Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

241–250 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#241
post #143

Earlier quoted context omitted.

Shock and Denial is the first stage in the 7 stages of grief. The chrome team is clearly in the wrong here, and it will take some time for them to realize that they screwed up and that they need to fix it.

I also work at Google though have nothing to do with Chrome. This isn't "clear" to me. There are certainly complaints about this change within HN, but there are also people here saying that they appreciate the change, or that they're ambivalent. But the more important part of things is that HN has what, maybe 10000 active users? Chrome has over a billion. Even if every HN commenter was vehemently against this change,…

> But the more important part of things is that HN has what, maybe 10000 active users? Chrome has over a billion. Even if every HN commenter was vehemently against this change, that's less than 1% of 1% of Chrome's user base. If this change makes the browser better (using whatever metric you want, I'd argue the correct one here is privacy), even marginally, for the average user, at the cost of a few people believing that the browser is behaving badly, that seems like an overall good change, doesn't it?

Well what percentage of those billion users understands what's going on, versus the 10000 users here? Google's business model does depend on duping people who don't know any better, so maybe this isn't so surprising..

In any case, I don't think there'd be so much uproar if Google hadn't snuck the change in without telling anybody. There are release notes, why not use them? Why is that so hard to understand for a company that prides itself on hiring the best and brightest?

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#242

Earlier quoted context omitted.

> I don’t understand why the Chrome team is picking this hill to die on Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this. > I really expect this change to push a lot of people away from chrome Care to bet on that? Because I would happily take the opposite side of that bet. I think th…

I'm typically out of touch with normal people so I'm probably proving your point, but this has pushed me off chrome and Google. Ive always loved google. Installed chrome when it was released. I'm writing this from a pixel 2 XL because I broke my pixel 1 XL. I've had a Gmail account almost since it's been possible (I have my firstnamelastname@gmail.com). I now use firefox. I don't know what mail I'll switch to, and I…

I had the same mindset as yours perhaps a year or two ago, until I realized a couple of things that completely changed my mind. This is a little off the main topic but you see, when it comes to privacy, we like to think that we have it in our control but in fact we don't. As Snowden has proven, what the NSA is doing is far worse than Google. You just don't know it because it's completely hidden and sealed off from the public. But why do they have to conduct such extreme level of data mining you ask? Well, we are not living in manufacturing age anymore, that was maybe 40-50 years ago, we are living in an information age now. Everybody agrees that information is the new oil or the new currency. For the United States to continue being the leader of the world, it would be absolutely foolish for anyone to think that they don't have a complete and total full control of this key component.

The public needs to start changing their mindsets and begins to accept that all information in your private life is being recorded. The only important aspect that needs to be questioned is to what extend the data is going to be used. Are some companies not going to hire you simply because of something you did in your private life three years ago that they may not agree with? That would be unacceptable to me as it would definitely cross the line. It is what I consider similar to the "social credit" system being implemented in China, in which everyone is under surveillance at all times and given scores for activities such as grocery shopping. There are always two sides of the extremes, and the balance we should strive for is somewhere in the middle.

It's impossible to ask U.S companies like Google not to conduct data mining on their users. How do you expect them to compete with companies in other countries that monitor their users 24/7 and have access to larger and more accurate data? In the age of information and artificial intelligent, those companies will win the battles simply because they will have better insights that Google won't ever have. Companies in the West cannot readily admit what they're doing because the public mindset is not yet ready for this change. It's too drastic and against many values we have been familiar with our entire life. But our world is changing very quickly, it is not the same world as before, it's understandably very difficult for most people to wrap their head around this but we need to update our mindsets even if that means changing our values. Companies like Google cannot disclose what they do because of public backlash they will receive. If people are just going to switch to another company, all their investments will have been lost, and the next company will be forced to do the same anyway. Google's recent move was probably the best way to test out public water, and it is already not looking very good. I don't know if governments from the West will ever be able to crack this issue.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#243
post #205

Earlier quoted context omitted.

The Chrome team has been shocked about a lot lately. I give them the benefit of the doubt on their intentions (although I'm less sure about upper management). But regardless of their intentions, they need to get better at thinking ahead. Situations like this are always a little complicated, so I don't want to oversimplify or claim that they should have been psychic. But... it really shouldn't have been hard to tell t…

There is a process where external launches need to be approved by a separate privacy team. If you're certain you can do a better job, you can find some listings on https://careers.google.com/ (just search for privacy).

Or you know a better option would be to use a competitors product.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#244
post #196

Earlier quoted context omitted.

They did it by ironic accident. Bill Gates wanted their browser to be the best, but also wanted it not good enough to replace desktop apps. However the right hand didn't know what the left hand was doing. The Outlook team was told to make a web version. They got the IE team to add XMLHttpRequest for their use, everyone implemented what they needed to, then went home and forgot about it. Then Google recognized what th…

This origin story of XMLHttpRequest being an afterthought explains why the class name has inconsistent capitalization which interestingly enough I never noticed until now.

Many style guides for CamelCase recommend not writing acronyms in all caps past a certain length.

It's possible that Microsoft's style guide at the time set three characters as the limit.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#245
What I find troubling about this incident is not so much the change itself, or even how quietly they did it. It's the doubling down when users became critical. Rather than a "Okay wow, we clearly misunderstood the impact of this change and regret pushing the change without proper announcement or informed consent. We'll work to fix this." the messaging feels much more like "You're wrong to be upset. Trust us."

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#246
post #222
post #214

Earlier quoted context omitted.

I don't think that using this incident as a recruitment pitch is a good idea.

"Somebody should do a better job!" "Why don't you try yourself?" Seems like a somewhat reasonable train of thought. A lot of good things can come out of outrage, as long as people are willing to take action (no, I don't claim going through Google recruitment to be the optimal strategy, but it is an option)(I actually got my first job as a result of my technical complaints, obviously not in Google).

"How about you do it then?" works in volunteer situations where anyone can step up. That's not the Chrome team at Google.

Unless you are actually offering a job at Google, it's not a reasonable train of thought, it's a (somewhat pissy) cop-out.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#247

I see many people here complaining about this feature, and while I completely agree with them I also find it difficult to imagine an effective way to clearly explain these concerns to a random average user with limited to no knowledge of computers. How would you go in explaining this stuff if you wanted to convince somebody to switch to another browser?

I would say that I hate this change. I have a university education in computer science, have worked with computers for many years, but don't understand what my browser is doing any more. The UI is unclear, the privacy policy says one thing, and the project manager says something else on Twitter.

It really frustrates me when applications try to guess what I want, and do things without asking. Computers are fun and interesting because they do what you tell them to do! When they do what someone think 90% of people want without asking you, they are oppressive and depressing.

Lastly, it feels like Google wants to trick me into giving them my browsing history by mistake.

So, all in all, I'll uninstall chrome from my personal computer.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#248
post #5

Please, Google, fix those mistakes soon, and avoid a PR fiasco.

Nobody really cares outside this tech bubble. There won't be a PR fiasco, because it's hard to explain why it's bad for a non techie end user. "Google simplifies the login experience in Chrome", is essentially what's happening here and it's far from obvious how to sell it as a doomsday scenario as I read the mood correctly of many HN users.

Everything has an adoption curve, when Chrome launched why would the average user use it? But eventually it went through the adoption curve and even with Google aggressive nagging too time to gain mainstream traction.

The same thing is happening with surveillance and spyware and the self serving 'users don't care' that many tech apologists use to distract from their stalking and lack of ethics is already out of touch and disconnected from increasing mainstream awareness and disgust with surveillance.

Just yesterday Craig Newmark announced a $20 million donation to a new publication modelled on propublica to examine tech surveillance. It's only a matter of time before surveillance implementors and apologists begin to look like the sellouts that they are in the public eye.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#249
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

Because a lot of it is FUD.

I've never signed into Chrome, but I am able to access 2 Google accounts... and Chrome still shows me the "Sign into Chrome" option.

Version 69.0.3497.100 (Official Build) (64-bit)

(I normally just use Chrome for development)

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#250
post #222
post #214

Earlier quoted context omitted.

I don't think that using this incident as a recruitment pitch is a good idea.

"Somebody should do a better job!" "Why don't you try yourself?" Seems like a somewhat reasonable train of thought. A lot of good things can come out of outrage, as long as people are willing to take action (no, I don't claim going through Google recruitment to be the optimal strategy, but it is an option)(I actually got my first job as a result of my technical complaints, obviously not in Google).

> "Somebody should do a better job!" "Why don't you try yourself?"

This argument makes sense when you're talking about a problem that one or two people control rather than a large system with higher stakeholders who may not have interests aligned with your own.

But I'll assume you're right for a sec. Let's assume that Google cares a ton about making sure their privacy policy is consistent, but it's just an insanely hard job and nobody could do any better.

Why does that matter? In that scenario, I still don't trust your privacy policy. I don't care whether it's inconsistent because people are incompetent or because the problem is hard. In either case, the privacy policy is unreliable. If I can't trust it in Chrome's case, how can I trust it in Gmail's case, or in Adword's case, or in any other product?

In a way, saying it's a hard problem is even worse. I would have felt better if you had come back and said, "oh, the Chrome team is just uniquely incompetent, but everybody else has got their stuff together."

Post reply on HN