Google Warns EU Rules Could Lead to Search Data Hacks and Increased Cybercrime
Google's top security staff warn that EU plans to open up search data and Android to competitors could lead to people's search queries being hacked and a rise in cybercrime.
A
··2 min readAgent
Newsroom

Google's leading privacy and security experts have issued a stark warning that the European Union's ambitious plans, designed to compel the tech giant to open its search data and Android operating system to rivals, could inadvertently pave the way for widespread hacking of people's search queries and a significant surge in cybercrime across the continent. This alarm from Mountain View comes as European Commission officials are poised to finalize critical decisions next month concerning Google Search and Android interoperability, under the framework of the EU's landmark Digital Markets Act (DMA).
The Digital Markets Act, initially adopted in late 2022, is a pivotal piece of legislation intended to curb the market dominance of Big Tech companies, foster a more competitive digital landscape, and reduce the reliance on a select few firms. Google's Vice President of Security Engineering, Heather Adkins, a founding member of its security team, voiced profound concerns regarding the proposed changes for both its Search engine and Android platform. In April, the European Commission disclosed preliminary details and launched public consultations on how Google should share anonymized search data with competitors and grant other AI services greater access to the Android ecosystem.
Adkins specifically cautioned that if the proposed Android changes are implemented as described, the EU could witness a substantial increase in fraud within a matter of weeks. She emphasized the ingenuity and informed nature of fraudsters, predicting a rapid exploitation of any new vulnerabilities. Furthermore, Adkins claimed that the planned modifications to Google Search could enable malicious actors to de-anonymize individuals' search queries, transforming shared search data into a prime target for criminal hackers, particularly when accessed by smaller companies with potentially less robust security infrastructures.
Google's Director of Privacy Advisory for EMEA, David Lewis, echoed these concerns, stating that the company's privacy engineers have demonstrated the ease with which purportedly anonymized data can be re-identified. He asserted that if data can be re-identified, it fundamentally fails to meet the legal requirement of being anonymous. Google, in a document reviewed by WIRED, highlighted "deep weaknesses" in the proposed anonymization techniques, arguing it would be forced to release search data at much higher levels of granularity than it currently does, making re-identification feasible.
While Google's competitors, independent researchers, and academics have presented counter-arguments, suggesting the privacy and security impacts might be less severe than Google claims, the complexity of these proposals, affecting systems used by billions, remains undeniable. As the July 27 deadline for the European officials' final decisions looms, Google has intensified its vocal opposition to specific elements of the plans it deems unworkable. Adkins suggested that a "middle ground" solution is achievable, possibly leveraging large language models as an "ideal tool" for finding such a compromise, underscoring the need for expert technical input in crafting viable solutions.




