Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

141–150 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#141

Earlier quoted context omitted.

There's debate on if it's PII.

If an IP can be tied to a data subject's identity it's PII. If it can't, it's not. This isn't a debate.

So the answer is yes, they are PII. But that doesn't actually answer the question of whether or not collecting them without consent is illegal under the GDPR

> “Processing shall be lawful only if and to the extent that at least one of the following applies: […] (f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”

And

> “The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems, […] by providers of electronic communications networks and services and by providers of security technologies and services, constitutes a legitimate interest of the data controller concerned. This could, for example, include preventing unauthorised access to electronic communications networks and malicious code distribution and stopping ‘denial of service’ attacks and damage to computer and electronic communication systems.”

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#142
post #27

Earlier quoted context omitted.

> I don’t understand why the Chrome team is picking this hill to die on Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this. > I really expect this change to push a lot of people away from chrome Care to bet on that? Because I would happily take the opposite side of that bet. I think th…

> because nobody cares A lot of people do not understand, but we do, we're the techies. It's our job to understand. Don't mistake people not understanding for not caring. Once people understand, they care.

It's the early adopters who breed the late adopters. If we all stop using Chrome, and thus stop recommending it to our friends/co-workers they will stop using it too. I've personally turned dozens of people away from IE towards Chrome. Now I'll turn dozens of people away from Chrome towards Firefox. Also, I'm also IT and I'm now phasing out Chrome on my company workstations and phasing in Firefox. It will take time as it's low on my list of priorities, but every workstation I touch I'll take the time to scrub free from Chrome and setup FF. There's 30x users right there.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#143
post #126

As a Googler with no connection to the Chrome team: I'm pretty sure they made this change in good faith and are shocked people don't like it. Just imagine yourself in their shoes: wouldn't your first instinct be to explain yourself?

Shock and Denial is the first stage in the 7 stages of grief.

The chrome team is clearly in the wrong here, and it will take some time for them to realize that they screwed up and that they need to fix it.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#144

Earlier quoted context omitted.

They may understand it on a superficial level, but do they understand it on a practical one? Everyone "understands" that Facebook collects user data. It's the contextual understanding that makes techies uneasy.

What you're saying is a pretty condescending way to treat other people's opinions. You're essentially questioning whether or not they really understand (complete with scare quotes) if they don't share your opinion. It's not the "contextual understanding" - or any kind of understanding - that makes some techies uneasy. It's their own opinions and personal comfortability with regard to data monetization. Many people un…

Actually, they are questioning whether understanding makes sense, given people are unaware, uninformed.

The answer on all that is advocacy.

They may still not care, and that is fine. At least it is with eyes wide open.

Professionals do that sort of thing. It is consideration, not condescension.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#145
post #118

Earlier quoted context omitted.

Excuse my cynism but the options would be: "Yes / Ask again later"

You're on the right track but it'd probably be a modal popup with "Google is making things better by inventing foo and elevating bar to the height of technology, as part of this change we'll be cloudifying some technical data. [Accept and Continue?]" with a teensy tiny little x in the corner... possibly burying all these in a EULA update.

I’m thinking just a banner along the top of the viewport with “Dismiss” and “Learn more…” buttons. The latter pops up a window with a small gray “More options…” link at the bottom, which invokes a modal with the options “Continue signed in as Alice” and “Manage Profiles…”, the latter of which allows you to disable syncing while simultaneously deleting all your local bookmarks and browser history.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#146
post #4

http://info.iapp.org/dz0uBmdUa20MA00Z5o100E0 redirects to: https://blog.lukaszolejnik.com/am-i-logged-in-or-not-gdpr-ca... Please update the submission URL.

A tracking link from the International Association of Privacy Professionals...

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#147
post #118

Earlier quoted context omitted.

Excuse my cynism but the options would be: "Yes / Ask again later"

You're on the right track but it'd probably be a modal popup with "Google is making things better by inventing foo and elevating bar to the height of technology, as part of this change we'll be cloudifying some technical data. [Accept and Continue?]" with a teensy tiny little x in the corner... possibly burying all these in a EULA update.

Judging by all those post-GDPR popups I frequently receive the text would also contain some text like “by clicking ‘accept’ or ‘X’ you consent to XYZ.”

Theres almost never a true choice.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#148
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

Reducing their userbase is exactly their aim. They are doing that the only way possible that won't bat an eye. Firefox has to grow so that chrome is no longer considered a monopoly.

Well they could start by removing the nag box on their home page asking non-Chrome users to switch to Chrome.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#149
post #126

As a Googler with no connection to the Chrome team: I'm pretty sure they made this change in good faith and are shocked people don't like it. Just imagine yourself in their shoes: wouldn't your first instinct be to explain yourself?

Sure, from more junior engineers. I'd expect senior engineers to know about the value of stopping and listening, first. So far, I don't see any signs of that. The reactions are looking at this as a purely technical issue, and that's only part of the story here.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#150
post #47

Earlier quoted context omitted.

It's bad because it's by default signing you into a service you didn't ask to be signed into, and don't have an easy option of turning this off. Sure, it doesn't automatically sync your browsing history now , but we all know change happens gradually. It's just a "feature" to be enabled later. I've never once signed into chrome in my life (on purpose). I don't want anything synced between browsers, I like to try and l…

What is (or was) the difference between signing in to Gmail in the browser, vs signing in to the browser without sync? (You might feel that this is a tipping point but it's still not a GDPR issue as far as I can tell.)

For one thing they have completely different privacy policies. By signing into the chrome they are automatically forcing people to accept the privacy policy that is far less private than the when people aren't signed in.
Post reply on HN