Google seems to have signed me up for Google Pay without asking
twitter.com
twitter.com
If you give a company your information in one department, another department will invariably use it. See also: Facebook using the phone number you put in for 2FA for targeted marketing [1].
[1] https://techcrunch.com/2018/09/27/yes-facebook-is-using-your...
> The old "don't be evil" Google wouldn't have done this.
What's the "old" Google? You mean like Google Latitude, circa 2009? [2] [3]
[2] https://www.computerworld.com/article/2530951/privacy-group-...
[3] https://www.nytimes.com/2011/03/22/technology/22privacy.html
I am avid DDG user and advocate ever since realizing wow Google stomps on all the dreamers it inspired.
My point is Google's motto/PR was "Don't Be Evil," and that was just a ruse and her experience helps prove that as well prompts users to be disenchanted by them who also were sold and bought that same crap.
Further I am more then happy to tell my story and more importantly her story with evidence to warn those who have Google's stars in their eyes to demand millions before taking a meeting!
The combined amount of fines across all companies over the GDPR's entire 4-year lifespan is just 1Bn.
If the lower don't suffice, we will get closer & closer to the maximum.
So, for a one-person startup, €20M means game over.
Fines may deter small and medium-sized corporations, but not large ones. Therefore something else might. Like prison.
[1] https://www.privacyaffairs.com/gdpr-fines/
[2] https://www.statista.com/statistics/507742/alphabet-annual-g...
I'm also all for throwing C levels in jail ALONG WITH the board as well. They want to benefit and sign off on choices of the company? They can also hold said responsibility on illegal stuff.
Ostensibly, so is Google Pay. And yet here we are. See also, from the third link in my previous post:
> And the privacy watchdog said users of Latitude were not informed that Google tracked their movements to enhance its database of Wi-Fi information.
> And the privacy watchdog said users of Latitude were not informed that Google tracked their movements to enhance its database of Wi-Fi information
This looks like they are confusing two different things (Latitude and Location Services, though maybe Latitude required Location Services to be enabled). Are iOS users warned that getting their location on iOS at all is used to enhance Apple's database of Wi-Fi information? The difference is that on Android, this is opt out with an explicit prompt at device setup, and on iOS, you can't even opt out. Which is more evil? https://news.ycombinator.com/item?id=21708157
The Google Latitude case also resulted in an actual fine levied. Your stance is that this fine was all because the regulatory body "was confused"?
It was absolutely for nonconsensual data collection. From the very link that you provided:
> The CNIL held that since it was carried out without the knowledge of the data subjects, the collection of data using the “Google Cars” or the mobile phones of “Google Latitude” users was carried out unfairly and therefore in breach of article 6.1° of the French data protection law.
> In order to implement this service, the company used the same vehicles used for “Google Street View” – the “Google Cars”, equipped with 360° cameras and sensors to enable different types of data to be collected.
If there were any nonconsensual data collection in Latitude, you would expect to see other fines or Google changing the service. Neither happened. On the other hand, there were other fines for Wi-Fi data collection from the Street View cars, and Google did make fixes to it in response.
I will post the quotation one more time:
> The CNIL held that since it was carried out without the knowledge of the data subjects, the collection of data using the “Google Cars” or the mobile phones of “Google Latitude” users was carried out unfairly and therefore in breach of article 6.1° of the French data protection law.
Notice the whole "or the mobile phones" section, which comes after the Google Cars section which you are pretending is the only pertinent section?
Edit: I can't respond because you've made this thread too long. Once again, reread the numbered claims that CNIL brought against Google. None of your quotes are supported by the claims. (Technically, you're misinterpreting the first quote in your comment below, which is about data collected for Latitude, not data collected by Latitude. To avoid making mistakes of interpreting the author's interpretation, simply read the numbered claims.)
This is clearly explained, multiple times, in the article that you yourself linked to:
> This time, the CNIL decision, dated 17 March 2011, concerns data collected for the implementation of the “Google Latitude” service, which enables geolocation of users that have a Google account and a “smartphone”.
> The users’ phones themselves since they are used for the purposes of geolocation.
If you are claiming that no phone data was collected, then how do you explain this quotation which I have now quoted three times:
>>> The CNIL held that since it was carried out without the knowledge of the data subjects, the collection of data using the “Google Cars” or the mobile phones of “Google Latitude” users was carried out unfairly and therefore in breach of article 6.1° of the French data protection law.
I think the confusion here is around having a payments profiles and Google Pay. Looks like we started calling your payments profile now having a "Google Pay account".
There is Google Pay (the app for tap-and-pay, along with P2P payments), then there is having a Payments Profile (which apparently we're now calling Google Pay, because that's not confusing), which you use for buying things on Google's properties.
There used to be a https://payments.google.com but that just redirects to https://pay.google.com/. This is your payments profile. As far as I understand, when you added a card for chrome autofill, it would create a payments profile, as the card was stored as part of that system. The support docs say something like this: https://support.google.com/chrome/answer/142893?hl=en
> When you’re signed in to Chrome and you enter your payment method into an online form, Chrome may ask if you want to save your payment info in Google Pay. If you accept, your payment information is saved in Google Pay. If Google Pay doesn’t support your payment method, Chrome may offer to save it locally on your device.
The Google Pay app (used for Tap-And-Pay) has its own activation process for being able to use a card, as it requires a 2FA process (depending on your bank).
Even though I had (somewhere, somehow) entered multiple cards into one of these google payment systems previously, none of them were actually usable for "tap to pay" purposes. I never cared about this fact because I have a Garmin watch which implements its own tap to pay.
It turns out that Lyft required that I have a "tap to pay" account set up. Upon requesting a ride, I received an error stating that none of my existing Google Pay methods were valid. The only thing I could do at that point was to register one of the cards that Google already had on file for "tap to pay," which in turn required that I complete the provider MFA enrollment process.
This meant that I had to sit on hold for 10 minutes and give them some personal information before I was even able to request a ride with Lyft. Which sucked, because I was tired and wanted to get home.
The UX was completely terrible here. I don't know if Uber would've been the same way, but I want to nope right out of this entire stupid ecosystem.
I think this is done as a way to do "in app" purchases that don't flow through Google. Tap-to-pay cards are effectively single use (due to the cryptogram that gets passed with it), it won't store the card with Lyft.
The other way Google does integration with 3rd parties is the "Pay with Google" button on websites, that will vault your card on file at Google into stripe or braintree, then the merchant can use that for a transaction.
Both of these methods move the liability of the payment onto the merchant (Lyft in this case).
chrome://flags/#enable-autofill-credit-card-upload
"Enables a new option to upload credit cards to Google Payments for sync to all Chrome devices. – Mac, Windows, Linux, Chrome OS, Android, Fuchsia"
They've really ramped up the "Google" in Google Chrome these last few years. The "save payment" nag box was annoying before, now I'd move it firmly into the dark pattern region, as it attempts to convince you to move your payment into their payment services not just saved locally.
The fact that there is no "never ask me again" option for that save payment dialog seems like nefarious UI 101. How could a billion dollar company make such a rudimentary UI mistake in a flagship product? Well, they probably didn't make a mistake, they're just getting worse as a company.
Meanwhile, I am blocked from reading any more of that twitter thread by the uncloseable twitter sign up nag screen. What an antagonistic web!
Ironically, this may be what finally drives me back to Firefox!
Chrome does have a built in "log in" screen, but I guess websites are embedding one similar enough that it confused me.
Weird... do they offer this to everyone, or do they have tracking that lets them know i'm logged into google?
I see it on media/news sites, among other places.
I bet that's where his "signup" came from - although every time I want to add a card to Google Pay on phone/watch I need to go through a tedious signup process involving my bank and SMS tokens, so I find this tweet very suspect.
Apple does the same thing.
I'm in the EU though, I'm not sure what it's like in the US.
The tweet is a little bit weird too because he assumes its because he used a card somewhere and makes it seem like his card was added to Google pay which can't automatically happen..
"Google Pay" is also the name of the peer-to-peer transfer service Google has (had?) which accepts debit and credit cards and allows you to pay others. This only uses standard address verification.
"Google Pay" is also the name of the payment processing service Google uses for their own services, like the Play Store. Adding a card here also only uses standard address verification.
Data is shared between these three systems. If you have already registered cards with 2/3, they will be pre-populated when you try and add a new tap-to-pay card, and at that point you do the SMS verification.
>Data is shared between these three systems.
I understand the point you're making, but if the three systems share the same name, and they all share data between themselves, then for all intents and purposes it's one system.
Whether it's considered one or multiple systems is a pedantic opinion that will depend on the person and doesn't really change the core point I'm making.
> A month ago I was asked in a surprise email to verify my age for YouTube with a credit card, which I did to avoid landing in support hell later on, because I publish browser extensions with the Google account.
> I rarely log in, and I wasn't using the Google account at the time the email was sent, nor do I ever use the attached YouTube account. The card was saved in Google Payments without my consent.
> I live in the EU. Their support page mentions that they will ask for age verification when you attempt to watch a restricted video, but I was not using the YouTube account.
> https://support.google.com/youtube/answer/10070779
> Then there's also the question of creating a payment profile for the user without consent.
> > If you enter your credit card info for age verification, Google will retain this data as necessary to meet legal and regulatory requirements.
> https://support.google.com/accounts?p=age-verify
> Meeting legal requirements is very different from saving your card in Google Payments, which then you can readily use to buy products in any Google service.
They are hopelessly deceptive, and will not shy away from breaking the law every step of the way just to prop up other Google services.
He left Google in 2006 to join Facebook.
I like the idea of Zelle, owned by the banks, no fees, no spam, instant - but ripe with fraud, so I don't feel fully comfortable having aging family members enable it. You cannot increase or decrease your send limit either. Complete shit. It's all automated, of course it should be possible to set a limit.
Google Pay keeps changing. I hate it because it's inconsistent and thus not trustworthy that I'll have anything like the same functionality today, tomorrow.
Paypal and Venmo are really the same company, and I long ago lost respect for Paypal. Venmo is worse because it adds social media on top of Paypal. So those are out.
Apple might have the best pay app now except it's iOS only and thus I think it's shit, because I value interoperability.
2 Billion DAUs is an insanely larger number of users and I hardly know anyone who is using Facebook much anymore. Surely that's anecdotal and there are parts of the world where FB is the gateway to the Internet.
Just so we're on the same page, I have to assume that'd be the Google that predates Buzz auto-populating your contacts from Gmail, which resulted in people being "Buzz friends" with abusive ex's and other folk that people will do business email with but don't want social conversations with.
So, pre-2010 Google.
I wonder how much they’ve made in finance charges from customers who were tricked into using this card this way.
I have added my card via the play store, but now my chrome tries to auto-populate the credit card number. I'm pretty unhappy with it, since I don't want that information in google chrome.
(Sounds like the same thing, they share the data between all of the services, which doesn't feel great when the data they're freely sharing is credit card info.)
I didn't appreciate finding out that Google had my passwords...
I am actually very hopeful for the next generation of hackers building things.
Cracks are starting to show in the massive walls of these large organizations.
I have a feeling soon we are going to have the next generation of wonderful companies and technologies and they won't be Google et al.
Apple still seem to be able to pull of great things such as the M1 but I wonder how much of that is TMSC.
Great time to be a venture capitalist who understands hackers.
> Surprised when he has an account on google’s payment product y
How is this evil? There is literally zero negative outcomes from this.
Edit:
> How is this evil? There is literally zero negative outcomes from this.
I like to think of every online account as a liability, because any one of them can be compromised and cause me a bunch of headaches. The "level" of headache depends on how much information each service has about me. What gives Google the right to expose me to more risk in this way?
If you type your cc info into vscode with your msft account logged in and a sync option enabled then you also shouldn't be surprised if you found it into your msft account.
That Google appears to be so cavalier about this is a serious, but unsurprising, thing. I don't think I'd call it "evil", though, so much as "abusive".
In storing card data in product x, the assumption of the user would be that that product is storing that card data for future autofill purposes in product x
Discovering that this data has somehow been turned into an entire financial account on product y without consent should enrage any reasonable user of product x
It seems like what happened is Chrome used a special backend for storing credit card info associated with your Google account, and this Google Payment product now literally just became the interface that let's you manage your credit card information that was already associated with your entire Google account across all Google products.
I think if there was "leakage" it happened some point earlier than this: the user thought they were storing an credit autocomplete in Chrome but actually they were storing credit card info associated generically with their Google account, and eg was already linked to Play Store for purchases. The fact that the spot where you go to manage the "Google account associated credit card info" is accounts.google.com or payments.google.com seems pretty irrelevant here.