Live data from Hacker News

Google Calendar Unexpectedly Leaks Private Information

shkspr.mobi

61–70 of 138 posts

Re: Google Calendar Unexpectedly Leaks Private Information

#61
post #44

Earlier quoted context omitted.

Generally speaking you might be right, but I fail to see the profit motive behind this specific case. It's just a UX disagreement it seems.

This is simply one expression of the corporate protocols in which privacy does not exist. It's not a bug. It's not an honest mistake. It is an implementation detail of a higher level abstraction.

... or it's just the statistical certainty of having a disagreement over a feature implementation in a multi-featured app which in turn is a part of larger app suite, which is a part of a even bigger software infrastructure.

Re: Google Calendar Unexpectedly Leaks Private Information

#62

Earlier quoted context omitted.

This seems like a business opportunity -- come up with a steady stream of "security issues," then use the resulting access to provide paid customer service for GOOG.

You can get great paid GOOGLE customer service if you just sign up for Google Apps.

I did sign up. My customer service experience was robotic at best and didn't help me. I canceled the account.

Re: Google Calendar Unexpectedly Leaks Private Information

#63
post #20

This is not a "private information leak." It's expected behaviour. Entering information in that field to create a new event results in Google Calendar parsing your information as best as it can, to automatically set things like the date, time, event description and of course, the participants (the apparent privacy leak here.)

If you're aware of the feature, it's not a privacy leak. If you aren't, it could be very damaging. It would have been nice if the first time the Calendar parsed and sent emails on behalf of a user, it would ask if this is what they wanted. It doesn't have to bug them ever again, but that's a single instance of training that would minimize confusion.

Agreed. A simple confirmation popup is a quick fix which might prevent a lot of headaches.

Re: Google Calendar Unexpectedly Leaks Private Information

#64

Privacy, where it exists, creates impedance in Google's cash flow because it requires designing for some n sigma tail where n does not entail statistical significance and the case analysis must be very fine grained. Google doesn't have a category labeled "private" information". It never has and creating one is not planned. Privacy is not amenable to computer science. It is a social concept not a technical one. The cl…

Yes, but how does this particular privacy leak benefit Google? Google wants to have all your information themselves. Why would they want to give that info to your boss?

This sounds like somebody being really clever and whipping up a fancy feature, but forgetting to finish it with proper meeting requests and a freaking confirmation box and whatnot.

The idea itself is good - check for email addresses in meeting information and tying those to a Google account as invites. The problem is that the user isn't asked.

Re: Google Calendar Unexpectedly Leaks Private Information

#65
post #44

Earlier quoted context omitted.

Generally speaking you might be right, but I fail to see the profit motive behind this specific case. It's just a UX disagreement it seems.

This is simply one expression of the corporate protocols in which privacy does not exist. It's not a bug. It's not an honest mistake. It is an implementation detail of a higher level abstraction.

Of Course this isn't a bug- It's a feature. the only problem is that there isn't a confirmation screen when it detects that you have put a person's email address in the incorrect spot. All that is needed is for a popup to ask "Would you like to send this event to email@example.com?".

Re: Google Calendar Unexpectedly Leaks Private Information

#67
post #7
post #5

Earlier quoted context omitted.

God I love the idea of ownCloud so much but secretly hope it's not written in PHP. I run a wordpress site for 3 years, and one day a hacker took my site over with a bug from a plugin.

Indeed, that's proof that PHP is bad. And that all other frameworks in other languages don't have bugs that can be exploited.

(cough yaml parser cough) ... indeed.

Re: Google Calendar Unexpectedly Leaks Private Information

#69
post #3

The worst thing about things like this happening is the feeling of helplessness when you can't reach anyone in the company or when they just say "it's not a problem".

Or the company shill shows up and burns through four HN accounts trying to spread FUD. https://news.ycombinator.com/threads?id=ritikk https://news.ycombinator.com/threads?id=ritikk2 https://news.ycombinator.com/threads?id=ritikk3 https://news.ycombinator.com/threads?id=ritikk4 (Should I add the 5th link or wait for him to create that ID as well?)

If they work for Google, I wish they'd say so in their HN profile, or a comment. And if they don't, they should probably clear that up, too.

Re: Google Calendar Unexpectedly Leaks Private Information

#70
A good friend told me once: " the moment you enter info in an electronic device, you can assume it's public ".

It was in response to me getting a pic of him wearing red thongs (dont' ask), but the point stands in regards to Google, any email account, your PC, your phone, and everything else.

Post reply on HN