Google Counsel to Arrington Allegation: We Don’t Snoop on Gmail to Find Leakers
recode.net
recode.net
For whatever it's worth, Google is also not Enron. It's not hard to imagine Enron executives saying anything, because Enron was a sham business, "faking it until they made it" or, as it happened, fell off a cliff. Google generates tens of billions of dollars of revenue per year. They have a lot to lose. When Google's General Counsel says something newsworthy, it's not done casually.
Finally: I think it's worth reminding people that the other side of this argument is a person who claims not to have reported on this story until a few days ago because --- despite the fact that the story was immensely relevant to the public interest, and despite the fact that not reporting it put his own sources at grave risk not merely of losing their jobs but of being sued by billion dollar companies --- to have reported it earlier would have risked the bottom line of his own publication. Who are you going to believe?
http://www.wired.com/threatlevel/2010/09/google-spy/
I tend to believe Google's GC and think Arrington is having some paranoid attention-seeking fantasy. At the same time, can some schmoe at Google read a gmail email? It seems like they can.
There are people who can, though that number is small. However even then, the access is highly audited.
The only way around it would be to just steal a disk, I think. That's why you can't take any hardware in to or out of one of the data centers.
As far as I can tell, a site reliability engineer is a very common position.
"Google Engineer Fired for Accessing Teens' Gmail, Chat Logs" http://www.pcmag.com/article2/0,2817,2369188,00.asp
They went on to say this: "While our terms of service might legally permit such access, we have never done this [opened email messages in Michael Arrington's Gmail account to investigate a leak] and it’s hard for me to imagine circumstances where we would investigate a leak in that way."
> Who are you going to believe?
Technically, neither contradict the other. Considering who they are and what they are, technicalities matter, I think.
> “Mike makes a serious allegation here — that Google opened email messages in his Gmail account to investigate a leak,” Kent Walker, Google general counsel, said in a statement.
and
> “The source had corresponded with me from a non Google email account, so the only way Google saw it was by accessing my Gmail account,” wrote Arrington. “A little while after that my source was no longer employed by Google.”
Arrington declined to comment.
See, you don't need to actually open the email to see if a correspondence occured.
At least that was the first thing I thought when I read the article. But of course, we'll probably never know. And I agree with you that we shouldn't jump to conclusions, it's just a possibility.
Should they get caught I doubt there will be a fall out. They can go the NSA route: It was just metadata.
Ignoring that is 3 layers of hearsay, there are multiple ways Google could have received that email without checking the Gmail account.
If I'm comparing the veracity of Kent's blanket denial vs. Mike A's hypothetical well-maybe-they-did (which could be satisfied through multiple alternative methods), well, that's an easy call.
The definition of this in context:
> that Google opened email messages in his Gmail account to investigate a leak
So that's not a blanket denial. Mike accused them of "accessing my Gmail account". Which Kent explicitly rephrased to "that Google opened email messages in his Gmail account to investigate a leak".
That's pretty narrow in my books.
Ok, let's assume, it's only written like that as an accident - so surely they will change it right away, so it doesn't say that anymore, right?
But I doubt they will. I really hope Google intends to add end to end encryption to Gmail, as least as an obvious option (UI wise), if not by default. Otherwise, I'm moving away from Gmail as soon as such a simple solution comes up.
Wait a minute, this is not the kinder garden. When a company's motto[1] is "Don't be Evil"[2], I expect them to live up to certain standards. Not specifically lying in the real world is exactly the same as not saying anything when something unacceptable happens (Talent poaching agreements, PRISM, Privacy infringements, Tax evasion, etc.). So either you are soliciting a situation (Poachign agreements) or take part in a privacy breach (PRISM), you're in both cases equally responsible in a social frame. We can argue about your share of responsibility (and Google's is big, because they are BIG kids, know and understand repercussions of their actions), but either way you're guilty.
Also keep in mint that to prove any allegation against Google or any other company of the caliber it takes a lot of resources. How many people or companies actually DO have these resources? Only organizations like the EFF try to figure out if/what/when happens and even these organization can't really perform any real inspection.
After PRISM, whatever Google/Apple/MS says, it makes sense to take their words with a grain of salt.
[1] A motto (derived from the Latin muttum, 'mutter', by way of Italian motto, 'word', 'sentence'; plural: mottoes (always listed first) or also mottos) is a phrase meant to formally summarize the general motivation or intention of a social group or organization.
"The source had corresponded with me from a non Google email account, so the only way Google saw it was by accessing my Gmail account."
No, that's not the only way Google could have seen this email. It could easily have leaked via the non-Google email account: The employee could have (intentionally or accidentally) forwarded the email to their work account. Or they could have sent it or accessed it unencrypted from a Google internal network. They could have also sent the email to someone else who passed it on to Google. And so on.
Yes, these are all stupid mistakes that your careful, tech-savvy leaker shouldn't make, but people make mistakes like them all the time. And I wouldn't expect an inebriated leaker to make a point of mentioning whatever stupid mistake they might have made (if said leaker even realized where they went wrong).
This is the most likely scenario. If you are using a shared network administered by someone other than you, you should assume nothing about privacy or secrecy.
If I were a Google employee I'd be pretty interested in getting answers as to how they acquired this information, and to advocate to change internal policies if this was the case.
It also makes me think twice about ever working for an organization where I don't have root on the devices I use.
Just about every company in America will assert the right to do whatever they want with the traffic from any device you use on their network.
I have a relevant anecdote. When I was an intern at Facebook, during one of the university relations event that was of a "hackathon" genre, I was creating with my friends a multiplayer web game that was using websockets for communication. The guest wi-fi network wouldn't let packets between different machines connected to it go through, so we decided to just tunnel all traffic to my laptop (the game server) through AWS using ssh tunnel.
It took only a few minutes for network security people to contact me, asking what's this big encrypted transfer to AWS all about, and mind you, it was Saturday evening.
Arrington couldn't conceive of any other way Google could get the mail, so he's "nearly certain" that Google read his Gmail.
Even assuming his drunken source was accurate and truthful, there are in fact many legitimate ways Google could have obtained the information.
Arrington's accusation is just reckless and irresponsible.
(That link isn't working, for whatever reason, so I'm just assuming it's the same case that I'm thinking about)
"• This article was amended on 20 March 2014 to remove statements in the original that the testimony by Rajesh De contradicted denials by technology companies about their knowledge of NSA data collection. It was also updated to clarify that the companies challenged the secrecy surrounding Section 702 orders. Other minor clarifications were also made."
They may have updated their article to excise the denials about PRISM - however the water is still muddy regarding the truthfulness of their statements under numerous other programs that the NSA has conducted under other legal authorities like Section 702, Section 215, etc..
For show?
Amongst other things, it makes NSA tapping of fiber in front of their datacenters less useful. It also makes switches that replicate traffic to NSA less useful.
The http/https question is completely irrelevant to the PRISM-complicity question. I'm not sure why you brought it up.
The right to snoop through your email is the problem (the algorithmic searching to place ads I can understand some people finding annoying but that is the bargain for using Gmail - it isn't that I am talking about - it is the snooping for whatever purpose Google has for reading your emails by a person at Google).
That you promise to not do what you give yourself the right to do is not worth much of anything. I don't imagine this lawyer would sign off on legal contracts that had bad clauses that the other side said "no, leave the contract the way it is, just trust us to not ever use that clause."