Google is a surveillance company
securitytube.net
securitytube.net
And it is also a matter of the lack of serious support for maintaining such privacy and anonymity at the internet infrastructure level, and at the level of applications that interface with the internet (web browsers in particular).
These things go hand in hand. As the general public becomes more educated about the value of privacy and anonymity (and what happens when, due to the lack of either, abuses occur) there will be more demand for technology that supports keeping their data and lives more private.
Then software, hardware, and services that protect privacy and anonymity will become more economically viable, and companies like Google will have a much harder time spying on their users.
This is why education about the value of privacy and anonymity is so valuable.
Until that happens, people will voluntarily leak information about themselves all over the place. Witness the popularity of Facebook, or hundreds of other sites where people gladly give up their privacy for various dubious enticements.
A decade or so ago I still had hope that tools like PGP/GPG will be widespread amongst the Internet population. But this all completely changed. People who used to use PGP to encrypt their mails and who've used to run their own mailservers because they didn't trust their provider just use GMail today.
We're moving from a decentraliced infrastructure to a pure client/server infrastructure and there's not much you can do about this. There are a few areas where it's possible to avoid the cloud, but in most other areas the choice is either to use the prevalent centralized infrastructure or to not communicate with others.
What is wrong with this response?
The problem is that consequences of transparent pants are easy to understand, but the consequences of unencrypted email are less so.
I should also add that I think it's evil to take advantage of the user ignorance of the issue to improve ad targeting.
Two-factor auth, on the other hand, protects you when you can't guarantee the security of the machine you're using -- someone able to capture the logon sequence won't be able to replay it at a later point in time.
Note that two-factor auth without https isn't clearly of huge benefit, as an attacker with access to your network may be able to capture the session token (e.g., through firesheep or similar tools).
That's the choice now. But it doesn't have to remain that way in the future.
The problem is that most people are relatively ignorant about technology and its potential for abuse (especially when they don't guard or value their privacy).
Not only is this ignorance not inevitable, but there's every sign that it's decreasing.
People are becoming more technologically savvy, and computer literacy is spreading. Along with this, and with the various media exposes on viruses, identity theft, etc.. people are slowly starting to become more security conscious, bit by bit.
The main thing that's lacking right now is a strong appreciation for privacy and anonymity. This is especially troubling and prevalent among the youth, who are growing up in a world where so many people's lives are on display on Facebook, Twitter, MySpace, etc..
They don't really realize or appreciate how much of what they reveal can come back to haunt them and bite them in the ass in the future: from the potential for stalking, to various abuses of private information by employers, insurers, etc.
But, as more and more people get bitten by these sorts of abuses, I think it's inevitable that a greater appreciation for privacy and anonymity will emerge. It may take some time. But the process can be accelerated with deliberate education campaigns and efforts from people who do understand the value of privacy now.
a lot of people became aware that they could be tracked down for downloading movies and mp3s because of all the lawsuits.
perhaps it will take a few (more) lawsuits or criminal cases where prosecutors use data retrieved from google or facebook before people realize they are voluntarily putting a lot of data out there that could come back to bite them in the ass.
"BlackHat Europe 2010 - Changing Threats To Privacy From TIA to Google"
What Google is doing is actually monitoring every aspect of our online life! Really worrisome!
Deleted comment
Really? What about their search engine? What about targeted advertising?
Not Google nor even Facebook are privacy’s real threats, they are just easy targets.
There is a fine line - it would seem - between a security expert and an alarmist. That line is getting crossed more often as of late seeing as spreading FUD is their marketing strategy.
Yes privacy is important but some people are loosing all prospective in advocating for it, and in doing so are entrenching on other rights mainly freedom of speech.
Relevant: http://gigaom.com/2011/02/17/jarvis-publicness-needs-its-adv...
I had two motivations in giving this talk. One was to explore the shift in where data accumulates and is collected on the internet. The other was to explore the concept of "choice," in terms of how these technologies are subsequently presented to us.
Given the events of the past year, along with the CALEA II conversations that have recently begun in DC, it doesn't seem particularly alarmist to start having a conversation about these things.
I'm not sure whether you watched the talk or not, but my premise isn't that everyone should stop using Google or Facebook, as you seem to assume. Because I don't actually believe that's even possible. Or at least, that it's not a simple choice.
Don't be an idiot. Privacy online and privacy in the real world are very different beasts.
(PS: you meant "encroaching", not "entrenching")