I think I would normally disagree with a govt. agency using a cloud platform, but it might actually be MORE secure than what they can do themselves.
I think I would normally disagree with a govt. agency using a cloud platform, but it might actually be MORE secure than what they can do themselves.
Heather Adkins who leads security (and is one of those ultra-longtimers) brought a number of senior eng for internal, ultra-private meetings where they showed the eng leadership exactly what had happened. I wasn't invited but at that time, sat near the exit door and their faces were just ... aghast at the consequences of what had just happened as a function of the systems they built.
The snowden dumps also showed that the NSA had packet traces of BigTable RPCs which was quite an eye-opener and definitely sped up privacy projects.
I knew wikipedia was going on a dangerous path, but I didn't know they had fallen so low. I'm talking about calling the entities involved in that affair as "belligerants" and also having the lack of tact of writing about "Casualties and losses" (in a non-ironic manner, I suppose).
A lot of people have selective memory when it comes to security issues.
And those breaches are multimillion record breaches.
The China one was bad enough for google to terminate the entire link to china and pull out entirely.
I can't find the article now but it had a picture of an NSA presentation with what was obviously a bigtable RPC (spend enough time debugging protocol buffers and stubby). From what I can glean, it seems likely that they tapped an undersea cable carrying Google's traffic between a frontend and a backend, although that's speculation.
[1] https://www.blackhatethicalhacking.com/articles/hacking-stor...
Ninja edit: seems like dekhn just confirmed what I said above
Have Amazon or Apple had a major breach?
(I do think Google takes security atypically seriously, though)
Apple only has if you count exploits that allow for hacking Macbooks and Iphones as far as I know (and I wouldn’t count that personally).
citation needed
I mean if users followed best practices it won't have been possible [2]
---
[1] which could be known more easily than if you are a celebrity
[2] Not trying to defend Apple here or absolve them of responsibility, but trying to differentiate a product hack (design choice and social engineering) from a pure technical compromise like a RCE or speculative execution which is developer purview and more interesting.
> nothing like those million record breaches that EVERYONE is afflicted by.
Why do you think that? Google has had several major breaches.
There was a google+ bug that exposed info on 52.5 million users, one on 500,000 users' data, and other disclosures. There have also been corrupted apps on the play store, like Brain Test that infected at least a million devices with difficult to remove malware. A decade ago there were about 5 million Google passwords leaked online.
That's just what I can recall atm.
There was a vulnerability discovered internally by Googlers. There's no evidence it was exploited.
>A decade ago there were about 5 million Google passwords leaked online.
Those weren't taken from Google. They were stolen from somewhere else (possibly multiple places). Less than 2% were val
Disclosure: I work at Google.
[1] https://security.googleblog.com/2014/09/cleaning-up-after-pa...
They continue to fail badly on all three of those fronts from an end user perspective. However, most of their problems on that front are self-inflicted / intentional cost saving / revenue generating.
Edit. Examples:
Sent box message injection in gmail getting (edit: people) fired. People sneak a forged sexual harassment message (or whatever) to the victim past the gmail spam filter, put the victim's address in the from header, and then corporate IT checks the account, sees the "outgoing" message in the victim account and fires the victim.
Google drive data loss (many examples in web search results).
Permanent account lockouts through no fault of the end user.
Their entire targeted ad business.
Malicious you tube take downs.
...and dozens of other examples
Alternatively... They could just not route inbound messages to "sent".
What possible reason would enterprise customers have to demand that certain incoming messages get black holed into a folder that no normal user will ever look at?
My best guess is something like outlook or other client integration for "legitimate" impersonation.
Google itself uses gmail in both of the ways I mentioned.
Personally, I'd be pretty pissed if a tool injected into my sendbox instead of sending an (optional) copy of whatever it generated to my inbox.
On the other hand, I know how to set up filters.
Anyway, it has been a half-decade since I gave up on figuring out what fresh UI hell gmail has shipped each year. (I autoforward whatever must be sent to gmail elsewhere, and set up a logical contradiction email filter to nerf their broken and mandatory spam filter).
I guess if random systems are sent box injecting me, then I'll lose the emails. Oh well.
https://www.theguardian.com/technology/askjack/2018/jun/28/c...
It sounds like there are third party G Suite tools that force you to enable delegated access (from the article, it is unclear if this is possible for personal accounts).
On top of that, some manage to enable it without prompting. Yet, somehow, Google let them keep their API keys.
Nice.
Wow, that's pretty loaded. Is this some kind of no true Scotsman situation?
"Matters" in this context was related to national security concerns.
Hate to burst your bubble..
https://www.washingtonpost.com/world/national-security/chine...
[1] https://www.washingtonpost.com/world/national-security/nsa-i...