside for storage.
- youareostriches 7y agoWhich is exactly why you shouldn’t use them.
- tyingq 7y agoInteresting that the bug was in Takeout, which might have a fair amount of privacy concerned users that were trying to leave Google. Guessing some caching or "generate a unique url" type bug.
- minikites 7y agoGoogle respects your data just as much as Facebook does.
- brenden2 7y agoThe usual argument for using "cloud" over managing your own files/data is that it's very hard to safely manage your own data without making mistakes (data loss, etc). However, this is an example of how companies like Google also make mistakes. Furthermore, when Google/FB makes a mistake (like leaking your private data) they do it at a global scale. I offboarded myself from all of Google's services a while ago, but I also think "cloud" is dead, at least in the cases where the cloud service holds the encryption keys on my behalf. I don't trust, and never will trust, any company to hold on to my data without either selling it to a third party or accidentally leaking it.
- jimbob45 7y agoWhat do you use for email over Gmail?
- brenden2 7y agoI use fastmail. I'm a happy customer.
- PunchTornado 7y agoIt seems from another world when I see people paying with money for products. I don't know why, maybe because I'm very cheap, but I'd never do this when I can pay with my data.
- beckler 7y agoDidn't Australia like pass a bill or something that compels corporations like Fastmail to give the government any and all encrypted communications if they ask?
- ocdtrekkie 7y agoThis is one of those stories that had no relevance in actuality, yet gets brought up in nearly every single mention of Fastmail: The bill applied to a requirement for backdoors/the ability to decrypt data. Fastmail was never E2E encrypted in the first place (like Gmail, Outlook, and most other major mail providers), and hence, Fastmail was always required to comply with lawful requests for your data.
- ipsum2 7y agoIt would be nice if they could tell you what photos/videos were sent to strangers.
- londons_explore 7y agoLogging is really locked down due to GDPR stuff... Which ironically means the privacy laws means they've deleted the specifics of the privacy violations that occurred.
- TuringTest 7y agoSomewhat relevant: host your own web applications easily https://news.ycombinator.com/item?id=22231922 https://news.ycombinator.com/item?id=22231922 Reviving Sandstorm (sandstorm.io)
- Macha 7y agoI've seen services (Google Photos, Dropbox, OneDrive) try to opt in the user to having data automatically uploaded when they take a not really related action (like logging into the google account on their phone, connecting a USB device, or misclicking on an icon in their file list). I do wonder if there's any penalty that'd apply to them if they then lost data that users hadn't realised was being uploaded?
- scarejunba 7y agoI'm pretty sure there's a huge number of these CCPA/GDPR implementation bugs. I know of a couple myself.
- subject119 7y agoDesktop based applications making a come back
- londons_explore 7y agoConsidering this is 4 months later... This can't have been very widespread. If I saw someone else's video in my takeout archive, I'd have totally contacted the tech media...
- x__x 7y agoWhat if it was a celebrity? This kind of thing could have been used for blackmail
- PeterisP 7y agoHonestly, I would not have noticed if a bunch of someone else's videos were on my takeout archive - I've downloaded that takeout archive multiple times as a backup, and I've browsed some stuff there (a fraction of the total) once to see if the things I care about are there, and that's it. For all I know, your videos might be in a zip file on my external HDD I use for backups, and I'll never know unless I need to restore data after some disaster and that's the latest takeout that I have.
- martythemaniak 7y agoI posted this here a while back, some super-weird compilation of what appeared to be a random video showed up in my Assistant. https://news.ycombinator.com/item?id=20373112 https://news.ycombinator.com/item?id=20373112 Seems like something similar. Ie, someone else's weird crap was used by my account's Assitant to make a compilation/summary.
- gregsadetsky 7y agoDoes anyone have suggestions for a self hosted photo service with - importantly - a solid iOS companion app to do photo sync and possibly browse photos? I would prefer using a simple S3 backend. It seems that finding a reliable photo sync'ing app for iOS (outside of Google Photos or Dropbox) is difficult. I've been manually using Image Capture and uploading to S3 but that's quite inefficient. Thanks!
- kylehotchkiss 7y agoNot S3, but self hosted by NAS and can push encrypted backups to S3 - Synology Moments? https://www.synology.com/en-us/dsm/feature/moments https://www.synology.com/en-us/dsm/feature/moments
- cleee 7y agoI find Nextcloud pretty great. There's a sync client available on f-droid. It also has capabilities for calendar and contact list synchronisation, so you can move that off your google account. It came preinstalled with my instance of mail-in-a-box (https://mailinabox.email/ https://mailinabox.email/), which is an easy way of hosting your own email. With my self-hosted instance of mailinabox and LineageOS my phone is completely google-free. :) Edit: And it has a decent iOS sync client as far as I know.
- nahtnam 7y agoNot self hosted but mega.nz has a really good photo syncing app and all data is encrypted
- gregsadetsky 7y agoThank you, the great iOS app and end-to-end encryption really sealed the deal. Also being able to try it out with the 50Gb included in the free account...! I'll be moving backups there. Maybe I can run a weekly / monthly rclone to sync Mega to S3 to have some redundancy. Thanks!
- jayFu 7y agoCheck https://lomorage.com https://lomorage.com, you can host in your home network using raspberry pi.
- nkrisc 7y agoSo far it seems that Google is notifying the people who received videos that weren't theirs, not yet the people what had their video leaked. > Google has been sending emails to affected Takeout users. In the email, which was first spotted by 9to5Google, Google writes, "Some videos in Google Photos were incorrectly exported to unrelated user's archives. One or more videos in your Google Photos account was affected by this issue. If you downloaded your data, it may be incomplete, and it may contain videos that are not yours." > While this message is directed to Google Takeout users who tried to download their own data and accidentally got someone else's, we've yet to see a message directed to the "unrelated users" whose videos ended up in the archive. We've asked Google if it plans to notify users who have had their private videos exposed, and we'll update this article if the company responds. From https://arstechnica.com/gadgets/2020/02/google-photos-bug-let-strangers-download-your-private-videos/ https://arstechnica.com/gadgets/2020/02/google-photos-bug-le...
- MarioMan 7y agoThe way I read it, it seems that only Takeout users were affected, on either end. Either way, this still needs to be made explicit for the sake of transparency.
- dang 7y agoUrl changed from https://www.theverge.com/2020/2/4/21122044/google-photos-privacy-breach-takeout-data-video-strangers https://www.theverge.com/2020/2/4/21122044/google-photos-pri..., which copies from this.