8 ms·
The journalist refers to the feature to delete sensitive locations as a "Privacy promise". Google never uses the word promise, but it does market this feature
by htag 3y ago
The journalist refers to the feature to delete sensitive locations as a "Privacy promise". Google never uses the word promise, but it does market this feature as something that can keep your health data secure. The user shouldn't have to understand how technology works, or have a grasp about how hard the problem is. This is Google over promising and under delivering. This tech is not applicable for the use cases Google bills it as. Users will always hate over promising and under delivering.
This puts people at personal risk, erodes their faith in tech, and provides an image of political grandstanding. (Washington should protect you, but Google will is a major message [0]). I'm defending this guy. He saw Google make a promise it couldn't keep, ran real world tests, and told the world where they fell short. I wish there was more we could do to keep tech companies accountable for failed promises, but this is the bare minimum.
[0] https://blog.google/technology/safety-security/protecting-peoples-privacy-on-health-topics/ https://blog.google/technology/safety-security/protecting-pe...
- Spivak 3y agoThis is 100% the right take. Thinking about it from the perspective of, "well I'm in tech and I know we're all bad at our jobs[1] so of course this will have these failure modes" for a thing that is an actual security feature is totally unacceptable. It cost them nothing to do nothing on this front. There could have been an incognito mode for location history and a "delete the last 4 hours" that, while manual, would have worked 100%. [1] https://xkcd.com/2030/ https://xkcd.com/2030/
- rattlesnakedave 3y ago> The user shouldn't have to understand how technology works, or have a grasp about how hard the problem is. They enabled location tracking, and got mad when their location was tracked. You can really only do so much from the product side here. Personal responsibility has to come into play at some point.
- flangola7 3y agoFunny how "personal responsibility" always applies to the consumer and never to the developers and corporations.
- vuln 3y agoCorporations are not people. Full stop.
- Randomizer42 3y agoActually they are. Look up the definition of a corporation.
- JohnFen 3y agoPeople work for a corporation, but a corporation is not a person. It is a legal entity that exists separately and distinct from the people that work for it.
- brightlancer 3y agoLegally, a corporation is a person. It's not a human being, but it is a person. This was not some accident of the law: this was deliberately designed hundreds of years ago and is well understood outside of internet comment sections.
- JohnFen 3y ago> Legally, a corporation is a person. It's not a human being, but it is a person. A corporation is a unique legal entity that has a limited subset of the rights of a person, but is not considered the same as a person as a blanket statement. Specifically, a corporation is considered a "person" for the purposes of being able to enter into contracts, being able to sue and be sued, and similar.
- corndoge 3y agoBrave
- htag 3y agoSo your position is "buyer beware". A company can make untrue claims about their product, and all of the responsibility rests on the consumer. I do not want to be a consumer in that world.
- rattlesnakedave 3y ago> Location History: Location History is a Google account setting that is off by default, and for those that turn it on, we provide simple controls like auto-delete so users can easily delete parts, or all, of their data at any time. Some of the places people visit — including medical facilities like counseling centers, domestic violence shelters, abortion clinics, fertility centers, addiction treatment facilities, weight loss clinics, cosmetic surgery clinics, and others — can be particularly personal. Today, we’re announcing that if our systems identify that someone has visited one of these places, we will delete these entries from Location History soon after they visit. This change will take effect in the coming weeks. This seems to be pretty clearly what was happening, as described by the author of the article. *If* the systems detected an abortion clinic visit, it was deleted. No further guarantees were made in the blog post. The same post provides links to documentation on managing your location settings and history, so the user can adjust if they are unhappy with Google's behavior.
- htag 3y agoThe blog post spends lot of effort talking about the importance of privacy, and protecting your health data. It shames other organizations for not protecting your privacy. It describes how privacy is a value at Google. Then it announces auto-delete as one of their major features. A journalist reported auto-delete works about half of the time. Strictly speaking I'm unsure if something illegal happened. Ethically it feels like Google is overpromising and making empty political gestures. I just hope no one relies on this feature for their personal or legal safety.
- junofan 3y agoCome on. The VP of whatever signed off on the press release and moved on. There’s a problem here.
- coding123 3y agoThis isn't about the journalist, it's about the millions of people they are trying to help that have no freaking clue about what location history means.
- hutzlibu 3y ago"that have no freaking clue about what location history means" Then maybe they should not activate, what they don't understand? Location history is opt in, you have to enable it by hand. So google overpromising is one thing, but people acting infantil is something else.
- bakugo 3y ago> it's about the millions of people they are trying to help that have no freaking clue about what location history means. Maybe they should consider learning to read before complaining about not being able to understand things? Google very clearly explains what it means.
- stef25 3y ago> Personal responsibility has to come into play at some point Amazing that there will be people who find this preposterous. Everything must be perfect. Including free shit that logs your secret abortions.
- JKCalhoun 3y agoWe're engineers, we could implement location tracking in a way that only the user being tracked has access to it. Google could store it in the cloud but encrypted with a key Google has no access to. It's irresponsible I think in 2023 to have any technology that is this privacy-vacuous.
- rattlesnakedave 3y ago> We're engineers, we could implement location tracking in a way that only the user being tracked has access to it. Google could store it in the cloud but encrypted with a key Google has no access to. Many other features that people find useful wouldn't be possible in this world. If that's the product you want, find an alternative that's not Google maps. I suggest OsmAnd.
- nilespotter 3y agoHe's probably not even mad, but rather eager to seize on a flimsy pretext to write a hysterical headline. A simple report to Google would have sufficed.
- SiempreViernes 3y agoThis is the report to Google though? Or do you suggest he should have turned to googles fabled "customer support"?
- nilespotter 3y agoYes, whatever their normal reporting avenue is, rather than a hyperbolic not-news article
- nugget 3y agoThere are privacy "promises" and then there are privacy laws like CCPA in California which companies are supposed to comply with. CCPA requires data brokers and large tech companies to maintain at least two channels by which users (including users who have no account / nothing to do with the company) can submit basic privacy requests like right to know and right to delete. I searched for a couple hours last week and couldn't find a single way to submit a CCPA request to Google. If anyone has the links, I'd love to be proven wrong here, but the sense I came away with is that Google is somewhat hostile towards real, accessible user privacy.
- Deathmax 3y ago> I searched for a couple hours last week and couldn't find a single way to submit a CCPA request to Google. 1. Navigate to google.com 2. Click on Privacy on the bottom of the page, redirecting to https://www.google.com/intl/en/policies/privacy/ https://www.google.com/intl/en/policies/privacy/ > https://policies.google.com/privacy https://policies.google.com/privacy 3. Go to the "U.S. state law requirements" section, click on the "contact Google" link which redirects to https://support.google.com/policies/answer/9581826 https://support.google.com/policies/answer/9581826 4. Go to "Your privacy & security controls" > "Get help with privacy-related questions" > "Contact Google's Data Protection Office", and you get a link to their web form at https://support.google.com/policies/contact/general_privacy_form https://support.google.com/policies/contact/general_privacy_.... The privacy policy can differ from country to country, I had to proxy into the US to get the section on US state law requirements, otherwise from the UK it's replaced with a European requirements section instead. > CCPA requires data brokers and large tech companies to maintain at least two channels My interpretation of the CCPA is such that a business that operates exclusively online only needs to provide an email address and the two or more designated methods does not apply.