Are you ready? This is all the data Facebook and Google have on you
theguardian.com
theguardian.com
> The data Google has on you can fill millions of Word documents. > Google offers an option to download all of the data it stores about you. I’ve requested to download it and the file is 5.5GB big, which is roughly 3m Word documents. This link [Google Takeout] includes your bookmarks, emails, contacts, your Google Drive files, all of the above information, your YouTube videos, the photos you’ve taken on your phone, the businesses you’ve bought from, the products you’ve bought through Google …
Well duh, Google stores your gmail emails and Youtube videos and Drive documents and so on! This is the service they're providing you! Google Takeout doesn't give you a 5GB archive of advertising profile or covertly gathered info, it gives you a 5GB archive of the documents you deliberately uploaded to Google services - emails, docs, pics, videos, calendar appointments. The list of Android apps installed on your devices is there so that when you link a new device to your Google account, these apps will be automatically installed on it. And so on.
There's a single link on that list related to surveillance - namely, your Google Ads profile, which only shows very basic data, I'm sure they have vastly more complicated data stored on me.
There's enough genuine reasons to be upset with Google's surveillance, let's not promote this kind of silliness. Google knows which Google Groups you're subscribed to, really? 5GB could fill 3m Word docs - how many is that in Libraries of Congress?
https://www.goodreads.com/quotes/65213-briefly-stated-the-ge...
Correct me if I am wrong but are you saying one of these two companies buys people's credit card transaction history and then compares people's ad history against the transaction history? If yes, that sounds really incredible.
"And even if your business doesn’t have a large loyalty program, you can still measure store sales by taking advantage of Google’s third-party partnerships, which capture approximately 70% of credit and debit card transactions in the United States."
According to what they presented at a crypto conference, they went to great pains to avoid capturing personally identifiable transactions. The overall strategy is that Google Knows = Set A = (all ads shown for user X at Merchant Y) Merchant/Credit Card Proccessor Knows = Set B = (all $$$ paid by User X at Merchant Y), and that it is possible to cryptographically compute sum($$$ of A intersect B) without either side learning Set(User X).
Now whether you believe in the security of the algorithm and whether there are side channel leaks or attacks is another issue.
Edit: http://bristolcrypto.blogspot.com/2017/01/rwc-2017-secure-mp...
About 10 minutes in https://www.youtube.com/watch?v=ee7oRsDnNNc
(I'm interpreting "has on you" as meaning "not anonymized.")
This article is just dumb clickbait. It's too bad the conversation is now being driven by rank nonsense. G, Jolie Facebook, does not sell data or profiles of you to third parties. That is what people should be focused on as a first step, the buying and selling of data.
I think that's a point to take home. Users know that Google looks at their "location information". In their minds, it's to provide relevant weather info and whatnot. Seeing it aggregated in this way makes you realise that you actually are sending your entire life to Google servers.
Apple is a bit better (less-worse) on this. They do log many things in the background, and hopefully stopped (as they promised) to upload everything on every sync you do.
That's the problem, right here.
Not that entities are selling people's privacy. Bad guys have always been there, and will always be. But usually people want to act against them.
In this situation people don't want to. We got a very sudden outrage out of sheer media amplification effect. It will fade. And they will go back to trading what's important to what's convenient.
Most of these people don't even know how the technology works. Enabling firewall makes them feel secure because it shows them a Green tick mark in a green circle. A file shred application is good to them (if they even care) because it shows an animation that feeds a file to a shredder and breaks them into pieces.
They are never going to agree that they can be manipulated this way. Oh, and some people feel website x is secure because there is a green lock symbol in the URL bar. Some are more secure, because the green bar is a bit longer.
Except when all other measures have been exhausted, we shouldn't be so quick to run to the legal system clutching our ban hammer with our perceived state of righteousness.
Another problem I often see (not here, just saying in general) is how false equivalence is constantly brought up. Oh, so we should just let companies poison food or build insecure cars or whatever. I hope that with user data we can be more reasonable in how we legislate it and at least try to realize the unforeseen costs on the "good guys" vs the "bad guys".
Some of this is genuine indifference to the problem, yes. But I think some of it is a lack of perspective.
After years of sweating tech privacy issues, it's very easy for me to say "oh, they track app usage, which means they track app opening times, which means they can probably tell when you go to bed every night based on the last time you open Twitter." Or construct a hundred other scary (and accurate) stories about how this sort of data can be used to build whole-life profiles of people.
Outside of tech, it's not so obvious. "They track which apps I open when, and said it's to help improve battery usage. What's the big deal?" And of course that's also true, this is useful data for innocent purposes like "predicting what you'll reopen next to expire that from memory last".
But my concern is that there's an enormous gulf between showing people what's been collected, and how it's used. This article makes a bit of an effort, but it's still far short of the sort of example narrative that actually catches people's attention.
Back during the Snowden stuff, there was a lot of talk about three-hop collection. And I think basically no one cared, because it's such an arcane description. But somebody made a tool (which, damn it all, I can no longer find) showing how location + call data at three hops could create a false-but-convincing narrative that someone was a terrorist. I showed that to a couple of family members, and suddenly they were way more concerned with the topic.
It's not easy, I think this is a losing battle and I'm not sure how to change that, but I think people do care when they have useful context to work with.
Rest assured that this happens all the time and when people read news about a topic that they are an expert on, they cringe all the time. For example, a paraglider pilot will get triggered if the reporter uses the word "Jumped" in a story about a paraglider pilot who crash-landed and injured two more people. This is because paragliders don't jump but take off from hills etc.
Usually reporting on technical topics is very hard because you need to reach the non-technical audience so you will HAVE TO use illustrative examples and not exactly accurate descriptions so that can be absorbed by the non-technical readers. Unfortunately, this will put you in a position where can be called on by technical readers who are triggered by the "implementation details" of your story.
I do believe that calling out the 5GB illustrative example is missing the point of the article. It's just a way to portray size of the data collected on you, it doesn't have any meaning even if this data was 3Mb or 100Gb. For example, if it was 3Mb Google might have used it to convey how little data they collect on you as if the size that this data takes has any correlation about the impact, then why even bother with such an irrelevant point of the "article implementation"?
I think they don't have a choice but to do it this way. A typical news outlet will report on hundreds of topics a day and probably covering the entire spectrum of topics out there.
How likely it is that all of the readers will be well versed in all the areas of expertise that human race was able to achieve in the last few thousands of years of recorded history?
Also, these journalists[not necessarily this one but in general] are usually not experts on the topic that they write on and the better ones usually would consult with someone who is well versed on that topic. There's no way that the expert that the journalist is consulting with, will be able to educate the journalist, so he/she will dumb it down and then the reporter will dumb it down further and re-shape it in a form that the news outlet can sell it to its audience(right wing, left wing, alt-right, communist, highly educated ... whatever, they too are making a product for their customers).
I don't think that this is the case here. To be an "end justifies means" the writer would have to give a false information on an information that is relevant to the core of the story. Does it really matter what's the size of some digital data? Would it be O.K. if Google collected 100Mb of data but totally unacceptable if that was 5Gb?
The size of the data is an irrelevant implementation detail of the story. Even assuming that this is all the data about you is silly in the first place but the articla is not about that - even if the title says so.
Please see my reply to bhauer's sibling comment, I think it applies here too. The problem isn't with the 5GB size or how they compare it to 3 million Word docs. The problem is with measuring the size of something completely irrelevant. The problem is with saying "Google collects data on you for advertising, they have data you wouldn't expect them to have" and then linking to data you explicitly, deliberately uploaded to Google yourself. The problem is with linking to Google Takeout and pretending it's something that it's not.
To be able to interpret the article in a useful way, it is important to be aware that a single long, high-res youtube video could be 5.5 Gb and therefore that figure doesn't imply anything about what google knows about you. Of course, it would be easy for a non-expert to mischaracterize an aircraft accident in a way that matters to a layperson's understanding of why the accident happened and who is responsible.
A veteran who relives the horrors of war when fireworks go off is not nearly in the same space as a developer who is annoyed that someone misused technical jargon.
Certainly not. While many military personal certainly have faced mind-altering situations, they are far from the only ones who have ever suffered from traumatic events.
Children and Women are the subjects of the most twisted and abusive stories I've ever been able to fathom.
> The word "triggered" should really be reserved for military vets AND those who have experienced traumatic events in their past that would cause severe distress
(emphasis mine)
You can't just cut a sentence in half and then try to form an argument against it. That's not fair.
Simply giving up on definitions means always ceding power.
The entire world is participating in shaping English and we have no Académie Française equivalent. Sometimes the changes are unflattering.
That said, I do appreciate your points and see your intention with empathy about this word in particular.
It's not so much "you shouldn't use that word in that manner because of some linguistic pedantry" but "you shouldn't use that word because the externalities of doing so have outsized effects on certain people," or for the self-centered and machiavellian, "you make yourself look bad when you use it such."
As you say, it is a matter of empathy. The N-word has been around for a while - it's still not acceptable for certain people to say it[0]. As for why, that's a matter of education, and it begins with pointing it out.
“Briefly stated, the Gell-Mann Amnesia effect is as follows. You open the newspaper to an article on some subject you know well. In Murray's case, physics. In mine, show business. You read the article and see the journalist has absolutely no understanding of either the facts or the issues. Often, the article is so wrong it actually presents the story backward—reversing cause and effect. I call these the "wet streets cause rain" stories. Paper's full of them. In any case, you read with exasperation or amusement the multiple errors in a story, and then turn the page to national or international affairs, and read as if the rest of the newspaper was somehow more accurate about Palestine than the baloney you just read. You turn the page, and forget what you know.”
However, a counter point: I feel it is useful and helpful to our cause to have authors such as this creating those colorful metaphors. We have tried in vain to communicate to laypeople the importance of data safety, self-ownership of data, being mindful of one's privacy, and being suspicious of the data collected by third-parties. I believe laypeople remain disinterested because the way we raise these concerns is abstract.
In order to convince laypeople that control of one's data is important, those of us who are matter-of-fact on the matter will convey the facts and try to construct fairly mild-tempered plausible threat scenarios that are, frankly, unconvincing to the majority of people we are trying to convince.
For a good chunk of those we're trying to convince, vibrant and (to our minds, exaggerated) illustrations of the magnitude of the threat are what is necessary to tip the scale. The recent twitter thread that showed a map of Ireland with every point the user had been in the past several years was a poignant visual representation of our argument. It made the argument way better than repeatedly saying, "Google tracks your location, always!" When we've presented that abstract point previously, we've heard "I don't care, that's fine" as a response every time.
And then someone shows them this map and suddenly: "Whoa, that is creepy!" Yes!
I for one welcome a bit of colorful language, as long as we don't get totally carried away. I don't really dig the "Well, duh!" attitude if we convey that to the people we're trying to convince. We're trying to make laypeople value their own privacy and feel good doing so. Not judged for having been ignorant of or disinterested in our previous arguments. Be welcoming of this good favor in the fight for data privacy.
I didn't say "well duh, Google has at least 5GB on you, that's a small number really". I said "well duh, of course Google has your gmails and Drive docs" - and they are as small or large as you make them, their size is completely irrelevant.
I did snipe at the comparison to Word docs, not because it's a non-commensurable unit but because Word docs don't have a size - I can easily make a single Word doc 5GB large. But that was an aside quite irrelevant to my main point and maybe I should have omitted it.
In this case, though, I don't think it's an illustration of the threat at all.
The location tracking map may be visceral enough to motivate people, and that's fine. Sometimes people need a strong visual to act on something they already knew.
But the "5.5Gb, millions of Word documents!" bit? That's an archive including your Google Drive files, of course it's comparable in size to the free storage Google provides. And perhaps more importantly, if your Takeout archive is only 10Mb, that doesn't even begin to imply Google lacks records on you.
Potent metaphors are great, and I certainly recognize the problem of techies saying "yeah, duh, obviously" without helping people really understand the consequences of a topic. But in the Takeout case it feels like responding to consumer indifference about real problems by sparking fear over a basically meaningless topic.
Maybe it will stop folks from uploading unencrypted data to cloud providers down the road and improve research that allows cloud providers to process encrypted data meaningfully without every being able to decrypt.
The 3m pages of word doc is odd, but its not uncommon to convert overall size to word doc pages in journalist speech (just map size to average word doc size), and then they disregarding data type. I have seen this in other places too.
What I don't get in all of this debate: People grant FB/Google/any other app access to their data and seriously expect that their data isn't harvested? IMHO, there really is zero surprise that Facebook has your call and SMS history, if you granted access to that. Or every single login timestamp.
What is way scarier is that the dump you can download is probably far from complete. My Facebook dump shows rather few items, because I'm not a heavy Facebook user. But I'm quite sure that they have A LOT more on me, because of friends uploading my phone number, profile pictures, meta data from the WhatsApp acquisition.
The big scary question is: How do you access the data in your shadow profile that they won't give to you? How do you even prove that they have more on you than they admit?
Edit: Same for Google. I don't use a Google account most of the time and I bet they STILL have my entire search history associated to some kind of shadow profile.
when you provision a new android device it will try to link your account to chrone, and its very hard even for a developer to catch its chrome and not android os. after that small mistake (which is an optout in the ui pattern) its game over. google have all your history and every webview ad has your full profile. not to mention your web bank passwords are now conveniently save in google servers in plain text.
and yes, an even worse problem is the hidden data/shadow profile.
Do you have a citation for this?
If files are in your "trash" they will be included in your takeout. If you clear your trash, they will not be included in your takeout (after a reasonable amount of time, if you "empty trash" then instantly go and make a new takeout bundle it might still be included). It's the same way with spam and email trash. It's given to you in your bundle until you manually fully delete it.
Implying they keep everything you ever deleted is wrong.
Edit: I don't want to get into hypothetical arguments about what Google could possibly be doing. I'm simply saying that the reason the author had "deleted" things in their takeout archive was because it was most likely in their "trash" and wasn't fully deleted in the UI. And that "things in your trash folder are included in your takeout bundle" isn't "proof" that they never delete anything.
But from what I have seen Google takes infosec very seriously, and will fully delete information when they say they delete information. They even point out that it could "linger" for (IIRC) 90 days after you delete it in backups and other replicated copies, but after that should be fully and completely deleted.
However, we have repeatedly seen profits prioritized over security in the corporate world with negligible repercussions when the data is inevitably compromised.
If Google ever gives me a reason to not trust them I won't. But thus far they have been okay in my mind and I'm happy with the services I received and the tradeoffs made with regard to my information.
I fully expect more nastygrams and threats from people for saying this, because it happens every time I say I trust a company.
Saying "I trust company X with my data" is the same as saying "I trust that company X cannot be hacked".
"There are two types of companies: those that have been hacked, and those who don't know they have been hacked."
-John Chambers
No it is not, and it's also why I didn't reply at first because I had a feeling it would go down this path.
I don't believe for a second that my data will never be "hacked" at Google (for whatever definition you want to think of for "hacked"). But I do believe that Google has done their due diligence in preventing that kind of attack to the fullest extent they can, they give me the tools to remove data that I want removed, they are competent in their architecture to make leaks and hacks have limited scope, and i'm confident that they will be able to uncover evidence of "hacking" and will use the legal system to go after those responsible limiting the damage that a "hack" can do.
I enjoy the benefits I get from Google. I like that they scrape my email for calendar info, flight info, package info, etc... I like that they track my location and create automatic albums for pictures I take (and upload to them) while at a location. I like that they can get location indoors using wifi APs or that they use my voice in ML training to improve the product, or that they offer me relevant ads to pay for those free services and products instead of ads that have little or nothing to do with my interests. I like that I can go back and search my hangouts (then google talk) chats from my friends from over a decade ago, or that they backup my files that i put on google drive, or that they record what apps are on my phone (and some data from those apps) so that if I need a new phone I can quickly set everything back up, or that they store saved passwords on their servers so that I can easily get the same ones on multiple devices, I like that my reviews of apps/places can have my name and face put on them and that reviews from my family and friends show up over random people online, etc... And I especially like that I get most of this for no effort on my part. No servers to maintain, no software to setup and manage, no security needed on my part aside from keeping my username, password, and second factor auth secure. I only have a limited time on this planet, and I don't want to spend it setting up private email, storage, photo backup utilities, and whatever else that I get "for free" through Google services.
I'm not being tricked here, i'm not "missing something" or pretending that these companies are infallible. I'm making a consensus decision to trade information about myself to a company I trust for tangible benefits. If that company becomes untrustworthy, then I will adjust my feelings and behaviors, and I will most likely be hurt by it at some point (because you can't un-give information, especially not to a bad actor), but again that's a risk i'm willing to take.
I don't know why I typed all this out, and I don't mean to target it all at you personally, just at the boogeyman I've built up in my head of "internet person telling me i'm dumb for trusting a company". It's exhausting constantly having to defend against what-if's because I want webmail, or being constantly berated and insulted for making tradeoffs with my own privacy like it's some kind of personal insult to people that I am not as private as they are (there's nothing wrong with privacy, I advocate for it quite a lot, but your whole life doesn't need to be private all the time, i'm happy to share some aspects!).
However, have you considered the threats to national and global security that are posed by the centralized aggregation of billions of the most detailed psychological data profiles the world has ever seen?
If you reported it as "not spam" and then trash it, is it removed from the "ham" training set?
If it is collected as part of a warranted intercept and you delete it, is it removed from the intercept collection as well?
If you delete an email, are any resulting changes to your personal ad profile maintained by Google reverted?
Deleting an email from all of Google is not quite so trivial as "empty your trash, and it's gone entirely".
Obviously google won't "unsend" email, they aren't a DRM platform that will delete data anywhere that anyone you have ever shared it will has ever sent it.
> If you reported it as "not spam" and then trash it, is it removed from the "ham" training set?
But things like "spam" email will be "unlinked" from your account at the very least, and possibly fully deleted (does information "learned" from a spam email count as that email in your mind? If they use a neural-net to train spam filtering does that become "your data" when it learns from something of yours?)
But regardless, I didn't want to get into internet arguments about what the big companies might possibly be doing through a shitload of what-if's. I just wanted to point out that the reason the author of the blog had 'deleted' things in their takeout was because they were in the trash, and the trash wasn't emptied...
I feel most technical people are aware of the level of tracking going on. The more privacy concerned do what they can to mitigate it.
Facebook broke my trust with data I didn't know they had collected.
1. Those who actively use Facebook and willingly tell it everything about their lives
2. Those who actively use Facebook and unwillingly tell it everything about their lives (who don't know what data it collects)
3. Those who once actively used Facebook
4. Those who have never created a Facebook (or WhatsApp or Instagram) account
The real issue is, FB likely has as much private data about group number 4 as group number 1 because of their shadow profiles (which they euphemistically refer to as "future Facebook users"). And their current or past employees seem to be a little too conveniently blind to this matter. See here for e.g.: https://news.ycombinator.com/item?id=16676720
All Google's posturing about 'review and manage your data' is meaningless to me in that regard. Why can't I ask them to delete everything associated with my IPv6 block, for example?
Like most people here with a Google Account, I've disabled as much of their harvesting as I can.
I've received an extraordinary amount of value from several of their products - such as maps, search, email, apps - and I never click on ads. The value received versus given disparity is beyond comically in my favor.
By comparison at this point I'd rate my value context with Facebook as net negative across my lifetime use of the product. The value has plunged the last four or five years. The first few years I used the product (after it became freely available to the masses), were slightly positive or quasi-benign at worst.
The difference in terms of product experience is largely that with Google, I don't deal with other assholes that routinely make my day worse, whether in the form of ugly politics, petty rage, or spam posts (whether commercial or personal posts).
Google buys your credit card purchase data. Did you give it that? Why do you think Google wants you to stay logged into Chrome?
Let’s be honest here and call a spade a spade.
The world is just realizing how ads based business models work and there’s no difference between Google and Facebook.
I never told Facebook to upload my cell-phone contacts to their servers, where-as with Google, I willingly store them using Google Contacts.
It's not so much the data they have, but how they obtain and use the data they have.
A more accurate explanation of the scare quote:
https://news.ycombinator.com/item?id=16698587
> IIRC, this was announced as part of a program that uses double-blinded crypto that allows google to perform matching against this data in aggregate (Set intersection knowledge), but not individually identity of what a given user purchased, at the same time preventing the merchants from learning the identities of individuals either.
> According to what they presented at a crypto conference, they went to great pains to avoid capturing personally identifiable transactions. The overall strategy is that Google Knows = Set A = (all ads shown for user X at Merchant Y) Merchant/Credit Card Proccessor Knows = Set B = (all $$$ paid by User X at Merchant Y), and that it is possible to cryptographically compute sum($$$ of A intersect B) without either side learning Set(User X).
> Now whether you believe in the security of the algorithm and whether there are side channel leaks or attacks is another issue.
> Edit: http://bristolcrypto.blogspot.com/2017/01/rwc-2017-secure-mp...
> About 10 minutes in https://www.youtube.com/watch?v=ee7oRsDnNNc
For example, voice search history you can enable or disable, if you enable it, you can see and listen to all your queries and delete them if you so choose. If you disable the history, Google still stores recordings of your voice and uses it to "improve their service", they just associate it with an anonymous identifier. The downside here, of course, is that you can't delete the copies of your voice Google is now saving despite your desire for them not to keep your history.
(I am having a hard time finding exactly where Google currently states this, but I have a high level of confidence this is how it works, as officially stated by Google, for voice activity.)
USA Today takes it a step further, and claims that "deleting" your voice activity merely converts it to the anonymous identifier, that Google keeps it either way: https://www.usatoday.com/story/tech/news/2016/03/02/how-voic...
The better Google help article is this one, but it merely states changing the setting determines whether or not the audio activity is "saved to your account": https://support.google.com/websearch/answer/6030020
I recall Google's articles being clearer on this point before, either I'm not looking in the right place or they may have obfuscated it.
1. collecting data and hiding it during times it was paused
2. checking if data collection is paused during collection time and keeping it/throwing it away
Option (2) is the easiest and most foolproof. For (1), all it takes is a single tiny bug in any code that handles your data history and their whole privacy stance is shot.
That doesn't seem any easier; as hiding is harder than checking a bit and discarding at collection time.
"For (1), all it takes is a single tiny bug in any code that handles your data history and their whole privacy stance is shot."
That doesn't sound foolproof at all.
Checking a bit and discarding at collection time is the easiest. You need to ensure data collection is aware of this setting, and anything that manipulates this data doesn't need to care whether or not some data is "hidden" or not.
> That doesn't sound foolproof at all.
Right - If you go the route of collecting all data and hiding it later then all tools that interoperate with customer data need to make sure they don't accidentally expose "paused" data back to the customer.
Given two choices of throwing away data at collection time, or forever in the future trying to hide data from the customer, it seems simpler to throw away data at collection time.
Is there a valid use case for "encrypting" email with a private key? I guess signing a message is technically encryption, but it's not typically called that, right? I'm hoping their use of "encrypt" in this context is just an error, and that tech reporters at the Guardian understand how key pairs work...
Having your private key in a non-client-side-encrypted cloud is like keeping a vector representation of your hand signature on your website.
Because their behavior fits the legal definition of stalking in many jurisdictions. Yes, the user "consented" to the stalking, but many of their friends which are being stalked as a result did not.
That's a pretty huge caveat. "This isn't news, except to the majority of people". It's an article in The Guardian, it's obvious intended for the "laymen", of which there are a pretty big number.
> of course they store everything the user does, why wouldn't they?
That's the crux of it, for me. I agree, they have no incentives not to hoard data. So those incentives, like GDPR, should be created.
TL;DR defaults matter to the layman - the 99%, google will say they gave you the options (so many that it's tiresome for most people to bother going through).
Yup, when reading through all of the stuff I was just checking off my mental list of all the things that don't affect me. I don't use google on phones, and for gmail stuff i've already trawled through the massive list of options to stop tracking and logging various stuff. Additionally I only log into a google account in isolation so it can't join history together.
Even after all of this I recognise that google mostly likely has other tricks up it's sleeves like browser fingerprinting to join sessions together and associate their activity with my account in secret, not to mention they are mining all of my email of course, but this is the best I can do while continuing to use a google account (and even without a google account they can still track individuals via other means).
This is only practical for those the most aware of what these companies do and the most interested in preventing - understandably, the layman just wants to use it as intended without doing days of research and digging through piles of options in paranoia trying to turn everything off, these types of services rely on this fact. I am not a normal user and they really don't care that 1e-10% are evading them, they are relying on the fact that almost all of their users wont be going to great lengths to turn all the tracking and logging options off.
They are storing your emails, for instance, and your photos.
This isn't google tracking you any more than a storage unit company is stealing from you.
You can get people to do anything with the right incentives.
I may be alone in this, but I expect that everything I do on the Internet is done in public. Nothing new here.
So how do you send private messages? Carrier pigeon? Even Signal uses the internet, after all.
Then I got hooked.
I learned how to fold paper into its own envelope. I bought supple wax and sent a design for a custom wax seal stamp, so now I can mail a letter that is wax sealed domestically or internationally.
My friends love getting letters in the mail that's not spam. And a few even write back. One made his whole envelope out of duct tape.
We still call and text, of course.
And now I am practicing calligraphy in order to craft my own book, binding and all. I got very inspired when I saw the Book of Kells and Chester Beatty collection in Dublin.
Practically this has cost me (the fountain pen setup plus forever stamps) $100 USD. But that's because I bought a nice ink. So I think if people have a little bit of disposable income, and have Netflix to cut out of their life, could pick up old fashioned writing to catch up on life's details in private.
Heck, could even skip the writing and just buy the envelope and stamps, and type up a letter to print and mail!
There's also Tor, which I use in combination with an obscure e-mail service that allows you to create accounts and login over Tor.
If you want to encrypt the actual email message, then I use GPG, but it isn't always practical.
Once keys have been exchanged, it switches to AES encryption with your peers, so carriers will only log a blob of encrypted text.
Since most sites implement google Analytics and Facebook tracking code (ghostery is reporting both on the guardian website). They could use browser fingerprinting, which has already been proven to be extremely accurate, to augment known user profiles and data. Facebook already creates shadow profiles for people without profiles. I don't think there's any US law from making these inferences from "voluntarily" submitted information so it's perfectly plausible they would do this without telling people, no?
A more compelling argument for users to take privacy seriously would be to tell them: Hey guess what Google has the ability to know what porn you search for (yea even in your private window) since you're sending them all the data required to track you, and there's no laws in place to prohibit it.
The biggest factor for tracking without the ability to store things on the client is IP-based tracking. In many cases, the IP address narrows the number of possible persons down to a handful. Then you can use behavioural analysis, fingerprinting or factor in other data to narrow it down those last few meters.
And well, any time you visit a webpage which has a DoubleClick ad on it, uses a font from Google Fonts, incorporates JQuery from Google's server, incorporates Captcha, Maps, YouTube, Custom Search Engine, Google+-Button from Google's server, etc., or in fact, even though this is the least of your worries then, Google Analytics and Google Tag Manager, any time one of these is on a webpage you visit - which is pretty much every time you visit any webpage, your IP address is sent off to Google.
And now comes the bad part: As is information about what webpage you're currently on, as part of the HTTP Referrer.
And I mean, if your URL is not resolved by 8.8.8.8, you can consider yourself lucky, too.
So, Google effectively has your complete browsing history, whether you're in private mode or not.
Facebook is not nearly as bad in this respect, but their Like-Buttons are rather widespread, too, and they do have an analytics framework, as you've already pointed out.
Things like MAC address logging and such is also missing.
The only things included in the download are things you've given them; pictures, messages, likes, contacts, web browsing history, and phone metadata if you gave them permission on your phone.
If they were able to purchase phone metadata from your service provider, it won't show up there.
If all Facebook kept was user-submitted data it would be orders of magnitude less creepy than it is.
Creepy, that’s what they said they would do when I opened my gmail account.
If your phone doesn't connect to anything and enable location services (GPS is costly in terms of battery though), it has no idea where you are. Of course, your phone -is- connected to the cell network most of the time, and so theoretically it could calculate where you are to within a mile or so, but that, 1. Takes battery, and 2. Isn't that accurate. So there's a good chance it wouldn't bother.
But most here know about this, many are intimately involved in it and are happy to defend it. Outrage targetted at Facebook while making excuses for Google feels inauthentic.
Everyone wants an ethical society but when it comes to paying a price economics always wins out and we are left with the spectacle of the privileged hand wringing, blaming the system, blaming the victims and acting helpless. If you can't be ethical you can't expect ethical behavior from anyone else and you get the society you deserve.
I'm surprised they didn't have anything in search or youtube because I deleted the history long enough ago that I didn't remember doing it, so I've successfully stayed away from using them.
Still waiting for the data download, but I know they have all my gmail messages and some stuff I put on Drive a long time ago.
https://www.google.com/maps/timeline?pb
I’m getting the following error:
“Location Services permission is not set to always. Timeline cannot function properly if you don’t allow Google Maps access to your location while in background. [Skip][Turn On]”
Seems like I should be able to see what historical location data they have without enabling background location.
Disclaimer: I work for Apple
An accurate title for this piece would have been "This is all of the data Facebook and Google are willing to tell you they have on you"
It's pretty obvious Facebook needs to store the stickers you sent if they store your chat history. They come in their own directory in the bundle so they can be shown in the chat HTML pages.
When they are thinking about this article, no one will worry that you can't see any profile they have for you when you aren't logged in.
Err ya that's the service right :P
Why can't this be easier ? Why can't google produce a tool for this ?
[0]: https://techcrunch.com/2013/03/27/turbotax-maker-funnels-mil...
It's not. It's difficult to file taxes, because tax prep softwsre and services firms have lobbied very hard on the issue, and the other side hasn't.