Slashdot Mirror


Google Says It Mistakenly Collected Wi-Fi Data While Mapping

Even if Google says there's nothing to worry about, newviewmedia.com writes, the company "said it would stop collecting Wi-Fi network data from its StreetView cars, after an internal investigation it conducted found it was accidentally collecting data about websites people were visiting over the hotspots. From the WSJ article: 'It's now clear that we have been mistakenly collecting samples of payload data from open [i.e. non-password-protected] Wi-Fi networks, even though we never used that data in any Google products.'"

13 of 215 comments (clear)

  1. Hey, by Threni · · Score: 5, Insightful

    they're not called `open networks` for nothing. Tighten up, or shut up. Oh, and postmen read your postcards too.

    1. Re:Hey, by marcansoft · · Score: 4, Insightful

      It's not a man-in-the-middle attack. They were probably just capturing all WiFi traffic in order to search for hotspots, but forgot to filter it so only beacon frames were stored. A proper set of cards sniffing are much more effective at detecting faint hotspots than just mashing on the "scan" button on one card, which probably discards stray beacons.

      It's your fault if you're broadcasting your data all over the airwaves unencrypted where anyone with a passive receiving antenna can pick it up.

    2. Re:Hey, by tomhudson · · Score: 3, Insightful

      The article indicates that the original software was expressly written with logging capability. They somehow "forgot" to remove it. And nobody noticed. For three years!?!

    3. Re:Hey, by tomhudson · · Score: 3, Insightful

      They were storing the payload for the last 3 years. Three years, and NOBODY noticed? Nobody said "is this even legal in all the places we operate?" Nobody said "Can this come back and bite us on the ass?"

      3 years is a long time to "accidentally" be doing something when it's your profession.

    4. Re:Hey, by Ganthor · · Score: 4, Insightful

      OK Here's my view. Flamebait or not.
      Google have repeatedly demonstrated some sketchy regard for privacy of others. They have to be dragged kicking and screaming to implement procedures that allow people to remove street view pictures for example.

      I agree that in pushing the envelope that they will come across some interesting social topics like the ones that they found in the first run of street view and the one they are back peddling now. And I do believe in the large amount of good Google have done for open source and data use for the public good, (Google earth and maps for instance).

      However Google repeatedly are coy whenever they think about collecting information and get asked for explanations on what they will be doing with it.

      In this instance I read a BBC article that indicated that the German government asked to review the data and that's when Google "discovered" this "gaff". It wasn't Google unprompted..

      What makes even more sobering reading is Google's own blog which admits they were intending on collecting wi-fi SSID's and MAC addresses.
      http://googleblog.blogspot.com/2010/05/wifi-data-collection-update.html
      For what purpose, I ask, would MAC addresses be collected?

      However officially Google now admit to collecting snippets of payload data which is something they expressly ruled out in the original blog. They say this was a mistake...I have my doubts.

      Think it through...They are collecting this data ... the data is 3 years old....did they just sit on it and do nothing with it?
      Surely when they started extracting the SSID's and MAC's, they would've noticed the snippets of people emails and websites they also captured...surely the tested the code and the data collected? And then what did they do...Nothing! They didn't exercise any moral judgment and raise the issue of people's privacy on unencrypted networks. They have the platform they could have won some serious brownie points by telling people how to protect themselves. But did nothing. I don't believe they held all this data and didn't know what it was.

      This is yet another example of a "mostly good" company collecting peoples personal data for reasons us mere mortals can't understand.

      I think there is a real difference between data that is public to your neighbors and then someone posting that data on a billboard in the the main street. For instance, when I'm on holiday perhaps?
      Clearly here is an example of data that is not private, in the public domain but is not intended to be distributed to strangers. That level of privacy is not covered by the current laws but needs to be in my opinion.
      I could go on but I recon half the people who started reading have stopped already;-), ... suffice to say, I'll be doing less of my searches with Google as a direct result, and ensuring my network is buttoned up even tighter the ever.

    5. Re:Hey, by khchung · · Score: 4, Insightful

      So I assume you would be OK if Google told you their street view cars also contained sensitive microphones, which just happened to record some dirty jokes you told your friend on the street? And now everyone can get on the street view, see your (blurred) image and click "hear recordings" to hear your dirty joke too, you would be OK with that too? After all, whatever you did in public should be ok to be publicized, right?

      Seriously, if you don't think there is something wrong with collecting local and transient data and putting them into a big permanent database correlating with other data, by a private corporation that is best known to profit from large scale datamining, you just haven't thought deeply about the issue.

      --
      Oliver.
    6. Re:Hey, by the_womble · · Score: 3, Insightful

      Entirely believable. No one looks at code if its working OK.

  2. I use Google a lot but... by Mordok-DestroyerOfWo · · Score: 3, Insightful

    How in the heck do you "accidentally" gather information over a wireless network? If all you want is a collection of AP's that's one thing, but any storage of packet data no matter how temporary cannot be considered an accident. It has to be planned out and executed. An accident is stubbing my toe on the nightstand, this is an invasion of privacy.

    --
    "Never let your sense of morals prevent you from doing what is right" - Salvor Hardin
  3. Sounds like my daughter when she was 6 by Locke2005 · · Score: 5, Insightful

    Me: "Why are there drawings all over the wall?!?"
    Her: "It was an accident! I didn't mean to do it!"

    --
    I've abandoned my search for truth; now I'm just looking for some useful delusions.
  4. Re:Shenannigans! by Anonymous Coward · · Score: 5, Insightful

    Yeah you do. When you say "Hey, let's see what open wi-fi stuff is out there", and tune into those signals, you pick up on some spare traffic...and if you're saving every packet you come across for later processing (like 'what open wi-fi router was this'), then yeah, it's going to get saved like the rest.

    Then they looked at the data they'd saved, said "Oh hey we didn't mean to get that stuff". Kind of like if you're logging all data that someone sends when they're connected to your open Telnet port, and you realize later that it saves their username/password along with the rest--it wasn't a conscious decision, you might not have thought about it at all, you might never plan to even look at the logs except in some specific cases, and while a workaround might take some time...you kind of drop a brick when your legal team realizes you have it.

  5. Re:Google is great and all... by Dirtside · · Score: 4, Insightful

    As far as I can tell, Google posted this message without being forced to by any government. Most companies would keep this kind of thing quiet, or lie about it, especially if privacy advocates got wind of it. Google, within a few days of finding out about the issue, posts an APOLOGY for doing something that MIGHT have possibly damaged a few people, IF the information they collected had been leaked.

    Unless we have reason to believe otherwise, Google screwed up, and as soon as they were aware of the mistake, took steps to rectify it and then went public about the mistake. If we get evidence that Google is lying about this, that's another story, but has there been any such evidence yet? I'm all for raking corporations over the coals when they make mistakes and don't own up, but how often do you see a giant corporation blurting out "mea culpa" like this?

    Also:

    As much as I like Google I hope they get the book thrown at them over this. To claim that they have accidently been collecting this data for three years is just silly.

    It's not remotely silly. A week ago I discovered a DB table at my (multinational media conglomerate) company that had been silently logging data for -- wait for it -- three years. It wasn't any personal info, or data we needed, but everyone had forgotten about it. The idea of Google making a similar mistake is not "silly" at all.

    --
    "Destroy science and religion. Science would re-emerge exactly the same; but not religion." - Penn Jillette, paraphrased
  6. Re:Google is great and all... by FriendlyPrimate · · Score: 3, Insightful

    I respectfully disagree. If they're telling the truth (and I have no reason to believe that they're not), then they didn't even realize they were collecting this information. They did not use it for monetary gain.

    If anything, this gives me more respect for Google, since they did not have to reveal this information (they could have indefinitely stonewalled...there's no external evidence that they kept this data). They're willing to admit when they do something wrong. That scores points in my book. Kudos to Google.

  7. Re:How would they notice? by eln · · Score: 3, Insightful

    The idea that a large company like that would embark on a huge project like StreetView without thoroughly auditing the code they planned on using boggles the mind. Either they didn't carefully audit the code before deploying it in their massive global project or they did and knowingly collected this data. I'm not sure which of those options makes Google look worse.