Google to shut down Google+ after failing to disclose user data leak

This March, as Facebook was coming under global scrutiny over the harvesting of personal data for Cambridge Analytica, Google discovered a skeleton in its own closet: a bug in the API for Google+ had been allowing third-party app developers to access the data not just of users who had granted permission, but of their friends.

If that sounds familiar, it’s because it’s almost exactly the scenario that got Mark Zuckerberg dragged in front of the US Congress. The parallel was not lost on Google, and the company chose not to disclose the data leak, the Wall Street Journal revealed Monday, in order to avoid the public relations headache and potential regulatory enforcement.

Disclosure will likely result “in us coming into the spotlight alongside or even instead of Facebook despite having stayed under the radar throughout the Cambridge Analytica scandal”, Google policy and legal officials wrote in a memo obtained by the Journal. It “almost guarantees Sundar will testify before Congress”, the memo said, referring to the company’s CEO, Sundar Pichai. The disclosure would also invite “immediate regulatory interest”.

Shortly after the story was published, Google announced that it will shut down consumer access to Google+ and improve privacy protections for third-party applications.

Google announced it is shutting down the consumer version of its online social network after fixing a bug exposing private data in as many as 500,000 accounts. Photograph: Josh Edelson
 Google announced it is shutting down the consumer version of its online social network after fixing a bug exposing private data in as many as 500,000 accounts. Photograph: Josh Edelson

In a blog post about the shutdown, Google disclosed the data leak, which it said potentially affected up to 500,000 accounts. Up to 438 different third-party applications may have had access to private information due to the bug, but Google apparently has no way of knowing whether they did because it only maintains logs of API use for two weeks.

“We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any profile data was misused,” Ben Smith, the vice-president of engineering, wrote in the blogpost.

Smith defended the decision not to disclose the leak, writing: “Whenever user data may have been affected, we go beyond our legal requirements and apply several criteria focused on our users in determining whether to provide notice.”

None of the thresholds for public disclosure were met, Smith said. 

There is no federal law that obliges Google to disclose data leaks, but there are laws at a state level. In California, where Google is headquartered, companies are only required to disclose a data leak if it includes both an individual’s name and their Social Security number, ID card or driver’s license number, license plate, medical information or health insurance information.

Google also announced a series of reforms to its privacy policies designed to give users more control on the amount of data they share with third-party app developers.

Users will now be able to have more “fine grained” control over the various aspects of their Google accounts that they grant to third-parties (ie calendar entries v Gmail), and Google will further limit third-parties’ access to email, SMS, contacts and phone logs.

David Carroll is a US professor who sued Cambridge Analytica earlier this year to find out what data the company had stored about him. He said that given the legal issues Facebook faces over its Cambridge Analytica cover-up, it’s not surprising Google tried to keep the leak out of the public eye.

“Google is right to be concerned and the shutdown of Google+ shows how disposable things really are in the face of accountability,” he said.

For others, the leak was further evidence that the large technology platforms need more regulatory oversight.

“Monopolistic internet platforms like Google and Facebook are probably ‘too big to secure’ and are certainly ‘too big to trust’ blindly,” said Jeff Hauser, from the Centre for Economic and Policy Research.

He argued that the US Federal Trade Commission should move toward “breaking these platforms up”.

“In the interim, since we cannot trust that we know much or even most of what ought to concern the public, the FTC should install public-minded privacy monitors into the firms as an element of accountability.”

The Guardian

Other News

Hanoi approves controlled pilot of two technology projects

Hanoi approves controlled pilot of two technology projects

The two projects involve an intelligent autonomous transportation system developed by Phenikaa-X JSC and a technology for producing mixed rare-earth oxides with a purity of over 95% on a semi-industrial scale developed by the Mining Technology and Construction Consultancy JSC.

Banking industry in AI era: When data becomes competitive advantage

Banking industry in AI era: When data becomes competitive advantage

In just a few years, AI has evolved from an experimental technology into an “assistant” for many banks, supporting everything from customer service, credit approval, and fraud detection to risk management. However, as the technological gap between institutions narrows, a new question is emerging: What will determine banks' competitive advantage in the AI era?

Bac Ninh considers establishing AI centre of excellence

Bac Ninh considers establishing AI centre of excellence

A meeting has been held in Bac Ninh to discuss potential cooperation with Plug and Play in developing the northern province’s innovation ecosystem and establishing an artificial intelligence (AI) centre of excellence, with Standing Vice Chairman of the provincial People’s Committee Mai Son receiving a delegation from the global innovation platform.

Hanoi allows 24-month trial of autonomous vehicles at Hoa Lac

Hanoi allows 24-month trial of autonomous vehicles at Hoa Lac

The project aims to assess the safety, reliability and readiness of autonomous vehicles under real traffic conditions, as well as the effectiveness of autonomous public transport and compatibility with existing systems. Its results will contribute to developing technical standards, operating procedures and management models suited to Hanoi’s traffic conditions.

Singapore's experience suggests solutions to Vietnam's human resources challenge in AI era

Singapore's experience suggests solutions to Vietnam's human resources challenge in AI era

As Vietnam accelerates digital transformation and high-tech development, Singapore’s experience and the engagement of global technology companies demonstrate that human resources preparation must stay ahead of the curve. The ability to filter knowledge, collaborate, innovate and effectively use AI will increasingly become essential to helping workers adapt to a changing labour market and strengthening the competitiveness of Vietnam’s economy in the new era.

Protecting national security amid digital transformation, cyberspace

Protecting national security amid digital transformation, cyberspace

Cybersecurity, information security and data security risks must be identified and addressed early and from afar, with appropriate defensive measures ready to neutralise threats and protect national interests in cyberspace, said Lieutenant General Le Xuan Minh, Director of the Ministry of Public Security’s Department of Cybersecurity and Hi-tech Crime Prevention (A05).

Mekong Delta launches first robotics, AI research institute

Mekong Delta launches first robotics, AI research institute

Dr. Nguyen Van Quang, Rector of Nam Can Tho University, said the university is developing a value chain covering training, research, technology development, testing, technology transfer and commercialisation. The model is designed to link research more closely with practical needs, ensuring that technologies generate products and products create value for society.

Vietnam positioned to harness AI wave, World Bank report says

Vietnam positioned to harness AI wave, World Bank report says

The WB report identifies Vietnam as one of the few economies outside the European Union (EU) to have adopted a comprehensive AI regulatory framework as early as 2025. Vietnam applies a risk-tiered approach similar to that of the EU AI Act, imposing different obligations depending on whether an AI system poses “unacceptable,” “high,” “low” or “minimal” risks. The approach is viewed as a strategic step towards ensuring safe and transparent AI governance.

AI offers both opportunities, challenges for Vietnam's growth

AI offers both opportunities, challenges for Vietnam's growth

Dr. Ho Duc Thang, a full-time member of the National Assembly’s Committee for Cultural and Educational, said productivity is the key to sustaining double-digit economic growth, and AI has greater potential to improve productivity than any previous technology.

Top leader unveils people-centred vision for new development model

Top leader unveils people-centred vision for new development model

Vietnam's growth model, long fueled by low-cost labour, resource extraction, contract manufacturing, expanded investment, and capital accumulation, has run out of road. The country now needs a sweeping reform agenda to shift from extensive growth to a model driven by productivity, knowledge, science and technology, innovation, and digital transformation.