Welcome | Sign In
ECommerceTimes.com
SaaS

EPIC Threatens to Burst Google's Cloud

Print Version
E-Mail Article
Reprints
EPIC Threatens to Burst Google's Cloud

Following the discovery of a bug that allowed the sharing of people's cloud-based documents with unauthorized users, the Electronic Privacy Information Center has asked the Federal Trade Commission to investigate Google's cloud security promises.


Major companies around the world value the opinion of thought leaders like you! Join our new tech panel to be invited to a variety of interesting and rewarding survey opportunities. In exchange for your valuable time and insight, you will have exclusive access to rewards programs such as Paypal, Amazon and retail gift cards. Learn more.

Privacy rights organization EPIC, the Electronic Privacy Information Center, has asked the Federal Trade Commission (FTC) to shut down Google's (Nasdaq: GOOG) cloud services on grounds that the company is misleading consumers.

This follows a breach in Google Docs on March 7, which was caused by a software bug that led users to inadvertently share some of their files with others. Google has since fixed the bug.

EPIC's formal letter of complaint says that Google promises users their documents are stored securely and assures them that their documents, spreadsheets and presentations will remain private unless they publish these to the Web, or invite viewing or collaboration.

On the other hand, it points out, Google's Terms of Service explicitly disavow any warranty or liability for harm that might result "from Google's negligence, recklessness, mal intent, or even purposeful disregard of existing legal obligations to protect the privacy and security Planning for the next peak season? Ensure your website is fast, secure and available 24/7. Click here to learn how. of user data."

Stop the Services?

EPIC wants the FTC to enjoin Google from offering cloud computing services until safeguards are verifiably established. It also wants the FTC to make Google revise its terms of service for its cloud computing services, make its information security policies more transparent, and disclose all incidents of data loss or breaches to the FTC.

Enjoin what? That means Google would have to stop providing access to its Docs, Calendar, Gmail and other apps. Won't that impact millions of people and thousands of companies using these apps?

Yes, it could. But don't reach for the smelling salts yet. "The likelihood of stopping access to Google apps is very small," EPIC executive director Marc Rotenberg admitted. "What's more important is to ensure they improve security."

Nothing But the Truth

In essence, EPIC's letter says that by promising security and privacy and failing to deliver, Google is subject to allegations of unfair or deceptive trade practices.

It calls on the FTC to open an investigation into Google's cloud computing services, focusing on the adequacy of Google's privacy and security safeguards in two areas: for storage of personal information, and in light of its assurances to consumers regarding its cloud computing services.

EPIC's letter also points out that Google's cloud computing services have known flaws. It cited the March 7 Google Docs data breach, and said that, in 2005, researchers identified several security flaws in Gmail and in Google Desktop.

"It's obvious that we've become increasingly dependent on cloud computing services," Rotenberg told the E-Commerce Times. "The benefits are clear, but what's not so clear are the security and privacy risks. We think the FTC has a responsibility to investigate the reliability of these services, and that's the reason for this complaint."

"We have received a copy of the complaint but have not yet reviewed it in detail," Kovacs said.

Google Docs and the Aftermath

Cloud computing can be more secure than storing information on users' own hard drives,Google spokesperson Andrew Kovacs told the E-Commerce Times. "Many providers of cloud computing services, including Google, have extensive policies, procedures and technologies in place to ensure the highest levels of data protection."

The Google Docs breach, caused by a bug, affected 0.05 percent of Google Docs users, Kovacs said. "The sharing was limited to people with whom the account owner, or a collaborator with sharing rights had previously shared a document."

Google has since fixed the bug, and contacted the users who were affected to notify them of the bug and to identify which of their documents may have been affected, Kovacs said.

Still, the bug and its effects do point to concerns about cloud computing security, especially for public cloud services like Google's.


Print Version E-Mail Article Reprints More by Richard Adhikari


Talkback: Join the Discussion.
EPIC Threatens Google
mzcat
Posted 2009-03-19
Nothing or noone is perfect in this life. Stuff happens. Google should not be punished for this ...
EPIC vs Google
ncp911
Posted 2009-03-19
I don't believe that Google should be reprimanded for this. If this really made people mad ...

More by Richard Adhikari

Ballmer: The Windows 7 Tablet Will Have Its Day
July 30, 2010
Microsoft is hard at work on a tablet, it will run Windows 7, and it'll be ready when it's ready -- that was the message CEO Steve Ballmer conveyed to financial analysts Thursday. While the company has been gliding on sales of its Windows 7 operating system, many investors feel it's also missing a big opportunity in tablet computers, the popularity of which is underscored by the rapid ascent of Apple's iPad.
Microsoft's Mobile Morass, Part 1
July 30, 2010
If sales and financial performance say anything, Microsoft has generally corrected its desktop OS course with Windows 7. But the company's growth in mobile appears seriously stunted. The technology it's building into Windows Phone 7 may make it some friends in the enterprise, but the software won't hit the market for months. In tablets, Apple's claimed a big lead, and it looks like Android's already out of the gate too.
Hacker Makes ATMs Cough Up Cash Willy-Nilly
July 29, 2010
Using exploits with names like "Scrooge" and "Dillinger," a security researcher presenting at the Black Hat conference demonstrated a way to hack into ATMs, reprogram them to spew money, and even steal unsuspecting users' information. Barnaby Jack says the companies that make the machines he demoed have patched their systems, but similar flaws may remain in other machines.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network