Google Releases Full Report On Street View Investigation, Finds That Staff Knew About Wi-Fi Sniffing

evilbear

Earlier today Google released the full report of the FCC’s investigation into the collection of  “payload data” from open Wi-Fi networks — aka passwords, email and search history from open networks — that its fleet of Street View cars obtained between 2008 and April 2010. An earlier and heavily redacted version of the report was released on April 15 but today’s version only redacted the names of individuals.

The report found no violation of any wrong doing by the company because there was no legal precedent on the matter. The FCC found that Google did not violate the Communications Act citing the fact that Wi-Fi did not exist when it was written. However, the FCC did fine Google $25,000 for obstructing the investigation, which was presumably the outcome of Google refusing to show the FCC what the data being collected entailed because it might have shown that the company broke privacy and wiretapping laws. Google says any obstruction was result of the FCC dragging out the investigation. Interestingly enough, the report did reveal that the data harvesting was not the act of a rogue engineer and that said engineer notified the Street View team of what was going on.

(Wait. What? Google knew this was going on! It gets even better.)

Except that those members of the team told the FCC that they had no idea it was going on even though the engineer in question sent documentation of the work being done to the entire Street View team in October of 2006. The report also found that up to seven engineers had “wide access” to the plan to collect payload data dating back to 2006.

From the report:

In interviews and declarations, managers of the Street View project and other Google employees who worked on the project told the Bureau they did not read Engineer Doe’s design document. A senior manager of Street View said he “pre-approved” the design document before it was written. One engineer remembered receiving the design document but did not recall any reference to the collection of payload data.

For a little more background, let’s examine what Alan Eustace, Senior VP, Engineering & Research blogged back in 2010:

Nine days ago the data protection authority (DPA) in Hamburg, Germany asked to audit the WiFi data that our Street View cars collect for use in location-based products like Google Maps for mobile, which enables people to find local restaurants or get directions. His request prompted us to re-examine everything we have been collecting, and during our review we discovered that a statement made in a blog post on April 27 was incorrect.

In that blog post, and in a technical note sent to data protection authorities the same day, we said that while Google did collect publicly broadcast SSID information (the WiFi network name) and MAC addresses (the unique number given to a device like a WiFi router) using Street View cars, we did not collect payload data (information sent over the network). But it’s now clear that we have been mistakenly collecting samples of payload data from open (i.e. non-password-protected) WiFi networks, even though we never used that data in any Google products.

However, we will typically have collected only fragments of payload data because: our cars are on the move; someone would need to be using the network as a car passed by; and our in-car WiFi equipment automatically changes channels roughly five times a second. In addition, we did not collect information traveling over secure, password-protected WiFi networks.

So how did this happen? Quite simply, it was a mistake. In 2006 an engineer working on an experimental WiFi project wrote a piece of code that sampled all categories of publicly broadcast WiFi data. A year later, when our mobile team started a project to collect basic WiFi network data like SSID information and MAC addresses using Google’s Street View cars, they included that code in their software—although the project leaders did not want, and had no intention of using, payload data.

As soon as we became aware of this problem, we grounded our Street View cars and segregated the data on our network, which we then disconnected to make it inaccessible. We want to delete this data as soon as possible, and are currently reaching out to regulators in the relevant countries about how to quickly dispose of it.

Fair enough. But the following excerpt from the report doesn’t quite sit so well with me: “We are logging user traffic along with sufficient data to precisely triangulate their position at a given time, along with information about what they were doing.” To be more specific, the last portion about knowing “what they were doing” seems a bit peculiar. Why would Google need to know what they were doing? Seems irrelevant if you’re just mapping the location of networks, doesn’t it?

So how did Google spin this to the media? It said the data mining was “inadvertent” and that Google now has stricter privacy controls than in the past. Oh and the company hopes the release of the full report would allow them to “put this matter” in the rear view mirror.

Crazy, right? Or maybe not! Discuss.

Correction: April 28, 2012 9:46PM PT

An excerpt from the report has been added regarding the pre-approval of a document sent out by “Engineer Doe” to the Street View team that detailed the work being done and included the fact that Google would be collecting such data.


Was It Google And Verizon Or The FCC That Just Screwed Us On Mobile Net Neutrality?

We’ve already covered the FCC Net Neutrality vote earlier today, but something new has come to light. Something that’s very odd. Something that’s quite frankly a little terrifying.

Engadget dug up the FCC’s release [PDF] and found the following nugget buried in the all-important section “Measured Steps for Mobile Broadband”:

Further, we recognize that there have been meaningful recent moves toward openness, including the introduction of open operating systems like Android.  In addition, we anticipate soon seeing the effects on the market of the openness conditions we imposed on mobile providers that operate on upper 700 MHz C-Block spectrum, which includes Verizon Wireless, one of the largest mobile wireless carriers in the U.S.

In light of these considerations, we conclude it is appropriate to take measured steps at this time to protect the openness of the Internet when accessed through mobile broadband

While that may read like it’s a statement from Google or Verizon — actually, the entire section reads a lot like their joint proposal — it’s actually the FCC’s statement. Yes, that’s the FCC citing Android’s openness as a reason why they don’t need to impose net neutrality rules for mobile broadband.

Except wait. What the hell does an open operating system have anything to do with network access? Nilay Patel wonders this. John Gruber wonders this. Everyone should wonder this. It really does almost read as if they just copied what Google and Verizon laid out and forgot to remove the self-promotion.

As Patel writes:

… if we were slightly more paranoid, we’d be pretty sure there’s a link between the FCC’s Android mention and the combined furious lobbying of Google and Verizon.

I am slightly more paranoid. What the hell is Android doing in that statement?

I’ve made my thoughts on Android’s “openness” very clear. So have others. I believe the carriers are taking advantage of it and will continue to do so to the detriment of consumers. Now the FCC is using the “openness” label to screw us on net neutrality? Great.

Why doesn’t the FCC just say something like: “We just attended this great Google conference and heard that Android was open. Therefore, we see no need to regulate mobile broadband. It’s open, you see. That’s good for everyone. That means that everyone is going to do the right thing. An open operating system ensures there won’t be any throttling or filtering. Why? Because. Well. Open! Verizon agrees.”

It was only a month ago that FCC head Julius Genachowski said that the Verizon/Google proposal “slowed down” the process of coming up with a net neutrality proposal. Apparently, that’s because they had to rewrite the thing to include exactly what Verizon and Google agreed upon.

And now you see the danger of Google backtracking and screwing us in this regard. It seems greed, for lack of a better word, was just too good.


Facebook Enters the Google-Verizon Net Neutrality Debate


Facebook has entered the net neutrality debate with a statement critical of the key provisions of Google and Verizon’s net neutrality proposal.

Ever since we found out Google and Verizon were in talks over net neutrality’s future, the web has been awash with an endless stream of opinions, most of them expressing outrage. The Federal Communications Commission (FCC) is not happy, and neither is the Electronic Frontier Foundation (EFF).

Facebook, it seems, isn’t a fan of the Google-Verizon proposal as it’s currently written. Here is the company’s statement (emphasis ours):

“Facebook continues to support principles of net neutrality for both landline and wireless networks. Preserving an open Internet that is accessible to innovators — regardless of their size or wealth — will promote a vibrant and competitive marketplace where consumers have ultimate control over the content and services delivered through their Internet connections.”

There are several sections of the proposal that trouble a lot of people, but the biggest sticking point is the exclusion of wireless networks from net neutrality regulations. Verizon and Google exclude it from their proposal for wired connections because “imposition of too many rules up front would not allow us to optimize this network in a fashion that would supercharge the growth we’ve seen in the past.” Critics say that Google and Verizon are trying to protect their own interests, especially their highly profitable Android partnership.

Facebook’s statement doesn’t surprise us; the Google and Facebook are now at war, and allowing Google to define net neutrality on its own terms presents a grave threat to the social network’s business.

For now, expect more of these nuanced statements from all of the parties involved — that is, until the Google-Verizon proposal makes its way to Congress. That’s where you’ll find the real fireworks.

More About: facebook, fcc, Google, net neutrality, verizon

For more Tech coverage:

12 visitors online now
5 guests, 7 bots, 0 members
Max visitors today: 14 at 03:41 am EDT
This month: 35 at 05-16-2013 08:04 am EDT
This year: 112 at 04-11-2013 09:43 am EDT
All time: 112 at 04-11-2013 09:43 am EDT
Get Adobe Flash player