Earlier quoted context omitted.
What is (or was) the difference between signing in to Gmail in the browser, vs signing in to the browser without sync? (You might feel that this is a tipping point but it's still not a GDPR issue as far as I can tell.)
For one thing they have completely different privacy policies. By signing into the chrome they are automatically forcing people to accept the privacy policy that is far less private than the when people aren't signed in.
Am I logged in or not? GDPR case study on the example of Chrome browser change
181–190 of 507 posts
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#182Earlier quoted context omitted.
Shock and Denial is the first stage in the 7 stages of grief. The chrome team is clearly in the wrong here, and it will take some time for them to realize that they screwed up and that they need to fix it.
I also work at Google though have nothing to do with Chrome. This isn't "clear" to me. There are certainly complaints about this change within HN, but there are also people here saying that they appreciate the change, or that they're ambivalent. But the more important part of things is that HN has what, maybe 10000 active users? Chrome has over a billion. Even if every HN commenter was vehemently against this change,…
First off, since it applies to people logged out of Chrome and it forces them to log in it increases, not decreases, the chances of someone accidentally leaving their account available to others on the machine. Since the sync button no longer requires a password this means someone can log in at a library to check their email, walk away, and someone else can step up, hit the sync button, and steal all of their information.
They've just made people less secure, not more.
But lets take your argument and assume it's right. You could apply the same logic to every website on the internet- Amazon, people's bank accounts, phone companies, etc. Google is therefore abusing their status as the browser developer to give themselves special functionality that other websites can't give. This should open them up to a variety of antitrust actions (particularly in the EU).
At the end of the day this could have been done by letting people opt-in to the login. Add a button on the google login sites that say "log into browser as well" and let the people who want it click it.
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#183Earlier quoted context omitted.
Shock and Denial is the first stage in the 7 stages of grief. The chrome team is clearly in the wrong here, and it will take some time for them to realize that they screwed up and that they need to fix it.
I also work at Google though have nothing to do with Chrome. This isn't "clear" to me. There are certainly complaints about this change within HN, but there are also people here saying that they appreciate the change, or that they're ambivalent. But the more important part of things is that HN has what, maybe 10000 active users? Chrome has over a billion. Even if every HN commenter was vehemently against this change,…
How does automatically signing me into Chrome improve my privacy?
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#184As a Googler with no connection to the Chrome team: I'm pretty sure they made this change in good faith and are shocked people don't like it. Just imagine yourself in their shoes: wouldn't your first instinct be to explain yourself?
I give them the benefit of the doubt on their intentions (although I'm less sure about upper management). But regardless of their intentions, they need to get better at thinking ahead.
Situations like this are always a little complicated, so I don't want to oversimplify or claim that they should have been psychic. But... it really shouldn't have been hard to tell that people would be upset. I kind of feel like if nobody on the Chrome team could have predicted this, then the Chrome team is seriously out of touch with users.
I mean, heck, the change contradicted Chrome's own privacy policy, which had to be updated after the fact. Is there seriously no process to check stuff like that before features ship? How is anyone supposed to trust Google's privacy policy when any team can break it inadvertently and it takes a Twitter thread weeks later for them to find out?
The Chrome team has a nasty habit of simultaneously saying, "just trust us, we're experts, we know what we're doing", and "there was no way we could have predicted that users would be upset by this."
Both of those things can't be true.
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#185Chrome has been the new IE for years. "just use chrome" is an endless refrain from webdevs who don't want to test on Firefox. Not sure why it is so hard for people to see what is going on here. Google has a massive conflict of interest with their web development efforts. This is classic Microsoft-esque Embrace, Extend, Extinguish.
That's a bad example. In technical progress, Chrome is the complete opposite of IE (which seems to be replaced by Safari these days) and way better than the rest in pushing forward new features. Also 99% of the time Firefox and Edge work just fine. EDIT: Yes, IE was great in the beginning, but then it stagnated and earned the wide reputation of being terrible obsolete anchor that it is now known for. It's with this l…
It was IE who added XMLHttpRequest and invented AJAX.
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#186Earlier quoted context omitted.
Safari is the new IE, Chrome has been responsible for a huge number of positive changes in the browser landscape. I develop in Chrome because that's where the majority of our conversions come from. I (my QA team) also tests Safari, Firefox and other browsers where a significant number of conversions come from. I never heard "just use chrome" in any professional environment.
Same was true for IE, IE for instance pioneered asynchronous requests (which is pretty much the norm these days) and things like that - still was a bad browser though.
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#187Earlier quoted context omitted.
Shock and Denial is the first stage in the 7 stages of grief. The chrome team is clearly in the wrong here, and it will take some time for them to realize that they screwed up and that they need to fix it.
I also work at Google though have nothing to do with Chrome. This isn't "clear" to me. There are certainly complaints about this change within HN, but there are also people here saying that they appreciate the change, or that they're ambivalent. But the more important part of things is that HN has what, maybe 10000 active users? Chrome has over a billion. Even if every HN commenter was vehemently against this change,…
More importantly, doing so without users clearly knowing and consenting to it is a clear violation of GDPR. This is an absolute, not a relative standard. Which means that it doesn't matter how it compares to what things were like before.
This for Google could be up to a $2 billion fine. 2% of worldwide annual revenue - annual revenue is around $100 billion. It would only take 13 fines per year of that size to reduce Google to not being profitable.
So you shouldn't think about it as a question of opinions about UI design. Instead think about it as a question of liability. Do you as an employee want the people working on Chrome to be subjecting your employer to this kind of legal risk?
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#188I can see why they thought this was a good change. It makes the UX for G-suite apps much more pleasant, almost like you get the full functionality of G-suite productivity stuff as part of installing Chrome. For most people, that's a good thing. I think as tech people we systematically tend to under-think the second-order effects of the systems we build. Case in point, Chrome and G-suite being that closely integrated…
It's a good change only if you are permanently logged in to google services, which is probably why it seemed like a great idea to the Chrome team, who probably have no idea how much distrust Google has started to build up. It moves the browser closer to an app runner for google services - I'd understand that if this was on Chrome OS or a specific 'Google' app, but in a general purpose browser the browser chrome should never indicate login state about specific websites, nor should my browser be logging in to google itself. It was bad enough when that was a choice for users, now it is one policy change away from being obligatory.
This is how we end up living in a world where google has access to all your data. I've switched browsers due to the move, not just because of this specific action, but because combined with all the other dark patterns Google has engaged in recently, and their clear moves to abuse their monopoly in search, it tipped me over the edge.
I no longer use google search (have been using ddg for a while), and now no longer use google browsers as a result of their disregard for user privacy.
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#189As a Googler with no connection to the Chrome team: I'm pretty sure they made this change in good faith and are shocked people don't like it. Just imagine yourself in their shoes: wouldn't your first instinct be to explain yourself?
If that's true, then the Chrome team is severely insulated from their critics. Chrome's "Sign-In" feature has been on lists of features that privacy advocates have recommended avoiding for years, and watchdogs have consistently raised questions about Chrome's data collection policies and practices. As a Googler, you should encourage your colleagues to read negative and critical coverage of your company and its produc…
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#190I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…
I had some legitimately scary things that may or may not be tracking but I cannot explain it without tracking. I watch some youtube video where the audio mentions a historic place of battle and then seconds later it shows up in my Google Chrome autosuggestion because I wanted to google some more information on it. I dont see how that is possible, it was a very specific location. I only typed "battle of" and it showed…