It's funny because different people would interpret this sentence differently.
If you have high level understanding of the tech behind it, this feels like a threat. But if you don't, this sounds like an honest message from someone who genuinely wants to protect you.
A regular user log into Google account and see their photos today. Tomorrow they log in and see the photos again. And they would assume this system will always work like this.
This actually happened to me - a decade ago or so, Google suddenly did not allow me to access my Google Mail unless I provided them with my phone number for "additional verification and security". I had got a job offer and was desperate to access my mail and so caved-in with a lot of resentment. (Ofcourse, now it is nearly impossible to create a Google account without a phone number, but in those days people considered phone numbers to be private and were leery at services that demanded it for sign-up). And then, later on they suddenly stopped allowing you to reset your passwords using email and security questions unless you provided them even more data for "verification" (which nearly often wasn't enough to allow you to recover the account).
Self-hosting will become the norm very soon.
I think the usual bottlenecks of "hard to manage, no backup" are no longer there. There are very good managed self-hosting solutions so you don't need to worry about anything.
You just run your immich instance and you're good
I’m not sure I understand why this particular line bothers you. They seem to just be emphasising that your Google account has a lot of information and therefore they are providing another way to secure it?
Whether this is a good method or not is a different discussion and I probably will not use this method
I uploaded a picture to Google Maps once. They told me they needed to access my photos to be able to upload the picture.
A week later I get a notification “hey do you want to upload this photograph of a restaurant you took at location x?”. So Google Maps was busy rifling through my photos while I was going about my day-to-day business.
GrapheneOS has storage scopes which make the app think it has full folder/file access but in reality you can choose the exact files or folders to give access. It helps keep invasive apps in line.
why are so many people so comfortable making this assumption, based on writing style or a checklist of supposed tells or notoriously unreliable detectors, and making kneejerk accusations like they can do no harm and are already settled fact? It's one thing to feel suspicious or disregard the article yourself, but being so incautious about making public accusations without solid evidence is another.
At best, you've identified LLM use. At worst, you've insulted a human writer. Either way, you've derailed the conversation away from the topic at hand.
There is no information about the author of this article, and it has the "AI smell". It's safer to operate under the assumption that it is AI generated unless and until the author reveals themself or at least anonymously confirms that it is not AI generated. This saves you from having made a fool of yourself by spreading it around, if it later becomes apparent that AI wrote it.
worst case, it's not generated and they just used ai for editing without realizing it has such a distinct style. that might be the case here: in the couple of paragraphs around the "I am but one" heading the writing style seems (to me) different (more human-ish?) compared to the style at the beginning.
unfortunately I also think they're quite bad, so I'm not sure what the moral here is for the author (who, true to their word, has elected to stay anonymous).
the question I asked in my comment isn't rhetorical, by the way: I genuinely think it's a pattern, and I want to look into it a bit deeper
oh and for the record, I don't suggest you disregard the article. it raises valid points and I agree with it. go read it!
Fucking hell, they modified Chrome/ium to pop up an application dialog (it's not just somr HTML inside the web page) to "log-in using Google".. fuck Google!
Maybe next they'll get Chrome to automatically turn on your webcam, capture your face and say "Thanks for logging in!"
uBlock Origin with the EasyList Annoyances filter is better than anything that Google can ever provide. I haven't seen Google popups in my desktop browser for a long time.
Yes it does. Biometric information (e.g a picture of your face) is famously not nearly as protected under the 4th amendment compared to things like passwords.
Anyone opting into this feature is effectively giving any US law enforcement (including ICE, local law enforcement, etc) free reign over their data.
If there were a Doomsday Clock for how close we are to "please drink verification can" (https://files.catbox.moe/eqg0b2.png), scientists would now move it to 3 minutes to midnight.
Can you please explain why it is depressing? This feature is widely celebrated in the accessibility user groups in India, since the traditional sign-in methods have been proven to be a major friction point for users with special needs.
I wonder. I know a lot of people who hate this kind of thing, but because they don't want to be "tinfoil hat oddballs" they just keep quiet.
I think it would be nice to applaud or support people who think this way.
Instead of ridiculing these folks, or using semi-apologist "you're not the target market" type comments, it would be nice to say "good for you" or support them in some other way.
Let us get this straight and clear, because at first reading it seems like an "innocent" extra option:
the risk we assess is that under some conditions the provider could block the account, and the user would remain locked out unless he had the ability to do camera-based verification, so camera-based verification becomes from just optional to substantially mandatory?
--
Edit: elsewhere it seems it is mandated:
> To help keep you and others safe online, you may need to complete additional steps to access certain services. This extra confirmation helps us verify that the account owner is a real person and that the account wasn't created or used by computer programs or bots for the purpose of abuse, like spamming
Plus,
> To take a selfie [for "selfie video verification"], you'll need a mobile device with a Camera app
Of course. I wish that Immich had existed when I started using Google Photos, but it didn't. And I'd just had my first child so I really wanted to ensure I didn't lose any memories.
These days I run the two in parallel.
Plus friends and family inadvertently give Google/Facebook (etc) your personal info via tagged photos, contacts, DMs without your consent and they gather/link/sell this collateral info to the highest bidder without anyone being the wiser.
Sure, but that's not the same thing. How they use the data is the important part. The google photos are not to be used for security for example. Different ToS.
We should try and not have a defeatist attitude and fight back as much as we can
Every time Google comes out with a new "feature" like this, it reminds me to resume my de-Googling journey with reinforced vigor. Drive and Photos are low-hanging fruit. GMail and YouTube will be more difficult.
I migrated away from Gmail after 15+ years to Fastmail, it wasn't that hard.
Whenever I got an email from a company to my Gmail, I logged into my account with that company and made the change. After about 2 or 3 years, I had 99.99% switched over.
Fastmail has a fast bulk import tool, and also allows you to automatically import future emails as the arrive (which is how I got that remaining 0.01% that only emailed me once every 5 years).
I gave each company a (unique identifier)@mydomain so that I could catch when my email address was sold, shared, hacked, etc, which has happened. That also allows me to easily move away from Fastmail to another service provider that has a catchall ability anytime I need to, but hopefully will never need to.
No government has yet regulated online services to require financial KYC compliance afaik, other than banking services which are already covered by ‘banking’. To the best of my understanding, the regulations about age verification don’t tend to mandate forever storage of the identity data, only storage of the verification outcome — even if business misrepresent that in order to harvest, train, aggregate, resell. (Whatever China is doing is not KYC: the government performs the Know verb in those cases, rather than the business.)
Meanwhile google has been locking out and closing the gmail accounts of people, myself included, that signed up before a phone number was required. If you don't log into your account for ~a year or so they will lock it and demand you log in. Which you can do, and you can even input the 2FA code, but it still won't let you log in because it says "there's not enough information to prove this is your account" despite having all the information ever associated with it. The only way to prevent deletion is to add a completely new, never before there phone number. I couldn't do that so they deleted mine saying I never logged in despite logging in literally dozens of times.
> The only way to prevent deletion is to add a completely new, never before there phone number.
Just happened to me. They "confirmed" it was me by getting a phone number they'd never seen before, that didn't belong to the false name on the account, and that I'd refused to give them for like 20 years. If anything, the fact that I eventually agreed to give them a phone number under duress was evidence that it wasn't me.
> despite logging in literally dozens of times.
Despite logging in literally thousands of times. I went in and deleted almost everything. Email now considered harmful. I'll feel better once they're locking me out of an empty account.
The problem is that everything in life requires a persistent email address, and hates email addresses that aren't on a whitelisted domain. The choice is between having some major provider, or not being able to pay your taxes online or log into your health insurance website. The fence is closing.
This already exists and is called FaceID and doesn't have the same privacy risks since the face check is done locally to allow the user to use the passkey to authenticate.
>Your selfie video is encrypted at rest
All data nowadays is encrypted at rest. That doesn't really matter since someone stealing a hard drive from Google with your information on it will never happen. The more likely risk is Google decrypts it and then sends it somewhere it shouldn't go and potentially trained into some AI system.
But I guess Google coming out with a cloud-based FaceID clone was just a matter of time...
apart from using just a vastly larger amount of 2D photos and more precise PI techniques, instead of that stupid local-only, small-AI-based, 3D-scanning technique that falls back to passwords...
eh, I prefer Apple as my good cop ever since I can afford Apple devices
The main threat, and this covers Face ID, is that law enforcement and ICE have a much easier time compelling these auth methods. The legal bar is much, much lower than passwords. You should always turn Face ID off when traveling, and ideally power off the phone.
What you are is one factor. What happened to MFA approach here?
Also it is a factor we cannot change, so if someone obtain a video of our face like that or success in making a working fake, we cannot change our look like we can with a password.
"Google analyzes one or more videos of a user's hand as they perform various actions or gestures. The video is processed to extract hand landmark data, which includes 21 hand-knuckle coordinates."
Some Countries and legislations radically ban reading private communications. So, there is no linear, direct assumption that the email provider abuses the role.
But there is a juridical mess, already evident in matters like the eu's "ChatControl" laws (exemption to national rules about privacy for communication providers).
reply