Google Resolves One Foreign Issue, Succumbs to Another

Updated Emily Banks 1 Tallied Votes 380 Views Share

Just as it seemed one Google Street View debacle in a foreign country came to a resolution today, another was just beginning thousands of miles away.

The problems first began for Google in Germany in May, when the company's Street View vehicles collected private data that was sent across unencrypted Wi-Fi networks, according to the Christian Science Monitor .

After Germany's data protection authority detected Google's indiscretion regarding the collection of payload data.

"...It’s now clear that we have been mistakenly collecting samples of payload data from open (i.e. non-password-protected) WiFi networks, even though we never used that data in any Google products," the company said in a blog post at the time. "However, we will typically have collected only fragments of payload data because: our cars are on the move; someone would need to be using the network as a car passed by; and our in-car WiFi equipment automatically changes channels roughly five times a second. In addition, we did not collect information traveling over secure, password-protected WiFi networks."

The company chalked up the error to a mistake that stemmed from code written in 2006 for an experimental WiFi project.

Today Google announced it had come to an agreement with Germany. The company will accept requests from homeowners who would like their homes removed from the program. Google will also automatically blur faces and license plates.

"The engineering team at Google works hard to earn your trust—and we are acutely aware that we failed badly here. We are profoundly sorry for this error and are determined to learn all the lessons we can from our mistake," wrote Alan Eustace, senior vice president of engineering and research in the blog post from earlier this year.

That failure though continues to haunt the company as they expand Street View around the world.

It was likely the original privacy issue that came up earlier this year in May that caused South Korean police to seize computers at Google's Seoul office today. The authorities there are investigating if Google stole private data.

One official told the Korea Times that authorities were concerned Google had collected the personal data of people communicating over unsecured wireless networks.

Dani AI

Generated

A brief expert primer and practical follow‑ups to the points raised.

"Payload data" is not just SSIDs or router MACs — it is the body of 802.11 frames and can contain the actual content of communications (URLs, e‑mail/text content, login credentials). That technical distinction is why regulators and courts treated the Street View captures differently from simple network indexing. (streetviewsettlement.com)

What happened next matters for remedies and policy: the episode spawned consolidated lawsuits and a U.S. settlement that required deletion of captured payload data and limits on future collection in Street View, while the FCC later declined to treat the captures as wiretapping (but fined Google for impeding its probe). Different countries reached different conclusions, so legal outcomes varied by jurisdiction. (streetviewsettlement.com)

Practical takeaways for users (answering and echoing ): treating an open Wi‑Fi network like a private connection is risky, but there are effective mitigations. At home: enable WPA2 or WPA3, change default admin credentials, install firmware updates, disable WPS and guest isolation for IoT. On the go: turn off auto‑join, avoid sensitive transactions on unknown hotspots, use a reputable VPN for public Wi‑Fi, and prefer cellular data for banking. Also check that sites use HTTPS/TLS and enable multi‑factor authentication where possible. Official consumer guidance from the FTC and the National Cybersecurity Alliance covers these steps in plain language. (ftc.gov)

A final note for implementers: this was as much an organizational failure as a technical one — poor code reuse, weak review, and lax retention policies amplified the harm. Strong code review, privacy-impact assessments, third‑party audits, and minimal data‑retention rules are the practical controls that prevent a repeat. EFF and investigation reporting from the period highlight those governance lessons. (eff.org)

Agilemind 0 Posting Whiz in Training

And what is the real moral of this story: Don't use an insecure wireless connection for any personal information.

Fbody 682 Posting Maven Featured Poster

And what is the real moral of this story: Don't use an insecure wireless connection for any personal information.

Can I get an AMEN!!!?

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.