TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Some Google Photos videos in backups were sent to strangers in November

405 pointsby midefover 5 years ago

16 comments

brenden2over 5 years ago
The usual argument for using &quot;cloud&quot; over managing your own files&#x2F;data is that it&#x27;s very hard to safely manage your own data without making mistakes (data loss, etc). However, this is an example of how companies like Google also make mistakes. Furthermore, when Google&#x2F;FB makes a mistake (like leaking your private data) they do it at a global scale.<p>I offboarded myself from all of Google&#x27;s services a while ago, but I also think &quot;cloud&quot; is dead, at least in the cases where the cloud service holds the encryption keys on my behalf. I don&#x27;t trust, and never will trust, any company to hold on to my data without either selling it to a third party or accidentally leaking it.
评论 #22236905 未加载
评论 #22239280 未加载
评论 #22237072 未加载
评论 #22237290 未加载
评论 #22236321 未加载
评论 #22236444 未加载
评论 #22237389 未加载
评论 #22238600 未加载
评论 #22237446 未加载
评论 #22236425 未加载
评论 #22236919 未加载
评论 #22236187 未加载
nkriscover 5 years ago
So far it seems that Google is notifying the people who received videos that weren&#x27;t theirs, not yet the people what had their video leaked.<p>&gt; Google has been sending emails to affected Takeout users. In the email, which was first spotted by 9to5Google, Google writes, &quot;Some videos in Google Photos were incorrectly exported to unrelated user&#x27;s archives. One or more videos in your Google Photos account was affected by this issue. If you downloaded your data, it may be incomplete, and it may contain videos that are not yours.&quot;<p>&gt; While this message is directed to Google Takeout users who tried to download their own data and accidentally got someone else&#x27;s, we&#x27;ve yet to see a message directed to the &quot;unrelated users&quot; whose videos ended up in the archive. We&#x27;ve asked Google if it plans to notify users who have had their private videos exposed, and we&#x27;ll update this article if the company responds.<p>From <a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;gadgets&#x2F;2020&#x2F;02&#x2F;google-photos-bug-let-strangers-download-your-private-videos&#x2F;" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;gadgets&#x2F;2020&#x2F;02&#x2F;google-photos-bug-le...</a>
评论 #22240394 未加载
SnowingXIVover 5 years ago
How does this happen? I realize it&#x27;s a small percentage, but this is one of the first tests you build. Even 1 photo (not to mention this is regarding videos) should never make it to another non-authenticated user. This is a massive mistake.
评论 #22236694 未加载
评论 #22236623 未加载
评论 #22241518 未加载
评论 #22237663 未加载
评论 #22238969 未加载
评论 #22236084 未加载
friendly_frenover 5 years ago
Don&#x27;t store your private information in the cloud unencrypted. Caching bugs frequently leak unintended data.
评论 #22237732 未加载
评论 #22237922 未加载
londons_exploreover 5 years ago
Considering this is 4 months later... This can&#x27;t have been very widespread. If I saw someone else&#x27;s video in my takeout archive, I&#x27;d have totally contacted the tech media...
评论 #22241962 未加载
评论 #22239543 未加载
ipsum2over 5 years ago
It would be nice if they could tell you what photos&#x2F;videos were sent to strangers.
评论 #22238943 未加载
gregsadetskyover 5 years ago
Does anyone have suggestions for a self hosted photo service with - importantly - a solid iOS companion app to do photo sync and possibly browse photos?<p>I would prefer using a simple S3 backend. It seems that finding a reliable photo sync&#x27;ing app for iOS (outside of Google Photos or Dropbox) is difficult.<p>I&#x27;ve been manually using Image Capture and uploading to S3 but that&#x27;s quite inefficient. Thanks!
评论 #22240110 未加载
评论 #22240137 未加载
评论 #22240205 未加载
评论 #22242275 未加载
tyingqover 5 years ago
Interesting that the bug was in Takeout, which might have a fair amount of privacy concerned users that were trying to leave Google. Guessing some caching or <i>&quot;generate a unique url&quot;</i> type bug.
dangover 5 years ago
Url changed from <a href="https:&#x2F;&#x2F;www.theverge.com&#x2F;2020&#x2F;2&#x2F;4&#x2F;21122044&#x2F;google-photos-privacy-breach-takeout-data-video-strangers" rel="nofollow">https:&#x2F;&#x2F;www.theverge.com&#x2F;2020&#x2F;2&#x2F;4&#x2F;21122044&#x2F;google-photos-pri...</a>, which copies from this.
Machaover 5 years ago
I&#x27;ve seen services (Google Photos, Dropbox, OneDrive) try to opt in the user to having data automatically uploaded when they take a not really related action (like logging into the google account on their phone, connecting a USB device, or misclicking on an icon in their file list). I do wonder if there&#x27;s any penalty that&#x27;d apply to them if they then lost data that users hadn&#x27;t realised was being uploaded?
martythemaniakover 5 years ago
I posted this here a while back, some super-weird compilation of what appeared to be a random video showed up in my Assistant.<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=20373112" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=20373112</a><p>Seems like something similar. Ie, someone else&#x27;s weird crap was used by my account&#x27;s Assitant to make a compilation&#x2F;summary.
scarejunbaover 5 years ago
I&#x27;m pretty sure there&#x27;s a huge number of these CCPA&#x2F;GDPR implementation bugs. I know of a couple myself.
kerngover 5 years ago
This is big, and has GDPR fine written all over it. And I&#x27;m sure this will not be the last time we hear about this.<p>Also, very curious to learn more of the technical details down the road?
评论 #22236176 未加载
minikitesover 5 years ago
Google respects your data just as much as Facebook does.
TheCapnover 5 years ago
Now that&#x27;s spicy. Were people receiving random videos? Was this being targeted to retrieve videos of specific users through an exploit?
评论 #22236018 未加载
TuringTestover 5 years ago
Somewhat relevant: host your own web applications easily<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=22231922" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=22231922</a> Reviving Sandstorm (sandstorm.io)