|
|
|
|
|
by ImPostingOnHN
740 days ago
|
|
I think you have it backwards: an expectation is a standard (the term is used loosely here) that someone should be meeting. We expect people to do the right thing, but sometimes must, as in this case, assume they are doing the wrong thing. Applied here, the expected and right thing to do is follow the principles of least access. However, we must assume google is not doing this, because there is insufficient evidence that they are, and there is actual evidence that they don't have sufficient controls to limit who is able to see information. |
|
However, you make a fair point that it is reasonable to assume that entities you trust are willing to go above and beyond, for various reasons.