SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security

OPINION: Buzz privacy can’t be in perpetual beta

OPINION: Buzz privacy can’t be in perpetual beta

By:  Warren Shiau  On: 19 Feb 2010 For: ComputerWorld Canada Creator

Google faces a class-action lawsuit and criticism from Canada’s Privacy Commissioner over its new social networking tool. A Strategic Counsel analyst investigates

Well, Google has egg on its face over privacy issues stemming from the launch of its Buzz social networking service. How serious is the problem? Just "housekeeping," according to Google, where the company line, given by Google Canada spokesperson Wendy Rozeluk, is: "We’ll be making significant (Buzz) product improvements over the next few days based on user feedback. The user always comes first."
 
This comes after "user feedback" (more like "user backlash") prompted Google to disable the highly criticized Buzz auto-follow function and make privacy controls and options within Buzz more visible.

Buzz product manager Todd Jackson tried to explain the situation as new product growing pains.

"We've been testing Buzz internally at Google for a while," Jackson said. "Of course, getting feedback from 20,000 Googlers isn't quite the same as letting Gmail users play with Buzz in the wild."

Okay, let’s get this straight. Google depends on its users to vet the adequacy of its privacy protection and controls? Because ultimately that’s what Google, after testing the service internally only, and okaying its release without real-world testing or consultation with the Canadian Privacy Commissioner’s Office, is telling us: "WE tested it, WE felt it was okay. But after the fact, if users or the Privacy Commissioner tell us it isn’t, hey, don’t worry, we’ll fix it fast because the user always comes first."

Worryingly, Google responded to questions from the U.S. trade press about its lack of a Chief Privacy Officer, or indeed any top executive charged with privacy, by saying that "rather than having a single, isolated privacy department, we embed the importance of privacy into our products and systems from engineers through executives, guided by trained privacy professionals."

I say worryingly, because what’s being exposed here is a lack of privacy discipline and process within Google. This isn’t a case of mistakes slipping through the system, it’s a case of not having an adequate system to begin with. Google’s "embedded importance of privacy from engineers through executives and trained privacy professionals" approved what the company was doing with Buzz. And with all the same people and "embedded importance of privacy" still there, there’s obviously nothing in terms of formal policy baked into product development at Google to prevent something like this from happening again. Google really just doesn’t get it.

In the spirit of offering advice rather than just criticism, I believe Google can quite easily start itself on the road to "getting it" by implementing a four-component "privacy prime directive."
1) Consult your users and applicable privacy bodies/organizations (e.g. don’t just dog-food it, test with real-world users)
2) Give notice to users about anything that could affect their privacy
 
3) Require users’ consent for anything that could affect their privacy
4) Bake (1), (2) and (3) into all product and service development as part of policy and the development process

Sign up for our Newsletters












Print |  Views: 2449   |   Rating:ononononoff  (2 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




warren shiau Warren Shiau is a respected technology analyst and research consultant with sectoral expertise in software, hardware and communications. His wide-ranging experience in IT-industry research and analysis i... more

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.