Leaked Document Says Google Fired Dozens of Employees for Data Misuse
vice.com
vice.com
Google is enormous with thousands of employees and a lot of data. There will always be an edge case where an idiot employee decides to do unethical things, looking at data they shouldn't.
If no one had been fired for this, I would presume that means Google either isn't paying attention to who looks at what, or that they aren't firing people when they find out they've done this.
That's why I practice data avoidance and data economy.
https://nypost.com/2021/07/13/facebook-reportedly-fired-52-w...
It reminds me though, that are some industries that frankly know more about you than they should (e.g., mortgage loans). I don't think the politicians have found the right balance of not creating another housing crisis, and requiring your neighbor to know virtually everything about you just to get the keys.
Another is that private companies holding massive databases of info about everyone is barely better than the government doing the same, if you're more worried about government abuse than private abuse of data. Many companies can and do sell access to governments, and of course warrants & other orders exist.
(yes, this also applies to the "credit bureaus", banks, and all sorts of other companies that hoard and sell all kinds of creepy stalker data about people)
[1] https://therumpus.net/2010/01/conversations-about-the-intern...
But a quick google reveals this AP story [1]:
“But the AP, through records requests to state agencies and big-city police departments, found law enforcement officers and employees who misused databases were fired, suspended or resigned more than 325 times between 2013 and 2015. They received reprimands, counseling or lesser discipline in more than 250 instances, the review found.”
[1] https://apnews.com/article/699236946e3140659fff8a2362e16f43
But "misuse of systems" could be mining Bitcoin or whatever, I guess.
Rarely do I think we need more laws and regulations, but that these are not disclosed to the public and impacted users as data breaches strikes me as terrifyingly unjust. When cops misuse power to do this they are criminally prosecuted. Seems appropriate.
I don't disagree that this is completely unjust, but cops are also completely under-prosecuted for basically anything (in the US, at least).
Information systems are very open to snooping by programmers and tech staff, however. Ultimately some (usually small) group of employees must be trusted more (but never completely) b/c they have access to the network, programming or databases. Audit trails, logs, encryption and yes, "internal affairs departments" all play a role in maintaining a secure system so that even the god-like programmers must be careful not to overreach.
I've never heard of a reference to "Google IAD" but I certainly hope one exists.
Humans do not always act in their rational self interest.
Most people would think they won't get caught and there is probably a large number of unreported cases.
https://www.amazon.com/Google-Leaks-Whistleblowers-Expos%C3%...
Encryption doesn't really change the problem. It moves the problem from access control over the data to access control over the keys.
How could you make an e2ee calendaring service? E2ee google sites like page with groups based access control? Realtime group collaborative editors?
Any one of these features is distinctive and novel enough that if you had something that worked even in a moderate scale you could turn it into a company.
https://www.amazon.com/Google-Leaks-Whistleblowers-Expos%C3%...
> Using Google's own internal search engine, Zach discovered their six-part plan for complete information dominance and released 950 pages of these documents to the world in June 2019 with an appearance with James O'Keefe on Project Veritas, which quickly became one of their most popular stories.
Of course he's into QAnon and thinks that Covid-19 was planned: https://www.vice.com/en/article/k7qqyn/an-ex-google-employee...
What a great source.
If you're working on a system that doesn't have data usage policy, one where there is no auditing or monitoring mechanism and no visible enforcement being done against abusers you don't deserve your customers trust because you're not protecting their privacy.
Translucent Databases explains how.
https://www.amazon.com/Translucent-Databases-Peter-Wayner/dp...
Source: Was once an insider. Created and ran electronic medical record exchanges.
Wherever normal people have the access to gain an information advantage, they will.
If someone evil working for Google looks at a millionaire's private data, will they be able to blackmail them for more money than what they lose if Google fires and potentially sues them?
I'd be really interested in the answer, because if it is yes, then Google is surely collecting way too much information and it is actually somewhat reasonable for people to "game the system" and take advantage of it. Of course, I fully agree that it is illegal and unethical, but so are shoplifting and robbing people at gunpoint, and both of it sadly still happens quite regularly.
Also, I remember a while ago reading about some sort of professional insurance and broker that celebrities use to pay off what is effectively journalists attempting to blackmail them.
"Schmidt has a reputation for contacting celebrities in advance of trying to publicly sell private photos or videos to see if they want to purchase them back."
https://www.dailymail.co.uk/tvshowbiz/article-471218/Sultan-...
https://www.businessinsider.com/10-victims-of-celebrity-blac...
An example from the article has an employee listening to children's voicemail. Google operates a voicemail service. It is not clear to me how you would operate a voicemail service without storing that data somewhere. (Yes e2e encryption, however let's acknowledge that is very uncommon).
Google operates a number of services (docs, Gmail, photos, etc) that require the storage of sensitive data and I am actually happy they have programs that seem to be catching internal abuses.