Google Shuttering Google+ for Consumers After Undisclosed Data Exposure

    The Google+ social network that Google introduced back in 2011 suffered from a major bug that Google opted not to disclose to the public, reports The Wall Street Journal.

    A Google+ software glitch provided outside developers with the ability to access private Google+ profile data from 2015 to March 2018. In the spring of this year, internal investigators discovered the issue and fixed it.

    The problem was caused by a bug in a Google+ API designed to let app developers access profile and contact information about the people who signed up to use their apps. Google found that Google+ was also allowing developers to access the data of users who had their profiles set to private. Up to 438 apps had access to customer data.
    In an internal memo, Google's legal staff recommended against disclosing the bug because it would invite "immediate regulatory interest" and result in a comparison to Facebook's Cambridge Analytica scandal.

    Data from hundreds of thousands of users was potentially accessible, but Google did not discover misuse of the data by outside developers. Exposed data included names, email addresses, birth dates, gender, profile photos, places lived, occupation, and relationship status.

    Phone numbers, email messages, timeline posts, and direct messages were not accessible.

    As a result of the data exposure, Google today announced that it is shutting down Google+ for consumers and introducing new privacy measures. According to Google, it put together a privacy task force called Project Strobe at the beginning of the year to review the company's APIs.

    Buried in a long document describing all of the privacy changes being implemented, Google confirms that a Google+ bug made private Google+ content accessible to developers.

    Google explains that it did not opt to disclose information about the exposed data back in March because there was no evidence of misuse and no action a developer or user could take in response.
    Google is planning to shut down Google+ over a 10-month period, with the social network set to be sunset next August.

    In addition to shutting down Google+, Google is introducing several other privacy improvements. More granular controls will be provided for granting Google Account data to third-party apps, and Google is going to limit the number of apps that have access to consumer Gmail data.


    For Android users, Google will limit the apps able to access Call Log and SMS permissions on Android devices, and contact interaction data will no longer be available through the Android Contacts API.

    Google's full list of privacy changes can be found in its new Project Strobe blog post.

    You will struggle to get me to believe Google+ ever had “thousands” of users...
    I had high hopes for it originally but it didn’t take long to realize it was never going to take off. Surprised it took this long to pull the plug.
    Wait, it was still alive? I thought it was dead years ago :eek:
    Google+ was DOA, seemed futile the day it was announced. Glad I never signed up and never had my data breached from it.
    It was dead the day it came out and it has remained that way. The only reason it has as many "users" as it does is because it forced a lot of people into it through YouTube, etc and none of them have ever posted anything.
    Choosing to intentionally not disclose a data breach is the lowest of the lows.
    surprising that something as large as G+ prompted me to think, "Google+ is still a thing?"
    Man. First Ping and now G+?

    See you guys on MySpace!
    All 3 of them.
    Google mutters, "plus it would make us look bad, for no reason." Yes, telling the truth might make people further question whether handing you large amounts of information is a good idea.
    Google is a threat to industry security. They have no problem calling out other companies and their security issues, sometimes before even alerting said company.

    But when their own products have security issues, let's sweep it under the rug.
    Once again Google ****s with peoples data and nothing happens.
    Imagine if Apple did something like that, the coverage would be HUGE.
    No social network will ever survive if they do not allow to freely claim and/or change one's username

    Snapchat didn't listen, and now they're on their deathbed
    "In an internal memo, Google's legal staff recommended against disclosing the bug because it would invite "immediate regulatory interest" and result in a comparison to Facebook's Cambridge Analytica scandal."
    Seriously. Hopefully some non-immediate regulatory interest and backlash will come their way over this. Reminds me of Yahoo sitting on their data breaches.
    It was utter garbage and never made any sense. It was horrible to navigate and for the 60seconds I tried it for, it was incredibly difficult to see what of my data would be private and public.

    They would have been better off coming up with an eBay alternative rather than this garbled mess. Considering how quick they are to shutter other useable projects it was a surprise how it survived. Probably forgotten by even them.

    The lucky thing is that the data breach would have surely been comparatively non-existent compared to the likes of Yahoo! who took it further and actually lied (I am still not entirely clear why Marissa Mayer isn't in jail after the part disclosure of their breach during the sale of Yahoo!) so I don't imagine there is going to be a massive backlash on this one.

    Not unless Taylor Swift decides to weigh in that is....
    Oh, jeez, somebody should really send this to the person that uses Google+. They're not going to be happy.
    I came to the conclusion long ago that my data is never going to be safe. For every paid 9-5 'security expert' working to keep something safe there is a more committed guy/girl at home working harder, longer hours for no pay to find what the 'experts' have missed.
    Well that sucks. Not surprising though. G+ has been languishing for a while. I'm one of a few remain users. Time to detach myself from the Googleverse completely.
    I always hated it and how it randomly connects to their other services like you are on YouTube or MyBusiness, go into the settings and suddenly and up on Google+ like huh?
    But Google: We can't trust you, because you don't actually do what you say, or say what you actually do. No relationship is possible without trust. Your integrity is zero.

