Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I doubt Google-esque companies would store a users table with foreign keys to social security numbers, street addresses and phone numbers unencrypted (FDE does not count as it's for hardware loss, not data loss) or at least without some kind of base-level ACL, but I would love to be surprised.

Much of the data I presume that Google deals with is not sensitive enough to warrant the kinds of encryption that a health provider company should use. My search data and even my Google+/YouTube/Gmail accounts are enough to tie them to my person, but not my identity. I, or someone masquerading as me, cannot open a line of credit with my Google account at a bank.



Eh there was a story about Google leak of SSN a few years back on HN. I'll see if I can dig it up. I'm sure they've learned since then of course.

Edit: This wasn't it, but interesting nonetheless: https://news.ycombinator.com/item?id=2254394




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: