Live data from Hacker News

Never connect to ProtonMail using Chrome

old.reddit.com

211–220 of 289 posts

Re: Never connect to ProtonMail using Chrome

#211
post #10

If you care about privacy these days: Remote self-destructible VM for browsing with Firefox in incognito mode (only sites you NEED to, that REQUIRE JS), through multiple VPNs over multiple proxies. Everything else is command line HTML parsers (also on different, remote VMs), or API endpoints (HN API as an example?). Need email service? Self-hosted, tiny email-server somewhere in eastern Europe. DDNS etc. Local machin…

> Everything else is command line HTML parsers (also on different, remote VMs), or API endpoints (HN API as an example?).

This is somewhat how Richard Stallman uses the internet:

> I am careful in how I use the Internet.

> I generally do not connect to web sites from my own machine, aside from a few sites I have some special relationship with. I usually fetch web pages from other sites by sending mail to a program (see https://git.savannah.gnu.org/git/womb/hacks.git) that fetches them, much like wget, and then mails them back to me. Then I look at them using a web browser, unless it is easy to see the text in the HTML page directly. I usually try lynx first, then a graphical browser if the page needs it (using konqueror, which won't fetch from other sites in such a situation).

> I occasionally also browse unrelated sites using IceCat via Tor. Except for rare cases, I do not identify myself to them. I think that is enough to prevent my browsing from being connected with me. IceCat blocks tracking tags and most fingerprinting methods.

> I never pay for anything on the Web. Anything on the net that requires payment, I don't do. (I made an exception for the fees for the stallman.org domain, since that is connected with me anyway.) I also avoid paying with credit cards. For freedom's sake, insist on paying cash. When a business pressures you to pay in an identified way, that means your help as a citizen is needed: say, "If you won't take my cash, no sale!"

Source: https://stallman.org/stallman-computing.html

Re: Never connect to ProtonMail using Chrome

#213
post #147

Earlier quoted context omitted.

I just went to create a google account to see for myself because this sounds egregiously bad. I think you are exaggerating quite a bit: * Phone number is clearly marked as optional and it says they use it for security. (Of course, Facebook said the same thing, and look how that turned out...) * The only information requests that I think are unnecessary are date of birth (they say because some services are age restric…

UPDATE: Location sharing is off by default. > Phone number is clearly marked as optional That is because your IP has a good reputation. For me registering a Gmail Account from Firefox looks like this [1]. Note that the text is misleading (this is not for my security, this is to prevent bulk registration). > date of birth (they say because some services are age restricted) If the user is over 18 you don't really need…

> I don't understand whether this really means that they collect my browsing history

That's what it means. You can look at the data google is storing at https://myactivity.google.com/myactivity

Re: Never connect to ProtonMail using Chrome

#214

I would make the advice more general: avoid dealing with Google. Recently I had to install Hangouts app on the Android phone (it was easier than using it on desktop because I don't have the latest Chrome). One has to register a Google Account in order to use it, and I had to answer a lot of questions as if I was applying for a visa, including a phone number (of course I used a fake number) and date of birth. Then the…

Agreed. Avoid Google services. Wrote a post about how to do it: https://righteousruminations.blogspot.com/2018/09/migration-...

Re: Never connect to ProtonMail using Chrome

#215
post #201

Earlier quoted context omitted.

I don't think cloudfare really does traffic analysis. At least nowhere near the level that google does. It is not their core business.

Why then they offer free fully functional CDN-like service, free SSL ? Data is new oil, and CF has all data in plaintext - your logins/passwords included.

Because...

a. It's really cheap for us to offer that service

b. Lots of those free customers end up upgrading, paying for extras, etc.

Between a and b offering the free service makes sense. We make money from the customers who pay us for our service (https://www.cloudflare.com/plans/), not from doing something nefarious with data. We'd be shooting ourselves in the foot if we did because that data is our customers data. We need to be very careful with that or we'd lose trust and not be in business.

Also, free means anybody can try the service and kick the tires. Often those people turn out to me the CIO, CSO, CISO, CTO, ... of big corp.

Re: Never connect to ProtonMail using Chrome

#216
post #182

"But the conclusion is frightening : it means that the content of every webpage visited using Google Chrome is sent back to Google." This is how it always worked and the number one reason I'm avoiding Google Chrome.

This neither is nor was true though. In this context pages are sent only if you are on a page which looks like it could be translated and you request the translation. That's a long way from "every page"

In another thread here the OP is quoted as saying Chrome sent the data even when translation is disabled.

Re: Never connect to ProtonMail using Chrome

#217
post #161

Earlier quoted context omitted.

Question is, how does it know to ask? If it is based on analysis done by the local machine, no problem. However, if it is based on analysis done by google servers, big problem!

> Question is, how does it know to ask? The html tag has a "lang" attribute, and the server itself can send a Content-Language HTTP header. Most CMSes these days set one or both once multi-lingual is enabled. Additionally the browser can utilize the OS or it's own spellcheck word database: check every word in every dictionary and the dictionary with the most matches is likely to be the relevant one.

> Additionally the browser can utilize the OS or it's own spellcheck word database: check every word in every dictionary and the dictionary with the most matches is likely to be the relevant one.

Every word seems excessive, especially if a page has an excessive amount of text on it.

Re: Never connect to ProtonMail using Chrome

#218

When I visit a website in a foreign language I've never translated before, Chrome asks my permission to translate the site, it doesn't do so automatically. You could argue they could give you more details on what it will do when you click the 'Translate' button, but to argue they shouldn't offer the feature as a permission-requested option at all seems pretty extreme. I read a lot of foreign websites, and the built-i…

It asks permission to show you the translated version.

But does it send the page's content to some Google server only if you agree? The point here is that it seems that the content is sent over to Google no matter what.

Re: Never connect to ProtonMail using Chrome

#219

RTFA - the user discovered that chrome was sending all text from all webpages to the translate service. The advice in the thread isn't "never connect to protonmail using Chrome." It's "don't use Chrome". 100% agree. Firefox is so good now, there's really no excuse.

And if you don't like Firefox Quantum for its own egregious privacy issues, you can use Waterfox. The next major Waterfox release will have all the speed enhancements of Firefox Quantum without the privacy issues.

Would you mind elaborating on what those egregious privacy issues are for those of us who don't follow particularly closely?

Re: Never connect to ProtonMail using Chrome

#220

RTFA - the user discovered that chrome was sending all text from all webpages to the translate service. The advice in the thread isn't "never connect to protonmail using Chrome." It's "don't use Chrome". 100% agree. Firefox is so good now, there's really no excuse.

And if you don't like Firefox Quantum for its own egregious privacy issues, you can use Waterfox. The next major Waterfox release will have all the speed enhancements of Firefox Quantum without the privacy issues.

What are Firefox Quantum's egregious privacy issues? All I'm aware of is the encrypted DNS experiment which is a huge, unqualified privacy win. I'm not aware of anything it does that's objectively worse than the privacy catastrophe which is the status quo.

Perhaps you are angry because it doesn't send your DNS requests in the clear to Google's 8.8.8.8 service? Perhaps you are angry because you don't like encrypted communication protocols?

Post reply on HN