Live data from Hacker News

Is Facebook Really Scarier Than Google?

nautil.us

341–350 of 360 posts

Re: Is Facebook Really Scarier Than Google?

#341

Earlier quoted context omitted.

> No, they value their average user over you specifically. If the average user will gain more from Uber than from the feature you suggest, it is in Google's users' best interest to not implement that feature. No, they don't. They could make this an optional feature, and they choose not to. And I can't think of any way that preventing users from controlling there own data could be good for users. > Then you can certai…

>No, they don't. They could make this an optional feature, and they choose not to. If adding such an optional feature causes Uber to leave the Android platform, adding the optional feature is a net loss to Android users. "You are not the user" rings true here. To put this another way, if your "feature" harms the ecosystem, it is not, in fact, a feature. I asked for examples of Google lying about data collection, whic…

> If adding such an optional feature causes Uber to leave the Android platform, adding the optional feature is a net loss to Android users. "You are not the user" rings true here.

That's a big if. I highly suspect that Uber wouldn't want to leave one of the biggest platforms just because of a simple option that might already exist. What if Uber demanded to be able to have root on Android phones? Would Google be willing to bow to that because losing them would be a "net loss to Android users"?

I'd have to ask you to point out why giving user's more ways to manage their data "harms the ecosystem".

> I asked for examples of Google lying about data collection, which was the accusation you levied. You responded with Google being transparent about responding to legally binding government requests.

Yeah. I did. It doens't matter why they lie, it matters that they lie. Especially If they are willing to lie to me about how they use my data, they why wouldn't they be willing to lie to me about how they collect my data? And I fully admit that I have no direct proof of them lying about how they collect data, but I don't see why you would trust a company that regularly lies to it's users about what it does with that data.

Re: Is Facebook Really Scarier Than Google?

#342

Earlier quoted context omitted.

>No, they don't. They could make this an optional feature, and they choose not to. If adding such an optional feature causes Uber to leave the Android platform, adding the optional feature is a net loss to Android users. "You are not the user" rings true here. To put this another way, if your "feature" harms the ecosystem, it is not, in fact, a feature. I asked for examples of Google lying about data collection, whic…

> If adding such an optional feature causes Uber to leave the Android platform, adding the optional feature is a net loss to Android users. "You are not the user" rings true here. That's a big if. I highly suspect that Uber wouldn't want to leave one of the biggest platforms just because of a simple option that might already exist. What if Uber demanded to be able to have root on Android phones? Would Google be willi…

You haven't actually shown an example of them lying though. Are you saying that complying with lawful requests for data, as Google explicitly stares it will do and then publicly announcing the ways it complied, as well as when lawful, announcing to the affected users, is lying? I find that difficult to believe.

Re: Is Facebook Really Scarier Than Google?

#343

Earlier quoted context omitted.

> If adding such an optional feature causes Uber to leave the Android platform, adding the optional feature is a net loss to Android users. "You are not the user" rings true here. That's a big if. I highly suspect that Uber wouldn't want to leave one of the biggest platforms just because of a simple option that might already exist. What if Uber demanded to be able to have root on Android phones? Would Google be willi…

You haven't actually shown an example of them lying though. Are you saying that complying with lawful requests for data, as Google explicitly stares it will do and then publicly announcing the ways it complied, as well as when lawful, announcing to the affected users, is lying? I find that difficult to believe.

> Are you saying that complying with lawful requests for data, as Google explicitly stares it will do and then publicly announcing the ways it complied, as well as when lawful, announcing to the affected users, is lying?

By not notifying their users that their data was breached they aren't being honest about how how data is being used. They could also set up the system in such a way that their user's data couldn't be mishandled, but they choose not to.

Not exactly the actions of a company that I would consider trustworthy.

Re: Is Facebook Really Scarier Than Google?

#344

Earlier quoted context omitted.

You haven't actually shown an example of them lying though. Are you saying that complying with lawful requests for data, as Google explicitly stares it will do and then publicly announcing the ways it complied, as well as when lawful, announcing to the affected users, is lying? I find that difficult to believe.

> Are you saying that complying with lawful requests for data, as Google explicitly stares it will do and then publicly announcing the ways it complied, as well as when lawful, announcing to the affected users, is lying? By not notifying their users that their data was breached they aren't being honest about how how data is being used. They could also set up the system in such a way that their user's data couldn't be…

>By not notifying their users that their data was breached they aren't being honest about how how data is being used.

But they do notify the user unless doing so is illegal (and then, they do so when it becomes legal). You still haven't substantiated this claim of lying, unless you are claiming that "obeying the law" is lying about how data is being used. But again, Google is clear that they will obey court orders.

> They could also set up the system in such a way that their user's data couldn't be mishandled, but they choose not to.

This is also one of those things that appeals to a small group of privacy enthusiasts, but isn't actually a good thing for the average user. The same set of changes that make it impossible to as you describe it "mishandle" data, also make it impossible to recover data in the case of user error. If you're willing to make that tradeoff that's fine, but for most people, the looming spectre of a court order is a much less worrying issue than forgetting one's password.

That may not be the case for you, and that's fine. But to say that not doing that is unethical is a stretch. See this thread[1], where a number of security professionals who to my knowledge aren't Google-affiliated (and me, who is neither a security professional, nor independent) discuss this.

It comes down to the average user's threat model not involving state level actors. Designing a broadly appealing service to respond to that threat is a disservice to the average user, because it comes at the cost of other features.

You personally may have a different threat model, and that's ok. But to claim that anyone who does not follow your exact threat model is lying or mishandling data is disingenuous and potentially harmful.

[1]: https://news.ycombinator.com/item?id=15853477

Re: Is Facebook Really Scarier Than Google?

#345

Earlier quoted context omitted.

DNS over HTTPS is great for the average Joe/Jane, but if you're technical and care about dns leaks ... I'd suggests a DNS over TLS (unbound) + filter setup. This way your dns traffic is still encrypted, and you retain the capability to block/proxy.

> you retain the capability to block/proxy Only if you are smart enough to know the browser has its own resolver, and that you need to turn it off first. We may not be able to turn it off in the future, meaning if you want to have privacy you have to run a privacy-specific browser. This may end up breaking traffic as Google shifts more and more of the web into its proprietary products. For example, Google owns the .D…

Let's see where this gTLD thing goes. I can probably see an ICANN or EU intervention in case of a self-mandated requirement of this kind. But, as long as the market stay healthy, more competition can't be nothing than good.

After all, DOH is mainly a technical answer to hijacks (and monitoring). Some ASes seem to have a policy on that... Once it's ready, if it's enforced, you'll have a way to provide a custom resolver you control.

Re: Is Facebook Really Scarier Than Google?

#346

Earlier quoted context omitted.

I'd like to expand this because I don't see it written much, and please correct me if I misunderstand: The scandal is that FB sold or allowed the ability for third party companies like Cambridge Analytica to harvest the whole social graph and FB sold or allowed the ability for them to use that same data on FB to target and manipulate people.

It is nuanced a bit so some background: Cambridge Analytica did violate Facebook terms of service as that wasn't truly allowed to pull down the whole social graph, but the protections against pulling friend data without their knowledge in the Facebook OpenGraph APIs weren't truly in until v2 around 2013-2014. I know this because we used to do lots of Facebook apps/games and back then, once someone gave you access to…

Wow! Clearly nuanced, this is a fantastic answer, I did not expect a worthwhile reply, let alone such a great synopsis. Thank you for typing it out. This quality dialogue is why I, and so many others frequent this forum! It's definately not an either or situation, and I hate how our regulators have, for about a half century now, sold out to the ISP/Telco mafia, which enables their continually shitty operations and service while holding on to their anti-competitive market positions. AT&T figured out quite long ago that excelling at cronyism was their most effective long-term business model. I am worried the tech giants will embrace regulation and skate the same path.

https://www.fastcompany.com/40520529/big-tech-lobbying-spree...

Re: Is Facebook Really Scarier Than Google?

#347

Earlier quoted context omitted.

> Are you saying that complying with lawful requests for data, as Google explicitly stares it will do and then publicly announcing the ways it complied, as well as when lawful, announcing to the affected users, is lying? By not notifying their users that their data was breached they aren't being honest about how how data is being used. They could also set up the system in such a way that their user's data couldn't be…

>By not notifying their users that their data was breached they aren't being honest about how how data is being used. But they do notify the user unless doing so is illegal (and then, they do so when it becomes legal). You still haven't substantiated this claim of lying, unless you are claiming that "obeying the law" is lying about how data is being used. But again, Google is clear that they will obey court orders. >…

Im sorry, but I cant take any of what you are saying seriously. You can ignore the facts all you want, but an uncomfortable truth is still true.

Re: Is Facebook Really Scarier Than Google?

#348

Earlier quoted context omitted.

>By not notifying their users that their data was breached they aren't being honest about how how data is being used. But they do notify the user unless doing so is illegal (and then, they do so when it becomes legal). You still haven't substantiated this claim of lying, unless you are claiming that "obeying the law" is lying about how data is being used. But again, Google is clear that they will obey court orders. >…

Im sorry, but I cant take any of what you are saying seriously. You can ignore the facts all you want, but an uncomfortable truth is still true.

I'm not ignoring any facts. You haven't substantiated any of your accusations. You're the one who is transforming "transparently obeying lawful warrants as they disclose they will" into "lying about data usage", or at least that's the best interpretation of what you're saying I can come up with.

If you want me to engage with facts, please provide some first! I can't ignore what isn't there.

Re: Is Facebook Really Scarier Than Google?

#349

Earlier quoted context omitted.

Im sorry, but I cant take any of what you are saying seriously. You can ignore the facts all you want, but an uncomfortable truth is still true.

I'm not ignoring any facts. You haven't substantiated any of your accusations. You're the one who is transforming "transparently obeying lawful warrants as they disclose they will" into "lying about data usage", or at least that's the best interpretation of what you're saying I can come up with. If you want me to engage with facts, please provide some first! I can't ignore what isn't there.

> I'm not ignoring any facts.

You most certainly are.

Fact: They are willing to lie to me, and are unwilling to set up their systems in such a way that they don't have to lie to me.

Fact: They could also set up the system in such a way that their user's data couldn't be mishandled, but they choose not to.

Bonus Fact: They say that they store our data securely, but it's clear that they don't, if they can comply with a NSL.

You keep making up excuses for them, but those don't matter. The facts matter. If I'm wrong, then it would be easy to prove, and I'd ask you to do so.

> You're the one who is transforming "transparently obeying lawful warrants as they disclose they will" into "lying about data usage", or at least that's the best interpretation of what you're saying I can come up with.

And what is factually wrong about that? If I ask them if my data is being mishandled, they'll tell me it isn't. And by not notifying me of breaches of my data, they are lying about the quality of the security of their system.

Re: Is Facebook Really Scarier Than Google?

#350

Earlier quoted context omitted.

I'm not ignoring any facts. You haven't substantiated any of your accusations. You're the one who is transforming "transparently obeying lawful warrants as they disclose they will" into "lying about data usage", or at least that's the best interpretation of what you're saying I can come up with. If you want me to engage with facts, please provide some first! I can't ignore what isn't there.

> I'm not ignoring any facts. You most certainly are. Fact: They are willing to lie to me, and are unwilling to set up their systems in such a way that they don't have to lie to me. Fact: They could also set up the system in such a way that their user's data couldn't be mishandled, but they choose not to. Bonus Fact: They say that they store our data securely, but it's clear that they don't, if they can comply with a…

>And what is factually wrong about that?

Because Google states that it will comply with such orders. That means that they do not lie to you about complying with court orders. They tell you in advance that they will comply with them. This isn't a case of Google saying "we will never give your data to the government" and then walking back on that. That would be lying. But they don't do that, they say

> We will share personal information with companies, organizations or individuals outside of Google if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to meet any applicable law, regulation, legal process or enforceable governmental request

(edited for formatting from [1])

So again, what is the lie?

I already explained why 'designing a system so you can't comply with an NSL' is a nonstarter. The design requirements to do that make such a system untenable for most clients, for example most corporate clients need data recovery features that are impossible in a system designed to meet your requirements.

[1]: https://www.google.com/policies/privacy/

Post reply on HN