- Joined
- Apr 10, 2003
- Messages
- 22,793
A new Google+ API bug has been discovered and it affects 52 million consumers and enterprise customers. Google discovered the bug and believes that no app developers knew of or exploited the system in the 6 days that the bug was present. This discovery has made Google rethink the August 2019 shutdown date for Google+. A decision has been made to expedite the shutdown of the social media service to April 2019.
The consumer version of Google+ will be sunsetting in 90 days. Although the bug shared information that may have been set to not-public, it didn't share information such as financial data, national identification numbers, passwords, or similar data typically used for fraud or identity theft. We reported on the first security breach and closing of Google+ earlier this year.
With respect to this API, apps that requested permission to view profile information that a user had added to their Google+ profile--like their name, email address, occupation, age (full list here)--were granted permission to view profile information about that user even when set to not-public. In addition, apps with access to a user's Google+ profile data also had access to the profile data that had been shared with the consenting user by another Google+ user but that was not shared publicly.
The consumer version of Google+ will be sunsetting in 90 days. Although the bug shared information that may have been set to not-public, it didn't share information such as financial data, national identification numbers, passwords, or similar data typically used for fraud or identity theft. We reported on the first security breach and closing of Google+ earlier this year.
With respect to this API, apps that requested permission to view profile information that a user had added to their Google+ profile--like their name, email address, occupation, age (full list here)--were granted permission to view profile information about that user even when set to not-public. In addition, apps with access to a user's Google+ profile data also had access to the profile data that had been shared with the consenting user by another Google+ user but that was not shared publicly.