Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

8/22/2011
05:32 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

5 Reasons Google+'s Name Policy Fails

Google should rethink its policy and empower users rather than restrict them.

Google should have recognized that the similarity between its Google+ name policy and the Internet usage policies favored by authoritarian regimes represents a problem.

The company's recently launched social network requires that users sign up under the name by which they're referred to in real life.

But not only is this maddeningly vague definition inconsistently applied, as has been demonstrated by individuals with unusual names like Stilgherrian and Violet Blue, it is poorly thought out. Some even suggest it is evil.

No, not evil on the scale of mayhem and physical harm. Evil as Google meant it in its unofficial motto, "Don't be evil." Evil with a small "e."

Google, like Facebook before it, offers a social network that doubles as a surveillance network.

Google maintains that it has only users' best interests at heart. But the company is doing as much harm as good by insisting on such an inflexible policy. It is depriving users of the opportunity to define their own level of comfort with online identity.

Google's legitimate interest in defining Google+ names extends to the aesthetic--insisting on a standard set of alpha-numeric characters--and the protective--insisting on non-offensive names. But Google should not be forcing users to participate in its social network under such inflexible terms.

The Google+ user should be able to choose to interact under his or her legal name, a pseudonym, or anonymously.

And in turn, other users of Google+ should be able to determine whether they want to see content generated by identified, pseudonymous, or anonymous users.

These decisions are not Google's business. Yet Google and its peers have made identity their business. Identity has become important because Facebook and the social gaming industry have proven that it appeals to the mass market audience.

Real names turn the hostile Internet into a friendlier place, like Disney World or the social gaming world, where people feel safe enough to pay for virtual seed to grow crops. This is a business that Google covets, as its newly launched Google+ Games section suggests. The focus on identity is not directly about marketing--a cookie ID number works as well as a real name. Rather, it's about building an environment that's minimally hostile to marketing and about making it easy for friends to find one another.

Identity is also essential for accountability. And therein lies the problem. By denying its users the ability to operate pseudonymously, Google is making Google+ users accountable to perceptions derived from online postings, activities, and associations. Accountability of this sort has consequences:

Google's Policy Exposes Users To Potential Harassment And Persecution

Unless Google's intent is for Google+ to be filled with banal, uncontroversial chatter, Google+ users can be expected say things that generate controversy. When there's legitimate cause to identify these people, existing legal processes will suffice to keep order. But Google's policy goes beyond what's necessary. It enables anyone with an axe to grind to target a Google+ user for harassment.

Google's Policy Stifles The Free Exchange Of Ideas

When people fear that their posts or profiles may be misconstrued or held against them, they won't speak freely. Anonymous and pseudonymous speech have a long, noble tradition in the history of American democracy. Google's lack of tolerance for this tradition is disappointing, to put it mildly.

Google's Policy Is Not Being Enforced Fairly

There's no shortage of reports of problems with the way Google has enforced its policy. It's hardly surprising. Names, and how people use them, vary and aren't going to fit into Google's box.

And it will get worse when Google allows businesses to participate: Businesses are pseudonymous entities in that their names aren't necessarily tied to the individual or individuals operating the business. Yet, a business can be formed by an individual, often without disclosing the identity of those involved in the business.

This is what's going to happen: Those seeking to use pseudonyms on Google+ will file fictitious name statements, or form some business entity, in order to use Google+ under a name that's not their own. Google should give up now, before it gets worse.

Google's Policy Denies Privacy

It's already well-established that employers and lawyers trawl through social networks. Without pseudonyms, the activities of Google+ users can more easily be correlated, on and off Google+. There are plenty of reasons that people may wish aspects of their lives to remain separate.

Google says it takes user privacy very seriously. Type "define: privacy" into Google and you get this: "The state or condition of being free from being observed or disturbed by other people." One could argue that social networks are inherently antithetical to privacy, but there's no good reason that Google couldn't offer both a social network and the limited privacy of a pseudonym.

Google Supports Pseudonyms Elsewhere

Google has already allowed pseudonyms with other services, like YouTube. Were the company to devote some of its considerable resources to improving comment filtering options, it would have quality discussion there too.

If Google really cares about its users--and projects like its Data Liberation Front suggest it does--then the company should revise its policy to be more tolerant of pseudonyms and revise its technology to give users the ability to block content by varying levels of identity. Google+ users, not Google, should setting the parameters for interaction.

See the latest IT solutions at Interop New York. Learn to leverage business technology innovations--including cloud, virtualization, security, mobility, and data center advances--that cut costs, increase productivity, and drive business value. Save 25% on Flex and Conference Passes or get a Free Expo Pass with code CPFHNY25. It happens in New York City, Oct. 3-7, 2011. Register now.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft to Officially End Support for Windows 7, Server 2008
Kelly Sheridan, Staff Editor, Dark Reading,  1/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7227
PUBLISHED: 2020-01-18
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, ...
CVE-2019-15625
PUBLISHED: 2020-01-18
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
CVE-2019-19696
PUBLISHED: 2020-01-18
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishi...
CVE-2019-19697
PUBLISHED: 2020-01-18
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administr...
CVE-2019-20357
PUBLISHED: 2020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.