Showing posts with label privacy and security. Show all posts
Showing posts with label privacy and security. Show all posts

Government requests for user information double over three years

Donal Trung 4:15 AM Add Comment
In a year in which government surveillance has dominated the headlines, today we’re updating our Transparency Report for the eighth time. Since we began sharing these figures with you in 2010, requests from governments for user information have increased by more than 100 percent. This comes as usage of our services continues to grow, but also as more governments have made requests than ever before. And these numbers only include the requests we’re allowed to publish.
Over the past three years, we’ve continued to add more details to the report, and we’re doing so again today. We’re including additional information about legal process for U.S. criminal requests: breaking out emergency disclosures, wiretap orders, pen register orders and other court orders.

We want to go even further. We believe it’s your right to know what kinds of requests and how many each government is making of us and other companies. However, the U.S. Department of Justice contends that U.S. law does not allow us to share information about some national security requests that we might receive. Specifically, the U.S. government argues that we cannot share information about the requests we receive (if any) under the Foreign Intelligence Surveillance Act. But you deserve to know.

Earlier this year, we brought a federal case to assert that we do indeed have the right to shine more light on the FISA process. In addition, we recently wrote a letter of support (PDF) for two pieces of legislation currently proposed in the U.S. Congress. And we’re asking governments around the world to uphold international legal agreements that respect the laws of different countries and guarantee standards for due process are met.

Our promise to you is to continue to make this report robust, to defend your information from overly broad government requests, and to push for greater transparency around the world.

How not to get tricked: Your favorite online safety tips

Donal Trung 8:01 AM Add Comment
Whether it’s defending yourself from identity thieves or removing bad software from your family’s computer, it’s important to know how to stay safe online. Over the course of the past few months, we’ve explored the simple steps you can take to help keep yourself, your family and the web safer. And in celebration of October's National Cyber Security Awareness Month, for the past 30 days we’ve posted a daily tip on how to #staysafe online.


Even though our favorite month of the year is about to end, it’s good to know how to stay safe all year round. Here are the top five most popular tips from the month:

Security and privacy are important and Google provides tools to help you protect yourself and your information. For example, 2-Step Verification adds another layer of security to your Google Account. Google+ Circles and YouTube settings help you control what you share and keep your information private if you want to keep it to yourself. Verify Apps helps protect your phone from malware, and Android Device Manager will ring your phone and locate it on a map to help you find your device if you lose it (and remotely delete your information from the device if you can’t get it back).

For more information on how to stay safe and improve your online security and privacy, visit our Good to Know site, which has more information and details about Google’s tools and helpful advice on staying safe.

Securing your WiFi network

Donal Trung 8:01 AM Add Comment
This post is part of a regular series of privacy and security tips to help you and your family stay safe and secure online. Privacy and security are important topics—they matter to us, and they matter to you. Building on our Good to Know site with advice for safe and savvy Internet use, we hope this information helps you understand the choices and control that you have over your online information. -Ed.

More than a quarter of Internet users worldwide use WiFi at home to connect to the web, but many aren't sure how to protect their home network, or why it is important to do so. The best way to think of your home WiFi network is to think of it like your front door: you want a strong lock on both to ensure your safety and security.

When data is in transit over an unsecured WiFi network, the information you’re sending or receiving could be intercepted by someone nearby. Your neighbors might also be able to use the network for their own Internet activities, which might slow down your connection. Securing your network can help keep your information safe when you’re connecting wirelessly, and can also help protect the devices that are connected to your network.

If you’re interested in improving your home WiFi security, the steps below can help make your home network safer.

1. Check to see what kind of home WiFi security you already have.
Do your friends need to enter a password to get on your network when they visit your house for the first time and ask to use your WiFi? If they don’t, your network isn’t as secure as it could be. Even if they do need to enter a password, there are a few different methods of securing your network, and some are better than others. Check what kind of security you have for your network at home by looking at your WiFi settings. Your network will likely either be unsecured, or secured with WEP, WPA or WPA2. WEP is the oldest wireless security protocol, and it’s pretty weak. WPA is better than WEP, but WPA2 is best.

2. Change your network security settings to WPA2.
Your wireless router is the machine that creates the WiFi network. If you don’t have your home network secured with WPA2, you’ll need to access your router’s settings page to make the change. You can check your router’s user manual to figure out how to access this page, or look for instructions online for your specific router. Any device with a WiFi trademark sold since 2006 is required to support WPA2. If you have a router that was made before then, we suggest upgrading to a new router that does offer WPA2. It’s safer and can be much faster.

3. Create a strong password for your WiFi network.
To secure your network with WPA2, you’ll need to create a password. It’s important that you choose a unique password, with a long mix of numbers, letters and symbols so others can’t easily guess it. If you’re in a private space such as your home, it’s OK to write this password down so you can remember it, and keep it somewhere safe so you don’t lose it. You might also need it handy in case your friends come to visit and want to connect to the Internet via your network. Just like you wouldn’t give a stranger a key to your house, you should only give your WiFi password to people you trust.

4. Secure your router too, so nobody can change your settings.
Your router needs its own password, separate from the password you use to secure your network. Routers come without a password, or if they do have one, it’s a simple default password that many online criminals may already know. If you don’t reset your router password, criminals anywhere in the world have an easy way to launch an attack on your network, the data shared on it and the computers connected to your network. For many routers, you can reset the password from the router settings page. Keep this password to yourself, and make it different from the one you use to connect to the WiFi network (as described in step 3). If you make these passwords the same, then anyone who has the password to connect to your network will also be able to change your wireless router settings.

5. If you need help, look up the instructions.
If you’ve misplaced your router’s manual, type the model number of your base station or router into a search engine—in many cases the info is available online. Otherwise, contact the company that manufactured the router or your Internet Service Provider for assistance.

Please check out the video below to learn more about the simple but important steps you can take to improve the security of your Internet browsing.



For more advice on how to protect yourself and your family online, visit our Good to Know site, and stay tuned for more posts in our security series.

Helping passwords better protect you

Donal Trung 10:00 AM Add Comment
Knowing how to stay safe and secure online is important, which is why we created our Good to Know site with advice and tips for safe and savvy Internet use. Starting today, we'll also be posting regularly with privacy and security tips. We hope this information helps you understand the choices and control that you have over your online information. -Ed.

It could be your Gmail, your photos or your documents—whatever you have in your Google Account, we work hard to make sure it’s protected from would-be identity thieves, other bad guys, or any illegitimate attempts to access your information.

But you can also help keep your information safe. Think of how upset you would be if someone else got access to your Google Account without your permission, and then take five minutes to follow the steps below and help make it more secure. Let’s start with the key to unlocking your account—your password:

1. Use a different password for each important service
Make sure you have a different password for every important online account you have. Bad guys will steal your username and password from one site, and then use them to try to log into lots of other sites where you might have an account. Even large, reputable sites sometimes have their password databases stolen. If you use the same password across many different sites, there’s a greater chance it might end up on a list of stolen passwords. And the more accounts you have that use that password, the more data you might lose if that password is stolen.

Giving an account its own, strong password helps protect you and your information in that account. Start today by making sure your Google Account has a unique password.

2. Make your password hard to guess
“password.” “123456.” “My name is Inigo Montoya. You killed my father. Prepare to die!” These examples are terrible passwords because everyone knows them—including potential attackers. Making your passwords longer or more complicated makes them harder to guess for both bad guys and people who know you. We know it’s hard: the average password is shorter than 8 characters, and many just contain letters. In a database of 32 million real passwords that were made public in 2009, analysis showed (PDF) only 54 percent included numbers, and only 3.7 percent had special characters like & or $.

One way to build a strong password is to think of a phrase or sentence that other people wouldn’t know and then use that to build your password. For example, for your email you could think of a personal message like “I want to get better at responding to emails quickly and concisely” and then build your password from numbers, symbols, and the first letters of each word—“iw2gb@r2eq&c”. Don’t use popular phrases or lyrics to build your password—research suggests that people gravitate to the same phrases, and you want your password to be something only you know.

Google doesn’t restrict password length, so go wild!

3. Keep your password somewhere safe
Research shows (PDF) that worrying about remembering too many passwords is the chief reason people reuse certain passwords across multiple services. But don’t worry—if you’ve created so many passwords that it’s hard to remember them, it’s OK to make a list and write them down. Just make sure you keep your list in a safe place, where you won’t lose it and others won’t be able to find it. If you’d prefer to manage your passwords digitally, a trusted password manager might be a good option. Chrome and many web browsers have free password managers built into them, and there are many independent options as well—take a few minutes to read through reviews and see what would be best for your needs.

4. Set a recovery option

Have you ever forgotten your password? Has one of your friends ever been locked out of their account? Setting a recovery option, like an alternate email address or a telephone number, helps give the service provider another way to contact you if you are ever locked out of your account. Having an up-to-date recovery phone or email address is the best thing you can do to make sure you can get back into your account fast if there is ever a problem.

If you haven’t set a recovery option for your Google Account, add one now. If you have, just take a second to make sure it’s up to date.

We have more tips on how to pick a good password on our Help Center, and in the video below:

Your online safety and privacy is important to you, and it’s important to us, too. We’ve made a huge amount of progress to help protect your Google Account from people who want to break into it, but for the time being, creating a unique, strong password is still an important way to protect your online accounts. Please take five minutes today to reset your important passwords using the tips above, and stay tuned for more security tips throughout the summer.

Transparency Report: Shedding more light on National Security Letters

Donal Trung 11:10 AM Add Comment
Our users trust Google with a lot of very important data, whether it’s emails, photos, documents, posts or videos. We work exceptionally hard to keep that information safe—hiring some of the best security experts in the world, investing millions of dollars in technology and baking security protections such as 2-step verification into our products.

Of course, people don’t always use our services for good, and it’s important that law enforcement be able to investigate illegal activity. This may involve requests for personal information. When we receive these requests, we:

  • scrutinize them carefully to ensure they satisfy the law and our policies;
  • seek to narrow requests that are overly broad;
  • notify users when appropriate so they can contact the entity requesting the information or consult a lawyer; and
  • require that government agencies use a search warrant if they’re seeking search query information or private content, like Gmail and documents, stored in a Google Account.

When conducting national security investigations, the U.S. Federal Bureau of Investigation can issue a National Security Letter (NSL) to obtain identifying information about a subscriber from telephone and Internet companies. The FBI has the authority to prohibit companies from talking about these requests. But we’ve been trying to find a way to provide more information about the NSLs we get—particularly as people have voiced concerns about the increase in their use since 9/11.

Starting today, we’re now including data about NSLs in our Transparency Report. We’re thankful to U.S. government officials for working with us to provide greater insight into the use of NSLs. Visit our page on user data requests in the U.S. and you’ll see, in broad strokes, how many NSLs for user data Google receives, as well as the number of accounts in question. In addition, you can now find answers to some common questions we get asked about NSLs on our Transparency Report FAQ.


You'll notice that we're reporting numerical ranges rather than exact numbers. This is to address concerns raised by the FBI, Justice Department and other agencies that releasing exact numbers might reveal information about investigations. We plan to update these figures annually.



(Cross-posted on the Public Policy Blog)