XSS Hole In Google Apps Is "Expected Behavior"
You know, just when I think I'm being a super nice guy, and I go out of my way to go through responsible disclosure, I am slapped in the face with the exact reason why I don't think responsible disclosure works for some companies.
Context & Ripple Effects
This is the third time ha.ckers.org has documented Google shipping with cross-site scripting flaws: the site covered an XSS vulnerability in Google back in July 2006 and returned to the theme in June 2007 with its "XSS Irony" post. What changed this time is not the flaw but Google's response — a researcher who followed responsible disclosure says the company classified the reported hole in Google Apps as "expected behavior," effectively declining to fix it.
The story travelled beyond the security blog circuit the same week, with InfoWorld picking it up under a framing aimed at mainstream readers: Google Gadgets can be misused by phishers. For a vendor whose hosted-applications business depends on enterprise trust, having a rejection of a responsibly disclosed bug become the story is the reputational risk.
First-order effects
- The disclosed XSS vector in Google Apps stays exploitable as long as Google treats it as intended behavior, leaving phishers a scriptable entry point into a trusted domain — the exact misuse InfoWorld's coverage highlights for Google Gadgets.
- The researcher publicly concludes responsible disclosure failed him here, which puts his future findings — and those of readers who take the same lesson — on a path toward publication without vendor sign-off.
Second-order effects
- Other vendors now face researchers who arrive pre-cynical: after Google brands a confirmed XSS "expected behavior," the implicit bargain of quiet fixes weakens across the industry, raising the odds that the next disputed bug goes straight to public posting.
- Enterprise buyers evaluating hosted suites get a fresh data point that Google's application-security posture lags its brand, giving competitors like Microsoft a trust argument in SaaS sales conversations without spending a dollar of their own.
Third-order effects
- If large platforms keep classifying script-injection flaws as acceptable, the dispute shifts from any single bug to who defines severity — pushing the industry toward formalized disclosure policies, response-time commitments, and eventually paid vulnerability programs rather than ad-hoc goodwill.
- Persistent XSS in trusted domains accelerates the argument that browser-level and platform-level defenses, not per-bug patching, are the only scalable answer — the position ha.ckers.org has been building since at least its 2006 Google write-up.
The trend: Vendor dismissal of cross-site scripting as low-severity "expected behavior" is eroding the responsible-disclosure norm and pushing the security community toward public disclosure and structural defenses instead of private fixes.