52.5 million users affected in new Google Plus data breach 2018
Google disclosed the data leak, which it said potentially affected up to 500,000 accounts. Up to 438 different third-party applications may have had access to private information due to the bug, but Google apparently has no way of knowing whether they did because it only maintains logs of API use for two weeks.
“We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any profile data was misused,” Ben Smith, the vice-president of engineering, wrote in the blogpost.
“Google is right to be concerned and the shutdown of Google+ shows how disposable things really are in the face of accountability,” he said.
For others, the leak was further evidence that the large technology platforms need more regulatory oversight.
“Monopolistic internet platforms like Google and Facebook are probably ‘too big to secure’ and are certainly ‘too big to trust’ blindly,” said Jeff Hauser, from the Centre for Economic and Policy Research.
He argued that the US Federal Trade Commission should move toward “breaking these platforms up”.
“In the interim, since we cannot trust that we know much or even most of what ought to concern the public, the FTC should install public-minded privacy monitors into the firms as an element of accountability.”
Google Minus
The vulnerability in Google+, which the company discovered and re-mediated in March, specifically related to one of the service's programming interfaces for third-party developers to access user profile data. Google says the bug exposed data like user names, email addresses, occupations, genders and ages, but the company found no evidence that anyone exploited it to steal user data, or misused the data in any of the 438 applications that might have used the API while the bug was live. The company found and investigated the flaw internally, rather than from an outside researcher, and opted not to disclose it until the Wall Street Journal report effectively forced them to.

Comments
Post a Comment