Live data from Hacker News

Google Chrome silently installs a 4 GB AI model on your device without consent

thatprivacyguy.com

891–900 of 1001 posts

Re: Google Chrome silently installs a 4 GB AI model on your device without consent

#891
post #692

Earlier quoted context omitted.

> You are conflating disk and memory. I never conflated anything. I said it's a neglible amount of space for current hardware, which I still believe. If anything, the fact that I think the amount of space is acceptable for the amount of ram a modern laptop has exaggerates the point. > There’s a reason they picked an opt-out model for this, and not an opt-in approach. That's the approach they take for most of their fe…

> I never conflated anything. I said it's a neglible amount of space for current hardware, which I still believe. > > If anything, the fact that I think the amount of space is acceptable for the amount of ram a modern laptop has exaggerates the point. How does the memory usage of your browser tabs relate to the amount of disk space taken up by the downloaded models? > That's the approach they take for most of their f…

> How does the memory usage of your browser tabs relate to the amount of disk space taken up by the downloaded models?

I am talking about space in general. Data size. The relation of data stored in one place vs another is the fact they both store *data*. The components to store data can be cheaper or more expensive based on how it's architected. The fact I still see 4GB as an acceptable cost in ram exaggerates the point because it shows that I'm okay with 4GB being consumed in a relatively expensive component used for data storage (meaning I'd obviously be okay with it being stored on hard disk).

> if and when they decide to pick a model that isn’t half brain dead (apparently it’s based on Gemma 3)

Gemma 3 is far from brain dead and can be used for a variety of different tasks, translation being one I've personally used it for.

Re: Google Chrome silently installs a 4 GB AI model on your device without consent

#892
post #585

Framing this as needing "consent" is deeply misguided. It's as silly as claiming that Microsoft Word installed an English language spellcheck dictionary without your consent. It's just part of the software. You consented to installing the software and having it autoupdate. That covers it. Now we can argue whether or not it's an appropriate amount of disk space or bandwidth to use, but that's just a reasonable practic…

It's additional software that many users didn't ask for, don't want and will not be aware of. Reminds me a bit of back when installing software was a minefield due to all of the integrated "promotions" for things like toolbars, only now they've vertically integrated the unwanted software, cutting out the middleman. Honestly, for most features you could justifiably say its fine. I mean honestly, how large is an Englis…

That 4 GiB will also update daily, because without churn it will be dead.

Re: Google Chrome silently installs a 4 GB AI model on your device without consent

#893
Pure, unadulterated, poorly researched and factually incorrect clickbait.

Question from last November, even referring to macOS, by @paulirish: https://superuser.com/q/1930445/can-i-delete-the-chromes-opt...

With policy setting, debug url, docs in the answers.

One search away.

Re: Google Chrome silently installs a 4 GB AI model on your device without consent

#894

I stopped using chrome 15 years ago and de-googled my life 5 years ago. The hardest thing to let go in fact was Gmaps (most alternatives, until recently, were not great) and I'm still captured by android, but rome was not built in a day. Quitting chrome these days is the easiest thing to do. The writing is on the way. You don't control the browser on your network, google does. ANd for better or worse, google's priori…

> most alternatives, until recently, were not great Curious to know, what viable alternatives did you discover?

Gmaps WV while using VPN. Download from Fdroid.

Its miles ahead of something like Osmand , which i really, really, tried to like for a year, but its a UX disaster (i could never ever figure it out)

Re: Google Chrome silently installs a 4 GB AI model on your device without consent

#895

Pure, unadulterated, poorly researched and factually incorrect clickbait. Question from last November, even referring to macOS, by @paulirish: https://superuser.com/q/1930445/can-i-delete-the-chromes-opt... With policy setting, debug url, docs in the answers. One search away.

For completeness: The single policy setting name to disable model download is GenAILocalFoundationalModelSettings https://chromeenterprise.google/policies/gen-ai-local-founda...

The current state can be viewed at the internal debug URL chrome://on-device-internals/

Since January there's a user facing toggle in Settings > System > On-device AI in Chrome Canary https://www.bleepingcomputer.com/news/artificial-intelligenc..., described in Chrome Help Center at https://support.google.com/chrome/answer/16961953https://sup...

Re: Google Chrome silently installs a 4 GB AI model on your device without consent

#896
post #649

Earlier quoted context omitted.

> It's additional software that many users didn't ask for, don't want and will not be aware of You just described 95% of the parts of all software, especially in this era. And think of the Web - how many gigabytes of terrible adtech and tracking code does the average user download in a month of web browsing without an adblocker? Remember, each one probably packages in a couple hundred NPM dependencies into its bundle…

You just described 95% of the parts of all software, especially in this era. Yes, that's the problem

The problem here is that the on-device model is old news packed as clickbait without any research beyond his file system. https://news.ycombinator.com/item?id=48034889 And all news outlets spreading it w/o any further research of their own.

Policy GenAILocalFoundationalModelSettings disables and removes the local model without any flag hacks since 2024. In Canary since January behind Settings > System > On-device AI

The article doesn't mention Chrome version, release channel, whether on fresh vs existing install an if settings were altered.

Re: Google Chrome silently installs a 4 GB AI model on your device without consent

#897

Framing this as needing "consent" is deeply misguided. It's as silly as claiming that Microsoft Word installed an English language spellcheck dictionary without your consent. It's just part of the software. You consented to installing the software and having it autoupdate. That covers it. Now we can argue whether or not it's an appropriate amount of disk space or bandwidth to use, but that's just a reasonable practic…

"You consented to installing the software and having it autoupdate. That covers it." Were the terms something like https://chromium.googlesource.com/chromium/chromium/+/refs/h... "11.1 The Software which you use may automatically download and install updates from time to time from Google. These updates are designed to improve, enhance and further develop the Services and may take the form of bug fixes, enhanced funct…

First of all I want to thank you for your intelligent and reasoned post. As the author of the article in question, I have been mostly shocked at how many people are excusing this behaviour and playing Google Apologist.

Now to answer your question on the remedies. I didn't put them in this article because I covered them in another article that went viral a week or so earlier (the first reference in the Google article). The Google article was already a long read, I didn't want to repeat information I had already posted elsewhere.

As for my actions - well I will take the same actions I took against Anthropic.

I am currently preparing two legal complaints:

The first is under the GDPR and ePrivacy Directive here in the EU and will be sent to the IDPC (Information and Data Protection Commissioner) who will then initiate a Cross Border investigation with the Irish Data Protection Commissioner (Google is "established" in Ireland for the purpose of GDPR) for the GDPR aspects and conduct their own investigation on the ePrivacy violations.

The second will be a criminal complaint against Google under Chapter 9 of the Maltese Criminal Code for alteration of the configuration of my device (Google remotely flipped a profile flag to enable the download which I witnessed in real time and have logs for) and for unauthorised access and use of my computer (to download and redownload the model) under computer misuse and access statutes (think CFAA in the US and how it was used against Aaron Swartz if you are looking for a way to file a criminal complaint against Google for this - the arguments used against Swartz are just as applicable to Google here).

So again, thanks for the post, it was nice to read someone actually understanding (unlike Reddit where it seems they do anything but read what they are talking about despite being called Reddit).

I also want to take this opportunity to thank everyone else in this thread for their time and comments and to YC for hosting the discussion.

Also my apologies for the 503's some people got yesterday (and thanks for posting mirrors) my blog runs on my home server and I had the rate limit set too low (I increased it once I saw the messages on here and it seemed to have fixed it).

Now that said - wait until you see what I am publishing next week (the project I was working on when I discovered this), it makes this look like child's play...

Re: Google Chrome silently installs a 4 GB AI model on your device without consent

#898

Earlier quoted context omitted.

That was an even more ridiculous post. It wasn't spyware, it was a messaging bridge being installed for exactly the purpose it was intended. It was Claude Desktop installing a bridge that would allow Claude browser plugins to communicate with it. It was only used if the user had installed the browser plugin, and all it did was grant that plugin access to the app that had installed it!

So it's a backdoor to bypass the browser sandbox. Spyware is an apt label for that.

It's not a backdoor: it's using a feature for the purpose for which it was designed. It's not granting plugins access to anything except itself

Re: Google Chrome silently installs a 4 GB AI model on your device without consent

#899

Earlier quoted context omitted.

Auto-updating browsers is one of the best advances in the web dev space in the past decade. I find it hard to believe that anyone who did web development before evergreen browsers became a thing would ever disagree.

Best advances for whom? Lazy web developers? Considering that most websites are optimized to just barely run on what the developers are targeting, letting them target the "state of the art" instead of what came installed on grandmas machine is been a huge negative for website efficiency and thus average user experience, not to mention global resource waste.

Web developers, users who want don't want security issues in their browser, and anyone who wants consistent rendering of sites

Re: Google Chrome silently installs a 4 GB AI model on your device without consent

#900
post #874
post #679

An extra 4GB per user on our NFS home file server is going to be a huge pain (several thousand students). And for our Windows lab machines, they end up in AppData\Local (which isn’t redirected for operational reasons) so we either leave the profiles in place and let them accumulate (suboptimal) or clear out the profiles as we normally do and let it redownload, over and over again. As much as I’m against unexpected 4G…

I tend to deal with unwanted installations by creating a zero length file with the name (weights.bin) and remove all permissions from all users, taking the ownership as well. While the download and friends commence they fail to overwrite it. The tactic used to work even as prevention to common RPC exploits (viruses/worms) on windows as well (in the early 2000s).

The zero size filed with the same name trick was the first thing I thought of as well.
Post reply on HN