11 ms·
>Which is a nice way of knowing that Google employees aren't randomly snooping on your files. Why would I, as a end user, be given to trust this if I think Goo
by ohithereyou 7y ago
>Which is a nice way of knowing that Google employees aren't randomly snooping on your files.
Why would I, as a end user, be given to trust this if I think Google employees are snooping in my files? I have no way to audit how this is kept, so I'd have to assume that any Googler snooping these files is either doing so using a backchannel that is not audited or the log is a no-op.
- joshuamorton 7y agoWhat's your threat model? If your worry is Google, as an organization, is actively trying to steal your stuff, that's one thing. If your worry is a rogue google employee is doing some unsanctioned thing, that's another. This (imo) mostly helps with the second, unless you also assume that Google as an organization is fairly inept and so can't log things reliably.
- otakucode 7y agoI'd like to add an additional possible threat model that gets ignored pretty comprehensively and, in some cases, intentionally: Your data being fed to automated systems that provide summaries or derivative information based upon your data. People ignoring this is behind much of the NSAs snooping. They believe that until a HUMAN operator views the cleartext of some communication, the communication can not legally be said to have been 'intercepted' at all. And if you look up any statement ever made about reforms done at the NSA after Snowden's revelations, you will find that all of them, every single one, spoke exclusively about human analysts reading communications directly. They avoided addressing analysis, profiling, ML training, summarization, and other automated things very intentionally. The government has dropped a good many cases, serious cases involving child pornography even, to avoid ever testing this idea of theirs in court. We learned about this particular legal opinion of theirs (which would almost certainly never survive any court challenge at all) before Snowden even, back when the AT&T whistleblower came forward. The likelihood a company like Google is reading your emails directly and trying to scoop your business on a product idea or something like that is slim. The likelihood they are profiling your communications in aggregate and producing derivative information like "how many companies in the space are considering hiring" or "do the employees at this company talk about Chipotle" and using that for advertising or data products is, I would guess, pretty high.
- joshuamorton 7y agoThis is just a specific form of my "Google as an organization is out to get you (and willing to lie in their privacy policy)" threat. It may sound more reasonable to you, but its still the same set of actions.
- Nextgrid 7y agoWe just had 2 incidents where both Facebook and Twitter broke their privacy policy by using phone numbers for ad targeting when they were only supposed to use them for 2FA & account recovery. I wouldn’t trust a company with personal data while their main business model depends on violating your privacy, just like you wouldn’t trust an alcoholic with guarding a warehouse full of vodka. The only way to be somewhat sure is to deal with companies that have zero uses for your personal data - this will not mitigate the risk of a malicious employee poking around but will at least mitigate the risk of large-scale data misuse like ad targeting because there’s simply no ads to target and no infrastructure to do so.
- joshuamorton 7y agoIn this context, we're discussing gsuite, which doesn't use any data for ad targeting. Edit: from the privacy policy: > No. There are no ads in G Suite Services or Google Cloud Platform, and we have no plans to change this in the future. We do not scan for advertising purposes in Gmail or other G Suite services. Google does not collect or use data in G Suite services for advertising purposes.
- Nextgrid 7y agoWe're talking about a company that makes the bulk of its money with ads, running a (supposedly ad-free) product on the same infrastructure that the ad-contaminated products run on. There's both a risk of accidentally misusing data given the two services share infrastructure and code, as well as a business incentive to commit such "accidents", especially given both Facebook and Twitter set a precedent that there's absolutely no downside in doing so.
- Twirrim 7y ago> What's your threat model? Government action that I'm left in the dark over. If the government is interested in something from my mail servers, I'll see the legal request or judges orders and will know what is going on, and will be able to take appropriate action. If the government makes appropriate legal threats against Google, I won't necessarily know (National Security Letters) until long after the fact.
- joshuamorton 7y ago> If the government is interested in something from my mail servers, I'll see the legal request or judges orders and will know what is going on, and will be able to take appropriate action. Or the mail servers of the person/people you're communicating with. At which point you wouldn't know, because they'd be subject to the same laws, and less well equipped to fight them.
- kelnos 7y agoIf your threat model includes the US government, then I would expect you would self-host anything sensitive. Even then, there's still the possibility that they could exploit some 0day they've been stockpiling, and root your servers without leaving a trail. Certainly harder than sticking Google with a gagged NSL, but possible. But I don't think most people's threat model includes the US government. Probably not even most news organizations.
- paggle 7y agoIf you don't trust that the access transparency log is genuine then why on earth would your files be in G Suite in the first place?
- K0SM0S 7y agoSeriously, this. At the end of the day, you want to trust that your provider isn't out to get you, otherwise why are you even a customer (Oracle gets a free pass, because reasons). However, you want to know that they're serious about their claims, and transparency in their tools and processes is a big part of that.
- lonelappde 7y agoAccess Transparency is a new feature, and for some reason pre existing customers used GAuite before Access Transparency.
- paggle 7y agoSure, I was one of them. But if your distrust of Google is high enough to believe that Access Transparency is basically a fake feature (i.e that there is a way for Google employees to access your files without showing up in the logs, except for legally required reasons), then I don't see how or why you would be giving them your files in the first place. I don't think that level of distrust is unreasonable -- Google has proven to be a bad actor in many scenarios -- but I just don't see how you could be a G Suite customer at that level of distrust.
- treypitt 7y agobecause you've planted malware in sheets files and your account is a honeypot to catch the baddies