Live data from Hacker News

Massive spying on users of Google's Chrome shows new security weakness

reuters.com

261–270 of 270 posts

Re: Massive spying on users of Google's Chrome shows new security weakness

#261
post #260

Earlier quoted context omitted.

I disclosed that in the comment this user was commenting in response to, before they commented. In other words, they accused me of shilling in reply to a comment where I openly and willingly clarified my relationship with Google. It is possible to ask someone to, or disclose for someone, a conflict of interest, without breaking the HN guidelines. The comment did neither.

Do you work primarily on ads or DoubleClick at Google? Would you stake your own reputation on this tracking ID not being using in any behavioral, group or user tracking algorithm at DoubleClick or any other ad system at Google?

You've overdone it in this thread and now you're breaking the site guidelines, which explicitly ask you not to cross-examine other users.

We're here for curious conversation. Please don't harangue.

https://news.ycombinator.com/newsguidelines.html

Re: Massive spying on users of Google's Chrome shows new security weakness

#262
post #259

Earlier quoted context omitted.

> If Google can't keep things quiet, where can I find a rough list of factors DoubleClick uses in order to track users? Do you mean like, categories into which it divides users (age, gender, interest), in which case a reasonable answer is https://adssettings.google.com/ or do you mean what request attributes it uses to make these determinations initially and tie them to particular users? In which case the answer is p…

>How can something be a factor in ad targeting without being used to target individuals? Really weird question. Easy. The tracking ID sent to DoubleClick could be used to target groups of people, such as "people who rarely update their browser". Such heuristics can indicate age, tech knowledge, etc. No other browser is doing this. Why does Google need to send such tracking information to DoubleClick? You cannot justi…

> The tracking ID sent to DoubleClick could be used to target groups of people, such as "people who rarely update their browser".

The hash sent to the various google websites when you make requests to them is determined by chrome/chromium on the client side, at approximately installation time. So this would require the RNG thats sitting in a publicly auditable source repository to be flawed and abusable in such a way that chrome could bias the hash based on various system attributes that we're just going to assume for the sake of argument are correlated with various ad demographics.

> Shifting the goalposts to "well we don't abuse it" is classic gaslighting.

I never shifted the goalposts. You just did. Please don't accuse me of gaslighting you when you're the one changing your argument.

> Why should I trust an advertising network with a hard-coded, impossible to disable, opaque tracking backdoor in the first place?

If you don't want to personally, that's fine. But don't presume to get no criticism when you accuse any person or group of actively lying based on literally no evidence.

> No other browser is doing this. Why does Google need to send such tracking information to DoubleClick? You cannot justify it without also explaining why Safari and Firefox don't need this.

There's a difference between "want" and "think it's the best decision". I'm certain there are people at both Apple and Mozilla who would prefer to have more robust client side analytics. I have no doubt about that. But whether they think that's worth the perceived loss of privacy is another question. Right now, Firefox has a comparative advantage with certain types of privacy conscious users. Why throw that away? The increase in development speed may not be worth the loss of user trust. And that's okay, but using that to then imply that Google is lying about things, again based on no evidence.

Let me put it this way: I trust Google (obviously), and so I'm fine to take them at their word that they aren't using this for ad targeting.

Someone who didn't trust Google could reasonably say "I don't put much faith in Google's press release", but without any other evidence that there's actually any targeting happening, the most you could reasonably say is that they might be.

You're taking an even more extreme position that given the opportunity to do a nefarious thing, Google must be doing it. Despite other reasonable explanations existing. This is a weird position to take and I don't get it.

Re: Massive spying on users of Google's Chrome shows new security weakness

#263
post #261
post #260

Earlier quoted context omitted.

Do you work primarily on ads or DoubleClick at Google? Would you stake your own reputation on this tracking ID not being using in any behavioral, group or user tracking algorithm at DoubleClick or any other ad system at Google?

You've overdone it in this thread and now you're breaking the site guidelines, which explicitly ask you not to cross-examine other users. We're here for curious conversation. Please don't harangue. https://news.ycombinator.com/newsguidelines.html

The OP explicitly invited questions about conflict of interest, which I took to mean beyond his employer (which he already established). I also didn't accuse him nor do I believe he is a "shill". I disagree with this characterization based upon the parent comment but I'll stop as asked.

Re: Massive spying on users of Google's Chrome shows new security weakness

#264
post #263
post #261

Earlier quoted context omitted.

You've overdone it in this thread and now you're breaking the site guidelines, which explicitly ask you not to cross-examine other users. We're here for curious conversation. Please don't harangue. https://news.ycombinator.com/newsguidelines.html

The OP explicitly invited questions about conflict of interest, which I took to mean beyond his employer (which he already established). I also didn't accuse him nor do I believe he is a "shill". I disagree with this characterization based upon the parent comment but I'll stop as asked.

It's possible that I misread things because I didn't see the entire thread. If so, I'm sorry. It's unfortunately a hazard because we can't come close to reading all the comments, and certainly not as closely as I (or at least my conscience) would like.

Re: Massive spying on users of Google's Chrome shows new security weakness

#265
post #138

Earlier quoted context omitted.

I feel like this argument is the same as ‘how third party apps are allowed in windows and macOS by Microsoft and Apple’ To me there has always been a trusted part of computing which is audited to some extent and marked as trusted. Browser extensions work the same way as software on an operating system. If they blocked all extensions outside trusted ones they would be criticised as well. However the auditing process i…

In 2016 we proved that the owner of "Web of Trust" was exfiltrating and illegally selling clickstream data to anyone who would pay. For Germany alone the data contained the browing information of more than three million people, often revealing highly intimate and sensitive details about their lives. Still, Chrome and Firefox reinstated the extension after less than four weeks, and to this day it keeps collecting clic…

Keep in mind that almost everything that is free is because you will be its product.

Re: Massive spying on users of Google's Chrome shows new security weakness

#266
post #263
post #261

Earlier quoted context omitted.

You've overdone it in this thread and now you're breaking the site guidelines, which explicitly ask you not to cross-examine other users. We're here for curious conversation. Please don't harangue. https://news.ycombinator.com/newsguidelines.html

The OP explicitly invited questions about conflict of interest, which I took to mean beyond his employer (which he already established). I also didn't accuse him nor do I believe he is a "shill". I disagree with this characterization based upon the parent comment but I'll stop as asked.

> The OP explicitly invited questions about conflict of interest,

FWIW, I don't think I did, at least not intentionally. I certainly disclosed mine, but it's not clear that that's intentionally inviting more questions.

That said, to your first question, no I don't work on chrome, or ads or anything related, and I don't proclaim to have any particular insider knowledge thereof (if anything, the opposite).

To your second question, while I'd prefer to be able to answer you, responding to that kind of question is the kind of thing that I believe could put me in hot water, whether my answer was a "yes" or "no". Ultimately while I think the risk of answering is small, so is the perceived value (I don't think a "yes" would change your opinion, and a "no" would just embolden you), and it's mostly moot anyway since, again, I'm not working off of any particular knowledge beyond Google's already public statements.

I'll add that I originally had a bit more in this response, but I removed it because I don't think it would be used as anything but an additional way to attack me and my character, which is unfortunate.

Re: Massive spying on users of Google's Chrome shows new security weakness

#267

Earlier quoted context omitted.

These are strong words. Mozilla is miles ahead of chrome with recommended extensions [1]: > Recommended extensions undergo full code review by staff security experts to provide a strong additional security check. It has a list of blocked addons [2]. And I believe that is Chrome who turned addons into Wild West, Mozilla had a long review process [3]. [1] https://blog.mozilla.org/firefox/firefox-recommended-extensi...…

It's still so easy in Firefox to install add-ons that spy on your entire browser session and send tons of telemetry data to a backend (Ghostery is a popular example) while the user has no clue that any kind of data transfer even happens. Such behavior shouldn't be something that can be turned on with two clicks.

>Ghostery is a popular example

I'm a little confused. I used to use ghostery (don't anymore), but there was always an option to have them not collect data. This is even a recommended app! I went to their privacy policy to check

> II. Basis to Collect and Use Personal Data There is no obligation on your part to provide your Personal Data. However, if you do, we have a legitimate interest to collect and use it, namely so we can provide products or services, or complete a transaction with you.

> III. Notion of Personal Data Personal Data means any information concerning the personal or material circumstances of an identified or identifiable individual such as name and age. Non-personal data are all data that cannot be used to identify an individual, such as statistics about usage of a website.

Re: Massive spying on users of Google's Chrome shows new security weakness

#268
post #245
post #205

Earlier quoted context omitted.

I wonder if EFF or somebody could issue a "verified" badge that apps could apply for, with a small fee to finance the devs doing the audits?

A prerequisite of that type of badge that I really wish existed is a standardized, interoperable protocol for curation . Instead of trying to solve the problem of malicious software with a walled garden app store, anyone should be able to publish their own curated list of software (or any type of project?). The core component is a crypto-signed statement like: { "curator": { name="Alice", pubkey="...", url="..." }, "…

Would this verification feature be similar to how keybase works? You post a "fingerprint" message to a host of public web sites (ie. Twitter, Facebook, GitHub Gist, etc.) that anyone use to verify your identity. The idea is that even if someone tried to impersonate you, they would have to take over all of your accounts in order to do so.

I like this idea and think it would be a great addition to the development world.

Re: Massive spying on users of Google's Chrome shows new security weakness

#269
post #263

Earlier quoted context omitted.

The OP explicitly invited questions about conflict of interest, which I took to mean beyond his employer (which he already established). I also didn't accuse him nor do I believe he is a "shill". I disagree with this characterization based upon the parent comment but I'll stop as asked.

> The OP explicitly invited questions about conflict of interest, FWIW, I don't think I did, at least not intentionally. I certainly disclosed mine, but it's not clear that that's intentionally inviting more questions. That said, to your first question, no I don't work on chrome, or ads or anything related, and I don't proclaim to have any particular insider knowledge thereof (if anything, the opposite). To your seco…

This thread is tired at this point and I don't think we're going to get anywhere, but the reason I asked is because I was trying to imply that just because you work for Google that doesn't mean you necessarily have knowledge of how data is used in other departments, and I suspect Google isn't a moral singularity from my perspective (meaning some departments really care about user privacy and security and others are far more 'open-minded' with data).

I never attacked your character, and I don't think you're a shill at all -- nor would I ever use any of your posts against you except in the spirit of genuine debate. Not everyone is a vengeful ideologue. Work anywhere you want.

Re: Massive spying on users of Google's Chrome shows new security weakness

#270

Earlier quoted context omitted.

Why I specified "fixed URLs", to close that loophole

My fixed URLs are example.com/0 and example.com/1; I'm going to load them a lot, sometimes in different sequences.

So restrict it even further: extension manifest lists URLs, contents of which shall be made available to the extension, but keep the browser in control of when to fetch, with an enforced minimum cache lifetime.
Post reply on HN