/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

XSS Hole In Google Apps Is "Expected Behavior"

You know, just when I think I'm being a super nice guy, and I go out of my way to go through responsible disclosure, I am slapped in the face with the exact reason why I don't think responsible disclosure works for some companies.

ha.ckers.org web application security lab RSnake

Context & Ripple Effects

This is the third time ha.ckers.org has documented Google shipping with cross-site scripting flaws: the site covered an XSS vulnerability in Google back in July 2006 and returned to the theme in June 2007 with its "XSS Irony" post. What changed this time is not the flaw but Google's response — a researcher who followed responsible disclosure says the company classified the reported hole in Google Apps as "expected behavior," effectively declining to fix it.

The story travelled beyond the security blog circuit the same week, with InfoWorld picking it up under a framing aimed at mainstream readers: Google Gadgets can be misused by phishers. For a vendor whose hosted-applications business depends on enterprise trust, having a rejection of a responsibly disclosed bug become the story is the reputational risk.

First-order effects

  • The disclosed XSS vector in Google Apps stays exploitable as long as Google treats it as intended behavior, leaving phishers a scriptable entry point into a trusted domain — the exact misuse InfoWorld's coverage highlights for Google Gadgets.
  • The researcher publicly concludes responsible disclosure failed him here, which puts his future findings — and those of readers who take the same lesson — on a path toward publication without vendor sign-off.

Second-order effects

  • Other vendors now face researchers who arrive pre-cynical: after Google brands a confirmed XSS "expected behavior," the implicit bargain of quiet fixes weakens across the industry, raising the odds that the next disputed bug goes straight to public posting.
  • Enterprise buyers evaluating hosted suites get a fresh data point that Google's application-security posture lags its brand, giving competitors like Microsoft a trust argument in SaaS sales conversations without spending a dollar of their own.

Third-order effects

  • If large platforms keep classifying script-injection flaws as acceptable, the dispute shifts from any single bug to who defines severity — pushing the industry toward formalized disclosure policies, response-time commitments, and eventually paid vulnerability programs rather than ad-hoc goodwill.
  • Persistent XSS in trusted domains accelerates the argument that browser-level and platform-level defenses, not per-bug patching, are the only scalable answer — the position ha.ckers.org has been building since at least its 2006 Google write-up.

The trend: Vendor dismissal of cross-site scripting as low-severity "expected behavior" is eroding the responsible-disclosure norm and pushing the security community toward public disclosure and structural defenses instead of private fixes.