Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

231–240 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#231
post #126

As a Googler with no connection to the Chrome team: I'm pretty sure they made this change in good faith and are shocked people don't like it. Just imagine yourself in their shoes: wouldn't your first instinct be to explain yourself?

The Chrome team has been shocked about a lot lately. I give them the benefit of the doubt on their intentions (although I'm less sure about upper management). But regardless of their intentions, they need to get better at thinking ahead. Situations like this are always a little complicated, so I don't want to oversimplify or claim that they should have been psychic. But... it really shouldn't have been hard to tell t…

They should have just put the new behavior in an extension and heavily promoted that to g-suite users.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#232
post #189

Earlier quoted context omitted.

If that's true, then the Chrome team is severely insulated from their critics. Chrome's "Sign-In" feature has been on lists of features that privacy advocates have recommended avoiding for years, and watchdogs have consistently raised questions about Chrome's data collection policies and practices. As a Googler, you should encourage your colleagues to read negative and critical coverage of your company and its produc…

I already do. There is a strong internal culture of argument and we do tend to use critical news, forum or blog posts as anecdata points. The higher quality and quantity of external voices on a subject, the better argument can be made one way or another. So please keep them coming, but do remember that usually the best result of those is starting proper research into the topic, which then can show that the best for t…

Is it really that what's best for the 99% lies the other way? Or is it that Chrome has so many users that there will always be a majority that don't care about the latest privacy violation Google has forced upon 1/6th of the world population?

When you have 1 billion users, I think it's easy to say that "most of them are better off" with whatever, because there's no possible way that you'll ever have a majority of your 1bn users arguing for or against anything. This is why watchdog organizations exist, and why they're so important.

Doing the "right thing" for 99% of your users isn't actually the right thing if it does harm to your most vulnerable users.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#233

Earlier quoted context omitted.

>Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this. Ever since I updated to 69 I've been absolutely loving it. The most noticeable improvement is it feeling incredibly faster, but as someone who's been using 4-5 profiles on Chrome for over a year the new user management stuff just fee…

I wrote elsewhere that Chrome 69 marks a big change for the browser world. Chrome 69 is simply the best. Not for me, but for the average user. The reading and work flow is incredible for casual browsing. The negative reaction on HN is understandable, but it's not relevant for most people. The goal of Google is merging the user experience of Android, Chrome, Google search and personal Google accounts into one, and it…

I find this reality highly disturbing, but, as you mention, the average user is impartial if not completely ignorant. I think Google is very clearly exploiting both its monopoly and this end-user ignorance to centralize and control all aspects of the web and user devices. It's not far-fetched to consider that soon there will be no OS on the PC, but rather just Chrome as an interface to everything Google and the web. And so controversy like this is momentary and seen only in a vocal minority, quickly forgotten. Just a couple months ago, Chrome was found to be scanning user files for malware - this was quickly forgotten, probably even by the very same vocal people discussing Chrome on HN today. At this point, it's almost faux outrage.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#235
post #167

Earlier quoted context omitted.

What's the point of signing in at all for users who don't use sync?

(if my understanding is correct) Consider the case of two users, Alice and Bob. Alice has sync enabled, Bob does not. Bob wants to check his email on Alice's computer, so he logs Alice off and logs into to his account. This syncs across all website he visits (due to shared auth cookies), but doesn't sync to the browser itself. Chrome is still logged into Alice's account, so Bob's browsing history is synced, but to Al…

That is an extremely narrow example that ignores many other scenarios, some of them privacy related and some of them functionality related.

But I'll bite. In the scenario you just described, can't Alice still just look at her local history and get all of the same information? I just tested -- local history is accessible across accounts in Chrome 69.

So this change doesn't actually protect people who are sharing computers -- a private browsing session is what protects them. And this change doesn't make private browsing any easier.

Also in this scenario, if Bob isn't checking his email or something, he's very unlikely to go log Alice out of her account. So the extremely minor privacy boost that doesn't actually exist because all of Bob's history is still stored locally will still only happen if both Alice and Bob use Gmail.

Which makes it sound like this entire feature was the brainchild of some executive who genuinely can't comprehend someone borrowing a computer and not immediately signing into Gmail. A much better solution to the problem you're describing above would be to draw more attention to private browsing sessions in the UX, or to just have some kind of notification when the user signs out of Gmail.

Heck, you could have the same exact feature, except drop the auto-login part and only have the auto-logout. That would still be a useless feature because of the reasons above, but it would get rid of the vast majority of the privacy concerns the tech community is currently raising.

Auto-login is not necessary to fix the problem you're talking about.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#236
post #182

Earlier quoted context omitted.

I also work at Google though have nothing to do with Chrome. This isn't "clear" to me. There are certainly complaints about this change within HN, but there are also people here saying that they appreciate the change, or that they're ambivalent. But the more important part of things is that HN has what, maybe 10000 active users? Chrome has over a billion. Even if every HN commenter was vehemently against this change,…

This is some real Orwellian stuff here. First off, since it applies to people logged out of Chrome and it forces them to log in it increases, not decreases, the chances of someone accidentally leaving their account available to others on the machine. Since the sync button no longer requires a password this means someone can log in at a library to check their email, walk away, and someone else can step up, hit the syn…

Just anecdotally since I used to manage the computers at a public library, we did have time software that would reset the computers back to a clean state after they either were done and clicked "end session" or they left it unattended for a minute.

I'm still against this Chrome change for the same reasons, but I would hope other libraries do the same thing as we did. From my experience library tech people are usually really privacy focused.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#237

https://twitter.com/__apf__/status/1044109898013765632 > My teammates made this change to prevent surprises in a shared device scenario. In the past, people would sometimes sign out of the content area and think that meant they were no longer signed into Chrome, which could cause problems on a shared device I can see why there is pushback against this, but the issue described above is also understandable. There are v…

I sort of want Google to go further with this change, and simply have a "Sign in to Chrome, Google Sites, Amazon, and everything else" button.

In fact, it could also sign you in to local applications like Photoshop and Word.

They could call it the 'logon screen'.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#238
post #167

Earlier quoted context omitted.

What's the point of signing in at all for users who don't use sync?

(if my understanding is correct) Consider the case of two users, Alice and Bob. Alice has sync enabled, Bob does not. Bob wants to check his email on Alice's computer, so he logs Alice off and logs into to his account. This syncs across all website he visits (due to shared auth cookies), but doesn't sync to the browser itself. Chrome is still logged into Alice's account, so Bob's browsing history is synced, but to Al…

Thanks for the explanation. It seems to assume that Gmail is the internet. If people sometimes use Facebook or forums or games instead of Gmail, then history will appear to sync to random places, no?

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#239

Are there any lawyers here who can tell us if this is actually a GDPR violation? Most of the discussion here is about why people don't like the new Chrome feature -- but is it actually in violation of the GDPR?

As long as they don't really gather any data without an additional consent, I can't see how it could be. IANAL, of course.

But, if I was responsible for GDPR in Chrome I would be very worried that they are conflating "signed in" and "syncing" some places in the code, since this appearently used to be the same concept, per the old privacy policy.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#240
post #196
post #185

Earlier quoted context omitted.

I think you forget that in it's time IE was massively innovative. It was IE who added XMLHttpRequest and invented AJAX.

They did it by ironic accident. Bill Gates wanted their browser to be the best, but also wanted it not good enough to replace desktop apps. However the right hand didn't know what the left hand was doing. The Outlook team was told to make a web version. They got the IE team to add XMLHttpRequest for their use, everyone implemented what they needed to, then went home and forgot about it. Then Google recognized what th…

This origin story of XMLHttpRequest being an afterthought explains why the class name has inconsistent capitalization which interestingly enough I never noticed until now.
Post reply on HN