Live data from Hacker News

Chrome client “variations” can be used to identify you (2020)

zapek.com

11–20 of 79 posts

Re: Chrome client “variations” can be used to identify you (2020)

#11
Chrome only sends these headers to Google-owned domains.

As an attack surface, if you're worried about being spied on by the company that you got your browser from, I'd be more concerned about the closed-source control they have over the code in the browser itself than the unique identifier you're sending to their servers when you use their browser.

Re: Chrome client “variations” can be used to identify you (2020)

#12

Earlier quoted context omitted.

It's incredibly convenient. I sat down at a new laptop about a month ago and realized I was blanking on my bank account credentials. Fortunately, since I use Chrome, I was able to log in and get them clouded over. Whew!

That means you were already logged into google. At that point just use Bitwarden.

I'm not familiar with Bitwarden. After a bit of Wikipedia and web search research on them, I'm not sure why I'd trust 8Bit Solutions over Google for storage of my PII. Do they have the resources to keep it secure? What is their incentive structure to do so? What happens if they get bought? Should I be concerned about past errors such as "In March 2018, Bitwarden's web vault was criticized for embedding unconstrained third-party JavaScript from BootstrapCDN, Braintree, Google, and Stripe"?

It sounds like it'd add an additional layer of complexity to my situation without an obvious up-side over my existing solution.

Re: Chrome client “variations” can be used to identify you (2020)

#13
post #4

Earlier quoted context omitted.

Borg is the name of the backend service that runs a lot of Google software - https://research.google.com/pubs/pub43438.html?hl=es#:~:text... .

That's the nod-and-wink joke about the name Kubernetes. While it's a "controller" (hence the name) its design was inspired by borg. ... Kubernetes, or "kube" for short. ;)

Can you also explain the "rnetes" part? And why is it spelled with a K?

Re: Chrome client “variations” can be used to identify you (2020)

#14

Earlier quoted context omitted.

That's the nod-and-wink joke about the name Kubernetes. While it's a "controller" (hence the name) its design was inspired by borg. ... Kubernetes, or "kube" for short. ;)

Can you also explain the "rnetes" part? And why is it spelled with a K?

Kubernetes is a Greek word meaning helmsman.

Re: Chrome client “variations” can be used to identify you (2020)

#15

Earlier quoted context omitted.

That's the nod-and-wink joke about the name Kubernetes. While it's a "controller" (hence the name) its design was inspired by borg. ... Kubernetes, or "kube" for short. ;)

Can you also explain the "rnetes" part? And why is it spelled with a K?

> Kubernetes (κυβερνήτης, Greek for "helmsman" or "pilot" or "governor", and the etymological root of cybernetics)

Source: https://en.wikipedia.org/wiki/Kubernetes?wprov=sfti1

(The Borg have cybernetic enhancements, I’m guessing that’s the link)

Re: Chrome client “variations” can be used to identify you (2020)

#16
post #2

Chrome also syncs your browser history and passwords with their servers. They have your search history. They have your private email. They have your YouTube history. They have your private documents and photos. They run your phone. They possibly run your laptop. I guess my point is it goes far beyond Chrome. Google is running the Borg hive mind.

tbf they're fairly competent with it, I don't think I've ever had anything Google related compromised. I'm honestly not sure what the better solution is.

There's a lot of security theater around this where people will de-google their software and then run random binaries compiled by unknown people on the internet instead

Re: Chrome client “variations” can be used to identify you (2020)

#17
post #2

Chrome also syncs your browser history and passwords with their servers. They have your search history. They have your private email. They have your YouTube history. They have your private documents and photos. They run your phone. They possibly run your laptop. I guess my point is it goes far beyond Chrome. Google is running the Borg hive mind.

And so does Apple, Microsoft, and pretty much anyone else you share that info with. It's a little surreal to hear people complaining about companies having all their data when they were the ones who gave it to them in the first place. You want to buy privacy? They make you pay with convenience.

Re: Chrome client “variations” can be used to identify you (2020)

#18
post #2

Chrome also syncs your browser history and passwords with their servers. They have your search history. They have your private email. They have your YouTube history. They have your private documents and photos. They run your phone. They possibly run your laptop. I guess my point is it goes far beyond Chrome. Google is running the Borg hive mind.

They still have a few of my emails but besides that, only Youtube browsing... I use LineageOS without Gapps on my phone and some other web search engine, most of the time.

Re: Chrome client “variations” can be used to identify you (2020)

#19
This is great and all - but what's the alternative?

I've been using Firefox as my primary browser for about 2 years now - and the javascript engine on it has recently... sh*t the bed (I cannot paste links or images into facebook, I cannot paste text with line breaks into twitter, I cannot paste using reddit's "markdownmode").

I use google-chrome for netflix, recently chromium stopped working for netflix (apprently the browser is no longer supported)

Edge isn't an option for me, brave isn't on my radar (WHY include cryptojunk with a BROWSER???, it's like the early 2000s where a major vendor was trying to claim that the browser is tied so closely to their kernel as to make it a part of an OS)

Is Opera any good?

Re: Chrome client “variations” can be used to identify you (2020)

#20

Earlier quoted context omitted.

That means you were already logged into google. At that point just use Bitwarden.

I'm not familiar with Bitwarden. After a bit of Wikipedia and web search research on them, I'm not sure why I'd trust 8Bit Solutions over Google for storage of my PII. Do they have the resources to keep it secure? What is their incentive structure to do so? What happens if they get bought? Should I be concerned about past errors such as "In March 2018, Bitwarden's web vault was criticized for embedding unconstrained…

Bitwarden uses end-to-end encryption. So you don't have to trust them as much as Google.
Post reply on HN