If any of those Googlers would please comment on how to square those statements with the featured article, I’d appreciate it.
If any of those Googlers would please comment on how to square those statements with the featured article, I’d appreciate it.
Except they don't, they sell access to targeting based on that data. Google's entire valuation is based on the data they have on users, if others could come in and scoop it up, they would have an instant competitor. I think calling it 'privacy' is the wrong word - Google takes data security and access control seriously, and only Legal and a dozen engineers can actually access data (and even then, it'd be logged and looked into if it was out of the ordinary).
https://static.googleusercontent.com/media/gsuite.google.com...
Yes, Google goes to immense lengths to protect user data in all its forms. That is security.
Privacy is orthogonal, and Google is well aware of the difference and how they complement each other.
You are completely wrong about Google's treatment of privacy.
There are plenty of companies that say they take privacy seriously. There are a handful that actually do. But smaller still is the number of those that have actually built what it takes to deliver on those promises, or re-engineered massive systems to deliver on privacy and transparency promises.
I suggest you look at any of Google's public privacy statements. There's no need to read between the lines.
The thing Googlers and Xooglers alike seem absolutely unable to grapple with is that Google itself is a major privacy threat, and we don't want Google itself to have this information.
The fox is guarding the henhouse, and all the fox is doing is telling us it's protecting it from other foxes.
The article here talks about how google executives deliberately made privacy settings harder to find because the people were actually using them. The article also suggests, through court documents, that google coerced other manufacturers to do the same.
This is almost impossible by design. As mentioned before, every field on a protobuf is tagged for sensitivity, meaning right down to the bare disks there is privacy controls on data.
Engineers under orders to decrypt & copy data literally could not, without a delegated authority from senior people (some will be GDPR officers too), and there would need to be a staggering level of process failure just to get at the data for a few users.
Ultimately you have to decide if you trust Larry & Sergey, nobody else could make this happen. But insider risk just isn't going to happen from a company that treats user data like military treat classified documents.
Is Google like that? If so, then it is easy to square things. The parts of Google that handle health stuff could have completely different policies about handling private information than the parts that deal with smartphones.
First of all, the quote from Jack Menzel about figuring out home and work locations sounds 1) about typical for him and 2) exactly correct. If Google is giving you directions and popping up traffic along your route between home and work every day, it's pretty clear what's going on. There's nothing weird or unexpected going on there.
Second, the settings thing. I see this as two issues: one, multiple settings, and two, making the settings hard to find. For the first, both search and maps had their own settings (web whatever vs location/location history), and they didn't talk to each other. I'm sure the relevant VPs talked about relevant VP-things, which probably did not include the config page. Both were sure they had an option to turn location off (for their project), so that box was checked, and done. Yes, someone should have made sure there was a single button, not three, but the org chart was shipped instead.
The hard-to-find thing is harder. I, as a regular schlub engineer, think that sounds pretty sleazy, but I have no idea how true it is. If someone's A/B test said, oh user engagement was down on this arm, I can see that happening. It'd be a failure, but I can see that happening.
I guess at my level, it seems like all the people I'm working with take user privacy really seriously. If someone wants their data deleted, we go through a lot of hoops to make sure it's really gone. Any feature using user-data gets a privacy review and usually ends up requiring pretty strict differential privacy bounds.
This is a little unfair and possibly just ignorant, but my impression is that Google is far better at protecting user location info than the telecoms, who have more complete data from cell-tower triangulation and who are generally willing to sell that data to whoever, and yet they get a lot less attention for it.
No doubt google puts in heroic efforts to make sure that nothing that doesn't make them money gets access to your private data.
The mere presence of heroic efforts isn't enough.