3 ms·
> Are you saying that complying with lawful requests for data, as Google explicitly stares it will do and then publicly announcing the ways it complied, as well
by CaptSpify 9y ago
> Are you saying that complying with lawful requests for data, as Google explicitly stares it will do and then publicly announcing the ways it complied, as well as when lawful, announcing to the affected users, is lying?
By not notifying their users that their data was breached they aren't being honest about how how data is being used. They could also set up the system in such a way that their user's data couldn't be mishandled, but they choose not to.
Not exactly the actions of a company that I would consider trustworthy.
- joshuamorton 9y ago>By not notifying their users that their data was breached they aren't being honest about how how data is being used. But they do notify the user unless doing so is illegal (and then, they do so when it becomes legal). You still haven't substantiated this claim of lying, unless you are claiming that "obeying the law" is lying about how data is being used. But again, Google is clear that they will obey court orders. > They could also set up the system in such a way that their user's data couldn't be mishandled, but they choose not to. This is also one of those things that appeals to a small group of privacy enthusiasts, but isn't actually a good thing for the average user. The same set of changes that make it impossible to as you describe it "mishandle" data, also make it impossible to recover data in the case of user error. If you're willing to make that tradeoff that's fine, but for most people, the looming spectre of a court order is a much less worrying issue than forgetting one's password. That may not be the case for you, and that's fine. But to say that not doing that is unethical is a stretch. See this thread[1], where a number of security professionals who to my knowledge aren't Google-affiliated (and me, who is neither a security professional, nor independent) discuss this. It comes down to the average user's threat model not involving state level actors. Designing a broadly appealing service to respond to that threat is a disservice to the average user, because it comes at the cost of other features. You personally may have a different threat model, and that's ok. But to claim that anyone who does not follow your exact threat model is lying or mishandling data is disingenuous and potentially harmful. [1]: https://news.ycombinator.com/item?id=15853477 https://news.ycombinator.com/item?id=15853477
- CaptSpify 9y agoIm sorry, but I cant take any of what you are saying seriously. You can ignore the facts all you want, but an uncomfortable truth is still true.
- joshuamorton 9y agoI'm not ignoring any facts. You haven't substantiated any of your accusations. You're the one who is transforming "transparently obeying lawful warrants as they disclose they will" into "lying about data usage", or at least that's the best interpretation of what you're saying I can come up with. If you want me to engage with facts, please provide some first! I can't ignore what isn't there.
- CaptSpify 9y ago> I'm not ignoring any facts. You most certainly are. Fact: They are willing to lie to me, and are unwilling to set up their systems in such a way that they don't have to lie to me. Fact: They could also set up the system in such a way that their user's data couldn't be mishandled, but they choose not to. Bonus Fact: They say that they store our data securely, but it's clear that they don't, if they can comply with a NSL. You keep making up excuses for them, but those don't matter. The facts matter. If I'm wrong, then it would be easy to prove, and I'd ask you to do so. > You're the one who is transforming "transparently obeying lawful warrants as they disclose they will" into "lying about data usage", or at least that's the best interpretation of what you're saying I can come up with. And what is factually wrong about that? If I ask them if my data is being mishandled, they'll tell me it isn't. And by not notifying me of breaches of my data, they are lying about the quality of the security of their system.
- joshuamorton 9y ago>And what is factually wrong about that? Because Google states that it will comply with such orders. That means that they do not lie to you about complying with court orders. They tell you in advance that they will comply with them. This isn't a case of Google saying "we will never give your data to the government" and then walking back on that. That would be lying. But they don't do that, they say > We will share personal information with companies, organizations or individuals outside of Google if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to meet any applicable law, regulation, legal process or enforceable governmental request (edited for formatting from [1]) So again, what is the lie? I already explained why 'designing a system so you can't comply with an NSL' is a nonstarter. The design requirements to do that make such a system untenable for most clients, for example most corporate clients need data recovery features that are impossible in a system designed to meet your requirements. [1]: https://www.google.com/policies/privacy/ https://www.google.com/policies/privacy/