Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

91–100 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#91
post #5

Please, Google, fix those mistakes soon, and avoid a PR fiasco.

Nobody really cares outside this tech bubble. There won't be a PR fiasco, because it's hard to explain why it's bad for a non techie end user. "Google simplifies the login experience in Chrome", is essentially what's happening here and it's far from obvious how to sell it as a doomsday scenario as I read the mood correctly of many HN users.

Agreed, this will be forgotten about even by tech power users in under a week. Google needs to take the initial PR blow and then it will be over. The only thing that will put pressure on Google is EU with GDPR.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#92
post #80

Earlier quoted context omitted.

> I think that currently pretty much every service, device and website violates the GDPR. Not really, my website doesn't :-) In case you're using Google Analytics, it's easy to make it compliant, you just activate IP anonymization, which you had to do anyway, out of common sense and because tracking by IP without consent was illegal anyway in countries like Germany. [1] https://support.google.com/analytics/answer/276…

> I'm sure the cost will be high for many companies, but that's just karma. What about for companies that do handle user data responsibly, but have trouble with the formal compliance costs?

Not sure what your question is. If they handle data responsibly they're already compliant, no? In which case what compliance costs do such companies face?

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#93
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

I personally know people who think they are signing into Chrome when they sign into google.com. Maybe the Chrome team is right about their larger user base?

They could support both use cases by popping up a dialog on sign-in to a Google web property:

"You're signing into Gmail. Would you like to link Chrome to joebloggs@gmail.com? This will enable automatic notifications in Gmail, sync passwords and web history, and also automatically log into other Google websites when you visit them".

"Yes / No / No, and don't ask again"

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#94

Earlier quoted context omitted.

> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.

Super-simple answer: it's the law (GDPR). Kopplungsverbot. Art. 7 (4) GDPR. End of story. It says: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract. " It's like a butcher shop s…

The GDPR law says, "I consent" buttons that link to detailed policies are fine.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#95
post #2

So, it's bad because it doesn't sync your history by default? Even if the UI is confusing, the worst case here is thinking that your data is being synced when it's not. It's like the opposite of a privacy problem.

Anecdotally when I tested this the "sync your data" screen seemed a lot more like a "yes" prompt. Similar to Facebook's 3rd party fiasco of an app asking for tons of permissions, and just saying "accept" to be done with it. So most people are going to just sync their data and probably have no idea what's happening. They might not even care, but I don't think that is a good measure of if this is good or bad. Most users are ignorant.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#96
post #27

Earlier quoted context omitted.

> I don’t understand why the Chrome team is picking this hill to die on Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this. > I really expect this change to push a lot of people away from chrome Care to bet on that? Because I would happily take the opposite side of that bet. I think th…

> because nobody cares A lot of people do not understand, but we do, we're the techies. It's our job to understand. Don't mistake people not understanding for not caring. Once people understand, they care.

> Don't mistake people not understanding for not caring.

Once people understand, they care.

Conversely, don't mistake people not caring for not understanding. Many people both understand and don't care. Reasonable people can disagree about how their personal data should be monetized.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#97
post #45

Earlier quoted context omitted.

> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.

I'm not talking about ethics or business models. I just say that pretty much every site, device and service out there violates the primary rule of the GDPR. They all store data about their users without the users consent. One of the main points of the GDPR is that the user has to actively agree to storage of data. Making it very clear that storing can not be the default. Yet when you visit the New York Times today, t…

I'm not sure that is the interpretation the EU GDPR commission will use.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#98
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

I've been considering switching over to Firefox after being a day-one adopter of Chrome and this helped become a tipping point to get me to switch over. Though, full disclosure: I've been working to limit Google services in my day-to-day life (Maps, Gmail, and now Chrome) in the last couple of months over privacy concerns.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#99
post #27

Earlier quoted context omitted.

> because nobody cares A lot of people do not understand, but we do, we're the techies. It's our job to understand. Don't mistake people not understanding for not caring. Once people understand, they care.

Yeah, but my parents _understand_ Facebook collects/sells their data. But they don't _care_ enough to stop using Facebook.

Most people incorrectly think along the lines of "they have all my data already, so there's nothing I can do." Most probably also believe that many of the things that are going on are illegal and that someone is watching out for their interests. If they really understood the consequences of the data collection on a deeper level, most people wouldn't agree to it.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#100
post #80

Earlier quoted context omitted.

> I think that currently pretty much every service, device and website violates the GDPR. Not really, my website doesn't :-) In case you're using Google Analytics, it's easy to make it compliant, you just activate IP anonymization, which you had to do anyway, out of common sense and because tracking by IP without consent was illegal anyway in countries like Germany. [1] https://support.google.com/analytics/answer/276…

> I'm sure the cost will be high for many companies, but that's just karma. What about for companies that do handle user data responsibly, but have trouble with the formal compliance costs?

If you want to "handle user data" in any way but can't afford the formal compliance costs, then one less company is hoovering up user data. I don't see the problem.
Post reply on HN