MS and Apple can be far more aggressive in this regard because they simply don't really need your data in the same way to make money.
MS and Apple can be far more aggressive in this regard because they simply don't really need your data in the same way to make money.
Surely, you haven't heard of Windows 10's horrendous surveillance?
Data collection: https://news.ycombinator.com/item?id=9976298
Ads: https://news.ycombinator.com/item?id=13835733
Phone home: https://news.ycombinator.com/item?id=10053352
These shenanigans are not existential to their business.
MS could quit that instantly and they'd be fine.
As privacy becomes a thing, they are well prepared.
And the thing is that most people would never knowingly make the privacy vs utility trade-off. The risk (that the entire world gain access to one's search history) is not in the best interest of most users. Personalized search does not provide that much added value.
John Podesta: http://www.thesmokinggun.com/documents/crime/how-john-podest...
Colin Powell, and others: https://www.theguardian.com/commentisfree/2016/sep/15/colin-... https://www.nytimes.com/2016/09/16/us/politics/email-hacking...
Tibetan activists, broadly: https://www.sfgate.com/business/article/Tibet-activist-s-e-m...
NSA and other surveillance operations claim access to Google, and other online service providers: https://www.theguardian.com/world/2013/jun/06/us-tech-giants...
There's been no widescale mass comprehensive breach of Google yet, that we are aware of. But that may simply be a matter of luck and time.
Google have said Gmail users should not expect privacy:
People sending email to any of Google's 425 million Gmail users have no "reasonable expectation" that their communications are confidential, the internet giant has said in a court filing.
https://www.theguardian.com/technology/2013/aug/14/google-gm...
And, though I cannot find a link presently, in the wake of the Snowden revelations, Google employees told the Guardian that integrity of Gmail and associated Google accounts (and they are all associated) could not be assured. Probably 2013-2014 timeframe.
And Google allowing the NSA access is not them getting hacked either.
Google reading your mail is not hacking either.
We're talking someone hacking into G and grabbing millions of emails or passwords, I don't think that has happened.
There was plenty in, e.g., the Podesta, Powell, and related hacks, to suggest at the least suspicion. The fact that single-password hacking is a keys-to-the-kingdom event is itself a major flaw. And it's not as if phishing is a new attack vector, the concept dates to at least the 1980s.
And also, Google have changed internal proceses in consequence. But a massive blame component absolutely falls squarely on Google.
There were and are mechanisms Google could implement (and to some extent has) to reduce the attack surface further.
Encrypting contents and doing so independently of access is probably the most significant. Google does not do this, and in fairness, no other major player, not even Protonmail, does this, at least not by default. The problem is hard, it intoduces inconveniences. It is not impossible. Lack of the feature has cost Google users, a small but aware and technical cohort, myself included.
(Protonmail's encryption prevents static-storage-on-disk attacks, including subpoena and insider access, but password compromise remains an extant risk. bI no principally use Protonmail.)
Patterns-of-use fingerprinting (which Google does), app-specific passwords for non-Web access (ditto), special attention to politically exposed persons (PEPs), and exceptional internal access and process controls, yes.
But the mass-sweep attack appears still viable through multiple potental vectors, stream, static, and dynamic (programmatic).
They'd be out of business pretty quickly.
Search, e-mail, social - particularly as they relate to ads - this will be the problem.