Google fired engineer for breaking internal privacy policies
techcrunch.com
techcrunch.com
If anybody from Google can (anonymously if necessary) step in and answer questions, it'd be great.
* Different gmail accounts. Google knows they're all you.
In the original Gawker story, this caught my eye:
"...pulled up the person's email account...[and] a list of other Gmail addresses that the friend had registered but didn't think were linked to their main account—within seconds"
Keeping separate Gmail accounts is how many protect against "Google knows everything about me." In fact on Google's "What Google knows about you" page, it never crosses accounts (unless you've manually connected them). This story basically tells us the "What we know about your account" page is a bit misleading. Of course most folks in IT know it's a bit naive to think one could never figure out that different gmail accounts are related. But it was interesting that Google pretty formally knows the relationship, but doesn't tell you right where it should.
* SREs, and their level of access.
It's not so much that I care is a specific group has lots of access. I care that not that many groups do in total. This story makes me concerned that actually many groups have lots of access. Despite the "elite navy seal" vibe presented in the Gawker story about SREs, I'm now thinking that many, many teams have this kind of access. (Previous to this story, I was led to believe that SREs were quite low level (not in importance. but in nature of responsibilities. Very performance oriented, having little reason to have access to an individual user's data.).
Please feel free to jump in and correct this, Google peeps. It would make me feel better.
* What this does for SaaS and web apps in general
I love Google Docs and sincerely believe that most web apps that allow across-the-net collaboration are good for us. And are preferable to The Old Way. I want people to TRUST their stuff to Google (and Github and Amazon, etc).
I hate security FUDers who love to derail conversations of great possibility with some far out scenario, "Can my enemy see my Google Docs?!?!"
I'm way less worried about a few creeps who work at Google (they work everywhere...) and more concerned about laissez-faire access processes.
This surprised me too. In the absence of any further comment from Google, I'd be very interested to see some journalists doing some investigation here.
Assuming that this is real and not mis-reporting or user error, I'm guessing Google links using either their google.com cookie, IP address and/or browser identification. Any of those methods have potential for errors (in particular they mean you should never share a browser with another person in case your account ends up linked. That seems.... extreme..)
From this it seems to me like this is not a deliberate maneuver to deceive, but rather just an oversight.
Are you sure you didn't use the first gmail account to send an invitation? Because in that case it does add the address to both accounts address books.
From all reports, it seems that this Google employee accessed data which he knew he had no authorization to access. That sounds like a textbook case of computer crime -- why hasn't he been arrested yet?
http://gawker.com/5637234/gcreep-google-engineer-stalked-tee...
- reading private communications of people he knew in real life
- retrieving IM conversations and publicizing them without consent or knowledge of the user
- re-inserting himself in contact lists after being removed to stop the harassment
- seeking real life contact with people whose private information he had retrieved
Let's hope there wasn't more.
Each and every one of those would be a firing offense, the fact that this is beyond just snooping and led to irl contact between this guy and the people (kids?) he was stalking means the situation is more than out of control.
Mistakes happen, but such a series is not a mistake any more.
A position of such trust requires a more than ethical behavior and good oversight. Google failed in the second.
A good sysadmin has 'sysadmin blindness', even when you're looking at user data to do your job, you are not going to read the emails that sit in those inboxes unless you are specifically directed to do so by the owner of the data.
For the rest those files might as well contain random bits.
That is why I got angry with PG in this thread:
I am not a lawyer, but I can imagine at least asking for someone to look within these categories. I would personally feel very violated if I had some stranger even commenting about an email that was not directed towards them ... and even more violated if that stranger manipulated the system to get beyond whatever walls I threw up.
(Edit: Note that I work at Google as an SRE. This limits how much I can say in this discussion.)
This is the huge problem we are still facing with computer crime; because the law is still quite vague and unresolved. Juries have a tendency to not really "get" what has happened and so figure it's not all that bad etc.
It seems rotten but the best chance you would have with this is in getting the Jury excited about the stalking aspect and the contact with children.
Technically he has broken the law (at least, I think he has). Proving it though, along with mens rea (intent) is an absolute minefield and it would be torn apart by a decent lawyer. This is why most computer criminals are currently prosecuted for other crimes (in this case, probably the stalking offences).
If I break into google and poop on the floor of their server room, I can be arrested, but if one of their sysadmins gets in with their key and then poops on the floor of the server room, they can only be fired.
http://www.justice.gov/criminal/cybercrime/ECPA2701_2712.htm
Even if it's not, I maintain that if you've done something that seems like it might be illegal, they can usually find something to charge you with.
http://www.pcworld.com/article/154392/snoopy_verizon_employe...
Didn't get charged, let alone arrested, either.
And better selection of the people put into that position?
Is it indicative of the downside of Silicon Valley's youth culture that you can wind up in a position of "high trust and engineering seniority" at the age of 27? You don't see many 27-year-olds in other ultra-high-trust professions, do you?
Besides, this guy just looks creepy.
/30
We dismissed David Barksdale for breaking Google’s strict internal privacy policies. We carefully control the number of employees who have access to our systems, and we regularly upgrade our security controls–for example, we are significantly increasing the amount of time we spend auditing our logs to ensure those controls are effective. That said, a limited number of people will always need to access these systems if we are to operate them properly–which is why we take any breach so seriously.
I would assume that the logs he is talking about are logs of accesses made by Google employees to data covered by the privacy policy.
(Disclaimer, I am an SRE at Google. I do not speak for Google.)
Required Skills/Qualifications:
* BA/BS in Computer Science, MS or PhD is preferred.
* 0-15 years experience.
* 3+ years developing web-based applications.
Also most SREs don't get access to the same things that this guy did. (What you get access to depends on what you're working on.)
It is like someone seeing an ad for entrepreneurs that says, "Willing to work. Willing to take risks. Strong computer skills a significant plus"." And then concluding that the bar to being a successful entrepreneur is very low so they should be dismissed as a group.
Becoming an SRE is much, much harder than just having the credentials you listed. Being an SRE generally does not give you full access to everything at Google. I never met this one, so I don't know what his role was or why he was given that level of access. But that access really isn't something that just gets handed out to people off the street.
The fact that you found that ad, and that Google screwed up this particular case, doesn't say that Google doesn't limit who gets access to sensitive data.
It goes beyond just snooping too, apparently this guy changed end-user settings which had specifically made to lock him out, and spent a lot of time and effort to use his position at google to achieve real world effects with the people he was snooping on.
This guy has a serious case of sysadmin god complex and while I'm really not sure if it is ok for him to be exposed with name and picture I hope he'll never be in a position of such responsibility again, and I hope that google will perform better oversight of the people that have access like this.
The only thing that got the ball rolling here was the parents of some of the kids alerting google.
The only way to get around this is to have someone audit all their actions constantly, which you need someone equally or more familiar with the systems they are working with.
I think that is pretty impossible to implement that level of overview with humans, the best way to go normally is the 'buddy system' so no one can access a system unless they have a 'buddy' with them. Like the military do in nuclear weapon silos.
I am not sure this is a 'solvable' problem. You can mitigate by always working in pairs. But even that just reduces the potential for privacy breaches.
For example if an application uses Bigtable, then the key + column names often gives a lot of information about what data is stored there, which if somebody had access to some basic application data they might be able to get at somebodies specific data.
However as you might expect there are many safeguards in place, including ensuring every action is fully and securely authenticated so even low level SREs cannot read application data without a paper trail. This story is pretty surprising to me, and if true this guy is an idiot.
But then someone needs to audit the auditors. Just before I started here we used to have an employee who would look in the Oracle database used by Lawson to check payroll data. Nobody knew for a long time since he was the UNIX admin and DBA.
So they tried to sweep it under the rug by just letting the guy go.
If an employee of mine had ever snooped on end-user data and would have used that data in order to get real-world effects in the lives of those users I'm fairly sure I would have registered a complaint with law enforcement.
Google has their 'image' to be aware of, but in this case just letting the guy go may not be the best way to preserve that image.
If what you say about the practices at Facebook is even remotely true then it is disgusting and shameful behaviour.
Google's mere dismissal of the guy comes across as pretty evil. According to the article, there was a previous instance of malfeasance. If the bad PR behind all these privacy breaches were taken more seriously, Google would probably have to clean up their act and users would benefit as a result.
As for David Barksdale, good luck to you, you will need it.
It is a shame that PGP only took off in the hardcore user community. If it was made insanely accessible to users -- maybe even transparent -- maybe we could have a better assumption of privacy for our communications (as well as a potential reduction in spam?).
I think we ought to have some kind of equivalent HIPPA act for ALL data personally identifiable to us, not just in medical contexts. That'd put the fire under googles ass enough to take our privacy seriously. Fuck Eric Schmidt and his "change your name at 18" bullshit. We know who that fucker is right now.
> Mr. Schmidt is surely right, though, that the questions go far beyond Google. "I don't believe society understands what happens when everything is available, knowable and recorded by everyone all the time," he says. He predicts, apparently seriously, that every young person one day will be entitled automatically to change his or her name on reaching adulthood in order to disown youthful hijinks stored on their friends' social media sites.
Which makes sense to me. Hell, I wish I could delete some videos and/or photos of me on various sites.
Lately Schmidt has been making statements like this though; they are reasonable when complete, but some reporters snip out five words (or, just paraphrase or interpret) and create a news storm. CEOs are supposed to be good at avoiding that sort of thing.
> equivalent HIPPA act for ALL data personally identifiable
We ought to start with getting the same level of laws for voip, IM, and email that phone and mail have. "All PII" is too vague, but those seem like a slam dunk.
That way, if something goes horribly wrong, someone's ass is more on the line than them just losing their paycheck.
And I think at this point Mr. Barksdale ass is pretty much screwed -- it's unlikely he'll ever get a job doing this sort of work again.
It's a tricky problem. I know to do my job I need root access to everything. I guess at Google scale you could compartmentalize so the same person doesn't have free access across services.
But at some point you just gotta trust your people.
OTOH, perhaps I just don't understand -- what this fellow did is so over the top it's difficult for me to understand why he would do such a thing. It's wrong on so many levels -- it's just not something I can comprehend.
Some people are born knowing all the rules to social interaction. But others have to learn them through painful trial and error. A lot of us got that out of the way in middle school, high school, and college, before we were given the responsibility to do anything truly damaging to ourselves and others. Maybe he just had the bad luck to not seriously screw up until he's at an age where everyone will blacklist him for it.
However, I do know people who work at a local ISP, and I'm sure as hell not passing my email through those servers.
So yes, it is refreshing to see transparency of "Engineer fired for snooping where they shouldnt". But we keep using them as a service, so it's a hard problem to combat. After all, the price is right. Just costs your privacy.
If you're on the internet, your information will always be available to someone. On the internets, as in real life, this power can be abused.
Appreciate the fact that they're open about it.
I have a blackberry hooked up to Google Voice and Mail servers. They know my name, address, all my phone numbers, all my emails, my contact lists, frequency I receive calls on my Google number, text transcription of voicemails. They also can potentially record every call I receive and make with GV.
Considering the benefit I get from just Mail and GV, the datamining is a cost I'm willing to make. I also know if my phone is lost, I dont lose my data. And I can back it up elsewhere.
And I am somewhat happily shocked that they came such forthright that they "fired him for snooping". Most places will only say "They no longer work for the company".
http://news.ycombinator.com/item?id=1689025
Good to see google is taking a hard stance on this.
It is worth pointing out that payable cloud services may also cost you your privacy. It has happened before, various data leaks, stolen passwords, etc.
He's totally dumb.