Live data from Hacker News

Chrome 69 will keep Google Cookies when you tell it to delete all cookies

twitter.com

531–540 of 848 posts

Re: Chrome 69 will keep Google Cookies when you tell it to delete all cookies

#531

Earlier quoted context omitted.

>people have mortgages, families and other commitments. Some have social anxiety and find job hunting an impossibly scary prospect. Others might suffer from depression. So what? Standing up for what you believe in is never easy, and almost always involves challenges like those. Imagine if Dr. King gave up because he was anxious and depressed with death threats coming in on a regular basis. Failing to take a moral/eth…

You don't have a right to subject your children to homelessness just because you felt like taking a stance based on feelings.

Does one have a right to give a crappy life example to one's children?

Re: Chrome 69 will keep Google Cookies when you tell it to delete all cookies

#532

Earlier quoted context omitted.

With firefox, you can disable extension auto updates.

You can't disable it installing new extensions behind your back without telling you, though. These are "system extensions" and you can't opt out of them.

System extensions are not really extensions, they're just parts of built-in browser functionality that have been implemented by programmers with good code hygiene.

It's unfair to describe these as "installing random extensions without asking" because you would then have to admit that it's equally true of every new feature of every software program that is ever updated.

Re: Chrome 69 will keep Google Cookies when you tell it to delete all cookies

#533
post #521

Earlier quoted context omitted.

>Firefox did that once At least twice. https://www.engadget.com/2017/12/16/firefox-mr-robot-extensi... https://www.reddit.com/r/firefox/comments/9ii8sj/firefox_kee...

I stand corrected. Of course, “ twice ever ” is still a lot less frequent than “ keeps doing it all the time ”.

It's already compromised. Who cares how much times it was?

Re: Chrome 69 will keep Google Cookies when you tell it to delete all cookies

#534
post #62

Earlier quoted context omitted.

Dropping chrome is not enough. Switch to bing (Just as good as G), or ddg if you really want. Then ditch android which is the spy in your pocket. If you're installing G analytics for clients then choose an alternative (I'm open to suggestions here). It's really time to disentangle ourselves from google. They've quietly and effectively insinuated themselves across the web. Enough is enough.

It would be nice also for websites to have an alternative to recaptcha. I hate to have to train google's models for free just to access a website. I'd prefer to do some work for data that can be openly accessed (OpenStreetMap for example).

I quit using all websites that use Google captcha. I also don't want to train Google's models and spend 2-3 minutes doing free work for Google just to sign into Discord. It's extremely annoying using a VPN with Google services too, as you 9/10 times have to do lengthy captchas. I miss early-mid 2000's captchas.

I'm pretty much done with Google now, and I think a lot of tech users will start pulling this way too.

Re: Chrome 69 will keep Google Cookies when you tell it to delete all cookies

#536

Earlier quoted context omitted.

>people have mortgages, families and other commitments. Some have social anxiety and find job hunting an impossibly scary prospect. Others might suffer from depression. So what? Standing up for what you believe in is never easy, and almost always involves challenges like those. Imagine if Dr. King gave up because he was anxious and depressed with death threats coming in on a regular basis. Failing to take a moral/eth…

So, assuming you're tight on money, the job market is looking crap, but you got lucky and got a well paying job. Chances of getting another job are slim. You have a few responsibilities, a wife, say 2 kids, maybe even someone who needs medical bills paid. Do you just say "fuck it", and quit, ignoring all your responsibilities? Over cookies? Of course, when its not about cookies, but about something more drastic, say…

This isn't just about cookies though. When Google designed HTTP/2 they kept cookies in favor of a separate authentication mechanism. Arguably because otherwise people would end up removing cookies altogether making themselves harder to track and with Google losing ad money in the process. Now Google have seemingly decided they want to have their cake and eat it too, just only for themselves. This isn't one incident but Google manifesting thier direction for themselves and the Internet. (Just recently they also disabled sign out from their YouTube app for instance). If you disagree with this direction that is certainly a good reason too quit sooner rather than later. Pretty much everyone I have ever talked to that ended up changing e.g. jobs because of a disagreement wish they did so earlier. It is very easy to sit in the same position and hope that things will get better and hard to see what else is out there even if it is very clear in hindsight.

Re: Chrome 69 will keep Google Cookies when you tell it to delete all cookies

#537
post #28

Just got the update at work, and miraculously my uBlock adblocking extension was removed and DuckDuckGo as the default search engine replaced with Google. Looks like all my customizations were replaced by defaults. Now I'm wondering whether it was our IT's fault or due to Google actions.

No IT staff in my shop. And the last 3 version upgrades have removed all my extensions, while trying to force the Google Drive extension on my installation. So the thing is, I’m heavily reliant on 1Password, and force uninstalling that extension has made Chrome useless to me. I refuse to reinstall my extensions again and I refuse to log in to Chrome to have my extensions synced. If they want to break my browser on au…

This sounds like a bug. Could you please file it at https://crbug.com/new?

Re: Chrome 69 will keep Google Cookies when you tell it to delete all cookies

#538
post #521

Earlier quoted context omitted.

I stand corrected. Of course, “ twice ever ” is still a lot less frequent than “ keeps doing it all the time ”.

It's already compromised. Who cares how much times it was?

And if they implemented these "features" as part of the core browser update rather than as an extension, it would have been okay?

There may be a legitimate debate worth having here, but basing the complaint on the good code hygiene practised by Mozilla's developers is silly.

These so-called "compromises" were nothing in any practical sense. Meanwhile, every web page you visit leaks the fact of your existence a hundred different ways and 99% of us don't care much.

Re: Chrome 69 will keep Google Cookies when you tell it to delete all cookies

#539
post #315

Why are we assuming maliciousness? My best guess that Chrome works this way would be due to combining the sign-in cookies with the general cookies of the browser (e.g. 1 cookie store instead of 2). So when you log in to Google, you log in to Chrome - and vice versa. For non-technical users this is a convenience feature, though for many it does come with privacy concerns. Judging by the comments re cookie clearing, th…

I agree — malicious would be to hide the Google cookies that are associated with your browser-level Google login.

As it is, I think it's quite transparent. You get new cookies. It shows you their age. They're new. You're still logged into your Google account.

Solution: Log out of your Google account.

Re: Chrome 69 will keep Google Cookies when you tell it to delete all cookies

#540
post #62

Earlier quoted context omitted.

Dropping chrome is not enough. Switch to bing (Just as good as G), or ddg if you really want. Then ditch android which is the spy in your pocket. If you're installing G analytics for clients then choose an alternative (I'm open to suggestions here). It's really time to disentangle ourselves from google. They've quietly and effectively insinuated themselves across the web. Enough is enough.

Im a longtime ios user thinking of switching to android soon - can you elaborate on android spying? All android devices? How do they spy and what do they gather? I hadnt come across this in my research so far

I'm not OP but I've been an Android user since the release of the T-Mobile G1 and have been trying to get rid of Google stuff for a while:

> All android devices?

No, not all Android devices. Only the ones with the Google Services Framework installed (or, if you're as paranoid as I am, any other Google service that is running as root).

To give you an overview, Google's power over Android users basically rests on the following pillars:

1. Google Services Framework (GSF): AFAIK every Google app requires the GSF to be installed on your phone these days. The GSF runs as root, includes all kinds of analytics libraries. It also links your phone to your account if you decide to set it up on your phone (which, theoretically, you don't have to but, in practice, you are often forced to). If you indeed do that and connect your phone to your account, things like contacts, calendar entries and so on get synchronized automatically.

Even worse, there's also a way for the GSF to back up all your apps' data and upload them to the Google servers. I'm just mentioning this to make it clear that the GSF really has access to everything on your phone.

Solution: Use MicroG (https://microg.org) as a GSF replacement. This, in turn, requires using a custom ROM like LineageOS and, thus, your phone's bootloader to be unlockable. Not all Google apps will work with MicroG but most do in my experience (see below).

2. Google Play Store: Most apps are only available on the Play Store, so if you want to use any of these you'll have to use the Play Store in one way or another. The Play Store, however, needs the Google Services Framework. And even if you got rid of the GSF and replaced it with MicroG (see 1), you would still have to install the Play Store as a system app, giving it root access to your phone.

Solution: Apart from getting rid of the GSF (see 1), use F-Droid for open-source apps and something like Yalp Store (or the Aurora fork) to download apps from the Play Store. (There are also ways to download apps from the Play Store using F-Droid, see e.g. https://github.com/NoMore201/playmaker) You won't be able to obtain paid apps this way, though. (Or, more precisely, you won't be able to download apps that you haven't already paid for.)

2. In-app payments ("Android Pay")

As you might expect, these are also tied to the Play Store and the GSF.

Solution: I haven't tried this in a long time but you might be able replace the GSF with MicroG and just have the Play Store installed and tied to your Google account in order for in-app payments to work. No guarantees, though.

3. Google SafetyNet (part of GSF, as well)

From my POV, this is the most painful Google "feature". It's a Google library that apps like Netflix and online banking apps use to verify that the device they're running on has not been "tampered" with. (What "tampered" means exactly is unclear -- it definitely includes rooted devices but the precise definition is Google's secret.)

If you want to use apps like Netflix, there is no real way around SafetyNet. This is because, if installed on your phone, SafetyNet will download a binary blob from Google, execute it and send its output (basically all the information the blob collected about your phone) to the Google servers. The latter will then do the verification process and notify the Netflix servers (or your bank's servers) about the result. The Netflix servers can then tell the Netflix app on your phone to lock you out if need be.

Solution: While MicroG can't circumvent this, it does support SafetyNet these days by emulating the original SafetyNet implementation. So it, too, will download the binary blob and execute it.

Put differently, in order to use Netflix and most online banking apps you will still have to make sure that your phone passes the SafetyNet test. Here, you've got two options:

Option a): Hide root access and other system modifications (like Xposed) from SafetyNet by using something like Magisk (https://forum.xda-developers.com/apps/magisk/official-magisk...).

Option b): Don't use root or any of those modifications in the first place. (I.e. you could just run LineageOS without root and you should be fine.) The problem with non-rooted devices is that they also don't allow you to run a firewall or apps like Xprivacy for more fine-grained privacy control. (When it comes to firewalls not requiring root, NetGuard does come close, though. However, it should be noted that you won't be able to use VPNs anymore.)

4. Google services that are tied a Google account, e.g. Gmail, Drive, Maps, Picasa, Home, Google Now/voice assistant etc.

As already mentioned, they all require the GSF to be installed on your phone.

Solution: I would recommend staying away from them but if you really need them you should be able to replace the GSF with MicroG and they should still work. There might be exceptions, though, depending on how deeply they are integrated with your phone. (The voice assistant might be one such example.)

5. Google services that are not tied to a Google account, e.g. Maps

Solution: Same as 4) and/or use an OpenStreetMaps-based app like OsmAnd as a replacement for maps.

Post reply on HN