Google Admits Streetview Cars Collected "Entire Emails, URLs and Passwords"
securityweek.com
securityweek.com
> their investigations revealed that some incredibly private information was harvested in some cases.
Well now, slow down. If someone transmits information into the public airspace in a public street, that data can no longer be referred to as private.
If Google had been breaking WEP while they drove along they would be violating people's "reasonable expectations" of their privacy. But there's no reasonable expectation of privacy if you're broadcasting radio signals that contain your passwords. That's just dumb.
And yes, people should have secured their wireless routers.
So collecting that information is only unethical when done on a large scale?
I don't know if it's more of an issue, but articles like this one make it more visible certainly.
It's not that people didn't go to the trouble of hiding it. It's that people are (essentially, figuratively) loudly shouting their secrets for the world to hear.
If I were pushing this argument, it would mean it is ok to copy say a movie I am downloading from a pay-per-view website on the condition it is not encrypted. Which I think does not stand legally speaking, but IANAL.
Well technically speaking, they are the same thing. Your WiFi router and your computer's WiFi card are both radio transmitters. If someone doesn't understand that, there's going to be a problem. But it's definitely not Google's problem.
As for your second point, taping video from the air on the VCR is fine. I'm sure it's fine digitally too.
I'm sorry, but that's blatantly incorrect. Using unencrypted wireless isn't a consequence of using the internet, considering you also have the options of either using a wired signal or setting up even basic encryption for wireless ones.
The fact that you didn't intend to broadcast this information is irrelevant. Consider this contrived scenario: a pair of criminals are in a house with the windows open, and they're discussing the details of a recent crime. Unbeknownst to them, there are a pair of cops walking by who overhear all the details. By your logic, these cops couldn't arrest these criminals because the criminals "didn't intend" to give this information away.
I definitely think that there need to be better defaults for people who don't know what they're getting into when they get a wireless router, or at least a warning on the box, but if they broadcast their data unencrypted, the fault is their own if someone intercepts it.
As for your example, it is indeed contrived: the criminals are doing something illegal at that moment, so most usual expectations as far as privacy goes become moot, especially w.r.t. law enforcement people.
I don't see how that's relevant at all: the key points is that you are doing something that is legal, may be looked at by anyone who has the skill to do so, but you do not indent this thing to be known. By your argument, anything that is not hidden can be looked at by anyone ? If you have a letter, or some private packages that you loose by accident, are you ok with anyone looking at it because you did not encrypt it or protect it well enough ?
As for the example, I think in the interest of making it more realistic, I lost a lot of the impact. Regardless, you sort of made my point for me. We're talking about the expectation of privacy, and the moment you start broadcasting your private information - whether shouting in public or sending out an unencrypted data signal - it can no longer be considered private.
As for your example, it depends entirely on the letter/package. Opening someone elses mail is a felony/indictable offence, so there is a reasonable expectation of privacy. AFAIK, while connecting to someone elses private connection might be illegal (war driving, etc.), I don't think that's what Google was doing. Please correct me if I'm wrong, but it seems to be that Google was just sniffing data in the air rather than making an actual connection to the network.
What Google seems to have done is more like reading a postcard. The data was clearly visible, you just needed to know how to read it. I don't think anyone could rationally say that postcards are a secure form of communication.
I think it is reasonable to expect the same kind of privacy independently of the technical means for the communication channels between well intentioned people. Of course, you need encryption because people are not well intentioned, but not using it does not justify the wrong behavior.
There is a difference between the the million of little pieces of private information we leak every day and the collection and preservation of that data. Google is doing the right thing here and is going to delete this data and make sure they don't collect it again, but I think you are wrong to dismiss the collection of private data as unserious.
Having said that, I know there were some recent cases where this was brought in to question. I just don't know what the outcome was. Also, different countries obviously have varying views on this topic.
There are legitimate unanswered questions about what privacy means in an increasingly networked world... but what to do with personal information broadcasted in the clear and recorded by accident is not one of them.
From the article, from Alan Eustace's (Senior VP Research & Engineering) quote:
>It’s clear from those inspections that while most of the data is fragmentary, in some instances entire emails and URLs were captured, as well as passwords.
If Google cracked my WEP key or something, that would be notable.