Google will shut down Google+ four months early after second data leak
theverge.com
theverge.com
* With respect to this API, apps that requested permission to view profile information that a user had added to their Google+ profile—like their name, email address, occupation, age (full list here)—were granted permission to view profile information about that user even when set to not-public.
* In addition, apps with access to a user's Google+ profile data also had access to the profile data that had been shared with the consenting user by another Google+ user but that was not shared publicly.
> We discovered this bug as part of our standard and ongoing testing procedures and fixed it within a week of it being introduced. No third party compromised our systems, and we have no evidence that the app developers that inadvertently had this access for six days were aware of it or misused it in any way.
I know you can't say "no one did", but I wish announcements like this gave some level of confidence. "All API calls are logged and no 3rd party made calls that exploited this vulnerability" is very different from "We have no idea if anyone used this, but there's no proof that they did".
I mean, one has to assume your data was exposed anyway, but still, it'd be nice to know.
You should be testing your software at every step of its lifecycle, especially in production. Production is where it matters if there's bugs.
If Google Drive had a failure like this it would be a lot worse than Google+. And that's a much more complex environment.
The technical constraints that protect data are pretty solid, and I have no concern at all about any kind of generalized breach or exposure with one of Google's core data systems like drive, docs, and Gmail. But looking at the sharing configuration for g+, it's just not intuitive what's shared and with whom, because the states seem to contradict each other.
You can have proper technical controls managing your permissions only if you can articulate what those permissions are supposed to be. And you can't just v2 the API with a better sharing model because users have already expressed their intent using the old model. You'd have to reacquire user intent, which is basically a non-starter.
So either you put up with a crap sharing model which is impossible to get right, or you delete everything and start over. It's no wonder they're killing it.
There's a colorable argument that you don't even want this to be a norm, because of the incentive problems it creates:
http://flaked.sockpuppet.org/2018/10/09/internal-disclosure-...
Regardless: bear in mind that you haven't even heard about a fraction of the horrible vulnerabilities internal teams at tech companies have discovered over the years.
We'd be recommending people be starting their migrations by Feb - May, and now they've got to complete them by April. That's something of a PITA.
https://social.antefriguserat.de/index.php/Exodus_Planning_a...
There are 7.9 million Google+ Communities. Sure, 3.9 million of those are 1 (or fewer) users, but that leaves tens of thousands of 1,000 or more members. Even at only a few percent of those as active, that's a lot of communities and people involved. And Google+ has no effective community migration process.
Source on communities: I counted them myself, well, via sampling: https://old.reddit.com/r/plexodus/comments/9zx67d/google_com...
Does the shutdown of Google+ mean that Google Search users will get the + operator back?
>I know from considerable experience that the plus operator had a distinct meaning from the quotes operator so this change definitely implies that Google queries will be less fine-grained no matter what quotes means now.
I remember those discussions, but I'm not aware of even one great example of how + was so amazing compared to "...". (others pointed out it allowed spellchecking, which is okay, but far from the secret dark arts)
Granted, the amount of UI they are carrying along with them is much larger, but the attitude of Google with regards to existing users has gone from really cool to downright disdainful. If you aren't a 20-something or barely 30-something techie, they think you should just go along and acknowledge their intellectual superiority. What you want either agrees with what they want, or is misguided.
There was a time when one could ask meaningful questions and see links to useful websites like hyperphysics, engineering toolbox, and others. Now, even if you're lucky enough that Google recognizes the technical nature of your question, you still end up with a page full of ads, commercial websites, blogs, and unrelated garbage on the first page[1]. Remember when if it wasn't on the first page it probably didn't exist?
I only lament that I have no way to compare modern and legacy Google search functionality to prove the decline I've noticed for years. Even the way we search has changed, as Google seems to have normalized asking full questions instead of just searching for keywords.
The internet seems to be regressing. This is just one of many fronts. Of course Google is only partly to blame. Users and their obliviousness to harmful commercialization are also a part of the problem.
1. Unless you're asking a coding related question, in which case Google is still great for directing you to the correct stack overflow question.
"foo bar" is actually treated like "foo" "bar", which is far less useful than it once was.
No it isn't. Compare "internal engine" with "internal" "engine":
However, it doesn't work the way it used to either.
I get frustrated once or twice a year about this, and every time I fight with the many (old) tutorial examples, but eventually end here: https://productforums.google.com/forum/#!topic/websearch/6gH...
Where we see that "foo bar" only says that "foo" will appear in the text before "bar" (but anything can be between them), and that's assuming the bug is actually fixed.
That status of "we think it's fixed and users don't agree" is the last I've ever seen.
Also, the intext: operator works for me (make sure there is no space after ':').
More than one author has described this better than I can, in articles, blog posts, and comments. (If you can "find" them -- heh; but of an unexpected joke come up as I type this.)
--
"6 common misconceptions when doing advanced Google Searching"
http://musingsaboutlibrarianship.blogspot.com/2015/10/6-comm...
(Blogger "Javascript era/template workaround):
I wasn't aware of some of the tips described there, but still not parity.
--
The + operator has been replaced. (google.com)
261 points by hammock on Oct 21, 2011 | hide | past | web | favorite | 167 comments
+ was an exact match. I believe it also precluded stemming; thus the ~ operator, when you wanted stemming (stemming: Not just "wonder", but also "wondering", "wondered", "wonderful", ...).
+ designated "must be in result". With double quotes -- this may be part of or in kind with other changes made to by Google to search results matching -- Google insists and becomes more aggressive at including results that don't include all the specified terms. Sort of a forced default "Did you mean..." inclusion that many find has come to clutter search results to the point of being unusable.
There are some other aspects, I believe, that I'm not recalling right now.
My experience seems to mirror others': I know what I'm looking for. I may well even have seen it, months or even years ago -- my memory's pretty decent, in such matters. Yet I can no longer get Google to cough it up in a search result -- or, it's on page 15 or 20. Despite my focusing my search terms to try to target it.
There are other factors in this degradation. But, to the best of my recollection, the loss of the + operator was a significant factor.
And the link in a sibling comment states that + is/was simply double quotes. No magic at all.
Specifically, I'm wondering if someone's working on a script that does the following:
- Ideally for each post URL given, it would preserve the post, and the comments (including the first few ones, not just the last few ones that are shown by default). It would be nice if it also preserves the +1s (including who +1d them), but that's optional.
- And given a user, it would do the above for each (public) post of the user, or (optionally) use your account to save (just for yourself) the posts that you can see.
There were a lot of people posting great stuff on G+ and resulting in wonderful thoughtful conversations (especially a couple of years ago), it would be shame to lose all that permanently.
(If someone doubts this: see e.g. (if you're interested in mathematics) the posts by https://plus.google.com/+TerenceTao27 https://plus.google.com/+TimothyGowers0 https://plus.google.com/+johncbaez999 etc, or https://plus.google.com/+DanPiponi for more CS-y stuff, or for more "general" stuff https://plus.google.com/+YonatanZunger etc -- and for all these people, especially in 2015-2016 or so.)
Edit: You can download your own content using Google Takeout https://takeout.google.com. Just learnt of these other places where this question has been asked / is being asked: this G+ community (https://plus.google.com/communities/112164273001338979772) and this wiki (https://social.antefriguserat.de/index.php/Main_Page) -- if you have any answers those may be good places to post too :-)
The archivist in me is screaming that yes, of course it should be archived.
The web-old-timer in me just shakes his head that people never learn to keep a copy of their content on the actual free - as in freedom - web, on their own website. Let it be a mere text file, uploaded by ftp, or a WordPress, or anything, just do it. Nobody should expect others to archive it for them. (For more on the topic, see http://indieweb.org/why ).
Back on topic: talk to https://www.archiveteam.org/index.php?title=Main_Page .
If this is the company with the best security team in the world does that mean we should simply abandon all hope?
There was drama in the first instance because they didn't immediately disclose the bug. But disclosure of internally-discovered vulnerabilities in SAAS products isn't a norm. You see disclosure of bugs in consumer products, like the ones Apple issues, because they have to be disclosed to motivate end-user patching. That's not the case for serverside bugs, and you haven't heard about virtually any of the horrible vulnerabilities internal teams at tech companies have caught.
I think you are falling for Google's marketing efforts with a statement like this. Project Zero, where all the positive association around Google's security comes from has little to do with their product security. Their product security hasnt been so stellar, just look at Android. And don't forget the entire company was breached for a while without them knowing. Just trying to put things into perspective.
sadly, they are a bit limited by product strategy.
Unfortunately, Google (and Facebook) has a business model that depends on acquiring as much personal data as possible and keeping it forever.
There is also a difference between "having a team of the best security people" and "having an organization that is best at security" I suspect Google is much more the prior and very little of the latter.
tldr: don't use any Google services that have less than 1 billion monthly active users.
> We discovered this bug as part of our standard and ongoing testing procedures and fixed it within a week of it being introduced. No third party compromised our systems, and we have no evidence that the app developers that inadvertently had this access for six days were aware of it or misused it in any way.
Yeah, imagine how that can go at other "trustworhy" companies holding your personal and credit card data :(
What is this the 3rd or 4th social network Google has failed at?
G+ was such a silly play, when you consider that Google already had the key to centralized identity all along: the ubiquitous GMail account. They will continue to push that for sure.
The fact that every now and then they have a success speaks better of the specific team driving it than it does of Google as a whole organization. That is usually the case with any corporation though.
So basically, you can have all the resources in the world, but if you’re not organized well, then you will not accomplish your goals more efficiently than your smaller competitors. The fact that your competitors are comparatively resource starved probably helps them optimize better than you can, because what is just a side project to you is their entire existence to them.
I've been reading the threads about Google killing off products - to the point where it's become a meme. Lost in this are the number of products killed off by other large tech firms. A shame because sometimes objectivity is lost in the analysis.
Your phrasing got me thinking about some of Google's successes (off the top of my head):
They have old successes in search and gmail. In these cases, they climbed their way to the top. The have google.docs, youtube (oldish) but entering TV/Movies now, android (not that old), Chrome Browser, ChromeOS & their entry into schools, translate, google.storage, maps, that dohickey used to stream video to TV sets (can't remember the name:)...
Google Plus probably deserves a quick death. I just wouldn't underestimate Google by downplaying their successes.
Chromecast and it's probably one of the best things Google has built in recent years. It's entirely removed the need for me to hook up a media PC to the TV, and now I can just stream content from the home server. Also multi-participant Youtube parties are a thing, and work well (everyone can add things to a shared queue).
Yes, I love mine … and yet, why doesn't it have a remote. No, my phone is not a suitable remote: it's locked, so I must unlock it before I can do TV stuff with it. Also, for some reason Chromecast & my phone tend to desync a fair amount of time.
I've never been happy with the Apple TVs I've used, either (the UI is pretty painful), but at least they have remotes.
A remote doesn't make sense for it honestly.
I would pay $20–$50 for a decent remote. I'd also love for the Chromecast to have the ability to use my accounts to play entertainment directly from that remote.
Android - Aquisition
Maps - Aquisition
Docs - Aquisition
Google is great at scaling up aquisitions and optimizing them for the audience.
I'm not sure if I buy this line of thinking related to Google only. It just sounds like another dig. Most big tech companies are fairly good at either scaling acquisitions or buying them for their IP/Talent. Some big tech companies can't even get this right.
I'm still forced to ask myself: what was Android or Maps before the acquisition?
If we compare, for example, the hacked version of CP/M (that later become DOS) with Windows 10... can we not say the same for Android - pre-acquisition? Google has certainly done much more than simply optimizing it.
If it's basically an idea that Google's buying: the idea of a hut. Optimizing that hut might be akin to building a skyscrapper. At what point does Google get credit for actually building something useful vs "optimizing and scaling" (which I think has become another meme)?
This also still leaves us with Chrome, ChromeOS, Entry into schools, some hardware, and a host of other stuff someone more in tune with Google could address.
If the response is that Chrome is based on Linux, then the counter is that macOS is based on BSD. The question remains, what is Google doing differently from other tech firms. Might they actually be building a better mousetrap (re: their successes)?
Not a fan of Google. Just think that too often people box companies in and disparage the actual work they do while, in the meantime... they take over the world.
Maps - Acquired 14 years ago
Android - Acquired 13 years ago
Docs - Acquired 12 years ago
YouTube - Acquired 12 years ago
Are we assuming Google didn't change or innovate with those at all in last 10 years?
Android - significantly improved all over
Docs - never a big user, don't really know
YouTube - significantly better video quality, significantly worse user experience with everything else
It seems the hit rate is low whether inside or outside Google.
It's a shame the implementation was so complex (apparently) that now it can't be easily maintained. This does seem to happen to Google a lot. It probably has more to do with too many resources, rather than not enough.
But maybe it's not simple to compete with Facebook. Maybe this has little to do with technology.
The only reason I didn't use it on G+ is that no one outside of my RPG circles was on it in the first place.
G+ mostly mitigated the frustration of it for people who didn't care years ago: You can just click follow and it puts them in a default following circle.
um "simple"? walks off cackling maniacally into the sunset
But technically speaking, they had the best support for high-quality photos, good features for private groups, and a few other wins on features like Hangouts.
Ironically, this is exactly the attitude that led Google to fail in social media! Why do you think it's simple? Because you think it's technologically simple?
https://social.antefriguserat.de/index.php/Platforms_and_Sit...
Does anyone know of a good way to archive a Google+ group. There is a bunch of good info about hacking the Kankun smart plug that I would like to preserve.
There are some tools.
https://social.antefriguserat.de/index.php/Data_Migration_Pr...
Its like most of us live behind this wall of our behavior online, like it isn't shared unless there is a hack.
But its sold, shared and traded without us knowing it, and used to display a reality tailored to us with the unintended consequence of us living in a bubble and not seeing much outside the edge of the bubble.
This site is a great example of bubble breaking.
Google+ had 52 million users?
That should be the headline.
About 9% of Google+ accounts ever posted any public data. That's roughly 300 million profiles there, though for many of them, the posting was at best minimal.
Based on publicly-visible posting activity, I and Stone Temple Consulting independently determined that there were ~4 - 16 million profiles publishing on a monthly basis or better in 1Q2015. Given other forms of participation, it's reasonable to assume a ~10x larger general active, but lurking, population, which gets us to about 40 - 160 million users.
Various other forms of population estimation come up with fairly similar statistics. Keep in mind that until 2007, an online community with >10m users was extraordinary of itself. A few were larger (Google's own Blogger had 200m MUA in 2008, larger than Facebook at the time: https://techcrunch.com/2008/12/31/top-social-media-sites-of-...).
The most interesting thing about the 52 million user statistic reported is that it is in the general ballpark of at least one set of estimates of G+ user counts. A number on which Google have been showing remarkably more candor as of late, though far from crystal clarity.