5 ms·
Google is watching
- brettgriffin 1y agoWhat I find interesting about this article is that the author is the founder of Cloudera. Cloudera was one of the pioneers of the Hadoop ecosystem (and de facto data lake movements). For the uninitiated, data lakes are used to centralize vast quantities of data - often consumer data - usually by large organizations and governments to provide insights and inform decisions within the organization. Some call this surveillance capitalism. Cloudera IPO'd somewhere around $2B and was taken private in a deal led by KKR for around $5B.
- esafak 1y agoGood catch! Cloudera did not last long and grow enough to suffer the same problem.
- FuckButtons 1y agoOther than possibly loosing social capital, why does this surprise you? they are intimately familiar with the intricacies of how the technology is used to hoard and catalogue every aspect of our digital lives.
- gnerd00 1y agomy neighbor said he recently plugged in his iPhone to a PC while logged in to his Google account in the browser, and all his iPhone contacts were imported into GMail contacts.. is this possible? the contacts are now in Google GMail, and he did not affirmatively consent at any stage, is the story.
- klik99 1y agoI’m pretty sure that Apple blocks any exporting of contacts without consent, maybe he previously consented and it stored it, or he clicked ok without thinking. Even things that require consent can be engineered to make it easy to thoughtlessly agree
- zenmac 1y agoAt this point FOSS address book on F-Droid has a way to store your contact that is NOT visible to other apps.
- zenmac 1y agoWow can't believe this is still happening! Twitter pull that shit very early on iOS before they had the permissions, all my contacts were uploaded to their server. Never ever trust that company again.
- jeffbee 1y agoSure are a lot of leaps of logic in here.
- deleted 1y ago[deleted]
- jkingsman 1y agoI believe the location tracking is necessary for apps that are trying to detect the default/config access point that many devices spawn for setup. As I understand it, because wifi AP name awareness is approximately equal to location knowledge, wifi control requires a location information grant. It doesn't forgive the crummy design that implies (what about providing an allowlist of AP masks that can be scanned for?), but there is another side to the coin of "please give us location access so we can spy on you" in that uses that AREN'T for spying still require the same prompt for permission. I wouldn't say /never/ attribute to malice anywhere we're in the vicinity of an an enormous data actor with a not-great track record, but probably at least /even/ are the number of cases of privacy violation attributable to maliciousness vs. terrible design that is either excessively encumbered or insufficiently granular. I'm perfectly happy for Acme Random App to scan for `pps-setup-wifi-**` at one time, but not all wifi networks forever.
- shaftway 1y agoIt's likely for Bluetooth access rather than WiFi. It's not uncommon for IoT devices to use bluetooth for setup, and it would be trivially cheap to put BLE beacons on every subway station exit in NYC, essentially giving you fine-enough location detection to uniquely identify most people within a week.
- jkingsman 1y agoI believe on Android that's the "find devices near you," which used to be part of location but now is discrete.
- unethical_ban 1y agoGoogle requested access to all the friends pictures? Or is that just the limits of Android permission? GrapheneOS has storage scopes that get between app and OS to be able to do what the author wants: only let the app know of the existence of specific files, not entire libraries.
- foota 1y agoThis is a part of Android natively. I assume that since most users intend to use Google Photos to manage their photos that it would request access to all photos. I don't believe that Google would upload your photos remotely that haven't been backed up through Google Photos. Technically it sounds like their privacy policy would allow photos uploaded to Google to be used for training a model within Photos (e.g., I suspect their Ask Photos AI was probably trained on Google Photos data?) but it states that it won't be used for Ads or for training models outside of Photos.
- antonyl 1y agoCurious to get HN's take on this. I was pretty surprised at Google a few days ago. A family member had recently passed away, and so I Googled ("funeral homes <location>") in incognito on Google Chrome (I suppose it felt a bit sensitive and I didn't want my Google account associated with it). A few minutes later I opened up Google Maps on my phone (different device, but logged into my Google account) and there were a few ads for funeral homes (they looked like squares and were highlighted). Obviously, this is technically feasible: I was on my home internet (both computer & phone), and presumably there are <5 accounts that share this IP address. So when I search, they ~know who I am, and so therefore could serve me ads when I'm logged in. But I was still surprised that Google would do it — I guess I would've thought that Google would drop incognito mode requests and not use them for ad targeting. (Since, well... it is quite trust destructive.) Does anybody know if Google is doing this intentionally? It seems like this is pretty value destructive for them long-term? Or... am I just being paranoid and this is just a frequency illusion?
- zenmac 1y agoI also heard many similar stories. Seems like we may all need to run Tor Browser now!
- thfuran 1y agoI would be surprised if they weren’t. Incognito mode is for cleaning up cookies and browser history, not actual privacy.
- Lammy 1y agohttps://www.skeletonclaw.com/image/710734055173472257 https://www.skeletonclaw.com/image/710734055173472257
- user3939382 1y agoGoogle fully understands that users are reaching for incognito because they want their session to be 100% ephemeral they just don't care because they're paid to not care. Technical distinction between local and remote data is unrelated, Google could offer privacy if they wanted to.
- esafak 1y agoThe good thing is that they are largely a consumer company, which means they are sensitive to consumer sentiment. No users, no ad revenue.
- supportengineer 1y agoI've always wondered why we can't just re-create a product in its original form. The original Dropcams from 2014, along with their app, had a far superior user experience to anything available today.
- mostlysimilar 1y agoYou can. Just be the kind of founder that won't sell out your users for an extra payday (private equity, VC, sale to a bigger corporation, squeezing extra money by enshittifying the product, etc.)
- smartician 1y agoFull disclosure: I'm a Google employee, but not in the areas mentioned in the article. This is my personal opinion. Regarding the Nest thing: I don't think those devices stop working completely if you don't enable location sharing for the "home and away" feature. It might be bad UI that made the user think that this is the case? Regarding photo sharing: I think that permission is necessary to show a "photo picker" inside the app that allows the user to pick and choose which photos to upload. I'm not quite sure what the alternative would look like: "he can identify specific pictures in his library and grant access to just those" --> How exactly would that work without the app having access to the pictures? Also, does the author believe the app would then secretly analyze all pictures and send content back to the mothership without the user's consent? Again, this might be a communication/UX issue...
- rlue 1y agoSelective access to a set of user-specified photos is a native feature of iOS. Any time an app prompts you to choose some photos from your photo reel, you are first given the option to explicitly choose which photos the app even has access to.
- skywhopper 1y agoBad UI is an intentional decision by the app developers to shepherd folks into thinking they have no choice. As for how to make photo library access selective, iOS does this just fine. The app thinks it’s seeing everything, but it can only see what you selected. Plus Apple has made it easy to edit those choices. And if you do grant an app unlimited access, it checks in every once in a while to be sure you still want it (particularly if you don’t use the feature very often).
- KTibow 1y ago> How exactly would that work without the app having access to the pictures? Android recently added an option that lets apps pop up a picker and only get access to the picked pictures. They probably just didn't realize that some users might want to only share some photos with Google Photos or didn't think the slice was big enough to justify implementing.
- 1y ago
- oxqbldpxo 1y agoNothing man-made is free.
- dragonwriter 1y ago> Nothing man-made is free. That's only true if you define "free" differently than it has always been defined in the whole history of using it as a label for man-made things.
- mgiampapa 1y agoInstead of writing a blog post or throwing away a working device, I would have just removed the location permission after updating the wifi...
- skywhopper 1y agoThat hacky workaround is beside the point. Most people arent that conversant with the permissions options on their devices. And even if they are, intentionally forcing them to turn it off is the problem: Google doesn’t care about your experience or your privacy. They just want to take advantage of captive users.
- r2vcap 1y agoIt seems I’m not the only one who feels that Google’s ad tracking has improved a lot — to the point where it makes me a bit nervous. A few days ago, I searched for a medicine just once using Firefox’s private mode, and now both Google search ads and YouTube ads are filled with related topics. Maybe I need to reset all my Google ad tracking IDs and stop using Google for anything sensitive.
- nuker 1y agoCheck out Firefox PPA.
- Permit 1y ago> I acknowledge, by the way, that I use Google services to run my vanity domain, including my web site and mail server. It's a hassle to move all that, but one I am ever nearer to taking on. > And a final response is for the engineers who work for these big tech companies simply to refuse to build systems that work this way. If you're at Google, you have agency – you decide what code you write. Yeah, I know: "No" might get you fired. But there are other jobs. Am I to understand that it’s too much of a hassle to move domains but not to change jobs (after being fired, no less)?
- Firehawke 1y agoYeah, that's a pretty big case of dissonance there. While I agree with large parts of the article in general, the bit about getting yourself fired is just completely out of touch with reality in a job market trying to replace engineers with shitty AI.
- ajross 1y agoNitpick: it's not cognitive dissonance, just "selfishness". Wanting others to take on burdens that you don't want to bear is a universal human desire, and not very surprising. It's just frowned on as a matter of moral philosophy, so you're not supposed to frame it like that in formal writing. The author's crime is poor editing, basically.
- Firehawke 1y agoI never said cognitive, just dissonance. A tension or clash resulting from the combination of two disharmonious or unsuitable elements.
- ajross 1y agoJust to un-spin this a bit... > As part of [a Nest update], Google demanded that I allow the app to track her location at all times, whether the app was active or not. The stated rationale was that it would allow Google to manage devices in her home The app requests the permission via the normal mechanisms any app uses; it doesn't "demand" it. And you don't have to allow it (and of course can turn it off at any time by going to the app's permissions settings). If you don't, it will indeed pop up a warning that it can't enable the home-occupancy-detection feature, and direct you where you need to go to disable that in settings. Contra the confused language in the article, Nest hardware works just fine if you disable that feature, though obviously it's a pretty useful feature to enable. (And yes, I work there, but nowhere near Nest stuff. I do own one though.)
- hopelite 1y agoExpecting engineers to refuse and get themselves fired or even finding another job is not good advice at all. It would be far better advice for people with like minds remain in a company like Google and collect data, share knowledge or information, and maybe even just not make certain improvements, etc. it is always far better to have someone on the inside than not. This self-righteousness of refusing to do something in a system that will hardly notice your protest for more than a day, is utterly foolish. These organizations need to be infiltrated and smartly, using intelligent methods report what is going on. This monster cannot be slayed from the outside and time is running out before tech companies totally remove the human threat vector from the system.
- fallinditch 1y ago> Larry and Sergey said the company's motto was "Don't be evil." I believed them! Yes I believed it too back then, and I reckon Larry and Sergey did too. Whenever I am reminded of this failed motto I can't help but wonder if Larry and Sergey are disturbed by nightmares.
- nuker 1y ago> What do we do to fight it? Switch to Apple, a.k.a Not an Ad Company.
- poemxo 1y agoI had the same train of thought when I moved from Android to iOS, back when Google killed off App Ops. It was incredibly suspicious of Google to remove a tool that lets you take away a permission that an app autogranted itself upon install.
- rob44 1y agoGet in touch with a professional hacker ( tech ) to help hack your cell phone. Trusted and verified with quick responds and legit services. They offer services like (Cell phone hack , GPS tracker, Delete criminal records, Retrieve wallet, Retrieve Gm ail, face book, whatsApp, photos and many more...), All these services are done remotely, distance is not a barrier. You can reach out with them on ( Techspymax @ gm ail c om ).
- rob44 1y ago[dead]