4 ms·
As an engineer on cloud, at Google, that is very extremely patently false. First, all your data at rest, on disk, is encrypted. You can even supply your own ke
by ryanobjc 10y ago
As an engineer on cloud, at Google, that is very extremely patently false.
First, all your data at rest, on disk, is encrypted. You can even supply your own keys if you wish: https://cloud.google.com/compute/docs/disks/customer-supplied-encryption https://cloud.google.com/compute/docs/disks/customer-supplie...
If you are using Google Managed keys, the keys are stored in a special key storage service. To access your files, a staffer would have to read the keys, then go and read the data and decrypt it. Both of these steps are extremely logged, and require Googlers to take particular, and specific steps that are audited and easy to spot (and we audit this all the time, proactively). And not every Engineer (and no non-engineers) has the access to even get to that.
Accessing user data, in any form, is a very fire-able offense, and people have been terminated over it.
Our internal controls are very robust. We spent a lot of resources on encryption and ensuring it's available at many different levels. This is one area where I feel Google Cloud is better than bare hardware, the on-disk encryption is default and cannot be turned off.
- notyourwork 10y agoThank you for answering this question! I wish cloud storage providers would be much more transparent about their security to allow user's to decide which option provides them with the proper security. Right now it is hard to know whether or not what you said applies equally to other cloud providers. Also, (no discredit to you) you are a random person on the internet so your claim is far from 100% validated. edit: spelling
- ryanobjc 10y agoThat's fair - random person on the internet, I get it. I have common usernames on the various services you know and love, so feel free to dig about. As for transparency, there is a big push to increase the trust in Google Cloud. We're a big company, and it's hard to get that personal connection to build the trust. I think our blog is trying to get this info out, here is a good recent one: https://cloudplatform.googleblog.com/2017/01/how-we-secure-our-infrastructure.html https://cloudplatform.googleblog.com/2017/01/how-we-secure-o... My opinion is that Google is a very honest company. These whitepapers are our attempt to accurately describe what steps we are taking, in good faith, to ensure Google Cloud is the best, and most secure place, to do your computing on. As a personal anecdote, I once worked for Google (and quit, and came back) about 8 years ago. The difference in how secretive we are is night and day. I can say the word 'borg' in public, and even tell you what it is. And this is accelerating under Cloud, because we know that big enterprises aren't going to use us without a lot of details and assurances.
- X86BSD 10y agoBased on Googles track record with Android, and the atrocious deployment of TV on Google fiber, as well as a host of other examples of Googles beliefs and competencies, Google has a better chance of putting a person on Mars than me trusting them with anything. Time will tell what happens to Google.
- sigstoat 10y ago> > The thing that bothers me is employees inside these companies can look at your data... > ... that is very extremely patently false. > Accessing user data, in any form, is a very fire-able offense, and people have been terminated over it. what were they terminated for, if it is three-adjective false?
- CPAhem 10y agoThis still doesn't stop an attacker who has your Google credentials from accessing all the data. There is a single point of failure. Would it not be better if the encryption was end-to-end, being encrypted at the source, before being uploaded to the Cloud?
- ripdog 10y agoAre you able to talk about Google Drive in particular? What kind of automated scanning goes on when I upload something? I know child porn is scanned for, what else?