Hacker News new | ask | show | jobs
by tmorton 3696 days ago
Here's an important difference.

The 18F post says:

"we reviewed all Google Drive files shared between Slack and Drive, just to be sure nothing was shared that shouldn't have been. Our review indicated no personal health information (PHI), personally identifiable information (PII), trade secrets, or intellectual property was shared."

While the OIG report says:

"[the integration] permitted full access to over 100 GSA Google Drives, resulting in a data breach."

2 comments

(I work at 18F but am speaking personally). I would point out this FedScoop article that discusses how the OIG defines "data breach:" http://fedscoop.com/18f-slack-gsa-ig-oauth-20

> situations where persons other than authorized users with an authorized purpose have access or potential access to PII

There's a difference in emphasis, but not of fact. Full access to over 100 drives does not mean they were actually accessed.