Live data from Hacker News

Where does Google actually say that they won’t read Gmail or Google Docs?

blogs.law.harvard.edu

91–94 of 94 posts

Re: Where does Google actually say that they won’t read Gmail or Google Docs?

#91
post #24

The real question is not whether google, dropbox or anyone else has explicit "policies" about reading content from users. They're just going to say whatever makes them look good from a marketing and legal perspective. Companies lie all the time, systematically and comprehensively. They act in their own self-interest period. From their point of view it is merely a question of how much they can get away with. The more…

Exactly. And that applies to any company not just "evil" ones. It is a bit naive to trust something as abstract as an organization. Trust applies to individual people, and a company is bound to be a very diverse group of people with different agendas. If you want your mail to be reasonably safe from third-party reading, the only solution is to encrypt it before sending, and ask people that mail you to do the same. An…

In theory, yes of course, you can encrypt your communications personally and "figure out" on a case by case basis how to do key exchange with the end-party. But that is a MAJOR OBSTACLE for all but the most patient and tech-savvy people and totally overkill for all but the most critical life-or-death information exchanges.

In practice, unless both you and your recipient are operating your own email servers and key-exchange/encryption services, you HAVE TO "trust" a third party with your private information.

Re: Where does Google actually say that they won’t read Gmail or Google Docs?

#92
post #38

Earlier quoted context omitted.

Until there is something in it for them. It's a pretty classic security question, sometimes usability means that you accept zero security and completely share your private correspondence with the world. I think trust is the wrong word, you are really just accepting the risk of sharing all your data for the benefits because the risk is low.

Yes, I agree "trust" is the wrong word. It is perhaps better to think of it as a trade-off of some risk for some convenience and that's OK. In any case, back to the OP's question, the stated "policy" about privacy means virtually nothing unless there exists a third party who can effectively verify that policy.

Yes, in my experience on either side of those "policies" they really do mean nothing.

You just have to assume that all the data you share is no longer yours and will be used however the company sees fit.

I am amazed by the number of people who assume that "that would be bad PR if they got caught" is good enough security to protect data they consider sensitive. Especially when the PR damage historically has been very low, especially if you are a sexy and loved company like facebook or google.

Re: Where does Google actually say that they won’t read Gmail or Google Docs?

#93
post #91

Earlier quoted context omitted.

Exactly. And that applies to any company not just "evil" ones. It is a bit naive to trust something as abstract as an organization. Trust applies to individual people, and a company is bound to be a very diverse group of people with different agendas. If you want your mail to be reasonably safe from third-party reading, the only solution is to encrypt it before sending, and ask people that mail you to do the same. An…

In theory, yes of course, you can encrypt your communications personally and "figure out" on a case by case basis how to do key exchange with the end-party. But that is a MAJOR OBSTACLE for all but the most patient and tech-savvy people and totally overkill for all but the most critical life-or-death information exchanges. In practice, unless both you and your recipient are operating your own email servers and key-ex…

The point is that if people send their mail encrypted it is encrypted both in transit and when it is stored on the mail server. So the third party can be anyone, and you don't need to specifically trust them.

Also this isn't that big of an obstacle you make it to be. We're not living in 1995 anymore. A lot of mail clients have plugins or even have built-in support for encryption.

Re: Where does Google actually say that they won’t read Gmail or Google Docs?

#94
post #57
post #56

Store your plaintext email on someone else's server. Act surprised it's not private.

what makes you think it's plaintext?

If it weren't, then it wouldn't be an issue. Right?

And what makes me think that is that I suspect 99.999% of email is in plaintext. I have no foundation for this. Just a gut feeling.

Post reply on HN