Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

261–270 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#261

Earlier quoted context omitted.

I'm typically out of touch with normal people so I'm probably proving your point, but this has pushed me off chrome and Google. Ive always loved google. Installed chrome when it was released. I'm writing this from a pixel 2 XL because I broke my pixel 1 XL. I've had a Gmail account almost since it's been possible (I have my firstnamelastname@gmail.com). I now use firefox. I don't know what mail I'll switch to, and I…

I had the same mindset as yours perhaps a year or two ago, until I realized a couple of things that completely changed my mind. This is a little off the main topic but you see, when it comes to privacy, we like to think that we have it in our control but in fact we don't. As Snowden has proven, what the NSA is doing is far worse than Google. You just don't know it because it's completely hidden and sealed off from th…

What? I should just ignore Googles harvesting of my data because "everyone does it"? That's ridiculous.

Also, why do companies need to "compete"? There's no reason that core software like internet browsers or operating systems need to be commercial in the first place. I will happily continue using Firefox.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#262
post #201

Earlier quoted context omitted.

That's a bad example. In technical progress, Chrome is the complete opposite of IE (which seems to be replaced by Safari these days) and way better than the rest in pushing forward new features. Also 99% of the time Firefox and Edge work just fine. EDIT: Yes, IE was great in the beginning, but then it stagnated and earned the wide reputation of being terrible obsolete anchor that it is now known for. It's with this l…

IE at its core was technically very advanced, way faster than Netscape, and pushed a ton of new features. Dynamic HTML as it was called, CSS, encryption, and so much more stuff came to IE before any of the competitors. Then it became the IE6 we all came to know. The analogy with Chrome starting as a trail blazer and progressively taking the same trajectory is perfect, really.

How is Chrome taking the same trajectory when it is actively developing and releasing new features?

As far as I can tell, it's still on the bleeding edge and only recently met there by new advancements from Firefox.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#263

Earlier quoted context omitted.

(if my understanding is correct) Consider the case of two users, Alice and Bob. Alice has sync enabled, Bob does not. Bob wants to check his email on Alice's computer, so he logs Alice off and logs into to his account. This syncs across all website he visits (due to shared auth cookies), but doesn't sync to the browser itself. Chrome is still logged into Alice's account, so Bob's browsing history is synced, but to Al…

How about popping up a message saying, "you're logging in to someone else's computer, would you like to do this in an incognito window?" Or something like, "you're signing in to a different Google account, would you like us to remember this account and preserve/sync history to account X, which is currently signed into Chrome".

> How about popping up a message

Doesn't work. Between the cookie pop-ups, update notifications, and "you've got mail"s, people have learned to ignore pop-up notifications.

... of course, the real problem here started with "Bob checked his email on Alice's computer." There are so many ways it can go wrong, like Alice using a browser other than Chrome, Bob using an email service other than GMail, or Alice deliberately installing a keylogger on that computer...

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#265
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

I personally know people who think they are signing into Chrome when they sign into google.com. Maybe the Chrome team is right about their larger user base?

Maybe the Chrome team is right about their larger user base?

Maybe the Chrome team was wrong to introduce signing in to a browser at all?

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#266
post #222

Earlier quoted context omitted.

"Somebody should do a better job!" "Why don't you try yourself?" Seems like a somewhat reasonable train of thought. A lot of good things can come out of outrage, as long as people are willing to take action (no, I don't claim going through Google recruitment to be the optimal strategy, but it is an option)(I actually got my first job as a result of my technical complaints, obviously not in Google).

> "Somebody should do a better job!" "Why don't you try yourself?" This argument makes sense when you're talking about a problem that one or two people control rather than a large system with higher stakeholders who may not have interests aligned with your own. But I'll assume you're right for a sec. Let's assume that Google cares a ton about making sure their privacy policy is consistent, but it's just an insanely h…

My thinking is more in line of: if privacy team was bigger, it would intuitively have a way easier job keeping tabs on all the developments. However, that's a job without talent attractors like glamorous launches. When you're sailing smooth, nobody knows you exist. But when I mention they're hiring in an incident, I learn this is the wrong time to mention them.

But then again, I'm neither in privacy team, nor Chrome team, know no specifics of this case and can't really argue any position (note how I'm neither defending nor condemning the issue of OP). Just pointing out generalities that I don't see mentioned.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#267
This is an absurd and unfair hit-job.

Let me just spell out, for emphasis, what the article actually says:

* Logging in to a Google service via its website will now automatically show you as logged in to Chrome in the top-right corner. This will provide you with the OPTION to explicitly opt-in to syncing your browser data with the Google cloud by clicking a big blue button that clearly says "Sync as " and then clicking through one of the two clearly-labelled options to confirm that you do indeed want to turn on sync in the following dialogue (which does in fact have a prominent "Undo" button in case you clicked by mistake).

* The entire extent of the alleged practical user privacy issue is that a user might accidentally click the first button, and THEN mistakenly click on the small "Want to manage sync and personalisation before they're turned on? Visit Settings." link instead of the larger, more prominent "Undo" button. This, the blog alleges, will turn on syncing without a chance for the user to undo. (Although, at least as of 69.0.3497.100, this is just plain false - there's an "Undo" button even on the settings page. It may have previously been true; I have not checked.)

* The entire extent of the alleged GDPR violation is that the privacy policy erroneously says that when you sign into Chrome with your Google Account, data is synced with Google's servers, when in reality it isn't unless you explicitly consent. (This was true at the time that the post was written, but the privacy policy was tweaked to correct the factual error - compare https://web.archive.org/web/20180924020748/https://www.googl... vs https://web.archive.org/web/20180924123556/https://www.googl...) For what it's worth, I see no reason why briefly and accidentally claiming to process some data in a consent-ignoring way when you don't actually do so would be a GDPR violation, and the article does not elaborate on this particular legal theory.

Other commenters here have already explained that this change offers security/privacy benefits to some users by protecting them from a failure mode in which they wish to sign out of Chrome on a shared computer (in order to not sync their browsing history to a friend's or family member's account), but instead they only sign out of, say, Gmail, and thereafter end up inadvertently syncing their browsing history and passwords to their friend's Google account instead of their own. Connecting the browser login and Google web service login eliminates that privacy-violating failure mode. That seems like a real gain to user privacy and security to me, and it seems plainly absurd to argue that it's actually a loss on the basis of a hypothetical in which the user accidentally clicks through clearly-labelled buttons in two different dialogues and therefore accidentally enables syncing. That seems doubly true given that even in that hypothetical scenario, syncing can, per the article's own admission, then be immediately disabled (and all synced data deleted).

I'm not an uncritical fan of Google, but criticising them for this is bullshit.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#268

https://twitter.com/__apf__/status/1044109898013765632 > My teammates made this change to prevent surprises in a shared device scenario. In the past, people would sometimes sign out of the content area and think that meant they were no longer signed into Chrome, which could cause problems on a shared device I can see why there is pushback against this, but the issue described above is also understandable. There are v…

Except this doesn't actually "prevent surprises in a shared device scenario" for the web, in general; it does for Google sites and services only. Logging in to Facebook or Amazon or my personal blog does not show up as a browser indicator, nor does logging out of the browser also log one out of Facebook or Amazon or my personal blog.

This makes Chrome less of a browser and more of gateway to Google services that happens to include a browser. Which will also trick non-technically-savvy people to accidentaly share their non-Google logins when sharing computers/"browsers".

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#269
I am baffled by The particular Article 25 of GDPR is rarely seriously and meaningfully discussed in practice, not least because probably still almost nobody actually knows what the “data protection by design” even means.

This seems to be a confusion straight out of a five-stages of grief denial of GDPR principles.

Let's work this through:

Step 1: Are you collecting personal data?

Step 2: If so, are you obtaining consent prior to collecting this data?

Step 3: Are the instructions to the users transparent and understandable?

Step 4: Is your system designed to handle these?

Or is it hard, and since we haven't had to do it before, I would like to get out of this requirerment?

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#270
It's a shame that this is where identity is going. Google had such a great opportunity to do this in an open way by making this a more extensible format...perhaps by dusting off OpenID. Identity is probably the most under-built part of the web, and anything Google could do to positively move that forward would've been hailed as a huge improvement.

Instead, because it's closed, it'll set the web identity conversation backward...hopefully it doesn't set it back too far.

Post reply on HN