4 ms·
Pretty much nobody at Google has that kind of access. You can be an SRE of just about anything at Google and never access user data. The "break-glass" means o
by retrovm 7y ago
Pretty much nobody at Google has that kind of access. You can be an SRE of just about anything at Google and never access user data. The "break-glass" means of emergency access is ridiculously booby-trapped. A person wanting to do this thing has to 1) badge into a special room, at which time both production security and privacy incident teams are notified, 2) use a special hardware security device that is used for no other purpose than to activate a VPN box with a hard-line into the production network. By the way if a random Googler just rolls up to a datacenter without a reason to be there, that also triggers privacy incident response, even though physical access to production storage is virtually useless due to all the encryption.
I would say it is much more likely that Google will accidentally lose the organizational ability to become root-in-prod, than it is that a person has done this thing without being noticed.
In short, insider risk cannot be mitigated with hiring practices. You need robust technical measures against insider risk.
- remarkEon 7y agoThanks for proving my point, I guess? I’d love to see a formal write up from google about these procedures. It would go a long way to increasing confidence in how they handle this data.
- mehrdadn 7y agoWhat I would love to see is somebody at Facebook comparing their barriers against accessing user data with these from Google.
- remarkEon 7y agoI’m actually inclined to think they have similar procedures, if only because we haven’t seen “whistle blower” stories in the news about folks reading texts and looking at other private user data. Maybe I’ve missed them, but because bashing Facebook is kind of a trend one would think there’d be an appetite for “I read illicit group texts for a year here’s what I saw AMA” stories.
- dannyw 7y agoIf this happens, every incentive (of every party that is aware) is to not whistleblow, as it is a criminal offence for the snooper, and a PR disaster for the company.
- belltaco 7y agoWhen did that start? Here's an account of someone working at Google accessing info to stalk teens. https://www.businessinsider.com/google-engineer-stalked-teens-spied-on-chats-2010-9 https://www.businessinsider.com/google-engineer-stalked-teen...
- dredmorbius 7y agoThat story dates from 2010. Snowden's revelations (2013) were a major watershed. There'd been several measures taken since, based on what I heard on the outside, largely through discussions, mostly public, a few direct, with Google staff via G+. Starting on, of all days, November 9th, 2016, I began regularly posting an image of Jewish shop windows shattered during Krystallnacht, asking whether Google were thinking of brownshirt-proofing their data. That generated responses including from G+'s architect (then in a role with user data safety & privicy), and the data security lead. It wasn't until some time later that I realised I'd entirely accidentally picked the anniversary of the event for the post. Though the coincidence was useful. My understanding was that numerous protections were in place by that time. I continue to have concerns.
- ForHackernews 7y ago> I began regularly posting an image of Jewish shop windows shattered during Krystallnacht This is so incredibly cringey. You're actively building the panopticon and yet you think of yourselves as righteous warriors for justice. I don't mean this to be a personal attack, but yours is such a revealing comment about the mindset of people inside these surveillance behemoths. (See also: this "pledge" http://neveragain.tech/ http://neveragain.tech/ to not build registries for targeting citizens...signed by a bunch of people who work at companies whose entire business is targeting citizens with ads)
- justinclift 7y ago> Pretty much nobody at Google has that kind of access. Sounds like you'd be surprised at what storage, and backup engineers have access to.
- retrovm 7y agoTremendous amounts of ciphertext?
- justinclift 7y agoBecause encryption keys are never backed up by the same system either? /s
- iratei 7y ago> Pretty much nobody at Google has that kind of access. OK, Google.
- the-rc 7y agoEven if you managed to get direct access to production through the special room's direct link, you'd still need a special kind of credentials to send RPCs to any service. There was a video with some of the datacenter security measures, e.g. iris scanning (just to get yours in the DB required approvals from senior people). On the actual floor, to which very few have actual access, you need to badge both on your way in and out, individually. If you badge out without having badged in, the door won't open and an alarm will go off.