Live data from Hacker News

How to Set Your Google Data to Self-Destruct

nytimes.com

61–70 of 76 posts

Re: How to Set Your Google Data to Self-Destruct

#61
post #35
post #16

Earlier quoted context omitted.

By definition, any really effective backup (off site, offline) can't simply be modified instantly when you click a button in a web UI. The reason it takes months for backups to clear out your deleted data is that's how long it takes for the entire backup to be discarded and replaced by a new backup that reflects your deletions. While the data is likely inaccessible forever in this case, the reason the company can't j…

You can delete user data from backups much more quickly than that: * Encrypt each user's data to a user-specific key * Keep the key in hot replicated storage * When you get a deletion request, delete the key

You still need to back up the keys? How does this solve anything?

Backups aren't just about replication/redundancy, they also protect you from bugs and other sources of corrupted data.

Re: How to Set Your Google Data to Self-Destruct

#62

Earlier quoted context omitted.

This is how I feel about it. I don’t have any faith that I’m going to be protected from current / future persecution because I ticked / didn’t tick some box on some control panel on some service provided by Morally Bankrupt MegaCorp .

That's a bit pessimistic/paranoid and off the bat doesn't make a whole lot of sense. If your data is supposed to have been deleted but they ignored it, they have it illegally. If someone from the state wants to prosecute you and requests the data, the company wouldn't own up to having it, because they're not allowed have it. Why would they lie to you, and then sell themselves out to the state? Fine, they might keep i…

Parallel construction. Advanced Persistent Threat. State Level Actor.

I think we ought to assume Big Corp doesn't delete anything and shares that not-deleted data with, at least, the Five Eyes.

Re: How to Set Your Google Data to Self-Destruct

#63
post #17

Earlier quoted context omitted.

Be very careful about combining Inactive Account Manager with telling Google not to store activity data. I started getting countdown to deletion warnings telling me I needed to log in to show I wasn't inactive, but no matter how often I did it was ignored completely until I turned on activity tracking. I'm not sure if this is a rare bug or working as intended, but it could go badly. In the end I turned off Inactive a…

What counts as logging in? Do you check Gmail or drive weekly? Backup and Sync? Can you set up an API key app that pings an API weekly?

If I recall correctly their documentation suggests that a single login to the Gmail web app or several other properties should count as well as the official Gmail apps, but no web logins I tested had any effect for me. Sadly I can't retest this without setting a new timer on an account.

If you end up in a position to tet this you'll want to keep an eye on multiple account logins as well since the link they send you in the warning doesn't go to a specific account. If you're logged in to more than one account and the first one isn't the one you got the warning about you'll end up looking at the manager for the wrong one and need to either log out entirely or find it manually. A minor design issue, but it can be confusing for a few minutes.

Re: How to Set Your Google Data to Self-Destruct

#64
post #45
post #36

Earlier quoted context omitted.

Sounds like a gdpr violation

Or an edge case they didn't consider, and will likely fix.

My bet was on a mix of just a predictable edge case and Google not prioritizing testing when users have stopped activity. I don't think they sat down and decided the kind of people who care about the inactive account manager were especially good targets for manipulation. I'm sort of surprised that they didn't use the info that they have on last logins instead of the web activity tracking, but there's probably some architectural reason it was easier.

Re: How to Set Your Google Data to Self-Destruct

#65
post #61
post #35

Earlier quoted context omitted.

You can delete user data from backups much more quickly than that: * Encrypt each user's data to a user-specific key * Keep the key in hot replicated storage * When you get a deletion request, delete the key

You still need to back up the keys? How does this solve anything? Backups aren't just about replication/redundancy, they also protect you from bugs and other sources of corrupted data.

You can back up the keys in ways where it's very easy to purge them: no tapes, easy to recall and edit.

Re: How to Set Your Google Data to Self-Destruct

#66
post #65
post #61

Earlier quoted context omitted.

You still need to back up the keys? How does this solve anything? Backups aren't just about replication/redundancy, they also protect you from bugs and other sources of corrupted data.

You can back up the keys in ways where it's very easy to purge them: no tapes, easy to recall and edit.

The fact that backups can't be accessed and modified easily for a long period of time is a feature, not a bug, regardless of the actual mechanism of implementation (like tapes). That's what stops e.g. ransomware from affecting backups in addition to the primary storage.

A backup that can be edited to delete data like an encryption key instantly when the user tells it do is also a backup that can be easily lost or corrupted.

Re: How to Set Your Google Data to Self-Destruct

#67
post #37

Earlier quoted context omitted.

If they can't keep a cache of your recent locations, it would be difficult for them to apply optimization of your location, prediction of your car's path, etc. and Google Maps would be a much more jarring experience, akin to a GPS device. I think they do need the client to send recent locations per request if they want to deliver an optimal experience. For example, what if I wanted to implement loading automatic near…

> if they want to deliver an optimal experience I should be able to decide what "experience" I want. I don't want "more", I'm happy with "good enough". Anyway, I'm very fine with how it works now, except for the nagging. I allow the app to know my location, of course, just not to store any history.

Nobody wants to use a maps app that feel like it's from 2004. There's a reason people put up with giving their data away -- because data drives machine intelligence, which makes your maps app smoother, more responsive, more useful, and overall a much better experience.

I, too, don't want to give my data away. But when I'm in my car, the most important thing is that I get to my destination safely and on time. That acute need vastly outweighs my own philosophy on who I think should have my data.

I'm just being honest with myself. I can't deny that I make heavy use of products that make heavy use of my personal data. People in this community seem to think of personal data collection as a form of parasitism, but in reality, it is far closer to mutualism.

Re: How to Set Your Google Data to Self-Destruct

#68
post #40

Earlier quoted context omitted.

That's a bit pessimistic/paranoid and off the bat doesn't make a whole lot of sense. If your data is supposed to have been deleted but they ignored it, they have it illegally. If someone from the state wants to prosecute you and requests the data, the company wouldn't own up to having it, because they're not allowed have it. Why would they lie to you, and then sell themselves out to the state? Fine, they might keep i…

The way Google acts with regard to privacy law is similar to how they act with regard to tax law. That is they look for loopholes and places they can use dark patterns to nudge users into giving up more data. They stay within the rules but push the envelope of what’s acceptable to the legal limit. It’s not that they are holding onto data specifically to support prosecutions it’s that they hold onto data because that’…

So the conspiracy is rather that the delete button simply doesn't do anything?

I don't think that would go down well for the prosecution if you ever ended up in court.

The reality is that 99.99% of users never even open their account settings, let alone micromanage their identity's state across dozens of platforms. Google wouldn't even notice if all hn readers deleted all of their data and deactivated their accounts tomorrow.

The most reasonable thing for them to do is to actually delete the data, and avoid all headaches. It's the more profitable move. You look like good guys and avoid legal problems.

Re: How to Set Your Google Data to Self-Destruct

#69
post #64
post #45

Earlier quoted context omitted.

Or an edge case they didn't consider, and will likely fix.

My bet was on a mix of just a predictable edge case and Google not prioritizing testing when users have stopped activity. I don't think they sat down and decided the kind of people who care about the inactive account manager were especially good targets for manipulation. I'm sort of surprised that they didn't use the info that they have on last logins instead of the web activity tracking, but there's probably some ar…

Logins can occur without user interaction by a logged-in device, so it's not as meaningful as user activity.

Re: How to Set Your Google Data to Self-Destruct

#70
post #51

Earlier quoted context omitted.

This just ... isn't true. People can and do evolve their opinions, feelings and levels of trust over time. I.e. people change. Particularly in response to external changes as you imply ("regardless of what happens").

people are like slowly boiling frogs, google stopped not being evil a long time ago

Not arguing on the point of whether google is evil or not, or when that happened.

But the boiling frog analogy is something that just isn't true:

> "According to Dr. George R. Zug, curator of reptiles and amphibians, the National Museum of Natural History, 'Well that's, may I say, bullshit. If a frog had a means of getting out, it certainly would get out. And I cannot imagine that anything dropped in boiling water would not be scalded and die from the injuries.'"

> "Professor Doug Melton, Harvard University Biology Department, says, 'If you put a frog in boiling water, it won't jump out. It will die. If you put it in cold water, it will jump before it gets hot -- they don't sit still for you.'"

> "Vic's (Dr. Victor Hutchison of the University of Oklahoma) answer was as follows: 'The legend is entirely incorrect! The 'critical thermal maxima' of many species of frogs have been determined by several investigators. In this procedure, the water in which a frog is submerged is heated gradually at about 2 degrees Fahrenheit per minute. As the temperature of the water is gradually increased, the frog will eventually become more and more active in attempts to escape the heated water. If the container size and opening allow the frog to jump out, it will do so. Naturally, if the frog were not allowed to escape it would eventually begin to show signs of heat stress, muscular spasms, heat rigor, and death.'"

Quotes from: http://answers.google.com/answers/threadview?id=758865

Additional info: https://www.theatlantic.com/technology/archive/2006/09/the-b...

Post reply on HN