Google Drive may restrict files identified as violating ToS
workspaceupdates.googleblog.com
workspaceupdates.googleblog.com
They don't actually block the file though, and there were (and still are) ways around the rate limit. (Which presumably they knew about to some extent, given you now cannot make copies of said files.)
They could easily start taking action on obvious copyright violations using Drive, but it's unlikely they would want to, unless actually mandated to legally.
I'm not sure what they would do about massive encrypted collections that have been rcloned onto their servers though. Aside from "please stop breaking our de-duplication".
Is anyone surprised by that? Every file sharing tool will invariable be used to share pirated and worse material until the people behind that tool show a willingness to stop that behavior. It is practically a universal law of the internet.
If Google were genuinely interested in stopping the spam, they would create a way for recipients to establish which organizations could send files to them.
Whitelisting orgs would either be an opt-in or opt-out feature. If it’s opt-in, it won’t prevent 99.999% of spam because nobody will set it up. If it’s opt-out, it will break sharing for 99.999% of users.
These are never easy problems.
I would. And anyone who doesn't want the spam would. Right now we send "550 Too much spam" responses to docs and sharepoint emails. I'd be happy to, as an alternative, use an interface at Google or Microsoft that let me whitelist the organizations who can send files.
Spammers ruin everything.
> When it’s restricted, you may see a flag next to the filename, you won’t be able to share it, and your file will no longer be publicly accessible
So it's probably a combination of things, including piracy. They're not forbidding people from storing or retrieving the files, just not allowing anyone to publicly host whatever they want on Google's servers. Seems reasonable.
Of course this point of view is silly - Google have done very well to make users the product. A win:win scenario for those which couldn't afford the pay-for equivalents, but their ceaseless ability to kill useful services proved that they were never benevolent, nor a charity.
The internet has grown up, and so has the ability to scan masses of data for liabilities - Google's change here is not controversial or unexpected, and realistically if people have a problem with the many problems with US copyright laws they need to pick up their pens, change who they vote for and vote with their wallet.
As for the implementation I think it's pretty fair - they aren't stopping the user from their 'backups', they're just preventing their hardware and bandwidth being used as a piracy BBS.
OTOH, I welcome this change. Instead of losing my access or getting a strike on my account, I'd rather have my file merely flagged and stopped being shared (not that I share a lot).
I think service providers should be more transparent about problems they see with the users' accounts, so users can take appropriate actions. Of course there can be other mechanisms to prevent abuse, or lawful intercept (which is another can of worms that I want to leave it at the top shelf for now).
So, I've read a Google blog without bad feelings for once. That's good.
This seems to be more related to DMCA violations to be honest.
Anyways, my spam issue stopped around two months ago. After I complained to Google for those spammy tags with multiple examples forwarded and multiple cases opened, they seem to have solved the issue (or added me to some sort of mention exclude list lol)
Conversely, the information for how to report what you perceive as a ToS violation is far more complete: https://support.google.com/docs/answer/2463296
> Should we ban this user? YES
Then you request a review, and the support person double-checks that the output really does say "YES" and not "NO". Then they tell you they reviewed their decision.
I wonder if someone has already tried to invoke it against a Google/FB/.. ban hammer.
This feels like a slippery slope to be on.
How do you figure out legality of having a document from the document? Unless it's child porn, where it's implicit, this simply isn't computable.
Those interested in google's slippery-slopes should look into "keyword warrants" [1] and "geofence" warrants [2]
[1] https://www.cnet.com/tech/services-and-software/google-is-gi...
[2] https://nlsblog.org/2021/01/08/google-data-and-geofence-warr...
Google scanning photos you upload to their cloud seems fine to me. Not a slippery slope.
Their cloud doesn't mean its their content. If said content is public, I mostly agree, but not if its private.
When I hire a storage box and put stuff in it, I don't own the storage box. Yet still it cannot be searched by anyone, not the company nor the authorities, unless there is a credible criminal suspicion.
I think that would be crazy. When they end up being CSAM or whatever, you're the one that will go to prison for possessing them, not the person that sent them to you.
Sounds more to me that they are pulling up the ladder to impede competitors.
For public files, I fully agree with you. For private ones, not at all.
No it wouldn't. It would only scan photos you upload to their cloud.
"This feature only impacts users who have chosen to use iCloud Photos to store their photos. It does not impact users who have not chosen to use iCloud Photos. There is no impact to any other on-device data."
and
"Does this mean Apple is going to scan all the photos stored on my iPhone? No. By design, this feature only applies to photos that the user chooses to upload to iCloud Photos, and even then Apple only learns about accounts that are storing collections of known CSAM images, and only the images that match to known CSAM. The system does not work for users who have iCloud Photos disabled. This feature does not work on your private iPhone photo library on the device."
- https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
https://www.cbsnews.com/news/child-sexual-abuse-scans-apple-...
They were very much planning to scan all photos on the device independent of iCloud. It was going to be another phase of the rollout. It was going to be in iOS 15.x and they backpedaled.
Apple clearly documented that this was only for iCloud uploaded photos, and indeed the technical description makes clear that this is only designed to work with uploaded photos: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni....
Not sure why they would need to do that. It does open up your phone for scanning and uses beyond what they initially layout.
The whole point of the protocol (as described in the Apple whitepaper) is to allow clients to attest to perceptual hash matches without the server having access to the plaintext.
So, the irony of all of this is that the Apple design is effectively more private than the status quo, but everyone freaks out about it.
Apple's plan was to to scan photos that you uploaded to iCloud, only. Even that plan was canceled.
Google, however, still does scan everything in your account and has been doing so for the past decade.
For instance, this article from 2014:
>a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account
https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le...
Whether this is good or bad is a topic for fair debate, I think, but it continues to astound me both how little people are aware of this and that, in comparison, Apple's relatively privacy-preserving approach generated so much flak.
And you still need to scan local photos on the phone?
The only thing this adds to the threat model is mistrust for false positives in scanning engine - but in even the worst case scenario here (forged false positives), you're still ahead of the Google model, where the same forged false positives would be extremely likely to result in a full account review rather than review of specific images. Everything about "the device looking at your photos" is tinfoil hat, because the device is already looking at your photos, they're decrypted in RAM! All of the threat scenarios about "Apple adds a secret government backdoor that downloads your photos and sends them to the FBI" are already equally possible today!
The massive difference being that they would scan photos on my device. Not on the cloud. On my local device. How is that people consider that better?
The important bit is that Google does not currently have any capability to scan stuff on my phone. This is good. It's my stuff. They have no right to look at my stuff.
Apple proposed to implement tech that could scan stuff on my device, with a promise that they'll only do it when I am uploading stuff. Wait a few years, and some pressure from Authorotarian Government/Corporate Overlords and now the promise is just a promise that they can be easily removed and we can scan all stuff to make sure you're not stealing "content"/spreading "propoganda".
Apple's plan was to have your device conduct the scan and encrypt the scan results so not even they could see them until a threshold of ~30 image matches was reached.
This protects the user from false positives.
Once the 30 image threshold was crossed, the plan was to have a human review before turning someone into the authorities.
I think we all know that Google is not ever going to hire expensive human beings to supervise it's algorithms, so a single false positive would likely see you turned in for kiddie porn.
My point is that the difference between the approach from Google and Apple is that in one case (Google), we have a tech level blockage, it's not currently possible for Google to even do that.
On the other hand (Apple), the "blockage" is policy or "promise". That's far less reliable than the tech just not existing.
There is nothing stopping Google from inserting code to scan everything on your device. They can stick it into the binary blob of closed source Play Store code, and you would have no way of knowing it is there.
Google still does scan everything in your online account and has been doing so for the last decade.
Apple has backed down from even doing that for iCloud Photos.
CSAM opened the door to a conversation but we're a long way down the road to cloud backed storage being a gatekeeper not just a storage space. In my cloud or on my device, it's being looked at.
What's missing is arbitration via neutral mediator. The contracts are written to favour the provider. Automated reasoning of your breach and the abysmal restitution process is bad, but we're also a lot further down that road than people think. The "help by public shaming" here is not a solution at scale.
I pay for Google "one" and my hope is that excluding frank breach of the terms, paying them gives me one small extra edge in the "why did that happen and how do we fix it" space. I have found with ad spend, being a customer changes the relationship compared to free service. So.. there's hope. Probably misplaced.
We would subscribe to updates to a CSAM scanning corpus which would parameterize the scan. The whole thing requires "trusting the client" but I bet there are ways to make it work. If it would defuse this movement toward total black box checking of content, then I think it's worth it to voluntarily do this kind of scan. The effectiveness presumes that the intersection of child porn consumers and users sophisticated enough to disable a scan like the one I'm imagining is very small.
> to voluntarily run a CSAM scan on our systems
The results of such a scan are meaningless to anybody who doesn't control the computer that performed the scan. If these results are to be trusted by authorities, that implies that we no longer control the computers that you are describing as "our systems".
> nuetral arbiter (ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine".
Wait, wait, wait. So the response to finding suspected CSAM would be to make a copy of it, then to deliver that copy TO OTHER PEOPLE OVER THE INTERNET!? Every single study about Facebook's CSAM reviewers shows it to be an emotionally damaging job, because you're constantly shown psychologically damaging material. With that in mind, who do you think would volunteer to be on such a review board?
> We would subscribe to updates to a CSAM scanning corpus
This introduces an unnecessary failure mode to devices whose core functionality does not require internet access. If I have a digital camera, a tv, or a picture frame, those fundamentally do not require internet access. Given the prevalence of targeted advertising and surveillance of customers, any device requesting internet access should be viewed with immediate suspicion.
> The whole thing requires "trusting the client" but I bet there are ways to make it work
There aren't. There really, really aren't. You can only trust computers that you control, or that are controlled by people that you trust. Trying to implement these leads to obscenities such as the Clipper Chip, Sony's rootkit, ring-0 DRM, and so on. Every single one takes control of the computer away from the owner and gives it to somebody else.
> defuse this movement toward total black box checking of content
Your suggestions would require implementing a black box checking of content, running on my computer, and not under my control. Calling it "voluntary" in the sales pitch makes it useless, because the person who controls the computer can disable any reports from it.
> presumes that the intersection of child porn consumers and users sophisticated enough to disable a scan like the one I'm imagining is very small
The size of the intersection doesn't matter, because only a single person needs to write a script that disables the scan. In addition, if a scan requires sophistication to disable, that implies that it is an opt-in scan, and that goes against your sales pitch as "voluntary".
And even then it won't work. Video games are a great example: a lot of annoyance is caused by cheaters. Games have been ruined by cheaters. And yet there exists no solution that gets rid of them. Even LAN tournaments in CSGO have had an aim botter at a high level. The hardware they use is provided on location, but the players bring their own mouse and keyboard. In the case of CSGO the mouse had an aim bot on it.
How does someone who doesn't know me determine that it's my kids in the bathtub? (The answer can't be "you have to submit other pictures of your kids" because if I can get pictures of random kids in a bathtub, I can probably get other pictures of said kids.)
The only change here is end-users will be explicitly notified (and can theoretically contest the decision).
One of the terms included in its abuse policies is "hate speech." This is an extraordinarily ambiguous word which can virtually apply to any speech that is critical of anything. It is a term that has come to be known, by some of us, as a tool the political left uses to censor dissent. For example, saying that a man is a man and a woman is a woman can be considered hate speech against the trans community.
This move is part of a larger trend. Some people see it. Others don't.
"Put a sock in it, ya wanker." -- You in 1775, probably.
If you can't understand why this is the case, then I'm sorry for your lack of critical thinking.
That second part I consider close to critical thinking and it seems to be what people does.
https://web.archive.org/web/20141222190112/https://support.g...
Again, none of this is new. People have been abusing Drive to host illegal file for years, and have been getting banned for it. The only change is that now you get a notification and can dispute it. It's a strict improvement.
To the writer this was incomprehensible because she couldn't understand that any of her files could even be close to violating anything.
I am already seriously considering discontinuing my subscriptions of their storage services, and this post about restricting files doesn't give me comfort.
Moving off Gmail is likely impossible for most non-technical folks.
The effort is only one time or one day at max. And the rewards are worth the time.
I just keep the old GMail for now, and whenever I receive a valid email there, I visit the sender website to update it.
This depends on you remembering your "low-volume important accounts" like government websites you visit once a year, but otherwise, I would not cry if my imgur account got lost or something eventually.
Edit: Looks like LastPass does it with a screen scraper https://support.logmeininc.com/lastpass/help/how-do-i-update...
For a non-technical user (like my mom), this is a herculean task.
Over time, the old gmail account will lose its importance, and there'll be no real risk if Google decides to ban it.
Companies like Google would be required to provide a basic service to basically everyone and are required to go through a court before suspending accounts (or maybe just some core features).
On one hand it would enshrine their position in the market, on the other hand it would remove some of their ability to make arbitrary decisions with no recourse and no information why it hapended.
At least in the UK utilities such as electric or gas only need to go to court to get a warrant to access your property to physically disconnect you - I do not believe the court process is about the disconnection itself, but rather the physical access to your home to physically cut you off.
For a digital service they'd just cut you off without needing a warrant to access your home.
But anyway, public utilities need to be paid for - I can't imagine people being too pleased to suddenly need to start paying for things like email or search (Google or otherwise).
That would probably involve payment but not prevent others from entering the market.
Where I am located there is one designated electricity provider who must service everyone (and is usually more expensive). People are free to switch if they want.
I feel like the free market is not doing particularly well in basic digital services like file storage or communication. While there is some competition on price, all providers reserve themselves the right to cut you off for no reason at all without due process. Their rules are intransparent and are inforced by dependent employees.
The only change now is that the file gets unshared, you get a notification, and can try to dispute the claim. This is a strict improvement.
Google is a consumer hostile company at this point. Unless you have a friend with pull there, or make it a big enough news issue, the little things are treated with automated hostility.
Google isn't alone here, it's the result of very large companies being under regulated on the consumer side.
"...you must not even try to do any of the following ...: ...
- publish, share, or store materials that constitute child sexually exploitative material (including material which may not be illegal child sexual abuse material but which nonetheless sexually exploits or promotes the sexual exploitation of minors), unlawful pornography, or are otherwise indecent;
- publish, share, or store content that contains or promotes extreme acts of violence or terrorist activity, including terror propaganda;
- advocate bigotry or hatred against any person or group of people based on their race, religion, ethnicity, sex, gender identity, sexual orientation, disability, or impairment;
...
We reserve the right to take appropriate action in response to violations of this policy, which could include removing or disabling access to content, suspending a user’s access to the Services, or terminating an account."
Quoting from their privacy FAQ:
"Examples of Dropbox processing your data in furtherance of its legitimate interests in operating our Services and business include:
...
- Investigating and preventing security issues and abuse of the Dropbox Services or Dropbox users."
I’d like some balance because I don’t want Google and Dropbox to suck as much as my power and phone company. But do want some regulation around lack of due process and “bundling” where a YouTube comment can result in my GCP account shut down.
We build roads; yes, those roads might be used to transport stolen goods but the road builder doesn’t get to sit there and inspect every vehicle (and accuse the wrong people sometimes and ban them from driving).
It’s just so damned complicated now and I don’t know how it got that way.
Use of these consumer-grade cloud services comes with pitfalls. I see no utility in pretending that alternatives don't exist though, because they're pretty abundant.
Can you though? I would consider AWS "in the cloud" yet they will give you the boot if they disagree with you morally[0]. Same with Cloudflare[1].
So it seems even infrastructure-level cloud offerings are prone to moral arbitration. Hosting on your own hardware is the only option, but even then... I don't see any reason twitter mobs couldn't pressure Comcast or whoever is connecting your hardware to the internet to cut you off.
[0] https://telecoms.com/508138/aws-banning-of-parler-exposes-th...
[1] https://blog.cloudflare.com/why-we-terminated-daily-stormer/
But this is probably not your best bet.
I don't think this is accurate. They pretty much only ban you if you're exposing them to legal liability.
https://arstechnica.com/tech-policy/2013/02/heres-what-an-ac...
I also don't think you would be arguing that people bothered about WhatsApp or iOS tracking them should just create their own messaging app or mobile OS. The vast majority of software is not just difficult do yourself, but almost completely infeasible. In fact it's hard to even think of any software I use regularly which I as a experienced software engineer could easily build myself, let alone an average user concerned about this stuff...
You're totally right. Depending on one's standards and expertise, yes, there are alternatives to the mainstream dumping grounds for your files.
The most basic is to just store files on external drives. This is what I do because, most of the time, I'm not actively sharing or using all my photos and downloads. I've scattered them between drives for well over a decade and only had a problem when one of my magnetic drives began to fail, but I ended up not losing anything. Even if I lost all my photos and stuff I really wouldn't care that much. That's why I can't be arsed to trust The Google or Zuckerborg or whomever with my files or using Dropbox. I'm more likely to wake up one day to be hard locked out of all my Google accounts than to lose anything meaningful because of physical on-premises storage.
There's also network drives, and plenty of off-the-shelf ones exist. My parents have one and it's exactly what you'd think; a device with a ton of storage that's accessible through a Dropbox-like web interface.
And if you're really geeky, you can hack together a way to shove files into S3 or whatever storage service of choice.
Yes, the average person won't have the motivation or wherewithal to do anything besides my first option, but that's really the kind of thing you'll always get by being average.
And obviously those who believe they need all the bells and whistles of Dropbox or Google Drive may also believe there are no practical alternatives outside of Silicon Valley Big Tech, in which case it's entirely up to them how comfortable they are with that. Personally, I would rather rely on services as little as possible.
You can, I can (actually, I run my own file servers, even better).
Average person can't (won't even be aware they should). We could say let's educate people (yes, let's). But really, infrastructure should be neutrally available to everyone like roads or the old POTS network.
It can only be achieved through regulation, since these companies will always be self-serving at every step otherwise.
Only because you chose the wrong solution. ;-)
Look at Tresorit[1] instead.
It’s because cloud should have been just custodianship of the data in order to funnel it into their application but it was all too easy for these companies to want to profit further by prying on the data, monetising the data, curating the data and ultimately taking control away from the owner of the data.
This includes files that are identified as: CSAM, Circumvention, Dangerous and Illegal Activities, Harassment, Bullying, Hate Speech, Misleading Content, Spam, Violent Organizations and Movements, and more.
Google further notes they "may make exceptions based on artistic, educational, documentary, or scientific considerations, or where there are other substantial benefits to the public from not taking action on the content."
Obviously it can be easily defeated with encryption / changing the metadata, but it's so easy to implement I'm shocked they didn't do it earlier.
Google drive is commonly used for a backup of media or even a host of media when using rclone.
Many, many pre-sales conversations are now focused on whether or not we hash files or keep databases of file hashes, etc. Do we collude with other cloud providers to report file incidence. Or, for people who really have no idea who they are talking to "which cloud do (you) run on top of".
This was not the case before. I think the advent of 'rclone'[2] has created a lot of use-cases that very efficiently use (cheap online drives) and all the kids are storing their warez with it.
Yes, trivially easy to defeat with encryption and rclone has a very nice and simple workflow for this.
[1] You know who we are.
What's new is that customers with paid accounts are going to be notified when their content has been restricted from sharing. Before this change it was silent from the user's perspective.
https://www.bleepingcomputer.com/news/technology/amazon-aws-...
https://www.techzine.eu/news/infrastructure/57005/ovh-share-...
(A) it's a usable interface accessible by pretty much anyone [with a phone number, as of recent]
(B) it's cheap as you don't pay for bandwidth and storage is either $0 for 15GB or paid storage at a low-priced rate[0]
(C) all of that storage is geo-redundant and thus extremely unlikely to ever be lost, outside of Google terminating accounts (which isn't part of a lot of people's risk models).
- google reads all your files
- google judges your files
- google has a set of opaque, arbitrary, ever changing list of things that can turn your files into a reason for locking you out
So, basically: s/your files/their files
Any cloud service can change their Terms of Service without notice, and those changes are almost always detrimental to customers.
Seriously, move your saved data in-house. Cloud drives are for ignorant consumers.
Regular users need something that just works instantly and never needs maintenance. If it doesn’t just work it’s broken.
Or you could just choose a provider who respected your privacy and had a very long history of standing for freedom of speech and the rights of users.
If only such a provider existed.
If only ...
- I wonder how long it would take for your Workspace account to get shutdown if you have 10 users sending mass document invitation? - If a file is blocked from sharing, can i duplicate and re-share?
Does anyone use the service MEGA?
As with many topics, this should be self evident to many HN readers, but I doubt it is obvious to most users of Google Drive.
Syncthing is also another great option. A little more setup, a little more control, significantly less trusting.
So this isn't general Drive, only the paid for version? ie to prevent businesses from having employees with these files on their company Drive?
same prediction as always, moderation is an ecosystem that requires transparent enforcement and dispute processes.
new moderation norms will bend the economics of social media towards the reddit model: small communities, moderation primarily provided by 'community owner'.
Platforms provide a layer cake of less frequent 'nuclear option' bans on top of that -- platforms deplatforming communities so their host doesn't deplatform them.
Which is to say, the problem is organizations using storage.googleapis.com URLs, not organizations blocking them. And probably Google should be doing a better job policing content on their content domains if they don't want them to be blocked by default.
(Similarly, all Chrome Web Store extensions should be blocked by default, with an allowlist for requested and vetted ones... there's simply too much malware to default to anything else.)
I'd love to block Google Drive by default too, but there is enough legitimate use that at present that would cause too many false positives, and it's a balancing act.
Blocking this domain definitely isn't common, at least not in large organizations. Several of my company's B2B apps use Google Cloud Storage (it's just Google Cloud's version of S3) and have always used storage.googleapis.com/bucketname rather than bucketname.storage.googleapis.com. (AFAIK it was the default URL format shown in their documentation when I last looked at it years ago.)
We've had to deal with overzealous corporate web filters now and then - comes with the territory of B2B apps - but I've never heard of storage.googleapis.com being blocked. It'd be pretty straightforward for us to change it if a customer had trouble, but we'd probably gently push back and ask them to whitelist the domain before doing so.
I'd be comfortable whitelisting a bucket subdomain, but as I said, it's only come up once, so we worked around it the one time. And I've blocked a lot of phishing sites this way. I'd highly recommend large organizations follow suit. :)
If my organization is likely enough to be targeted intentionally, the chance of having an attack directly solely at my organization (and hence, likely a URL not found by other parties already) is much higher as well.
What would be a good collaborative platform for creative writing?
- your business secrets
- GDPR data that you legitimately have
This is exactly why I do not use Google Drive for anything business critical.
Depending on your jurisdiction, small claim courts can actually shut down the binding arbitration clause.
In Canada, Google had a long history of losing by defaults in small claims
And be blacklisted from using Google products and services.