4 ms·
Google has a huge number of activist (and surely some corruptible) employees, and yet the incidents of users data getting out are very close to zero. I think t
by tomComb 6y ago
Google has a huge number of activist (and surely some corruptible) employees, and yet the incidents of users data getting out are very close to zero.
I think this demonstrates that user data can be managed safely and effectively.
Usually the incidents reports on user data leaks show that the company seemed to barely be trying - We need laws that force them (even small companies) to put serious effort into it.
- varispeed 6y agoYou don't know that. While the publicly available data leaks are indeed rare, you cannot know if they don't use the data for trading or other purposes for their personal gain without disclosing it to the public.
- tomComb 6y agoThere are infinite things we can't know - opening the discussion up to that really makes anything possible, but the discussion wasn't even about what they might do with the data beyond leaking or selling it.
- Judgmentality 6y agoSure, but if you have no evidence of it happening you have a fairly weak argument.
- varispeed 6y agoPeople do have access to privileged information and that will influence their decisions on both conscious and unconscious levels. It's not possible to detach yourself from work completely and asses your thinking whether it is influenced by something you saw or not on an objective level. It will also be difficult to prove. For example if an employee hobby is trading, how do you prove that the trades they made are based on their own independent research or based on what they saw? If they saw something that could make them money, they could easily create a trail of evidence that they researched the matter on their own - it will be difficult to prove that it originated from looking up the privileged information and unless someone is going to be making millions, it's frankly not economical to commit resources to. It is also in the interest of the company that such incidents don't see the light of day.
- Judgmentality 6y agoI understand your point, but everything you're saying is hypothetical. You're not going to persuade anyone of something happening if you can't come up with any evidence of it happening.
- cutemonster 6y ago> Google has a huge number of activist (and surely some corruptible) employees, and yet the incidents of users data getting out are very close to zero Am I reading this wrong, or are you saying that activists would be more likely to leak data? Then I would wonder what kind of activists you have in mind. Agreed that yes indeed it seems possible to build a security serious company, and that Google is (seems to be) a good example. (Now, there are other things I don't like about Google but I guess that's of topic.)
- thu2111 6y agoSurely they would. We already learned that members of their own security team don't seem to see any problems with employees abusing privileged access to mandatory Chrome extensions to agitate for unionisation (at Google of all places!!). Twitter employees screwed with the account of the president of the United States. Ideological employees of big tech firms taking a sudden disliking to someone or some group and abusing privileged access is certainly a threat that ever larger numbers of people are talking seriously. In particular, it is a concern for industries that do things activists don't like, such as working with immigration control (though perhaps that's no longer an issue now Trump is gone).
- cutemonster 6y ago> employees abusing privileged access to mandatory Chrome extensions Sounds interesting, you don't happen to have a link? (So I can read more)
- thu2111 6y agohttps://www.nbcnews.com/news/all/security-engineer-says-google-fired-her-trying-notify-co-workers-n1103031 https://www.nbcnews.com/news/all/security-engineer-says-goog... Kathryn Spiers, who worked as a security engineer, updated an internal Chrome browser extension so that each time Google employees visited the website of IRI Consultants — the Troy, Michigan, firm that Google hired this year amid a groundswell of labor activism at the company — they would see a pop-up message that read: “Googlers have the right to participate in protected concerted activities.” Discussion here: https://news.ycombinator.com/item?id=21813619 https://news.ycombinator.com/item?id=21813619 Note that she wasn't able to do that unilaterally. Some other member of the team approved her CL and others defended her in public. I have a vague feeling there was another case like this some years ago where some security engineer modified a Chrome extension for political reasons, but I can't remember the exact details and can no longer find it.