37 States now investigating Google StreetView snooping
July 21, 2010
37 States are now involved in a “powerful multi-state investigation” of “Google’s Streetview snooping” per a press release from investigation leader, Connecticut Attorney General Richard Blumenthal, who released a new follow-up letter to Google asking for more information and clarification of its representations to date.
The letter shows the investigation is very serious. Its prosecutorial exactness strongly suggests that investigators believe Google has not been forthright in its answers to date and that it could be covering up material information to the investigation.
- Several questions in the letter also indicate that the investigators are seriously concerned about the integrity and completeness of Google’s systems of internal controls and supervision to ensure the safety and privacy of consumers.
What appears to be the most problematic line of inquiry is whether or not Google tested this software before it was used in public to collect private information on consumers.
- If Google did test the code in question, then Google has misrepresented the facts and deceived investigators and the public about the scandal.
- If Google did not test it, Google will have to explain how code that could affect consumers’ security and privacy could get out without supervision or review, which would then open up the inquiry to what other types of Google software is capturing private information on the public without appropriate and responsible Google internal controls and supervision.
In sum, Google is in a real pickle.
- It appears as if Google will have to admit either to misrepresentation/deception/cover-up or accept full liability for gross negligence concerning consumers’ privacy/security.
Google’s wanton “wardriving,” i.e. detecting, accessing, and recording residential WiFi networks in 30 countries for over three years, was not simply a “mistake,” “inadvertent,” or an “accident” as the Google’s PR machine has spun it. The evidence to the contrary is overwhelming to anyone who bothers to examine it closely.
- Google’s wanton wardriving was either: gross incompetence/negligence or wrongdoing.
- Government investigators must determine for themselves via subpoena, whether or not anyone at Google, in a supervisory or management position, knew that this private “payload” data was being collected, and whether or not this private data had been accessed, copied, analyzed, or used by Google in any way.
The case for why Google’s wanton wardriving is more than just a “mistake.”
I. Identifying the questionable practice: “Wardriving”
It is obvious that the media and regulators have only scratched the surface of this problem because none have even researched the practice enough to use the appropriate dictionary term, “wardriving,” to describe what Google has been doing in 30 countries for over three years.
- While Google will try and characterize “war-driving” as a benign practice with good purposes, much like many try to characterize p2p filesharing as benign, the cold reality is that wardriving is a common practice of hackers and cybercrooks to find and exploit peoples’ vulnerabilities so that they can more efficiently defraud them with phishing and other scams.
- The more government officials learn about wardriving the more horrified they will become that Google was able to secretly collect, right beneath their noses, what constitutes the world’s largest and most complete map of which Internet users around the world are most vulnerable to being hacked, taken advantage of, or harmed.
- Simply, Google created a dream “IP” phone book/map for cybercrooks and/or spy agencies to potentially target.
- The risk that this global “easy target” list could fall into the wrong hands is not theoretical.
- Cybercrook access: Google’s “crown jewel” and most sensitive security system, its password access control computer code (Gaia), was was stolen by hackers/intruders, per John Markoff’s important investigative journalism in the New York Times.
- The most troubling part of this massive Google security failure is that Google cannot guarantee that this 600 gigabits of wardriving data was not breached, or if the intruders were able to secretly install “backdoor” access to Google’s “big table” omni-database for convenient access in the future. (See “Security is Google’s Achilles Heel” series.)
- NSA spy access: Google reportedly is partnering with the top U.S. spy agency, NSA, after the big China-Google cyberbreach, per Ellen Nakeshima’s front page scoop in the Washington Post.
- The other 29 foreign countries which Google systematically wardrived, now must be wondering which of their government or other sensitive personnel “targets” have been identified as vulnerable to hacking by Google and potentially the NSA.
- Google condoning shady behavior: Look and see how many Google links and YouTube videos show the “how to” hack networks and computers.
- Cybercrook access: Google’s “crown jewel” and most sensitive security system, its password access control computer code (Gaia), was was stolen by hackers/intruders, per John Markoff’s important investigative journalism in the New York Times.
II. Gross incompetence as a defense?
For Google to prove that this systematic wardriving was inadvertent or accidental, Google essentially has to plead gross incompetence. This is not an easy pill to swallow for the world’s #1 brand that depends on users believing that Google is sincere and competent in protecting their privacy and security when using Google.
- Google has proven to be culturally averse to accountability and internal controls as I have copiously documented on my sister site www.GoogleMonitor.com under the “accountability” tab.
- Erik Sherman of BNet cuts to the quick here with his outstanding analysis of how Google’s claim of a “mistake” is simply not credible. He asks about whether or not Google’s code was: documented; supervised; supervised competently; overseen by management; etc.
- It is not credible that Google, the world’s leading crawler and organizer of information could have unknown, and unmanaged code on all its StreetView vehicles in 30 countries… that could go undetected for over 3 three years of operations and analysis by the hundreds of Googlers involved in StreetView… who were regularly vacuuming up vastly more, and qualitatively and quantitatively different, kinds of WiFi data than it was intended to accumulate… and no one else was involved but the lone orginal software developer that made this solitary lasting “mistake?”
- To believe that we have to believe that no one at Google ever cross-checks, tests, understands, or reviews Google’s original code!
- If Google is being truthful, the staggering list of supervisory, management, privacy, security, and internal controls breakdowns Google would have to admit to would be tantamount to admitting that the world’s #1 repository of the world’s private information has no systemic integrity.
- It is also highly suspicious that if Google truly cares about privacy and safeguarding private data, why has there been no disclosure or reports of a single Google employee that was reprimanded, reassigned or fired over any of Google’s serial privacy scandals: Gmail; Google search; Google Earth; Street View; Latitude Geo-tracking; Google Picassa Facial Recognition; Google Translation; 411 voice recognition; Google Books; Google Docs; Google Buzz; cloud computing; DNA prints; Google-NSA partnership?
- Accountability for Google requires robust management and internal controls systems like any other publicly-traded company, not a serial practice of asking for forgiveness when Google is caught, and not PR misdirection.
III. Wardriving eerily resembles other Google efforts.
It is not credible that Google was unaware that this pervasive and systemic wardriving practice was actually occurring, when wardriving is so similar in both goal and effect to so many other “free” or “crowd-sourced” activities that Google “openly” engages in.
- Remember that another big potential benefit of a global map of vulnerable WiFi hotspots is to let the open wireless movement know where all potential wireless hotspots are, and that are “free” to use, so people can “share” others’ bandwidth with their implicit permission or piggyback others’ bandwidth illegally without their explicit authorization.
- Moreover, what fuels Google’s business model is free or near free inputs: content, private information and bandwidth. Furthermore, there is a lot of evidence that Google aggressively tries to “change the world” from a place where it has to pay for the inputs it uses, to one where it does not have to pay for the inputs it uses.
- Promoting “Free” content: Book authors and publishers have sued Google for illegally copying over 12 million books without permission.
- The Viacom vs. YouTube case has unearthed undisputed facts that Google leadership premeditatedly decided to change its video model from a legal one that respected copyright to one that did not, when it decided to buy YouTube.
- The MPAA is suing Google for proactively promoting movie piracy websites with higher search rankings.
- Promoting “Free” wireless: Google has long supported “free” wireless, via its support for free unlicensed White Spaces spectrum; “open” regulatory conditions on the 700 MHz auction; its Nexus One experiment to commoditize wireless bandwidth; its “free” Android operating system to commoditize wireless applications; and its support of “free” community wireless networks via New America Foundation’s advocacy — where Google’s CEO is Chairman.
- Promoting free software: Google strongly supports free/open source software for all software, but the software that runs Google’s monopoly search engine, auctions and quality score.
- Promoting subsidized bandwidth: Google’s lobbying leadership for net neutrality and Title II common carrier regulation of broadband providers is all about de facto bandwidth subsidies for Google-YouTube’s world-leading bandwidth consumption.
- Promoting Internet engineering changes: Google also is proactively working at all levels to make the web faster: by re-engineering the DNS (Domain Name System); by forcing websites to load content faster or have their search ranking lowered; by backing Measurement Lab to be the world’s bandwidth speed cop; and by collecting copious user network data via Google’s pilot program for ultrafast broadband.
- Promoting “Free” content: Book authors and publishers have sued Google for illegally copying over 12 million books without permission.
- Does it not stretch all credulity that a company that is so interested in every aspect of the Internet, making if faster, gaining access to whatever information it can crawl, and getting it all for free, knows absolutely nothing about a Google global three-year information collection effort that would dovetail perfectly with most all of their goals, projects and initiatives?
IV. Conclusion: What to expect.
In conclusion, expect multiple serious investigations of Google’s wanton wardriving around the world.
EU: Google should be deeply concerned about the EU’s investigation and reaction because the EU has very strict data protection laws and expectations. It is hard to fathom the EU not holding an aggressive and dismissive American monopoly like Google accountable for serial violations of its laws.
- Google should be especially concerned of criminal penalties in Italy, given that Italian authorities have already criminally convicted three Google executives in absentia for YouTube not having sufficient internal controls to quickly pull down an obviously objectionable video of students bullying a disabled schoolmate.
U.S. Overall in the U.S., it is unlikely that Google’s well-known political influence will be able to snuff out Federal law enforcement investigations of Google’s wanton wardriving.
- In part that’s because Google’s former top lobbyist, Andrew McLaughlin, who is now the Federal Government’s Deputy Chief Technology Officer, was just reprimanded yesterday by the White House for violating the Federal Records Act, and for violating the Administration’s code of ethics, because Mr. McLaughlin communicated with Google officials on matters relevant to Google.
- Moreover, Google’s wanton wardriving effort is an unhelpful reminder of Google’s efforts to get Google a White House special waiver so that Google could track Americans who visit the White House website via YouTube, contrary to longstanding Clinton-Bush policy.
DOJ: It is likely that the FBI will have to investigate to ensure that Google’s systematic eavedropping effort via its wanton wardriving effort did not illegally record any personal VoIP phone calls without authorization.
State AGs: Various state privacy and communications laws may have been violated by Google as well, so some State Attorney Generals will likely be investigating, especially if they have any concerns that the DOJ/FBI/FTC are not taking the issue seriously enough.
FTC: The FTC appears to be losing patience with Google’s double speak of supporting privacy in their statements but exhibiting serial disdain for users in their business actions. This latest Google violation of privacy is so at odds with what the FTC says are its privacy policies and expectations for U.S. companies like Google, it will be very surprising if the FTC does not formally investigate Google’s wanton wardriving. If they don’t, Facebook and Google will rightly see it as a green light to continue pushing the privacy-publicacy envelope.
FCC: Don’t expect the FCC to see any need to respond to the data-driven evidence of Google’s actual wanton wardriving of the Nation’s last hundred feet to the home, because this FCC is preoccupied with preventing potential last mile problems everywhere in the country — except for Mountain View, California.
Congress: Political interest and bipartisan consensus is clearly increasing in Congress concerning privacy legislation, in large part because of Google and Facebook’s egregious privacy track records. This latest major Google privacy scandal, on top of the Google Buzz fiasco, and on top of Facebook’s serial moving of the privacy goal posts during the game, easily could increase support for Rep. Boucher’s important new privacy bill.
Consumer Groups: Given that Google’s unauthorized tracking efforts are increasingly spiraling out of control, there could be renewed interest in the recommendation of privacy groups to institute a national “Do not track List” modeled after the populist, simple, effective, and wildly successful FTC “Do not call” list, which prevents unwanted invasion of privacy from telemarketers calling one’s home.
The open question is if this latest major Google privacy scandal will be the proverbial straw that broke the camel’s back for Google.
*****
Publicacy vs Privacy Series:
Part II: Implications of User Location Tracking
Part III: Extreme Publicacy — Does Privacy Stand a Chance?
Part VI: Why FTC’s Behavioral-Ad Principles Are a Big Deal
Part V: Privacy prevailed in Facebook’s privacy-publicacy earthquake
Part VI: Do People Own Their Private Information Online?
Part VII: Where is the line between privacy and publicacy?
Part VIII: “Privacy is Over”
Part IX: “Interventional Targeting? “Get into people’s heads”
Part X: “Latest publicacy arguments against privacy”
Part XI: “The Web 2.0 movement is opposed to the privacy movement.”
Part XII: “No consumer control over the commercialization of their privacy?”
Part XIII: “Does new Government cookie policy favor publicacy over privacy? “
Part XIV: “Google Book Settlement “absolutely silent on user privacy”
Part XV: Yet more evidence of Google’s hostility to privacy
Part XVI: Poll: Americans strongly oppose publicacy & expect online privacy
Part XVII: FaceBook CEO throws privacy under the bus
Part XIII: Fact Checking Google’s privacy principles
Part XIX: Google’s Privacy “Buzz” Saw
Part XX: Facebook and Google in a race to the Privacy bottom?
Questions for Google on its Latest Act of Privacide — Part XXI Privacy vs. Publicacy series
April 23, 2010
Google’s latest privacy-killing act of privacide is “Google’s roving Street View spycam,” which is not only taking pictures, but is also scanning to log WiFi network addresses and unique Media Access Control (Mac)addresses per Andrew Orlowski’s excellent scoop at the Register.
- Let’s not forget that this is just the latest in Google’s serial privacide: Gmail; Google search; Google Earth; Street View; Latitude Geo-tracking; Google Picassa Facial Recognition; Google Translation; 411 voice recognition; Google Books; Google Docs; Google Buzz; cloud computing; DNA prints; Google-NSA partnership; Schmidt on privacy; these links are illustrative of Google’s pervasive invasiveness of everyone’s privacy, not comprehensive.
- Privacy International was dead on in ranking Google worst in the world on privacy. (Also see relevant congressional testimony here and here.)
Privacide Questions for Google:
- Why not be open about Google’s Street View’s wireless surveilance and reconnaissance? Why be so secret? Is Google afraid people/governments would object?
- Does Google have any other antennae that are recording voices or other sounds via the Street View spycams?
- What other information is Google recording, surveiling, and capturing that Google is not telling us about?
- What legitimate business purpose is there for this latest clandestine surveilance and information capture?
- Is this type of surveilance information gathering shared or subpoena-able with spy agencies (NSA) or law enforcement? If yes, why is an American company doing this on foreign citizens?
- Is there any type of information surveilance/collection that may be appropriate for an American company with American citizens in American jurisdiction, that is not appropriate with foreign citizens, or in a foreign jurisdiction?
- Is anyone else doing this with comparable scale to Google?
- Where is the privacy line for Google that it will not cross and why? Does Google believe it should intrude on people’s privacy up and to the point where they object?
- Who at Google authorized this? Or was this just an organic bottom-up outgrowth of Google’s innovation-without-permission culture?
- What supervision and internal controls are there to protect this private information from abuse?
Question for Privacy Authorities:
- How often, deep, and broadly does Google have to push beyond privacy norms, expectations, regulations and laws… before privacy authorities act?
***
Publicacy vs Privacy Series:
Part I: The Growing Privacy-Publicacy Fault-line — The Tension Underneath World Data Privacy Day
Part II: Implications of User Location Tracking
Part III: Extreme Publicacy — Does Privacy Stand a Chance?
Part VI: Why FTC’s Behavioral-Ad Principles Are a Big Deal
Part V: Privacy prevailed in Facebook’s privacy-publicacy earthquake
Part VI: Do People Own Their Private Information Online?
Part VII: Where is the line between privacy and publicacy?
Part VIII: “Privacy is Over”
Part IX: “Interventional Targeting? “Get into people’s heads”
Part X: “Latest publicacy arguments against privacy”
Part XI: “The Web 2.0 movement is opposed to the privacy movement.”
Part XII: “No consumer control over the commercialization of their privacy?”
Part XIII: “Does new Government cookie policy favor publicacy over privacy? “
Part XIV: “Google Book Settlement “absolutely silent on user privacy”
Part XV: Yet more evidence of Google’s hostility to privacy
Part XVI: Poll: Americans strongly oppose publicacy & expect online privacy
Part XVII: FaceBook CEO throws privacy under the bus
Part XIII: Fact Checking Google’s privacy principles
Part XIX: Google’s Privacy “Buzz” Saw
Part XX: Facebook and Google in a race to the Privacy bottom?
Google’s Titanic Security Flaws — “Security is Google’s Achilles Heel” Part VIII of Series
April 22, 2010
Well informed reports (that Google will not deny), that hackers breached Google’s most sensitive software code, the Gaia password system, surface titanic security flaws at Google.
Why Google is too big not to fail.
1. “Bigtable” Storage design: How Google stores and accesses “all the world’s information” in and from its data centers is: “‘Bigtable:’ a Distributed Storage System for Structured Data.” It is Google’s innovation to maximize scalability, speed and cost efficiency — not security, privacy, or accountability. Simply, Bigtable is an “all eggs in one basket” approach to information storage and access.
- It is the single largest database of information the world has ever known. It is also distributed across the world in Google’s multiple data centers. Per Yale computer science Professor Michael Fischer: “Google stores every piece of data in three centers randomly chosen from the many it operates worldwide in order to guard the company’s ability to recover lost information.”
- Per Google’s own Peter Fleischer on his blog: “It’s actually very hard to answer the apparently simple question: ‘where’s my data?‘”
- If Google doesn’t know where your data is at any given time, how do they know if your own private data has been breached?
- The “Titanic” security flaw in Bigtable’s fundamental design is that it is not compartmented.
- Like the Titanic ship that sunk fast because it did not have compartments to partially contain the breach of rapidly incoming water, Google’s Bigtable design, where Google stores all the world’s information in basically one virtual receptacle without compartments, means that when Google’s system was breached, the hackers could theoretically have gone most anywhere in Bigtable.
- Since Google does not employ the standard omni security protocol of compartmentalization, Google would not know what information was breached so that those affected could try and protect themselves from the new liability and danger.
- This helps explain why Google is “turtle-ing” and not giving guidance about what’s secure and what’s not.
- Most likely, they don’t have a clue because Bigtable is simply too big and complex to check.
2. Biggest Target: Google’s unique mission to “organize all the world’s information and make it universally accessible and useful” has effectively created a world central bank of information. As bank robber Willie Sutton said when asked why he robbed banks, he infamously replied: “Its where the money is.”
- The reason Google will always be a number one target for hackers is that in designing a system and database for Google to quickly and efficiently access all the world’s information, Google has created the ultimate convenience for hackers to quickly and efficiently access the information they prize because Google put all the valuable information in one virtual place so hackers have a one stop-shop and only one outer wall to overcome.
3. Biggest Speed Freak: Google’s #3 corporate priority is “fast is better than slow;” thus speed is one of Google’s key competitive differentiators. Google’s #2 design principle is “every millisecond counts“… “Nothing is more important than people’s time.” Unfortunately, if Google actually bothered to ask users what their top priority was, most would say safety and security. Without a foundation of trust, what good is speed?
- As I have written extensively, Google is proactively forcing everyone on the Internet to be faster. Google now ties search ranking to the load speed of websites, Google is trying to change the DNS system, and Google has a whole initiative “to make the web faster.”
- Is speed compatible with security, safety and privacy protection? Almost every aspect of security involves some inefficiency, or slowing down to create security checkpoints, verifications, authorizations, patrols, gates, locks, sweeps, spotchecks, etc.
- Do we consider the fastest of just about anything to be safe or the safest?
- Google believes nothing is more important than people’s time. By definition, security is thus a subordinate or tertiary concern to Google’s business, leadership and engineers.
4. Biggest “Open” Proponent: Google is the single biggest force pushing for openness on the Internet. Google has a corporate philosophy that information and content should be shared. Google’s mission is to make all the world’s information accessible — showing that Google feels deeply about breaking down any barriers to bringing information to people (even if it means bending/breaking the law… see: Viacom vs Google, Book Settlement).
- Does anyone consider openness the same as security? Open sharing, an open door, open window, an open interface, are these what most people view as what is most safe and secure? Does openness offer the most protections from bad actors?
- Moreover, Google is attacked because Open Source is more vulnerable to attack than proprietary software, per blogs by a leading open source proponent, here and here.
- Furthermore, Google’s own Director of entreprise application security, Eran Feigenbaum, told CIOs and CISOs: “A lot of data and access is exposed in an open API; it’s not the traditional UI that a user might expect.” “It is incumbent upon you as security officials to know what the security controls of your cloud provider are.”
5. Biggest “Free” Proponent: Like Google’s philosophy and activism for openness, Google is also widely-recognized as the leading proponent of “free content.” At Chris Anderson’s Google book signing of his book “Free: the Future of a Radical Price,” Mr. Anderson said: Google’s Chief Economist Hal Varian “taught me everything I know about free.”
- It is both human nature and business practice to treat what is “free” as if it has less value and like it is not in need of extensive protection or security measures.
- Since Google generally takes whatever information it can find and copy, and since it’s mission is to make that information universally accessible to everyone for free… in Google’s mind it should not be focused on making that information secure from those who seek it.
- The titanic big problem here is that while Google may view the information as free to users, users and others certainly don’t view the private information that cohabits Bigtable with “free” information, as not valuable or worthy of high security.
6. Big Monoculture Mindset: Google has a “monoculture” and a “one size fits all” approach to customer service per Yale computer science professor Michael Fischer. Google is well known for its vigorous hiring practices that demand top grades and scores from the top universities, mastery of Mensa brain teasers, and surviving a guantlet of interviews to weed out anyone that won’t fit in with the clone culture of the Google founders.
- The result is a very insular culture that tends to all share the same blinders. The most recent example of this monoculture-with-blinders is how Google claimed to have thoroughly vetted its Google Buzz service internally and no one within Google anticipated the privacy uproar that automatically exposing people’s previously private email lists to the public would be a problem.
- (Ten nations just sent an open letter to Google wondering how Google’s process could have so badly missed these obvious privacy concerns.)
- To better understand the depth of this Google monoculture and “group think” on security matters, consider how Google CEO Eric Schmidt described his Google culture goal in an Economic Club speech in Washington. The company’s goal is “to think big and inspire a culture of yes” and that “Google is melding a positive office culture with minimal accountability controls.” per Washington Internet Daily 6-10-08).
- A corporate culture that respected and valued security, would have a culture that encouraged someone to be able to say “no” and demanded substantial accountability controls.
In sum, for all the big reasons documented above, Google is a security-challenged company and “security is Google’s Achilles heel.”
-
Google’s titanic security flaws will only become more problematic now that hackers have figured out how vulnerable Google is, and more importantly, how accessible all this extremely valuable information is.
-
Simply, Google is too big not to fail.
***
- Part I: “Why security is Google’s Achilles heel”
- Part II: “Google values security much less than others do”
- Part III: “Google: “Security is part of our DNA” (Do Not Ask)
- Part IV: “Why Security is Google’s Achilles Heel”
- Part V: “Google Apps Security Chief is a magician/mentalist”
- Part VI: “Google-China: Implications for Cybersecurity”
- Part VII: “Did Google Over-React to China Cybersecurity Breach?”
For even more information, see the Security section of PrecursorBlog’s sister site: www.GoogleMonitor.com.
The abrupt change, that Google’s CEO Eric Schmidt will no longer be accountable to shareholders on Google’s earnings calls, should prompt investors to ask why?
- Google claimed that they wanted to put more focus on Google’s strong financials, but they did not disclose any more than Google’s usual barest of minimum of information to investors.
- The most obvious reason for this abrupt change is the literal explosion of real franchise liabilities and risk overhangs to Google that reared their ugly heads this past quarter.
- Had CEO Schmidt been available to answer investor questions, Google’s exploding liabilities could have dominated the Q&A and the investment narrative coming out of the earnings call.
What has changed, and what Google has been not been open about, is the very serious ripening of three different types of going-forward franchise risks (antitrust, privacy/security, and intellectual property) that cumulatively herald a de facto change in Google eras: from the roaring “Growth Decade” of 2000-2009, to the more unpredictable “Liability Decade” of 2010- 2019.
- Long-postponed simmering problems are now beginning to boil over and threaten to potentially burn Google shareholders periodically going forward. The result for:
- Opportunistic Google investors is recurring and intensifying headline risk overhang; and
- Longer-term Google investors is the increasing need to discount for the growing and uncertain franchise liabililities/risks emerging from multiple directions.
What franchise liabilities now overhang Google?
I. Antitrust
The speed, breadth and depth of Google’s growing antitrust liability is unprecedented. And where there is this much smoke there’s fire.
- FTC: The FTC is preparing to litigate to block Google’s acquisition of AdMob arguing that Google, the #2 mobile app advertiser with 25% share is attempting to monopolize over 70% of the relevant market by buying #1 Admob, which has 50% share.
- If Google chooses to fight the U.S. Government in court it would put Google’s antitrust liabilities on the front page and also cause the FTC, DOJ and the EU to circle Government wagons for a broader antitrust war with Google.
- If Google walks away, it suggests to investors that Google has acquiesced to the notion that Google has hit an antitrust wall and that Google may no longer rely on acquisitions as a source for: preemptive competitive defense against first-movers, growth or innovation.
- The FTC appears to be making good on its promise in approving Google-DoubleClick 4-1:
- “We want to be clear, however, that we will closely watch these markets and, should Google engage in unlawful tying or other anticompetitive conduct, the Commission intends to act quickly.”
- On a separate but related antitrust matter, the FTC has forced Google CEO Eric Schmidt to resign from Apple’s board and Google Director John Doerr to resign from Amazon’s board.
- DOJ: According to Sandy Litvack, the DOJ’s special counsel on the Google-Yahoo ad agreement, the DOJ was literally hours away from filing a Sherman Section 1 & 2 monopolization case against Google if it did not stop attempting to collude with Yahoo to corner the search advertising and search advertising syndication markets.
- The DOJ has now twice opposed (here and here) Google’s proposed book settlement as a violation of three different areas of law: antitrust, copyright, and class action. The most likely outcomes are Google agrees to a court decree with permanent DOJ supervsion of the settlement’s market mechanism in order to gain court approval, or the settlement is disapproved and DOJ eventually sues in a broader Google monopolization case.
- Evidence of the building clamor in D.C. for a DOJ Section 1 & 2 monopolization case against Google is a Consumer Watchdog Google antitrust panel hosted by John Simpson at the National Press Club (at 10:00 EST 4-21-10.) The panel features:
- Gary Reback of the Open Book Alliance and Microsoft antitrust fame;
- Simon Buckingham, a mobile advertising entrepreneur who believes Google-AdMob is anti-competitive; and
- Joseph Bial, the Cadwalader, Wickersham and Taft counsel representing TradeComet and MyTriggers in two different private antitrust lawsuits against Google.
- EU: What may be the most dangerous antitrust threat to Google may come from the recently announced EU preliminary inquiry into Google. It is likely to bloom into a broader formal investigation of Google because the EU has a much lower legal and policy threshold to bring an antitrust action than the U.S, and because the EU has never been shy about using its power to bring a dominant American firm to heel.
- Three companies, the UK’s Foundem, France’s Ejustice.FR, and Germany’s Ciao, have all alleged that Google punishes niche search competitors, by discriminating against them in Google’s search results and anti-competitively favoring Google-owned content with top search rankings.
- Foundem’s filing to the FCC is the best source of evidence of Google’s anti-competitive behavior and it is compelling.
II. Privacy/Security
Now that it is public that Google’s vociferous indignance over China’s censorship of its search results was clever PR misdirection from the real story, that Google’s main password system was hacked and breached, Google now has an incalculable liability to all its users and business, government, and foreign government customers whose personal information and secrets have been made available to who knows who — and those users who have had no ability to protect themselves for the last few months since Google became aware of the breach.
As John Markoff of the New York Times reported:
- “…the losses included one of Google’s crown jewels, a password system that controls access by millions of users worldwide to almost all of the company’s Web services, including e-mail and business applications.”
Google could be liable for the largest identity theft in history, and/or one of the largest corporate breaches ever. And Google does not believe it material for the CEO to disclose to shareholders in the quarterly call that covers it? This is precisely the type of new material adverse information that SEC rules mandate that shareholders be informed of so they can protect themselves. This extended lack of disclosure to people and businesses at risk is also an invitation for class action lawsuits by shareholders and users.
- Google has particularly large liability here to its users because, as I have written extensively in my “security is Google’s Achilles heel” research series, security has not been, and is still not a high public corporate and engineering priority for Google. Moreover, Google’s “publicacy” business model means that Google has collected much more private information on users than most any of them appreciate. (See my House testimony on Google privacy weaknesses.)
- Simply, Google has huge potential liability now because of Google’s longstanding low priority for security and Google’s anti-privacy “publicacy” business model characterized by CEO Schmidt’s cavalier statement on CNBC: “If you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place.”
Google’s CEO also ducked disclosing the new massive liability and threat to Google’s international business, which represents 53% of Google’s revenues. The Washington Post lead story that Google was working with the National Security Agency (NSA) on the China cyaber-security issue will make foreign governments and foreigners much less comfortable using Google’s products and services going forward.
- The liability for Google’s pervasive invasion of privacy norms around the world coupled with the news that Google is working with America’s top spy agency, means that nations around the world will be cracking down on Google more, or blocking their products, services and monetization more.
- This backlash is not hypothetical:
- Google blogged today that: “Google products — from search and Blogger to YouTube and Google Docs — have been blocked in 25 of the 100 countries where we offer our services.”
- Today a broad group of the data protection heads from many major countries have written an open letter to Google and other online companies asking that Google better safeguard private information. The countries included, Canada, France, Israel, Netherlands, Spain, Germany, Italy, Ireland, New Zealand, and the UK.
- Google’s privacy-security liabilty is real, material and growing/spreading fast. It is material and should be discussed in an open investor forum so shareholders can hear from Google the extent of Google’s liabilities. It will be interesting to what extent Google discloses these new exploding liabilities and risks to the SEC in their quarterly filings. (It should be of no surprise that the forensic accounting firm Audit Integrity characterizes Google’s accounting and governance as “very aggressive” and ranked in the top 3% for most risk.)
All these new privacy-security risks/liabilities are on top of:
- The disastrous launch and consumer privacy breach of Google Buzz that:
- Prompted an EPIC privacy complaint to the FTC and
- Embroiled Google’s former top lobbyist, Andrew Mclaughlin in a congressional oversight investigation for potentially deleting Presidential records.
- The FTC’s potential mandate of new consumer privacy safeguards for behavioral advertising that could hem in Google’s very aggressive tracking of most all Internet users web behavior. (See Google’s reply to the FTC urging they go slow.)
- The increasing potential for bipartisan comprehensive privacy legislation in the House that for the first time would give consumers more control over what private information Google could collect on them without their meaningful consent.
III. Intellectual Property
Viacom: Now that key documents have been made public in the Viacom vs. Google-YouTube copyright infringement trial, it is clear that Google has employed a deliberate business model/strategy to infringe copyrights to dominate traffic share.
- Anyone that reads the key Google documents in the case will come away with the concern that Google has deep legal, monetary and brand liabilities for serially infringing copyright to grow its business to dominance. Read the quote summary first here, then review the copious evidence/history in the 86 page Viacom Statement of Facts here, then review Viacom’s Summary Judgement memo of law here, and finally see the several new Google documents here.
- Google’s copyright infringement liablities will not end with Viacom. If Viacom prevails, which is likely, it will embolden all the other IP owners to redouble their efforts to gain restitution and a changed business model from Google. Those include, but are not limited to, news wires, newspapers, publishers, authors, songrwriters, studios, programmers, photographers, etc. (See Googleopoly IV at www.googleopoly.net)
Apple’s Trade Secrets Suit against HTC (Google):
Apple’s patent infringement suit against Google Nexus One manufacturer HTC, puts Google CEO Eric Schmidt, a former long time Apple Director, in potentially very hot water with Government officials. The suit looks like a very clever “carom shot” at Google CEO Schmidt as it allows Apple to legitimately discover CEO Schmidt’s emails involving any communication that Schmidt had with his mobile team concerning the development of Google’s Android operating system and Nexus One handset, especially after Schmidt returned from Apple board meetings. It is apparent that Apple believes that Google stole its intellectual property and trade secrets involving the iPhone and iPad, especially the multi-finger screen pinch control patent.
- This is a serious liability for Google’s CEO. Mr. Schmidt had a fiduciary duty to Apple shareholders not to harm them by lifting trade secrets for Google’s and Mr. Schmidt’s financial benefit.
- It also creates a strategic pincer situation/problem concerning Mr. Schmidt’s email practices. The Viacom case unearthed that Mr. Schmidt has a Quatrone-esque, “clean-up-those-emails” personal practice of deleting all his personal emails. This is particularly ironic and ineffective with a company that copies and stores most everything and deletes hardly nothing that it collects on people.
- It is also a big red flag for any investigator, because it strongly suggests that one knows they have something to hide, encouraging the investigators to examine everyone else’s emails that communicated with Mr. Schmidt at those times. At a minimum, Mr. Schmidt’s email deletion practices preventing any discovery creates a serious perception problem for Google as it goes before multiple court and policy fora.
In sum, the litany of exploding major liabilities to Google’s business model, growth and value — from the slew of real and worsening antitrust, privacy-security, and intellectual property problems — are not going away.
- These liabilities will increasingly overhang Google’s stock and brand, especially if Google continues to “turtle” and avoid public accountability to Google shareholders.
- Uncertainty and distrust are bad company attributes to allow to fester and grow.
- This past quarter certainly has been a fast start to “Google’s Liability Decade.”
***
For more information on these issues, see PrecursorBlog’s sister sites: www.GoogleMonitor.com and www.Googleopoly.net.