So no, it is not just my problem or your problem, it's everyone's.
So no, it is not just my problem or your problem, it's everyone's.
I think this example serves both our points. To your point, it's totally leaked this other person's info into my "google world" because I'm on gmail. On the other hand, that person is leaking his information directly to me just because of typos when he fills out online forms. Perfect privacy requires a lot of vigilance in a digital world, with or without google/gmail/hotmail/yahoo/etc.
I receive a ridiculous amount of other people's email - for serious things like email account reset, to banking info. When the Ashley Madison hack happened, my email address was there multiple times! Imagine if my then-partner had bothered to look, what a mess that would be.
I've called American Express a couple of times to report errant emails with account info ending up in my email. THEY didn't care that one of their customers had an issue, they thought it was a great time to have me fork over MY info "to check".
From time to time I have had messages relating to a government planning committee as one of the members got the domain of someone's departmental email account wrong and the messages come instead to the domain I administer.
In another instance I was getting emails about an account someone created with American Express using my email address. I sent multiple emails to their customer support to get them to stop sending financial information to the wrong person with no results. In this I also found it difficult to even figure out what agency to report them to for failing to take action when notified. Eventually I took the time to call them. It took around 20 minutes (not counting time on hold) of talking to multiple people to get them to remove the email address from the account. This included them asking me several times for my social security number - which I flatly refused to provide since I had zero business relationship with them. This refusal actually seemed to confuse them.
Many of the people I know who have very common gmail addresses have set up canned replies to let senders know they've reached the wrong person.
It's not clear whether these AI models have much incentive to correct anything. If 99% of people with attributes x,y and z are bad candidates for a job, will you even get an interview? Is there any attempt to account for the fact that attribute x is something you were born with? Or that you are actually in the 1% and really are a good candidate? Or that you don't actually have attribute y, and it was just inferred from something else or some kind of mixup like an email address typo?
Machine learning is also very opaque.
If you verify the race field, then now you're in the business of enforcing racial definitions.
Why would that matter to the company? People are born with stupidity.
The former doesn't fix the issue at all, and the latter is unworkable because the guy reliably giving out the wrong email address will absolutely not remember his public key.
Have the browser suggest the key IDs from `gpg --list-secret-keys`.
I often get some misdirected emails because of a very banal name in my country.
When the email contains a thread history, I sometime noticed that the address was simply corrupted by a recipient, such as numbers getting dropped from the genuine address in their reply.
I guess some systems can't handle correctly numbers or other characters in email addresses.
Fun story there. Because Google's internal privacy safeguards are so strict, the people working on features like that can't look for example emails to train their ML models with.
They can only look at emails that were explicitly sent to them in order to improve the feature (and almost no one forwards along positive nor negative examples). What they can do across the email corpus is run jobs that return aggregate stats, where each stat must be coarse enough that it is infeasible to trace back to original users (often 100k+ users per data point).
So, AFAIK, training & testing models under these safeguards is more or less done blind. Build a model with the few examples you do have, and then run it against the corpus. If you see numbers change, you have no idea if that's good or bad, since you can't actually inspect the run.
(at least, this is the way it was a few years ago)
One time, when I marked a bunch of incorrectly-classified emails as "not spam", the Gmail web UI asked me if I wanted to send these emails to the Gmail spam team. Was this what you meant, or something else?
(That's different than just marking an email as spam, though)
I was somewhat radical about privacy in the late 90s (only person I knew that read every EULA) and am still a supporter of the EFF but I don't really understand the issue here.
When you visit you friend's house, the data is not under their control, it is under Google's control.
Therefore, Google has a WAY bigger responsibility than most people realize, once they decided to collect this data.
Ultimately, whenever you visit any place, business or home, the data is under the control of the owner and anyone they abdicate those rights to.
Some interesting scenarios to consider: If I visit a friend's house, and I start getting targeted ads for a service I didn't subscribe to without prior consent or my knowledge, can I sue her/him? What about a scenario where some service collects my data, said service is hacked, and someone commits identity theft on me, who is liable for damages? Do I need my buddy to sign a waiver when he visits to play some Xbox for a bit?
With LTE, I don't need wifi.
I would imagine if you walk into a home with google's AI doodads all over the place, you're gonna be picked up.
Rumor is that even when your phone has been turned off, it can be turned back on remotely.
There was even a note about this feature in the privacy policy, IIRC.
I have a couple of cameras, and at least one visitor has been uncomfortable with their presence, despite the fact they're not sending the data to a third party.
But it was your friend's decision to delegate that control. So, Google having that control is still a consequence of your friend's control.
A business is typically located in a public space, where there is no expectation of privacy. In contrast, a home is by definition a private space where there is a strong expectation of privacy.
Aren't there some wiretapping laws around this sort of thing?
(IANAL, YMMV, etc.)
Tl;dr there's privacy in decentralization.
I'm very optimistic about Google making my life better in lots of little ways. I have virtually no concerns about my openness to Google causing me trouble.
I think that's a common goal and widespread belief and find its implication of having given up on "bigger ways" troubling.
Our industry was going to change the world. Rewrite the cultural rules of socializing. Rebuild the economy in a new form. Encourage major cultural and political shifts by empowering the little guy. Bring knowledge to the ignorant, companionship to the lonely, power to the powerless, jobs to the jobless.
What we have now is, well, maybe, with some luck, timidly, sometimes google can analyze the last time I went to a gas station, the number of miles I've driven at various speeds since then, the time of my next appointment, then it can adjust my google now card to encourage me to leave home earlier so I'll have time to fill up the tank and it'll find the cheapest advertised price along the way. That's nice ... but wheres my revolution?
Even worse in context of the article, OK well say I have to give up all privacy and go hard core 1984 telescreen big brother is always watching, to save endangered species and house the homeless and feed the starving and bring peace to the victimized. Well OK I'll think about it. Oh wait, we don't get any of that, all we're offered is slightly better appointment scheduling. Eh, no thanks.
Nothing is ever really new, and this era is likely similar to pre-quantum era Physics around 1890 where nothing is left to discover other than adding a few more decimal places here and there. The meme and speech patterns are all the same (although I'm not quite that old)
For centuries, people have navigated using stars and maps, yet now you have turn by turn navigation in your pocket with real time traffic and crowd sourced traffic incidents. You can reach most of the world population instantly by dialing a few numbers or even sending them a text message or mms, no matter where they are.
In the context of the article, a couple of years ago, Google Now told me I had to leave for a meetup in my calendar that I completely forgot about, gave me transit directions for a part of a city I've never been at and got me in exactly at the meetup start time.
While that all seems like modern conveniences nowadays, even thirty years ago if you'd have told people that you couldn't get lost anywhere in the world and could get ahold of just about anyone at anytime instantly, they'd think you'd be talking about science fiction, not today's reality.
Example: "Intuit’s TurboTax stores highly detailed financial data for millions of users who import their W2s, their banking data, info about their mortgages and more. Right now, all of this data is locked into TurboTax, but the company is now thinking about how it can do more with it by giving its users the option to share this data with reputable third parties." ... https://techcrunch.com/2016/09/22/intuit-wants-to-turn-turbo...
True, I don't mind Google today, but what about tomorrow? What about N years from now when they have failed to hit their financial targets 2 years running. Will that company have the same set of standards as the one today?
The reality is that once you've given up your privacy there is no getting it back.
Google might handle the data it collects better than other companies, but it would do much better still if it didn't collect any personal data at all.
Hands off my data, Google!
Going further, given that an encrypted email to Gmail will simply be unencrypted and then available to GMail, include in the protocol authorized (via both white and black list means) agents of the recipient. So, if you are hosting your own email but the intended recipient is expected to be not hosting their own email, the sender can blacklist "agents" such as Gmail and Yahoo! Mail, or blacklist all except for those chosen to be white-listed such as Proton Mail.
For almost all users getting a message from someone you personally know containing a message that they would legitimately send would be sufficient to trust the referenced key. If you are a little paranoid you could ask them over the phone or in person to send a specific message that you would then trust, or just ask for the URL itself. I believe that in-person key exchanges utilizing large trust networks are overkill for the vast majority of people sending everyday communications.
Make it so simple as 1) one time key creation and copying to each device 2) one time trust per other person that is completely streamlined by the software. If the gmail team implemented this for example other email providers would soon do the same and it would spread like wildfire. Very quickly a huge amount of email would be encrypted. Of course this would require an open design that anyone can implement.
Maybe there's a fundamental flaw with this idea that I'm not seeing. If so, please say so because otherwise I'm going to just be disappointed in five years when email is still 99% unencrypted.
Granted there may be a place for regulations to help us restrict what companies are able to do(perhaps making it easier for you to identify a region that is being recorded, right?), but, at some point society can't help the fact that you'd prefer if machines were unaware of your existence. That's just something you have to solve for yourself.
GPG doesn't hide that one is emailing, or when, or with whom; it only hides content.
Personally, I would have downvoted you because your original point seemed to condescendingly assume something about a large proportion of the community and their intentions - then you assume again that it's "The Google People" (and only them)?
Unless you can show that your downvotes came because of a specific reason, and from specific people...