Live data from Hacker News

The Many Ways Google Harvests Data

wsj.com

51–60 of 189 posts

Re: The Many Ways Google Harvests Data

#51

i find it interesting that no one points out how much data AT&T and Verizon have collected ... they know the location of your phone, which cell tower you are connected to, which stores you've been in and when, who you've called, who has called you, all of which can be cross referenced ... and there is no reason to think they don't where the IP they supplied you has been, to which websites you've visited, etc ... same…

ISPs present a tiny footprint compared to the global tech behemoths (they're regional), and they already actually are significantly regulated even with the loosening of various restrictions over the past year or so. Contrary to popular belief, ISPs can't sell your browsing history legally, whereas tech companies generally can.

Re: The Many Ways Google Harvests Data

#52
post #5

Earlier quoted context omitted.

> controls that I trust. I think this trust might be misplaced. > Example: Location history. It is turned off by default. Displaying your location history to you is turned off by default. Google's own recording of your location, for their purposes, cannot be turned off.

> Google's own recording of your location, for their purposes, cannot be turned off. Citation needed. Android even lets you turn off AGPS, which collects anonymous location data to update itself. As far as I know, this is not even possible on iOS.

I'll copy an earlier post of what I found:

On Android, I noted before that when I turned on and off location services, the GPS lock was near instantaneous (i.e. when I turned on location, Google Maps located me with GPS precision immediately. There could be other ways of how this happens, it was noted in another post of mine, but that had still had me a bit suspicious. I replaced Google Play Services with microG recently (https://lineage.microg.org/). I then saw that it was MicroG, NOT the OS, that had control over my location, and MicroG still tracks my location when Location is off(https://github.com/microg/android_packages_apps_GmsCore/wiki...).

While none of this conclusively points to Google Play Services tracking me when it is off, the way that Android is set up makes me very strongly suspect that's what they did.

Re: The Many Ways Google Harvests Data

#53
post #45
post #3

Just some of the ways Google collects data [1]: Google Search, Google Fiber, Google Recaptcha, Google Translate, Google Adsense, Google Chrome (Safe Browsing checks etc.), Google DNS (8.8.4.4 etc.), Google Mail, Android Integrations, Google GSuite (Sheets, Docs, etc.), Google Drive, Google Analytics, Google AMP, YouTube So on and so forth. Of course, Google keeps most of this data to themselves to improve products an…

A more egregious way Google collects data on internet users is through their hosted libraries service. You visit some completely unaffiliated site which happens to use jquery or some other library and instead of hosting it themselves they have a script tag with a src=ajax.googleapis.com/...

The solution to this is here:

https://decentraleyes.org

Re: The Many Ways Google Harvests Data

#54

Earlier quoted context omitted.

Firefox extensions can be malicious too, but this has nothing at all to do with backend data security, a red herring. If you create an open system that allows users to do anything to their systems, you create footguns. I don’t see you whining that this is universally true for desktop computers as well.

I agree with you, though it should be noted that Mozilla does review the addons submitted to AMO, including - if this hasn't changed in the past few years - reviewing the code. I don't know how effective those are in preventing malware, though.

Human reviewers are not fabulous at detecting make are sight unseen. This is also wildly unscalable.

Re: The Many Ways Google Harvests Data

#55
Why is Apple given a pass?

They gave all their China user data to the China government so they could stay in China to make a buck. Is that not selling users data?

Versus Google chose to leave China instead of handing over the data.

https://www.amnesty.org/en/latest/news/2018/03/apple-privacy... Campaign targets Apple over privacy betrayal for Chinese iCloud ...

Re: The Many Ways Google Harvests Data

#56
post #45
post #3

Just some of the ways Google collects data [1]: Google Search, Google Fiber, Google Recaptcha, Google Translate, Google Adsense, Google Chrome (Safe Browsing checks etc.), Google DNS (8.8.4.4 etc.), Google Mail, Android Integrations, Google GSuite (Sheets, Docs, etc.), Google Drive, Google Analytics, Google AMP, YouTube So on and so forth. Of course, Google keeps most of this data to themselves to improve products an…

A more egregious way Google collects data on internet users is through their hosted libraries service. You visit some completely unaffiliated site which happens to use jquery or some other library and instead of hosting it themselves they have a script tag with a src=ajax.googleapis.com/...

For that, see https://developers.google.com/speed/libraries/terms

That stuff is kept separate from all account data (like with Google DNS[0] and fonts[1], too): no common cookies, "unauthenticated" (ie. no cross-referencing with Google accounts), logs retain no referrers

[0] https://developers.google.com/speed/public-dns/privacy [1] https://developers.google.com/fonts/faq#what_does_using_the_...

Re: The Many Ways Google Harvests Data

#57

Earlier quoted context omitted.

I agree with you, though it should be noted that Mozilla does review the addons submitted to AMO, including - if this hasn't changed in the past few years - reviewing the code. I don't know how effective those are in preventing malware, though.

Human reviewers are not fabulous at detecting make are sight unseen. This is also wildly unscalable.

Extensions do not come in at the volume of YouTube videos. Not only is the scale orders of magnitude smaller: But there's little to gain from an endless supply of browser extensions.

Unreviewed browser extensions should not be permitted, full stop. Microsoft has (finally) figured this out: There's a few dozen Edge extensions which Microsoft has vetted, and that's it.

Additionally, scrutiny for extensions can be filtered by their capabilities. In my given example, the issue is the ability to read and modify content on all websites you view: This permission should only be granted after extreme scrutiny, whereas an extension which can only access a single domain and does a simple thing needs only a cursory glance.

Re: The Many Ways Google Harvests Data

#58
44 blocked scripts loading the article - nearly half of which was tracking related. Surely the irony of that isn't lost on people? Google's ability to track users is 99% entirely due to companies like the WSJ using them for tracking users. These companies are just as much to blame, if not more, than Google itself.

E: What I mean by that is Google provides the means, but Google couldn't track nearly half of all sites if nearly half of all sites weren't complicit in the tracking.

Re: The Many Ways Google Harvests Data

#59

Why is Apple given a pass? They gave all their China user data to the China government so they could stay in China to make a buck. Is that not selling users data? Versus Google chose to leave China instead of handing over the data. https://www.amnesty.org/en/latest/news/2018/03/apple-privacy... Campaign targets Apple over privacy betrayal for Chinese iCloud ...

Because Facebook sold to an entity with the wrong political affiliation and we still have not passed the stage of one group in denial for why they lost and until they exhaust things to point fingers at it is not coming to an end soon.

We all should be highly critical of Apple's stance in China and we should all fear the direction China is going because a great many Western politicians like that direction too and simply are working out how to sell it to us, from think of the children, stopping exploitation, stopping hate speech, and more.

Re: The Many Ways Google Harvests Data

#60
post #39

Earlier quoted context omitted.

> Google's own recording of your location, for their purposes, cannot be turned off. Citation needed. Android even lets you turn off AGPS, which collects anonymous location data to update itself. As far as I know, this is not even possible on iOS.

They do track it and will prevent logins from unusual locations. Happened to me when using a VPN.

Yes, but not through GPS, or the location information compiled about my logins would be way more accurate than it is (often off by 100-200 km in any direction). Probably IP based geo location (that would naturally trigger with VPNs that give you an IP in $whereever).

That has nothing to do with the GPS setting of your phone.

Post reply on HN