Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

291–300 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#291
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

> I don’t understand why the Chrome team is picking this hill to die on Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this. > I really expect this change to push a lot of people away from chrome Care to bet on that? Because I would happily take the opposite side of that bet. I think th…

Once upon a time "nobody cared" that IE was trash either, now look what's happened - and that was preinstalled on the OS.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#292
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

> I don’t understand why the Chrome team is picking this hill to die on Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this. > I really expect this change to push a lot of people away from chrome Care to bet on that? Because I would happily take the opposite side of that bet. I think th…

Just a small meta-point that betting is a great way for both sides of a debate to tone down rhetoric, engage in dialogue, and discuss objective terms or processes for evaluating a disagreement. It looks like another commenter is taking you up on the bet and I hope neither of you were being sarcastic, because I think betting isn't something to joke about but a wonderful tool that we don't use often enough.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#293

Earlier quoted context omitted.

> I don’t understand why the Chrome team is picking this hill to die on Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this. > I really expect this change to push a lot of people away from chrome Care to bet on that? Because I would happily take the opposite side of that bet. I think th…

I would take a small bet. We're the trend-setters in technology. We're the ones who got everyone on Chrome to begin with. Otherwise they'd still be on IE. If all the tech people abandon Chrome, they will start recommending FF or IE again and discourage Chrome use. The impact is slow, but it is significant.

See my other comment in response to the parent - I hope neither of you were being sarcastic and that a bet is worked out.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#294
post #201

Earlier quoted context omitted.

IE at its core was technically very advanced, way faster than Netscape, and pushed a ton of new features. Dynamic HTML as it was called, CSS, encryption, and so much more stuff came to IE before any of the competitors. Then it became the IE6 we all came to know. The analogy with Chrome starting as a trail blazer and progressively taking the same trajectory is perfect, really.

That is known, but the point is that IE stopped. That has been reported somewhere, can't find a useful link right now but I remember the discussions. It was reported - and what was observable matched the description - that as soon as Netscape was out Microsoft stopped pretty much all their efforts, and IE became the laggard that due to its market share prevented innovation and became a huge obstacle for quite a long…

I can confirm this. I used to work on the IE team. Went from a team of hundreds to just a handful.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#295
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

I work at Google; opinions are my own.

> I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on.

My impression is that this is the new norm at Google. It happens with everything, internal or external. The sad reality is that most decisions will deeply upset at least some people, and those people likely don't have the context into the decisions but still complain loudly.

From my perspective what happens is that it doesn't matter whether a decision was a good or bad one, there will be people who complain (ESPECIALLY internally as Googlers can be very entitled) and so at some point you're just completely immune to this.

This is not helped by the fact that people externally often think Google is on some evil plan and speculate in wild ways which are completely wrong.

To give you an idea of how these things usually happen.. it goes something like this..

Someone finds a UX problem, and makes a plan to fix it. In this case I guess it's confusion among signed on accounts. Someone on the team probably raises some concerns, likely similar if not the exact ones being raised now, and they debate it but eventually they say well, the proportion of people who seem to care about this is only 0.1% of users (Because we are objective!).

Sadly, even though it's "only" 0.1% of users, those users are extremely negatively impacted in a way that's not really reflected by the small percentage, and 0.1% of a billion is still a considerable amount.

On the other hand, there are many other decisions which were released just fine and we would not be able to do anything if we were always afraid of negatively impacting some small proportion of users. To me this is a weakness of the attempt to have everything be objective and "measurable".

Let me state that I don't think this is good or even acceptable, but I'm definitely not smart enough to know how to solve this on a wider scale than my immediate team. However I hope this at least provides some insight into why these kinds of thing happen.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#296
post #252

Earlier quoted context omitted.

FWIW, that's exactly what the updated [1] says. Maybe they missed that sentence. [1] https://www.google.com/chrome/privacy/#signed-in-chrome-mode

Yeah I directly quoted from the privacy statement and the line I quoted is still there. Seriously though, searched for "signed in" (like, ctrl-f). There's an epic ton of things that they are allowed to do for signed in accounts versus normal browsing even with sync disabled. These are all directly quoted from the privacy policy and do not require syncing to be enabled- * If you are signed in to a Google site or signe…

> * If you are signed in to a Google site or signed in to Chrome and Google is your default search engine, searches you perform using the address bar in Chrome are stored in your Google account.

Note the "or". If you're signed into Google and you do a Google search, that's stored in your account by default. The only reason signing into Chrome is relevant is that that also signs you into Google.

> * Payments. If you are signed in to the Chrome browser and you have credit cards stored in your Google Payments Account, then Chrome will offer you the option of filling those cards into web forms. In addition, if you enter a new credit card into a web form, Chrome will offer to save your credit card and related billing information to your Google Payments account.

This doesn't suggest any data being sent to Google unless you accept the offer to save a card to your Google Payments account.

> * Language. In order to customize your browsing experience based on languages that you prefer to read, Chrome will keep a count of the most popular languages of the sites you visited. This language preference will be sent to Google to customize your experience in Chrome. If you are signed in to Chrome, this language profile will be associated with your Google Account and, if you include Chrome history in your Google Web & App Activity, may be used to personalize your experience in other Google products. View Activity Controls.

Okay, this is one actual example of signing in causing more data to be sent to Google than would happen otherwise. It seems pretty benign, though.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#297
post #266

Earlier quoted context omitted.

> "Somebody should do a better job!" "Why don't you try yourself?" This argument makes sense when you're talking about a problem that one or two people control rather than a large system with higher stakeholders who may not have interests aligned with your own. But I'll assume you're right for a sec. Let's assume that Google cares a ton about making sure their privacy policy is consistent, but it's just an insanely h…

My thinking is more in line of: if privacy team was bigger, it would intuitively have a way easier job keeping tabs on all the developments. However, that's a job without talent attractors like glamorous launches. When you're sailing smooth, nobody knows you exist. But when I mention they're hiring in an incident, I learn this is the wrong time to mention them. But then again, I'm neither in privacy team, nor Chrome…

If Google's privacy team is understaffed or doesn't have enough resources to do its job, we should have a conversation publicly about that. I get where you're coming from, but Google isn't a company without resources. In this specific scenario, where there is an actual power dynamic at play, it's not enough to just say, "well, people should get involved." The people who get involved are not the people who are making long-term decisions about process.

If Google itself isn't acknowledging the problem, or worse, if Google is actively thwarting or working against its own privacy team, then anyone who gets involved will also end up starved for resources or moved to other teams. Google is not a level playing field for people who want to change the system from inside.

So it's not wrong at all for you to bring this up during an incident. But if we take the premise that this incident is the result of one of the largest companies in the world starving its own privacy team, not paying enough to attract talent, or not giving them enough input into internal processes... well, that's honestly something that needs to be discussed company wide. That's a very serious situation.

And if that's the case, users should be distrusting Google's privacy commitments until it has that conversation. The first step to fixing a problem is acknowledging the problem -- you won't get anywhere trying to fix a system that doesn't want to be fixed.

From the responses that have come out of Google regarding this incident, it doesn't sound much like it wants to be fixed. Changing that is the first step. Hiring people is the second.

By all means, let's talk about Google's privacy team. I am all for that. Let's get productive. But let's get actually productive. Let's have an open, public talk about management and resource allocation, and why the team is understaffed. From Google's AI/self-driving divisions, we know what it looks like when the company gets serious about attracting talent. And we know it has the resources to do so.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#298

Earlier quoted context omitted.

I'm typically out of touch with normal people so I'm probably proving your point, but this has pushed me off chrome and Google. Ive always loved google. Installed chrome when it was released. I'm writing this from a pixel 2 XL because I broke my pixel 1 XL. I've had a Gmail account almost since it's been possible (I have my firstnamelastname@gmail.com). I now use firefox. I don't know what mail I'll switch to, and I…

I had the same mindset as yours perhaps a year or two ago, until I realized a couple of things that completely changed my mind. This is a little off the main topic but you see, when it comes to privacy, we like to think that we have it in our control but in fact we don't. As Snowden has proven, what the NSA is doing is far worse than Google. You just don't know it because it's completely hidden and sealed off from th…

please note the announcement of the French 'security OS'

https://news.ycombinator.com/item?id=18031201

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#299

Earlier quoted context omitted.

I personally know people who think they are signing into Chrome when they sign into google.com. Maybe the Chrome team is right about their larger user base?

Maybe the Chrome team is right about their larger user base? Maybe the Chrome team was wrong to introduce signing in to a browser at all?

I imagine most people want their bookmarks/history/extensions/settings synced..

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#300
post #229

Earlier quoted context omitted.

I don't want to get too far into specifics because I'm not an expert, but I'm pretty sure there are a number of inaccuracies in this comment. Notably, synced data would have been visible in myaccount.google.com already, and if he had syncing disabled, I don't think there wouldn't be any data synced with his account to view. In other words, assuming Alice was nefarious, yes this is still terrible, but I don't think it…

> Notably, synced data would have been visible in myaccount.google.com already, and if he had syncing disabled, I don't think there wouldn't be any data synced with his account to view. That makes no sense at all unless syncing is an account wide setting instead of a browser setting, and it's pretty clear that this is a browser setting. Bob could have syncing enabled on his primary computer, log into gmail on Alice's…

It makes perfect sense. If Bob has syncing enabled on his primary computer, Alice could enable syncing to copy the previously synced data to her browser. But she could also view the same data on myaccount.google.com.
Post reply on HN