Live data from Hacker News

Google tracks individual users per Chrome installation ID

github.com

591–600 of 642 posts

Re: Google tracks individual users per Chrome installation ID

#591

As long as web developers continue to create (app-)sites that only work in the latest versions of Chrome(and Chromium-ish) browsers, giving users little effective choice over what browsers they can use, this sort of abusive behaviour will continue. The sort of "feature-racing" that Google engages in is ultimately harmful for the open web. Mozilla struggles to keep up, Opera surrendered a while ago, and more recently,…

> [...] this sort of abusive behaviour will continue.

Can you elaborate what exactly is abusive behavior?

> [...] reliance on hostile browsers, [...]

What exactly is a hostile browser?

Re: Google tracks individual users per Chrome installation ID

#592
post #360

Earlier quoted context omitted.

Please don't respond to a bad comment with another one. That just makes the thread worse. Doubly so for personal attacks, which are a bannable offence on HN.

What was so bad about my comment? Saying that I don’t support Mozilla/Firefox or just not being anti-Google enough? Also, the guy that you’re responding to simply said that I seemed angry. How is that a personal attack? Somebody else responded that I’m ruining the Internet and somehow that’s not flagged?

"You seem very upset", "I suggest going for a walk", "Take a couple deep breaths", "Calm down", and even "It's just a browser" are patronizing personal comments that cross into insulting. Even worse, "By the way, what sites do you work on? I'd like to make sure to avoid them." is an ugly personal attack. I'm delighted that you didn't take offense at any of that, but that puts you above the 99th percentile of non-offense-taking. We can't pitch moderation at that level!

I wish it were obvious, but no, we don't care (I mean we really don't care) whether HN users support Mozilla or Firefox or Google or hate them. The only thing we care about [1] is whether the stories and comments on this site gratify intellectual curiosity. Most for-or-against rants of that nature don't have much curiosity in them. They're more like sports fans yelling at each other. That's great in its way! It's something to do. It gets juices flowing. But it's not really the kind of discussion we're going for here. By the way, although I don't frequent sports fan sites, I'd bet a lot of money that users there feel like the mods are biased against their team.

To be honest, I didn't really think your comment was that bad. It broke the site guidelines by being a name-calling rant. But it was so over-the-top that to me it felt more exuberant than mean, and that's actually not the kind of thing we're trying to eliminate here. Meanness is. The reason I didn't spell this out in my reply to Shaaaaaaare is that their comment really did break the site guidelines badly, and this is much too subtle a distinction to have gone into in that context. Much better to say: even if the other comment was really bad, you still can't post like this. In other words, two wrongs don't make a right, just as mothers have always said.

1. See https://news.ycombinator.com/item?id=20186280 and https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

Re: Google tracks individual users per Chrome installation ID

#593

Downvote me how many times you want, but Mozilla needs to fork Chromium, degoogle it and fix the web. Mozilla is the only internet entity I can say I trust, I am donating to it, and yet I am using Chrome and Brave on both Desktop and mobile. Just follow the users and fork it!

There is a Chromium fork that does that already.

Re: Google tracks individual users per Chrome installation ID

#594
post #4

Not endorsing this, but according to https://www.google.com/chrome/privacy/whitepaper.html#variat... > We want to build features that users want, so a subset of users may get a sneak peek at new functionality being tested before it’s launched to the world at large. A list of field trials that are currently active on your installation of Chrome will be included in all requests sent to Google. This Chrome-Variations he…

So it’s just a poor excuse to send an evercookie.

Re: Google tracks individual users per Chrome installation ID

#595

Earlier quoted context omitted.

It is an abuse of Chrome's position in the marketplace. Google is using their powerful position to give themselves tracking capabilities that other online players can't access. It is a major competitive advantage for Google.

can't alternate browser makers who base on chromium simply disable that portion? like, I expect identifying users was a key business concern in moving Edge to Chromium. Is there something (other than work) preventing them from making it so it'll report back to microsoft-owned domains instead?

I'm using Vivaldi on MacOS and it doesn't send this header. I'm sure others like Brave don't send it either.

Re: Google tracks individual users per Chrome installation ID

#596

As long as web developers continue to create (app-)sites that only work in the latest versions of Chrome(and Chromium-ish) browsers, giving users little effective choice over what browsers they can use, this sort of abusive behaviour will continue. The sort of "feature-racing" that Google engages in is ultimately harmful for the open web. Mozilla struggles to keep up, Opera surrendered a while ago, and more recently,…

This proposal would not accomplish what you intend. By slowing the adoption of open web technologies, developers and users would lean more heavily on mobile apps, which are also under Google's control considering Android's huge market share.

Developers who want to level the playing field need to develop sites that fully support Firefox and other browsers that are not based on Chromium. Users who want to see a more open web need to use Firefox and non-Chromium browsers, and complain to developers who don't properly support them.

Re: Google tracks individual users per Chrome installation ID

#597
post #251

Earlier quoted context omitted.

Well, I'm an ex employee. Actually nothing has changed inside the company. "Tracking" as you put it isn't perceived as evil, it never has been, and for good reasons. The only thing that's changed is people's perception of the company and - very recent post 2016 political issues aside - that was mostly driven by a sustained campaign by an angry media industry that wanted money (see: link taxes). Firstly, if tracking u…

Most people use default settings and have no idea about the software they are using at all. "everyone would hate it" assumes people know about these things, but they do not. Don't use this as a point. ad 3), you make it sound as if it was one xor the other. This is sometimes the case to some degree (like checking urls for phishing sites), but far from always. ad 4), it is not my problem as a user that you have troubl…

"everyone would hate it" assumes people know about these things

It's based on direct experience of these tradeoffs.

Firstly, yes, people accept the defaults most of the time. They expect those defaults to be convenient and secure. But even when forced to click through screens that literally won't let them proceed until they consider their privacy settings, they don't care and routinely opt in to data sharing because it's more convenient.

Believe me, Google has tried everything in this space. Every combination of popup, click through, interstitial, notification, endless usability studies. Everything. New products that use user data in clever ways get instant uptake on the order of hundreds of millions of users with virtually no promotion at all. Privacy-oriented features get nearly none despite heavier promotion. To the extent people don't know about privacy settings it's because they do not care.

I know this goes against the tech industry zeitgeist or groupthink. It's unpopular to spell this out, but that's why it's important to do so. Way too many companies and engineers are working on dead-end privacy projects that address an imaginary market demand.

you make it sound as if it was one xor the other. This is sometimes the case to some degree (like checking urls for phishing sites), but far from always.

It's not 100% always, but it's hard to come up with cases where privacy and security aren't in tension.

For instance, one of the reasons you can't build truly end to end encrypted consumer services is people don't want to swap public keys. It's more hassle and nobody has it, so every end-to-end encrypted service has a big central key directory ... which makes the encryption pointless, as the service can still decrypt conversations on demand. That's not the only problem but it's a big one.

Another problem is people expect password reset. You can't build a service without password reset or else you'll have an angry mob at your door demanding their accounts back. If you say, sorry, there's no password reset because the data is all encrypted and we can't get it back then you'll lose your market position. Hence why iPhone backups are unencrypted.

It's not hopeless. Google get the most pressure on these topics so they've been coming up with some of the best solutions. Their Titan architecture is quite innovative in this space, although we'll see what happens when people realise "I forgot my PIN, please verify my identity some other way" doesn't work anymore.

And if others do this to gain an advantage over your business, don't whine, sue them.

I'm afraid this is extremely naive. There is nothing illegal about running user tests, server logging and gathering metrics. And don't talk about GDPR to me. It's a meaningless law that is so badly drafted it affects nothing. You can do basically anything if it's justified by a genuine business need, and understanding customers is an absolute need of any business.

But if the EU under German direction decides to interpret the GDPR such that it bans making convenient and secure software, then so what? America crushes the EU in the software business already. It will simply extend its lead. American startups will learn "don't open offices in Europe and you're OK" and so the EU will continue to degrade its own economy, continue to have no tech startups of note and the USA's more sensible approach to privacy will continue to be the only one that matters.

"boring statistics about religion" led to the murder of hundreds of thousands of Jews.

At the risk of going full Godwin on this thread, that's a severe mis-understanding of your own history. No wonder Germans have such strange approaches to internet privacy if that's what you're being taught. Americans haven't "forgotten" the reasons for wanting privacy, they just don't think spreadsheets were relevant to what happened. And BTW I'm not American.

So: Nazi-ism wasn't enabled by the collection of statistics. They would have hunted down and eradicated groups of people all the same. We know this because communists hunted down threw huge numbers of anti-communists into concentration camps, although being anti-communist isn't a birth trait and that fact existed in no statistical databases. They didn't need Big Data because they had a large network of ideologically motivated informers and collaborators instead: just like Hitler did.

Finally, I'll say that going from "Google runs A/B tests to learn if a new feature is popular" straight to "sue anyone who does this because they're directly leading to Jew murder" is really quite offensive and shows no sense of proportion. Google is not enabling the Third Reich. It's just doing what any boring old city shop does when they experiment with putting different items on sale, or experiment with different layouts of the stores. The fact that it's online changes nothing.

Re: Google tracks individual users per Chrome installation ID

#598

Earlier quoted context omitted.

Well, I'm an ex employee. Actually nothing has changed inside the company. "Tracking" as you put it isn't perceived as evil, it never has been, and for good reasons. The only thing that's changed is people's perception of the company and - very recent post 2016 political issues aside - that was mostly driven by a sustained campaign by an angry media industry that wanted money (see: link taxes). Firstly, if tracking u…

Your points are sound, but I'm puzzled by your last line: >It's really only Google and Facebook that get the vitriol. The way I read it, it seems as though it's unfair that they get away with doing questionable stuff when "others do worse". Why yes, if you have nefarious intentions but no power to act them out, people are going to throw less "vitriol" at you than if you do act them out.

What I mean is that offline businesses have been running experiments to see what works forever. They run a billboard campaign in city X and run a slightly different one in city T to compare the results. They count customers as they come through the door. They issue loyalty cards that people sign up for in their millions, making a special effort to share data with giant supermarkets because they're (effectively) given a share of the resulting revenue increase.

Nobody cares or talks about any of these things. But when Google does the online equivalents, it's suddenly the next coming of Hitler (literally, look at the comment I replied to above!).

This isn't really proportionate, it doesn't make sense, and it's quite offensive to people who work or used to work at these firms.

Re: Google tracks individual users per Chrome installation ID

#599
I'm surprised this hasn't gotten any mainstream tech press attention. Chrome's Privacy Whitepaper describes a number of privacy-questionable nonstandard headers which are only sent to Google services. Just try searching for X- here:

https://www.google.com/chrome/privacy/whitepaper.html

And for ease of reading, a few others:

> On Android, your location will also be sent to Google via an X-Geo HTTP request header if Google is your default search engine, the Chrome app has the permission to use your geolocation, and you haven’t blocked geolocation for www.google.com (or country-specific origins such as www.google.de)

> To measure searches and Chrome usage driven by a particular campaign, Chrome inserts a promotional tag, not unique to you or your device, in the searches you perform on Google. This non-unique tag contains information about how Chrome was obtained, the week when Chrome was installed, and the week when the first search was performed. ... This non-unique promotional tag is included when performing searches via Google (the tag appears as a parameter beginning with "rlz=" when triggered from the Omnibox, or as an “x-rlz-string” HTTP header).

> On Android and desktop, Chrome signals to Google web services that you are signed into Chrome by attaching an X-Chrome-Connected and/or C-Chrome-ID-Consistency-Request header to any HTTPS requests to Google-owned domains. On iOS, the CHROME_CONNECTED cookie is used instead.

Re: Google tracks individual users per Chrome installation ID

#600

Earlier quoted context omitted.

Well Mozilla burnt my trust in them over the last couple of years ... maybe Brave? Some don't like their model to tip content providers but they seem - and I've not made rigorous enquiries here (please inform!) - to be a relatively trustworthy mod of Chromium!?

Brave is commercial entity, same as Google.

Mozilla Corp isn't a charity, gets several hundred million $USD from Google, pays 7-figure wages, manipulates is users to achieve commercial aims, ... you're saying it's not a commercial entity?
Post reply on HN