Customer Questions around Security/Privacy boundaries

98 views
Skip to first unread message

Julie Zhu

unread,
Jun 17, 2022, 7:06:56 PM6/17/22
to Google Cloud Translation API
Hi Translate API experts,

My customer is currently evaluating the use of translate API.
They have below questions, wonder if you can provide some guidance on it, thank you so much!

  • What privacy attestations are available for Google translate?
  • What security controls are available to limit access to “translated content”?
  • Does Google delete the translated content, or is it retained for any reason.?
  • Any other information you can shed some light on to help us better assess the use of Google translate.

Julie Zhu

unread,
Jun 21, 2022, 1:25:53 PM6/21/22
to Google Cloud Translation API
Gentle ping,

Anyone can point the customer to the right direction?

Thank you!
sincerely,
Julie
--

Julie Zhu

Customer Engineer @ Google Cloud

Mobile 860 480 5265

10 Summer Street, Boston, MA, 02110  


Yingjie He

unread,
Jun 21, 2022, 1:48:05 PM6/21/22
to Google Cloud Translation API
Hi Julie,

Here is the public doc for the data usage: https://cloud.google.com/translate/data-usage, I think it will resolve most of your questions.

Please let us know if you have other questions. 

Thanks very much!

Julie Zhu

unread,
Jun 29, 2022, 6:26:31 PM6/29/22
to Google Cloud Translation API on behalf of Yingjie He
Hi Yingjie and all,

This is super helpful! Thank you!

one additional customer concern, though, ( the doc doesn't address)

How does Translate API deal with issue when people use the translate solution to bypass firewall rules and access blocked sites?

As described in this article

Thank you!
sincerely,
Julie

--
You received this message because you are subscribed to a topic in the Google Groups "Google Cloud Translation API" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/google-translate-api/4pH7bt16_hw/unsubscribe.
To unsubscribe from this group and all its topics, send an email to google-translate...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/google-translate-api/1d7c653b-f632-44c8-bad0-b0f3b46beb59n%40googlegroups.com.

Julie Zhu

unread,
Jul 1, 2022, 12:23:40 PM7/1/22
to Google Cloud Translation API on behalf of Yingjie He
Hi Experts,

Just bubble this up, see if you can help with any pointers?

Thank you!
sincerely,
Julie

Raul Saucedo Ramirez

unread,
Jul 1, 2022, 5:28:30 PM7/1/22
to Google Cloud Translation API

This scenario you mentioned could happen if your firewall is misconfigured to the internet, you could have some security issues. You could follow official tutorials to correctly configure the firewall with a translation API. 

Julie Zhu

unread,
Jul 11, 2022, 1:08:04 PM7/11/22
to Google Cloud Translation API
Hi Raul and Translate team,

Customer's concern is not about firewall, firewall can be very well configured but using the method indicated here
People can still bypass firewall using translate api as a proxy.

What would be your recommendation to avoid /mitigate such breach?

\Thank you!
sincerely,
Julie

Jose Gutierrez Paliza

unread,
Jul 12, 2022, 11:34:50 AM7/12/22
to Google Cloud Translation API

The key principle to understand: Which IPs can connect to the instance: Port being secured by IAP[1]? Connections that don't go through GCLB or TCP API aren't subject to IAP access control.

If the firewall allows connections from any other IPs, those connections are not subject to IAP. This means that if your firewall allows connection from any other IP’s it is possible to have a bypass.

You could Restrict Peer Ip’s through a Cloud VPN Tunnel[2] reducing the risk of bypassing existing security controls.

For apps hosted on Google Cloud Load Balancing, you can configure the GCE firewall to allow direct access to the backend for certain IPs.


[1]https://cloud.google.com/iap 

[2]https://cloud.google.com/network-connectivity/docs/vpn/concepts/overview#vpn-org-policy 

Reply all
Reply to author
Forward
0 new messages