You can now ask Google to remove your phone number, email or address from search
krebsonsecurity.com
krebsonsecurity.com
I have yet to reach a page where I can submit the URLs to be removed. I consider myself a neophyte technologist, since I just started a few decades ago with punch cards. I doubt most of the general public will figure out how to perform this process.
I will give some grace, and come back in a month.
Internet literacy is probably unrelated to punch card literacy.
I followed the link in the article (from kreb) to the google blog post announcing it:
https://blog.google/products/search/new-options-for-removing...
That linked to this form:
https://support.google.com/websearch/troubleshooter/9685456?...
First you tell them what the info it (eg address Pcture SSN etc). Assuming it matches what is in the announcements as a supported type, you get an inline form asking for your name/email, then a URL to the offending site(s), query terms on google search that yield the site(s), and then optionally screenshots of the content.
After, you click a button saying you’re legally the person you’re saying you are. I don’t have data to submit in the form so i don’t know what happens next but it looks like the end. Are you sure you didn’t just submit a successful request and they redirected you to the landing page?
Disclosure: I work at G but didn’t know this existed until I heard from Kreb.
The parent commenter was using self-deprecating "humor", which I understand can be confusing for Lumon Industries innies. Your outie will appreciate it!
There's a lot of personal info we'll remove such as images of minors, involuntary fake pornography and other issues as outlined here: https://support.google.com/websearch/troubleshooter/3111061
Our announcement this week was about an expansion of removing personally identifying information -- PII -- (such as email addresses, physical addresses, phone numbers, etc),. This is the page that explains in more detail and where people should begin the removal process: https://support.google.com/websearch/answer/9673730
The removal process will lead you to a troubleshooter. That's designed to help people more quickly get things resolved. For example, if a web page no longer exists on the web, or the site owner removed info, there are faster options you can use rather than going down the formal removal request option.
But let's say you want something removed that has PII from a page that's live on the web and where you for whatever reason don't want to contact the site owner. The troubleshooter from that page I mentioned will lead you here: https://support.google.com/websearch/troubleshooter/9685456#...
Say No to contacting the site owner, select Personal Info from the next option, pick the type of info and you'll get to the form (such as here if it involves contact info): https://support.google.com/websearch/troubleshooter/9685456#...
That's where you enter the info. Appreciate the feedback that we should look at how to improve this more -- that said, the troubleshooter itself isn't new, and people have used it to successfully remove information beyond our recent expansion. But we'll see how to make it better.
I found that a usability expert can come handy.
Like why not offer tools to make it easy to submit “here’s my phone number - delist it” or “here’s my name and all addresses I’ve lived - delist”and then you use Google’s awesome search and AI capabilities to figure that out. Then facilitate disputes between site owners and individuals. But forcing me to scan the internet looking for things that other malicious crawlers are finding. That’s not user friendly I think (in addition that finding this needs someone on the team to explain it on HN, one of the most technical sites on the world).
It’s like the Douglas Adam’s joke from Hitchhikers (going from memory so I’m sure I’m butchering it): “but we published the plans to destroy the Earth in the center of the next galaxy in the 100th underground floor of the administrative building in the filing cabinet in the locked room guarded by man eating lions.”
To kill off the root cause, Google could feed peoples privacy data into the SSO ranking. Websites with a lot of privacy data get a lower SSO. This cripples the business and with it, your business.
Just a hypothetical, I wish all the best for DeleteMe. I'm checking out optery.com right now and will check DeleteMe next.
"Don't be evil" I think may still be true and may actionably translate to "Don't sell user data _directly_"
> “But the plans were on display…”
> “On display? I eventually had to go down to the cellar to find them.”
> “That’s the display department.”
> “With a flashlight.”
> “Ah, well, the lights had probably gone.”
> “So had the stairs.”
> “But look, you found the notice, didn’t you?”
> “Yes,” said Arthur, “yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard.”
The quote about the destruction of Earth is:
>‘There’s no point acting all surprised about it. All the planning charts and demolition orders have been on display in your local planning department in Alpha Centauri for fifty of your Earth years, so you’ve had plenty of time to lodge any formal complaint and it’s far too late to start making a fuss about it now.’
> ‘What do you mean you’ve never been to Alpha Centauri? For heaven’s sake mankind, it’s only four light years away you know. I’m sorry, but if you can’t be bothered to take an interest in local affairs that’s your own lookout.
> ‘I don’t know’ said the voice on the PA, ‘apathetic bloody planet, I’ve no sympathy at all.’
Disclosure, I work at Google, but not on anything related to this, so I'm just speculating.
I found google hits listing it as a german number, italian number, swedish number and more. Clearly not all of these are "my number" even if it's the same number. It's not reasonable that those pages are all delisted, is it?
The instruction is: "Please enter one query term per line (max 10000 lines)"
How do you protect someone filing fake requests to hide another person or personal business from being findable, to damage them? How do you prevent abuse?
This isn’t a binary issue. Removing data from Google will usually have 90 % of the effect of removing it everywhere.
The amount of hoops you need to jump through to protect your privacy / shield your address in the US is quite incredible. And if you don't do it correctly from the start (use an anonymous land trust, etc), you're hosed.
Privacy should be the default. People's home addresses shouldn't be public info
The U.S. has a decentralized land registration system. The downside is it usually cannot provide indefeasible title [1]. The upside is it's tremendously robust. That robustness comes, in part, from publicly-verifiable records.
> People's home addresses shouldn't be public info
Confidential property ownership has its own issues.
It's less stable. In the event of a dispute you only have the registrar's and disputing owners' records to consult. It's also associated with embezzlement, money laundering and tax fraud. (The set of societies where a public home address puts one at risk and the set that have problems with embezzlement and laundering overlap in their institutional weakness.)
(For tenants, on the other hand, there are fewer compelling reasons to publish residence.)
[1] https://en.wikipedia.org/wiki/Torrens_title#Indefeasibility_...
My post-lobotomy view of privacy is all my secrets are known to the people I hate the absolute most ("I hate them with perfect hatred // I call them mine enemies" PSALMS KJV), and while I thank them as enemies (Matthew KJV) I do not forgive them, the intention is someday they thank me in return, as the Christians they claim to be, for acting against them as an enemy.
So then, what is privacy? If you're lobotomized, privacy is divulgation. I cannot erase my lobotomist's memory, and I cannot recollect all my own selfsame memories, so instead I divulge, and divulging is privacy.
Understand this: privacy is about who knows what. Who do you want to know what? Some options are out of the question for me. After all, there is a condition right on the box of all cryptographic products, in this case especially 1Password which I used before, during, and after my lobotomy, which is this: cryptography is about forcing the government to torture you. Not just the government though! If you get tortured? Forget it! Warranty void!
Well so then what? Nobody asks, OK so I get tortured, THEN WHAT? ANSWER ME! And I think I'm supposed to not be able to see the answer, I've been conditioned to avert my attention to the answer, not see the ads for the answer like fucking literal pathological banner blindness. So many ads I wanted so badly to see, I just couldn't see. The most targeted advertising, missing completely. Like it's invisible to me, I read the statute in the Federal Codes about torture, how it was defined, and I simply couldn't read the lawyer's advertising with a phone number to call them.
So privacy? Before torture, divulging works against privacy. After torture, it works in its favor.
I had to deal with a stalker at one point and found over 100 of such sites, it took me a few days to opt out of all of them (and some ignored my requests).
Data brokers are total scum.
Not to mention that this Google effort requires an explicit threat to be made on the page in question. They won't remove data broker pages, you have to contact each on individually and hope they'll actually fulfill your request.
But my solution to that is to use a burner credit card number! Specifically from privacy.com. I just make a new card with a limit of $20 to ensure it can't be billed again next month. I should of course just cancel the subscription, but if I forget they can't charge me next month anyway. I highly recommend privacy.com or other burner card services.
I haven’t used it yet, and it feels rough around the edges. I donated however and talked to their founder and I think this model fits better than a commercial one. The way it’s built you don’t actually share any data with them. They essentially provide templates to make erasure requests and follow-ups easier.
Was just with someone for the past few months who said all their relatives passed due to a horrific car accident and they would talk a lot about saying how much they missed them and are alone; have no one. Ummm they are all alive and well.. there was no horrific accident and she is just a crazy manipulator... gain sympathy to get whatever she wanted (toxic ... gross.. go away) ... Amber Heard type.
thanks SearchPeopleFree.com for letting me learn and move on quickly!
Apparently they've always had a process for bank account info and other related things, but I can't get some of the newly included items, like login credentials, removed unless I can show actual or implicit threats of harm?
IMO there should be as few barriers to entry as possible with something like this.
And the only way to opt out of it is to not use credit cards.
Is it somehow OK for someone to build a dossier on another person as long as they use that information for their own purposes?
Source, please.
https://www.google.com/search?q=Google%20buys%2090%25%20of%2...
The "90%" might not be easily sourced, but also not the crux.
Making things easier to find can be a threat - it's why there's a lot of compelling discussion around websites that take rosters of arrest records and post them on big scary websites along with pictures and lurid descriptions of the person's crime - offering to remove the information for a fee.
The US needs a GDPR-equivalent law.
It seems you're misreading the policy. See my comment above [1].
There is NO requirement of threat to remove anything listed as personally identifiable information on this page (such as personal contact info, medical records, login credentials, etc): https://support.google.com/websearch/answer/9673730
Beyond those things listed, in some cases someone who is being threatened might feel there's additional information that someone might feel is somehow personally identifying. This is where the doxxing/threat option can be used, for something not on the list where no threat is required.
Appreciate this is confusing to some; we'll be looking at how to clarify that.
Content on or from government and other official sources Newsworthy content Professionally-relevant content"
1. This removal process does not remove those public information aggregator sites, like "Who lives here.whatever", "Didthispersoneverappearincourt.com". The problem with the court aggregator sites is they are wrong some times. I imagine Google makes a ton of money off them though?
2. Google should remove all personal details, unless a person was in the news.
3. I'm on the fence whether you should even index sites like Yelp.com?
1) Remove personal info, which includes things like email address, phone number, physical address. You can ask those be remove; no proof of threat is required.
2) Remove doxxing content, where there's anything you might consider to be contact info that's not covered in the policy above and which is linked to a threat.
It is not.
From the form [1]: "...that has POTENTIAL to create significant risks of identity theft, financial fraud, harmful direct contact, or other specific harms..." (emphasis mine).
The requirements section states that you may request removal due to the page having "personally identifiable info" OR doxxing content "used in implicit or explicit threats".
Now, there's exceptions to this (e.g. public records, newsworthy content), but nowhere it says you have to receive threats first before requesting removal.
disclaimer: Googler, but no relationship with the team, and have no other knowledge of this policy other reading the public blog post.
>... nowhere it says you have to receive threats first before requesting removal.
Oh come on now, this is taken directly from your link:
>Requirements to remove doxxing content
>For us to consider the content for removal, it must meet both of these requirements:
>1. Your contact info is present.
>2. There’s the presence of:
>- Explicit or implicit threats, or
>- Explicit or implicit calls to action for others to harm or harass.
So, yes. To remove doxxing content, you are required to show proof of explicit or implicit threats.
If you think about it, the way the requirements are set up are pretty damn backwards. Are you just requesting your personal info to be removed just for the sake of having it removed? Sure, as long as it's your CC/bank account/SSN/whatever else on that list, they'll remove it. But if you tell them you're being doxxed? Well fuck you, they won't just up and remove the data like they would've before, now you have to prove you're being targeted, too. It's like it'd be easier to have the doxxing content removed if you didn't tell them you're being doxxed.
It looks like the form has design errors that don't match the policy.
The other part of the form allows you to require removal just by stating that it has your "personally identifiable information". For example, the many sites offering background checks, your address history, etc.
I agree the form is confusing and should be simplified (i.e., the whole doxxing section seems redundant to me, and should be sub-bullets of the PII section), but OP's comment that you can only request removal after receiving threats is factually incorrect.
- Yes, the contact info is being shared with doxxing intent - No, the contact info is not being shared with doxxing intent"
The headline is extremely misleading.
This was not well reviewed.
Because the biggest hoop is that the data is not located in just one place. It's the internet, so the data is shared/duplicated as fast as it becomes available. You have no idea how many places it lives because not all places are available for public browsing. Some one buys it, then resells it ad nauseam.
Give me a break, especially the "googler" in this thread.
No. Just no. This is a 1.7 trillion dollar company. They can spend some of that money fixing the broken system they created, but they chose no. So no slack will be cut/granted from me to them.
>they just return everything you can type in right away.
No they don't. They return something that is most monetarily beneficial to them whether that is relevant to you or not.
Beyond those things listed, in some cases someone who is being threatened might feel there's additional information that someone might feel is somehow personally identifying. This is where the doxxing/threat option can be used, for something not on the list where no threat is required.
Appreciate this is confusing to some; we'll be looking at how to clarify that.
Really neat.
It probably came from resumes or something but still
Bing, on the other hand, was an absolute nightmare. After emailing for around a month with MSoft support, they claimed they removed content that was still showing up, and still is showing up to this day. This content doesn't even exist on the pages that Bing is showing excerpts from, and hasn't for around a year now. It became very clear to me that Bing had no effective process in place to carry out content removal requests, so I eventually gave up. Unfortunate, because alternative search engines like Ddgo and Brave show results from Bing, IIRC.
I guess you can't place all the blame on these sites. I also found out my state releases the entire registered voter database for anyone to download online, without any reason or identification required. So if you're a registered voter, it is possible that the information you provided to register is public and available online anyways. This includes full name, email, address, and phone number - if I remember correctly. It's been some time since I looked through the database though. I found my entire family within it, and it receives quarterly updates. I would not be surprised if the government was at least one primary source of information for PII scam sites in the first place.
The National Conference of State Legislatures breaks out a by-state view of what info is available and how it can be used [2]. There's another good article [3] doing a state-by-state analysis of voter file privacy. The public file should only contain: Name, address, year of birth. The following should be kept confidential: DL number, last 4 of SSN, month and day of birth, phone number, information that a person declined to register to vote, the office that received a registered voter's application, digitized signature.
[1] https://www.nbcnews.com/tech/security/u-s-voter-info-has-alw...
[2] https://www.ncsl.org/research/elections-and-campaigns/access...
[3] https://www.comparitech.com/blog/vpn-privacy/personal-voter-...
I think you should make it clearer that "the voter record" does not include who you voted for.
Joe Schmoe is a Democrat and voted in the last election is presumably public information.
A record of who he voted for would be unprecedented and explosive news.
1. Google already does a good job of filtering out email addresses. I remember searching email addresses I was curious about 5ish years ago and getting results. Today, I get far fewer hits. So my theory is that google is already attempting to sort of scrub peoples email addresses from their searches. Us filling out the form is feedback to the machine learning.
2. Google wants to corner the market on this information and this is how they bleed the companies out. (I don't they have _actually_ devoted enough resources to this to bleed the other companies out) The business motive? There isn't a particular offering this data is good for besides selling to 3rd parties besides the business Google is already in. This data could enhance other data sets for other offerings. As simple as "auto-complete" for phone number after you have entered your name or address fill after entering your phone number.
After I saw this news article about phone # removal I went to look for the search results that I had previously found on Google but apparently Google had already delisted them. Good stuff.
The whole thing feels like a /r/maliciouscompliance post.
There is NO requirement of threat to remove anything listed as personally identifiable information on this page (such as personal contact info, medical records, login credentials, etc): https://support.google.com/websearch/answer/9673730
Beyond those things listed, in some cases someone who is being threatened might feel there's additional information that someone might feel is somehow personally identifying. This is where the doxxing/threat option can be used, for something not on the list where no threat is required.
Appreciate this is confusing to some; we'll be looking at how to clarify that.
I did reconnect with someone I lost track of a long time ago via google-stalking, found their email address. I'm pretty sure they agree that it was nice to reconnect, we talk regularly again.
(Neither of us are FB users, so no, it doesn't substitute.)
Anyone wanting to deploy dirty tricks to remove things from Google can do so very easily already
https://support.google.com/websearch/answer/9673730
From that article:
> We evaluate each request based on the criteria listed below, and evaluate the content for public interest. As a result, we may...deny your request.
With the exception of email addresses below, can anyone provide a circumstance when Google might legitimately find that not removing the following would be "in the public interest"? * Confidential government identification (ID) numbers like U.S. Social Security Number (..) etc.
* Bank account numbers
* Credit card numbers
* Images of handwritten signatures
* Images of ID docs
* Highly personal, restricted, and official records, like medical records
* Personal contact info (physical addresses, phone numbers, and email addresses)
* Confidential login credentials
It seems there's quite a bit of wiggle room in this policy to remove some search results and not others.There's a reason we have sex offender registries, even if they go too far sometimes. You should be able to look up why a person is on the registry using a search engine, and criminals shouldn't be able to hide their past.
Some of them probably will get harassed for it, but I'm fine with that.
Scaling it wouldn't be hard regardless, this would be very basic task based work, that they would hire out to India or via companies that handle this sort of work.
A slow and frustrating process to stop displaying your private information does Google no harm, so the answer from their side is likely "who cares?"
That in theory means that if your details are on a website, you've already given consent for it to be shared with Google.
Does that happen in reality? Most of the time I doubt it. But it pushes the liability onto the website owner.
UPDATE: I suppose if you specifically allow the Googlebot via robots.txt, then in that case they could probably argue that you gave them permission to access the site.
So yes, you do allow them to visit your website.
This is worse than shrinkwrap agreements and TOS banners at the bottom of a website, since for those you could at least argue that the person who opened the box/visited the site saw the agreement. But in this case, there is absolutely nothing to indicate that the person who created the website even knew that Google as an entity existed.
In theory you're right. In practice, just because something responds publicly does not mean it's public.
If someone left the vault door open on an ATM it doesn't mean you can just have the money, or even take pictures of the insides.
Obviously, in IT, people should strive to prevent leaking information, but that's obviously going to be an issue for a great long while.
If anything, that's more to the discussion of giving social security numbers to inept IT departments.
I would suggest maybe s/Remove/Drop/ or just s/from Searc//.
Instead you have to submit an edit and state in there that it's a private road and on private property so should not be used for navigation purposes. It will then be removed from navigation etc.
"Not visible from an aerial shot with leaves on" doesn't really mean anything. If the roads aren't buried underground or in a tropical rainforest, they are probably visible to a satellite at the right time or wavelength.
Several attempts at reporting this to Gmaps has gone ignored.
Google sucks so much at these countless edge cases that it drains all the benefit of anything they're actually good at.
Don't get me started.
It was my only source of income as I had just graduated and losing it completely pivoted my life. Now I see Youtubers say it daily and it still reminds me.