4 ms·
Don't believe this horseshit. I work in Google Support, and I can assure you that the personal information of users is tightly protected and subject to stupid a
by androidbishop 10y ago
Don't believe this horseshit. I work in Google Support, and I can assure you that the personal information of users is tightly protected and subject to stupid amounts of security and oversight. Like, to the point of constant frustration by support staff.
Gmail personal data is stored encrypted. Just because algorithms can profile you doesn't mean every google employee can simply read your emails or personal information raw from some db somewhere. I can't even pull up basic technical troubleshooting data from a cloud customer without begging them for the data.
Higher up executives don't necessarily have more access, access is given based upon your responsibilities, and level of need. A VP of marketing is not going to be granted access to a customer's gmail messages, because they don't need that information to do their job. There is no reason to grant them that access, the liability of a leak is far worse than any benefit.
Everything an employee accesses is controlled by a complex system, subject to oauth2 authentication, a permission handling technology, and fido u2f yubico security key 2fa. Everything an employee accesses is logged and monitored. Nobody is able to walk out of there with an archive of user info, that would alert every alarm in the system. Nobody has been able, as far as we know, to phish access into our internal network since we started using yubikeys for everything[1].
The employees with the most access are typically SREs and Developers, and their access is designed to facilitate their jobs. Example: the data in your BigQuery db won't be able to be easily read by any employee, but the right ones will be able to read logs, activity histories, and relevant statistics in order to be able to troubleshoot and diagnose bugs and issues and things. They don't need to know what data the table holds, and therefore aren't given access to read it.
We are pretty far from a major offender of negligence over the security of our user's data. As far as I know, we were hacked by China and the NSA, which immediately prompted us to encrypt our server2server communications, encrypt our storage data, and research and develop novel security best practices. Our development and trial with fido u2f keys, for instance, has resulted in a drop to 0 KNOWN successful phishing attempts, all while making 2fa more convenient than ever[1].
It may be hard to believe, but Google's information about your lives in the machine. Our employees only have access to the bits we need to do our jobs, which always sides on your privacy. Trust me, I wish I did have more access, because trying to troubleshoot in the dark sucks.
But they respect you and your privacy more than they respect me. And they work hard to keep your private information safe, to levels I doubt most companies you regularly use or shop at would ever care to. Remember, just because some company doesn't sell your info to advertisers doesn't make them more trustworthy. They could be storing your info in an unencrypted db with a basic admin/login on a rack of poorly administered and configured servers in a budget datacenter somewhere. Google uses the latest technology, funds new research, and implements a security policy built on state of the art equipment and software other companies could only dream of. This is not a secondary consideration for them, they bust their ass to keep your info safe.
[1] https://www.yubico.com/2016/02/use-of-fido-u2f-security-keys-focus-of-2-year-google-study/ https://www.yubico.com/2016/02/use-of-fido-u2f-security-keys...