7 ms·
I know I shouldn't type this but isn't it weird that Google remains the last tech giant that hasn't had a major breach. I mean small breaches based on CSRF issu
by rhacker 4y ago
I know I shouldn't type this but isn't it weird that Google remains the last tech giant that hasn't had a major breach. I mean small breaches based on CSRF issues and what not, but nothing like those million record breaches that EVERYONE is afflicted by. Probably part of the reason the Army chose Google.
I think I would normally disagree with a govt. agency using a cloud platform, but it might actually be MORE secure than what they can do themselves.
- walrus01 4y agoDepends if you consider the NSA breaching their inter-data-center traffic 15+ years ago or not.
- ericmay 4y agoNo reason to really consider that as relevant here since if you consider it then you also have to consider that they’ve breached not only every potential contractor for the USG but also any company that matters.
- deleted 4y ago[deleted]
- feanaro 4y ago> but also any company that matters. Wow, that's pretty loaded. Is this some kind of no true Scotsman situation?
- jeffbee 4y agoI love the idea that the USG has simply backdoored Google, because it implies 1) a covert team of google3 shadow contributors, which is kind of funny and it must suck for them to not have platform support, but also 2) that the team responsible for micromanaging every joule that their datacenters consume, and charging back to every product group for resources used down to the nanodollar, simply hasn't noticed this ongoing campaign of bulk access.
- FateOfNations 4y agoI don't hold that one against them... they were not a willing participant in it, and at the time one wouldn't have reasonably included that in a threat model (and still isn't a part of a threat model for most people), so I wouldn't say they were negligent either.
- dekhn 4y agoChina broke into google and surveilled targets. Like, actually spied on dissidents through their gmail. https://en.wikipedia.org/wiki/Operation_Aurora https://en.wikipedia.org/wiki/Operation_Aurora This greatly sped up projects to protect user data from external threats. Heather Adkins who leads security (and is one of those ultra-longtimers) brought a number of senior eng for internal, ultra-private meetings where they showed the eng leadership exactly what had happened. I wasn't invited but at that time, sat near the exit door and their faces were just ... aghast at the consequences of what had just happened as a function of the systems they built. The snowden dumps also showed that the NSA had packet traces of BigTable RPCs which was quite an eye-opener and definitely sped up privacy projects.
- deleted 4y ago[deleted]
- Victerius 4y ago
- minedwiz 4y ago/r/nothingeverhappens
- DiggyJohnson 4y agoThis is a ridiculous comment. Please consider the guidelines, and your sense of untrustworthiness.
- Victerius 4y ago
- mupuff1234 4y agoIn internet years 2010 is basically a lifetime ago.
- 4y ago
- jefftk 4y ago> Google remains the last tech giant that hasn't had a major breach Have Amazon or Apple had a major breach? (I do think Google takes security atypically seriously, though)
- NineStarPoint 4y agoAmazon has a history of employees within the company leaking large sets of customer data, or using their internal access to target vulnerabilities in customer AWS setups. As far as I know they haven’t had any breaches by non-employees, but major internal data use issues are still security problems. Apple only has if you count exploits that allow for hacking Macbooks and Iphones as far as I know (and I wouldn’t count that personally).
- merely-unlikely 4y agoiCloud has been hacked more than once hasn’t it?
- manquer 4y agoI don't think there was a technical vulnerability , my understanding was there some social engineering and poor security defaults that led to some high profile accounts being compromised.
- thehappypm 4y agoIt was a technical problem. They didn’t throttle password guesses.
- Hextinium 4y agoRisky Business posited last week on their podcast that since Operation Aurora[1], where China hacked a bunch of companies, Google has just pulled out their checkbook to ensure that it never happened again. And it seems like they have successfully done so. [1] https://www.blackhatethicalhacking.com/articles/hacking-stories/operation-aurora-the-chinese-google-hack/ https://www.blackhatethicalhacking.com/articles/hacking-stor... Ninja edit: seems like dekhn just confirmed what I said above
- hedora 4y agoIt depends on your definition of security. I go with confidentiality, ineltegrity and availability. They continue to fail badly on all three of those fronts from an end user perspective. However, most of their problems on that front are self-inflicted / intentional cost saving / revenue generating. Edit. Examples: Sent box message injection in gmail getting (edit: people) fired. People sneak a forged sexual harassment message (or whatever) to the victim past the gmail spam filter, put the victim's address in the from header, and then corporate IT checks the account, sees the "outgoing" message in the victim account and fires the victim. Google drive data loss (many examples in web search results). Permanent account lockouts through no fault of the end user. Their entire targeted ad business. Malicious you tube take downs. ...and dozens of other examples
- jeffbee 4y agoIgnoring all the other un-parseable gibberish, the fact that messages get sent-foldered based on their apparent sender is a feature that enterprise customers demand and pay for. Gmail also maintains and exposes delivery audit logs so there is never uncertainty about the provenance of such messages.
- hedora 4y agoThe firing scam worked about a decade ago. Audit logs would fix it, assuming the company knew about them. Alternatively... They could just not route inbound messages to "sent". What possible reason would enterprise customers have to demand that certain incoming messages get black holed into a folder that no normal user will ever look at?
- joshuamorton 4y agoYou're asking this like "enterprise customers" as a group make sense or act logically. My best guess is something like outlook or other client integration for "legitimate" impersonation.
- jeffbee 4y ago
- chucky123 4y agoPart of why this doesn't happen is because if someone were to hack Google and they got caught, Google will simply disable all their services for that person.
- pengaru 4y ago> I know I shouldn't type this but isn't it weird that Google remains the last tech giant that hasn't had a major breach. Hate to burst your bubble.. https://www.washingtonpost.com/world/national-security/chinese-hackers-who-breached-google-gained-access-to-sensitive-data-us-officials-say/2013/05/20/51330428-be34-11e2-89c9-3be8095fe767_story.html https://www.washingtonpost.com/world/national-security/chine...
- reassembled 4y agoGoogle just posted a 5 part documentary series on IT security within Google and covers their response to operation Aurora. It’s pretty light on technical details but is a fairly entertaining watch.
- IncRnd 4y ago> I know I shouldn't type this but isn't it weird that Google remains the last tech giant that hasn't had a major breach. > nothing like those million record breaches that EVERYONE is afflicted by. Why do you think that? Google has had several major breaches. There was a google+ bug that exposed info on 52.5 million users, one on 500,000 users' data, and other disclosures. There have also been corrupted apps on the play store, like Brain Test that infected at least a million devices with difficult to remove malware. A decade ago there were about 5 million Google passwords leaked online. That's just what I can recall atm.
- User23 4y agoWhat's Emer^H^H^H^Hgoogle+?
- Thorrez 4y ago>There was a google+ bug that exposed info on 52.5 million users, one on 500,000 users' data, and other disclosures. There was a vulnerability discovered internally by Googlers. There's no evidence it was exploited. >A decade ago there were about 5 million Google passwords leaked online. Those weren't taken from Google. They were stolen from somewhere else (possibly multiple places). Less than 2% were val Disclosure: I work at Google. [1] https://security.googleblog.com/2014/09/cleaning-up-after-password-dumps.html https://security.googleblog.com/2014/09/cleaning-up-after-pa...
- api 4y agoHas AWS had a major breach?
- barkingcat 4y agoChina breached Google a while back. The NSA also hacked google wide open by decrypting/man in the middle SSL/TLS. I remember when that was disclosed Google went on a rampage implementing site-to-site/machine-to-machine SSL so that it's not relying on single point of failure SSL/TLS termination. A lot of people have selective memory when it comes to security issues. And those breaches are multimillion record breaches. The China one was bad enough for google to terminate the entire link to china and pull out entirely.
- dekhn 4y agoFrom my read of the NSA sections of the snowden docs, they didn't decrypt anything- they observed the Google front end that talked to the user was the end of the TLS chain and from there, inside Google's networks, the front end talked to its backends without any encryption, so as long as you had physical access to Google's network (which included intercontinental fiber) you could trivially sniff packets. https://www.washingtonpost.com/world/national-security/nsa-infiltrates-links-to-yahoo-google-data-centers-worldwide-snowden-documents-say/2013/10/30/e51d661e-4166-11e3-8b74-d89d714ca4dd_story.html https://www.washingtonpost.com/world/national-security/nsa-i... I can't find the article now but it had a picture of an NSA presentation with what was obviously a bigtable RPC (spend enough time debugging protocol buffers and stubby). From what I can glean, it seems likely that they tapped an undersea cable carrying Google's traffic between a frontend and a backend, although that's speculation.
- monocasa 4y agoThey did both. They tapped private inter-DC fiber of Google's that wasn't encrypted. Additionally they had a cute hack that could crack Diffie Hellman at a cost of about $100M a prime (and most of the internet at the time used the same primes). So most TLS/IPSEC/SSH etc was wide open to them too if they could catch the handshake.
- dekhn 4y agoCan you point me at the DH crack? This? https://www.theregister.com/2015/10/19/nsa_crypto_breaking_theory/ https://www.theregister.com/2015/10/19/nsa_crypto_breaking_t... I don't recall that ever being associated with breaking Google traffic although I recall there were some Google SSL changes around the time which may be related. I simply haven't seen any direct evidence, while a packet dump on a slide is direct evidence.
- deleted 4y ago[deleted]
- kart23 4y agohttps://en.wikipedia.org/wiki/2018_Google_data_breach https://en.wikipedia.org/wiki/2018_Google_data_breach
- User23 4y agoNo[1]. NSA slurped their entire intranet for only God knows how long. [1] https://www.washingtonpost.com/world/national-security/nsa-infiltrates-links-to-yahoo-google-data-centers-worldwide-snowden-documents-say/2013/10/30/e51d661e-4166-11e3-8b74-d89d714ca4dd_story.html https://www.washingtonpost.com/world/national-security/nsa-i...