Google shuts down Google+ for consumers due to bug found months ago
Full article640 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
In March, Google found that a flaw in its Google+ People API exposed data including name, email address, occupation, gender and age. "We found no evidence that any profile data was misused," the company said.
Google has decided to shut down consumer use of its Google+ social network after an internal privacy review discovered a flaw that exposed non-public profile data through its API, the company announced Monday.
Discovered in March, Google found that a flaw in its Google+ People API exposed data including name, email address, occupation, gender and age. The company said it doesn’t have a concrete number on how many people were affected because the API log data is only kept for two weeks at a time. However, during a two-week testing period before the company closed the bug, profiles of up to 500,000 Google+ accounts were potentially affected, and up to 438 applications may have used the API, Google said.
“We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any profile data was misused,” a Google blog post reads.
Despite finding the bug in March, the company has only made the exposure public as Monday. The company states in the blog post that its privacy office examined the type of data involved, whether it could inform users, evidence of misuse, and if developers or users could do anything in response.
“None of these thresholds were met in this instance,” the company states.
Google launched Google+ in 2011 as an attempt to start its own social network to compete with Facebook and Twitter. At its height in 2012, the service had more than 90 million users. However, the service floundered in comparison to its rivals and the company changed the product’s focus in 2015.
The privacy review that discovered the flaw, known as Project Strobe, also resulted in Google changing a number of permissions with regards to how users grant permission to how apps collect data. The company is also launching more granular Google Account permissions, limiting apps’ access consumer data within the company’s email products, and mobile apps’ ability to receive Call Log and SMS permissions on Android devices.
The data exposure comes as big time social networking companies have had security incidents of their own. Last month, Twitter announced an API flaw inadvertently leaked sensitive data to other developers, including direct messages and protected tweets. A week later, Facebook disclosed a bug that allowed for attackers to steal digital access tokens.
This is a developing story. It will be updated as information becomes available.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/google-plus-data-exposure-api/