Google Search

Showing posts with label Googles. Show all posts
Showing posts with label Googles. Show all posts

Tuesday, October 22, 2013

“Nej till Google!” – Sweden tells a local council that Google’s cloud is a no-go area

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Swedish bureaucrats have instructed a town in the Scandinavian country to say "No" to Google.

Salem, a municipality approximately 30km south-west of Stockholm, wanted to ink a deal to use Google Apps, but the Information Commission thought otherwise.

When I first spotted this story, my immediate thought was that it would have something to do with PRISM.

If you haven't been following computer security news lately, that's the USA's controversial programme to conduct widespread network surveillance of foreigners.

You can see why overseas jurisdictions might want to discourage their residents from using cloud services offered by companies which are themselves regulated by US law.

But Sweden's broadside against Google has nothing to do with whether the US government does or doesn't have its digital eyes on the cloud storage of non-US residents.

This is an argument directly with Google over its own privacy provisions.

The Swedish data protection mandarins already disagreed with the Municipality of Salem back in 2011, arguing that Google's contractual land-grab over its customers' data "for the purposes of providing, maintaining and improving the services" was a step too far.

The municipality apparently felt that this was reasonable because it would help to improve Google's IT-related services to everyone - in other words, that the people of Salem could tolerate this clause for the greater good of all.

But the Swedish Datainspektionen ordered Salem to renegotiate with Google, on the grounds that the clause was too open-ended to be safe.

The decision noted, amongst other things, that the contract was too loose about how the data might be handled by subcontractors, or by Google after the contract ended.

Salem did go back to the negotiating table, and came up with a revised deal last month, but it still wasn't enough for the regulators, whose decision is that the earlier shortcomings have not been addressed.

So Salem must negotiate again with Google, or find another way to deliver its IT services.

On the surface, this may sound like Nordic bureaucratic pettiness, but I think we should applaud the Swedish privacy experts here.

It's one thing to outsource your own IT services - personal email, blogging, web site, and so forth - to save time and money. That's your own choice to make.

And it's fair enough if you're a company whose customers can vote with their chequebooks (yes, they still exist, at least in Australia!) if they don't like the service provider you've chosen.

But as a "customer" of a local government, you don't have that liberty, so you are stuck with the privacy-related decisions made by your council.

I suppose, as Google's own Eric Schmidt once famously joked, "you can just move, right?"

But that's the same Eric Schmidt who's on the record as having said that "Google policy is to get right up to the creepy line and not cross it."

Let's see if Salem can win the battle to get Google to back off a bit in the next round of negotiations...

Follow @duckblog


View the original article here

Tuesday, December 4, 2012

Accidental data leak helps wipe $22bn off Google's stock value

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Google's cagey. Understandably so.

Google data center

It gave a peek into a sprawling maze of computers in its $600 million data center this week, but wouldn't say how many it has.

Lots, OK? Can't give a number.

Involves competitive advantage, intellectual property. Would have to kill you.

Oh, but wait, you say you want a peek at Google's less-than-stellar quarterly earnings report?

You want that around lunchtime, you say, about 3.5 hours before its scheduled release?

No problem!

Yes, that's what happened to the company that's so scrupulous about data protection that it uses what Wired's Steven Levy calls "a small cadre of engineers" to attack its own infrastructure, popping leaks in water pipes, staging protests outside the gates to distract attention away from intruders who aim to steal data-packed server disks, screwing around with the ad network, and cutting fiber connections to Asia.

That in-house staging of attack scenarios didn't really work.

What did bring down this data giant?

What nefarious, complicated scheme of Mission Impossible-esque ninjas and code crunchers caused the company's earnings to leak out hours early, carving $22 billion dollars from the flanks of Google's stock value, given the company's disappointing third-quarter earnings?

Google's stock price stumbles

Fingers. Fat ones.

It was human error, on the part of financial printer R.R. Donnelly, in whose ranks there exists somebody who now must be getting a stern talking-to, unless the poor sod has already been fed to alligators.

Here's what Google said in a statement after the early release, which caused its stock to plunge 9% before Nasdaq halted trading in the early American afternoon on Thursday:

"Earlier this morning R.R. Donnelley, the financial printer, informed us that they had filed our draft 8K earnings statement without authorization. We have ceased trading on NASDAQ while we work to finalize the document. Once it's finalized we will release our earnings, resume trading on NASDAQ and hold our earnings call as normal at 1:30 PM PT."

Wow. That's certainly a painful example of how accidental data loss can hurt your company.

The third-quarter earnings report was due out after the market closed but was instead published on the Securities and Exchange Commission's website at 12:30 pm ET on Thursday.

As the Wall Street Journal notes, the report wasn't quite ready for prime time - a fact denoted by a spot reserved for a canned bit of verbiage from CEO Larry Page that read "Pending Larry Quote."

Pending Larry quote

Doug Fitzgerald, a spokesman for R.R. Donnelley, told the WSJ that the company is investigating.

R.R. Donnelley's statement:

"We are fully engaged in an investigation to determine how this event took place and are pursuing our first obligation – which is to serve our valued customer."

Cyber attackers might make for more titillating headlines, but this mess-up shows that even a tech superpower like Google can get its shins badly kicked by data leakage caused by simple human error.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Thursday, August 16, 2012

Vote in our poll: is Google's fine of $22.5 million enough to buy privacy?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

An apparently unrepentant Google has agreed to cough up $22.5 million to the US Federal Trade Commission (FTC) to dispose of charges that it "misrepresented privacy assurances to users of Apple's Safari browser."

As with my previous story about Google and its WiFi trawling, we need a timeline summary to keep track (no pun intended) of what's been going on here:

* In February 2010, Google launched Buzz, a social networking application for Gmail.

The launch drew the ire of of those concerned about privacy, and a class action lawsuit arose alleging that Google "automatically enrolled Gmail users in Buzz, and that Buzz publicly exposed data, including users' most frequent Gmail contacts, without enough user consent."

* In November 2010, Google paid $8.5 million to settle the class action.

As we reported back then, Google didn't pay out nickels-and-dimes to each offended individual in the class action, but agreed to put the lump sum "into an independent fund to "support organisations promoting privacy education and policy on the web."

* In March 2011, Google apologised to Buzz users and settled with the FTC.

The settlement included an agreement by Google to implement a comprehensive privacy program that includes privacy and data protection audits by an independent third party every two years for the next 20 years. Google's apology certainly sounded pretty straight-from-the-hip, telling you that:

User trust really matters to Google. That's why we try to be clear about what data we collect and how we use it — and to give people real control over the information they share with us.

* In December 2011, the FTC busted Google using sneaky web coding to bypass Safari's cookie policy.

Briefly explained in a neat technical posting from the FTC itself, Google overrode Safari's cookie controls to bypass the browser's regular behaviour of blocking so-called third party cookies. (That's a cookie which is set by a site other than the original one you visited.)

Google achieved this by creating an invisible HTML form and then using JavaScript to pretend that the user had submitted it. This caused Safari to process the third-party page, and, by extension, its cookies, at the same trust level as the first-party page. The FTC understandably considered this dubious, not least because the HTML form had neither content nor a Submit button.

So much for giving people "real control over the information they share with us."

* In August 2012, Google agreed to pay $22.5 million to the FTC.

The FTC's argument against Google was simple: the company hadn't lived up to the privacy promises it made to its consumers.

And there you have it. What more to say?

Google will cough up $22.5 million for putting sneaky code into its web pages, even after agreeing that it would get comprehensive about privacy.

Nevertheless, according to reports, Google's public response seems unrepentant - or at least unapologetic - and comes close to dismissing the issue as old, tired and unimportant. The BBC, for example, quotes a Google spokesman as saying: "The FTC is focused on a 2009 help centre page published more than two years before our consent decree, and a year before Apple changed its cookie-handling policy."

Optimistically, the BBC goes on to report the comments of Nick Pickles, director of privacy campaign group Big Brother Watch:

The size of the fine in this case should deter any company from seeking to exploit underhand means of tracking consumers. It is essential that anyone who seeks to over-ride consumer choices about sharing their data is held to account.

To be sure, $22.5 million is a lot of money.

But Google already forked out $500 million in August 2011 for helping illegal vendors of pharmaceuticals to place ads on its servers. Not just for taking the scammers' money, you understand, but for helping these "customers" to bypass the controls Google had already put in place to prevent the abuse.

So...is the money enough? Or is Google just treating the penalty as part of its cost of doing business?

Have your say in our poll.


-
Follow @duckblog
-

View the original article here