Google’s 4k-Word Privacy Policy Is a History of the Internet
nytimes.com
nytimes.com
> [If you use technology, someone is using your information. We’ll tell you how — and what you can do about it. Sign up for our limited-run newsletter.]
Uh-huh. If there's even a trace of irony in that writing, I can't spot it.
[0] https://help.nytimes.com/hc/en-us/articles/115014892108-Priv...
Newspapers like NYT are one of the few institutions where workers enjoy a level of freedom from management in doing their work. The other example is tenured professors. We should celebrate this, not mock it.
[0] https://www.nytimes.com/2019/06/01/opinion/surveillance-came...
PhD student here. I think the impression that tenured professors have freedom from management is an illusion at best. As far as I can tell, getting a PhD, getting hired as a professor, and getting tenure seem to filter out people who would challenge the system. It's easy for a university to say that their tenured faculty are free to do whatever they want if they select and cultivate people who won't take them up on that offer. (Now that I write this, I'm reminded of web hosting companies that offer unlimited storage or bandwidth but get irritated if you actually use a lot of storage or bandwidth.)
Personally, I'm leaning towards the conclusions of the financial independence/early retirement community: real freedom comes when you have "FU money". Money is the unit of freedom in the US.
Compare this with people such as e.g. Glenn Greenwald who seems to have achieved "FU money" and you actually see insightful and meaningful journalism [1] that isn't boxed into predictable ideological or partisan tropes. Of course he doesn't live in the US anymore either. Money isn't the unit of freedom in the US - it's the unit of freedom in the world. Not such a bad thing in many ways though. In times past your blood lineage was the unit of freedom. Money can be earned even from humble beginnings, but lineage cannot.
What makes you think Greenwald's writing is not predictably ideological?
Sure, it's not partisan, in the sense that no particular party aligns with his ideological biases.
Of course everybody is influenced by their biases, but fortunately we have the intelligence to ensure that our biases are but a component of our decision making process rather than being that process in and of themselves. Because of this when you find an individual (or organization) that makes some effort to be impartial it can be difficult to determine where they will land on many issues. As an example Greenwald is gay and lives in Brazil with his husband. The current president of Brazil is Jair Bolsonaro who has made statements such as 'I could not love a gay son; if I had one I would prefer he die in an accident.' This [1] is Greenwald explaining why Bolsonaro was elected.
It's easy to expect to see him just repeat tropes. And this is something that increasingly often the NYTimes is doing such as here [2] where they chose to publish, without elaboration: "Mr. Bolsonaro is ... a brash nationalist whose populist appeal comes partly from his use of Twitter and his history of making crude statements about women, gay people and indigenous groups." Bolsonaro won by a 10 point margin in a country that was and remains very liberal. The only reason the NYT characterization is not overtly fake is because of the use of the weasel word "partly."
Instead Greenwald acknowledged the tropes are going to make up some part of Bolsonaro's support, but then got to the important question - why completely normal and unbiased people, and even some LGBT types, would be voting for people such as Bolsonaro. Obviously he does not want to do this. We like to demonize people we don't like - it's human nature. He'd like to imagine Bolsonaro's base is just loaded with monsters and slur them all as being racists, misogynists, homophobes, or whatever else. But this is, of course, not the case. And so he ends up considering things he would probably rather not consider. And that, rising above one's biases and petty instincts, is at the heart of effective, meaningful, and responsible journalism.
[1] - https://theintercept.com/2018/10/29/the-lessons-for-western-...
[2] - https://www.nytimes.com/2019/03/19/us/politics/bolsonaro-tru...
And let's take a look at the rhetoric used:
> THE RIGHT-WING AUTHORITARIAN
> his tyrannical movement
Knowing what I know about the two gentlemen, absolutely nothing about Greenwald's coverage was surprising or unpredictable.
Let's look at the rhetoric CNN uses to describe this chap.
> https://www.cnn.com/2018/10/28/americas/brazil-election/inde...
Actually, it's a lot more fence-sitting and clinical, and 'just the facts' than Greenwald's. So, in short, exactly the sort of predictable, unsurprising, 'both sides' horseshit that I expect from CNN.
Both publications are biased, neither publication's biases result in particularly surprising or unpredictable coverage, so I ask again - what is the difference? That Greenwald's a bit more introspective?
There's introspective writers in the CNN opinion pieces, too - you just might not be biased towards their flavour of introspection. I know I'm not.
On one side of a spectrum you have propaganda, on the other side you have journalism. The two are inherently at opposite ends. Propaganda aims to influence people and push them towards an ideology, journalism aims to inform people and let them make their own decisions. A disturbingly large percentage of all western facing media is now more of the kind aiming to influence than aiming to inform. Greenwald is a shining exception to this in that even in topics that he was a resounding conflict of interest in, you find reporting that focuses primarily on informing instead of persuading.
But said activism is not usually any kind of disagreement with school administration though.
Reminds me of Noam Chomsky's comment to Andrew Marr while being interviewed - https://www.youtube.com/watch?v=Y2EPgix5_5w
I don't know what dystopian world you want to live in, but any time I see a company profit off sheer hypocrisy, I am going to call it out and mock it. They can have freedom all they want, but this article is generating clicks and revenues for Parent Corp, so they deserve the scrutiny. This isn't some public service they are providing.
Or perhaps a more direct comparison: Are tenured faculty at D1 sports universities hypocritical for researching the benefits of more funding going towards education and less towards massive stadiums?
1) The faculty member from University A writes an article criticizing University B, without mentioning that University A also has the same problems.
2) The faculty member from University A writes an article criticizing a set of problems, including examples from both University A and B.
The subtle distinction between both #1 and #2 is why people have different opinions on this. Many people consider #1 to be hypocritical and #2 to be fair.
If people can't criticise at all due to some level of hypocrisy (which is separated from the author in this case!) then we all end up in a worse spot.
I wouldn't put up with this type of hypocrisy from my frozen yogurt shop, my clothing store, or coffee shop, so I shouldn't put up with it with my news organizations, schools and universities and politicians. The inputs to the situation might be different, but the output should be the same. Otherwise, we are being the hypocrite as well.
The only way the article, its writer, the editor and the organisation should not be ridiculed is if they explicitly reference their own t's and c's in the article. Or if we all agree this is not news but entertainment and should not be takrn seriously (or shared on hacker news)
I've hardly seen news in my life that wasnt actually just profit seeking entertainment.
I have never understood why society praises these huge corporations. They do not have your best interest at heart. They are not doing a public service. They are a private entity seeking money and power just like every other private company.
I'll grant you that diving into Google's TOS without mentioning their own is a bit tone-deaf.
Because let's face it, that's the more likely non-hypocritical scenario than the one where corporations behave nicely.
This theme seems to come up a lot with different topics, not just privacy policies. Would it be better for NYT to NOT be hypocritical and just not report on accessibility if they don't implement it correctly themselves? Would it be better if it as a whole never verified sources given that their editorials are largely their own opinions? Personally, I'd take the "hypocrisy" because I understand that in large corps, typically the right hand doesn't talk to the left hand.
Accusations of hypocrisy are useful because they act as a reality check. If 4k word privacy policies were so terrible the NYT wouldn't have one. Clearly nobody cares, so journalists should have taken this as a strong cue that they're chasing a non-story, almost certainly due to their own strong biases and desires. This isn't some evidence of heroic journalistic integrity, it's evidence they're spinning something out of nothing.
I think we're too quick to give a pass to business/leadership people for unethical behavior we rationalize to be good for business -- in education, journalism and anywhere else.
Then why do these articles not also criticize the NYT for these practices? Google is an easy target for newspapers because they are competitors for traffic and ads. Show me NYT reporters calling out their own practices and I will believe they enjoy this level of freedom from management.
Google is also a diverse company, with a lot of employees...
What matters, in the end, is the policies.
That is not the case. Every every reporter has an editor he or she must report to. Sure, reporters are given some freedom on the stories they pursue, but it's hardly a hands-off approach.
by institutions I'll assume you mean journalistic ones. Cause employees of non-consumer facing corporations have far more freedom.
The thing is, journalism, good journalism, and certainly public service journalism, no longer requires an institution. Don't believe in the lies that claim otherwise.
Good journalism is expensive, no current model sustainably funds that kind of work without advertising and infrastructure.
Journalism is ultimately writing about what you see and investigating it to get the facts. Most stories are broken by just one journalist, big ones sometimes multiple. Journalists don't earn very much either. This isn't an expensive endeavour compared to many things even quite small companies routinely do, like build and run a TV advertising campaign.
Moreover a lot of hard-hitting journalism appears to run on a shoestring. Look at Project Veritas. It's breaking a series of scoops about the internal behaviour of Valley firms, and it seems to basically be one or two people plus some cameras and a website.
Breaking a good, big story takes time and time takes money. Journalists don't earn a ton, but great journalists do pretty well. Their work and the merit of their work is considered worth paying for. The money has to come from somewhere.
The best a good news organization can do is not allow the money to directly influence the journalism. At least in theory then the source of the money - within reason - is somewhat irrelevant. Historically, that's advertising or subscription. People got so used to free or nearly-free journalism in the late 1800s that even today people bristle at subscription, particularly for a non-physical product. So you have advertising.
I've indeed not claimed journalism takes no money. I'm just pointing out it's not expensive. Corporations nobody has heard of routinely piss away more money than is spent on breaking a major news story by large papers on vanity website redesigns. News is extremely cheap, especially these days - so cheap it's literally given away for free.
This is fundamentally wrong. It's subsidized (largely by advertising), not naturally cheap. It's like looking at Google and saying "man, software development must be cheap, they're giving away this search engine!"
Good reporting is time and labor-intensive. It also has an extremely short shelf life, meaning the time available to extract value is limited. A single news story is financially valuable for a very short period of time.
Again, compare the cost of a news story vs many other things. Advertising campaigns are also time and labour intensive and usually only provide value for a short space of time. Yet people who do advertising work often earn more than journalists. News is simply not labour intensive, especially given that the vast majority of stories are not investigative and require nearly no effort to put together. Plus, the labour isn't well paid.
You haven't supported your argument all that well. First of all, ads have a significantly longer shelf-life than news stories and can often be re-used. Even short-term ads have value for weeks.
Second, creating a single, non-"investigative" (this is a nebulous term in this context) story takes, typically, 20-40 man hours to create and has value for typically 24 hours. 40 hours is in itself relative as a measure of cost, but against the term for recouping costs, it's very expensive. Without ads, this wouldn't be a viable business.
Eh, not really. They recently shuttered their daily political cartoon section, mainly due to a submission they published that was labelled as anti-Semitic.
Sure, they're trapped inside the system, but they're trying to change it!! And that certainly deserves our respect. At least it deserves better than knee-jerk "gotchas".
"Hey, there's a reason people do the thing you criticize, as demonstrated by the fact that you do it. So instead of making this about shaming others for moral inadequacy, maybe you should be helping to identify and fix the systemic problem that leads everyone to do it. Since you have firsthand experience with that dynamic, why aren't you sharing your expertise here?"
[1] Previous comment making the point: https://news.ycombinator.com/item?id=20166369#20166980
It is not just to say "Haha! you are an hypocrite therefore you are wrong!" That would be ad-hominem. This is to say that what they denounce is not the behavior of a single actor but the norm on the net. Failure to recognize that makes their opinion at least incomplete, probably invalid.
>Failure to recognize that makes their opinion at least incomplete, probably invalid.
What part is invalid?
The hypocrisy of the NYT as an institution does not invalidate their points about Google. However, their points about Google do not make their own practices any better.
It is also true that individual journalists and opinion authors don't get to decide how the NYT operates. However, they do get to choose what they write about -- and by broadly emphasizing Google's policies and by broadly ignoring the policies of institutions like the NYT, journalists risk rephrasing the cultural debate over privacy as "normal people vs big tech" rather than, "normal people vs big tech, the government, publishers, and the entire ad industry".
Journalists do not have a responsibility to force their publishers to change, nor is it a problem for them to write articles that focus on Google. However, journalists do have a responsibility to research and understand the broader topics they are reporting on -- and it is not incorrect for readers to observe that we're seeing a trend of journalists who are remarkably hesitant to apply the same level of reporting scrutiny toward publishers and news organizations that they do towards other institutions.
It's also not black-and-white whether this criticism is counter-productive. To the extent that it shelters companies like Google and plays into "whataboutism" -- yes, it's a problem.
However, criticism of this nature is also the reason why NYT as a publisher has recently started to get more self-aware of their own practices[0]. If journalists see criticism of this nature and it makes them more likely to report on publisher privacy policies, that's productive. If institutions like the NYT get criticized and it leads to them internally examining and changing some of their own privacy policies, that's very productive.
[0]: https://www.nytimes.com/2019/04/10/opinion/sulzberger-new-yo...
The Times DID publish a generic privacy policy article a week ago and it did call itself out as one of the worst ones [1].
It wasn't an explicit "at the Times we do this", but there's an infographic/chart in the article that places the NYT in a pretty damning spot[2]. They also called out a rival news organization (the BBC) which does a great job relatively speaking.
I think the Times has a huge point here in general and I find this article's narrative compelling and well done. Instead of making it about "why didn't we make this about themselves" I would rather focus on what it's trying to say. (Also, Google is probably the trailblazer here with this stuff and sets the tone/trend).
[1] https://www.nytimes.com/interactive/2019/06/12/opinion/faceb...
it did call itself out as one of the worst ones
And yet has not changed it in response.I actually appreciate that the journalists in the Times can call out other parts of the Times (this was a part of their Public Editor) but it doesn't mean that some journalist (or the entire newsroom) can change what the legal, ad or executive team think/do.
And that's not a bad thing. Because if they could, it can go the other way too and that's really bad.
You can't rewrite a privacy policy in 7 days.
It's been 13 months since it was last changed at all.But, sure, part of the motivation of writing it was presumably knowing that some/many people would find it dismaying or unfavorable to Google.
Presumably the journalists who wrote it don't have a lot of control over the NYTimes privacy polices or practices. I'm glad the NYTimes paid someone to research it, and then published it, because then it got to me and I liked the article.
I don't see any problems or surprises, this is the world.
I guess they could write an article about the history of the NYTimes privacy policy... but really, who cares about reading that so much? Although sure, they could do more to use the nytimes as an example to be more transparent.
That they didn't doesn't erase the value of the article.
(The NYT OP does (now as I read it, it may not when you did) end with an italisized paragraph mentioning that the Times "collects data on visitors" too and linking to their own privacy policy and some other information)
But let's go with your claim, that NYT's policy is "basically everything" that they critique Google for. You mention NYT sharing name and postal address with advertisers and direct mailers – while that's something that has been an industry (in general, not just media) practice well before the computer age, let's agree for the sake of argument that it's still evil, and both the NYT and Google do it.
What other privacy policies/potential abuses do you see them sharing? We might assert that both companies say they collect and store location information, but on closer reading of the NYT's policies, I see some specific and substantial differences:
On ad-targeting:
> The ads in our apps are not targeted to you based on your current GPS location, but they are targeted to you based on your ZIP code or device's IP address.
On retention:
> If you elect to have a location-based search saved to your history, we will store that information on our servers. If you do not enable the location-based service, or if an app does not have that feature, the app will not transmit to us, and we will not collect or store, location information.
So I didn't scour the policy pages completely -- I tried to find info based on keywords, e.g. Ctrl-Fing for "location", "gps", "ip", so I apologize in advance if I overlooked something. But as far as I can tell, Google does not state a limit to the precision of location info they give to advertisers. And they do not say that users have the option to opt out of location-processing, nor do they state if it's possible for users to deny the transmitting of location info, period, in the way that the NYT says "we will not collect or store location information" if a user disables it. Again, I apologize if I've missed a similar specific statement in Google's policy.
That's a key difference in scope of data collection and retention, one that strongly rebuts your generalization. But more to the point, it's a difference in scope that has extremely obvious differences in actual impact. I think it's safe to assume if the NYT were subpoenaed for a user's IP address (such as someone making illegal threats in the comments section) they would comply with authorities.
But if the NYT were subpoenaed for the timestamped location info of a user accused of crime, and known to use the NYT website/app, the NYT, if it follows its stated policy, simply cannot comply, because it has made a decision to not track or store that info without user approval.
That doesn't seem to be the case with Google. And the consequences to the user are not theoretical – Google has already acknowledged that it complies with sweeping requests made by law enforcement, such as "the coordinates of any phones that were in the area between 7:30 pm and 10:30 pm" on the night of a suspected arson fire [0]. You can argue all you want that Google is just following the law, but the fact remains that they choose to collect and store this info. And that being the case, claiming that the NYT's privacy problems are "basically everything" of Google's, seems so facile as to trivialize the debate.
Disclosure: I just noticed that a former student of mine is listed as a co-author, and I'm assuming she was key in creating the data visualization and analysis.
[0] https://slate.com/technology/2019/02/reverse-location-search...
Of course, when you have multiple full newsrooms, you care about location capabilities. I get a customized California feed (California Today) when I go to it.
"California Today" needing a location capability - I'm not sure if you're entirely serious. Why would it need to access your current location - people read local news for where they live, not where they happen to be. And whether you're in California or not is not something that changes frequently. Nor is California Today a travel guide - it has no relevance for people who happen to be in California. Do you actually know if it's based on your real time location? I doubt it. And even if it was, it doesn't have to be.
Also looking at this - https://www.nytimes.com/column/california-today - it consists of an article every other day or so? This is why they need the location data? And it doesn't look like it's a customized feed at all - seems like everyone gets the exact same feed. What data do they need to put this together? And it looks like they have a signup sheet - https://www.nytimes.com/newsletters/signup/CA - are you sure they don't automatically sign you up based on your permanent address? I mean, consider the level of location access (frequency and granularity) needed to show New York news vs California news and compare that against, say, turn-by-turn navigation.
Also I just downloaded the app and it has "Australia" as a top-level section by default (I'm in the US). Are you sure user location is used meaningfully for anything in the app?
If the president of the World Curling Federation were to publish an op-ed on how the NFL's policies and protocols were inadequate in protecting players from permanent brain injuries, would "How big is curling's global audience and revenue compared to the NFLs?" or "How many pages does the WCF policy book devote to concussion protocols?" be relevant angles of rebuttal?
It's not so much hypocrisy as the fact Google's collection and use of data is skewed towards providing better services to consumers while New York Times's (and their partners' through the site/app) collection and use of data is skewed towards monetization.
Their data collection helps them decide where to build new news bureaus and news rooms and also what content they should surface to their readers. I get a very California focused NYT vs my friends who live in NYC and London.
Also, I'm sure a chunk of their privacy policy is actually impacted by using Google as their ad service and a passthrough from Google's to them.
Some of the services and advertisements included in the NYT Services, including on NYTimes.com and within our mobile apps, are delivered or served by third-party companies, which may collect information about your use of the NYT Services.
These companies place or recognize cookies, pixel tags, web beacons or other technology to track certain information about our NYT Services website users. For example, in the course of serving certain advertisements, an advertiser may place or recognize a unique cookie on your browser in order to collect certain information about your use of the NYT Services. For another example, an advertiser or ad server may also be able to collect your device’s unique identifier in the course of serving an ad. In many cases, this information could be used to show you ads on other websites based on your interests.
We do not have access to, nor control over, these third parties' use of cookies or other tracking technologies or how they may be used.
For example, we use Google to serve advertisements on the NYT Services, which use the Google Doubleclick cookie, and in some cases, a unique device identifier, to show you ads based on your visit to NYTimes.com and other sites on the Internet. You may opt out of the use of the Google Doubleclick cookie by visiting the Google ad and content network privacy policy. If you would like more information about this practice, and to learn how to opt out of it in desktop and mobile browsers on the particular device on which you are accessing this Privacy Policy, please visit http://optout.aboutads.info/#/ and http://optout.networkadvertising.org/#. You may download the AppChoices app at http://www.aboutads.info/appchoices to opt out in mobile apps.
They are embedding third-party tracking technologies inside their app and letting each of them track however they want.
From a technical standpoint, what's happening is that New York Times is running arbitrary code that it doesn't know anything about on the browsers of people that visit their site. And they are claiming that they are not responsible for what it does, despite the fact it's delivered through New York Times.
Does any company in the world that serves ads from Google not do this or state this?
How would you technically host ads on your site without "running arbitrary code"? How would you add an analytics solution without doing that?
And also, focusing on this defeats the actual purpose of this article. I assume it means you agree with it's message and are just nitpicking? (Or don't and are deflecting.)
And no this is not something they have to do. The idea that they cannot control what their vendors do is completely absurd - they have contracts with these vendors so they can state exactly what vendors are allowed to do under these contracts in the privacy policy. The only excuse here is that they are either too embarrassed to put what's in these contracts and/or they have no idea what's in those contracts. What NYT is doing is more or less equivalent to selling their users' data, which Google does not do.
I don't think I'm willing to agree to that. What bit in the Google Privacy Policy makes you think they do it (it doesn't seem to fit in under any of the four categories of sharing)? And do you have an example of them actually doing it?
Re: location, I don't understand the distinction you're trying to make here. Under section 4 NYT says they collect "IP addresses, geolocation information, unique device identifiers". They "use and disclose this information for any purpose", which seems rather broad and "store it in log files". The retention is specified as "as long as needed or permitted in light of the purpose(s) for which it was obtained and consistent with applicable law".
(NYT then have a section on a specific app whose location information you can turn on/off, just like Google has a section on the Android location and Location History that can be turned on/off.)
Re: what does the article criticize Google for:
- Having a "sprawling 4000 word policy". NYT is the same.
- Treating the users as individuals rather than as aggregates. NYT is the same.
- Sharing data (which the article sneakily puts as the heading of a section that's not actually about sharing data). NYT is slightly worse.
- Personalized ads / ad targeting. Google basically just say they use data to personalize ads shown to you, and link to the controls for it. The NYT policy says they target ads by ZIP code or IP address, but on a re-read I agree that they don't say anything about personalization (I misread the last paragraph of 4.B, it seems to actually be about targeting ads for the NYT, not ads on NYT).
- License for uploaded content. The authors are pulling a fast one here, since that's the TOS rather than the privacy policy. The NYT TOS, of course, has almost exactly the same language.
> And that being the case, claiming that the NYT's privacy problems are "basically everything" of Google's, seems so facile as to trivialize the debate
But I didn't claim that. I said that everything the authors criticized Google's policy for was also in the NYT policy. And fair enough, maybe it wasn't everything but more like 4.5/5.
I think there would have been a much better article here somewhere, where they'd e.g. first done a critique on the NYT policy using a similar tone as here. Shredding NYT like that would have certainly gotten the reader's attention. And once you've established a baseline and gotten the reader worked up, show how the Google/Facebook/etc policies are even worse.
On the topic of location information, my justification for seeing the difference is based on a couple of factors:
1. What ability does the NYT have to collect GPS info from users other than through mobile and explicit permission? I can't remember when I was last prompted by my browser to allow NYT access to the browser geolocation API (some interactive apps may use it), but it's still an explicit prompt. And it's still limited by me having to actively use their services.
2. I do know that Google allows for users to opt-out of and delete Location History. I'm happy to assume (and don't know any counterexamples) that when Google says it deletes the history upon user request, that it's an actual deletion, not just a database flag. But in all that I've read, I've never been clear on how opting out of Location History affects or relates to any other location data collected by Google's services. For example, from the Manage Your Location History page:
https://support.google.com/accounts/answer/3118687?hl=en
> When Location History is off: Some location data may continue to be saved in other settings, like Web & App Activity, as part of your use of other services, like Search and Maps, even after you turn off Location History.
So as an engineer, this seems reasonable to me (even if I think it's not obvious to laypeople). But is there a section where Google describes the nature of that other location data, including how it's managed and stored? In other words, if I turn off Location History, and later I'm part of a police request for geolocated devices, what potential info of mine is there for Google to share?
For the sake of argument, I'll concede a couple of points: that the NYT reserves the right to collect, store, and use GPS-level data. And that the NYT is no less compliant than Google when it comes to legal requests (and to be clear, I do not believe that Google is particularly subservient to law enforcement, and is not opposed to fighting on behalf of its users when it can). So the main difference is what each company collects as part of its normal operations, and how important/sensitive that information is for each user.
What is the worst-case scenario for the NYT user whose complete information the NYT, through malice and/or incompetence, divulges to a third-party? Billing info, of course. All my devices and everything that shows up in an IP log. Every article I've clicked on in the past 5+ years, and related page analytics. My comments/interactions on the comment sections. And I'll assume every search query I've ever made on its site. Those are all things I would never willingly put out for display, and of course I don't know the unknown unknowns (all the potential risks I can't even imagine), but the NYT-exclusive data seems mostly limited to content I've consumed and when/where I was when reading NYT-operated sites.
With Google, I don't have to imagine hypotheticals. Here's a pretty bad situation -- but by far not the worst-case scenario I can think of -- in which a man was wrongly arrested based on information provided to police by Google's SensorVault:
https://www.nytimes.com/interactive/2019/04/13/us/google-loc...
By all accounts, this kind of geofenced dragnet is very new, and at the time of this man's arrest, used only a handful of times. And yet despite the best intentions of Google's legal and engineering team, and what I'm assuming is good faith work by experienced homicide detectives, we already have a known and publicized incident that turned into a classic and rare nightmare law enforcement scenario (an innocent person being imprisoned for a murder).
I don't think the above situation is an extreme one, other than it happened to involve a murder, which is a situation in which law enforcement generally acts with the most discretion. But in any case, Google search results are routinely used as evidence in criminal cases, and while they often correlate with the prosecutor's case (e.g. the suspect John Doe searched for "how to hide a body" just days before the victim James Doe went missing), search data is just as prone to wild and broad misinterpretation, and anyone who googles random questions/topics regularly is at risk of cherry-picked evidence -- A well-known case is Casey Anthony's misinterpreted search for "chloroform":
https://www.nytimes.com/2011/07/19/us/19casey.html
Again, I reiterate, these issues don't arise from malice on Google's part. But that's irrelevant -- Google has no choice on how well others use the data they give. But knowing the actual consequences, they do have a choice in data retention policies, even if it means making it clear to the user, "Sorry, we couldn't run our systems unless we kept data in perpetuity, and that's just how it is". Until I can even imagine a situation in which NYT-exclusive data can (justifiably or not) wreck my life, I simply don't expect the same level of scrutiny for their privacy policies.
And just to be clear, this cuts both ways. The NYT, like many news organizations, have public (and internal) policies regarding conflicts-of-interest and employee public behavior: https://www.nytco.com/company/standards-ethics/
For example, I do think Google, given an indisputable document trail, would punish or fire the shit out of an engineer who was found to have manually tweaked/censored search results as a favor to their politically-connected lover. And that would/should happen at any news outlet. But AFAIK, Google (and most non-media industries) does not require or suggest that an employee tell their managers about possible conflicts of interest (romantic or not). Whereas the NYT does [0], which gives the NYT the right to fire an employee for failing to inform their editor, regardless of whether the relationship results in unethical actions.
https://www.nytimes.com/editorial-standards/ethical-journali...
And to me, this is fine, because it's not just about the ethics, but the potential for harm given the realities and the nature the work. It is patently obvious to me (and most journalists, I would hope) that a reporter has unilateral power to dictate what does (and does not) get covered on their beat, such that a reporter could intentionally hijack their work for a long while before suspicions arose. Is this the same at Google? Can the average employee have the unilateral ability to maliciously change the search index, without it being caught in a pre-production review, or it being explicitly recorded in an audit log? It doesn't seem so.
And because of the stark difference in the expected work and responsibilities, if the NYT were to not have its current ethics policy, and a Google exec were to call them out (e.g. "don't trust the NYT, they don't have a policy preventing their tech reporters from dating, and thus being influenced by Microsoft or Amazon employees"), I would disagree very strongly with an NYT apologist who says, "Well neither does Google!"
Still, I don't think the purpose was to discredit the argument, as such - just to point out the hypocrisy.
However, this is also proof of how far we've come in regulating how personal information is identified and stored.
For example, the data comparison between 1999 and 2019 - Simply saying "We collect personal information you provide and clickthrough information" is certainly not enough nowadays. A short and generic policy lends itself to legal abuse, whereas the longer and specific policy tells you exactly what to expect from using the service.
Can things be made more clear? Always. But I think this trend is generally for the better.
They might as well just say “we collect everything.”
Well the policy is not a binary blob. Google does more than most services by providing a full archive of their policies, as well as a clear-cut comparison of each.
https://policies.google.com/privacy/archive
FWIW, their most recent comparison is nearly all clarifications, with only one completely new addition.
They're going to be making money off you. It's important that you don't have a means to claim retribution.
If the average person reads 250 words / min with 70-80% comprehension, that’s 16 minutes for a 4k word policy. Since it’s legalese, I bet it’s 30+ minutes for most people. That’s ridiculous.
The TOU is a different matter, but, again, users and the law have forced companies into the situation where they have to explicitly spell out every detail. Even with that, Google's terms are written in what seems to me to be plain English (https://policies.google.com/terms?gl=us). What would you cut from that to make it more concise? I can see a few things, but I'm also not a lawyer, and I'm not equipped to judge what liabilities each sentence might protect Google from.
Most people never read this stuff because most people just don't care. They'll never have a dispute with Google that would be covered by the terms, and they don't care enough about privacy to find a less convenient but more privacy-sensitive alternative. Even if they do care about privacy, they probably have a pretty good idea of what kinds of information Google collects, so the privacy policy is at most a reference for cases where they are unsure. Attempting to force them to read it would be unproductive, since it contains information that is either irrelevant or else already known to potential users.
I don't agree at all with your point of view. I still think consenting adults can take some responsibility for making their own decisions about things. Obviously there should be exceptions when there are serious safety concerns, but such is plainly not the case with search engines.
Anyway, the TOU doesn't even address privacy very much. It would be a paragraph shorter if Google collected no user data at all. So I don't really think that is the point the top-level poster in this thread was making. Or if it was the point they were trying to make, they were doing so circuitously indeed.
You can, if the companies would not track users.
"We are not logging your activity, we are not using cookies unless you are using the webshop's cart and we delete it when the transaction is confirmed. We do not share your private information to anyone but the payment company.
We log IPs for 3 months for technical debugging. We do not try to identify the people the IPs belong to unless an illegal intrusion is detected."
That said, it seems like the real issue is that the policies are too long and unreadable. For that, I think providing a plain language version that clearly states “this is not the official policy,” but links to the official policy, could be good enough. I don’t know how much legal exposure is involved for the company here, but it seems like a workable compromise.
Anywhere covered by GDPR, for one. One of the features of that law is that you don't get to make access to your service conditional on providing personal information that is not strictly necessary to make the service work.
Maybe we need to think about alternatives to what is effectively more legal paperwork in daily life?
Instead the notices happened.
My default assumption is that they're all out to f me on this front & it's not like you actually have a choice in the modern world. If it's 4k long then I guess they just needed lots of noise to hide the crux of it.
"The Go terms do include an opt-out provision for people who don’t want to give up their rights. However, you must opt out within 30 days of first agreeing to the Terms of Service.
Luckily, many Pokémon Go users have only downloaded and activated the app in the last week, meaning they are still within that timeframe.
To Opt Out: Send an email ASAP (before the 30 days have passed) to termsofservice@nianticlabs.com with “Arbitration Opt-out Notice” in the subject line and a clear declaration that you are opting out of the arbitration clause in the Pokémon Go terms of service."
https://consumerist.com/2016/07/14/pokemon-go-strips-users-o...
Fair point. That does assume same legal jurisdiction though.
Practically I'm not in the same jurisdiction as any of these websites anyway. None of this is legally enforceable unless a party is sufficiently aggrieved to spend a ton on specialist lawyers. Whether or not I clicked on some internet button privacy policy seems a little pointless in that context
To anyone who does this, who presents complicated privacy guidelines, EULAs in all-caps, insane cookie opt-out checkboxes, please have a hard look in the mirror. Think of a real-world analogy for the kind of roadblocks and contraptions you are building, how you are misleading and exposing your fellow humans. Thanks.
Was that typo in Google’s original 1999 privacy policy or is that just the New York Times sucking at copying and pasting?
> Google’s Policy Google’s policy on our wholly controlled and operated Internet sites...
This is what it should look like formatted:
Google’s Policy
Google’s policy on our wholly controlled and operated Internet sites...
1999 - we collect 4 things
2019 - we collect everything about you
1999 - we do 1 service
2019 - we do 100s of services
Maybe there is some new moore's law in EULA and Privacy Policies as they keep getting larger and larger, when will we reach peak, as there are published books out there with less words.
https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme...
https://news.ycombinator.com/newsguidelines.html
We detached this subthread from https://news.ycombinator.com/item?id=20404173 and marked it off-topic.
Do they have an entire department devoted to churning out this content? Are they hiring freelancers are paying them by the word/click? Do they also pay people to post them and upvote them on reddit/HN etc?
In the last day alone (from a search on HN): https://www.nytimes.com/2019/07/09/opinion/email-tracking.ht...
https://www.nytimes.com/interactive/2019/07/10/opinion/googl...
https://www.nytimes.com/2019/07/10/opinion/internet-democrac...
https://www.nytimes.com/2019/07/09/books/review/the-code-mar...
Most of them are just rehashing the same "big tech bad. media is freedom" spiel.
It’s because media companies used to control all the information and opinion. Now they’re losing that power to big tech. They are mad. But ultimately they will lose, for better or for worse.