Google+ Finds a Second Way to Die

Google+ Finds a Second Way to Die

Tech News data breach google google-plus privacy tech-news

Google+ Finds a Second Way to Die

So Google+ is getting killed off early. Again. Or I guess more accurately, faster than the first time they told us they were killing it.

Quick recap for anyone who wasnt paying attention back in October: Google admitted there was a bug in the Google+ API that let outside app developers see profile info — names, emails, occupations, that kind of thing — for basically half a million accounts, even ones marked private. That was the excuse to finally do what everyone already knew was coming and shut the consumer version of Google+ down, scheduled for August of 2019. Fine. Nobody cried.

Now, six days ago, Google put out a new post saying they found another bug. This one's bigger. They're saying up to 52.5 million users had profile fields exposed to developers who shouldnt have had access, and it sat there for about a week in November before their own internal testing caught it. Because of that, theyve moved the shutdown up to April 2019 instead of August. So Google+ doesnt even get the death date it was originally promised.

I dont think Ive logged into Google+ since maybe 2015, and even then it was to check if my employer at the time had actually gotten anyone to follow their business page (they had not, it was me and two bots). But theres something almost funny about a product dying of the exact same disease twice in two months. Its not like Facebook where the complaints are about what the product does. Nobody's mad Google+ is manipulating their newsfeed or selling ads against their vacation photos. Its just quietly leaking data nobody remembered was there, from a service nobody remembered using, and getting caught by nobody except Google's own engineers running routine tests. Thats almost a compliment, honestly, at least they found it themselves this time instead of the Wall Street Journal doing it for them.

Google says, again, that they have no evidence any of this data was actually misused. I believe them, mostly because I dont think misusing "job titles of dormant Google+ users" is a lucrative criminal enterprise. But "no evidence of misuse" is doing a lot of quiet work in that sentence, and it's the same phrase they used in October. At some point that stops being reassuring and starts being a tell that their auditing just isnt very good.

What actually gets me is the pattern, not this specific bug. This is a company that will happily kill a product you loved (RIP Reader, still not over it, wrote a whole post about that back in 2013 and I stand by every word) while apparently struggling to keep basic API permissions locked down on a product literally nobody was using anymore. Google+ had, what, a few thousand active daily users doing anything besides posting in tech forums by 2018? And it still managed to leak tens of millions of profiles because of an API bug that sat live for six days without anyone noticing. Thats not really a Google+ problem. Thats a "how many other APIs are sitting there quietly doing this right now and we just havent found out yet" problem.

Anyway. If you're one of the twelve people who still had a Google+ profile with photos or posts you actually wanted, you've now got until April instead of August to pull your stuff out, so dont wait until July like you were probably planning to. Takeout still works, it exports everything into a zip file that you will download once and never open again, which feels like the most fitting possible tribute to this entire platform.

I keep thinking about the fact that Google+ launched in 2011, the same year I started this blog. Eight years, and its ending not with the Facebook-style privacy scandal everyone predicted back when it launched, but with a whimper and a bug report. Somehow that tracks better than any dramatic ending would have.