Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

191–200 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#191
post #167

Earlier quoted context omitted.

What's the point of signing in at all for users who don't use sync?

(if my understanding is correct) Consider the case of two users, Alice and Bob. Alice has sync enabled, Bob does not. Bob wants to check his email on Alice's computer, so he logs Alice off and logs into to his account. This syncs across all website he visits (due to shared auth cookies), but doesn't sync to the browser itself. Chrome is still logged into Alice's account, so Bob's browsing history is synced, but to Al…

If Bob logs into Alice's computer and forgets to log out all she has to do is hit the "sync" button and she can now view everything that's his synced with his account. Previously she would have at most his email, now she has that and more.

To me that seems like a decrease in privacy.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#192
post #143

Earlier quoted context omitted.

Shock and Denial is the first stage in the 7 stages of grief. The chrome team is clearly in the wrong here, and it will take some time for them to realize that they screwed up and that they need to fix it.

I also work at Google though have nothing to do with Chrome. This isn't "clear" to me. There are certainly complaints about this change within HN, but there are also people here saying that they appreciate the change, or that they're ambivalent. But the more important part of things is that HN has what, maybe 10000 active users? Chrome has over a billion. Even if every HN commenter was vehemently against this change,…

Let's just say that I don't want my porn throwaway gmail account to have anything to do with my personal or work accounts.

Ya'll fucked up big time. I uninstalled Chrome off all my computers today.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#193
post #164

Earlier quoted context omitted.

Same was true for IE, IE for instance pioneered asynchronous requests (which is pretty much the norm these days) and things like that - still was a bad browser though.

That's one point of comparison that glosses over Chrome's compliance with standards in stark contrast to IE.

Google is just playing the game (embrace, extend, extinguish) - meaning the outcome they try to achieve is the same.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#194
post #187

Earlier quoted context omitted.

I also work at Google though have nothing to do with Chrome. This isn't "clear" to me. There are certainly complaints about this change within HN, but there are also people here saying that they appreciate the change, or that they're ambivalent. But the more important part of things is that HN has what, maybe 10000 active users? Chrome has over a billion. Even if every HN commenter was vehemently against this change,…

How is sending my personal passwords to a server under Google's control an increase in my privacy? More importantly, doing so without users clearly knowing and consenting to it is a clear violation of GDPR. This is an absolute, not a relative standard. Which means that it doesn't matter how it compares to what things were like before. This for Google could be up to a $2 billion fine. 2% of worldwide annual revenue -…

>How is sending my personal passwords to a server under Google's control an increase in my privacy?

If this change did that, I might be inclined to agree with you. But as far as I know, it doesn't. You still have to explicitly opt in to syncing. Which is a no-op compared to the old behavior.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#195
post #167

Earlier quoted context omitted.

What's the point of signing in at all for users who don't use sync?

(if my understanding is correct) Consider the case of two users, Alice and Bob. Alice has sync enabled, Bob does not. Bob wants to check his email on Alice's computer, so he logs Alice off and logs into to his account. This syncs across all website he visits (due to shared auth cookies), but doesn't sync to the browser itself. Chrome is still logged into Alice's account, so Bob's browsing history is synced, but to Al…

How about popping up a message saying, "you're logging in to someone else's computer, would you like to do this in an incognito window?" Or something like, "you're signing in to a different Google account, would you like us to remember this account and preserve/sync history to account X, which is currently signed into Chrome".

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#196
post #185

Earlier quoted context omitted.

That's a bad example. In technical progress, Chrome is the complete opposite of IE (which seems to be replaced by Safari these days) and way better than the rest in pushing forward new features. Also 99% of the time Firefox and Edge work just fine. EDIT: Yes, IE was great in the beginning, but then it stagnated and earned the wide reputation of being terrible obsolete anchor that it is now known for. It's with this l…

I think you forget that in it's time IE was massively innovative. It was IE who added XMLHttpRequest and invented AJAX.

They did it by ironic accident.

Bill Gates wanted their browser to be the best, but also wanted it not good enough to replace desktop apps. However the right hand didn't know what the left hand was doing. The Outlook team was told to make a web version. They got the IE team to add XMLHttpRequest for their use, everyone implemented what they needed to, then went home and forgot about it.

Then Google recognized what the feature allowed, and used it in gmail and maps. The rest of the internet said, "Wait, what, you can DO that?" Studied it, popularized the technique as AJAX and the rest is history.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#197
post #150

Earlier quoted context omitted.

For one thing they have completely different privacy policies. By signing into the chrome they are automatically forcing people to accept the privacy policy that is far less private than the when people aren't signed in.

This doesn't seem to be turning on Chrome Sync, so users aren't being forced into any privacy policy: https://twitter.com/__apf__/status/1044109898013765632

Read the actual privacy policy, not the tweet talking about it. Primary sources are always best.

> The personal information that Chrome stores won't be sent to Google unless you choose to store that data in your Google Account by signing in to Chrome.

That doesn't say "unless you enable sync", it says it changes "by signing in to Chrome". Since they're now forcing you to sign into chrome without your consent they are also forcing you to accept that they can send your data to their services without needing any additional permissions from you.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#198
post #126

As a Googler with no connection to the Chrome team: I'm pretty sure they made this change in good faith and are shocked people don't like it. Just imagine yourself in their shoes: wouldn't your first instinct be to explain yourself?

They obviously didn't think through privacy issues very deeply, since it completely crashed with the privacy policy when it was released.

And the feature might be fine, but the UI is not good. It's confusing whether the big "sync" button says you are syncing, or lets you start syncing. And as this article says, when you go into "options" instead of clicking "undo", it starts syncing...

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#199
post #187

Earlier quoted context omitted.

How is sending my personal passwords to a server under Google's control an increase in my privacy? More importantly, doing so without users clearly knowing and consenting to it is a clear violation of GDPR. This is an absolute, not a relative standard. Which means that it doesn't matter how it compares to what things were like before. This for Google could be up to a $2 billion fine. 2% of worldwide annual revenue -…

>How is sending my personal passwords to a server under Google's control an increase in my privacy? If this change did that, I might be inclined to agree with you. But as far as I know, it doesn't. You still have to explicitly opt in to syncing. Which is a no-op compared to the old behavior.

Look in the OP for the phrase "Mistaken synchronisation". You'll land at a section where he verified the steps by which a confused user could easily turn on synchronization without understanding that they had done so.

Does this change your opinion?

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#200
post #126

As a Googler with no connection to the Chrome team: I'm pretty sure they made this change in good faith and are shocked people don't like it. Just imagine yourself in their shoes: wouldn't your first instinct be to explain yourself?

The Chrome team has been shocked about a lot lately. I give them the benefit of the doubt on their intentions (although I'm less sure about upper management). But regardless of their intentions, they need to get better at thinking ahead. Situations like this are always a little complicated, so I don't want to oversimplify or claim that they should have been psychic. But... it really shouldn't have been hard to tell t…

Of course they knew technical professionals would be upset. That's why they are prepared and they all can react with a single voice.
Post reply on HN