Lea Kissner's job is making sure Google products protect the privacy of users
gizmodo.com
gizmodo.com
All this is is an attempt to show themselves as the good guys relative to Facebook whereas Google is in many ways just as bad, just along different axis. At heart both Facebook and Google are advertising scum of the very worst kind that hold the world hostage with some free functionality.
The problem with Google is that that functionality is of a grade that it is hard to get around them, Facebook you can do without just fine.
E-mail account is basically a concentration of personal data and doing so little to protect that negates everything else.
Even if you accept that that’s a price worth paying for the service, you’re “snitching” on all your friends you exchange numbers/emails with. If you avoid Gmail, they still have all your email, just from the other end.
Switching from pseudo-AI to humans isn't necessarily better. I had an attacker successfully social engineer a support person into changing the email associated with one of my videogame accounts which had some valuable items.
Preventing attackers from getting my password is something I can do myself. Preventing attackers from "recovering" my account is not something I can do myself. So I prefer services to have difficult recovery.
And now I have no way to change a password for my secondary account meaning bad guys still have a valid password. And since some services don't allow you to change e-mail you've used during registration (usually when your e-mail is your login) - I'm basically hostage to Google's login security system and have to rely on it preventing bad guys from logging in into my account while I can not do so myself.
Only if you define easier as 'badly designed process'.
> I had an attacker successfully social engineer a support person into changing the email associated with one of my videogame accounts which had some valuable items.
That is unfortunate, but why do you believe this will always be the case?
>So I prefer services to have difficult recovery.
Maybe this can be an opt-in for the more 'security-minded' minority. There is no reason to have the same process for every user. Both of the positions "Preventing attackers from getting my password is something I can do myself." and ". Preventing attackers from "recovering" my account is not something I can do myself." rely on humans not making mistakes. We can improve on both (service & user) sides to reduce mistakes.
I'd be interested to know what a good process is.
>That is unfortunate, but why do you believe this will always be the case?
I don't believe most (if any) online accounts that I have provide enough profit to the service owner to hire and train employees with enough expertise, time, and resources to properly determine a valid recovery attempt from a fake one.
Social engineering employees just seems so easy from what I've seen. It's so reliable it can be done on stage:
https://www.youtube.com/watch?v=SstZAIxl8wk
https://www.youtube.com/watch?v=lc7scxvKQOo
It just takes a single slip up and you lose. Whereas attackers can just keep trying.
>Maybe this can be an opt-in for the more 'security-minded' minority.
Yeah I agree it's a good idea. In fact that's what I've done on my primary google account
https://landing.google.com/advancedprotection/
But that implementation isn't perfect, it requires giving up some features and buying U2F keys. Preferably you could opt into exactly the protection you want, so you could get the recovery security without having to buy security keys for example.
I agree there could be better implementations, but they would cost more. I think it's a three way tradeoff between cost, easy recover, and security. When I hear someone advocating for easier recovery without advocating for higher cost, then I immediately think there will be a lowering of security.
IMHO, A good process would have several tiers, each being more manual, less automated, and more time consuming. The basic tier would be security questions, alternate email, SMS, 2FA, etc. The next tier could be establishing identity and would mean communicating with a real person. You can send a signed affidavit along with a government issued ID and the person would verify it. Then they would have to establish that the account itself belongs a specific person, and that that person is you. This can be done in various ways - billing address, CC info (if applicable to that service), etc, etc. A more real answer would be dependent on the actual service and what information the service captures at signup, etc.
>I don't believe most (if any) online accounts that I have provide enough profit to the service owner to hire and train employees with enough expertise, time, and resources to properly determine a valid recovery attempt from a fake one.
Well, then that is a different argument and I'd agree that it takes time and money to get a good process in place.
But if you think about it your logic can be applied to anything right?? I don't believe most (if any) software companies have enough profit motive to test their software for security bugs or hire people who have expertise in security.
>Social engineering employees just seems so easy from what I've seen. It's so reliable it can be done on stage:
Yeah, that is an example of a bad process.
But the cost of human intervention in recovery increases linearly with the number of users.
I agree with your ideas for automation. But human intervention has problems.
One solution for human intervention is to charge a non-refundable fee for recovery. This has the advantage of discouraging attackers from trying to recover. The problem is I think this would cause bad PR for the companies. Now instead of blog posts saying "Google locked me out of my account" there would be blog posts saying "Google is charging me $20 to access my own account" or "Google is holding my account hostage for cash".
Making users feel good about surrendering data, defined as “protecting privacy”.
Google’s positioning on the current furor is pretty interesting.
Specifically the preferred corporate definition of ‘privacy’ to mean...
> Being respectful of a user can be as simple as giving her a way to respond to a product that bothers her, whether its an ad for a chicken recipe that’s not relevant for her because she’s a vegetarian or an abusive message that she wants to report.
... Funnel-optimization (“user trust”), and enhanced personal data collection.
Very Googley.
#changetheworld
While you can't have privacy without security, security by itself does not equal privacy. Not once does this article talk about how Google tracks and records user behaviour on an industrial scale.
When you create a Google account, you're asked to provide your name, your gender, your date of birth, your location and your mobile phone number. Some of your most personal and private details, all of which will now be tied to your online behaviour.
That data capture starts right from school, where millions of students use a cloud-based OS called ChromeOS that records everything they do. It's quite horrible that this is happening - the kids don't even get a say, it's the adults who've decided this.
The G Suite for Education Privacy Notice [1] clearly states that Google collects device information, unique device identifiers, mobile network information (including phone number of the user). Also logged are IP addresses, location information, and app usage using unique application numbers.
Even if this information is detached from individual accounts and aggregated, it equals a phenomenal amount of data captured by Google on millions of students in the US.
And we've seen from Spotify and Netflix how even aggregated data can reveal very private and personal user behaviour.
It's baffling how little scrutiny the company faces, least of all from the tech community who, more often than not, rush to it's defence.
DDG does use Google search for a lot of things.
Many don’t realise they are still getting tracked as long as they use Chrome (with default settings).
Source? They use Yahoo/Bing in the backend, but Google?
His short stint in Privacy (8 months) before quitting Google for a startup makes me nervous. But maybe I'm reading too much and he just needed to move on from Google after 14 years.
https://plus.google.com/+YonatanZunger
Having read many of his internal rants at Google that’s not the epithet I would use. He certainly is a solid engineer though.
He has a lot of professional incentive not to disclose privacy problems at Google...
He is approachable on G+ and Twitter, but plain game theory means I'd doubt any reassuring answer.
If you care about user privacy, you don't deliberately build a panopticon.
Where is the opt-out for reading GMail content? Or better written: why is the scanning of emails activated by default and not as opt-in? What about the preinstalled Android Google Services, which upload data continuously on Googles' Servers?