I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…
I've been considering switching over to Firefox after being a day-one adopter of Chrome and this helped become a tipping point to get me to switch over. Though, full disclosure: I've been working to limit Google services in my day-to-day life (Maps, Gmail, and now Chrome) in the last couple of months over privacy concerns.
Am I logged in or not? GDPR case study on the example of Chrome browser change
111–120 of 507 posts
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#112This is the second time I've seen the reference to Chrome being the most secure browser. What's that based on?
Exploit prices and complexity usually accurately reflect the security of a product when compared to their competitors. Take a look at how much Zerodium pays for full-chain exploits here: https://zerodium.com/program.html $250,000 - Chrome RCE + SBX (Windows) including a sandbox escape (previously: $150,000) Whereas it's up to $100k for Edge RCE+SBX, $80k for Firefox RCE+SBX You obviously need to factor in other thing…
Another thing to take in consideration is the number of people that the exploit could be used against. For example, following this: http://gs.statcounter.com/browser-market-share/desktop/world..., Chrome would have almost 68% of the browsing share whereas Firefox is only close to 10% and all the others even less. It'd be surprising this isn't taken account by Zerodium in their price calculations!
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#113I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…
I had some legitimately scary things that may or may not be tracking but I cannot explain it without tracking. I watch some youtube video where the audio mentions a historic place of battle and then seconds later it shows up in my Google Chrome autosuggestion because I wanted to google some more information on it. I dont see how that is possible, it was a very specific location. I only typed "battle of" and it showed…
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#114I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…
I'm half thankful for the Chrome team doing this because it was just the push I needed to finally rid myself of Chrome once and for all.
I plan to do a clean re-install of the OS on my Mac as well to ensure that all vestiges of Google Chrome are indeed gone. I also took the opportunity to rid myself of Google Drive File Stream.
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#115Earlier quoted context omitted.
> because nobody cares A lot of people do not understand, but we do, we're the techies. It's our job to understand. Don't mistake people not understanding for not caring. Once people understand, they care.
Yeah, but my parents _understand_ Facebook collects/sells their data. But they don't _care_ enough to stop using Facebook.
Everyone "understands" that Facebook collects user data. It's the contextual understanding that makes techies uneasy.
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#116Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#117I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…
I had some legitimately scary things that may or may not be tracking but I cannot explain it without tracking. I watch some youtube video where the audio mentions a historic place of battle and then seconds later it shows up in my Google Chrome autosuggestion because I wanted to google some more information on it. I dont see how that is possible, it was a very specific location. I only typed "battle of" and it showed…
As for you watching a video and autocomplete coming in with the same topic, could it be that there was a surge of interest of that battle at the time? Otherwise it may be url analysis from other people searching through chrome.
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#118Earlier quoted context omitted.
They could support both use cases by popping up a dialog on sign-in to a Google web property: "You're signing into Gmail. Would you like to link Chrome to joebloggs@gmail.com? This will enable automatic notifications in Gmail, sync passwords and web history, and also automatically log into other Google websites when you visit them". "Yes / No / No, and don't ask again"
Excuse my cynism but the options would be: "Yes / Ask again later"
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#119"apt-get install apache2" violates GDPR (logs IPs). It's not a difficult line to cross at all.
Lets try the law on this one: Is the IP personal data for the GDPR? If I read the GDPR, the Debian foundation is not capable to pinpoint 1 person so it seems to me it is not (An ISP or someone receiving an IP to person mapping from them is something different): ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can…
However, I can't recall ever having seen this privacy policy before now. IANAL and don't know what kind of notice needs to be given for necessary data usage, if any, but maybe apt-get should display the privacy policy on first use.
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#120Please, Google, fix those mistakes soon, and avoid a PR fiasco.
Nobody really cares outside this tech bubble. There won't be a PR fiasco, because it's hard to explain why it's bad for a non techie end user. "Google simplifies the login experience in Chrome", is essentially what's happening here and it's far from obvious how to sell it as a doomsday scenario as I read the mood correctly of many HN users.
Even inside of this tech bubble there are people like me that think this change is fine the way it is and that it's actually a good idea for convenience. The vast majority of people are using Chrome to go to Google websites using their Google account and having one less step to sign in to Chrome Sync is just a good thing from a usability perspective.