Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

131–140 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#131
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

> I don’t understand why the Chrome team is picking this hill to die on Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this. > I really expect this change to push a lot of people away from chrome Care to bet on that? Because I would happily take the opposite side of that bet. I think th…

I would take a small bet. We're the trend-setters in technology. We're the ones who got everyone on Chrome to begin with. Otherwise they'd still be on IE. If all the tech people abandon Chrome, they will start recommending FF or IE again and discourage Chrome use. The impact is slow, but it is significant.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#132
Chrome has been the new IE for years. "just use chrome" is an endless refrain from webdevs who don't want to test on Firefox. Not sure why it is so hard for people to see what is going on here. Google has a massive conflict of interest with their web development efforts. This is classic Microsoft-esque Embrace, Extend, Extinguish.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#133
post #93

Earlier quoted context omitted.

They could support both use cases by popping up a dialog on sign-in to a Google web property: "You're signing into Gmail. Would you like to link Chrome to joebloggs@gmail.com? This will enable automatic notifications in Gmail, sync passwords and web history, and also automatically log into other Google websites when you visit them". "Yes / No / No, and don't ask again"

Excuse my cynism but the options would be: "Yes / Ask again later"

Given that the popup sitting in my Gmail window currently says

"Update now / Update in 1 week"

I think you're being a little optimistic.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#134
post #112

Earlier quoted context omitted.

Exploit prices and complexity usually accurately reflect the security of a product when compared to their competitors. Take a look at how much Zerodium pays for full-chain exploits here: https://zerodium.com/program.html $250,000 - Chrome RCE + SBX (Windows) including a sandbox escape (previously: $150,000) Whereas it's up to $100k for Edge RCE+SBX, $80k for Firefox RCE+SBX You obviously need to factor in other thing…

You have a valid point but you are using misleading data: Don't compare a RCE + SBX vs a RCE w/o SBX. Firefox RCE + SBX is 80k, edge is 100k, safari is also 80k. Another thing to take in consideration is the number of people that the exploit could be used against. For example, following this: http://gs.statcounter.com/browser-market-share/desktop/world... , Chrome would have almost 68% of the browsing share whereas F…

You're correct -- I was referring to the table that was easiest to quickly reference which is the changelog, not ALL current prices. The periodic table is more accurate. I'll update my post.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#135
post #6

I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…

> I think that currently pretty much every service, device and website violates the GDPR. Not really, my website doesn't :-) In case you're using Google Analytics, it's easy to make it compliant, you just activate IP anonymization, which you had to do anyway, out of common sense and because tracking by IP without consent was illegal anyway in countries like Germany. [1] https://support.google.com/analytics/answer/276…

That GA feature does NOT provide any useful anonymity, and I doubt it meet the requirements of the GDPR.

re the aip=1 feature: https://news.ycombinator.com/item?id=17167346

why masking the least interesting byte isn't anonymous: https://news.ycombinator.com/item?id=17170468

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#136
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

> I don’t understand why the Chrome team is picking this hill to die on Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this. > I really expect this change to push a lot of people away from chrome Care to bet on that? Because I would happily take the opposite side of that bet. I think th…

But the tech-savvy community has influence. We set up computers for our friends and families. We write IT policies. We are web developers, tech reporters, and more.

At least for me, Google's behavior means that I can no longer recommend Chrome.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#137
post #119

Earlier quoted context omitted.

Lets try the law on this one: Is the IP personal data for the GDPR? If I read the GDPR, the Debian foundation is not capable to pinpoint 1 person so it seems to me it is not (An ISP or someone receiving an IP to person mapping from them is something different): ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can…

Debian also has a privacy policy where they explain what kind of data they log and how long it is retained https://www.debian.org/legal/privacy However, I can't recall ever having seen this privacy policy before now. IANAL and don't know what kind of notice needs to be given for necessary data usage, if any, but maybe apt-get should display the privacy policy on first use.

I meant you're violating GDPR by letting that apache2 server run with its default config, not that the apt maintainers are violating it.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#138
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

Reducing their userbase is exactly their aim. They are doing that the only way possible that won't bat an eye. Firefox has to grow so that chrome is no longer considered a monopoly.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#139
I can see why they thought this was a good change. It makes the UX for G-suite apps much more pleasant, almost like you get the full functionality of G-suite productivity stuff as part of installing Chrome. For most people, that's a good thing.

I think as tech people we systematically tend to under-think the second-order effects of the systems we build. Case in point, Chrome and G-suite being that closely integrated brings up serious privacy concerns, and the part where the Chrome team doesn't seem to appreciate the nuance reflects poorly. I do cybersecurity now (didn't used to), and a good number of problematic things I run into just come from engineers like my previous self not thinking through the security implications of a specific design, mostly because not thinking about security means shinier UX delivered on less resources.

Just another example I encounter regularly: I use U2F to sign into my Google accounts. However, when you log in, the checkbox to "trust this computer" is checked by default, meaning that if you're not paying attention your account will get automatically downgraded to single factor authentication going forward. It's a clear nod to convenience, but done this way it makes you shoot yourself in the foot.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#140
post #35

Earlier quoted context omitted.

I personally know people who think they are signing into Chrome when they sign into google.com. Maybe the Chrome team is right about their larger user base?

The question is, what about other sites? Do they also think they're signing into Chrome when logging into amazon.com? Google services are getting preferential treatment over the rest of the web on a browser with a market share big enough to be subject to an anti trust case. Vestager must be licking her lips right now...

Finally the EU Commission will be able to levy a hefty fine on monopoly abuse and get the money they wanted from Google. Then the GDPR. EU, sucking the funding that was supposed to go towards innovation.
Post reply on HN