Related side note: I've always had a suspicion that one of the ideas I was working on using Google Colab was viewed by an employee and leaked, because someone wrote a blog post with the exact same idea (very niche) before I got round to releasing mine (I ended up not bothering due to being gazumped), and a Google Colab employee tweeted that blog post. (Puts on tin foil hat.. I stopped using Colab after that.)
There’s zero privacy with any ML/AI tools.
Nintendo leak:employee accessing private YouTube videos
61–70 of 91 posts
Re: Nintendo leak:employee accessing private YouTube videos
#62https://www.404media.co/google-contractor-used-admin-access-...
"Google Contractor Used Admin Access to Leak Info From Private Nintendo YouTube Video"
This is how companies harm users by using low-trust, low-attachment contractors to handle private data.
Re: Nintendo leak:employee accessing private YouTube videos
#63Earlier quoted context omitted.
My favourite are the one that leaked a tank data on a discord just to prove that they were right.
The number of state secrets protected by a 20 year old E-4 whose only motivation is to not get chewed out (and/or jail) is probably staggering.
Re: Nintendo leak:employee accessing private YouTube videos
#64Earlier quoted context omitted.
I never knew Youtube did child labour?
In many states its legal for people 16-18 to work, usually with limitations on hours worked per shift/week an what kind of jobs they can do. Even then, many older people in the US will call someone 18-20 "kids", even though they're technically adults. As a US English speaker I took it to mean "a bunch of young and immature people, probably on their first job" when I heard "most people are just kids", not that they're…
In my head I felt like my peers in college were "kids". I didn't feel like we were "adults" until we were in our mid-20s.
Re: Nintendo leak:employee accessing private YouTube videos
#65Earlier quoted context omitted.
> so the assumption is that anyone who is an agent of Google is in on the secret I think there is a difference here between "expectation" and "assumption". Without the ability to do a third-party audit I agree the only reasonable assumption to make is that everyone is in on the secret and when dealing with sensitive information it should always be the assumption you go with. However, as an expectation, I expect SaaS…
There may be a difference, but it seems you have them flipped. It is a reasonable assumption to think that they have controls to limit who is able to see information[1], but one must go in with the expectation that every acting agent has access. [1] Of course, since you don't know who the individuals are, you still have to place your trust in every single agent that works for the entity you chose to entrust. As such,…
Applied here, the expected and right thing to do is follow the principles of least access. However, we must assume google is not doing this, because there is insufficient evidence that they are, and there is actual evidence that they don't have sufficient controls to limit who is able to see information.
Re: Nintendo leak:employee accessing private YouTube videos
#66Earlier quoted context omitted.
There may be a difference, but it seems you have them flipped. It is a reasonable assumption to think that they have controls to limit who is able to see information[1], but one must go in with the expectation that every acting agent has access. [1] Of course, since you don't know who the individuals are, you still have to place your trust in every single agent that works for the entity you chose to entrust. As such,…
I think you have it backwards: an expectation is a standard (the term is used loosely here) that someone should be meeting. We expect people to do the right thing, but sometimes must, as in this case, assume they are doing the wrong thing. Applied here, the expected and right thing to do is follow the principles of least access. However, we must assume google is not doing this, because there is insufficient evidence…
However, you make a fair point that it is reasonable to assume that entities you trust are willing to go above and beyond, for various reasons.
Re: Nintendo leak:employee accessing private YouTube videos
#67Earlier quoted context omitted.
Yeah, man. These are all the end users' fault: https://en.wikipedia.org/wiki/List_of_data_breaches Totally.
Sysadmins are also people. Also I've been pushing for informative security scoring for publicly used services for over a decade. If you're in the field, it's pretty obvious which services are at high risk of being breached, but that really should be something more accessible to the general public, like FDA letter grading for restaurants.
> There absolutely is for anyone who cares to use it
> Sysadmins are also people.
is it your contention that the sysadmins at those organizations don't care about computer security? Or that users are responsible for knowing whether their organizations' sysadmins care about computer security?
Re: Nintendo leak:employee accessing private YouTube videos
#68Re: Nintendo leak:employee accessing private YouTube videos
#69Earlier quoted context omitted.
The number of state secrets protected by a 20 year old E-4 whose only motivation is to not get chewed out (and/or jail) is probably staggering.
A lot of these tank "leaks" are just PDF's of manuals you can buy on ebay. They're restricted but legal to own. It only becomes illegal when you export them to other countries.
Re: Nintendo leak:employee accessing private YouTube videos
#70Earlier quoted context omitted.
I think you have it backwards: an expectation is a standard (the term is used loosely here) that someone should be meeting. We expect people to do the right thing, but sometimes must, as in this case, assume they are doing the wrong thing. Applied here, the expected and right thing to do is follow the principles of least access. However, we must assume google is not doing this, because there is insufficient evidence…
Right, expectation is the standard. The standard is that anyone who is an agent of the entity you have entrusted is also considered trustworthy. After all, giving full trust to an entity you only trust partially is nonsensical. However, you make a fair point that it is reasonable to assume that entities you trust are willing to go above and beyond, for various reasons.
To clarify, I am the second person here telling you that that is not the expectation. The expectation, and/or the right thing to do, and/or "the standard we expect them to meet", is that Google follows the standard security principle of least privileged access, meaning each employee can only access data they need to see, with proper permission acquired beforehand, auditing during, and abuse-detection & alerting afterwards.
Unfortunately, they don't meet this expectation that we have of them. Your own expectations and/or standards might be lower, like you described.