5 ms·
I don't really want to dive into this conversation in any real depth, but I do want to point out that Google+, with old features or new, has never violated the
by Lewisham 13y ago
I don't really want to dive into this conversation in any real depth, but I do want to point out that Google+, with old features or new, has never violated the ACLs that users set. If you set something to private, it remains private forever.
To do otherwise would be corporate suicide.
Disclaimer: I work for Google, but not on G+.
- chimeracoder 13y ago> I do want to point out that Google+, with old features or new, has never violated the ACLs that users set. If you set something to private, it remains private forever. I know that, which is why I used the example of Facebook. However, Google+ does make it incredibly easy to leak information that I would otherwise consider private accidentally. For example, I can't use Google+ with my primary email address, as it's a Google+ account. However, because it's linked with my Gmail account (which does have a Google+ account), some people who have added me on Google+ have been able to figure out my Gmail address (which I haven't used for email purposes in years[0]). I can imagine all the technical reasons for this, but that doesn't change the fact that it feels a bit wrong for a service to hand out my old email address (which I never give out anymore) to people I've met recently and who have added me on Google+ using my current email address. Imagine your Google+ email address is something that you can't change, but don't really want people to see anymore - this isn't uncommon; it appeared in a New York Times piece just yesterday, in the context of college admissions[1]. Thankfully, my personal email address is much more tame than that student's, but that still doesn't mean I want anybody to know or use it nowadays. Furthermore, it's incredibly easy to sign up "accidentally" to use Youtube with Google+ and your "real name" instead of continuing to use your pseudonym. As for the distinction you point out - I know the difference, and you know the difference. But most users don't. > To do otherwise would be corporate suicide. Apparently not completely - Facebook's gotten away with it for years![2] [0] This may have been fixed, since it was a while ago that I last noticed, but it was still the case for quite a while. I would have to go through my inbox to remember the details of why this happened - I remember debugging and tracking it down. But the fact that it took that much effort to discover why my new acquaintances suddenly knew my old (personal) email address, and that I can't remember anymore, speaks volumes as to how easy it would be for a less savvy user to accidentally leak information that they wanted to keep private. [1]http://www.nytimes.com/2013/11/10/business/they-loved-your-gpa-then-they-saw-your-tweets.html?_r=0 http://www.nytimes.com/2013/11/10/business/they-loved-your-g... [2] http://mattmckeon.com/facebook-privacy/ http://mattmckeon.com/facebook-privacy/ - this graph doesn't distinguish clearly between those which were automatically retroactive and those which weren't, but that's a topic that's been well-reported and is easy to search for.
- Lewisham 13y agoI'm honestly not sure how your email address would be leaked, vanity URLs are name-based and at least one of the reasons Plus uses ID strings was in order to prevent leaking any account details through the URL. I'm sorry that other people are figuring it out, that sucks. If you remember what happened and think that G+ has had a hand in the leakage, please feel free to ping me (my URL is in my profile) and I'll try to follow it up. Personally I do feel that G+ has done a good job at communicating to users the privacy they do and don't have, as the ACLs were baked in at the beginning. I think users have had the possibility to be confused when data is being used outside the http://plus.google.com http://plus.google.com domain, like Shared Endorsements and the YouTube comments, as this opens up the worry ACLs are being violated. I think there's more work that can be done to communicate that this hasn't happened, such as putting the "Shared (publicly|privately)" on YouTube comments so you can see why those are there.
- chimeracoder 13y ago> If you remember what happened and think that G+ has had a hand in the leakage, please feel free to ping me (my URL is in my profile) and I'll try to follow it up Thanks for the offer - I really appreciate it. I think it had something to do with group contacts in Gmail, but I can't remember. If I have some time today I might take a look. To clarify: I'm not exactly mad at Google in this case, because I'm a developer and I know how tricky it can be to get these things right even in small, standalone products[0]. And unlike some people on HackerNews, I don't think this is a result of bad intentions. It's just that, every time I see something like this happen (beagle3 points out the example of Buzz below), I can't help but notice that users' trust is both fragile (easily broken) and unforgiving (no benefit of the doubt). These things are tough to get right, but they're very critical for the long-term success of a product. [0] Also, the consequences for me happened to be pretty mild, thankfully.
- rhizome 13y agoIt sounds like it was a failure of design.
- beagle3 13y agoNo, but Buzz was a horrible metadata leak. It's not like there's a guarantee no data will ever leak.