3 ms·
For comparison, at Google in 2011, I was one of ~10 or so engineers that had the ability to view private Gmail or Gplus data (access that was heavily documented
by throwaway220720 6y ago
For comparison, at Google in 2011, I was one of ~10 or so engineers that had the ability to view private Gmail or Gplus data (access that was heavily documented and audited).
That being said, Google did have to go through it's own public humiliation [1] to put a system like that in place.
https://gawker.com/5637234/gcreep-google-engineer-stalked-teens-spied-on-chats https://gawker.com/5637234/gcreep-google-engineer-stalked-te...
- necovek 6y agoDon't all engineers working on Gmail theoretically have the same access by conspiring with a code reviewer or two? It ultimately comes down to the person involved and I do not believe anyone can control the human factor.
- throwaway220720 6y agoThey can easily build and view their own versions of the gmail stack, but they would not be able to generate auth tokens to decode the private data of accounts they did not have passwords for.
- necovek 6y agoI was more thinking of deploying trojan-code into the production service (as a trivial example, allow a special password to access any account): it can't be practical to vet every production service change through too many people. You seem to suggest that you are using an encryption key based on the password or oauth token on login, which is great to hear, which stops the simpler forms of trojans like the example above. That makes it much more involved to achieve the same (and login from new computer reports make it harder too), especially undetected (because it has to happen over a short period) but not impossible (thinking of cases like just making a new API endpoint or perusing an existing one to store actual content in an often unlooked at log file/service).
- koheripbal 6y agoI almost wonder if government officials should be outright banned from using any private messaging platform that isn't hosted by the government itself. There is just too much power in information.
- necovek 6y agoI believe to an extent they are: Hilary Clinton's hacked email was not the govt provided one, and most of the flack she received was for using personal email for gov stuff at all.