5 ms·
When you have HN readers complaining about this issue, then we can be fairly certain that the average user of Google's products will have a very difficult time
by lucifer 17y ago
When you have HN readers complaining about this issue, then we can be fairly certain that the average user of Google's products will have a very difficult time finding their way to the "privacy features" controls, and in effect Google has already made these privacy decisions for them.
- jasonlotito 17y agoBeing an HN reader doesn't make someone immune to being wrong. At some point, the user has to take responsibility. Every complaint I've read that discusses this has mentioned not using Google Profiles to modify privacy settings previously. Either that, or it wasn't mentioned at all. So, I go back to what I was saying: did anyone using the privacy settings available have their privacy setting explicitly overridden, or was is just people not using the privacy settings available, and then getting run over when they realized what they had allowed opened? Edit: I get downvoted for asking questions. Apparently, not following the torch-bearers blindly is frowned on.
- jfager 17y agoThis morning, I've watched two coworkers open their gmail accounts for the first time since Buzz went live. In both cases, they clicked "No thanks, take me to my inbox" instead of the button to "Check out Buzz", and in both cases, Buzz was enabled anyways, and a bunch of people were listed as following/followers. We looked at their profiles, and all the followers/ees were publicly listed. What, exactly, should they have done to keep this from happening?
- jasonlotito 17y agoThey were using their profile privacy settings, and it violated it, or was it more a case of the feature enabling itself in Gmail and using existing privacy settings? Edit: And because it needs to be said here: I'm not suggesting enabling Buzz and then using existing privacy settings as a bases for how Buzz works is right. I'm just asking a question.
- jfager 17y agoThis was their first interaction with Buzz. There was no opportunity to set any privacy settings. They are both Reader users, and did have limited sharing enabled there, but under what logic should those permissions ever extend to a completely new, different service with wholly different privacy concerns?
- jasonlotito 17y ago"Inferring privacy preferences for new software, based on prior actions in old software, is a recipe for failure." From this thread: http://news.ycombinator.com/item?id=1121034 http://news.ycombinator.com/item?id=1121034 Anyways, here is my take. Buzz isn't a new product so much as it's a new feature of Gmail. It's as much a new product as any new feature of Gmail is. It's also tied into most of the areas Gmail is, and tied into the rest of Google, and uses Google Profiles. Google made the assumption that because this wasn't so much a complete new product, but rather an extension to an existing one, that it should use existing permissions. And looking at it that way, I can easily see them doing what they did. What they didn't suspect, or expect I'm sure, is that people would see it not as a Gmail feature, but rather as a completely different system unrelated to Gmail and rather, tacked onto it. I can see how Google looks at Buzz as merely an extension to Gmail. Gmail is, after all, their communications tool, including email, chat, and eventually (we know this is coming), Wave. Buzz is merely another way to communicate, and because so much of Gmail already includes so many other connections, Buzz being a framework to share things that Email, Chat, and what not are effective at, they built it with a familiar way of doing things. They then assumed (and I'm assuming all of this, mind you) that because they were building on top of an existing structure, that much of the privacy concerns that have arisen were already in use by the people that were concerned with it. So, the question is, not whether Google was right or wrong, but rather, where do we draw the line? When does a new feature become a new product that requires new permissions, and when is a feature merely a feature that can use existing permissions. After all, there is so much that they do add where we don't blink an eye or concern ourselves with permissions or privacy, despite the potential for problems down the line. I understand what they did, and why they did it (if my assertions are correct). However, there is more to learn here than to just say "Make everything private." The reality is, most users make assumptions about privacy (this is excellent proof of that), and so do companies. I honestly don't think Google went with Buzz and said "Let's destroy users privacy." I also hope this heightens people's awareness to the state or privacy on the web.
- cabalamat 17y ago> In both cases, they clicked "No thanks, take me to my inbox" instead of the button to "Check out Buzz", and in both cases, Buzz was enabled anyways That's exactly what happened to me. I'm really pissed off with Google now. If they are going to throw this sort of crap at me, I will have to reconsider whether I want gmail and reader accounts.
- tsally 17y agoI can confirm that this just happened to me as well. In fact, if not for this thread I wouldn't have known to go back to check if Buzz was silently enabled.
- weaksauce 17y agoClicking "No thanks" in this instance is not a command to disable buzz it is actually a dismissal of the tutorial page. Buzz will still be enabled either choice you make. There should be an obvious opt out of buzz on the splash screen page. The way to turn it off is a very small textual link in the footer of the page that says turn off buzz.
- algorias 17y agoObfuscated opt-out is pretty much the definition of 'evil'.
- weaksauce 17y agoHanlon's Razor comes to mind : "Never attribute to malice that which can be adequately explained by stupidity." I doubt the google programmers are stupid but I would say that they probably were excited by the new feature that they are proud of and didn't think that people would want to opt out of it before even trying it.
- CamperBob 17y agoObfuscated opt-out is pretty much the definition of 'evil'. (since it didn't seem to come through when the other guy posted it)