High ranking Google SRE's, on the other hand, can view your personal information as their job is to run and maintain the production servers where your personal information lives. I don't know what portion of Google employees are SREs but I would guess much less than 5 percent.
I don't agree that Google is a major offender as far as negligent or malicious data/privacy leaks. Their security seems fairly top-notch, especially considering the context of new hacks/leaks that come out constantly from other companies.
That sounds optimistic: a mass-leak would be a major company issue touching its credibility, with a possible black-out if the hackers do not make it public. Think of Yahoo: how many years to admit a massive leak?
In addition, who can be sure there are no DBA leaving with data on USB keys?
Any large org has measures the prevent that sort of thing, including Google.
Technically, it's possible to access it, bit no one person can do it without oversight.
* Anyone can access it but if it is monitored or found out afterwards, they're in trouble? * Or do you mean that after you ask permission, you get a privileged account or whatever and can then access the private info?
Because if the first is the case, I have a "delete Google account" button to click before the end of the day...
(I work for Google, and cannot access your data)
http://gawker.com/5637234/gcreep-google-engineer-stalked-tee...
https://www.wired.com/2010/09/google-spy/
I'm sure if you dug around you could find more. I'm certain it doesn't happen often. I'm not sure how accurate the "source" in those articles is but ...
> "We dismissed David Barksdale for breaking Google's
> strict internal privacy policies. We carefully control
> the number of employees who have access to our systems,
> and we regularly upgrade our security controls–for
> example, we are significantly increasing the amount of
> time we spend auditing our logs to ensure those controls
> are effective. That said, a limited number of people will
> always need to access these systems if we are to operate
> them properly–which is why we take any breach so seriously."
> — Bill Coughran, Senior Vice President, Engineering, Google
I mean, Google is a big company. If you can come up with a 100% accurate way to screen for people who would never act in an unethical way, the FBI and CIA would like to have a word.
There is no 100% test.
What verified stories are you referring to?
https://twitter.com/yonatanzunger/status/615356310410760193
It's not entirely clear who "we" is in that tweet.
A while ago I have been contacted by a Google recruiter several times over e-mail, which I found bizarre, as I did not apply to any job at that time. I asked the recruiter to disclose where she exactly got my mail from and she dodged the answer.
Turns out there's a guy with the same name as me who is also a programmer (except he has been in the field for several years and works on awesome stuff, unlike me) and they were eager to recruit him, since I got the same mail several times over the course of a year from two or three different recruiters.
The only thing connecting me and the other guy was our last name. My e-mail address doesn't mention my last name in the slightest, I did not post it publicly (just tried to google it - zero results) and it's not connected in any way to a service where one could figure out the combination of the email, user and password (such as facebook or linkedin). I've also checked the data breaches on haveibeenpwned and I definitively did not use my real name on the services where the data was stolen.
Considering that the original guy's e-mail address was lumped in CC (fully visible - how professional of them) I can only think that they essentially did "SELECT * WHERE lastname = 'myname'", spammed all the available e-mail address and hoped for the best.
> I can only think that they essentially did "SELECT * WHERE lastname = 'myname'", spammed all the available e-mail address
I'm pretty sure that's what they did, except they probably did something like trawl external 3rd party databases in order to find your email address.
It's a huge leap to go from "definitely yes" to "I can only think". Although I don't approve of it, leaking your email account -> name infromation is very easy to inadvertently do, and I am sure that there's a huge wall between recruiting and Google PII.
Google is the only company where the name / e-mail association is clear. I can't think about a single other source of information that could have lead a google recruiter to my e-mail address aside from the data that Google itself has.
Call it circumstantial evidence, but to me it's very clear what happened there.
> I can't think about a single other source of information...
It only takes one slip up.
> Call it circumstantial evidence, but to me it's very clear what happened there.
You sort of have to pick one.
Google is paranoid about PII. Most recruiters at Google are contractors, not allowed to access any PII. Heck, even as a high level engineer/manager, you're not allowed to see PII unless you have a specific business reason or work on an abuse or security team where you have business reasons to see the information, and even then the access is logged and traced.
My question for you is, even if you believe this is the case, are you still using Google services?
Beyond just keeping my data out of that ecosystem, I sure as hell hope Google has some serious talent to keep my data safe from outsiders, and insiders wanting to make a splash. I mean, I obviously trust them to some degree. But it's a scary prospect to think what would happen if an enormous trove of Google data were ever leaked.
Gmail personal data is stored encrypted. Just because algorithms can profile you doesn't mean every google employee can simply read your emails or personal information raw from some db somewhere. I can't even pull up basic technical troubleshooting data from a cloud customer without begging them for the data.
Higher up executives don't necessarily have more access, access is given based upon your responsibilities, and level of need. A VP of marketing is not going to be granted access to a customer's gmail messages, because they don't need that information to do their job. There is no reason to grant them that access, the liability of a leak is far worse than any benefit.
Everything an employee accesses is controlled by a complex system, subject to oauth2 authentication, a permission handling technology, and fido u2f yubico security key 2fa. Everything an employee accesses is logged and monitored. Nobody is able to walk out of there with an archive of user info, that would alert every alarm in the system. Nobody has been able, as far as we know, to phish access into our internal network since we started using yubikeys for everything[1].
The employees with the most access are typically SREs and Developers, and their access is designed to facilitate their jobs. Example: the data in your BigQuery db won't be able to be easily read by any employee, but the right ones will be able to read logs, activity histories, and relevant statistics in order to be able to troubleshoot and diagnose bugs and issues and things. They don't need to know what data the table holds, and therefore aren't given access to read it.
We are pretty far from a major offender of negligence over the security of our user's data. As far as I know, we were hacked by China and the NSA, which immediately prompted us to encrypt our server2server communications, encrypt our storage data, and research and develop novel security best practices. Our development and trial with fido u2f keys, for instance, has resulted in a drop to 0 KNOWN successful phishing attempts, all while making 2fa more convenient than ever[1].
It may be hard to believe, but Google's information about your lives in the machine. Our employees only have access to the bits we need to do our jobs, which always sides on your privacy. Trust me, I wish I did have more access, because trying to troubleshoot in the dark sucks.
But they respect you and your privacy more than they respect me. And they work hard to keep your private information safe, to levels I doubt most companies you regularly use or shop at would ever care to. Remember, just because some company doesn't sell your info to advertisers doesn't make them more trustworthy. They could be storing your info in an unencrypted db with a basic admin/login on a rack of poorly administered and configured servers in a budget datacenter somewhere. Google uses the latest technology, funds new research, and implements a security policy built on state of the art equipment and software other companies could only dream of. This is not a secondary consideration for them, they bust their ass to keep your info safe.
[1] https://www.yubico.com/2016/02/use-of-fido-u2f-security-keys...