I made a Google sheet of local elections and it's been removed from Google Drive
twitter.com
twitter.com
There is a yellow banner "This file looks suspicious. It might be used to steal your personal information" and an option to "Request a review".
It also says "This file can still be viewed, edited, and shared, but users will see a warning that alerts them that the content may be harmful. These restrictions were put in place because this content violates Google Drive's Phishing policy."
There is no indication of why the file was flagged.
Despite my concerns about a human looking at my personal file, I bit the bullet and clicked review several times but the banner remains after several months. Google support hasn't been helpful even though I'm a paid user.
I have now received 5 emails from "Google Drive Safety" notifying me of this alleged violation.
https://dev.to/petarov/store-encrypted-files-in-google-drive...
Thank you for your purchase. Sincerely, your caring daddy, government.
https://hn.algolia.com/?q=https%3A%2F%2Fcryptomator.org%2F
Perhaps the problem is that the privacy conscious have already deplatformed & do their own syncing to private cloud, whereas the others are still using the platform & don't care as much.
I'm in the first group, but have become increasingly weary of keeping servers online (I self host everything) & I'm see a lot of promising results in Crytomator... but there's one inevitable gotcha: those very platforms can cut you off at some point in the future. So, you'll need to multi sync across multiple platforms for redundancy.
That said, cryptomator looks good!
But the benefit to society is great of doing better on security and privacy.
This is why governments should regulate security and privacy. The whole point of governments is to solve collective problems together.
Plus side is plugging in hard drives whisked me back to building computers as a kid.
There is a whole ecosystem of plugins and stuff, but out of the box it works fantastic.
I'd wager the "reviewer" it's merely a more computationally expensive process
It says:
Review process
If you think this is an error, or if you've modified the file to comply with Google Drive's Terms of Service, you can request a review.
1. Your file will be reviewed
This file will remain restricted during the review.
2. A decision will be made
If the file is found to be safe, all restrictions will be removed and you’ll be able to use and share it with others. If it's found to be unsafe, the restrictions will remain in place.
> Your file will be reviewed
> A decision will be made
> If the file is found to be...
> ... restrictions will be removed ...
It is the archetypical "mistakes were made".
Note the constant use of passive voice, intended to hide the actor, and to keep you from even thinking about who is doing these things and thus who is responsible.
By the way, no better is the most likely alternative "Google will review...". I'll leave deducing the reasons why as an exercise for the reader.
Just because there are more edge cases where the human has no idea what their algorithm does, doesn't absolve them of responsibility. You don't get to go free after running a bunch of pedestrians over by claiming you were too drunk to know where the road was or which direction your car would turn when you moved the wheel. If I put a running metal lathe in a kindergarten, I don't get to throw my hands up and say 'you clearly don't understand machining' when some children get dismembered.
Because if it's measured in watt hours, this computational process is almost certainly drastically cheaper than using humans to do the same work, especially if you account for 20+ years of unprofitable training time per compute unit and 76% weekly downtime even at peak productivity.
Additionally, I suppose in a company as big as Google, all this decision making is backed by written communications.
All this written stuff is subject to legal scrutiny. All must abide by 'approved' rules, guidelines, etc..
Squinting a little bit (maybe some may need to squint harder) it's clear that in the end everything is being done according to a computational (written) process.
this is essentially what 'skynet' (from the terminator) or the matrix actually means. if every human involved is following data and written guidelines, the decisions are being made by a computer program running across many hundreds of humans pushing "paper" around.
> "These restrictions were put in place because this content violates Google Drive's Phishing policy."
> There is no indication of why the file was flagged.
Isn't your answer in the warning (albeit lacking some specificity)? If you have a bunch of URLs in there and admit not knowing about their legitimacy, it seems reasonable that at least one of them matches a database of known phishing URLs. Isn't it also reasonable to expect (and in many cases want) a company hosting publicly-shared files to notify users when content matches some heuristics for unsafe content, especially given the prevalence of phishing attempts?
That said, there may still be a case to argue that the review process, heuristic, lack of transparency, and other implementation details are flawed. But I don't have a problem with them posting a warning message on content that looks suspicious.
Complete removal, on the other hand (as in the case of OP) is another story, especially given Google's laughable process (or lack thereof) for appealing such cases.
What is wrong with a list of phishing urls ?
Sounds simultaneously useful and innocuous to me …
As someone who operates a service that allows people to create and share lists of links on a public site, I can tell you from experience that it's not as innocuous as you might think. Scammers routinely use a trusted domain to host a link to their malicious final destination since the initial, trusted domain in often the one given the most scrutiny (e.g., from an email). It sounds silly to more technical users who understand how the web works, but unfortunately it's effective and super popular in phishing campaigns.
To your point, yes - a list of phishing URLs would be useful in a lot of cases, but it's difficult for automated tools to tell the difference between those legitimate use cases and the much more common cases used for phishing, so they err on the side of caution. As mentioned, the human review / appeal process surely has room for improvement.
80/20 incomplete machine learning model.
One day people and institutions will get the message and stop using Google for important things.
Sadly it won't even be the next generation as they're all rusted into the ecosystem with Chromebooks provided by their school districts.
Meanwhile, they seem to be taking their eye off the ball when it comes to the spam filtering that many of their users might wish for. In just the past week, I've received noticeable amounts of spam via: Gmail, Google Drive, Google Calendar, and Google Photos.
I'm puzzled about how Google are choosing to allocate their resources. It doesn't seem likely that governments would be asking Google to specifically police spreadsheets for possible phishing data. The owners of the files definitely aren't asking for their access to their own data to be cut off. So what are the origins of this effort?
I have to admit, I originally thought that Google Drive was the obvious choice over every alternative that existed, but I can see now that I would prefer an offline or privacy-driven alternative. The risk of losing files to a Google Drive machine learning black hole & then facing Google's customer service black hole might be small, but it's also nightmarish.
Thankfully I'm about ready to close down my Gmail account (still stuck needing a Google account for now) but it's a good reminder of what I won't be missing when I finally get out.
The risk of facing the "black hole" may be larger then you think. There's a person who posts a common "recovery how-to" in the support forums when people get locked out and that page got 83,878 views last month.
I received a notification from Gmail the other day that "Someone added <made-up-email-address@my domain> as their recovery email.". And my only option was to disconnect the email. By disconnecting the email, I would be confirming to the account owner that the email landed in someone's inbox. By not confirming the email, I would be allowing my domain to be associated with a Gmail account potentially used for nefarious activity.
Given Google's scorched earth approach to deactivating associated Google Accounts when it comes to things like the Play Store, I felt I needed to disconnect the account.
Google Drive
> Random Name (randomcharactershere@gmail.com) has invited you to view the following document: Private__file-Nyela-(random characters)
> If you don't want to receive files from this person, block the sender from Drive
The painful part is the last bit, you can only block that single sender, you can't turn off all notifications.
Google Docs
> Random Name (randomcharactershere@gmail.com) mentioned you in a comment in the following document Direct_message_with_Salma
> 1 comment
> Random Name • 4:58 PM, Jul 11 Contact Helen and rate her request to date here https://morerandomcharacters.example/evenmoremorerandomchara...
Google Docs has the same problem, you follow the link to turn it off and you end up at:
> Notification settings of myemailaddress@gmail.com for Direct_message_with_Salma
So you can only ever disable notifications from that single document.
I'm not being miserable or spiteful when I say I'm really glad this happens. Mono-cultures are dangerous and undesirable, and whether the cause is "network effects" or more active monopoly tactics it's good that there's some drivers towards alternatives.
Ultimately, when we have interoperability (by legislation if necessary), people will have the genuine choice to share documents via Google, where their work may be censored or arbitrarily deleted, or through another service. It will not matter whether others in the group use AcmeDocs or GoogleDocs, we will all be able to share and edit via interoperable protocols. But when Google screw up like this, they will lose customers who have no barrier to migrate to another Docs client.
That will raise software quality. It would be a real marketplace.
I would think any first class modern day regime would be on the lookout for anyone who might have it in their mind to challenge that authority, and election related keywords could certainly fall into that filter depending on how coarse it is. I wouldn't expect they would just blatantly take down documents though, so I suspect I am being excessively conspiratorial here.
One report and the entire website is blocked, we clean the website immediately but already all the shitty antivirus and security software is blocking our domain, it took us weeks to have those bastards fix the issue, one of the big security companies even had the form you need to use to submit reports broken for weeks... So unfortunately if a "bad" link appears on your website it will costs you a lot of time to get it all back to normal, my advice , for user generated content just use a different domain so if shit happens your main domain does not get blocked by the browser makers and antivirus companies.
Removing files in google drive will kill drive. How can you trust them?
I looked at an "out of the blue" example just now:
1. Sent from a Gmail address where the name doesn't come close to matching the name suggested by the sender address.
2. Email body is in Latvian, a language I have no association with.
3. About 20 other recipients, none associated with me.
4. Subject line is nonsensical (not even words) and an email address.
5. Email body is one line.
6. PDF attachment, with no mention of it in the email body.
7. Looks automated, but came from a Gmail address.
Of course, none of these in isolation is a definitive indicator of the email being spam, but given that there's at least 7 anomalies, considering the amount of data Google has & that they pride themselves on machine learning, shouldn't they be catching something like this?
I wish I was being facetious.
Still scratching my head at how their calibration can let something like that through and stick a random genuine circular from Twitter in my spambox though...
The reason why Google Sheets was so handy was because it's a great interface for data exploration. I could show students features about the data, and sort/filter/highlight, without having to distribute/create spreadsheet files. I guess if Google Sheets ends up being draconian with its content filters, I could link to Github-hosted CSVs, but it's not quite the same.
Haven't checked my classroom Google sheets recently, but if they're untouched, it might have helped that they were all set to public view. Maybe the flagging algorithm looks at private sheets with much more suspicion.
You could be right, but jeez... shouldn't it be the opposite?
When you have literally millions of people whose livelihood depends on gaming algorithms, or getting past content filters, then some highly intelligent and motivated individuals are going to get through, that's a fact of life.
When someone figures out how to train their robots better than Google, then Google will have some competition, but they seem to be about a decade ahead of everyone else, and only accelerating relative to the rest of the field, so I'm doubtful that anyone is going to catch up any time soon.
> Everything else is much, much worse IMO.
I wouldn't say it's much much worse. Lot of the digital service I use, I pay for. And they have human support when I need it.
I don't miss Google services at all.
Of course Google and Microsoft both punish me by sending my mail to spam (even years later) for using my own domain but that's what I'd expect from the big players.
From what I can tell it's just that small domains are guilty until proven innocent. However it seems at lower volumes you can never send enough email to get past the thresholds they've set so you're forever guilty in their eyes. Very convenient.
I've also signed up to both Microsoft and Google's email tools and neither shows any information because I don't send enough mail while they still keep making my mail as spam. It's getting to the point where I'll probably have to use a 3rd party SMTP rely as the family don't appreciate their mail going to spam while all their friends on GMail go straight to the Inbox.
A nice new addition is Microsoft is flagging any links I include in my message as "suspicious" and giving the users scary warnings. Meanwhile I can see they still take the opportunity to scan and fetch the URL and yet still can't determine it's safe.
I think to switch to my own domain mail adress but I think to use Migadu [1] instead or even try to host anything.
Interestingly when I logged into Microsoft's Smart Network Data Services I could also see my VPS provider had claimed the IP block as well so they were clearly invested in making sure spam was under control. But nope, still not enough for Microsoft. At one point the mail was even getting hard 550 refused. I contacted their support who to their credit replied, but to less of their credit gaslit me and claimed there was no blocking occurring despite me pasting them full error message with all their tracking IDs in it. The next day mail was allowed in again but still ends up in spam.
If only they would send everything to spam. Microsoft outright blocks all mail from my VPS because some other IP on the block allegedly sent spam. Of course since I'm not running a commercial business I can just tell people to use a better mail provider if they want to create an account - not worth my time to deal with shitty megacorps.
No, we moved to google because they provided three orders of magnitude more storage than other free mail providers. Also, the interface was slick and fast.
Spam is an overrated problem - it doesn't take much time at all look over a dozen or so mail subjects a day to determinine if they are legitimate. Scammers are a problem for the more vulnerable but Google is never going to block all of their own kind either.
Yes. I went from self-hosted to Proton recently. Spam filtering is better, UI is better, and customer support / transparency is way better than anything I've seen from Google in the past decade. Of course the various outages / issues over the past three days have been frustrating so there's that.
This is so true that it hurts. I went back to college later in my life starting in 2018. It's astonishing to me how ingrained Google services are to the kids I'm in school with. Even though we have Office 365 and a full suite of apps available to us for free, when we do group work the de-facto decision that students come to is to create Google drive shares, or shared Google docs that are tied to personal accounts. It gets so stupidly messy and the apps just seem so inferior. Everyone uses the same Slides template so everything looks the same. Ugh.
I've taken to telling people for years now, for this exact reason, that friends don't let friends use Google's password manager.
This is something EVERYONE using Google Drive should be aware of. Your data on Google Drive is scanned by Google (and not only for policy violations), meaning it is not secured FROM Google, and false positives can and will cause your data to be lost and cause your account to be flagged. Using Google Sheets means that is your only copy of the data, so you also have no backup.
Google does not provide support for this service.
Personally I think local storage is a bit of a losing battle for long term personal backups; the running costs of expanding and replacing disks at 28tb size start to get significant if you do it properly with offsite compared to the range of affordable encrypted cloud backup services out there, many of which let you provide your own private key for storing the data encrypted at rest on their side (how I use backblaze right now for all my machines).
I'm honestly not sure I could do local storage well at less than the $65 per computer per year I pay Backblaze - one new drive a year for a NAS is already more than I pay Backblaze annually before other costs and my time to maintain are factored. While I'm not accusing you of this, my experience is many people running their own NAS do so because they enjoy running their own NAS if they are totally honest with themselves, not because its necessarily the best or most convenient option.
That being said, do you have any advice on how to encrypt data before uploading to cloud? I'm not at that stage yet so I haven't done deep research, but I've heard of things like veracrypt/truecrypt? And I've heard enough good things about backblaze (and enough bad things about other companies like google) that I'd be comfortable going with them if the price is in my budget and if I can just figure out the encryption angle.
> https://www.backblaze.com/backup-encryption.html - scroll to "Adding your own passphrase"
My NAS runs TrueNAS Scale. Any data I need to keep around long term goes into a personal share. I have restic installed on the NAS, with a USB drive hosting the repository for it connected to the NAS. At this point, copy may or may not exist on my personal computer, does exist in the personal share, and is copied to an encrypted backup repo locally. Finally, there's a sync job pushing the encrypted restic repo to Wasabi. I only follow 3-2-1 on things that need it, so things like my media library aren't part of it (I can just rebuild this stuff). At less than 1 TB, Wasabi can be pretty cheap.
In terms of documents, though, I tend to use tools like LibreOffice rather than cloud office tools. Having real documents that I can include in my 3-2-1 backups, as well as being able to share, is convenient and useful. Maybe not the best for collaboration, but that's easily worked around.
I still work with cloud office documents from time to time, as documents shared to me, not vice versa. If it's something important that I need to keep a copy of, I export it.
Just google:
Both holy grail backups
… for stavros’ nice write up.
What do you mean by this? There's nothing personally compromising on your hard drive?
- The specific policy violated is "Phishing"
- Sheet was titled "Boston Election candidate websites"
- OP says it's a list of candidate names and their campaign websites
- Created in Oct 2021, removed in July 2022
- OP says a similar worksheet with many more records has not been removed
Google monitors and restricts shared content. This is reasonable, IMO. If someone is hosting documents publicly on the Google domain, it's reasonable for them to make judgment calls about what can and cannot be hosted.
Note that the file wasn't removed, it just had public sharing and other public features restricted. (Read the dialog in the Tweet closely)
Does it monitor only shared content?
If the author is to be believed, and if Google made a judgement call as you suggest, it is bad judgement.
I'm not concerned about happens after Google reads the document. I'm concerned that Google reads the document, and I want to know which ones are read.
Not exactly what your scenario is, but damn close: https://boingboing.net/2007/12/06/western-digital-netw.html
I can't believe it's been 15 years. I remember this like it was yesterday, and it's still the reason I won't buy anything from WD.
On a related note, back in 2007 Western Digital did indeed decide to do some pro-active policing with users files:
https://www.theregister.com/2007/12/07/western_digital_drm_c...
And yeah, that was about as popular as you'd expect. ;)
E2E encrypted services are the exception, not the rule. This mischaracterization extends so far that when Apple announced plans to turn on E2EE for photos (necessitating an on-device scanning tool for banned photos before upload), the uproar against it was vast and unanimous. So now we still have the same photo scanning on Apple's servers, and no E2EE.
Google then prunes these malicious pages from their search and then also flags any docs that have those links in them.
It's a shame this person lost their work. More and more stories like this need to come to light and we need to convince others the cloud is a risk, not a solution.
[0]: https://arstechnica.com/gadgets/2021/07/google-is-finally-do...
It is 100% possible (and not even difficult) for Google to prevent me from receiving spam from other Google Drive users whilst also allowing me to access my own Google Drive files.
My guess is OP has multiple accounts, created this file on account A, and can no longer access the file while logged in as account B, so it seems to be "removed from Drive." But I could be wrong, in which case I agree with you, this doesn't make sense as an anti-spam measure.
https://workspaceupdates.googleblog.com/2021/12/abuse-notifi...
Maybe 15 years ago when all this was new....but it's been pretty obvious that this was the course of things over the last 6-7 years. It makes business sense when there is no competition.
Is it legal to keep a list of electoral candidates and their public info? Yes.
Could it be disinformation? It could. Would that be harmful to Google to have Google Sheets be used to distribute? Yes.
Does the risk of it being bad outweigh the benefit of keeping legal content? Yes, strongly, and it *always* will.
It is always in Google's interest to be as risk adverse as possible. They always will be. (This applies to all clouds too)
If it's a private file (not shared), the question doesn't even make sense.
Some degree of control might make sense for 100% publicly shared content on Google Drive, but how does it make any sense that they are cutting off access for the owner of the content?
You'd think after the original Photobucket meltdown people would be more cognizant of stuff like this, but here we (still) are :(
It's still pretty sucky.
1. The author of the thread refers to the file having been removed: https://twitter.com/mkramer/status/1547257266465914882
2. The author of the thread says they're storing csv files on their hard drive in future: https://twitter.com/mkramer/status/1547262861105397760
Otherwise it's super confusing to have the entire document be marked "suspicious", and end-user may reasonably (naively) still paste and visit the link. When this happens, the entire effort to keep them safe is subverted by Google's own poor design.
I made a voting tool (legitimate and funded by a campaign) with a throw away email as the contact:
<state><voting>@gmail.com
It was removed. For the OP, this could be an auto flag error or this could be something else.
(Edit: I bet) Google takes the election stuff seriously.
The filtering is phrase and word based generally, but sometimes also seems to use an ML model. We were able to use our own ML analysis to figure out the exact words causing content blocking and which carriers in a lot of scenarios. But yeah, it's definitely a thing at every major carrier.
It would be easy to register <state>voting@gmail.com, start using it as a contact for public-facing election-oriented documents, and get at least some people confused about whether I was officially associated with <state>'s election apparatus. Given the current environment, I'm positive Google very much doesn't want their systems being used to (even accidentally) impersonate election officials.
FTFY
Update: thanks for tips. Will have a look when I get home.
It integrates with NextCloud: https://nextcloud.com/collaboraonline/
https://www.onlyoffice.com/download-workspace.aspx?from=defa...
I haven't tried it myself.
Just a guess, but since it is a file which lists website urls one of those domains was probably flagged as a phishing site, and since your doc had a url with the same domain it got flagged as well. It wouldn't surprise me to find that one of those candidates' sites had actually been hijacked by some phisher. Unfortunately just visiting each site wouldn't necessarily reveal which one it was since they'd likely have tucked the php shell or other phishing stuff at some path away from the root of the site to avoid detection from the site's maintainer.
> I keep material in Google drive because my graduate school uses Google - so I use it to be able to share material with my professor.
Google doesn't seems to do fewer TOS checks unless they are shared with other people.
It's possible to self-host for free if you use google services because of the price: https://paul.totterman.name/posts/free-clouds/
The cloud can be convenient, but it's not under your control, so always also keep a copy that's under your control. Of course your local copy isn't secure either, so having a copy in the cloud is still a good idea, but it shouldn't be your only copy.
The combination of flag-happy AI and the way Google will nuke your entire account without recourse* or a human ever being in the loop makes them a non-starter for me.
*Google might give you recourse if you can get a public uproar going on Twitter or HN
Could understand certain kinds of causes being applied to public / shared files but private files ought to be pretty much untouched.
Of course, that's probably not how it really works when you're relying on cloud providers.
Nah that's stupid...
Oh wait.
Welcome to our glorious future of “internet scale” companies which make money by taking advantage of the information YOU GIVE THEM don’t have care, and can’t be made to.
Google drive in the last has restricted sharing of files that violate terms but I don't think I've heard if instances of then deleting private data.
That I am aware of, every one of my family members who has retired in the past 15 years was stuck using MS Windows at work. Every one of them has been happy to delete MS and Windows from their life - getting rid of their home computer, buying an Apple iPad, and running their modest on-line lives from that iPad.
If you actually care about the files you're using, neither of those are good choices.
- Always have backups.
- Cloud providers are not your friend, especially in their unpaid tiers.
I'd really like to know if Google does process every single file. I'll operate as if it does, but I wish someone from inside would confirm and elaborate.
https://filecoin.io/ looks to be something that could work as a backup for your storage needs. Anyone with experience using Filecoin ?
Google going through your private documents and arbitrarily deciding what’s legitimate and what is not?
Awhile ago there were a lot of fake login forms being made and getting hosted on official microsoft domains, via forms and Flow. Dont see that one as often anymore.
You are saying that it truly groks the permissions and other security applied to every accessible shared drive, every SharePoint location, anything not a local file, before it warns you about PII?
As well as all the relevant regulations from HIPAA, to European privacy laws, to company & corporate classifications...?
First of all, I wasn't talking about a situation where people use OneDrive to store their files. Was that what you meant by "You have to make stuff public on purpose in 365"?
Secondly, "of course they know what is visible" doesn't track. Microsoft isn't a person and I assume has internal silos. I also have not gone over all the user agreements with a fine-tooth comb, plus all of the privacy and other options configured in particular instances. I do not believe there is a general artificial intelligence in anything from MS that can manage the complete context, from firewalls to hackers.
Finally, in your follow-up comment, to which I'm directly replying, it sounds like you are talking about a specific configurable feature, whereas I was originally referring to default behavior and it obviously not being useful or intelligent.