Google Releases Project Shield To Fight Against DDoS Attacks (thestack.com)
An anonymous reader writes: Google has launched a free tool to help all media sites and and other organisations protect themselves against Distributed Denial of Service (DDoS) attacks. The Project Shield initiative allows websites to redirect traffic through Google's existing infrastructure, in order to keep their content online in the face of such attacks. Google will aim to work with smaller sites which do not necessarily have the money or are not fully equipped with strong enough infrastructure to the attacks. However, the Shield tool has also been made available to larger outlets, such as popular news sites and human rights platforms.
Nothing is free citizen.
Seriously, the size of some of the DDoS attempts is massive. That's a lot of bandwidth wasted, and there will be a dollar impact associated with this. What additional angle will google be targeting to make money off this?
Remove tin foil hat and read the story.
"“Project Shield only uses the data we obtain (such as logs from the Project Shield servers) for DDoS mitigation and caching and to improve the Project Shield service,” the company added."
Seems like they are aware of what people might worry about and have posted a policy statement to put people at ease.
See my blog http://ilovecookes.blogspot.com/ for light hearted technical information.
From the engadget/Wired article ...
"To use Project Shield, a site has to give Google visibility into who's visiting -- something likely to rankle the company's privacy critics. But Google says that it'll only keep logs for two weeks, after which the data will be stored in aggregate and used to learn more about attacks. The company also notes that the data it collects won't be used in its advertising programs."
The company also notes that the data it collects won't be used in its advertising programs. [But by using Project Shield you and your agents and seven generation of your children's children agree and that we can change the Terms and Conditions of use, in a 64 page-long document of legalise, that only 1 in 100 people will ever read and/or notice, at any time.]"
DaveyJJ
More information for them to mine, which is what they really crave.
From https://support.google.com/pro..., emphasis mine:
What data does Project Shield collect?
We collect traffic metadata and cached content for website traffic passed through Project Shield. This helps us detect and defend against DDoS attacks.
We also ask for your website’s configuration data — your website's origin server, domains, and subdomains — to set up Project Shield. We hold on to this for as long as you have an account with Project Shield. You can delete your Project Shield account at any time.
Data and web traffic may be processed and stored in the US or other countries.
How do you use my website and website visitors’ data?
Project Shield collects web traffic logs, and other data on how we serve your traffic, to help improve Project Shield's service and performance.
Project Shield does not collect data to improve search results or target advertising.
Does Google’s Privacy Policy apply to visitors to my website?
No. Your website’s own policies and terms of service — including how you manage user data and privacy — apply to people visiting your site, not Google’s privacy policy and terms of service.
Can people tell that I’m using Project Shield?
Yes. Domain Name System (DNS) records are public information and will show that you are pointed at Project Shield servers. When you set up Project Shield, you point your traffic at Project Shield servers. Anyone can use a public website to look up your DNS records and see what IP address or host name your website points to.
For now, until users get comfortable with the service. Once it gains traction they will be re-writing the terms and conditions.
Want to bet? Seriously, care to put money on that? I'll take that action in a heartbeat, assuming we can work out a way to do it.
Also just because a company has a policy, doesn't mean there isn't someone violating it behind the scenes
Pursuant to the consent decree signed after the Buzz fiasco, the Federal Trade Commission regularly audits Google to verify compliance with the terms of the decree, which includes compliance with Google's publicly-stated privacy policies. It would be very, very risky for Google to do anything to violate those terms.
Google also applies strictly-limited and closely-audited access controls on all such data, so it's virtually impossible for a "rogue" employee to do what you describe without approval from both his or her own manager, and from a separate organization that is tasked with monitoring and minimizing access. Attempting to bypass any of these controls is both very hard and is a firing offense.
(Disclosure: I'm a Google engineer. Security is my gig, not privacy, but the two overlap a bit so I see a lot of what goes on around privacy.)
Does anyone know how this differs from Cloudflare?
FWIW, I'm using Cloudflare on several of my sites, and it's been extremely useful so far.
I'd love to see a comparison between Shield and Cloudflare, especially any features that one might have that the other doesn't.
Just cruising through this digital world at 33 1/3 rpm...