Live data from Hacker News

Google users locked out after 15 years' use

businessinsider.com

541–550 of 720 posts

Re: Google users locked out after 15 years' use

#541
post #168

Earlier quoted context omitted.

I'm trying to not make this sound harsh; but you really don't need a government regulator to tell you that centralising all your data with Google, who are providing largely free services, is risky. It is like building a house on the edge of a cliff then falling off the cliff one day. It was always a real possibility. Being locked out of your stuff is quite a likely end of the story with Google.

Google is huge and they run a vast portion of the internet now. If they were to suddenly decide that all FastMail accounts should go to spam tomorrow, any users of FastMail would be SoL—they would be unable to communicate with a huge majority of the internet. They could decide to randomly throw every 5th email that is not a gmail into spam and blame it on other providers having low reliability. Make it random enough…

I am for banning all spam technologies.

Re: Google users locked out after 15 years' use

#542
post #497

Earlier quoted context omitted.

Should it also be a requirement for the government to posts what preferences you look for in a partner on dating websites, what gender you prefer when searching for doctors, what race you prefer when looking for cleaning or child care assistance?

This is a ghastly and inhumane comparison. Companies aren't people.

Oh no, you have hurt the companies' feelings!

Re: Google users locked out after 15 years' use

#543

Earlier quoted context omitted.

Did you have access to the entire source code and understanding of all services running the system? Capping could have been done by a service created by a team you wouldn't have access to and without knowledge something like that even exist (and rightfully so, as it would take one whistleblower to harm the business). So I am not surprised you would write that there was no such facility.

> Did you have access to the entire source code and understanding of all services running the system? Near enough, yes. Sure, there are millions of lines of code, and I did not read every one, but I debugged enough issues that I'm sure I would have come across this capping effect if it existed and affected more than some dormant/test accounts.

It's possible to implement something like this and you wouldn't be able to find out, as a service sitting between the network and ad servers, it could even be embedded in an innocent looking load balancer. Why would you think something like that wouldn't exist?

Re: Google users locked out after 15 years' use

#544
post #524
post #397

Earlier quoted context omitted.

An interesting perspective, but GDPR also requires them to delete data according to policy. If, by their policies, the data should still be held, then you have the right to access it. If they deleted it contrary to policy, that would itself be a breach of GDPR, and you would likely have strong grounds to sue and seek relief. If the data was to be held pending court action and they deleted it, that could get even more…

I don't think that's correct. The GDPR retention policy sets out maximum retention time. The guiding principle is that data should only be retained as long as is required to serve the purposes for which it was collected. So if your account is permanently terminated, there is probably an argument that GDPR requires the deletion of all data as soon as possible.

GDPR sets out a maximum retention time as you point out, but it also regards the act of "erasure or destruction" as a processing operation (Art 4(2)).

Recital 83 highlights the importance of preventing "accidental or unlawful destruction, loss, alteration" of data, and Art 5(1) says "Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’)"

I wouldn't want to be in Google's shoes in such a situation, as the principle of fairness and transparency would come to light, and I think it would be quite hard for them to argue against this.

You are also right that GDPR sets out principles of not retaining data for longer than is required (data protection by default), although all of these rights have to be balanced. If you could argue the deletion was not lawful, fair, or transparent, you would have a breach under Art 5(1).

The Art 20 right to portability would also be relevant here, around people's right to port a copy of their own data. Given the existence of these rights, a blanket "we nuked all your stuff" would deprive a person of reasonably exercising their rights, and I could envisage consequences for this.

It would be really interesting to see some of this get put to the test though - GDPR could become a way to force "human intervention" in some of these situations on the basis of not wanting exposure to unwanted legal risk.

Re: Google users locked out after 15 years' use

#545
post #269

Earlier quoted context omitted.

I recently wrote a step by step article about this, for people who might not know how, such as family members, et al. I chose ProtonMail (despite also being a FastMail customer) because I’m a bit concerned about the new Australian encryption key escrow mandate (which I assume affects FastMail) and I like ProtonMail’s “don’t store plaintext” approach, even if it does need special client software. https://sneak.berlin/…

How big a problem is this since emails are transported predominantly in clear text?

If you’re emailing other people on ProtonMail, it fetches their keys from the (presumed trustworthy) server, and does end-to-end encryption.

In that mode it’d at least as secure as iMessage (before Apple backdoored it by adding automatic key and plaintext escrow).

Most emails use TLS, so they’re encrypted on the wire between servers.

ProtonMail then encrypts the plaintext as soon as they receive it, for storage. It stays encrypted from that point until it reaches the client.

For most mail it’s not e2e, but it does cut down on the opportunities for the mail to get seized by anyone who can compel the provider to turn over their records.

Re: Google users locked out after 15 years' use

#546

Earlier quoted context omitted.

I used to work on adsense. There is no facility for an "earnings cap". Your revenue is the literal sum of earnings from every click on your property. While ads are showing and being clicked on, you will always be earning more. If I were to guess, you failed to implement ads.txt and/or your content didn't meet the standards required by some big advertisers, so auction pressure was very low for your site.

I've had similar issues with AdSense. Running a site for 10 years, and it was earning $250/day for years, then suddenly it dropped. For a while I had the same traffic and instead of 500 clicks a day Google would say I had 3 or 4 clicks. I contacted them, waited a month, and they said to label them "Advertisements" so users are not confused. Well, my site is mostly text based and I have at least 50px of space around a…

[deleted]

Re: Google users locked out after 15 years' use

#547
post #174

The second person lives in Britain. I wonder if he tried submitting a GDPR request, and if Google has any obligation to keep the data, or if they delete it immediately?

I wonder how Brexit fits into EU regulations.

The GDPR regulation is implemented into British law as the Data Protection Act 2018 [1]. It must remain until the end of the year. If there's "no deal" then, next year, the UK Parliament may repeal or modify it as it wishes.

However, there were data protection acts in 1998 and 1984, and it seems unlikely the general principle of access to personal data -- which was there before GDPR -- would be removed.

[1] https://en.wikipedia.org/wiki/Data_Protection_Act_2018

Re: Google users locked out after 15 years' use

#548
post #491
post #434

Earlier quoted context omitted.

The only thing worse than hanging your identity on @gmail.com is @comcast and the like. If you can, your own domain backed by a fastmail or a proton is the sweet spot of easy and flexible, or at least an @fastmail, @proton or similar. With payment comes the possibility of human support, which I have received easily from fastmail.

I have my email going to my own domain, but can’t figure out how to ground it out in anything other than someone else’s tld. So, now I’m in a situation where, if my gmail account gets banned, and the DNS provider decides to reset my password, then I’m permanently locked out of everything. I could point my DNS provider at my “real” email address, but that’s even worse, since needing to update the MX record could lock…

> I have my email going to my own domain, but can’t figure out how to ground it out in anything other than someone else’s tld.

What do you mean "ground it out"?

As a consumer, I suspect hosting a "holding" domain, and possibly email, with AWS Route53 DNS might be a sensible approach that wouldn't break the bank. AWS has policies on account and password recovery that even include a notarised affidavit.

It might help to further separate your AWS account from the Amazon account you use to shop with, since there's a chance Amazon might be trigger-happy with banning if you violate one of their shopping policies with too many returns.

Re: Google users locked out after 15 years' use

#549
post #491
post #434

Earlier quoted context omitted.

The only thing worse than hanging your identity on @gmail.com is @comcast and the like. If you can, your own domain backed by a fastmail or a proton is the sweet spot of easy and flexible, or at least an @fastmail, @proton or similar. With payment comes the possibility of human support, which I have received easily from fastmail.

I have my email going to my own domain, but can’t figure out how to ground it out in anything other than someone else’s tld. So, now I’m in a situation where, if my gmail account gets banned, and the DNS provider decides to reset my password, then I’m permanently locked out of everything. I could point my DNS provider at my “real” email address, but that’s even worse, since needing to update the MX record could lock…

Shouldn't you still be able to prove your identity to your DNS provider through your name, address, birth date, security questions, past correspondence, bank statements etc.?

Re: Google users locked out after 15 years' use

#550
post #194

Earlier quoted context omitted.

I have been managing my own mail server for 6 years now, and enabling and configuring all the mail security features (DKIM, SPF, etc), and keeping up with them, is indeed the most difficult part. I regularly check my mail server against tools like this: https://mxtoolbox.com/diagnostic.aspx . If you just do one thing wrong, you will end up on some black list from which it is very difficult to get off. So far, I did n…

This. So many people don't take the 10 minutes to configure DMARC, DKIM and SPF. I've been hosting my own domains since 1996 and I haven't ever had a problem with any of them sending mail to any of the big hosters. If your DMARC passes and you actually have a policy set to REJECT you're almost guaranteed to not have a problem as long as your domain isn't a few days old. The first thing I do for any new domain I plan…

> So many people don't take the 10 minutes to configure DMARC, DKIM and SPF.

Having just done this recently, it's more than 10 minutes, especially if it's your first time. But yes, everyone should be doing it, as well as doing their best to get off of blacklists[0]. Still doesn't stop incompetents like MS mail admins (so, @hotmail.com, @msn.com, @live.com and @outlook.com) from keeping their own internal blocklists, that you can't get off of, no matter how many times you fill out their form[1].

[0] http://multirbl.valli.org/dnsbl-lookup/

[1] https://support.microsoft.com/en-us/supportrequestform/8ad56...

Post reply on HN