{"id":75855,"date":"2017-06-13T11:03:42","date_gmt":"2017-06-13T18:03:42","guid":{"rendered":"https:\/\/www.backblaze.com\/blog\/?p=75855"},"modified":"2021-08-09T11:34:17","modified_gmt":"2021-08-09T18:34:17","slug":"privacy-vs-convenience","status":"publish","type":"post","link":"https:\/\/www.backblaze.com\/blog\/privacy-vs-convenience\/","title":{"rendered":"Balancing Convenience and Privacy"},"content":{"rendered":"<p><a href=\"\/blog\/wp-content\/uploads\/2017\/06\/blog-header-lack-line.jpg\" data-rel=\"lightbox-gallery-KiCnlIjZ\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-75870\" src=\"https:\/\/www.backblaze.com\/blog\/wp-content\/uploads\/2017\/06\/blog-header-lack-line.jpg\" alt=\"balancing convenience and privacy\" width=\"100%\" height=\"auto\" srcset=\"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-header-lack-line.jpg 1440w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-header-lack-line-300x171.jpg 300w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-header-lack-line-1024x583.jpg 1024w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-header-lack-line-768x437.jpg 768w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-header-lack-line-560x319.jpg 560w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-header-lack-line-220x124.jpg 220w\" sizes=\"(max-width: 1440px) 100vw, 1440px\" \/><\/a><\/p>\n<p id=\"bzdropcap\">In early January of this year, in a conference room with a few other colleagues, we were at a point where we needed to decide how to balance convenience and privacy for our customers. The context being our team earnestly finalizing and prioritizing the launch features of our revamped Backblaze<a href=\"https:\/\/www.backblaze.com\/business-computer-backup.html\"> Business Backup<\/a> product. In the process, we introduced a piece of functionality that we call Groups. A Group is a mechanism that centralizes payment and simplifies management for multiple Backblaze users in a given organization or business. As with many services there were tradeoffs, but this one proved thornier than most.<\/p>\n<h2>The Trade-off Between Convenience and Privacy<\/h2>\n<p>The problem started as we considered the possibility of having a Managed Group. The concept is simple enough: Centralized billing is good, but there are clear use cases where a user would like to have someone act on their behalf. For instance, a business may want a system administrator to create\/manage restores on behalf of a group of employees. We have had many instances of someone from the home office ordering a <a href=\"\/blog\/life-and-times-of-a-backblaze-hard-drive\/\">hard drive<\/a> restore for an employee in the field. Similarly, a managed service provider (MSP) might provide, and potentially charge for, the service of creating\/managing restores for their customers. In short, the idea of having an administrator manage a defined collection of users (i.e. a Group) was compelling and added a level of convenience.<\/p>\n<p>Great. It\u2019s decided then, we need to introduce the concept of a Managed Group. And we\u2019ll also have Unmanaged Groups. You can have infinite Groups of either kind, we\u2019ll let the user decide!<\/p>\n<p>Here\u2019s the problem: The Managed Group feature could have easily been used for evil. For example, an overeager administrator could restore an employee\u2019s files, at anytime, for any reason\u2014legitimate or nefarious. This felt wrong as we\u2019re a backup company, not a spyware company.<\/p>\n<p>This is when the discussion got more interesting. By adding a convenience feature, we realized that there was potential for user privacy to be violated. As we worked through the use cases, we faced potential conflict between two of our guiding principles:<\/p>\n<ul>\n<li>Make backup astonishingly easy. Whether you are a individual, family, or business (or some combination), we want to make your life easier.<\/li>\n<li>Don\u2019t be evil. With great data storage comes great responsibility. We are the custodians of sensitive data and take that seriously.<\/li>\n<\/ul>\n<p>So how best to balance a feature that customers clearly want while enabling sane protections for all users? It was an interesting question internally\u2014one where a fair amount of meetings, hallway conversations, and email exchanges were conducted in order to get it right.<\/p>\n<h2>Enabling Administration While Safeguarding Team Privacy<\/h2>\n<p>Management can be turned on for any Group at the time of Group creation. As mentioned above, one administrator can have as many Groups as desired and those Groups can be a mix of Managed and Unmanaged.<\/p>\n<p>But there\u2019s an interesting wrinkle\u2014if management is enabled, potential members of that Group are told that the feature is enabled before they join the Group.<\/p>\n<p><a href=\"\/blog\/wp-content\/uploads\/2017\/06\/blog-group-managed-invite.png\" target=\"_blank\" rel=\"noopener noreferrer\" data-rel=\"lightbox-gallery-KiCnlIjZ\" data-rl_title=\"\" data-rl_caption=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-75857 size-full\" title=\"\" src=\"https:\/\/www.backblaze.com\/blog\/wp-content\/uploads\/2017\/06\/blog-group-managed-invite.png\" alt=\"Backblze for Business Group Invite\" width=\"1159\" height=\"550\" srcset=\"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-group-managed-invite.png 1159w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-group-managed-invite-300x142.png 300w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-group-managed-invite-1024x486.png 1024w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-group-managed-invite-768x364.png 768w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-group-managed-invite-560x266.png 560w\" sizes=\"auto, (max-width: 1159px) 100vw, 1159px\" \/><\/a><\/p>\n<p>We\u2019ve, in plain terms, disclosed what is happening before the person starts backing up. If you read that and choose to start backing up, then you have been armed with full information.<\/p>\n<p>Unfortunately, life isn\u2019t that cut and dry. What if your company selected Backblaze and insists that everyone join the Group? Sure, you were told there are administrators. Fine, my administrator is supposed to act in the constructive interest of the Group. But what if the admin is, as the saying goes, &#8220;for badness?&#8221;<\/p>\n<p>Our solution, while seemingly innocuous, felt like it introduced a level of transparency and auditability that made us comfortable moving forward. Before an administrator can do a restore on a Group member\u2019s behalf, the admin is presented with a pop up that looks like this:<\/p>\n<p><a href=\"\/blog\/wp-content\/uploads\/2017\/06\/blog-group-managed-restore.png\" target=\"_blank\" rel=\"noopener noreferrer\" data-rel=\"lightbox-gallery-KiCnlIjZ\" data-rl_title=\"\" data-rl_caption=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-75856 size-full\" title=\"\" src=\"https:\/\/www.backblaze.com\/blog\/wp-content\/uploads\/2017\/06\/blog-group-managed-restore.png\" alt=\"Backblaze for Business Restore Notification\" width=\"615\" height=\"262\" srcset=\"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-group-managed-restore.png 615w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-group-managed-restore-300x128.png 300w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-group-managed-restore-560x239.png 560w\" sizes=\"auto, (max-width: 615px) 100vw, 615px\" \/><\/a><\/p>\n<p>If the admin is going to create a restore on a user\u2019s behalf, then that user will be notified of the activity. A less than well intentioned admin will have some reluctance if he knows the user will receive an email. Since permission for this type of activity was granted when the individual joined the Group, we do allow the admin to proceed with the restore operation without further approval (convenience).<\/p>\n<p>However, the user will get notified and can raise any questions or concerns as desired. There are no false positives, if the user gets an email, that means an admin was going to restore data from the user&#8217;s account. In addition, because the mechanism is email, it creates an audit trail for the company. If there are users that don\u2019t want the alerts, we recommend simply creating an email filter rule and putting them into a folder (in case some day you did want them).<\/p>\n<h2>Customer Adoption<\/h2>\n<p>The struggle for us was to strike the right balance between privacy and convenience. Specifically, we wanted to empower our users to set the mix where it is appropriate for them. In the case of Groups, it\u2019s been interesting to see that 93% of Groups are of the Managed variety.<\/p>\n<p>More importantly to us, we get consistently good feedback about the notification mechanisms in place. Even for organizations where one admin may be taking a number of legitimate actions, we\u2019re told that the notifications are appreciated in the spirit that they are intended. We\u2019ll continue to solicit feedback and analyze usage to find ways to improve all of our features. But hearing and seeing customer satisfaction is a positive indicator that we\u2019ve struck the appropriate balance between convenience and privacy.<\/p>\n<p>The late 20th century philosopher, Judge Smails, once posited, \u201cThe most important decision you can make right now is what do you stand for? Goodness or badness?\u201d<\/p>\n<p><iframe loading=\"lazy\" title=\"Caddyshack-Are you my pal Danny?\" width=\"750\" height=\"563\" src=\"https:\/\/www.youtube.com\/embed\/LQMr9DvXXF8?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" allowfullscreen><\/iframe><\/p>\n<p>We choose goodness. How do you think we did?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By adding a convenience feature, we realized that there was potential for user privacy to be violated. As we worked through the use cases, we faced potential conflict between two of our guiding principles. <\/p>\n","protected":false},"author":131,"featured_media":75870,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[121],"tags":[471],"class_list":["post-75855","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-backing-up","tag-businessbackup","entry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Privacy vs. Convenience: How Backblaze Solved a Thorny Issue<\/title>\n<meta name=\"description\" content=\"By adding a convenience feature, we realized that there was potential for user privacy to be violated. Fundamentally we had a conflict that had to be solved.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.backblaze.com\/blog\/privacy-vs-convenience\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Privacy vs. Convenience: How Backblaze Solved a Thorny Issue\" \/>\n<meta property=\"og:description\" content=\"By adding a convenience feature, we realized that there was potential for user privacy to be violated. Fundamentally we had a conflict that had to be solved.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/\" \/>\n<meta property=\"og:site_name\" content=\"Backblaze Blog | Cloud Storage &amp; Cloud Backup\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/backblaze\" \/>\n<meta property=\"article:published_time\" content=\"2017-06-13T18:03:42+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-09T18:34:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-header-lack-line.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1440\" \/>\n\t<meta property=\"og:image:height\" content=\"820\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ahin Thomas\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@backblaze\" \/>\n<meta name=\"twitter:site\" content=\"@backblaze\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ahin Thomas\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Privacy vs. Convenience: How Backblaze Solved a Thorny Issue","description":"By adding a convenience feature, we realized that there was potential for user privacy to be violated. Fundamentally we had a conflict that had to be solved.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.backblaze.com\/blog\/privacy-vs-convenience\/","og_locale":"en_US","og_type":"article","og_title":"Privacy vs. Convenience: How Backblaze Solved a Thorny Issue","og_description":"By adding a convenience feature, we realized that there was potential for user privacy to be violated. Fundamentally we had a conflict that had to be solved.","og_url":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/","og_site_name":"Backblaze Blog | Cloud Storage &amp; Cloud Backup","article_publisher":"https:\/\/www.facebook.com\/backblaze","article_published_time":"2017-06-13T18:03:42+00:00","article_modified_time":"2021-08-09T18:34:17+00:00","og_image":[{"width":1440,"height":820,"url":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-header-lack-line.jpg","type":"image\/jpeg"}],"author":"Ahin Thomas","twitter_card":"summary_large_image","twitter_creator":"@backblaze","twitter_site":"@backblaze","twitter_misc":{"Written by":"Ahin Thomas","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/#article","isPartOf":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/"},"author":{"name":"Ahin Thomas","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#\/schema\/person\/d96439e8602526b2212669b824c41c49"},"headline":"Balancing Convenience and Privacy","datePublished":"2017-06-13T18:03:42+00:00","dateModified":"2021-08-09T18:34:17+00:00","mainEntityOfPage":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/"},"wordCount":999,"commentCount":1,"publisher":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#organization"},"image":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/#primaryimage"},"thumbnailUrl":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-header-lack-line.jpg","keywords":["BusinessBackup"],"articleSection":["Backing Up"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/","url":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/","name":"Privacy vs. Convenience: How Backblaze Solved a Thorny Issue","isPartOf":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/#primaryimage"},"image":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/#primaryimage"},"thumbnailUrl":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-header-lack-line.jpg","datePublished":"2017-06-13T18:03:42+00:00","dateModified":"2021-08-09T18:34:17+00:00","description":"By adding a convenience feature, we realized that there was potential for user privacy to be violated. Fundamentally we had a conflict that had to be solved.","breadcrumb":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/#primaryimage","url":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-header-lack-line.jpg","contentUrl":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-header-lack-line.jpg","width":1440,"height":820,"caption":"balancing convenience and privacy"},{"@type":"BreadcrumbList","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/privacy-vs-convenience\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Balancing Convenience and Privacy"}]},{"@type":"WebSite","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#website","url":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/","name":"Backblaze Cloud Solutions Blog","description":"Cloud Storage &amp; Cloud Backup","publisher":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#organization","name":"Backblaze","url":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/www.backblaze.com\/blog\/wp-content\/uploads\/2017\/12\/backblaze_icon_transparent.png?fit=512%2C512&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.backblaze.com\/blog\/wp-content\/uploads\/2017\/12\/backblaze_icon_transparent.png?fit=512%2C512&ssl=1","width":512,"height":512,"caption":"Backblaze"},"image":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/backblaze","https:\/\/x.com\/backblaze","https:\/\/www.youtube.com\/user\/Backblaze","https:\/\/en.wikipedia.org\/wiki\/Backblaze"]},{"@type":"Person","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#\/schema\/person\/d96439e8602526b2212669b824c41c49","name":"Ahin Thomas","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1fd29930968c75c628d357b38fd5439de48f41a51a2ce641021e242cafbb946d?s=96&d=blank&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1fd29930968c75c628d357b38fd5439de48f41a51a2ce641021e242cafbb946d?s=96&d=blank&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1fd29930968c75c628d357b38fd5439de48f41a51a2ce641021e242cafbb946d?s=96&d=blank&r=g","caption":"Ahin Thomas"},"description":"Ahin enjoys writing in the third person, cookies (digital or baked), and is listening to the Matt Nathanson \"Live in Paradise\" album.","sameAs":["https:\/\/www.backblaze.com","Ahin"],"url":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/author\/ahin\/"}]}},"jetpack_featured_media_url":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2017\/06\/blog-header-lack-line.jpg","_links":{"self":[{"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/posts\/75855","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/users\/131"}],"replies":[{"embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/comments?post=75855"}],"version-history":[{"count":0,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/posts\/75855\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/media\/75870"}],"wp:attachment":[{"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/media?parent=75855"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/categories?post=75855"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/tags?post=75855"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}