The first step to data privacy is admitting you have a problem, Google
- Reference: 1648462627
- News link: https://www.theregister.co.uk/2022/03/28/google_data_privacy/
- Source link:
It didn't tell us, it didn't give us the option to stop it, and it didn't say what it was doing with all that data.
Google didn't have a leg to stand on. It coughed to the caper and promised to do better. As it has done previously, such as when its Street View mapping mobiles were shown to be [2]veritable black holes of Wi-Fi suckage . That history of leglessness suggests the company loves data a little too much for self-control. Google's dataholic behavior may take more than promises to fix.
[3]
That Google's problem is our problem is eloquently illustrated by [4]Leith's paper on his research . The question he asks is simple: what do the Android Messages and Dialer apps send to Google? The answer could only be found by an impressive display of mid-to-high-level infosec skills, backed up by lots of hard work and determination.
[5]
[6]
In brief, Leith set up a man-in-the-middle attack on his phones to crack open the data links' HTTPS/SSL encryption. He dug out as much as possible about the services Google was using to log this data, which involved doing the sort of things we're not supposed to do, like side-loading APKs from third-party app stores. This can be safe if you know what you're doing, which Professor Leith does. And that's all just the start: there's a ton of raw binary to analyse next.
Because it follows the protocols of science, the paper is a splendid how-to on hacking your own phone. It stands as witness to why attempts to limit security analysis should be fiercely resisted. Looking at you, [7]Governor Mike Parson . Yet as Leith admits, even after all that, he couldn't fully answer the question he asked himself.
[8]
The amount of data, the number of different ways it can move across the network, and the potential extra layers of in-app encryption mean you're going to bail once you've got enough, not when you've got it all. That's before you factor in the constantly changing behavior of apps that are constantly updating on an OS that is itself a moving target, never mind that the telemetry actually used could change from day to day, even hour by hour.
So if an actual professor of computer science can't find out about the full data privacy provision of just two apps, what chance do the rest of us have? If the security we demand to keep our data safe from attackers is instead shielding it from our own scrutiny, to protect abuse?
Let's tackle that by assuming good faith, that the abuse isn't the product of evil intent but bad habits brought on by dataholic intoxication. It's part of a more general problem, that complex systems built by humans to achieve goals can encourage undesirable patterns. This is explicitly recognized by organizations when it comes to code security; we know we can't always get it right, they say, so here are bug bounties to anyone who gets to the vulnerabilities before the bad guys.
[9]
That works. So let's extend the idea to privacy violation bounties. Find us breaking the rules and endangering our customers' privacy, and we'll reward you. They'll love that, right? The logic's the same, though; if you've made a mistake, you want to find it before it bites you and your customers, and does it matter whether the mistake is one in code or one in process? Encouraging bright, well-motivated people to help you here means more Professor Leiths will make you better.
The other major change in behavior that would help eradicate the class of error uncovered here is simple documentation. A lot of the data involved was under cover of "analytics," vaguely defined and never explained, some of which were deemed essential and some of which were optional. "We're going to use this to make things work better" is about as much as you're told.
[10]File Explorer fiasco: Window to Microsoft's mixed-up motivations
[11]114 billion transistors, one big meh. Apple's M1 Ultra wake-up call
[12]Machine learning the hard way: IBM Watson's fatal misdiagnosis
[13]IPv6 is built to be better, but that's not the route to success
That's hooey. Google knows what every byte of that data is, and what it's used for. So should we. The information exists. Let's have it. Let's have it in properly structured documents, available through an automated freedom of information request system – don't want to make it too burdensome, do we? – with types, structures, APIs, and purpose. Keep it up to date. Give it to us in ways we can use to automate our checks. All this is standard DevOps scaffolding: loop us in, and do it properly. Isn't that how DevOps is supposed to work?
In return for taking responsibilities seriously, companies who do take the pledge to handle their dataholism should get that good faith recognized if GDPR problems do subsequently occur. As with all regulation, the demonstration of bona fides goes a long way to mitigate offences. That's a bang-up benefit.
It's to Professor Leith's credit that he did this work, and to Google's that it took it on the chin. It is to nobody's credit that an industry which already has the tools, the experience, and the motivation to vastly simplify such work has failed to do so, nor even have a proper discussion about it.
Dataholism may not be curable, but it can be controlled: sign the pledge, sober up, and fly right. ®
Get our [14]Tech Resources
[1] https://www.theregister.com/2022/03/21/google_messages_gdpr/
[2] https://www.theregister.com/2010/05/18/google_street_view_wifi_analysis/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YkHbtn75EiY-Alsk444RUwAAAFQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.scss.tcd.ie/doug.leith/privacyofdialerandsmsapps.pdf
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YkHbtn75EiY-Alsk444RUwAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YkHbtn75EiY-Alsk444RUwAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2021/10/15/missouri_governor_prosecution_html_source_code/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YkHbtn75EiY-Alsk444RUwAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YkHbtn75EiY-Alsk444RUwAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2022/03/21/file_explorer_fiasco_column/
[11] https://www.theregister.com/2022/03/14/apple_m1_opinion_column/
[12] https://www.theregister.com/2022/01/31/machine_learning_the_hard_way/
[13] https://www.theregister.com/2022/01/24/opinion_column_ipv6/
[14] https://whitepapers.theregister.com/
Re: How often do we get to hear "Sorry"......
Now Google have the passwords for most APs in the world because Android syncs a backup copy, but it seems nobody cares about that.
Re: How often do we get to hear "Sorry"......
Simple answer maybe. Tax storage of non-anonymized data beyond a few hundred bytes of basic identifying information -- user name, contact info, password. Apply the tax to any digital storage on your country's citizens anywhere on the planet (No more "the information is stored in Ireland and you can't tax/examine/whatever it the US/EU/wherever). Make the tax high enough to discourage random data collection, but low enough that businesses can store data data on online transactions without increasing prices. Enact substantial fines for violating the spirit of the rules. Multiply the fines by 50 if the violation appears to be deliberate.
"Let's tackle that by assuming good faith"
That's the first mistake. There's no good faith. They hoard data because the want them to make more money. There will never be a "market self-regulation" - they will only bow, and not without fighting, lying and blackmailing - to laws that will make that behaviour a crime. And when I wrote "crime" I mean executive should get jail time for stealing user data - fees are no longer enough.
Re: "Let's tackle that by assuming good faith"
... the first mistake.
The most important mistake, if it was ever one.
I have always had serious doubts about that.
There's no good faith.
There never was, from the very beginning.
... hoard data because ...
Because it is what they do to make money by the shitload by selling/sharing/using it a myriad of ways.
And, as professor Leith has discovered, their system to make good on their illegal activities is designed to be as opaque as possible if not practically invisible.
Kudos to Leith for his hard work, his works opens a tiny window on what is going on.
But unless Google is fined 15 or 20 billion (yesterday) and then split up in 100 different baby Googles, it will have been all for nought because it is probably/already too late.
It has to be dealt with as a foreign company belonging to the enemy in times of war.
It is easy:
"Google, you have done this far too many times. Now, your time is up."
But there's far too much money and far too much power in Google's hands and a great many others benefit from that, the first ones being the governments and other corporations who cozy up to them.
In short: we're all thoroughly fucked.
O.
Re: "Let's tackle that by assuming good faith"
I'd say the first, and most important, mistake was to start by accepting that customer data was there for the hosts to harvest. Yes Google's stuff is "free" so if we want it we have to accept that they will throw adverts at us. They exist to make money. But we allowed them to go three significant steps further straight away. To accumulate, store and aggregate the data.
So they don't just send us adverts to get money, or even identify the content we are seeking/sending and immediately send us relevant adverts (you mention socks you get a sock advert), but they were allowed to store that information and use it to build up a database on each of us and then sell us to advertisers as a package. It's the difference between using data and stealing data.
Re: "Let's tackle that by assuming good faith"
"...and then sell us to advertisers as a package..."
And to governments. What we do today may not be a crime, but when it becomes a crime in the future we will be exploited, hoist by our own, newly-christened data-petard.
Re: "Let's tackle that by assuming good faith"
I think here the point of stating "by assuming good faith" is *not* because you actually believe there is good faith; it is rather to make it harder for the target to reject your arguments by characterising you as hostile.
Instead they have to actually engage in a discussion about how any claim to "good faith" they might make can be demonstrated; so, to an extent, *you* have set out the ground on which to debate the issue.
And if the target then tries to shift the focus of the debate away from "good faith", they can end up looking as if (or perhaps demonstrating that) they lack it.
Re: "Let's tackle that by assuming good faith"
Google & C. must be now assumed to be "hostile" entities. They become so large and so rich exploiting data they are prepared to fight every inch to avoid their business model upended.
They are trying to make people believe this is the only business model and surrendering data is inevitable - "resistance is futile". There could be no discussion about that - they will try to hoard ore and more to see how far they can go before getting caught, and how far again before being stopped. And once there it will be very difficult to push them back.
The only ground on which to debate this issue is people's rights.
Time to ramp up enforcement
This is a clear breach of GDPR. Collecting and exporting data without informing us. Let alone allowing an opt-out.
Up until now the fines have been little warning nibbles, but now the courts should bite hard. What is 4% of Google's gross?
Re: Time to ramp up enforcement
Can we multiply that 4% by 26/27?
Re: Time to ramp up enforcement
As long as the Irish Leprechauns are in charge for these violations, Google will put a pot full of gold at the end of the rainbow and get a slap on the wrist. I believe there should be a EU Privacy Special Unit in charge of the biggest transnational data hoarders. They are not different from Al Capone.
Reality check
> isn't the action of a well company
Shareholders might disagree strongly... Sorry, but you're assuming an ethical, just and altruistic society where people strive to help their fellow (wo)man. Actually it's a shameless, pathologically egoistic society where you have to stick it to the others, even if it costs you. And Google is just a child of its time, just more shameless than the others.
As much as it pains me, Google isn't the problem, it's us, all of us. Google is just the brat we terminally spoiled. If those values we pretend we adhere to were anything more than empty catchwords, our politics would be clean and serving the nation, not themselves, and companies would try to make money while respecting the law and a strong ethical guideline. Yeah, snowball's chance in hell, but we should at least try (instead of ignoring the problem), shouldn't we? Instead of running around like headless chicken crying "Help! The house I've put on fire is burning !"
Re: Reality check
Google isn't the problem, it's us, all of us. Google is just the brat we terminally spoiled. That is not exactly true. The drug-addict (user) is not the primary to blame. You should blame the drug-dealer (google) pushing the addicts.
Google has long known that it sells mobile addiction in exchange for the user's data. That means they are actively exploiting the users and reinforcing the user's addiction by any means possible. The same goes for all the other (big) players. They know how it works and don't care about the well-being of the users. They only care about the bottom line, just like any other drug-dealer.
Re: Reality check
"Google is just the brat we terminally spoiled."
Yes, but once we find we've created this outcome, this brat, this bête noire, we still have an obligation to drown it in the pond out back.
Let's tackle that by assuming good faith...
"...that the abuse isn't the product of evil intent but bad habits brought on by dataholic intoxication."
That's just it though, isn't it, one begets the other. The reason that dataholic intoxication exists (nice phrase, but I prefer "data fetishism" myself), not just in google but elsewhere, is because of the product of evil intent. I have no doubt that it would exist anyway but with everyone and their granny siphoning up as much data as they can, is anyone surprised?
Re: Let's tackle that by assuming good faith...
They seem to forget Data Science 101.
Data + Context = Information.
All this data is without context is worthless.
Google Access Denied for your link to Douglas Leith report
But I found it here:
https://www.scss.tcd.ie/doug.leith/privacyofdialerandsmsapps.pdf
Re: Google Access Denied for your link to Douglas Leith report
I'd quibble with one point in the paper. He complains that there's no way to opt-out of excessive data collection. This should, of course, say that it shouldn't happen without an opt-in.
Use the right word, please
-> Google's dataholic behavior may take more than promises to fix.
Google's diabolic behaviour...
If you use a Google phone, you are feeding the NSA with details about yourself.
Re: Use the right word, please
You should fear Google much more than the NSA....
Re: Use the right word, please
You should fear Google much more than the NSA....
True, because there is N o S uch A gency
"Google knows what every byte of that data is, and what it's used for"
I think that's very optimistic. In a lot of cases, Google has been hoovering up data without even having any idea whether it would ever be useful... Just in case.
Re: "Google knows what every byte of that data is, and what it's used for"
This statement again, assumes good faith (and as a post some distance above states, it's about setting the terms of the discussion).
Because, of course, the (hypothetically in-good-faith) data-hoovering behemoth has had teams of lawyers and technical experts plough through the various classes of data they collect, and has systematically categorised every data-point collected. Otherwise, they'd be breaking the law...
Hey Google!
How about stopping the practice of slurping every bit of data on each and every one of us that you can. That is just wrong.
Start cleaning your own house Google.
meanwhile...
...for those who would like an immediate solution, I suggest installing NetGuard and setting it to block these apps from being able to send/receive data. I recommend setting it to "whitelist" mode, and allowing only the few apps that *you* know absolutely need network access.
NetGuard is open source; you can get it from f-droid also if, like me, you avoid the plague-store.
Google doesn't "HAVE" a problem. Google "IS" a problem.
We block their stuff at the firewall level.
Someone here said they exist to make money. No they don't, they exist to spy on people and harvest your data.
Teach your kids to stop using the term "google for something", it's a problem that is embedded in the fabric of society and they need to be stomped out.
"You have no privacy, get over it"
Sorry, we're not getting over it.
It's not because you have the means, that you have the right.
And if you can't understand that, let me come over with a cluebat and I will make you understand.
Google is a group of people (so is Facebook)
So we have to assume that the people at Google and Facebook (and others) get paid LOTS of money to leave their ethics at the door.
If you know someone that works there, try having a conversation with them about this. Push them a bit. See where it gets you (and tell us). Can they defend what they are doing? If so, how? Try to do it without starting the conversation with 'Look, arsehole...'
Put a camera up to film their house. Put a microphone in their lounge and car. Hell, put a camera in their bedroom. Or at least suggest that you think that would be fine. Tell us what they say.
How often do we get to hear "Sorry"......
....only after egregious deeds are discovered?
....and this has been going on for a while now. Take this Google example from 2010 (yup....twelve years ago):
Link: https://www.wired.com/2012/05/google-wifi-fcc-investigation/
...now this!!
Personally, I don't believe a word of apology from any of them....Google, Facebook, Amazon, Microsoft, the NSA......
They are all responsible for the complete lack of privacy in the modern world.....responsible, maybe....BUT NOT ACCOUNTABLE!!!
When will the masses rise up and stop this charade?