Live data from Hacker News

Google Exposed User Data, Feared Repercussions of Disclosing to Public

wsj.com

271–277 of 277 posts

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#272

non-paywall version: http://archive.is/rpuA1

Or we could support the authors -- Let's not make HN the kind of community that encourages posting ways around paying journalists for their work on articles that keep our industry in check.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#273
post #272

non-paywall version: http://archive.is/rpuA1

Or we could support the authors -- Let's not make HN the kind of community that encourages posting ways around paying journalists for their work on articles that keep our industry in check.

Giving a random american company my payment details is unfortunately asking too much.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#274

Earlier quoted context omitted.

Jeez, just run your own resolver instead of dumping all your internet access data on $AntiPrivacyCo.'s reception desk.

They anticipated this reaction and have made some significant privacy promises about the data they receive via Google Public DNS: "We delete [the] temporary logs [which include your full IP address to identify things like DDoS attacks and debug problems] within 24 to 48 hours." "In the permanent logs, we don't keep personally identifiable information or IP information. After keeping [the data we do keep] for two week…

The key point in all the beautiful promises Google makes is that you need to extend then with "for now". That summarises the healthy skeptical stance, especially when it is about a company that should have given you plenty of examples about why we shouldn't trust them.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#275

Earlier quoted context omitted.

They anticipated this reaction and have made some significant privacy promises about the data they receive via Google Public DNS: "We delete [the] temporary logs [which include your full IP address to identify things like DDoS attacks and debug problems] within 24 to 48 hours." "In the permanent logs, we don't keep personally identifiable information or IP information. After keeping [the data we do keep] for two week…

The key point in all the beautiful promises Google makes is that you need to extend then with "for now". That summarises the healthy skeptical stance, especially when it is about a company that should have given you plenty of examples about why we shouldn't trust them.

In the past, I would agree with you, but with the recent legislative push for privacy around the world, especially in the EU, I doubt very much that any company as big as Google will be able to have much wiggle room to make privacy policies weaker in the future.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#276

Earlier quoted context omitted.

They anticipated this reaction and have made some significant privacy promises about the data they receive via Google Public DNS: "We delete [the] temporary logs [which include your full IP address to identify things like DDoS attacks and debug problems] within 24 to 48 hours." "In the permanent logs, we don't keep personally identifiable information or IP information. After keeping [the data we do keep] for two week…

The key point in all the beautiful promises Google makes is that you need to extend then with "for now". That summarises the healthy skeptical stance, especially when it is about a company that should have given you plenty of examples about why we shouldn't trust them.

Having seen how Google operates on the inside, I trust them to be fully able and willing to comply with the promises they do make, better than most companies. The typical tech startup overpromises and underdelivers with respect to data deletion and security, or simply does a really weak job at those things without making any promises either way.

Adhering to these promises is a separate question from changes of policy in the future, of course, and just as separate from failures in the areas of product design or ethics. Many parts of the conglomerate that calls itself Google have gotten worse in all of those areas over the last several years, though I am still a big fan of how GCP is progressing.

But none of this makes me think that they're retaining more Google Public DNS data than they claim. Given how little of that data they retain for the long haul, the risk of bad retroactive impact from a change in policy in this area is quite low. The risk is admittedly higher for other consumer services which do retain identifiable data over a long period of time.

Conversely, the risk is lower for G Suite and GCP offerings and for European residents, given the concerns and compliance obligations of business customers and the obligations imposed by the GDPR.

Re: Google Exposed User Data, Feared Repercussions of Disclosing to Public

#277
post #250
post #105

Earlier quoted context omitted.

Wow. “We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks.” The wording of this is really pushing the boundary of plausibility. I fail to understand the logic of how this would protect privacy? Access logs with no profile data logged would not compromise privacy would it? Can anyone confirm the timing of the google blog post? It seems the WSJ article was posted at a similar…

>Goog is trying to avoid using the words Data breach as they may get into hot water in EU. As far as GDPR goes technically this breach happened right before they would have faced large repercussions from it.

It sounds like it came up as a result of their Project Strobe audit. I would guess they launched this project precisely because the penalties were about to get bigger and they knew they had skeletons.
Post reply on HN