Live data from Hacker News

Is Facebook Really Scarier Than Google?

nautil.us

331–340 of 360 posts

Re: Is Facebook Really Scarier Than Google?

#331

Earlier quoted context omitted.

> So because some things are a bad experience, we should make more things a bad experience? I don't see how disparate experiences are bad experiences. Those are two entirely different things. > if I were Uber or Lyft, I wouldn't want to deploy my app on a platform where another app with root privileges could, for example, change the GPS lookup location to something adversarial whenever uber was in the foreground, lea…

>I don't see how disparate experiences are bad experiences. Those are two entirely different things Inconsistent experiences is perhaps the single biggest complaint about Android as a platform. This is on comparison to iOS which has much stricter controls on how things can look and what you can do. Unified interfaces are better experiences. Predictability is a part of good ux. >Is there any reason this can't be done…

> losing Uber for a feature that will be used by 6 people is not a reasonable trade-off for a platform to make.

Than it stands that Google values money more than they value designing a system with their user's best interests in mind.

> Unless you mean that you think they are lying and secretly storing your data in which case there's a plethora of legal reasons they can't do that.

Yeah, because Google never lies about what they do with data, or how they collect it. /sarcasm

I have no direct evidence of them doing it this time, but fool me once...

The point is that they could make it work without being dependent on Google Play Services, but they choose not to.

Re: Is Facebook Really Scarier Than Google?

#332

Earlier quoted context omitted.

Do you trust the EFF? > The number one creepiest thing on our list of privacy-invasive practices comes courtesy of Verizon (and AT&T, which quickly killed a similar program after Verizon started getting blowback). > Snooping through your traffic and inserting ads Which ISPs did it before? AT&T, Charter, CMA > Hijacking your searches Which ISPs did it before? Charter, Cogent, DirecPC, Frontier, Wide Open West All of t…

> Snooping through your traffic and inserting ads Ok, so Google doesn't inject ads into your web traffic. But they inject ads into websites using AdSense, and into search results, and their products, and any technology linked to their ad platform (which is basically all technology related to the web). To increase ad revenue, they snoop on any personal data you store with Google. And they use their ads to collect more…

> The ISPs want a shot at making money off you, too

- Do you want your ISP tracking you and selling your private data? Do you think that is the place of an ISP?

- Does it bother you you are PAYING your ISP and they are reselling your data as well?

- Do you trust Comcast and Verizon and like that you are paying them to sell your data when you just want to use them to get online and are ok with this?

I don't think anyone argues Google has power but they aren't your 'gateway' to the internet that you pay for privacy.

Your argument is basically that you think Google has overreach so you want ISPs to take that from them or also do that?

I am against Google Fiber ISP having access that ISPs just won with bribery over innovation/product offerings that people want.

If Facebook had an ISP I wouldn't want them doing it either via the ISP.

> What I'm curious about is, why is the EFF so upset about what ISPs do, but not upset about what Google does, when Google's actions are literally affecting an entire industry and most of the world, and not just its own customers?

Products built on top of the internet are way different than products that are the base of the network. You should not be tracked at the network/gateway level ever.

If ISPs 'want a shot at making money off you' then let them build a service such as a search engine, social network or maybe like Comcast is doing with Hulu. Don't give up your rights at the gateway of the web just because you have a grudge or bias against Google.

> Google has been reshaping the entire internet and web just to maximize the way they can profit off my personal information. I don't see the ISPs doing that.

Also your points about Google are rich considering you have a @gmail account in your HN profile. If they are so overpowering why do you use them and not your ISPs email system?

Since you have no issue with ISPs selling data that you are paying them to keep private, you would be fine with Google Fiber ISP also doing that? Careful what you wish for and freedoms you give up due to bias ...

Re: Is Facebook Really Scarier Than Google?

#333

Earlier quoted context omitted.

>I don't see how disparate experiences are bad experiences. Those are two entirely different things Inconsistent experiences is perhaps the single biggest complaint about Android as a platform. This is on comparison to iOS which has much stricter controls on how things can look and what you can do. Unified interfaces are better experiences. Predictability is a part of good ux. >Is there any reason this can't be done…

> losing Uber for a feature that will be used by 6 people is not a reasonable trade-off for a platform to make. Than it stands that Google values money more than they value designing a system with their user's best interests in mind. > Unless you mean that you think they are lying and secretly storing your data in which case there's a plethora of legal reasons they can't do that. Yeah, because Google never lies about…

>Than it stands that Google values money more than they value designing a system with their user's best interests in mind.

No, they value their average user over you specifically. If the average user will gain more from Uber than from the feature you suggest, it is in Google's users' best interest to not implement that feature.

>Yeah, because Google never lies about what they do with data, or how they collect it. /sarcasm

Then you can certainly name all the other times? There are a number of complaints about Google that I've heard, but being secretive about what data they collect is a new one.

Re: Is Facebook Really Scarier Than Google?

#334

Earlier quoted context omitted.

You don't think ISPs inject ads/tracking into requests after the page is rendered on subsequent requests and override ad networks? [1] > For years, Comcast and other large telecommunication companies around the world have injected javascript into your web browsing experience to serve advertisements and account notices. Their ability to do this stems from their upstream position as your Internet Service Provider (ISP)…

Can they inject javascript even in an https connection ?

The link I provided [1] has coinmarketcap.com that is forced HTTPS but not sure if that was or not.

There's some discussion of known Comcast injection here: https://news.ycombinator.com/item?id=15890551

The response from Comcast was [2]:

> This is our web notification system, documented in RFC 6108 https://tools.ietf.org/html/rfc6108, which has been in place for many years now. It presents an overlay service message on non-TLS-based HTTP sessions. If you click the X box or otherwise acknowledge the notice it should immediately go away. If that is not the case let me know and we'll have a look at what may be happening. [2]

But ultimately no, however there may be some possibilities:

- ISP offered 'apps'. Get people to agree to an install of some monitoring app for some [insert random marketing benefit] from ISP. Maybe if you install the app you get more data cap space etc and they can monitor browser access. Further, install this in known apps or as add-ons on setup for other apps.

- ISP offered 'VPN client' that again, gives some cheaper monetary benefit like more data cap space or more speed 'free', strips out other advertising or tracking as a benefit.

- ISP offered 'email client' that does all of the above.

- Check for subsequent request after page loads to known ad networks and replace with their own in HTTPS

- ISP level proxy MITM, modem customization for 'fast lanes' that are actually slow lanes.

- DNS level data collection not to inject but to sell marketing profiles via metadata and correlate with other data from apps.

First one is the most probable but as of right now HTTPS injection is obviously hard to do if not impossible without some social or security hole.

Nobody in here would probably fall for these attempts but most would considering the outrage that they didn't know friend harvesting was happening on Facebook. If whatever they try lowers their monthly data caps or limits then majority of people will do it.

Since ISPs are your 'gateway' to the internet and you pay them, most people assume trust and privacy, most don't know they bribed their way into the tracking/ad business, many didn't know cable tv modems had mics either. With that assumption of trust since people are paying them, they'll more easily fall for any of the possible attack/tracking vectors listed and more probably.

With the ISP privacy protections removed [3], my guess is most ISPs, due to lack of competition, end up more like hotel wifi where tracking/injection is the norm [4] as it is completely legal now. With the removal of privacy protections and net neutrality, we have killed the pristine, non tracked, private gateways to the internet we cherish.

[1] https://www.privateinternetaccess.com/blog/2016/12/comcast-s...

[2] http://forums.xfinity.com/t5/Customer-Service/Are-you-aware/...

[3] https://www.flake.senate.gov/public/index.cfm/2017/3/flake-i...

[4] https://medium.com/@nicklum/my-hotel-wifi-injects-ads-does-y...

Re: Is Facebook Really Scarier Than Google?

#335

Forget scary. Let's talk about utility. Facebook gives you distraction but Google gives you information (YouTube, Google Search, GMail, Maps, Voice, Fiber, Project Fi, etc) and is more restrictive about how it lets partners use its platform to interact with users.

YouTube suggesting extremist videos to people in order to maximize views is giving you “information”? Can we stop pretending Google is somehow more useful to the average person than Facebook?

Yeah, like YouTube might suggest that you do something like more extreme like machine learning if you like Python.

Re: Is Facebook Really Scarier Than Google?

#336

Earlier quoted context omitted.

> Snooping through your traffic and inserting ads Ok, so Google doesn't inject ads into your web traffic. But they inject ads into websites using AdSense, and into search results, and their products, and any technology linked to their ad platform (which is basically all technology related to the web). To increase ad revenue, they snoop on any personal data you store with Google. And they use their ads to collect more…

> The ISPs want a shot at making money off you, too - Do you want your ISP tracking you and selling your private data? Do you think that is the place of an ISP? - Does it bother you you are PAYING your ISP and they are reselling your data as well? - Do you trust Comcast and Verizon and like that you are paying them to sell your data when you just want to use them to get online and are ok with this? I don't think anyo…

[deleted]

Re: Is Facebook Really Scarier Than Google?

#337

Earlier quoted context omitted.

> Snooping through your traffic and inserting ads Ok, so Google doesn't inject ads into your web traffic. But they inject ads into websites using AdSense, and into search results, and their products, and any technology linked to their ad platform (which is basically all technology related to the web). To increase ad revenue, they snoop on any personal data you store with Google. And they use their ads to collect more…

> The ISPs want a shot at making money off you, too - Do you want your ISP tracking you and selling your private data? Do you think that is the place of an ISP? - Does it bother you you are PAYING your ISP and they are reselling your data as well? - Do you trust Comcast and Verizon and like that you are paying them to sell your data when you just want to use them to get online and are ok with this? I don't think anyo…

Your basic complaint is that it isn't fair that you can't opt out of your ISP pilfering your traffic. But 1) you can use https-only services, 2) you can use a vpn, and 3) you can use a different ISP. You obviously have alternatives, so there's no reason I can see that your ISP being unfair.

I care a teeny bit about privacy, but I care a whole lot more about anticompetitive monopolistic practices. IMO, ISPs are absolutely guilty of those - but my point is, so is Google. I care when somebody changes the design of the entire web for their company's sole profit.

That's why I'm pointing out Google's practices, and how I think they're doing much worse things than ISPs. If you don't care about anticompetitive monopolistic practices, and only care about privacy, then I can see how you might not mind what Google is doing. But soon, Google will be doing to you what they're making impossible for the ISP to do.

Re: Is Facebook Really Scarier Than Google?

#338

Earlier quoted context omitted.

Not if your browser sends it over HTTPS. Mozilla implementing it: https://www.ghacks.net/2018/03/20/firefox-dns-over-https-and... Google's: https://developers.google.com/speed/public-dns/docs/dns-over... Apparently Chrome uses this over QUIC, and Chrome's Data Saver also uses it IETF charter: https://datatracker.ietf.org/wg/doh/about/ The unfortunate side-effect of preventing your OS from doing DNS queries is DNS-bas…

DNS over HTTPS is great for the average Joe/Jane, but if you're technical and care about dns leaks ... I'd suggests a DNS over TLS (unbound) + filter setup. This way your dns traffic is still encrypted, and you retain the capability to block/proxy.

> you retain the capability to block/proxy

Only if you are smart enough to know the browser has its own resolver, and that you need to turn it off first. We may not be able to turn it off in the future, meaning if you want to have privacy you have to run a privacy-specific browser.

This may end up breaking traffic as Google shifts more and more of the web into its proprietary products. For example, Google owns the .DEV gTLD, and makes .DEV domains "completely closed for the sole use of Google". It may at some point buy some other gTLD (such as ".BLOG", which it was outbid for) and decide that the only way for you to access websites with domains using that gTLD is to use Google's DNS API. It may sound crazy, but if they already shut out everyone in the entire world from having a .DEV domain, this doesn't seem much crazier to me.

Re: Is Facebook Really Scarier Than Google?

#339

Earlier quoted context omitted.

> losing Uber for a feature that will be used by 6 people is not a reasonable trade-off for a platform to make. Than it stands that Google values money more than they value designing a system with their user's best interests in mind. > Unless you mean that you think they are lying and secretly storing your data in which case there's a plethora of legal reasons they can't do that. Yeah, because Google never lies about…

>Than it stands that Google values money more than they value designing a system with their user's best interests in mind. No, they value their average user over you specifically. If the average user will gain more from Uber than from the feature you suggest, it is in Google's users' best interest to not implement that feature. >Yeah, because Google never lies about what they do with data, or how they collect it. /sa…

> No, they value their average user over you specifically. If the average user will gain more from Uber than from the feature you suggest, it is in Google's users' best interest to not implement that feature.

No, they don't. They could make this an optional feature, and they choose not to. And I can't think of any way that preventing users from controlling there own data could be good for users.

> Then you can certainly name all the other times?

I can't name all the other times, but they misuse our data so often, they publish statistics about it:

https://transparencyreport.google.com/user-data/overview?use...

Re: Is Facebook Really Scarier Than Google?

#340

Earlier quoted context omitted.

>Than it stands that Google values money more than they value designing a system with their user's best interests in mind. No, they value their average user over you specifically. If the average user will gain more from Uber than from the feature you suggest, it is in Google's users' best interest to not implement that feature. >Yeah, because Google never lies about what they do with data, or how they collect it. /sa…

> No, they value their average user over you specifically. If the average user will gain more from Uber than from the feature you suggest, it is in Google's users' best interest to not implement that feature. No, they don't. They could make this an optional feature, and they choose not to. And I can't think of any way that preventing users from controlling there own data could be good for users. > Then you can certai…

>No, they don't. They could make this an optional feature, and they choose not to.

If adding such an optional feature causes Uber to leave the Android platform, adding the optional feature is a net loss to Android users. "You are not the user" rings true here.

To put this another way, if your "feature" harms the ecosystem, it is not, in fact, a feature.

I asked for examples of Google lying about data collection, which was the accusation you levied. You responded with Google being transparent about responding to legally binding government requests.

While you may feel that handing data over to the government is a misuse, Google is not secretive about this. They're very straightforward about the fact that they will obey lawful requests, and they're transparent both with affected users, and the general public, about when and how they comply with those requests, as evidenced by the report you just linked.

So I'll try this again: since you accused Google of lying about collecting data or lying about what they do with it, can you substantiate that accusation, by giving examples of Google lying about what data it collects, or lying about what it does with that data?

Post reply on HN