Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

301–310 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#301
post #197

Earlier quoted context omitted.

This doesn't seem to be turning on Chrome Sync, so users aren't being forced into any privacy policy: https://twitter.com/__apf__/status/1044109898013765632

Read the actual privacy policy, not the tweet talking about it. Primary sources are always best. > The personal information that Chrome stores won't be sent to Google unless you choose to store that data in your Google Account by signing in to Chrome. That doesn't say "unless you enable sync", it says it changes "by signing in to Chrome". Since they're now forcing you to sign into chrome without your consent they are…

Literally the next sentence after the one you quoted is:

> Signing in enables Chrome’s synchronization feature.

This is no longer true, so it seems most likely that that entire paragraph is simply out of date.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#302

Earlier quoted context omitted.

Just anecdotally since I used to manage the computers at a public library, we did have time software that would reset the computers back to a clean state after they either were done and clicked "end session" or they left it unattended for a minute. I'm still against this Chrome change for the same reasons, but I would hope other libraries do the same thing as we did. From my experience library tech people are usually…

> but I would hope other libraries do the same thing as we did In my experience, 9 out of 10 libraries, copy shops and internet cafés don't do this [properly].

I wouldn't expect copy shops or internet cafes to do so as they're private/profit focused entities, and I definitely wouldn't lump libraries in with them.

As a public entity we had a mandate to protect user information and make sure it wasn't stored by us or accessible by others. This applied across the organisation from what books someone checked out to what websites they visited.

Maybe this was just more of a thing in Canada or even Alberta but the concept was definitely agreed upon with other libraries and people in the system I was in contact with. I have read other articles and such from American libraries about protecting information so I assumed it was more widespread.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#303
I'm still not clear about what the actual change in behavior even is - seeing some statements on Twitter from someone on the dev team, it sounded to me like there isn't actually any difference, just a UI change to show which Gmail account is currently logged into.

If that's really all it is, I don't really get what people are upset about. Specifically, if there's no additional data being stored connected to your account (which is what one of the devs seemed to be very explicitly claiming) until you deliberately connect Chrome to your account, this seems like a whole bunch of drama over a misunderstanding.

If I'm wrong, then that's a separate matter. Personally, I appreciate the syncing features, but I completely understand why people would be bothered, and it's definitely something they should roll back.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#304

Earlier quoted context omitted.

I personally know people who think they are signing into Chrome when they sign into google.com. Maybe the Chrome team is right about their larger user base?

Maybe the Chrome team is right about their larger user base? Maybe the Chrome team was wrong to introduce signing in to a browser at all?

> Maybe the Chrome team was wrong to introduce signing in to a browser at all?

maybe, but that would mean that all browser vendors did it wrong. (including mozilla)

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#305
post #189

Earlier quoted context omitted.

I already do. There is a strong internal culture of argument and we do tend to use critical news, forum or blog posts as anecdata points. The higher quality and quantity of external voices on a subject, the better argument can be made one way or another. So please keep them coming, but do remember that usually the best result of those is starting proper research into the topic, which then can show that the best for t…

Is it really that what's best for the 99% lies the other way? Or is it that Chrome has so many users that there will always be a majority that don't care about the latest privacy violation Google has forced upon 1/6th of the world population? When you have 1 billion users, I think it's easy to say that "most of them are better off" with whatever, because there's no possible way that you'll ever have a majority of you…

> Doing the "right thing" for 99% of your users isn't actually the right thing if it does harm to your most vulnerable users.

But aren't the most vulnerable users the one who actually aren't tech savvy? And, arguably this change may actually make things simpler for them.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#306
post #65

Earlier quoted context omitted.

>I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. link to said threads?

Here's one: https://twitter.com/__apf__/status/1044109217903198210

Yeah...and that thread says that the change is basically nothing, just a UI indicator:

> Q: I don’t get, though — if you’re signed in to the browser but sync is off, then what does it mean to be signed in to the browser? What does it do besides sync?

> A: Not much, you can think of it like a Gmail login state indicator.

If that's fully the case, then there's nothing to see here and people are freaking out over nothing. Am I missing an important element here, other than that people don't trust Google?

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#307

I'm still not clear about what the actual change in behavior even is - seeing some statements on Twitter from someone on the dev team, it sounded to me like there isn't actually any difference, just a UI change to show which Gmail account is currently logged into. If that's really all it is, I don't really get what people are upset about. Specifically, if there's no additional data being stored connected to your acco…

[deleted]

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#308

I'm still not clear about what the actual change in behavior even is - seeing some statements on Twitter from someone on the dev team, it sounded to me like there isn't actually any difference, just a UI change to show which Gmail account is currently logged into. If that's really all it is, I don't really get what people are upset about. Specifically, if there's no additional data being stored connected to your acco…

Now if you log into a Google account, Chrome is logged into that same account as well. Also if you clear all cookies, cookies from Google aren't cleared. Some people (myself included) don't like that.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#309

Earlier quoted context omitted.

I’m thinking just a banner along the top of the viewport with “Dismiss” and “Learn more…” buttons. The latter pops up a window with a small gray “More options…” link at the bottom, which invokes a modal with the options “Continue signed in as Alice” and “Manage Profiles…”, the latter of which allows you to disable syncing while simultaneously deleting all your local bookmarks and browser history.

These last couple of comments were probably some exaggerating pun... But after this story I was running privacy checkup, surprisingly found that my location history was on (after turning it off several times long before, which is a separate question why it turns on), turned it off again and then got 404 when trying to delete it. All this in a labyrinth of often circular links without much clue where the actual switch…

(A year later) 'Over 90% of our users don't choose to turn these settings off. So we made on the default and removed the option.'

... We passed the point where dark UX patterns deserved the benefit of doubt a few years ago.

If it benefits the company, it's intentional.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#310
post #167

Earlier quoted context omitted.

What's the point of signing in at all for users who don't use sync?

(if my understanding is correct) Consider the case of two users, Alice and Bob. Alice has sync enabled, Bob does not. Bob wants to check his email on Alice's computer, so he logs Alice off and logs into to his account. This syncs across all website he visits (due to shared auth cookies), but doesn't sync to the browser itself. Chrome is still logged into Alice's account, so Bob's browsing history is synced, but to Al…

It's a potential privacy violation for Alice and Bob!

How about this scenario:

Alice has Chrome synced to her Google account on her PC.

Bob uses Chrome on his PC but has no Google account and does not log in to Google services. He does uses bookmarks though.

Alice visits Bob and borrows his PC to check her gmail, which logs her in to Bobs Chrome. Then either Alice at that time or Bob at a later date accidentally triggers sync in Bobs Chrome.

TWO bad things happen at this point.

1) all Alice's synced data is downloaded onto Bob's PC. Including her bookmarks and passwords

2) all Bob's bookmarks are synced with Alice's account and Chrome on her PC will download them next time it's online.

Post reply on HN