> The data Google has on you can fill millions of Word documents. > Google offers an option to download all of the data it stores about you. I’ve requested to download it and the file is 5.5GB big, which is roughly 3m Word documents. This link [Google Takeout] includes your bookmarks, emails, contacts, your Google Drive files, all of the above information, your YouTube videos, the photos you’ve taken on your phone, the businesses you’ve bought from, the products you’ve bought through Google …
Well duh, Google stores your gmail emails and Youtube videos and Drive documents and so on! This is the service they're providing you! Google Takeout doesn't give you a 5GB archive of advertising profile or covertly gathered info, it gives you a 5GB archive of the documents you deliberately uploaded to Google services - emails, docs, pics, videos, calendar appointments. The list of Android apps installed on your devices is there so that when you link a new device to your Google account, these apps will be automatically installed on it. And so on.
There's a single link on that list related to surveillance - namely, your Google Ads profile, which only shows very basic data, I'm sure they have vastly more complicated data stored on me.
There's enough genuine reasons to be upset with Google's surveillance, let's not promote this kind of silliness. Google knows which Google Groups you're subscribed to, really? 5GB could fill 3m Word docs - how many is that in Libraries of Congress?
Rest assured that this happens all the time and when people read news about a topic that they are an expert on, they cringe all the time. For example, a paraglider pilot will get triggered if the reporter uses the word "Jumped" in a story about a paraglider pilot who crash-landed and injured two more people. This is because paragliders don't jump but take off from hills etc.
Usually reporting on technical topics is very hard because you need to reach the non-technical audience so you will HAVE TO use illustrative examples and not exactly accurate descriptions so that can be absorbed by the non-technical readers. Unfortunately, this will put you in a position where can be called on by technical readers who are triggered by the "implementation details" of your story.
I do believe that calling out the 5GB illustrative example is missing the point of the article. It's just a way to portray size of the data collected on you, it doesn't have any meaning even if this data was 3Mb or 100Gb. For example, if it was 3Mb Google might have used it to convey how little data they collect on you as if the size that this data takes has any correlation about the impact, then why even bother with such an irrelevant point of the "article implementation"?
I think that's a point to take home. Users know that Google looks at their "location information". In their minds, it's to provide relevant weather info and whatnot. Seeing it aggregated in this way makes you realise that you actually are sending your entire life to Google servers.
However, a counter point: I feel it is useful and helpful to our cause to have authors such as this creating those colorful metaphors. We have tried in vain to communicate to laypeople the importance of data safety, self-ownership of data, being mindful of one's privacy, and being suspicious of the data collected by third-parties. I believe laypeople remain disinterested because the way we raise these concerns is abstract.
In order to convince laypeople that control of one's data is important, those of us who are matter-of-fact on the matter will convey the facts and try to construct fairly mild-tempered plausible threat scenarios that are, frankly, unconvincing to the majority of people we are trying to convince.
For a good chunk of those we're trying to convince, vibrant and (to our minds, exaggerated) illustrations of the magnitude of the threat are what is necessary to tip the scale. The recent twitter thread that showed a map of Ireland with every point the user had been in the past several years was a poignant visual representation of our argument. It made the argument way better than repeatedly saying, "Google tracks your location, always!" When we've presented that abstract point previously, we've heard "I don't care, that's fine" as a response every time.
And then someone shows them this map and suddenly: "Whoa, that is creepy!" Yes!
I for one welcome a bit of colorful language, as long as we don't get totally carried away. I don't really dig the "Well, duh!" attitude if we convey that to the people we're trying to convince. We're trying to make laypeople value their own privacy and feel good doing so. Not judged for having been ignorant of or disinterested in our previous arguments. Be welcoming of this good favor in the fight for data privacy.
Maybe it will stop folks from uploading unencrypted data to cloud providers down the road and improve research that allows cloud providers to process encrypted data meaningfully without every being able to decrypt.
The 3m pages of word doc is odd, but its not uncommon to convert overall size to word doc pages in journalist speech (just map size to average word doc size), and then they disregarding data type. I have seen this in other places too.
What I don't get in all of this debate: People grant FB/Google/any other app access to their data and seriously expect that their data isn't harvested? IMHO, there really is zero surprise that Facebook has your call and SMS history, if you granted access to that. Or every single login timestamp.
What is way scarier is that the dump you can download is probably far from complete. My Facebook dump shows rather few items, because I'm not a heavy Facebook user. But I'm quite sure that they have A LOT more on me, because of friends uploading my phone number, profile pictures, meta data from the WhatsApp acquisition.
The big scary question is: How do you access the data in your shadow profile that they won't give to you? How do you even prove that they have more on you than they admit?
Edit: Same for Google. I don't use a Google account most of the time and I bet they STILL have my entire search history associated to some kind of shadow profile.
when you provision a new android device it will try to link your account to chrone, and its very hard even for a developer to catch its chrome and not android os. after that small mistake (which is an optout in the ui pattern) its game over. google have all your history and every webview ad has your full profile. not to mention your web bank passwords are now conveniently save in google servers in plain text.
and yes, an even worse problem is the hidden data/shadow profile.
If files are in your "trash" they will be included in your takeout. If you clear your trash, they will not be included in your takeout (after a reasonable amount of time, if you "empty trash" then instantly go and make a new takeout bundle it might still be included). It's the same way with spam and email trash. It's given to you in your bundle until you manually fully delete it.
Implying they keep everything you ever deleted is wrong.
Edit: I don't want to get into hypothetical arguments about what Google could possibly be doing. I'm simply saying that the reason the author had "deleted" things in their takeout archive was because it was most likely in their "trash" and wasn't fully deleted in the UI. And that "things in your trash folder are included in your takeout bundle" isn't "proof" that they never delete anything.
I feel most technical people are aware of the level of tracking going on. The more privacy concerned do what they can to mitigate it.
Facebook broke my trust with data I didn't know they had collected.
Is there a valid use case for "encrypting" email with a private key? I guess signing a message is technically encryption, but it's not typically called that, right? I'm hoping their use of "encrypt" in this context is just an error, and that tech reporters at the Guardian understand how key pairs work...
You can get people to do anything with the right incentives.
I may be alone in this, but I expect that everything I do on the Internet is done in public. Nothing new here.
Since most sites implement google Analytics and Facebook tracking code (ghostery is reporting both on the guardian website). They could use browser fingerprinting, which has already been proven to be extremely accurate, to augment known user profiles and data. Facebook already creates shadow profiles for people without profiles. I don't think there's any US law from making these inferences from "voluntarily" submitted information so it's perfectly plausible they would do this without telling people, no?
A more compelling argument for users to take privacy seriously would be to tell them: Hey guess what Google has the ability to know what porn you search for (yea even in your private window) since you're sending them all the data required to track you, and there's no laws in place to prohibit it.
Things like MAC address logging and such is also missing.
The only things included in the download are things you've given them; pictures, messages, likes, contacts, web browsing history, and phone metadata if you gave them permission on your phone.
If they were able to purchase phone metadata from your service provider, it won't show up there.
If all Facebook kept was user-submitted data it would be orders of magnitude less creepy than it is.
Creepy, that’s what they said they would do when I opened my gmail account.
But most here know about this, many are intimately involved in it and are happy to defend it. Outrage targetted at Facebook while making excuses for Google feels inauthentic.
Everyone wants an ethical society but when it comes to paying a price economics always wins out and we are left with the spectacle of the privileged hand wringing, blaming the system, blaming the victims and acting helpless. If you can't be ethical you can't expect ethical behavior from anyone else and you get the society you deserve.
I'm surprised they didn't have anything in search or youtube because I deleted the history long enough ago that I didn't remember doing it, so I've successfully stayed away from using them.
Still waiting for the data download, but I know they have all my gmail messages and some stuff I put on Drive a long time ago.
https://www.google.com/maps/timeline?pb
I’m getting the following error:
“Location Services permission is not set to always. Timeline cannot function properly if you don’t allow Google Maps access to your location while in background. [Skip][Turn On]”
Seems like I should be able to see what historical location data they have without enabling background location.
Disclaimer: I work for Apple
An accurate title for this piece would have been "This is all of the data Facebook and Google are willing to tell you they have on you"
It's pretty obvious Facebook needs to store the stickers you sent if they store your chat history. They come in their own directory in the bundle so they can be shown in the chat HTML pages.
Err ya that's the service right :P
Why can't this be easier ? Why can't google produce a tool for this ?