Google Drive could soon start locking your files
techradar.com
techradar.com
Page 16 : https://www.oecd.org/officialdocuments/publicdisplaydocument...
Am I missing something here?
> These files will be flagged to their owner and restricted automatically, which means they can no longer be shared with other people, and access will be withdrawn from everyone but the owner.
I'm trying to confirm this comment:
> They removed it after they began using GIFCT to ‘prevent terrorists and violent extremists from exploiting digital platforms.’ All hashed versions of that video was removed from user accounts.
> Page 16 : https://www.oecd.org/officialdocuments/publicdisplaydocument...
Then there are other non-hash methods, similar to how Shazam determines a song in a noisy room. Poles, zeros, FFTs, there are many other strategies that are fault-tolerant.
This will cause their storage requirement to explode. However, if the goal is only to prevent public sharing of content in contravention of the user agreement then I'm surprised it took them this long to implement this.
As for size, you can always tar/encrypt its dir and include dummy files to modify its size.
Does it work? Mostly. Can it be tricked? Yes.
I wish the future is a NAS that is simple, fault tolerant ( Bit-Flip protection, Error Correction, Drive Redundancy ) and extremely affordable. That is something the Apple Time Capsule should have been.
Right now I cant even get a 2x 2.5" 2TB HDD and a NAS enclosure for under $200 RSP. I was hoping Kobol would be it someday. But chip shortage and many other things had them canceled the project.
You can get comparatively much more for much less if you look carefully at the used market and spend some time building it for yourself. My 5 bays home NAS cost me just a bit over €130, excluding disks of course: €46 for a SUPERMICRO X7SPA-L mainboard and €88 for a Ultron RPS19-G3380 case, power supply included. All purchased from ebay sellers. I already had the memory modules plus an additional slow SATA controller I use for a non RAID disk, so had to buy only the disks locally. It runs XigmaNAS and has been rock solid with multiple 1 year+ uptimes interrupted only for maintenance or disk upgrades.
I do have a couple of NetApps for mission critical stuff; and one of my customers runs an Isilon which I have to support; for almost every workload that can tolerate a few minutes of planned downtime per month, the Synology wins bigly as long as you have knowledgeable IT staff.
And no, you don’t want an Isilon or a NetApp if you don’t have knowledgeable IT staff around - you want a synology (or to get better IT)
Though while giving a warning is clearly inappropriate, they should certainly have explained what they did.
If it is not shared with anyone, why should a cloud provider get to decide what I can and can't store?
I want to be able to use that storage as an extension of my local hard drives/SSD's with the ease of use of accessing it between different devices. I still consider it my data.
That those bits and bytes happen to represent a document for a nuclear weapon shouldn't matter.
Now if you were to ask if I believe people should store a video of the Christchurch shooter? No, I full-heartedly believe its kind of sick that someone would want to store/archive that, but I don't want a cloud provider making that decision.
It seems like eventually the law will have to change so that these companies have to start treating users like tenants rather than serfs.
When primary sources are not available to the public then lies have the same footing as truth.
https://www.washingtonpost.com/news/worldviews/wp/2017/09/14...
Stimme Koreas is now gone too.
They didn’t want political pressure to stop it.
You can get a rough idea of what is needed from Wikipedia. They are simpler machines than a automobile engine, at least in the sense that there are fewer parts involved.
As far as encryptions and data go I just echo that "not your drive, not your data" remains true and that encryption is not going to stop a cloud provider from deleting your encrypted content. Feels like I've been saying this for 10 years now (I have) but I truly do not believe cloud use is the future for computing. Drives and mass storage are always getting cheaper.
In this case, people could have had the video because they agreed with the shooter, to using it to show people how horrible terror really is.
Regardless, I fully support peoples right to have videos of terrible events.
People draw the line when it affects their beliefs, in that case they say it was justified for Google, Apple and AWS to censor an application that potentially can be misused. But they get outraged at the thought of removing a video of a massacre, and also they outrage at the thought of limiting their access to tools that are made for the main sole purpose of killing people.
Go figure!
But it's not even about Americans, I'm from France and it's the same, no one would think to remove videos about the 11/13 except to keep it off Facebook so that kids would not see it.
It's entirely reasonable to handle that differently from someone's personal data storage.
But at the same time there are abominations of pure evil that should never exist, not even for "historical interest".
Somewhere in the middle there's a line.
Those two situations aren't even remotely comparable - nuclear weapon plans are straight-up illegal for individuals to own in the US, so by removing one of those, Google would be complying with federal law.
The Christchurch shooting video was not illegal under any law that I'm aware of, so Google was not legally required to delete it, and it was a primary source for a historical event, so Google shouldn't have deleted it, especially not from users' private drives that they weren't sharing (as then you can't even claim that they were spreading extremist material).
A magazine tried to publish the blueprints. The government argued all nuke related info is classified regardless of actual legal status.
The federal government dropped the case, fearing they would lose.
If you are dealing with case data, you should be have those policies reviewed carefully, and should likely be encrypting before storing anywhere anyway.
I say should because I almost never see case data stored to standard.
If a judge said that owning that video was probable cause or whatever, they could produce every user who used to have that file.
On an aside, such a setup is also a layer of defense-in-depth protection against a certain, uncommon class of bugs.
I do work for Google, but don't, in any way, speak for the company. All of the above information can be found on the internet, eg. https://www.quora.com/Does-Google-really-delete-the-account-... about Google accounts themselves.
Not encrypted (at rest and in transit) => not private.
There are no exceptions.
It is like arguing against capital punishment using Ted Bundy's case as example. Generally that works the other way with most people and that's the kind of person they enthusiastically support the state murdering.
Similarly the reaction of most people to Google removing that video is going to be "good" and you're going to have a very uphill battle convincing them otherwise, and you're probably going to lose.
If you talk about university researchers that study pornography and Google nuking their research or their ability to share their research with other institutions, you'd probably make more headway.
It is only on a site like HN where the most upvoted commment is "OMG they deleted practically the worst video imaginable from a mass shooting incident can you believe those fascists?" and everyone votes it up to the top.
The HN echo chamber bubble is real.
Let the law work - possession of illegal material should be enforced by the police, not by a corporation that the user cannot hold accountable.
For syncing between devices, I guess `rclone sync` should do the trick.
For example if you saved a folder of mp3 files using the rclone crypt functionality that you downloaded from a known BitTorrent, it would be easy for an adversary to match that set of known sized objects with high confidence at the storage provider end, or from observing encrypted network traffic (which in the S3 case leaks object size through traffic patterns) and deducing object sizes from there.
I totally switched off Dropbox when they limited the number of devices. Self host owncloud on a VPS, am very happy. From time to time I have to occ:upgrade something et voilà. Used for syncing, not backing up.
It helps that I can install and maintain it though, wouldn't recommend it to anyone without a bit of wed/IT experience or the time to lean some basics.
I'm not sure how much should I trust a vps host. I can mess around with encryption all day long but they can compromise my mail server without me ever knowing.
Basically, you can't. It all depends on your threat model.
edit: https://owncloud.com/features/end-to-end-encryption-2/ owncloud community and standard edition don't have e2e
The enterprise edition is out of my budget range unfortunately.
But yeah, if you have a business... don't self host too much sensitive stuff, delegate if you can.
Honestly, if you're keen to share something you shouldn't, it's pretty trivial to host it via https://rclone.org as an http server. The only person accessing it off of Google drive is the original owner and gdrive can't tell that it's being shared beyond that.
It is not announcing new content restriction policies. Those have already been in place. What's new are the user notifications:
Not new: "When a Google Drive file is identified as violating Google's Terms of Service or program policies, it may be restricted."
New: "Now, the owner of the item in Google Drive will receive an email notifying them of the action taken, and alerting them of how to request a review of the restriction if they think it is a mistake. For items in shared drives, the shared drive manager will receive the notification"
"Google Fi did me wrong, so I reversed the charges on CC - now my entire Google account is locked / all photos / all files in drive"
This seems... like it's going to get regulated soon. Just going to take blocking the wrong account some day and boom, here we go, legislation.
“we reasonably believe that your conduct causes harm or liability to a user, third party, or Google — for example, by hacking, phishing, harassing, spamming, misleading others, or scraping content that doesn’t belong to you”
Oh the irony, Google. It doesn't belong to you either.
Talk about a pot calling the kettle black. I can't believe they put that in their terms.
For future reference: https://policies.google.com/terms?hl=en#suspending-access
Think of it more as Google defending its turf. They want to be the only ones with access to data in bulk, so that if you want to find something, you have to go through them.
Fast forward a few years, and we can all predict which content will be "hate speech" and which almost identical content will be allowed. Detection of copyright protected content will be automated, but appeals for fair use will be manual, slow and difficult. Double standards will abound where the liberal ideals of the company run up against corporate interests, favored politicians or powerful governments.
And of course- someone will make a competing service which doesn't police content, and that service will in turn become a cesspool as all the worst offenders will be massively over represented there compared to merely the good netizens concerned about protecting a free internet.
Maybe a massive move to decentralization is the only thing that can save us. 100 different services with 100 different policies on which content is allowed seems far better than the direction we're headed. I'd rather at least have the easy choice and understanding of which ideology and set of interests I'm being filtered through.
I was once responsible for ripping 250,000 CDs, legally, on behalf of various record labels, from tiny to the big 5. I would love to store a backup of all that data in the big cloud services and see which ones deleted my legally-owned data.
I once digitized a large media collection for a company (not audio, though), and it regularly used me as a backup source of last resort for when the files failed/got lost/needed to be transferred in bulk to another company/whatever on their end.
I'm not saying it's likely, but it only has to be a one-in-100-million chance for it to hit a couple Google users.
If you really care about the data, two+ backups stored in different places is completely reasonable. Note that "places" is not limited by physical as trying to maintain independent dependency chains (e.g. a durable storage provider may decide to cut off account access so maybe a second independent storage provider using a different credit card makes sense)
Your OCD may also be helped a bit by having some way to verify you backups (e.g. use ZFS and scrub regularly and/or separate hash manifests of the files).
go to your local pc and rclone encrypt mount your drive. now you have your linux isos and they are encrypted upstream
The /r/datahoarder subreddit and it's wiki is a decent starting place for figuring out backup options.
Actually, it might be a good idea to encrypt everything on Google Drive - I wouldn't be surprised if they analyze your files and use the results to augment their internal profile about you (or, even if they don't now, they could very easily do so in the future - remember when they scanned your emails to target ads at you?).
AKA, it wouldn't surprise me at all, if given a disk with 100 folders, each with 8-15 encrypted files each, that someone couldn't figure out which albums comprise a good number of those directories simply from the resulting file lengths.
* A few songs have been removed, here and there, such you can't easily determine what has been removed. * Whole albums or your collection is removed. * Your account is disabled and you loose everything related to Google, including all other stored files, email, calendar, Android apps, music and video purchases, etc.
It's not your service, it's Google's. You're only renting access until they decide you're not.
If you are going to use cloud for backup, always use an encrypted backup so they have no idea what you're storing. I highly suggest considering using `rclone` to mount Google Drive. I've had mixed luck with using the encryption module. I would highly suggest `restic`, as it's very easy to backup and restore files.
I've got a feeling this will be mostly an automatic DMCA takedown tool.
If you put something on Twitter mentioning certain cryptocurrency keywords (e.g. MetaMask), you'll get reply tweets from bots in a few seconds with fake support documents hosted on Google drive.
My sense is that this is what they are trying to stop.
What __is__ your recommendation for setting up remote backup for private use? I am thinking of something that can be used to sync and / or backup different devices for people of differing tech affinity.
I think this question deserves re-examination now, since recommendations likely change due to the facts in the op.
As far as I know, it used to be that one should either "roll one's own cloud" (whatever that means for a non-technical user), or simply use the best-integrated tool like Google Drive, DropBox, Apple for the devices at hand and live with the fact that the company will train whatever AI model du jour on your private data.
The reason for this binary recommendation was as follows: while services like SpikerOak exist, who say they encrypt your data, the believability of that was never exactly high. Most likely, your data might still get mined. Most likely, the NSA still scans all your docs. However, now you pay extra for "security theater".
Instead of paying for such questionable offerings, the decision was rather binary: decide to either go full-hog (if able) and do your own, or just upload it to Google Drive and stop caring about who reads your private documents.
But now, if Google starts actively reading, policing and deleting your data without even pretending to give you privacy, I think encrypted services start to have a use case again.
obligatory mention that the first amendment doesn't apply to private companies, only governments. Then reply and say, "I mean the spirit of the first amendment" and then I'll agree with you. better to just say "free speech principles" rather than "first amendment"
That is...not accurate.
Net neutrality was FCC policy enforced by case-by-case action from 2005 until a couple such actions were struck down by courts in 2010 as requiring regulation. After that,the FCC adopted them as regulation in the 2010 Open Internet Order (which had been being drafted before the ruling); certain parts of the 2010 order were struck down by the D.C. Circuit in 2014, saying such regulations could not be applied without reclassifying ISPs as telecommunication providers under Title II rather than information service providers under Title I of the Telecommunications Act. Subsequently, the FCC adopted regulations reclassifying ISP and again imposing Net Neutrality regulations in 2015, which (with new leadership because of the Trump Administration), they withdrew in 2017.
A number of states have since adopted various net neutrality laws, including California.
While the FCC has not yet acted on it, the Biden Administration made bet neutrality executive policy in Executive Order 14036.
It just feels like every big tech company simultaneously and suddenly decided to crank up censorship. There are even examples of hosting providers and payment processors refusing service to other companies that don't follow certain "guidelines".
It's a censorship cartel. When all these companies suddenly decide to turn the screws on certain viewpoints, it is effectively limiting free speech on society. And I shouldn't have to say this, but free speech is a good thing.
Also, on some FB group someone said Google had deleted the copyright infringing files. Can anyone confirm it happens?
On an ethical and moral level: my opinion is subjective, but this puts an undesirable amount of control over people in the hands of a company that has demonstrated that it cannot be trusted. If Google cannot provide actual human customer support to avoid wrecking lives with bad algorithms that make wrong decisions, then their policy should be to merely allow everything that's not blocked by law/court-order.
Google claims files are encrypted at rest and encrypted during transfer.
Metadata inspection? Checksum during upload?
You seem to be under the impression that either of those imply end-to-end encryption, which they don't. (And in Drive's case, AFAIK, E2EE is not an offered nor advertised feature.) The data was encrypted during transmission to Google's servers, sure, but it was encrypted to them; similarly, yeah, they store it encrypted … and they have the key.
(This isn't atypical either, sadly. E2EE is the exception…)
> Encryption: your data can only be accessed with your personal keys. We can't access your data even if we wanted to!
It creates an encrypted file/folder for each decrypted file/folder you create. So when you change a file, only one encrypted file is uploaded into the cloud.
Obviously, I could encrypt my data before putting on such a service, but that makes access less convenient.
such as a Synology NAS
I pointed out that fight for fair copyright and culture in public domain has a historical analogy in fight for public lands, that were enclosed by capitalists by the end of the 18th century, to get people to the manufacturing plants. People didn't take me very seriously, because, we are white collar professionals, not some stupid peasants or communists, right? And of course, information wants to be free and are simple to copy, so they can obviously always be free.
I think digital enclosures are coming, and the digital "public sphere" is shrinking. Some (Varoufakis) even say they are already there. Unless people fight the trend, most of the digital stuff you "own" today will be someone else's property, and not public (similar to land today). Access to it will be limited by laws and controlled by mandatory digital devices.
before this they were great units that were very easy to setup and manage provided you were not concerned about cost.
https://www.reddit.com/r/synology/comments/r53ow5/synology_c...
The censorship is getting unbelievable.
And in the next iteration it will also block it for the owner.
It's also a decent solution rather than just dropping the banhammer and locking your account so you can't then get your files out of their system.
If you're concerned about it, encrypt your files before uploading them.
Have fun explaining to your grandmother how she has to encrypt and decrypt her family photos so that yet another bad Google "algorithm" doesn't delete everything she holds dear because of a copyright troll.