According to Google.
as well as an unspecified small number of others.
Nothing to worry about, I'm sure. Probably no way to exploit those issues. Probably.
Google never intended for it to happen
Obviously, it's a rookie mistake that anyone could make. And that's why I'm willing to forgive and forget when it comes to multibillion dollar global businesses that make billions more off of the private information they gather and store. Just like I did after Equifax goofed earlier this year. And Yahoo the year before that. And …
Look, I get it that the Google PR people have been super nice and accommodating and embarrassed about the whole thing. Maybe the writer is friends with people on the team, or there might be a job at Google down the road. And, of course, some writers don't want to lose access to free trials and potential interviews.
But I really would like to see specialized news outlets show more backbone when it comes to screw-ups, and not downplay or gloss over serious privacy issues such as this, or take Google's word about what happened. It's a fair question to ask whether the problem(s) may still be present in every other Google device … and if they are potentially exploitable.
Now we have “news” services like HaveIBeenPwned.com
These are the most powerful non-governmental agencies in the world (and more powerful than almost all governments). Developers have to stop giving in particular Google a free pass on virtually everything. We need to stop setting Google DNS servers to be the default in software or in example code. We need to stop pretending that turning separate URL and search boxes into a single omnibox is a great convenience or efficiency of space and recognize that it's just more comprehensive collection of user data. We need to stop turning that ever-smaller remaining free space on the internet, the Web, into another massive spiderweb of signals sent to Google and Facebook, with as many as ten or twenty requests sent to Google from a typical webpage, many of which no longer function when these requests are blocked, because the functionality of the site, and not just the advertising, now comes from Google servers.
Acquiescence to this status quo is easy and probably good for one's career, but it's also dangerous for democracy, dangerous for innovation, dangerous for independence of thought...
Now all the folks who can be frivolous and blase inspite of the growing mountain of evidence must be similarly dismissed.
This story from today's Washington Post is relevant:
Of course there isn't. This is the problem with surveillance: inherent in its nature is the fact that if it is done competently, its existence is indistinguishable from its absence.
Note that I'm not saying that Google is acting in bad faith. What I'm saying is that the following is fallacious reasoning:
1. This incident turned out not to be a case of bad-faith surveillance.
2. Therefore, Google never engages in bad-faith surveillance.
This is called the "hasty generalization" fallacy.