update: Found one of them,
https://news.ycombinator.com/item?id=1692754 ("Google fired engineer for breaking internal privacy policies" (2010))
It's not linked in there, but the Wired writeup adds that (0) there were at least two SRE's fired for something like this and (1) Google chose not to report this to law enforcement, seemingly prioritizing its public image over its users' safety.
https://www.wired.com/2010/09/google-spy/ ("Ex-Googler Allegedly Spied on User E-Mails, Chats" (2010))
One was targeted and the other was not, but they are in the same class of issues even if the severity is different.
There is indeed a culture problem.
While having it be ok as corporate culture is a bit worse, fundamentally the problem is that private personal data is available to these corporations so at that level it is the same problem.
The only systems which are safe are those which either never send private data outside of local (local to the user) devices, or, where data sent out is encrypted client-side with keys which are generated, stored and only ever available to the client.
Anything else, will be abused.
They still expect the same sort of treatment that they get from their traditional health care providers and banks etc, with strong regulations enforcing the correct behavior.
> Google engineer who allegedly used his internal clearances to access private Gmail and GTalk accounts so that he could spy on and harass people, including four minors.
In this article, it says some people in Tesla posted a few pics of funny signs and pets on an internal message channel read by some tens of people, and at least one intimate, but not nude pic. Which is not what I thought when I first read the headline here.
I guess there were some more concerning things, like someone approaching the car naked, but it doesn't have any context and that could be something they might be reporting as a crime for all I know. The article doesn't say one way or another and leaves us to assume that all incidents are the same as the people captioning pet pictures, but there's no clear relation.
It might shock me a little just because of the risk/reward if they were just snooping on random people. But not if it was exes/crushes/friends/etc.
I hate the Mail search, because I know it misses all kinds of things. I have to go open up my gmail account in the web browser to find things that I know exist.
From what I heard they did indeed have some LOVEINT problems before that i.e. an employee couple with a nasty breakup - but they were also orders of magnitude smaller.
Is this supposed to be comforting? "without a business justification" means that if there is business justification (e.g. more revenue) they will violate privacy.