Risk
8/22/2011
05:32 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

5 Reasons Google+'s Name Policy Fails

Google should rethink its policy and empower users rather than restrict them.

Google should have recognized that the similarity between its Google+ name policy and the Internet usage policies favored by authoritarian regimes represents a problem.

The company's recently launched social network requires that users sign up under the name by which they're referred to in real life.

But not only is this maddeningly vague definition inconsistently applied, as has been demonstrated by individuals with unusual names like Stilgherrian and Violet Blue, it is poorly thought out. Some even suggest it is evil.

No, not evil on the scale of mayhem and physical harm. Evil as Google meant it in its unofficial motto, "Don't be evil." Evil with a small "e."

Google, like Facebook before it, offers a social network that doubles as a surveillance network.

Google maintains that it has only users' best interests at heart. But the company is doing as much harm as good by insisting on such an inflexible policy. It is depriving users of the opportunity to define their own level of comfort with online identity.

Google's legitimate interest in defining Google+ names extends to the aesthetic--insisting on a standard set of alpha-numeric characters--and the protective--insisting on non-offensive names. But Google should not be forcing users to participate in its social network under such inflexible terms.

The Google+ user should be able to choose to interact under his or her legal name, a pseudonym, or anonymously.

And in turn, other users of Google+ should be able to determine whether they want to see content generated by identified, pseudonymous, or anonymous users.

These decisions are not Google's business. Yet Google and its peers have made identity their business. Identity has become important because Facebook and the social gaming industry have proven that it appeals to the mass market audience.

Real names turn the hostile Internet into a friendlier place, like Disney World or the social gaming world, where people feel safe enough to pay for virtual seed to grow crops. This is a business that Google covets, as its newly launched Google+ Games section suggests. The focus on identity is not directly about marketing--a cookie ID number works as well as a real name. Rather, it's about building an environment that's minimally hostile to marketing and about making it easy for friends to find one another.

Identity is also essential for accountability. And therein lies the problem. By denying its users the ability to operate pseudonymously, Google is making Google+ users accountable to perceptions derived from online postings, activities, and associations. Accountability of this sort has consequences:

Google's Policy Exposes Users To Potential Harassment And Persecution

Unless Google's intent is for Google+ to be filled with banal, uncontroversial chatter, Google+ users can be expected say things that generate controversy. When there's legitimate cause to identify these people, existing legal processes will suffice to keep order. But Google's policy goes beyond what's necessary. It enables anyone with an axe to grind to target a Google+ user for harassment.

Google's Policy Stifles The Free Exchange Of Ideas

When people fear that their posts or profiles may be misconstrued or held against them, they won't speak freely. Anonymous and pseudonymous speech have a long, noble tradition in the history of American democracy. Google's lack of tolerance for this tradition is disappointing, to put it mildly.

Google's Policy Is Not Being Enforced Fairly

There's no shortage of reports of problems with the way Google has enforced its policy. It's hardly surprising. Names, and how people use them, vary and aren't going to fit into Google's box.

And it will get worse when Google allows businesses to participate: Businesses are pseudonymous entities in that their names aren't necessarily tied to the individual or individuals operating the business. Yet, a business can be formed by an individual, often without disclosing the identity of those involved in the business.

This is what's going to happen: Those seeking to use pseudonyms on Google+ will file fictitious name statements, or form some business entity, in order to use Google+ under a name that's not their own. Google should give up now, before it gets worse.

Google's Policy Denies Privacy

It's already well-established that employers and lawyers trawl through social networks. Without pseudonyms, the activities of Google+ users can more easily be correlated, on and off Google+. There are plenty of reasons that people may wish aspects of their lives to remain separate.

Google says it takes user privacy very seriously. Type "define: privacy" into Google and you get this: "The state or condition of being free from being observed or disturbed by other people." One could argue that social networks are inherently antithetical to privacy, but there's no good reason that Google couldn't offer both a social network and the limited privacy of a pseudonym.

Google Supports Pseudonyms Elsewhere

Google has already allowed pseudonyms with other services, like YouTube. Were the company to devote some of its considerable resources to improving comment filtering options, it would have quality discussion there too.

If Google really cares about its users--and projects like its Data Liberation Front suggest it does--then the company should revise its policy to be more tolerant of pseudonyms and revise its technology to give users the ability to block content by varying levels of identity. Google+ users, not Google, should setting the parameters for interaction.

See the latest IT solutions at Interop New York. Learn to leverage business technology innovations--including cloud, virtualization, security, mobility, and data center advances--that cut costs, increase productivity, and drive business value. Save 25% on Flex and Conference Passes or get a Free Expo Pass with code CPFHNY25. It happens in New York City, Oct. 3-7, 2011. Register now.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7298
Published: 2014-10-24
adsetgroups in Centrify Server Suite 2008 through 2014.1 and Centrify DirectControl 3.x through 4.2.0 on Linux and UNIX allows local users to read arbitrary files with root privileges by leveraging improperly protected setuid functionality.

CVE-2014-8346
Published: 2014-10-24
The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile network traffic.

CVE-2014-0619
Published: 2014-10-23
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.

CVE-2014-2230
Published: 2014-10-23
Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) dest parameter to adclick.php or (2) _maxdest parameter to ck.php.

CVE-2014-7281
Published: 2014-10-23
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.