Live data from Hacker News

Internet Companies: Confusing Consumers for Profit

eff.org

11–20 of 60 posts

Re: Internet Companies: Confusing Consumers for Profit

#11
Edit: My initial comment was incorrect, corrected version below.

Chrome Sync encrypts sync data on the client. By default the encryption passphrase is your Google Account password. This allows Google to read the data, as described here: https://support.google.com/chrome/answer/1181035?hl=en

However, you can set a separate Chrome Sync encryption passphrase in settings. This second passphrase is never sent to Google at all and allows you to use Chrome Sync without Google reading the data. It should be obvious why this is not the default, as requiring a second passphrase is a very significant decrease in usability, but it's there if you want it.

Re: Internet Companies: Confusing Consumers for Profit

#12

Edit: My initial comment was incorrect, corrected version below. Chrome Sync encrypts sync data on the client. By default the encryption passphrase is your Google Account password. This allows Google to read the data, as described here: https://support.google.com/chrome/answer/1181035?hl=en However, you can set a separate Chrome Sync encryption passphrase in settings. This second passphrase is never sent to Google at…

Then how is this scenario possible:

Set up Google account with password "abc" on PC1, use chrome, set bookmark.

Go to PC2, select "reset password" and reset Google account password to "123". Login to chrome with "123". The bookmark from before appears.

Re: Internet Companies: Confusing Consumers for Profit

#13

I'm not aware of the technical details of how the user is tracked. Is it possible to be tracked even if the user has logged out of the social network website (based on the browser or machine being used)?

The technical details are simple. When you are "logged in" to Facebook, your browser stores a unique token in a cookie that can identify you. That unique token is sent with every request the browser sends to FB, even requests you don't initiate directly. These hidden requests happen all the time, like when a web developer embeds a FB like button on a page. The like button is actually generated and served by FB's serv…

I like to always use incognito browsing sessions when logging into Facebook. At some point I cleared all my cookies too.

I remember a while back an article was posted about how to uniquely identify users without cookies though. I don't recall the exact method though, or if in this scenario it would require javascript and not just a link to a like button.

Re: Internet Companies: Confusing Consumers for Profit

#14

I'm not aware of the technical details of how the user is tracked. Is it possible to be tracked even if the user has logged out of the social network website (based on the browser or machine being used)?

The technical details are simple. When you are "logged in" to Facebook, your browser stores a unique token in a cookie that can identify you. That unique token is sent with every request the browser sends to FB, even requests you don't initiate directly. These hidden requests happen all the time, like when a web developer embeds a FB like button on a page. The like button is actually generated and served by FB's serv…

Good explanation. I don't know if it'd be worthwhile to track logged-out users though.

Lumping it in with the same data that came from the last logged-in user would make the data less valuable, because there's far less of a guarantee of which user the data was collected from (imagine people using Facebook on a library computer, then logging out and 20 more people using the computer before someone else logs in).

I'm sure there'd be some use for the data though, so I'm sure Facebook will gather it if they don't already have plans to. They could just earmark it with the probability that it applies to the given user.

Or just lump it all together as anonymous data, I'm sure there's value in that too.

Re: Internet Companies: Confusing Consumers for Profit

#15

I'm not aware of the technical details of how the user is tracked. Is it possible to be tracked even if the user has logged out of the social network website (based on the browser or machine being used)?

The technical details are simple. When you are "logged in" to Facebook, your browser stores a unique token in a cookie that can identify you. That unique token is sent with every request the browser sends to FB, even requests you don't initiate directly. These hidden requests happen all the time, like when a web developer embeds a FB like button on a page. The like button is actually generated and served by FB's serv…

Is it also possible that the user be tracked or is being tracked based on the machine used to access the internet (maybe over time for one to one mapping of user to machine)? Just curious.

Re: Internet Companies: Confusing Consumers for Profit

#16
>> Starting this month, Facebook will use them to track your visit to every Web page that displays the buttons—even if you don’t click on anything.

This is why I have had everything from facebook.com or fbcdn blocked on any sire other than facebook.com for some time.

Re: Internet Companies: Confusing Consumers for Profit

#18
post #12

Edit: My initial comment was incorrect, corrected version below. Chrome Sync encrypts sync data on the client. By default the encryption passphrase is your Google Account password. This allows Google to read the data, as described here: https://support.google.com/chrome/answer/1181035?hl=en However, you can set a separate Chrome Sync encryption passphrase in settings. This second passphrase is never sent to Google at…

Then how is this scenario possible: Set up Google account with password "abc" on PC1, use chrome, set bookmark. Go to PC2, select "reset password" and reset Google account password to "123". Login to chrome with "123". The bookmark from before appears.

My initial comment was incorrect and has been updated. However, have you actually tried the scenario you describe? In the past, when I have changed my Google account password and logged into a new computer, I have had to enter my previous account password on the new computer to decrypt the data before Sync would work. Indeed, if you look in Chrome Sync's settings, you will see text that looks like this: "All data was encrypted with your Google password as of Jan 17, 2015", letting you know which version of your password to use.
Post reply on HN