Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

151–160 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#151
post #23

Well if the EU wanted to make an example, Google just handed it to them.

Hopefully that battle comes sooner than later. Either the EU will fold, or we would get some real guidance about what honoring this GDPR legislation actually means. Clearly nobody has any frigging idea what is and is not in compliance.

> Clearly nobody has any frigging idea what is and is not in compliance

The existence of a gray area doesn't mean that everything is gray area.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#152
post #2

So, it's bad because it doesn't sync your history by default? Even if the UI is confusing, the worst case here is thinking that your data is being synced when it's not. It's like the opposite of a privacy problem.

It's bad because it's by default signing you into a service you didn't ask to be signed into, and don't have an easy option of turning this off. Sure, it doesn't automatically sync your browsing history now , but we all know change happens gradually. It's just a "feature" to be enabled later. I've never once signed into chrome in my life (on purpose). I don't want anything synced between browsers, I like to try and l…

>I've never once signed into chrome in my life (on purpose). I don't want anything synced between browsers, I like to try and limit what gets kept in the cloud, and with this change they've simply just taken the option away from the user.

At the jobs I've been in since browser syncing became a thing, where there were internal web tools, there has been an explicit policy against enabling it, out of security concerns. Regardless of how good the security might be at Google or Firefox etc. around their syncing stuff, if the content isn't there, it can't be compromised.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#153
post #136

Earlier quoted context omitted.

> I don’t understand why the Chrome team is picking this hill to die on Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this. > I really expect this change to push a lot of people away from chrome Care to bet on that? Because I would happily take the opposite side of that bet. I think th…

But the tech-savvy community has influence. We set up computers for our friends and families. We write IT policies. We are web developers, tech reporters, and more. At least for me, Google's behavior means that I can no longer recommend Chrome.

I can't imagine the impact is significant even if we consider two degrees of acquaintances (you tell someone to not use Chrome and they tell someone else).

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#154
post #132

Chrome has been the new IE for years. "just use chrome" is an endless refrain from webdevs who don't want to test on Firefox. Not sure why it is so hard for people to see what is going on here. Google has a massive conflict of interest with their web development efforts. This is classic Microsoft-esque Embrace, Extend, Extinguish.

That's a bad example. In technical progress, Chrome is the complete opposite of IE (which seems to be replaced by Safari these days) and way better than the rest in pushing forward new features. Also 99% of the time Firefox and Edge work just fine.

EDIT: Yes, IE was great in the beginning, but then it stagnated and earned the wide reputation of being terrible obsolete anchor that it is now known for. It's with this late-stage IE that I don't see the comparison since Chrome is still on the cutting edge.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#155

Earlier quoted context omitted.

> I don’t understand why the Chrome team is picking this hill to die on Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this. > I really expect this change to push a lot of people away from chrome Care to bet on that? Because I would happily take the opposite side of that bet. I think th…

I'm typically out of touch with normal people so I'm probably proving your point, but this has pushed me off chrome and Google. Ive always loved google. Installed chrome when it was released. I'm writing this from a pixel 2 XL because I broke my pixel 1 XL. I've had a Gmail account almost since it's been possible (I have my firstnamelastname@gmail.com). I now use firefox. I don't know what mail I'll switch to, and I…

I respect your feelings, but with respect to one of the factual details you listed: the "don't be evil" slogan never got removed from Google's Code of Conduct.

That document has been reworded and the slogan is now at the end, but it's been there continuously. While I agree it's more of a passing mention than in the old wording, the end is one of the most prominent placements possible for such a statement other than the beginning.

The common Internet belief that they removed this came from the Code of Conduct of Google's new parent company Alphabet, which says "Do the right thing" instead, combined with the subsequent rewording. But Google's still applies to Google as well.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#156
post #143
post #126

As a Googler with no connection to the Chrome team: I'm pretty sure they made this change in good faith and are shocked people don't like it. Just imagine yourself in their shoes: wouldn't your first instinct be to explain yourself?

Shock and Denial is the first stage in the 7 stages of grief. The chrome team is clearly in the wrong here, and it will take some time for them to realize that they screwed up and that they need to fix it.

I also work at Google though have nothing to do with Chrome.

This isn't "clear" to me. There are certainly complaints about this change within HN, but there are also people here saying that they appreciate the change, or that they're ambivalent.

But the more important part of things is that HN has what, maybe 10000 active users? Chrome has over a billion. Even if every HN commenter was vehemently against this change, that's less than 1% of 1% of Chrome's user base. If this change makes the browser better (using whatever metric you want, I'd argue the correct one here is privacy), even marginally, for the average user, at the cost of a few people believing that the browser is behaving badly, that seems like an overall good change, doesn't it?

And that seems to be what the Chrome team is arguing, that while some "abnormal" users might see this as an attack on privacy, it isn't, and it's a privacy increase for the uninformed user.

I think I've seen exactly one potentially compelling argument, which is that it may now be easier to accidentally enable syncing when you don't want to, since its a single click instead of entering a password. That might be true, although I'm not 100% certain, since I've logged into the wrong chrome window before, and that would have enabled syncing in a previous world.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#157
post #7

does chrome let you choose what to sync? opera does (which is also forked from chromium), and you can encrypt the data with your own pw

Just in case you weren’t aware; Opera is owned by a Chinese consortium. I personally wouldn’t touch Opera with a ten foot pole.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#158
post #126

As a Googler with no connection to the Chrome team: I'm pretty sure they made this change in good faith and are shocked people don't like it. Just imagine yourself in their shoes: wouldn't your first instinct be to explain yourself?

If that's true, then the Chrome team is severely insulated from their critics. Chrome's "Sign-In" feature has been on lists of features that privacy advocates have recommended avoiding for years, and watchdogs have consistently raised questions about Chrome's data collection policies and practices.

As a Googler, you should encourage your colleagues to read negative and critical coverage of your company and its products. It might be eye-opening to many of them what people actually like and dislike about the products they're building.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#159

Earlier quoted context omitted.

There's debate on if it's PII.

If an IP can be tied to a data subject's identity it's PII. If it can't, it's not. This isn't a debate.

But what counts as "can be tied"? Does asking the ISP that owns the address count? What about correlating with logs from other services you have access to?

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#160
post #143
post #126

As a Googler with no connection to the Chrome team: I'm pretty sure they made this change in good faith and are shocked people don't like it. Just imagine yourself in their shoes: wouldn't your first instinct be to explain yourself?

Shock and Denial is the first stage in the 7 stages of grief. The chrome team is clearly in the wrong here, and it will take some time for them to realize that they screwed up and that they need to fix it.

I think it's unlikely that the Chrome team will revert their decision. This will annoy people for a few days or even weeks, but people will eventually accept it.

That's just how you make unpopular changes these days.

Maybe the EU will do something about it, but this will take years.

Post reply on HN