6 ms·
You're a step too far with your assumptions. I'm a Googler. I've noped away when Pebble sold to Fitbit. But seeing from the inside how Google treats user data,
by lrem 4y ago
You're a step too far with your assumptions. I'm a Googler. I've noped away when Pebble sold to Fitbit. But seeing from the inside how Google treats user data, I'd be 100% ok with the data going to Google instead.
- ernopp 4y agoCan you expand a bit on the quality of Google's internal practices with user data? eg what would an engineer on Google Photos need to do to be able to access my photos, if possible at all
- Eridrus 4y agoIn general, SWE/SRE do not have access to user data. SWEs just have no prod access at all, and SREs generally only have the ability to run signed binaries with code that has been code reviewed and submitted, though there are obviously break glass features with auditing. Though I am not super familiar with them. ML is where things tend to be a little bit more grey overall since being able to look at data is very useful for development, so some things are scrubbed for PII, but then accessible in some form. But for things like GMail or Photos, I would assume nobody (including ML engineers) can read your data as these are basically impossible to sanitize. Some products have systems train ML models without engineers seeing the data, e.g. spam filtering, even when the underlying data is considered sensitive.
- hansvm 4y agoBasically all the data is available with no oversight if you ask permission and have some allusion to a relevant $JOB reason to need it. The fairly recent case of people's private conversations being shipped out to basically unvetted contractors for labeling and analysis (and subsequently leaked) should serve as sufficient evidence that "shit happens," and if private conversations without having even initiated an interaction with your Google devices are being tossed around and leaked, forgive me if I don't believe that when producing the tagging, timeline, and album features in Google Photos there wasn't some underpaid, unwatched contractor snooping through my photos without my permission.
- lrem 4y agoI believe I can share an anecdote: a while ago I have uploaded a bunch of photos of a work event to the corporate account. This being corporate, it runs pre-release of everything. The gallery managed to hit some bug in the jillions of lines of Javascript, which I never cared to understand. I reported the bug. Knowing how security works technically, I added to the bug the words "I'm happy with whoever works on this to take a look at the gallery, here's a world-readable sharing link". A couple rounds of bug comments later, I have been asked to sign a legally binding consent form allowing an engineer to look at the gallery. Then somehow they decided I need to sign a different form to satisfy whatever other legal spirit needed appeasing. Only then someone finally looked at the bundle of photos. They figured out whatever was triggering the bug. They generated a gallery reproducing the bug with generic sample images. Whoever worked on the bug and adding a regression test worked off that synthetic gallery instead.
- imiric 4y agoMy concern—and I think what everyone's concern should be—is not that Google employees have access to my data. Or even that it's used to train ML models. It's that my data is sold to advertisers via a shady behind-the-scenes marketplace, and later used to profile me in order to show me content that manipulates me into spending money. And that, moreover, I get none of the profits from these transactions, and have no control over whom it's sold to and under what terms.
- addandsubtract 4y agoOk, I'll bite. How does Google, in your opinion, treat user data?
- jfghi 4y agoVacuum everything constantly and then horde it like Smaug, if Smaug was an unscrupulous salesman in a polyester suit? But somehow this is ok because within Google the common employee doesn’t have access, but is rather incentivized to make the vacuum or selling more efficient?
- smoldesu 4y agoAre you under the impression that the rest of FAANG doesn't do this? If so, I've got some big news for you... When people talk about 'security' at Amazon/Microsoft/Google/Apple, they're describing audit performance and ISO compliance. From a business perspective, that's really the only thing that matters. Everything else is played pretty fast-and-loose. Both Apple and Microsoft have been caught backdooring their infrastructure for foreign governments, if anyone out there still has faith in these companies then I hope they stop taking life advice from VC heads.
- jfghi 4y agoDisagreeing with the practices of one company doesn’t indicate support of companies with potentially similar practices.
- deleted 4y ago[deleted]
- mastazi 4y agoI agree with your second paragraph, but I don't understand the point of the first? Are you saying that Google can be forgiven, since its competitors do the same?
- 4y ago
- saagarjha 4y agoGoogle is a large company. You know how your team treats user data, but it would be difficult to have visibility into what all teams are doing. It only takes one or two to ruin user trust for years.
- jefftk 4y agoSort of? Unusually for a company of this size there's a ton of standardization and cross-company consistency. In this case, I believe the whole company (aside from very recent acquisitions still being migrated) used the same logs access framework. I think this is part of why Google has earned itself a reputation for killing things: if you require everything to use the same set of internal systems, and can't just leave old projects limping along on a fork of a deprecated system, the cost of keeping old things around is higher. (I worked at Google until June)
- saagarjha 4y agoI cannot speak for my employer, but I can speak in general terms that I agree that companies of this size have processes to try to avoid this kind of thing from happening. This is true at Google scale but also true once your company passes a certain size+age, although of course it can continue to mature. The thing is that these processes don't actually work, because in the end someone is going to do something dumb anyways and you really can't stop them. The same way your processes aren't going to stop an outage, someone is going to correlate data they shouldn't and somehow lack the tact to go "hey maybe I should not be doing this". Often various pressures will make it seem like something they should do. And when they do it they will cost the company an incalculable amount of user trust, to say nothing of the irreversibility of a privacy incident. Someone will do a writeup of it after it is discovered by the press but at that point the damage is done. (FWIW, I'm not even including the stuff that goes on with executive approval, where they make decisions on how likely they think they are going to be discovered and sued for large amounts of money. Of course this would bypass any policy…but it's usually kept under wraps for obvious reasons.)
- lrem 4y agoParadoxically, trust-ruining incidents is what makes Google trustworthy. There's a strong postmortem culture. "We messed up, what systems and processes are now needed to never mess up like this again?" I hear that's also reinforced by how legal achieves settlements. And usually it's one team messing up, but all of Google being in scope of the remediation. This has the downside that the number of organisations that need to approve any launch ends up being borderline overwhelming. This is a big part of why it takes so long, if at all, to get Google products outside the US. Another implication is needing the expensive security org and culture.
- mastazi 4y ago> But seeing from the inside how Google treats user data, I'd be 100% ok with the data going to Google instead. how does this make the following OK? > No Pebble user ever consented to their health data being sold to Google, but all of this is legal.
- lrem 4y agoI extrapolated this into the hypothetical "if asked, users would not consent to this sale". I would consent to it though. Entirely possible I misread the spirit behind the letter of what GP wrote.
- GeekyBear 4y agoI just can't imagine how you would think that others will just ignore Google's history of violating it's privacy promises. >In today's Big Tech antitrust hearing in front of a Congressional subcommittee, representative Val Demings questioned Google CEO Sundar Pichai about the company's merger with DoubleClick. Specifically, the way Google combined data from the advertising company -- bought in 2007 -- with Google's own data. Founder Sergey Brin had told Congress it would not combine the personal information, but the company quietly did so in 2016 anyway. https://www.engadget.com/google-antitrust-hearing-doubleclick-200745163.html https://www.engadget.com/google-antitrust-hearing-doubleclic... >Google’s privacy policies as of March 1, 2012 established that no combination between DoubleClick’s advertising data and Google’s personally-identifiable information would take place without the prior consent of its users, but an updated version of those policies subtly allowed the integration of both databases regardless of prior consent of its users https://www.promarket.org/2020/08/21/why-we-should-be-careful-about-googles-promises-in-the-fitbit-deal/ https://www.promarket.org/2020/08/21/why-we-should-be-carefu...
- stingraycharles 4y agoI think the parent is implying Google is better than Fitbit, rather than Google doing everything correctly. If the grandparent’s comment is correct, then I have no trouble believing Google will be an improvement.
- int_19h 4y agoWith Google, the more likely problem is that you get algorithmically banned with no recourse, and your Fitbit just stops working.
- edgefield 4y agoYes, because Google’s advertising based revenue model provides the right incentive scheme to discourage use of personal data to increase revenue and profits?
- jnwatson 4y agoGoogle signed an agreement with the EU that said we wouldn’t. Bad things would happen if they did. As a Googler that has access to some Fitbit stuff, I have to sign a form every 30 days that indicates I understand this.
- TedDoesntTalk 4y agoThat EU agreement is only for 10 years, starting from 2019. So it’s got 7 years before expiring?
- gaius_baltar 4y agoBut will Google respect this agreement? If the expected fines are lower the the value extracted from the data or if they can drag the eventual lawsuits for a long time, I'm pretty sure they will just exploit that information anyway.
- stjohnswarts 4y agoA whole lot of the world uses google but isn't under EU law (I'm in the USA and EU laws don't mean anything here) so how would that protect the rest of us?
- lrvick 4y agoAre we talking about the same Google who empowered blanket keyword search warrants? You could argue they had no choice, but I could argue that they had the choice to allow search history to be end to end encrypted and/or anonymous. That is if their business model did not rely on selling plaintext PII. https://www.nbcnews.com/news/us-news/police-google-reverse-keyword-searches-rcna35749 https://www.nbcnews.com/news/us-news/police-google-reverse-k...
- stjohnswarts 4y agoSince you have the inside scoop does this mean that as a result your health data is hooked into your regular gmail/docs account and the info sold to whomever wants to buy it as well as used for advertising? Say I'm 40lbs overweight and 55 so I'm quite possibly have diabetes and would be a mark for diabetes medicine?
- lrem 4y agoAn easy one: Google doesn't sell your data. For using it internally: health data is widely considered toxic. As in "I'm not touching that thing with a barge pole" toxic. I would personally be pretty surprised if Google ever started monetising it.