Fitbit users will have to sign into Google from 2023
theregister.com
theregister.com
We were bought by Fitbit which operated with almost complete disdain for any attempt at security or privacy that could slow down operations. Anybody who wanted paintext access to user data seemed to get it without delay. Security and privacy were not among the things that created shareholder value so every issue I discovered was permanently backlogged.
It was depressing seeing all the data I fought to hard to protect be absorbed into a machine that would sell it off to the highest bidder, or shrug when it got stolen by a blackhat. I quit 3 months before my golden handcuffs would have kicked in because it felt too unethical to keep working there.
Then of course all the data was sold again, this time to Google. No Pebble user ever consented to their health data being sold to Google, but all of this is legal.
This is probably a lost word-use game, as everybody just says e-ink, but it seems important given the major differences between reflective LCDs and the electrophoretic technology used in ereaders.
I had a MetaWatch watch with an e-paper display with silver reflective screen backing and it was, by far, the most comment-generating thing I've ever worn. Still miss it.
I'm genuinely wondering if the erosion of privacy, the breaking down of that wall, was the whole point of the Internet from the start.
ML is where things tend to be a little bit more grey overall since being able to look at data is very useful for development, so some things are scrubbed for PII, but then accessible in some form. But for things like GMail or Photos, I would assume nobody (including ML engineers) can read your data as these are basically impossible to sanitize.
Some products have systems train ML models without engineers seeing the data, e.g. spam filtering, even when the underlying data is considered sensitive.
The fairly recent case of people's private conversations being shipped out to basically unvetted contractors for labeling and analysis (and subsequently leaked) should serve as sufficient evidence that "shit happens," and if private conversations without having even initiated an interaction with your Google devices are being tossed around and leaked, forgive me if I don't believe that when producing the tagging, timeline, and album features in Google Photos there wasn't some underpaid, unwatched contractor snooping through my photos without my permission.
I reported the bug. Knowing how security works technically, I added to the bug the words "I'm happy with whoever works on this to take a look at the gallery, here's a world-readable sharing link". A couple rounds of bug comments later, I have been asked to sign a legally binding consent form allowing an engineer to look at the gallery. Then somehow they decided I need to sign a different form to satisfy whatever other legal spirit needed appeasing. Only then someone finally looked at the bundle of photos. They figured out whatever was triggering the bug. They generated a gallery reproducing the bug with generic sample images. Whoever worked on the bug and adding a regression test worked off that synthetic gallery instead.
And that, moreover, I get none of the profits from these transactions, and have no control over whom it's sold to and under what terms.
But somehow this is ok because within Google the common employee doesn’t have access, but is rather incentivized to make the vacuum or selling more efficient?
When people talk about 'security' at Amazon/Microsoft/Google/Apple, they're describing audit performance and ISO compliance. From a business perspective, that's really the only thing that matters. Everything else is played pretty fast-and-loose. Both Apple and Microsoft have been caught backdooring their infrastructure for foreign governments, if anyone out there still has faith in these companies then I hope they stop taking life advice from VC heads.
All data collection practices are not equal.
>Google Tracks 39 Types of Private Data, the Highest Among Big Tech Companies
Google takes the cake when it comes to tracking most of your data. This should not surprise, given that their entire business model relies on data.
Twitter and Facebook both save more information than they need to. However, with Facebook, most of the data they store is information users enter.
Apple is in a league above Amazon in protecting user privacy. It is the most privacy-conscious firm out there. Apple only stores the information that is necessary to maintain users’ accounts.
https://stockapps.com/blog/google-tracks-39-types-of-private...
Apple could have folded, like even (old) Google did, and refused to comply with the CCP but shareholders would have been too upset seeing the price go down.
Successful publicly traded companies will almost always do the most profitable thing legally possible, no matter how evil.
But that’s not the real danger of Google having this data. The danger is in ML. Google’s entire business model is predicated upon using information about you to change your behavior, and to sell on the market predictions of your future behavior.
Google is one of the few companies known to have caught, fired, and officially publicly named an employee who did something like this:
https://techcrunch.com/2010/09/14/google-engineer-spying-fir...
Most tech companies about which people don't routinely raise this type of concern have far weaker security controls against (and detection systems for) this threat model than Google does.
That said:
> But that’s not the real danger of Google having this data. The danger is in ML. Google’s entire business model is predicated upon using information about you to change your behavior, and to sell on the market predictions of your future behavior.
I'm of two minds of this. I'm not thrilled about how much data Google combines and unnecessarily insists on collecting in order to allow things like the Google Assistant and Google Maps to provide full functionality. At the same time, many of Google's assistance and search services are better than their competitors exactly for this reason. I primarily wish they were more transparent in this area with fewer dark patterns and more user control, with forcing users to pick between excessive data sharing and inadequate access to Google services.
Disclosure: I have worked for Google in the past, but not since early 2015. I certainly am not speaking for them here.
> I'm of two minds of this.
I'm of two minds on this.
> with forcing users to pick between
without forcing users to pick between
Not disagreeing with your broader point, but that specific employee was not caught by Google but was reported externally by parents of the minors after abusing access for months. I suspect the incident you linked predates - and was the impetus for - many controls that were subsequently added
Speaking speculatively: I've never worked for Google
(I left Google in June.)
That all mentioned here clearly means google doesn't have data privacy at the core of their priorities and this won't change unless forced by fines/regulation, just like banks. Slightly disappointed when reading this, but I guess I shouldn't have expected more.
What's wrong with granting engineers access to PII-less logs[1] by default? How does that compromise privacy?
I'm willing to bet your bank differed on the following ways from Google in absolute numbers and per-engineer:
* handled significantly less requests per second - at least 2 orders of magnitude - therefore lower log volumes
* shipped less changes to prod per unit time, so fewer problems to investigate
1. No IP client address, raw session id or username
I think this is part of why Google has earned itself a reputation for killing things: if you require everything to use the same set of internal systems, and can't just leave old projects limping along on a fork of a deprecated system, the cost of keeping old things around is higher.
(I worked at Google until June)
The thing is that these processes don't actually work, because in the end someone is going to do something dumb anyways and you really can't stop them. The same way your processes aren't going to stop an outage, someone is going to correlate data they shouldn't and somehow lack the tact to go "hey maybe I should not be doing this". Often various pressures will make it seem like something they should do. And when they do it they will cost the company an incalculable amount of user trust, to say nothing of the irreversibility of a privacy incident. Someone will do a writeup of it after it is discovered by the press but at that point the damage is done.
(FWIW, I'm not even including the stuff that goes on with executive approval, where they make decisions on how likely they think they are going to be discovered and sued for large amounts of money. Of course this would bypass any policy…but it's usually kept under wraps for obvious reasons.)
This has the downside that the number of organisations that need to approve any launch ends up being borderline overwhelming. This is a big part of why it takes so long, if at all, to get Google products outside the US. Another implication is needing the expensive security org and culture.
how does this make the following OK?
> No Pebble user ever consented to their health data being sold to Google, but all of this is legal.
Entirely possible I misread the spirit behind the letter of what GP wrote.
>In today's Big Tech antitrust hearing in front of a Congressional subcommittee, representative Val Demings questioned Google CEO Sundar Pichai about the company's merger with DoubleClick.
Specifically, the way Google combined data from the advertising company -- bought in 2007 -- with Google's own data. Founder Sergey Brin had told Congress it would not combine the personal information, but the company quietly did so in 2016 anyway.
https://www.engadget.com/google-antitrust-hearing-doubleclic...
>Google’s privacy policies as of March 1, 2012 established that no combination between DoubleClick’s advertising data and Google’s personally-identifiable information would take place without the prior consent of its users, but an updated version of those policies subtly allowed the integration of both databases regardless of prior consent of its users
https://www.promarket.org/2020/08/21/why-we-should-be-carefu...
As a Googler that has access to some Fitbit stuff, I have to sign a form every 30 days that indicates I understand this.
You could argue they had no choice, but I could argue that they had the choice to allow search history to be end to end encrypted and/or anonymous. That is if their business model did not rely on selling plaintext PII.
https://www.nbcnews.com/news/us-news/police-google-reverse-k...
For using it internally: health data is widely considered toxic. As in "I'm not touching that thing with a barge pole" toxic. I would personally be pretty surprised if Google ever started monetising it.
You're saying that Pebble users didn't sign a contract detailing use of data? That seems highly irregular.
I want the convenience of a watch to track my workouts without a single thought that GOOG et al can collect. I want to download it to a local device and analyze it there.
And I don't care if GOOG is "99.999999999%" better at protecting my data. The point is I do not want them to have my data.
I've always really enjoyed Garmin and their products and their services.
I'm sure they're not perfect but they're an alternative to the Google all seeing eye of sauron.
It order to fix the problems with modern corporate surveillance, we can't keep pretending that storing things in the cloud and using cloud services doesn't have huge benefits. Just telling everyone to only store things in flat files on their local disk just brings up the "old man yells at cloud" meme in my head.
What we need are stronger laws. For example, if one company is acquired by another, and that company demands a new login scheme that can link additional data, I think they should need to give you the option of a full refund.
Edit: I also have little faith in any legal remedy going far enough. The cat's out of the proverbial bag, too many businesses "depend" on data, and the government certainly enjoys being able to more easily access your data via cloud businesses than having to deal with a different enduser's setup every single time. Not saying we can't make progress, but I'm pessimistic.
And yes, it may not be that common for people to lose their Google account, but that's really just one failure mode of relying on in-app storage. The provider may decide to suddenly put parts of your data behind a paywall (like Slack just did), or may straight up cease to exist. Even if Microsoft were to do something similar to your OneDrive account, you'd still have your local copy and could change your cloud backup provider with very reasonable effort.
Even more people know a couple of people who have devices with some spare space.
Wouldn't it be great if we had a way that people could "join" trusted devices to create mutual background backups. So I could pair my laptop with my phone, and each would back up "essential" data for the other. But I could also pair my phone with my significant other, and our phones would also work as backups of each other. Syncing could be done on some kind of schedule, maybe when they're in bluetooth range, or maybe if they find each other on the same LAN. Or maybe they could use cloud storage to transfer E2E encrypted blobs.
(i.e. my phone would backup my laptop and my parter's phone, my partner's phone would back up my phone, and my laptop would also back up my phone. If my partner wanted/was willing to also back up my laptop, that would be a separate step, and they would back up each other.)
Deciding which data should be considered "essential" is left as an exercise for the implementor :-)
It’s also extremely rare for an average person’s house to burn down. Or extremely rare for a 500 year flood. Or an asteroid hitting the earth. Should we not prepare for, avoid, and mitigate these risks?
It’s not telling people to store flat files in the cloud. It’s encouraging sustainable protocols that decompose to strong flat files in the cloud.
Story time is when ynab originally just write their files to a file structure and used Dropbox to sync. Then they switched to saas, charged people a monthly fee and store customer data in their proprietary cloud. One day ynab will go away and so will their data. Their earlier method will last forever because of the portability of flat files.
Customer lock in makes companies more money.
Maybe they should be able to? I’d purchase that kind of insurance!
Just like I wouldn’t mitigate 500 year flood plain but would instead never buy or build a house there.
You mention laws and thats the core problem and its naive to just rely on them. Corporations are profit-first, bonus-first, and employ progressively more sociopaths as you move up the management hierarchy. This is simple sad fact regardless of industry or country.
Those folks see laws as obstacles, and unfortunately often try to game them. The results are basically all the fines big banks face from regulators, financial crises, endless internet privacy issues and so on. People just gaming well intended rules for their own profit.
plus re laws - we don't have judiciary hegemony over whole Earth. Corporations move their activities to weakest jurisdictions immediately, ie Ireland for taxes from Europe. Or they do pay minimal taxes in US. DOn't expect privacy to be handled better by default.
The truth is Apple came in and ate everyone lunch. Pebble was effectively dead the moment Apple announced their plans for a smartwatch.
At the end of the day there wasn't a robust market for hacker-focused e-ink Android watches.
I really wish Rebble were putting more effort into keeping it alive. I understand the firmware is now open source, but it seems the efforts to make new hardware (or even replacement hardware) never really went anywhere. I'm grateful that they're keeping the app store & weather & voice recognition servers active, but it feels like they could do more. I guess I'm maybe looking for the Framework of smartwatches, with the aesthetics of the Time / Time Steel team.
I'm also hoping that the Apple Watch Ultra will turn out to have 5-ish days of battery life in low power mode after this fall's software update. I could consider an Apple Watch at that point, though I don't love the stylings of the AWU itself. Mostly I like the battery and the fact that the screen is flat and protected by a lip. Hopefully they can produce another variant that isn't quite so extreme sports-focused.
Needs are required for life. You don't need sleep tracking, you want it.
GP didn't make it explicit but you can probably assume they were implying one of these contexts, rather than that they would die without that feature.
The smart watches with blood oxygen saturation sensors can be useful for detecting sleep apnea. But that only applies to people with the condition.
Why do you think you need sleep tracking? Is the data actionable?
If we want to improve sleep quality then it's no big mystery what to do. Consume less alcohol and caffeine. Exercise more. Don't be obese. Don't eat a large, protein-rich meal late in the day. Go to sleep earlier. Keep the bedroom cool, dark, and quiet. We all know what we ought to do, we just don't reliably do those things. Better sleep tracking won't fix a lack of discipline or give us more hours in the day.
iOS app limitations though, I agree. Fits their pattern of behavior.
Overall the list could go on for days, I think you nailed it on the head that it would fit their pattern of behaviour. And they already seem to be following that pattern with their current line of watches and what they can do versus what a non-apple watch can do interaction wise with their phones.
Also, recently I bought Polar HR10 heartrate monitor and was unpleasantly surprised by the fact their Android app is also "signup required", for practical purposes. I mean, it does let you use it offline, but I never found a way to actually export my data (I suppose it should be doable in their web-app, though). And I didn't find any alternative HR-logging app for Android that would allow me to do that, so that I could use the product I bought the way I want. Well, nobody promised me I will be able to, but I still feel kinda robbed.
Meanwhile the charge 5 takes ages to sync just to show metrics and doesn't work offline.
It's a cheap tracker that looks good but something is definitely off about the product.
If you can't actually formulate why the migration of the account system is bad thing, maybe it's actually not?
I think most, even non technologist feel the negative in this, even if they cannot articulate it.
You seem to be making an argument, in vague generalities, for why they shouldn't have been allowed to buy Fitbit. But that deal was approved by the regulators across the world, after concessions, so there is no point in relitigating that. Is there a concrete argument for why they should require indefinite support for a legacy account system?
There is a pretty obvious reason for why people cannot article why they feel negative about this... Because they are feeling negative about something else entirely, and projecting. But this particular change is be strictly an improvement: it's going to be much better to argue against the things that actually bother you, not use this as a proxy.
The data has different terms of use, depending on the account. Your personal health data is imperative for the Google ad wheel to keep spinning
If you're wearing a device that knows when you're asleep, awake, fucking, or sick and you're sending that data to a third party whose entire business is built on collecting your personal data and you've been viewing that data yourself on a cell phone running their OS you can't care very much about your privacy to start with. Being forced to sign into a google account at that point is a formality.
I tried to create a new Google account for a webservice that only allowed third-party logins:
The account was requiring a phone number immediately after creating it. After begrudgingly entering a phone number (that was, to be fair, already used with another Google account - I don't have random burner phone numbers lying around), the account was locked due to "unusual behavior".
(This was a Google account with an existing mail address from a normal mail provider, no new Gmail account, btw.)
In contrast, most "normal", non-SV companies don't even ask for a phone number as a hard requirement, yet alone decide your fate by ML algos.
The difference between that experience and creating a fitbit account is night and day.
Google continuously doing this means I’ll probably never pay for one of their services.
In fact, how could they? I currently hold Google Workspaces accounts at my community college and from my employer. In addition to these two, I also have a "main" personal account where I do most of my stuff, including my Android device. Then, I maintain two other separate accounts for volunteer work in various capacities.
So I have five accounts in total; in fact I've signed up to Google One and gathered three of them into my "family" group. Google actively encourages people to create as many accounts as we can handle. It's nothing like Facebook, which requires a 1:1 correspondence between humans and personal accounts.
No, that's not true.
Also you will need a whole new phone number for these alternative accounts which can get expensive
No, that's not true.
textverified.com
I love the idea of this, I love the convenience of it, but this was always (sadly) going to be a hard pass for me.