Patriot Act Haunts Google Service 277
The Globe and Mail has an interesting piece taking a look at Google's latest headache, the US Government. Many people are suddenly deciding to spurn Google's services and applications because it opens up potential avenues of surveillance. "Some other organizations are banning Google's innovative tools outright to avoid the prospect of U.S. spooks combing through their data. Security experts say many firms are only just starting to realize the risks they assume by embracing Web-based collaborative tools hosted by a U.S. company, a problem even more acute in Canada where federal privacy rules are at odds with U.S. security measures."
Not just Canada... (Score:4, Informative)
Unbelieveable! (Score:5, Informative)
Horror of horrors.
Re:Not just Canada... (Score:3, Informative)
You could replace the word "Google" in that sentence with the name of any other company. You can't just randomly give out personal data to anyone if you're following UK law.
If it's part of doing business and done properly, you can do it. It's standard that when the recipient is an American company there is a "safe harbour" agreement that requires they follow the provisions of the Data Protection Act.
The question is, do crazy US laws make it impossible for US companies to respect the privacy of their customers?
Probably. Ho hum.
Re:VIRUS ALERT (Score:5, Informative)
In-Q-Tel (Score:3, Informative)
Re:Unbelieveable! (Score:2, Informative)
I could accept the argument that "processing your private emails to better qualify my search engine results" could be considered "harvesting" but I wasn't aware that Google in any but the weirdest and most remote sense "sold" the information they collected.
Yes, they effectively "sell" the results of the analysis of what they collect, but that is not the same thing at all.
Otherwise I've got this "analysis" of 100tons of Pure Gold I'd like to sell you, bargain prices
Re:Don't keep logs (Score:5, Informative)
Ok, how naive are you?
Websites keep logs largely to trace attacks, don't they?
That's one element of it, but for most sites its a minor element. Most sites keep logs to trace where users are going, how they are using the site, etc.
Most site-admins are interested in where users are going on the site, how they get their, where they leave, how they arrive, how long they spend on each page, etc. They want to know which pages are popular, they want to know at which stage people usually abandon their shopping cart, etc, etc.
They generally want to make the site more effective, and logs (and analysis of those logs) are a primary tool.
Google, of course, being an ADVERTISNG company first and foremost, is further interested in logs in order to generate profiles, to attach your surfing habits to demographics. They want to know how old your are, what your interests are, how much you make, your ethnicity, level of education, etc. Now, getting that from one site would be nearly impossible. But when you consider that every site that has 'ads by google' on it, is doing its best to track you, they actually CAN get a lot of that information with a high degree of accuracy.
These logs are valuable. If they develop a new algorithm to extract new information they can run it against their logs and pull out that additional information.
And with google its not just -logs-, its content. Google apps like gmail, groups, documents, maps, store your content. So now they have your content (your email messages, your text documents and spreadhseets + a good chunk of your browsing history, possibly including what you've bought online... or at least what you've added to shopping carts, etc.
Google isn't in business to provide you with free useful applications. The value to google of google docs and gmail is to be able to data mine the content to generate profile information.
Can't they have a standard EFF-approved `we keep logs for 24 hours` policy, after which time they're removed permanently?
Even if they -would- delete your logs after 24 hours (They won't without a huge fight.) that still doesn't address the issue of google hosting (and data mining) your content, not to mention the risk they might turn it over to the us government if they ask.
Re:Unbelieveable! (Score:5, Informative)
The issue here is not with users voluntarily using Google services (search, gmail, etc.). Rather it is with companies who want to outsource their data needs to Google. In addition to the visible public products that Google has, it also offers corporate solutions: for instance if a company wants to outsource their email system, or have Google run search and collaborative software for use inside the company.
Google is trying hard to make these new kinds of products work. But unfortunately U.S. laws mean that any data that ends up on Google servers can be snooped by U.S. authorities. Many companies don't like the idea that the U.S. government will have such broad access to their data. In many countries where strong privacy laws exist (Canada, U.K., etc.), allowing the data to be managed by a U.S. company would then actually be illegal--since the company couldn't guarantee integrity or privacy of the data.
The end result of this is that Google is at disadvantage in the global marketplace because of the over-reaching U.S. laws. Google isn't the only one, of course: I'm sure U.S. companies have been losing lots of contracts because international businesses are wary of storing or moving data through U.S. systems since it is now well-known that such systems are not immune to U.S. government monitoring or interference.
Re:Don't keep logs (Score:5, Informative)
Google wants to play nice in Asia, the NSA upgrades in Hawaii.
http://cryptome.org/google/kunia-us.htm [cryptome.org]
Re:Huh?! (Score:3, Informative)
Re:Not good enough (Score:5, Informative)
You sir... are correct. (Score:2, Informative)
While Lakehead is not the only university (Arizona State is another education institution which uses Google AppsEd), it has the distinction of being a _Canadian_ university.
Arizona state already has its email server fall under the purview of the Patriot act, as it is in the US. Lakehead is in Ontario Canada and thus has troubles with the legality of following both Canadian Law, and US federal law. In the specific interest of privacy the two laws do not mix. Lakehead has a legal (and moral) obligation to protect the privacy of it's students, however by using the GoogAppsEd they knowingly violate this...
HOWEVER
Students and faculty _do not_ need to use GoogAppsEd. Gmail is a parallel service to their old email servers which are hosted in Canada.
So there is a choice... use the old shitty server OR relinquish your privacy (somewhat... its not like the FBI is selling your info to spammers, they just might treat you badly when trying to enter the US... which is their right when you think of it).
A better solution is for Google to start hosting Canadian email addresses in Canada so that Canadians do not have to submit to US Federal law... which many Canadians feel is unjust in many ways (we have our own laws that we bitch about... we dont need yours too).
BTW another solution is to encrypt your email... if the US border patrol picks you up for what you write in your encrypted email, well you can now alert major media that the US has methods of defeating modern accepted encryption techniques (do they really want to be outted?)
Anywho... my point is. You are correct, Google should move services to Canada.
Re:You sir... are correct. (Score:3, Informative)
This could work (Score:5, Informative)
I agree that exposing the extent of this could definitely help. When I received multiple FBI subpoenas in 2004 for Insecure.Org [insecure.org] web logs, I notified Nmap users [seclists.org] and it was posted to various web sites, including Slashdot [slashdot.org].
After all of that press four years ago, the subpoenas stopped and I haven't received another one since. Maybe it is just a coincidence, but I'm happy about it nonetheless.
In other Nmap news, version 4.60 was just released [seclists.org]. You might want to download it with Tor though, just to be on the safe side in case the subpoenas resume :).
-Fyodor
Re:Not good enough (Score:5, Informative)