For important infrastructure pieces, like how businesses communicate with each other, we should strive for this level of privacy and availability.
If not, it's definitely an option but I'd generally anticipate it'll lose out in userbase to the alternative that has those features.
I wouldn't make this a morality based argument if we just had transparency. If they were perfectly transparent, their business model would be fine (in terms of morality at least). But I believe, personally, that they have the responsibility to better inform consumers exactly what data they're collecting and exactly where it's going.
If you are a well educated consumer who decides that they are comfortable with the level of surveillance in exchange for that product, than by all means. I just wish it wasn't impossible to be a well educated consumer in this field.
Google is collecting surveillance data on it's consumers, that the majority of it's consumers don't even know is being collected.
At what point does it become Google's responsibility to make a reasonable effort to inform people about their surveillance practices? I'd say if polling shows that the majority of your consumers aren't aware of your surveillance practices, you aren't being honest.
The last time we tried to push the responsibility onto individual organizations to inform the public of the basics of how the Internet works, we ended up with "This site uses cookies" dialogs popping up redundantly and annoyingly everywhere.
I think I'd rather see the money spent on a public education campaign, not unlike the US Health and Human Services videos of the 1950s. While hokey and hilarious by modern standards, they provided a real service in helping Americans reconcile with rapid advances in technology and hygiene (including now "common sense" ideas such as "Don't play in construction sites" and "Drinking and driving are dangerous").
How do IT security staff sign off on stuff like that?
I think you've hit on a very interesting point. The fact that IT security staff (with careers and reputations on the line) do sign off on companies using Google's platform for business applications that include passing sensitive data around might indicate that our assessment of the risk model is flawed?
It's no secret that a lot of companies don't have great information security.
I think that the fact that people are signing off on it just emphasizes how little some people care about information security.
The cost-benefit analysis of their individual industries and the risk tolerance of their companies.
The cost-benefit analysis and risk tolerance doesn't tell us about how much Google secures their privacy, it tells us about how much the company cares about their privacy/security.
Beyond that, it's a trust and a penalties-for-violating-policy exercise.
And I agree with you: you can probably tell volumes about how much a company cares about the risk factors based on who they trust. But I don't generally think companies are being ignorant placing their chips on Google---it's a big org with a lot to lose if something goes wrong. That gives it advantages over either smaller competitors or rolling one's own (factoring in that to match the security of a dedicated service's cloud offering while approaching the convenience of such an offering, you basically have to hire your own full-attack-surface-spectrum infosec team, and that's one more line item in a small company's budget).
Sure Google can solve one of those problems, but we also shouldn't pat ourselves on the back unless we solve both problems.
I still think that in the context of this discussion, open source does solve both the privacy problem and the accessibility problem. But you're right that there are problems, namely incentive, that open source does not solve.
Open source is not the only solution to those problems, and sometimes solving those problems (privacy and accessibility) just isn't practical. In those cases, I would just wish for more transparency.