Skip to main content
  • Google says a fix is coming for disappearing text messages on Pixel 3
    15.11.2018 - 0 Comments
    Are disappearing texts worse than disappearing photos? I don’t know, but both are things that consumers…
  • The ACLU is suing a California sheriff for blocking activists on Facebook
    31.01.2019 - 0 Comments
  • Facebook has been paying teens $20 a month for total access to their phone activity
    30.01.2019 - 0 Comments
    Facebook has run a program to collect intimate user data from paid volunteers for the past three years,…
  • House lawmakers want answers from Google on censored Chinese search engine
    14.09.2018 - 0 Comments
  • A robot that can peel lettuce takes us closer to automating delicate farm work
    26.09.2018 - 0 Comments
    There are lots of barriers to automating agricultural work. The cost of robots is one and the difficulty of…

Google hid major Google+ security flaw that exposed users’ personal information

Google exposed the personal information of users of its Google+ social network, the company announced in a blog post this morning. The news, originally reported by The Wall Street Journal ahead of Google’s announcement, means that Google+ profile information like name, email address, occupation, gender, and age were exposed, even when that data was listed as private and not public. However, Google says that it has no evidence to suggest any third-party developers were aware of the bug or abused it. The bug appears to have been active between 2015 and 2018.

The company says it closed the bug in March 2018 shortly after learning of its existence. The WSJ reports that the company chose not to report it because of fear of “immediate regulatory interest” that would lump Google in with Facebook, according to one source’s description of the incident. At the time, Facebook had just publicly disclosed that data mining firm Cambridge Analytica had illegally purchased tens of millions of users’ profile information from a third-party app maker, who had gleaned that information from people who logged into a personality quiz and inadvertently granted the app access to their friends list.

Google says it discovered the bug as part of an effort called Project Strobe, which was launched to “review of third-party developer access to Google account and Android device data and of our philosophy around apps’ data access,” according to Ben Smith, the blog post author and a vice president of engineering. As a result of the breach, the company is shutting down the consumer-facing element of Google+, noting that 90 percent of sessions lasted less than five seconds. About 500,000 user profiles were affected by the breach, Smith notes. The shutdown will take place over the course of the next 10 months, concluding in August of 2019.

Developing...



from The Verge - Teches https://ift.tt/2Ofj2EE

Comments

Popular posts from this blog

The PlayStation Classic has a secret debug menu that can be reached with specific keyboards

Just a day after the release of the PlayStation Classic , the Retro Gaming Arts YouTube channel has discovered that you can access the emulator’s settings menu by plugging a keyboard into a free USB slot and hitting the Esc key. Doing so reveals a host of settings for the built-in open-source PCSX ReARMed emulator, potentially allowing access to options, including save states, controls, and cheats. The discovery has raised hope that some of the criticisms of the retro console , such as a limited game library and poor image quality, could soon be addressed with third-party modding. In the discovered menus, an option to “Load CD Image” is clearly visible, which suggests it might be possible to load additional games or perhaps just the better-performing 60Hz NTSC variants. An option to enable scanlines, the horizontal lines that allow an LCD screen to emulate the look of a traditional CRT monitor, is also present. Despite the discovery, it’s unlikely that the hardware limitations o...

With Toys R Us gone, Amazon wants to send out a holiday toy catalog of its own

Now that Amazon has helped kill off Toys R Us , it wants to borrow the retailer’s iconic print holiday toy catalog . The online behemoth is interested in creating its own print catalog to mail out and also be handed out at Whole Foods (which it owns), according to Bloomberg . Toys R Us was plagued with billions in debt when permanently closed last month — in part because of competition from online stores like Amazon . For many kids, its “Big Book” toy catalog was a staple of fall. The 100-page catalog would arrive near the end of October for kids to look through and create a wishlist before December. Now that the retailer is done, various companies are trying to scoop up the customers that headed to their shelves every December. Party City, for example, will open 50 pop-up toy shops for the holidays. Target will have more store space for toys . It’s just especially amusing that Amazon, having helped kill off these physical retailers, is trying to learn from them to make even mor...

Amazon’s plans for a New York office are under new scrutiny

A month ago, when Amazon announced that it would build regional offices in New York and Virginia at great expense to the taxpayers there, I wrote that it had misunderstood the moment : Perhaps the furor over Amazon’s regional offices will blow over. But it’s hard not to feel today as if the company misread the room — overestimating the public’s appetite for a billion-dollar giveaway to one of the world’s biggest companies, and underestimating the public’s ability to raise hell on- and offline. Amazon may yet feel that pain, in the long run. Today, Amazon met the room: 150 protesters who showed up to the first New York City Council hearing about the plan. According to reports from the scene, demonstrators’ concerns start with the $3 billion in incentives that New York plans to give Amazon in exchange for locating there — and, it says, creating 25,000 jobs. Here’s Leticia Miranda in BuzzFeed : ”You’re worth a trillion dollars,” New York City Council Speaker Corey Johnson told the ...