Posted in Shoddy Security, War on Privacy

How fitting: The NSA has been *pretending to be Google* in order to covertly capture user data

There’s no low the NSA won’t stoop to in order to snoop:

[I]n some cases GCHQ and the NSA appear to have taken a more aggressive and controversial route—on at least one occasion bypassing the need to approach Google directly by performing a man-in-the-middle attack to impersonate Google security certificates. One document published by Fantastico, apparently taken from an NSA presentation that also contains some GCHQ slides, describes “how the attack was done” to apparently snoop on SSL traffic. The document illustrates with a diagram how one of the agencies appears to have hacked into a target’s Internet router and covertly redirected targeted Google traffic using a fake security certificate so it could intercept the information in unencrypted format.

Documents from GCHQ’s “network exploitation” unit show that it operates a program called “FLYING PIG” that was started up in response to an increasing use of SSL encryption by email providers like Yahoo, Google, and Hotmail. The FLYING PIG system appears to allow it to identify information related to use of the anonymity browser Tor (it has the option to query “Tor events”) and also allows spies to collect information about specific SSL encryption certificates.

GCHQ, for those who don’t know, is the British equivalent of the NSA.

So much for Google’s security measures. Forced SSL may deter petty man-in-the-middle attacks from amateur hackers, but it doesn’t shield anyone from the likes of the NSA.

This isn’t to say that SSL is useless and shouldn’t be used. HTTPS is better than HTTP. But if Google was serious about security and protecting its users, it would make Gmail like Hushmail, offering the ability to encrypt entire user accounts and encrypt messages. There are enough Gmail users that offering encryption by default would have an immediate and huge effect on email security.

But, of course, if Google were to offer such encryption, it would no longer be able to read its users’ emails and place targeted ads within Gmail. Messages would be scrambled and unreadable by Google’s algorithms. So Google is never going to do what Hushmail does. It would interfere with their ability to offer “free” Gmail.

Posted in War on Privacy

Google tells court that Gmail users have no legitimate expectation of privacy

At last, the truth is starting to seep out of Mountain View:

In a stunning admission contained in a brief filed recently in federal court, lawyers for Google said people should not expect privacy when they send messages to a Gmail account. Consumer Watchdog said today that people who care about their email correspondents’ privacy should not use the Internet giant’s service.

Google’s brief said: “Just as a sender of a letter to a business colleague cannot be surprised that the recipient’s assistant opens the letter, people who use web-based email today cannot be surprised if their emails are processed by the recipient’s [email provider] in the course of delivery. Indeed, ‘a person has no legitimate expectation of privacy in information he voluntarily turns over to third parties.’”  (Motion to dismiss, Page 19)

Consumer Watchdog has posted the motion to dismiss in its entirety here.

The admission is stunning in the sense that it contradicts the facade on privacy Google has long tried to publicly maintain. Worker bees at Google have tried to paper over statements by the likes of Eric Schmidt about the company policy being to get “right up to the creepy line” but not cross it. Google claims users are always free to leave, and it has a project called the Data Liberation Front, which is intended to facilitate allowing Google users to take their data somewhere else if they choose.

In response to Consumer Watchdog’s unveiling of the court filing, Google said:

We take our users’ privacy and security very seriously; recent reports claiming otherwise are simply untrue. We have built industry-leading security and privacy features into Gmail — and no matter who sends an email to a Gmail user, those protections apply.

Sure. And we here at LGB always take Google at their word!

Seriously, though, if that’s the case, what’s with the court filing then? As John Simpson says:

“If they take privacy seriously, then they must amend their brief and stop reading and analyzing the content of email we send to their system,” said Simpson.  “If Google stands by the claim of no expectation of privacy it asserted in the court filing, they cannot claim to respect users’ privacy. These two claims are obviously incompatible.”

Or are they? Google is such a behemoth now that perhaps the legal department isn’t always acting in concert with the public relations and marketing division. It certainly appears that the position Google has taken in court was not one that the marketing division is comfortable representing to the public. And no wonder: it undermines all the false and misleading claims Google has made over the years about user privacy in its offerings, Gmail included.

Posted in War on Privacy

Google touts tighter integration between Gmail, Search, Drive, and other offerings

Everything shall be indexed! Quoting from an announcement made today by Google:

Ever had trouble checking your flight’s status on the go because it meant digging through your email for the flight number? Or wanted to just quickly see whether your package would arrive on time, without having to look up the tracking info first? You’ve told us it would be much easier if you could skip the fuss and just ask Google.

Soon you’ll be able to find this info instantly in Google Search if it’s in your Gmail, Google Calendar or Google+. For example, just ask or type, “What’s my flight status?” or “When will my package arrive”?

Over the next several days, we’ll be rolling this out to all U.S., English-speaking users on desktop, tablet and smartphone, with voice search (so you don’t have to type).

The announcement should have – but did not – go on to say: And we won’t ask your permission, either. We’re just going to do it, because that’s how we roll here at Google. Your privacy is not important to us. Your data is. At Google, we view *you* and your personal information as our most important asset, and we are constantly working to monetize *you* so we can bolster our bottom line. Ain’t data mining grand? Think about all the money we can make with your cooperation!

We foresaw this kind of integration by default across Google’s offerings years ago. Google claims, of course, that this is a “pro-user” change. But they’re really just offering up excuses for imposing new defaults on everyone. If you don’t like personalized search, you have to opt out or sign out, because if you do nothing and you have a Google account, the Big G will mine your data to its heart’s content.

 

Posted in Menacing Monopoly, War on Privacy

Google reportedly working on launching music streaming offering

Google is reportedly developing an offering to compete with the likes of Spotify and Rhapsody, because its cyber empire simply isn’t big enough:

Dear Spotify, Rhapsody and any other music-streaming service out there: Here comes Google.

The Wall Street Journal and now Bloomberg are reporting that Google is planning to launch a worldwide music streaming service in Q3 of this year. Google is reportedly talking to music companies about licenses for the service, which mimics that of Spotify.

Record labels currently have a strained relationship with Google because they believe Google acts as a gateway for sites where people can connect to swap tunes without paying royalties to the labels. It will be interesting to see if Google can come to terms with the industry’s few remaining major players. At this point, except for the independent labels, the music industry is a triopoly – it’s just Universal, Warner, and Sony. (EMI was subsumed by Universal and Sony).

Executives at Google seemingly feel the need to compete in every product category with every other major technology company, and they have tried to grow the Google empire through acquisitions in addition to product launches. In recent years, Google has attempted to buy many of the emerging players in Silicon Valley, including Twitter, Facebook, Yelp, and the now-struggling Groupon. All of those companies walked away from Google’s offers and overtures, forcing the Monster of Mountain View to launch its own offerings (including Google+, Google Offers, and Google Places).

A music streaming offering is just another way for Google to increase its treasure trove of user data. Google wants people to keep people on its properties, and its executives think it can best do that by having an offering for everything.

Posted in Menacing Monopoly, War on Privacy

Brazilian newspapers pull out of Google News

All of the major newspapers in Brazil have just quit Google News en masse:

Brazil’s National Association of Newspapers says all 154 members had followed its recommendation to ban the search engine aggregator from using their content.

The papers say Google News refused to pay for content and was driving traffic away from their websites.

Google said previously that the service boosted traffic to news websites.

“Staying with Google News was not helping us grow our digital audiences, on the contrary,” said the association’s president, Carlos Fernando Lindenberg Neto.

“By providing the first few lines of our stories to Internet users, the service reduces the chances that they will look at the entire story in our websites,” he said, in an interview with the Knight Center for Journalism in the Americas.

Though we’re not fans of Google, we fail to see exactly what these newspapers are trying to accomplish by pulling out of Google News. Google News is really just a twist on regular old Google search itself. The difference is that Google News draws its results from media sources instead of the larger Web. Essentially, it’s a filter that can be used to find recent content written by journalists and commentators.

Google News may not have been doing much for Brazil’s newspapers, but it’s very unlikely it was hurting them. The purpose of search engines is to help people find content on the Internet. While it’s true that Google has or is developing offerings intended to monopolize users’ time and attention (such as YouTube), Google News is more like regular old Google than YouTube. If Neto’s group believes that search engines reduce the likelihood that people will read newspapers online, they should be pulling out of Google altogether, not just Google News. But they haven’t, because they don’t want to lose the traffic.

Rather than delisting themselves from Google News, what the newspapers should do is end any participation in Google’s AdSense network. The papers should take charge of their own advertising so Google doesn’t get a cut of that revenue. That would be a sensible thing to do.

We allow Google to index this site because we want people who happen to be using Google to be exposed to criticism of the company. Google’s search engine has problems, but that’s small potatoes compared to the consequences of using offerings like Android, Gmail, Docs, and Drive. Those “services” collect and store a great deal of personal and sensitive information. Google’s search engine does log queries, but it is possible to use Google anonymously through tools like Google Sharing (which we recommend for people who can’t bring themselves to use an alternative like Blekko as their primary search engine).

Posted in War on Privacy

Google reportedly on the verge of making deal for facial recognition software

Google executives have publicly admitted on a couple of occasions that they have held back from introducing facial recognition technology into the Monster of Mountain View’s products, presumably because doing so would be an embarrassingly obvious jump over “creepy line” former CEO Eric Schmidt says the company avoids trying to cross (in order to prevent there from being a big public and regulatory backlash against Google). But that hardly means the company isn’t working on developing extremely invasive technologies behind the scenes, as this update from CNET shows:

Google is close to completing its deal to buy Viewdle, a Ukrainian maker of facial recognition technology that automatically tags photos, according to a person familiar with the deal.

The acquisition, which has been in the works for more than a year, is expected to close this week, the person said.

Representatives from Google and Viewdle declined to comment.

The move makes sense for Google because Viewdle’s technology provides a way for users of Google+, Android, Picasa, and other services on a range of devices to easily (even, automatically) tag photos of friends. Viewdle’s SocialCamera app automatically tags Facebook friends and the company has released an Android game called Third Eye.

Facebook also has made a play in this space, earlier this year buying Face.com along with its Photo Tagger auto-tagging app.

The reason Google and Facebook are so interested in facial recognition technology is that they want to be able to add faces to their rapidly growing databases, which contain profiles of millions of people. The companies already have access to a treasure trove of sensitive information, including names, phone numbers, addresses, credit cards, interests, relationships, and so forth. But they want more. The ability to associate photos of people with their profiles could be very lucrative.

Posted in Legal Troubles, War on Privacy

FTC hits Google with record $22.5 million fine

The Federal Trade Commission (FTC) announced today that the Monster of Mountain View has agreed to pay a fine for violating the terms of its earlier privacy accord with the agency from two years ago. Google is not admitting to any wrongdoing:

The Federal Trade Commission fined Google $22.5 million on Thursday to settle charges that it had bypassed privacy settings in Apple’s Safari browser to be able to track users of the browser and show them advertisements, and violated an earlier privacy settlement with the agency.

The fine is the largest civil penalty ever levied by the commission, which has been cracking down on tech companies for privacy violations and is also investigating Google for antitrust violations.

Consumer Watchdog criticized the settlement agreement, calling on the FTC to hold Google accountable for its war on privacy.

“While the $22.5 million penalty levied against Google is a record for the FTC, it is woefully insufficient considering that Google refused to admit any liability or wrongdoing,” said John M. Simpson, Consumer Watchdog’s Privacy Project Director.  “The Commission has allowed Google to buy its way out of trouble for an amount that probably is less than the company spends on lunches for its employees and with no admission it did anything wrong.”

One of the Commission’s five members agreed. In a statement explaining why he refused to sign off on the settlement, Commissioner J. Thomas Rosch said the FTC should have demanded – and gotten – more.

[T]his is not the first time the Commission has charged Google with engaging in deceptive conduct. This is Google’s second bite at the apple. The Commission accuses it of violating the Google Buzz consent order by “misrepresent[ing] the extent to which users may exercise control over the collection or use of covered information” and accordingly, seeks civil penalties for those violations. In other words, the Commission charges Google with contempt.

This scenario – violation of a consent order – makes the Commission’s acceptance of Google’s denial of liability all the more inexplicable.

We agree. A $22.5 million fine is nothing to Google. It is hardly going to dissuade the Monster of Mountain View from continuing to wage war on users’ privacy. The FTC should have at least gotten an admission of wrongdoing out of this settlement. They folded too easily.

Posted in War on Privacy

Surprise! Google *forgot* to delete data it was supposed to get rid of under privacy accord

As if we needed more evidence that the Monster of Mountain View keeps everything… even when it has agreed to erase data under a binding agreement with the government:

Google has admitted that it had not deleted users’ personal data gathered during surveys for its Street View service.

The data should have been wiped almost 18 months ago as part of a deal signed by the firm in November 2010.

Google has been told to give the data to the UK’s Information Commissioner (ICO) for forensic analysis.

The ICO said it was co-ordinating its response with other European privacy bodies.

In May 2010 it was revealed that Google had scooped up about 600 gigabytes of personal data from unsecured wireless networks while gathering images and location data for Street View.

The data was collected for years in 30 countries while Google compiled information for the mapping service.

The BBC has more.

This is hardly the first time this has happened, and it certainly won’t be the last, either.

Posted in War on Privacy

New York Times reveals identity of the technological mastermind behind the Wi-Spy scandal

“Engineer Doe” is no longer anonymous:

At the center of the uproar over a Google project that scooped up personal data from potentially millions of unsuspecting people is the company software engineer who wrote the code.

Google has declined to identify the engineer, as has the Federal Communications Commission. The F.C.C. recently closed its 17-month inquiry into the project, Street View, with a finding that Google broke no laws but had obstructed its investigation.

The agency also said it was unable to resolve all the issues it was considering because the engineer — whom it referred to in its report on the inquiry as Engineer Doe — cited his Fifth Amendment right and declined to talk.

Now a former state investigator involved in another inquiry into Street View has identified Engineer Doe. The former investigator said he was Marius Milner, a programmer with a background in telecommunications who is highly regarded in the field of Wi-Fi networking, essential to the project.

Who is Marius Milner? He is a talented engineer who still works for Google (in the YouTube division) and has been referred to by fellow hackers as a god. He developed a Windows-based utility called NetStumbler, popular with wardrivers, which excels at sniffing out wireless access points, including home routers. (A wardriver is a person who searches for wireless networks as a hobby).

Google has been attempting to shield Milner from public exposure, but now that he has been outed by the New York Times, they will no longer be able to do so. Milner has yet to be hit with litigation for his involvement in the Wi-Spy scandal. Google has contended in court that it spying, made possible in part thanks to Milner, was not unlawful and it should not be punished for invading the privacy of millions of people without their knowledge. We urge courts in every jurisdiction to find otherwise.

Posted in Menacing Monopoly, War on Privacy

“GDrive” finally materializes as Google Drive

We’ve long suspected that at some point, Google would launch an online storage offering in competition with Dropbox, Box.net, Microsoft’s SkyDrive, iCloud, and Amazon Cloud Services. And now they have.

Google is taking the wraps off a long-anticipated product that it views as one of its most important launches of the year, as the Internet giant continues its push toward a future in which users’ photos, spreadsheets and other data primarily live on the Internet “cloud” instead of a PC or some other device.

The launch of “Google Drive” Tuesday has been a poorly kept secret in Silicon Valley, with the name and a rough description of the online storage product widely circulated in recent weeks as Google has worked out the final bugs. Drive will open up to millions of users around the world starting Tuesday, allowing them to sync their files between PCs, smartphones and tablets.

Google’s main intention with its new Drive offering, of course, is to take mining of personal information to a whole new level. With Drive, Google is going beyond its existing Gmail, Docs, YouTube, and Picasa offerings, and inviting users to upload pretty much everything they might normally keep on their desktops and laptops to its datacenters. The problematic user agreement Google created for Drive naturally does not provide adequate protections for the privacy and security of the people who use it:

While private files winding up on Google Drive may not be as privacy-protected as the ones on your hard disk, fact is that Google is not granting itself free rein to use personal data. But you’d be hard-pressed to know that given a “toxic brew” of conflicting claims found in the company’s omnibus privacy policy, according to a legal expert who has closely reviewed Google’s policies.

“The language is not drafted nearly as tightly as we would expect from a company of Google’s size and stature,” says Eric Goldman of the High Tech Law Institute. He describes the covenants as poorly written and likely to confuse users by virtue of Google mashing licensing and privacy statements together.

Several companies and media organizations have already warned their employees that Google Drive’s terms of service are problematic, and the offering should not be used.

We agree. Stay far, far away from Google Drive.

MORE FROM ARS TECHNICAGoogle Drive files can end up in ads, even though you still own them