The Macrosite for News, Analysis and Opinion about the Future of the Internet
Chris S. Vargas

Connecticut Takes Aim at Street View

Written by Chris S. Vargas
12/14/2010 23 comments
no ratings
DISCUSS     Email This

Google (Nasdaq: GOOG) can be a favorite punching bag for a lot of people and organizations, thanks to the company’s success and overwhelming position in the market. News regarding Connecticut’s attorney general, Richard Blumenthal, shows just how far some are willing to go.

Google admitted in May 2010 that its Street View cars, which drove all over the world to take imagery for Google Maps, had accumulated roughly 600 Gbytes of WiFi network data from 33 countries since the project began in 2007. While Google initially thought this data was fragmented and held no tangible information, it later learned it included emails, passwords, and Internet browsing information. Google has already turned over this data in Germany, France, Spain, and Canada, and destroyed the data for the countries of Ireland, Denmark, and Austria.

So where does the motivation come from for a single state in America to lash out toward Google? A call to the Connecticut AG’s office provides little information and a lot of phone hopping. No other state thus far has acknowledged any sort of legal action against Google regarding Street View. The only probable reason Google is holding onto any of the data at this point is legal counsel insisting that it could be requested later on for review.

While the vast majority of people do have secured WiFi connections for their homes and businesses, Google should not be held accountable for errant data or communications that it unintentionally intercepted from its Street View cars that traveled the country. One could go so far as to say that any person with a laptop can drive down just about any populated street in the world and find unsecured networks. Companies such as Starbucks, McDonald's, and Panera Bread all offer free WiFi with little concern for those connecting to their networks.

Since the Connecticut attorney general’s office is a public office for an elected official, it is safe to say that his actions are politically motivated. The headlines listed on Richard Blumenthal’s Website boast demands for data from a variety of sources besides Google, including the US Department of Homeland Security.

There is no way that this office, or even a team of offices working together, would possibly ever be able to analyze all of the data and information it's requesting from these various sources. The AG appears to be on a witch hunt. Or maybe the State of Connecticut has such a surplus of state revenue that it's willing to contract this analysis out to a company with strong political ties.

With data being collected in the terabytes (at a minimum), it is safe to say that even for Google’s own staff to filter the information that was taken would be an undertaking that they would dread. Realistically, without the cooperation from Google, the AG’s deadline of December 17, 2010, will never be reached.

From a legal standpoint, Google has already acknowledged that it collected more data than initially intended while its Street Cars were underway, which is different from the initial statement Google had released. If Connecticut or any government entity wishes to view the applicable errant data that was collected during Google’s Street Cars being in their jurisdiction, then by all means it should be available. But the manner in which the data is sought, and the allotment of time being provided to gather that data for review, needs to be taken into consideration as well.

By all rights, Google can send a fleet of its own attorneys to Connecticut and table this entire scenario long past the current AG’s term in office. Worst-case scenario would include Google forcing this issue to be moved to federal courts, which could take years to be heard.

Where is the motivation in this? Where is the cooperation that should be sought? The vast majority of politicians deeply understand the term “politics” and how to maneuver accordingly. Could the underlying aspect of the deadlines and the methods that are being followed be a direct result of some particular company or governmental office not having been secured properly? Is this a case of the AG’s office trying to regain some level of control over those entities? One can only wonder.

— Chris S. Vargas is a director at an independent consulting firm located in the Midwest that focuses on marketing, IT, and management initiatives for companies.

DISCUSS     Email This
Current display:       newest comments first       display in chronological order
Page 1 of 3   Next >
Jason_13
IQ Crew
Saturday January 29, 2011 9:00:52 AM
no ratings

It's been interesting to follow this.

According to Google the code to capture was part of another project that an engineer was working on.  Now why Google had an engineer working on a project to sniff WIFI networks, is beyond me.  The code obviously did more than just collect SSID information.

When Street View project came about they used this code with the intent to collect just SSIDs.  Maybe they were looking to provide a more complete mapping over what Wigle.Net already provides.

To capture the data they did, the code had to have been written and configured to use passive mode.  Putting the wireless card in passive mode allows it to work in monitor mode, thus being able to capture all frames on the channel.  This mode is not necessary to identify the SSIDs and MAC addresses of WIFI networks, as Google has claimed they were trying to capture.

They captured entire emails, names, addresses, telephone numbers, passwords, and who knows what else.

I find it hard to believe that Google had a failure in their Software Development LifeCycle (SDLC).  This would mean that through code review and testing cycles, no one noticed the data that was captured.  That seems a far stretch to me.

State laws on hacking being different, I suppose it depends on the state as to whether Google's actions were illegal or just negligent.

Texas penal code defines the offense as:

Sec. 33.02.  BREACH OF COMPUTER SECURITY.  (a)  A person commits an offense if the person knowingly accesses a computer, computer network, or computer system without the effective consent of the owner.

Access is defined as:

Sec. 33.01.  DEFINITIONS.  In this chapter:

(1)  "Access" means to approach, instruct, communicate with, store data in, retrieve or intercept data from, alter data or computer software in, or otherwise make use of any resource of a computer, computer network, computer program, or computer system.

 

So, here in Texas we would have to prove the interception, which Google has admited to.  We would also have to prove that they knowingly did so, probably a little more difficult to prove.

So, I think we should give Google a spanking and make them promise to never do it again.

 

Paul Whyte
Researcher
Saturday January 29, 2011 6:11:39 AM
no ratings

"The US state of Connecticut said Friday it would hold negotiations with Google over the collection of private wireless data by its Street View mapping cars and not take the Internet giant to court.

"This is a good result for the people of Connecticut," Connecticut attorney general George Jepsen said in a statement about the agreement reached between state authorities and Google."

 

Google won't be taken to court over data gather

Mr. Roques
Researcher
Friday January 14, 2011 9:09:36 AM
no ratings

While the case isn't going to be easy, I still think they did something wrong that should be penalized. 

pjpugliese
IQ Crew
Friday December 17, 2010 11:04:02 PM
no ratings

Totally agree with torriatte! People in this country are way to eager to bring causes against others and corporations. There are much better things money, and time can be spend on. 

pjpugliese
IQ Crew
Friday December 17, 2010 11:00:06 PM
no ratings

Yes, excellent explanation & information cvargas!. It really helps those who may be unaware of the cause of the data collection. 

cvargas
Thinkernetter
Friday December 17, 2010 10:43:36 AM
no ratings

Actually there won't be much of a ground for a criminal case whatsoever.  Since the networks were unsecured, those people are not protected under CESA (Cyberspace Electronic Security Act of 1999).  However Google is in compliance thus far under those same guidelines established in CESA.

Mr. Roques
Researcher
Friday December 17, 2010 9:59:10 AM
no ratings

Oh, so there's an implied hacking process... people don't just go around connecting to WiFis and collecting data.

In my opinion, there's a criminal act there.

cvargas
Thinkernetter
Wednesday December 15, 2010 5:49:33 PM
no ratings

The information was first considered to be fragmented, meaning that it was just miscellaneous bits of data that had no coherent meaning or structure.  The data was later to have been discovered to contain entire emails and other such communications (browser related data).  It was at this point that Google notified the various countries and requested from them guidance as to what to do with the data that was specific to their country.  Some indicated that they wanted to review the information collected and others choose to just have it deleted.

While I'm sure some of the SSID information was also collected, I cannot confirm that myself.  But the data collected could have only been captured through networks that had unprotected SSID's.  I know that I can drive down the road and pick up several SSID myself just on my smart phone.  Some of them are open and others not.

So the question still remains (and has yet to be officially answered by the ASA assigned to this investigation) as to what the actual pursuit is regarding this case.

Mr. Roques
Researcher
Wednesday December 15, 2010 5:22:55 PM
no ratings

Hey, let me ask you about those 600GBs of info that was captured from WiFis around the World... what type of information was it? At what point is that considered hacking? 

I first understood they had gathered info on SSIDs, locations, but it can't be that that they are so angry about... so what is it? 

cvargas
Thinkernetter
Wednesday December 15, 2010 2:30:24 PM
no ratings

Even if Blumenthal isn't the one actually responsible for this and will not be in that role once it is resolved, his name is still the one responsible for the investigation being the current AG. 

I'm certain that his history for consumer protection is something that every politician wishes they were known for, but the ASA that is responsible for this investigation has yet to still reply to the inquiry from when I called him seeking to obtain the AG office's response prior to publishing this article.

Regarding your statement "He has on the side of the consumer for years and this is a situation where big business is interfering with personal data", if this is the case then why has his office not gone after thousands of other businesses (banks, credit reporting agencies, large corporations, etc) that constantly abuse consumer information and ultimately never get mentioned?  And based upon that statement, Google was forthcoming with the aspect they collected the data and only wanted determinations from each jurisdiction as what was to be done with the information which ultimately should be viewed from the aspect that Google was taking responsibility for the incident and was willing to work with the various entities to get it resolved.

Page 1 of 3   Next >
The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from Chris S. Vargas
Chris S. Vargas
Near Field Communication (NFC) in the mobile market is a topic that may or may not be getting the consideration that it should. Certainly, there are potential uses for it, both good and bad.
5
of
IETV: the thinkerNet on film
5
of
2pm EDT
Thu
Mar 15th
an IBM information resource
sponsored content
an IBM information resource
sponsored content
Empowered CMOs, Empowered Customers
Chief marketing officers (CMOs) are at a crossroads. Like CFOs a decade ago, their position in the organization is about to change dramatically, impacting not only traditional marketing functions like public relations and promotion, but also requiring a greater partnership with fellow C-suite decision makers. In interviews with over 1,700 CMOs worldwide, IBM found that CMOs are keenly aware of their specific set of challenges.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Free Internet Act Could Launch Positive Change
Joe Stanganelli
In a recent Internet Evolution post, Ron Miller
likened the current legal battles regarding intellectual property and the Internet to a fantasy universe. While Ron specifically invoked The Lord of the Rings mythos in his piece, new developments on Reddit suggest that this fantasy realm analogy may more properly reflect the DC Comics Universe.

CLICK FOR MORE
Steve Saunders' Outernet
The Death of Anonymity: Part 4

Part 4 of 4   |  
See complete series
10|29|09   |   1:40   |   8 comments


In the final episode of this series about the death of Internet anonymity, Saunders describes how the Internet of the future will start to attain a level of intelligence that requires no human intervention. Scary.
Steve Saunders' Outernet
The Death of Anonymity: Part 3

Part 3 of 4   |  
See complete series
10|28|09   |   1:35   |   4 comments


What can users today do to protect their online privacy? The simplest and most obvious option is to not use the Internet – at all. However, once all digital information is consolidated over the Internet, trying to protect digital identity by simply unplugging from the Internet becomes impossible – a fact that has manifest implications for civil liberties, Saunders says.
Steve Saunders' Outernet
The Death of Anonymity: Part 2

Part 2 of 4   |  
See complete series
10|27|09   |   2:08   |   9 comments


By 2011 the number of Internet-connected sensors will exceed 1 trillion, making your chances of doing anything or going anywhere unnoticed pretty much zero. Saunders talks about how the 'sensortization' of the Internet is eliminating the traditional divide between online and offline populations.
Steve Saunders' Outernet
The Death of Anonymity: Part 1

Part 1 of 4   |  
See complete series
10|26|09   |   1:29   |   13 comments


The 20th Century Internet was characterized by the ability to interact with other people and information on the Internet largely without anyone knowing who you were. The Internet of this century, conversely, will be defined by identity. Saunders explains how Internet users are unwittingly contributing to the demise of the anonymous Internet.
Wisdom of the Big Chair
Feds Provide Solution to Android's Security Problems

2|2|12   |   2:24   |   6 comments


Malware designed to infect Google Android smartphones has increased dramatically, and now the government is stepping in. The National Security Agency has developed SE Android, a system that tries to close up its security holes.
Kim Davis
Doublespeak on Internet Freedom

12|13|11   |   02:08   |   5 comments


Hillary Clinton stands accused of hypocrisy after speaking up for Internet freedom at a conference last week.
Second Shooter
Seeking the Truth Online

12|8|11   |   2:10   |   11 comments


The quest for Webpage clicks and ad impressions is creating a market for sensational truths and lies in equal measure. How are we going to get to the bottom of any real issue online – like what's really going on with Carrier IQ, for example – if we can't separate hype from reality?
David Vladeck
Keeping Privacy Policies in Check

11|9|11   |   1:36   |   6 comments


The FTC points to a settlement with Google Buzz as a warning for companies that don't inform users when changing their privacy policies.
Ann Cavoukian
Privacy Is Everyone's Responsibility

11|1|11   |   4:01   |   12 comments


Ontario's privacy commissioner offers advice to businesses and users for protecting privacy online.
Wisdom of the Big Chair
Big Brother Is Watching the Web

10|19|11   |   2:57   |   6 comments


The US government is funding controversial projects to collect daily Internet activity, including Web searches, Twitter messages, Facebook and blog posts, and the digital location trails generated by billions of cellphones. Its goal is to map these interactions to predict social behavior, such as protests.
Kim Davis
Thinking Pretty at TED

3|2|12   |   2:14   |   1 comment


Dewar's Hub at TED 2012 is an interactive Twitter tool that lets you rummage vaguely through a world of ideas.
what.the.ferraro
Goodbye, Real Life. Hello Video in a Hat

3|2|12   |   2:36   |   7 comments


Are you officially done interacting with society? There's a hat for that.
Second Shooter
AT&T Creates More Neutrality Confusion

3|1|12   |   2:12   |   2 comments


The AT&T notion of letting some apps "buy" the data for its users seems inconsistent with the neutrality principles designed to keep big sites from dominating the Internet. Is the principle wrong, or is AT&T's policy wrong? We need a consistent position here.
Reiter's Block
The Web Needs National Grammar Day

2|29|12   |   2:59   |   52 comments


March 4 is National Grammar Day, and you enterprise and consumer bloggers need to pay attention.
Wisdom of the Big Chair
Video Conferencing Presents New Security Holes

2|28|12   |   1:57   |   4 comments


Video conferencing is becoming much more common in business today, but it introduces new security issues. For instance, intruders may be able to tap into your sessions and learn trade secrets. Here are steps companies can take to ensure their sessions are secure.
what.the.ferraro
Adventures With Siri

2|27|12   |   03:56   |   14 comments


Nicole and Kim (and their respective accents) request things of Siri, the iPhone 4S virtual assistant, to see what she's capable of. The result? Not much.
Second Shooter
Gaming May Drive Apple's 7-Inch iPad

2|24|12   |   2:05   |   15 comments


We think Amazon's Kindle Fire is pushing Apple to a smaller iPad format. But Sony's Vita and the interest in a small device for portable gaming may create the real threat. Keep your eye on the tablet-gaming space!
Reiter's Block
Google's Password Generator Is Limited

2|23|12   |   2:51   |   15 comments


Google's developing a password generator and manager for Chrome, but it's got a ways to go.
Kim Davis
Angry in Space

2|22|12   |   1:41   |   19 comments


We've come 50 years from John Glenn's first Earth orbit to the launch of "Angry Birds in Space." Progress?
Mary E. Shacklett
Corporate Email Needs Best-Practices

2|21|12   |   2:08   |   8 comments


Corporate email is a great natural time manager, a great way to communicate across time zones, and a natural way to keep records on ongoing projects and conversations. But there are limits to its benefits.

Enabling People and Organizations to Harness the Transformative Power of Technology