Hindustan Times ST (Jaipur)

Google+ to shut following leak of users’ private info

- Reuters feedback@livemint.com

Google will shut down the consumer version of its social network Google+ after announcing data from up to 500,000 users may have been exposed to external developers by a bug that was present for more than two years in its systems.

The company said in a blog on Monday it had discovered and patched the leak in March of this year and had no evidence of misuse of user data or that any developer was aware or had exploited the vulnerabil­ity.

Shares of its parent company Alphabet Inc, however, were down 1.5% at $1150.75 in response to what was the latest in a run of privacy issues to hit the United States’ big tech companies.

The Wall Street Journal reported earlier that Google had opted not to disclose the issue with its Applicatio­n Program Interfaces (API) partly due to fears of regulatory scrutiny, citing unnamed sources and internal documents.

Google said it had reviewed the issue, looking at the type of data involved, whether it could accurately identify the users to inform, whether there was any evidence of misuse, and whether there were any actions a developer or user could take.

“None of these thresholds were met in this instance,” it said. “We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any Profile data was misused.” Under the European Union’s General Data Protection Regulation (GDPR), if personal data is breached, a company needs to inform a supervisor­y authority within 72 hours, unless the breach is unlikely to result in a risk to the rights and freedom of users.

“It seems like the downside risk of having a story that says they intentiona­lly hid informatio­n about a major breach from users is bigger than the upside of avoiding scrutiny,” said Geoffrey Parker, an engineerin­g professor at Ivy League college Dartmouth.

“I wonder if there wasn’t more depth to the internal debate.”

Google said a software glitch in the social site gave outside developers potential access to private Google+ profile data between a major redesign in 2015 and March 2018, when internal investigat­ors discovered and fixed the issue.

The affected data was limited to static, optional Google+ Profile fields including name, email address, occupation, gender and age.

The WSJ report said that a memo, prepared by Google’s legal and policy staff and shared with senior executives, warned that disclosing the incident would likely trigger “immediate regulatory interest” and invite comparison­s to Facebook’s leak of user informatio­n to data firm Cambridge Analytica.

Allegation­s of the improper use of data for 87 million Facebook users by Cambridge Analytica, which was hired by President Trump’s 2016 US election campaign, has hurt the shares of the world’s biggest social network and prompted multiple investigat­ions in the US and Europe.

BENGALURU/SAN FRANCISCO:

 ?? MINT ?? Google said it had discovered and patched the leak in March of this year and had no evidence of misuse of user data
MINT Google said it had discovered and patched the leak in March of this year and had no evidence of misuse of user data
 ?? REUTERS ?? Almost one million people in the country are currently “testing” the feature, said WhatsApp
REUTERS Almost one million people in the country are currently “testing” the feature, said WhatsApp

Newspapers in English

Newspapers from India