Audit Cleared Google Privacy Practices Despite Security Flaw
thehill.com
thehill.com
For that reason Mozilla "no longer accept audits carried out by Ernst & Young Hong Kong." [0].
[0]: https://blog.mozilla.org/security/2016/10/24/distrusting-new...
Either they bend to the folks paying the bills, or they flag a zillion, generally known to engineers, issues.
If you really want to make you security audit useless, hand the auditors C code. They will stare at you as though you just handed them the head of a small child.
Just because there exists a world of auditors who function as rubber stamps does not mean we all do.
That said, the opportunity to do this (scrub reports) is a driving decision behind many companies' choice to work with more permissive firms. If you want a rubber stamp, you can certainly get it, but if you want a true partner who will find and exploit issues you can get that too.
Could you name such a company? This is a perfect opportunity to get to know a good auditor, actually I can't imagine how would one look for a good auditor otherwise.
This is sour grapes of the worst kind.
(hint: you can't, because they covered them extensively)
The amount and type of data exposed isn't as bad but this is pretty similar to the Cambridge Analytica scandal, except in this case Google literally didn't even notice. Facebook at least noticed.
The reporting on this G+ story has been startlingly bad. There's apparently some juice to the narrative that Google is running headlong into a collision with the Trump administration, and so reporters seem to be starting with a public policy conclusion and working their way back. Somebody needs to start informing these people how professional software security works.
In any audit situation --- PCI, HITECH, SOC-2, you name it --- there is neither a norm nor a duty to notify auditors of internally discovered security problems. Nor would any such norm be productive: it would warp internal incentives, both to discover and to properly handle vulnerabilities.
If the auditors discover a security problem, that problem gets documented, just like it (typically) does with external reporters (researchers, bug bounty claimants). When that happens, you have an indication that your internal software security controls failed. But when your team finds a bug in its own code? That's a sign that the team is doing things right.
The reporting is definitely exaggerating the significance of the data that was exposed and making it sound like it's known that the data was collected by third parties, but it's absolutely the case that the ball was dropped here and it's inappropriate to pretend nothing happened. There's simply no way to know, which is itself a breach of user trust.
It's kind of a no-win situation here given the way the media reports on these matters, but attempting to keep it quiet was incredibly foolish - everything remotely bad that happens at Google is going to get leaked by internal troublemakers now, and legal/pr should know that and should have gotten ahead of this.
It doesn't feel like splitting hairs to separate this from things like 'we found an obscure xss exploit internally which is now fixed'. It is explicitly a Possible Breach, not just a Bug. If you're arguing that Possible Breaches don't require disclosure, well, that's a choice to make, but it worked out poorly in this case and it will probably keep working out poorly because everything G does is under a microscope until the far right gets bored with them.
There are about 430 developers that could have exploited this vulnerability. There was no evidence in the available two weeks of logs of it being exploited. And the number of users and types of data available make Google+ a low value target. The decision to not announce was reasonable, common, legal, and moral.
It sets a poor standard to suggest they should have acted different because they’re now under fire from people with far darker motives than reporting truth or advocating for consumer privacy. Those exploiting the story for their own gain should be shamed rather than capitulated to.
Literally all security bugs can be described this way. "Company closes security bug" is not really news, nor should it be. How many XSS bugs have been closed at your place of business? Those are literally all potential breaches. Should each one of those get published in the news? Or does this requirement only exist for the major companies?
I'd wager that FAANG companies are closing thousands of similar bugs annually. The only reason this one is treated differently is the chosen narrative by the journalists.