Google did something seriously wrong
scripting.com
scripting.com
I wrote more about their arrogance here: http://alanhogan.com/arrogance-of-google
(It says something that every time I criticize Google publicly I get a little scared because I know that flipping a bit in the Googleplex would cause my business to fold like an origami crane. Granted, they probably wouldn't play favorites with a site as small as mine. Probably.)
I trust the cops but I'm a big fan of having an adversarial process in place which reflexively distrusts them, because should the cops decide you're guilty for reasons fair or foul, the deck is otherwise incredibly stacked against you. I feel the same way about Google: they're a wonderful company, they've done more to improve the human experience than probably any other company in the last twenty years, and I assume every word out of their mouth is a lie until presented with evidence to the contrary. Note that if you do this you'll quickly clue onto the fact that aside from the meaningless PR about openness and self-righteousness about "evil" they are a ridiculously non-transparent company.
The answer for users is "don't trust Google with your information, and get as much of it out of Google's control as you can, even though you don't know how much there is and can't take some of it back."
But we knew that already. The question is "when will Google stop unethically publicizing all the information we don't forcibly remove from their control?"
It's interesting because I've rationally understood how scary it is that they have all of this data about me. Now I can finally see that there are places where it may come out, or they get hacked and someone steals it etc.
Just a wake up call really, which is something that Google should be scared about, because they have a scary amount of data bout all of us.
That unpology that they posted certainly isn't helping, either.
Google didn't set out to be evil or clumsy in this case. They created the product with the best of intentions: to improve your connections with your network, and as a result make that network (that they host) more valuable to them. I'm sure "win-win" was probably said in more than one conference room.
But they made a number of mistakes, in implementation and in rollout. Most of the mistakes were minor, but amplified by "the millions that have signed up with Buzz!" A few mistakes were serious and possibly dangerous to a smaller number of people. Personal and child security were mentioned by more than one commenter.
One of the lessons learned from this, and any other misuse of data, is that your data will almost certainly be misused, on purpose or by accident. The more data, especially in one place, the more certain. I think the freelancers who suddenly had their clients exposed to each other were somewhere between surprised and horrified.
My own actions include not using my gmail account anymore, since a couple years. I use some of their products, but I don't sign in unless I need to be signed in to do something.
That doesn't mean that Google doesn't still know a lot about me. Even if I never had a gmail account they would still know a large part of my network, because a large number of my correspondents use gmail. Depending on my correspondents, I might become interesting to the Chinese government in another breakin, or I might get unwanted attention from law enforcement because I correspond with on of their suspects, creating even more potential for mistakes and misuse. The larger my actual or accidental Google network, the more likely something like that might happen.
There's nothing wrong with using Google. There's nothing wrong with using free services. But you should certainly think about how things can go wrong, and proceed from there. If you need your data to be online, it might make sense to keep some of your data with a paid for service (they aren't expensive) whose only interest in your data is the fee for keeping it secure and available; at least there's less temptation to play with it in creative ways and risky ways.
This was obviously rolled out in a very different fashion. Plus they attached it to Gmail which is a tried-and-true product. Buzz feels very beta to me.
If Buzz we rolled out under labs or a separate interface I'm sure that there wouldn't be as much backlash as there has been.
If you think it does then I am very curious to hear how you felt when Microsoft leveraged their desktop strength to compete with Netscape in the browser wars.
Nothing was exposed to the public unless you agreed to create your Buzz profile. Nothing is exposed to followers unless you post something. Nothing is shared from your Reader unless it was already set to public.
So, you know, if you're a doctor or someone else who values the confidentiality of your user list very highly, don't go blithely clicking "Yes" when Google asks you if you want to make a public something-or-other. And if you could be physically put in danger by your correspondents, don't make comments like "ooh, this will be handy for my new house, its address is 123 xyz St" in public comments on your shared items.
Google didn't make a CEO-apology-level mistake here; they acted reasonably, if a bit cavalierly, and a lot of people had a hysterical and irrational freak-out, and a lot of those who are anti-Google picked it up as a stick to beat them with.
I don't know when their image changed so much. Perhaps it was the string of weird and useless launches recently. Wave must have cost them more reputation than I thought.
But, really, I think their apology was fine. They should be sorry for causing concern. I don't see how much further they could go. "we're sorry for not making it completely safe for you to click 'Yes' on any box we present to you without any consequences at all. We agree that you should never, ever have to read anything. Oh, and you can log in to Facebook here, and finally we pledge to protect your security-by-obscurity whenever you mark something 'public'. Love, Google."
They didn't invite them to fire, they forced them to fire. It's quite different.
There are millions of gmail users who haven't done this, and consequently have no public profile, and no information exposed. Users were not forced into anything. Buzz is there and inviting, sure, but I read the screen and was well aware of what would happen.
(Compare Facebook, which did recently force its users into publicising their names, small profile image and contacts list, with nary a whimper. It was a much more complicated opt-out box, too)
But nonetheless, it doesn't mean they forced people's data public, and it doesn't mean the NYT should have reported that as fact, as Winer demands. It's more nuanced than that, and only hit-seeking shouty tech blogs are saying otherwise. It'd be a disservice to their readers and the truth for the NYT to take their piece to the same histronic level as this link.
Ironically Google Cache helps: http://209.85.129.132/search?q=cache:http://www.scripting.co... ;)
edit: I should probably mention that google will eventually save that you viewed that website in its cache. Just to prevent angry blog post fury.
One of the big unsaid point i think is the expectation from Google. Companies like FB, MS and Apple are "expected" to do the wrong thing while Google is held to a higher standard, the "Do No Evil" standard. This of course has been brought upon by Google on itself hence the particularly strident criticism from the techie quarters.
But yeah, damage is still done.
When you sign up for a particular service that requires registration, we ask you to provide personal information. If we use this information in a manner different than the purpose for which it was collected, then we will ask for your consent prior to such use.
If we propose to use personal information for any purposes other than those described in this Privacy Policy and/or in the specific service privacy notices, we will offer you an effective way to opt out of the use of personal information for those other purposes. We will not collect or use sensitive information for purposes other than those described in this Privacy Policy and/or in the supplementary service privacy notices, unless we have obtained your prior consent.
The "storm" around this is reflecting really poorly on tech news blogs, many of whom are reporting this as if users had absolutely no say and just landed with a public profile. It's flat wrong, and we should stop promulgating that here.
For those that didn't hear about it, with Google Reader you can click on feed items to be shared, in which case they become visible from a URL that only you know about, and you can pass that URL to people you want to see the shared items (and they can subscribe to).
Then one day they decided that everyone you've every chatted to should be able to see what you've shared, which caused some rocky times for peoples relationships / jobs / families. Personally, I thought that was very, very predictable.
It was opt-out, and the official work around was to stop sharing things or to delete your contacts. I think they added some finer grain stuff later, but everyone effected had left by then.
They were unapologetic throughout - they didn't see it as a big thing at all, even with the various tales of woe rolling in. It seemed almost like they don't have any procedures for checking if something leaks personal data and that there were no repercussions when it did. Hopefully that will change now something with more public attention has gone in a similar direction.
They did have a point when they said that they never guaranteed privacy, but the secret (pseudorandom looking URL) implies that they weren't going to splash it around quite as much as they did.
See here for an overview http://www.eweek.com/c/a/Messaging-and-Collaboration/Google-... and here for the horror stories and complaints http://groups.google.com/group/google-reader-howdoi/browse_t...
The irony here is that Facebook has failed this way many time and here google is trying ot compete with facebook with buzz and did exactly the same thing.
Google is full of regular people and they make regular people mistakes and will continue to do so.
When I used FB I expect that my news feed is public to my friends. It's used for open social interaction. The same goes for Twitter.
When I use Gmail I expect my emails and contacts to be private. I don't expect strangers to see what I'm doing.
The user's experience and expectations are different. This is why Facebook has more leeway (but they still get * if they do something that opens up your profile to the public).
Google's done a lot of good things for us, and to insult them so much just because they made one mistake is just plain ungrateful.
Have loyalty to your friends/family. Not to some public company that doesn't know or care about you.