Live data from Hacker News

Google tracks individual users per Chrome installation ID

github.com

501–510 of 642 posts

Re: Google tracks individual users per Chrome installation ID

#501
post #480
post #362

TL;DR I think whoever posted that is trying to bury the UA anonymizing feature by derailing the discussion. What I'm seeing is an RFC for anonymizing parts of User-Agent in order to reduce UA based fingerprinting, which improves everyone's privacy, that's a good thing! Then I see someone comments how that could negatively impact existing websites or Chromium-derived browsers, comments which are totally fair and make…

https://cs.chromium.org/chromium/src/components/google/core/... Just thinking out loud. What happens, let's say, if someone malicious buys youtube.vg and puts a SSL certificate on it ? Will they be able to collect the ID ? I guess so ?

Yes, but they would also need a valid TLS certificate?

A country's government could also take over the TLD and grab its traffic overnight.

Re: Google tracks individual users per Chrome installation ID

#502

I don't understand why Google and some other tech companies use their users as involuntary, unpaid guinea pigs. No consent. No opt-out. What's the motivation? Is it simple laziness because they don't want to deal with wetware? Is it afraid that if people knew what was happening they wouldn't be happy? Google has eighty brazillion employees it can test new features on.

Google employees are not a random sample of their user base, so such experiments would be meaningless. See the fiasco where they broke Terminal Services last year as an example of what can go wrong even when doing experiments on the whole user base. Also consider how to measure the usage of web features Google's own websites don't use, but are popular on e.g. intranets in Korea. A/B testing isn't bad, it's a good thi…

Google employees are not a random sample of their user base, so such experiments would be meaningless.

This is a lazy argument. Google isn't some scrappy tech startup where 90% of the employees are programmers. Google has legions of lawyers, mailroom clerks, accountants, travel coordinators, janitors, cafeteria workers, middle managers of all stripes, and so much more. Thousands and thousands of people it can test on without violating the privacy of the general public.

Re: Google tracks individual users per Chrome installation ID

#503

Everybody imagine going back 15 years and tell yourself that you're using a web browser made by the parent company of DoubleClick. Your 15 year ago self would think you're a moron (assuming that 15 years ago you were old enough to know what DoubleClick was).

Well, it depends. Do I get a funny animation following my cursor if I do it?

Re: Google tracks individual users per Chrome installation ID

#504

So, an extremely unique identifier for tracking purposes, that effectively no one knows exists, and no one knows can be changed at all? With an obscure white paper that allows Google to claim they comply with the law because "they totally offer a way to change that and they even published that information to the web for anyone to find"? Gotcha.

Reminds me of this. "There’s no point acting all surprised about it. All the planning charts and demolition orders have been on display in your local planning department in Alpha Centauri for fifty of your Earth years, so you’ve had plenty of time to lodge any formal complaint and it’s far too late to start making a fuss about it now"

Beware of the leopard!

Re: Google tracks individual users per Chrome installation ID

#505
post #209

Earlier quoted context omitted.

Actual list: https://cs.chromium.org/chromium/src/components/google/core/...

Security flaw? Surely some entity is squatting youtube on some TLD?! If there is a country TLD of X where Google owns google.X but entity Y owns youtube.X then entity Y gets the X-CLIENT-DATA header information. See usage of IsValidHostName() in code.

Note this would be a privacy flaw which is not covered by the Chrome Rewards program (which only covers security flaws) so I haven’t bothered logging it as a bug since I don’t want to waste my time verifying it for nothing!

https://chromium.googlesource.com/chromium/src/+/master/docs...

Re: Google tracks individual users per Chrome installation ID

#506
post #461
post #362

TL;DR I think whoever posted that is trying to bury the UA anonymizing feature by derailing the discussion. What I'm seeing is an RFC for anonymizing parts of User-Agent in order to reduce UA based fingerprinting, which improves everyone's privacy, that's a good thing! Then I see someone comments how that could negatively impact existing websites or Chromium-derived browsers, comments which are totally fair and make…

I think the concern is that this disarms Google's competitors while keeping them fully-armed. Ads are a business, and they are Google's business. They are how they make money. And like all businesses, they are competitive. Tracking is a way to make more money off online advertising. By removing tracking from their competitors while keeping it for themselves, Google stand to make a lot of money off this change. Their…

I think this is a common strategy of big players at any industry.

First, they do some dirty thing to gain a competitive edge when the industry is still new and unregulated. Later they develop an alternative way to achieve the same competitive edge, and then criticize other players for doing an old way, saying they should be "mature and responsible".

Re: Google tracks individual users per Chrome installation ID

#507
post #481
post #461

Earlier quoted context omitted.

I think the concern is that this disarms Google's competitors while keeping them fully-armed. Ads are a business, and they are Google's business. They are how they make money. And like all businesses, they are competitive. Tracking is a way to make more money off online advertising. By removing tracking from their competitors while keeping it for themselves, Google stand to make a lot of money off this change. Their…

While I agree with some of your comment, I feel like it’s harsh to paint the whole chrome enterprise with that brush. Chrome was about freeing the world of a truly terrible web browser and a lot of devoted devs have spent a lot of time working on it. There’s an advertising aspect that it’s right to call out, but I think on the whole it was done to make the internet better, because the internet is google’s business to…

It wasn’t some noble mission to free the world. Chrome was always about Google controlling the client side of the web to guarantee their advertising access to web users. The ability to extract additional data from the user was a nice bonus.

Re: Google tracks individual users per Chrome installation ID

#508
post #471

Earlier quoted context omitted.

Firefox, chrome, linux ... all are full of unnecessary complexity. The point being - we need daily patches to keep it from falling apart. I have links (or lynx) on an old SuSE, maybe even a Mandriva CD. Would they be massively pwnable?

Hard to say, but not necessarily a great example; exploits on software are a function both of attack surface / complexity and installed userbase (i.e. nobody bothers to see if lynx is pwnable because a zero-day against that browser will be worth, what, twenty bucks to gain access to the five people who use it?).

Perhaps. Perhaps not. As a thought experiment:

How long would it be safe to go without browser updates with a browser of complexity/capabilies of links, if 50% of people used it?

With many people combing through it, would it become effectively unexploitable?

Re: Google tracks individual users per Chrome installation ID

#509
post #202

Earlier quoted context omitted.

" involuntary, unpaid guinea pigs. No consent. No opt-out" That sounds like all A/B testing...

That sounds like all A/B testing... In the tech world, maybe. But not in the real world. For example, one of the colleges I went to was in an area with a lot of pharmaceutical companies. My friends would A/B test drugs for the companies. They made enough money to pay for college. But it was all completely consensual, with contracts and disclosures, etc... Companies in the increasingly morally bankrupt SV bubble just…

Like it, or not, these companies believe the terms of service at the bottom of the page suffice for your consent. We really need this problem to be tackled on many levels (legal precedents that terms don't matter, education, encouragement of good alternatives, etc.)

Until that time, folks in the SV bubble will just keep doing this. Companies that can operate only from the US are effectively untouchable when it comes to regulation. Big companies like Facebook get caught a bit because they have offices, but many no name companies acting as data brokers, etc. don't have a presence and are hard to deal with.

Re: Google tracks individual users per Chrome installation ID

#510
post #395
post #356

Earlier quoted context omitted.

>Now this is interesting. If without that 13 bits of entropy, what will Google lost? Is it because of this 13 bits then Google suddenly able to track what they were not? At the very least, having those 13 bits of entropy along with a /24 subnet allows you to have device-level granularity, whereas a /24 subnet may be shared by hundreds of households.

They have more than 13 bits of entropy https://cs.chromium.org/chromium/src/components/metrics/entr... Look how the function is called, high-entropy source :)

But if you disable telemetry, they'll only have 13?
Post reply on HN