Google needs to search under “wrong”

Opinion
Jun 10, 20104 mins

* Google is collecting information on people without attempting to obtain permission and even without giving them an opt-out from the collection and distribution of data

It seems Google can’t do much of anything without riling some government somewhere in the world. The latest flap comes from an investigation launched by the Australians. This is a follow-on to an investigation started by the Germans in which “Google acknowledged that it had mistakenly collected fragments of data over public Wi-Fi networks in more than 30 countries while taking pictures of neighborhoods for the Street View feature.”

It seems Google can’t do much of anything without riling some government somewhere in the world. The latest flap comes from an investigation launched by the Australians (see “Australia Opens a Privacy Case Against Google,” in the New York Times). This is a follow-on to an investigation started by the Germans in which “Google acknowledged that it had mistakenly collected fragments of data over public Wi-Fi networks in more than 30 countries while taking pictures of neighborhoods for the Street View feature.”

Authorities investigating Google data collection

Google was collecting Wi-Fi data, including SSIDs (service set identifier, the name you assign your Wi-Fi network) and MAC addresses (a supposedly unique number burned into all network devices by their manufacturer.)

Google apologized for gathering data packets as part of its effort to map SSIDs and MAC addresses along with its other “Street View” data. But aren’t MAC addresses useful in identifying people, devices and what they are doing? Isn’t tracking the location of MAC addresses akin to following people around and noting where they go? Kim Cameron certainly thinks so. In fact, Microsoft’s chief identity architect paints a scary scenario of sexual predators using this data to track down children. You see, it’s not only that Google is collecting this data — it’s putting it into databases along with the Street View data, which can pinpoint where that MAC address and SSID were encountered.

Intel’s Conor Cahill disagrees, calling MAC addresses “local identifiers more like house numbers.” That is, simply a number (“123” for example) without any further identification (such as, say, “Main Street”). But this is disingenuous, I believe. The MAC address is the actual address to which a data packet is delivered. It goes through two (or more) transformations, though. When I send a packet it’s addressed to a particular node or service with a domain (e.g., mail.vquill.com) that DNS  translates to an IP address (e.g., 64.79.192.162), which a router than translates to a MAC address for the device hosting that service.

While there could be multiple services using that MAC address (on a domain server, perhaps), most are associated with user devices — PCs, laptops, smartphones and all the electronic panoply we accumulate. In a small number of cases, in other words, a MAC address defines multiple services. But in the vast number of cases multiple MAC addresses point to a single user!

When you associate MAC addresses, the SSIDs of the networks they are on, and the geolocation of the devices you’ve gone a long way towards collecting a dossier on a person without their permission. And that’s the objection here: Google is collecting this dossier — which is very useful both to Big Brother and creepy Uncle Sid — without even attempting to obtain permission from people and even without giving them an opt-out from the collection and distribution of data, something even Facebook (with its disastrous privacy policies) actually does.

Follow the link above to Cameron’s blog and read the dozen or so postings he has on this issue to get a full understanding of just how wrong Google’s behavior is.

Google needs to change its ways — and fast.