US senator urges investigation into Google+ bug ‘coverup’
sociable.co
sociable.co
It is not and never has been a norm for SAAS vendors to disclose internal vulnerabilities that have not been discovered independently by third parties. Tens of thousands are found every year by internal teams and contractors at companies around the country, many of them far more severe than the G+ bug (which would probably win a sev:low on a real assessment, less impactful than an XSS bug). You hear about none of them.
A coherent argument that this is as it should be: http://flaked.sockpuppet.org/2018/10/09/internal-disclosure-...
You can argue that things should be different for shrink-wrap software and hardware products, where vulnerabilities have a half-life and users need to be notified to patch. I won't disagree, but I will note that the norm of not disclosing internal discoveries holds there as well.
It's fair to say "Google followed current best practice." It's not fair to say "current practice is how it should always be."
What is acceptable for a company selling razors to Minessotans may not be for a behemoth with troves of personal data on every American. The question, "should Google have heightened disclosure requirements around confirmed and potential breaches," is not invalid.
An argument that wouldn't have been made if we weren't having this discussion. I'm not saying Google messed up. I'm simply defending the debate.
"A mandate to disclose internal vulnerabilities would change incentives. Firms would have a reason not to want to find vulnerabilities."
My problem with this thinking is that it could be extended to finding breaches. If you have to publish every breach you're not going to want to find them.
It's impossible to prove that a vulnerability has not resulted in a breach and so an argument could be made that every vulnerability has to be considered a breach.
That would not be very pragmatic though, especially if we also take the view that every bug is a vulnerability (as the linked article does).
I think if the ultimate goal is to protect users, we can't be dogmatic or formalistic about which incidents to publish. It has to depend on the likelihood and the severity of any damage.
If a vulnerability concerns highly sensitive data and we don't know whether or not there was a breach then users should be told about the incident so they can protect themselves or change their behaviour in the future.
I also think that in this particular event Google tried to downplay the likelihood of a breach. Bad idea.
And, again: so far as anyone knows, there was no breach. All software is in a continuous state of "likely breach". But words mean things: a breach happens when a vulnerability is exploited maliciously, not when it's discovered.
But that raises the question which ones should and which ones shouldn't be disclosed.
In my opinion, knowing for sure that there was a breach is not the right threshold in all cases.
A high profile public API that had a glaring vulnerability for years seems far more likely to have been breached than most other software.
Also, the more high profile the software the greater the reputational risk of being wrong.
What if the bug gets leaked eventually? What if there was in fact a breach and it only becomes known later when people have already suffered the consequences?
If that happens, people will question the decision not to publish and the damage to trust will be far greater. This has to be factored into the incentive structure of any disclosure or non-disclosure.
I think the best course of action is to routinely disclose all vulnerabilities but not necessarily alert all end-users to all vulnerabilities.
* The vulnerability we're talking about, like all G+ vulnerabilities, has no half-life. It's fixed decisively the instant they deploy the fix to prod. There is no user response we're looking for to mitigate the vulnerability.
* The incentive problem isn't eliminated just because you only target Google with the new norm. When we demand that "high-profile" companies disclose vulnerabilities, we create the sentiment, across the industry and in low-profile companies as well, that vulnerability discovery is a bad event, to be avoided. The exact opposite thing is true.
* Internal vulnerabilities in high-profile applications are discovered so often that people will quickly tune them out (until someone sets out to take a scalp). It could even wind up benefiting companies with actual breaches, whose announcements will be lost in the noise, and more easily PR-spun.
The basic problem here is very simple: found- and- fixed vulnerabilities aren't breaches. A vulnerability and its successful exploitation are not the same thing. It does not matter if the vulnerability is "leaked eventually", so long as it's fixed when it's found.
If Google had discovered this vulnerability and then just decided to ignore it for 6 months, that would be a story. That's not what happened.
What makes this less than simple is that we may not know whether or not a particular vulnerability was exploited (i.e if a breach has occurred).
My opinion is that the likelihood of an undiscovered breach and the potential damage of any such breach should be taken into account when deciding whether or not to disclose a particular vulnerability.
>The incentive problem isn't eliminated just because you only target Google with the new norm.
I have no interest in targeting Google specifically (I'm actually a shareholder). They just happen to be big and have a lot of personal data. They are in the crosshairs of regulators and politicians as well, which is another reason to err on the side of transparency.
I'm also not trying to eliminate the incentive problem by limiting it to Google (or other big companies). On the contrary, my opinion is that disclosing vulnerabilities in a timely fashion should be seen as building trust and become the new normal. Making it the new normal is what should fix the incentive problem over time as people get used to it.
People tuning out is not a bad thing. The difference between an actual breach and a fixed vulnerability will not be lost just because vulnerabilities are no longer kept secret.
But as I said, I don't think end-users should be notified of every single vulnerability.
Agreed. But it should reflect our collective views. The process for finding that collective agreement is discussion.
Judicial proceedings are based on law, not morals. Legislative proceedings consider morality. If something shouldn’t happen but does, we can address that through the law.
Their decision wasn't about what was best for users, it was about what they thought they could get away with. I'm not shocked Congress is interested in that, because the memo is far more condemning than anything about the actual bug.
As an additional note, we can't rely on Ron Wyden to keep Google in check: Google is one of his larger sponsors, spending somewhere around $20,000 a year on him.
How would you characterize this versus the data leak used by Cambridge Analytica, if you remove the difference in the scale of product users and developers building on the API? Being able to scrape a lot of API data that users explicitly defined as private is a pretty big deal, especially when you consider that Google pretty much forced G+ integration on everyone in the first place, causing them to have accounts they might not even want.
I feel in this thread sort of like how I do in those bug bounty threads where someone is trying to convince me that a logout CSRF should merit a $10,000 payout because a competitor could use it to make a UX experience worse and then shift all the customers to their product and after all Google is such a huge company they shouldn't have CSRF at all and $10,000 is a drop in the bucket.
I mean that's not what you're saying but I feel like we're playing Six Degrees Of Kevin Bacon the same way to get from this very marginal bug that they themselves found and fixed to "this merits federal legislative attention."
Let's not pretend the product was shut down because of this bug. Google Plus was a failed product. This security issue was just a convenient event to which they chose to attach the news.
Google's own words on the matter:
> This review crystallized what we’ve known for a while: that while our engineering teams have put a lot of effort and dedication into building Google+ over the years, it has not achieved broad consumer or developer adoption, and has seen limited user interaction with apps. The consumer version of Google+ currently has low usage and engagement: 90 percent of Google+ user sessions are less than five seconds.[0]
[0] https://www.blog.google/technology/safety-security/project-s...
But it was closed due to this bug and the drama surrounding it. It wasn't "convenient" to announce closure alongside the bug, the bug actually became much more widely discussed because it was attached to a product shutdown. I can't imagine anyone at Google wanted this to go down that way, it would've been better to quietly shutter it at a different time.
But the Wall Street Journal announced it, as part of the memo that they got internally. So Google had to announce it at the same time in the same post, and it was definitely the cause of the product shutdown.
That wasn't a leak as much as misusing data that FB happily gave out to anyone who asked -- which FB "disclosed" to great fanfare during the Obama presidential run to show how they could be leveraged for more than looking at pictures of your former college roommate's cat.
Blumenthal is also the senator behind the abomination that is SESTA[0]. He's an opportunistic scumbag - it's not that he's simply ignorant about technology; he's actively malevolent and uses his knowledge to that effect.
[0] https://www.eff.org/deeplinks/2018/03/how-congress-censored-...
The bug sounds like it would need reporting to a data protection authority under the GDPR, which doesn't make a distinction on who discovered the breach. But I'm not sure if the fact that there is no evidence of the bug being abused means they didn't need to report after all.
GDPR is clear about breach reporting, that is true. But a vulnerability is not a breach.
Like you, I've only ever seen it read in the verbal sense, but that isn't obviously correct.
Edit: expanded definition of breach.
A breach is when data actually escapes.
Also common English is notoriously unimportant when arguing over legal definitions, so this is all beside the point.
> A personal data breach can be broadly defined as a security incident that has affected the confidentiality, integrity or availability of personal data. In short, there will be a personal data breach whenever any personal data is lost, destroyed, corrupted or disclosed; if someone accesses the data or passes it on without proper authorisation; or if the data is made unavailable, for example, when it has been encrypted by ransomware, or accidentally lost or destroyed.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
The wording around data breach is quite specific i.e. "security incident that has affected ...".
They also give 6 examples:
- access by an unauthorised third party;
- deliberate or accidental action (or inaction) by a controller or processor;
- sending personal data to an incorrect recipient;
- computing devices containing personal data being lost or stolen;
- alteration of personal data without permission; and
- loss of availability of personal data.
Quite obviously enforcing disclosing security vulnerabilities was not the main goal of the authority or they would mention it explicitly.
Also, if they would want to process all security vulnerabilities they would need way, way more stuff. Just reporting CVEs (Common Vulnerabilities and Exposures) from products used by all companies would lead to hundreds of millions of reports. CVE list more than 100 000 vulnerabilities * all companies that use these products.
Note that DPAs have issues with processing actual data breaches where numbers are in thousands.
> Although the GDPR introduces the obligation to notify a breach, it is not a requirement to do so in all circumstances: > - Notification to the competent supervisory authority is only triggered where a breach is likely to result in a risk to the rights and freedoms of individuals. > - Communication of a breach to the individual is only triggered where it is likely to result in a high risk to their rights and freedoms.
After some clarification, it also states:
> Regardless of whether or not a breach needs to be notified to the supervisory authority, the controller must keep documentation of all breaches, as Article 33(5) explains: > “The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.” > This is linked to the accountability principle of the GDPR, contained in Article 5(2). Controllers are therefore encouraged to establish an internal register of breaches, regardless of whether they are required to notify or not.
So the answer seems to be "it depends". But when Google says "We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug." I'd argue it's better to err on the side of caution and report it.
The distinction the GDPR is making here is between intrusions that don't include exfiltration of data (ie, what happens when most teenager hackers break into something for the sport of it) and those that do.
1. They don't actually know if the breach was exploited, because of the limited log window.
2. It appears that Google intentionally avoided the congressional hearings last month because of this breach, if they asked a question such as "are there any other incidents you have not disclosed" they would have had to either perjure themselves or kick off a PR fiasco in front of lots of TV cameras in real time. When you're evading authorities because of an incident like this it's far worse than any hack itself.
Maybe it is high time for software companies to start disclosing internal vulnerabilities (whether they can demonstrate it has been exploited or not) in light of the massive, worldwide societal impact these companies now have.
People everywhere should be mad as hell that these mega corporations are so powerful that they regularly evade oversight to continue building their monopolies. It's not about disruption or innovation anymore, it's become something far more evil.
In an op-ed promoting campaign finance reform, the Oracle of Omaha, Warren Buffett, proposed raising the limit on individual contributions from $1,000 to $5,000 and banning all other contributions. No corporate money, no union money, no soft money. It sounds great, except that it would never pass.
Campaign finance reform is so hard to pass because the incumbent legislators who have to approve it are the ones who have the most to lose. Their advantage in fundraising is what gives them job security. How do you get people to do something that is against their interest? Put them in what is known as the prisoners’ dilemma. According to Buffett:
Well, just suppose some eccentric billionaire (not me, not me!) made the following offer: If the bill was defeated, this person—the E.B.—would donate $1 billion in an allowable manner (soft money makes all possible) to the political party that had delivered the most votes to getting it passed. Given this diabolical application of game theory, the bill would sail through Congress and thus cost our E.B. nothing (establishing him as not so eccentric after all).
Consider your options as a Democratic legislator. If you think that the Republicans will support the bill and you work to defeat it, then if you are successful, you will have delivered $1 billion to the Republicans, thereby handing them the resources to dominate for the next decade. Thus there is no gain in opposing the bill if the Republicans are supporting it. Now, if the Republicans are against it and you support it, then you have the chance of making $1 billion.
Thus whatever the Republicans do, the Democrats should support the bill. Of course, the same logic applies to the Republicans. They should support the bill no matter what the Democrats do. In the end, both parties support the bill, and our billionaire gets his proposal for free. As a bonus, Buffett notes that the very effectiveness of his plan “would highlight the absurdity of claims that money doesn’t influence Congressional votes.”
This situation is called a prisoners’ dilemma because both sides are led to take an action that is against their mutual interest. In the classic version of the prisoners’ dilemma, the police are separately interrogating two suspects. Each is given an incentive to be the first to confess and a much harsher sentence if he holds out while the other confesses. Thus each finds it advantageous to confess, though they would both do better if each kept quiet.
From the book The Art of Strategy. Great book.
You remove them from the system. This is why we have a process through which the states can amend the Constitution.
This presumes every politician is equally dependent on outside financing. Self-financed and small-donation financed politicians would be politically incentivized to bunch together and knock the legs out from under the competition's money machine.
Politics is complicated. Condemning campaign finance reform is premature. (Saying it's a tough fight would be accurate.)
The other half, selling proposed legislation to one's own (and one's colleagues') constituents, involves the same process.
i'm not trying to make a political statement here, just an observation that the Democratic party is of two minds when it comes to tech nowadays. it didn't used to be this way. further evidence of an emerging political realignment.
They're both screw-ups. If someone breaks into your house, we don't say "first let's solve peace in the Middle East; then we'll talk about your house."
Something being second (or further down the list) doesn't mean it should be ignored. It's just another reason to look at the issue.
Google is more politically vulnerable than Equifax because more people know what it is. That makes it a better whipping boy for getting public support behind any resulting legislation.
There is a case to be made that tech companies hoarding sensitive data should have heightened disclosure requirements around confirmed and potential breaches. It doesn't have to be a public process. But maybe there should be some process.
Regarding "it's just a bug," I personally disagree. A bug that takes down the video player is different from a bug that could expose data. ("Could expose" isn't language we like to use in technology, but the law is fine with such ambiguity.)
Analogy: we don't wait for bridges to fail before giving a damn about the cracks. Google et al have never been treated as critical infrastructure. This is a discussion about whether that should change.
While I agree that not all bugs are the same level of severity, if there is no evidence of abuse of a bug, and it has been fixed, I see no reason to have them disclose it in any way. It would be akin to forcing companies to disclose when they repremand an employee, or when they change an internal HR process to avoid interpersonal problems.
Oh, and are we going to be mad at Google for purging logs now? I thought our hobby horse was Google retaining unneeded logs, but I guess it's even more fun to be mad at them for both so we can be mad no matter what they do.
Who said mandatory public notices? There are lots of options between staying silent and broadcasting every bug.
One is the known burglary of your hotel room with your items for sale online. The other hotel used locks that could be bypassed, but only has security footage saved for the last month to show you weren't robbed then.
I'm not disagreeing with you. I'm just saying these are both examples of privately-owned American digital infrastructure being vulnerable. In one case, we have evidence of a breach. In the other, we do not.
Taken together, these cases don't argue against each other. They argue together. That's why this is getting Congressional attention. The "how dare they ask these questions" tone on this thread, while understandable given how most of us earn our keep, is a bit off the mark.
Nah, first hold OPM accountable then we'll talk about the private sector.
Do I also need to publish if I left my keys in the door for two hours, but nobody broke in?
And if you're responsible for storing personal data for millions of people in your home, and you left the keys in the door for a few hours, and you can't prove that nobody broke in, then maybe you should let people know that there's a chance their data has been compromised.
This applies to almost every security-related bug ever, so the analogy holds.
If you run a company with PII in your mysql, and mysql has a bug (not uncommon), are you now required to tell all your customers that someone may have hacked your database, and then erased the logs?
What if you irresponsibly didn't have a firewall (or your firewall allowed connections from business partners, to some non-PII tables)?
It's possible that between the time the bug was introduced (or made public), and the time you patched, that someone at your business partner stole personal information, and it's not feasible for you to in all cases know if this happened. No matter how good you are, it's not feasible in the real world.
> And if you're responsible for storing personal data for millions of people in your home, and you left the keys in the door for a few hours, and you can't prove that nobody broke in, then maybe you should let people know that there's a chance their data has been compromised.
Maybe I should. And in this case, I did. But not right away.
But it's a long way from "maybe you should" to "you MUST (by power of law) IMMEDIATELY".
Read up on some "keys left in the door" scenarios about nuclear weapons security. We tend to not find out about those right away either.
Has anybody actually proposed this? There are a lot of options between staying silent and public disclosure.
Off the top of my head, for companies above a certain threshold:
* Require disclosure to senior management. If Nest finds a serious bug, they have to Cc someone upstairs in Alphabet.
* Require disclosure to the Board.
* Encourage disclosure to a federal agency in exchange for limited liability if a breach using the vulnerability is later discovered.
I don't know. But I think it's worth a discussion.
The first 2 are basically unenforceable, and depending on the definition would happen so often as to make it easier to hide real issues, or would only happen when a public disclosure should happen, like user data was compromised. (I say "should" because I'm not sure if it's required in the US right now, and if it's not I absolutely think it should be).
The last one makes this situation worse, as now the incentive to correctly fix it is gone. Who cares if further issues with the fix are found? Their liability is limited, so they can half-ass whatever fix they want and be safe. Not to mention that it basically requires the federal agency to have full access to the source and development of all (I'm assuming publicly traded) companies code. Even if I trusted the agency with that information, now it's another target for attackers, and it still doesn't do anything to make code safer for the user.
I understand those were just discussion points or suggestions you are putting out there, and I get that you don't claim to have all the answers at this point, but I genuinely don't see any way that this can help the user in any way at all.
Edit: immediately after posting this I had a thought from re-reading your comments. I'd be open to an "OSHA for programming". An agency or group which creates guidelines or rules you must follow to safely handle data in companies. However I think we would need to be VERY careful to not enforce specific ways of working or specific algorithms to avoid a cryotographic monoculture or codify exploits into the law. And it would need to target only practices which are grossly negligent to avoid being a "shutdown any company at any time" button.
I'm honestly not sure it's possible to make a group like that and ensure it doesn't get out of control, or become so toothless it's just a waste of money. But if that's what you were trying to say, I can see the merit in the idea, but I still don't think it's a good idea.
You are not a giant company that stores the personal data of hundreds of millions of people. So, presumably, no.
Headlines like "500 000 people at risk! The bug was so serious that Google shuts down their social network!" just write themselves.