Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

101–110 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#101
post #80

Earlier quoted context omitted.

> I think that currently pretty much every service, device and website violates the GDPR. Not really, my website doesn't :-) In case you're using Google Analytics, it's easy to make it compliant, you just activate IP anonymization, which you had to do anyway, out of common sense and because tracking by IP without consent was illegal anyway in countries like Germany. [1] https://support.google.com/analytics/answer/276…

> I'm sure the cost will be high for many companies, but that's just karma. What about for companies that do handle user data responsibly, but have trouble with the formal compliance costs?

If the company handled user data responsibly already, it means the company was already respecting the privacy laws already in place in major European countries, Australia, etc and GDPR compliance shouldn't cost anything.

There's also no such thing as responsible data handling for services tracking users without their consent. If no explicit consent was given, consent obtained with a layman explanation and with no dark patterns, then it shouldn't be legal.

The problem often isn't how the data ends up being used, the problem is that the data is collected in the first place.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#102
post #98
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

I've been considering switching over to Firefox after being a day-one adopter of Chrome and this helped become a tipping point to get me to switch over. Though, full disclosure: I've been working to limit Google services in my day-to-day life (Maps, Gmail, and now Chrome) in the last couple of months over privacy concerns.

I've been using Firefox for quite awhile as my primary browser. I'm now to the point that I only use Chrome for checking websites I'm working on. I've had no complaints about Firefox. For me it is fast and stable.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#103
post #52

Earlier quoted context omitted.

Why would it violate GDPR? Logging IPs, especially short-term, is pretty easy to justify

There's debate on if it's PII.

If an IP can be tied to a data subject's identity it's PII. If it can't, it's not. This isn't a debate.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#104
post #80

Earlier quoted context omitted.

> I think that currently pretty much every service, device and website violates the GDPR. Not really, my website doesn't :-) In case you're using Google Analytics, it's easy to make it compliant, you just activate IP anonymization, which you had to do anyway, out of common sense and because tracking by IP without consent was illegal anyway in countries like Germany. [1] https://support.google.com/analytics/answer/276…

> I'm sure the cost will be high for many companies, but that's just karma. What about for companies that do handle user data responsibly, but have trouble with the formal compliance costs?

Mostly, I think GDPR makes reasonable requests for how you obtain, handle, store and use personal data. I think that the compliance cost for a company already doing ‘the right thing’ should be relatively low.

(Argument hinges on the idea that GDPR does overreach in what it asks to be compliant, happy to be proven wrong)

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#105
post #93

Earlier quoted context omitted.

I personally know people who think they are signing into Chrome when they sign into google.com. Maybe the Chrome team is right about their larger user base?

They could support both use cases by popping up a dialog on sign-in to a Google web property: "You're signing into Gmail. Would you like to link Chrome to joebloggs@gmail.com? This will enable automatic notifications in Gmail, sync passwords and web history, and also automatically log into other Google websites when you visit them". "Yes / No / No, and don't ask again"

Excuse my cynism but the options would be:

"Yes / Ask again later"

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#107
post #12

Earlier quoted context omitted.

The user has the option to not get through the "pile of nonsense" and just close the website. The fact that the user does not should tell you something. Unless you think every website should force the user to go through a 15 minute webinar to help them specifically understand privacy policies before letting them browse the website?

The lesson to companies should be, don't provide a Hobson's choice up front like this. Offer the webpage you meant to offer, and simply don't try to nickel and dime all the data out of your visitors.

So just kill the free and open internet and bring back the walled garden model of the mid 90s where you paid for website packages like you did for cable TV? That's not a future I want to live in.

Europe is playing a dangerous game with the internet right now and I don't think they have enough tech-minded people in power to keep things sane and in check.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#108
post #76
post #6

I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…

I had some legitimately scary things that may or may not be tracking but I cannot explain it without tracking. I watch some youtube video where the audio mentions a historic place of battle and then seconds later it shows up in my Google Chrome autosuggestion because I wanted to google some more information on it. I dont see how that is possible, it was a very specific location. I only typed "battle of" and it showed…

Google may have data that a lot of users searched for "battle of X" right after watching this particular youtube.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#109
post #2

So, it's bad because it doesn't sync your history by default? Even if the UI is confusing, the worst case here is thinking that your data is being synced when it's not. It's like the opposite of a privacy problem.

It's bad because it's by default signing you into a service you didn't ask to be signed into, and don't have an easy option of turning this off. Sure, it doesn't automatically sync your browsing history now , but we all know change happens gradually. It's just a "feature" to be enabled later. I've never once signed into chrome in my life (on purpose). I don't want anything synced between browsers, I like to try and l…

What is the service?

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#110
post #47

Earlier quoted context omitted.

It's bad because it's by default signing you into a service you didn't ask to be signed into, and don't have an easy option of turning this off. Sure, it doesn't automatically sync your browsing history now , but we all know change happens gradually. It's just a "feature" to be enabled later. I've never once signed into chrome in my life (on purpose). I don't want anything synced between browsers, I like to try and l…

What is (or was) the difference between signing in to Gmail in the browser, vs signing in to the browser without sync? (You might feel that this is a tipping point but it's still not a GDPR issue as far as I can tell.)

The difference for me is that, previously I knew I was multiple difficult steps away from having my browsing data uploaded to Google servers. That provided me a level of comfort that doesn't exist anymore. With the new method I'm one misclick away from giving everything to Google. Add on to this, Chrome has been increasingly pushy with its sign in prompts. There's no reason to think it won't eventually be equally pushy with its sync prompts.
Post reply on HN