Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

281–290 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#281
post #93

Earlier quoted context omitted.

I personally know people who think they are signing into Chrome when they sign into google.com. Maybe the Chrome team is right about their larger user base?

They could support both use cases by popping up a dialog on sign-in to a Google web property: "You're signing into Gmail. Would you like to link Chrome to joebloggs@gmail.com? This will enable automatic notifications in Gmail, sync passwords and web history, and also automatically log into other Google websites when you visit them". "Yes / No / No, and don't ask again"

Yeah, except:

> This will enable automatic notifications in Gmail

> sync passwords and web history

Chrome 69 does not enable either of these things just by signing into Gmail. (Sync being a separate opt-in has been well discussed. I just tested notifications on a new profile: they're not automatically enabled, and if I try to enable them in Gmail settings, I still get the usual browser permissions dialog.)

> and also automatically log into other Google websites when you visit them.

...and this one would happen regardless of any browser involvement.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#282
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

"I don't understand why the Chrome team is picking this hill to die on"

Years of double digit percentage revenue growth sets lofty stockholder expectations.

All the low lying fruit to sustain that trajectory is gone. So, anything (AMP, this, etc) that might boost their targeting ability or impressions is important for them.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#283

Earlier quoted context omitted.

I expect this is the case... I know I myself was thinking a few months ago why Chrome doesn't have the ability to keep the logins in sync. However, why in the world did they enable this by default for people who didn't want their browser to do anything with their Google accounts? It would make sense to keep them in sync when users request to connect their browsers to their accounts, but not when people don't want the…

Because almost every user in the world wants it connected.

I've been in at least 2 corporate positions where there were strong reasons to separate your personal environment and your professional environment.

I do not want synced browsers between my two environments.

This change makes it inordinately difficult to maintain that separation while utilizing other parts of the google ecosystem.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#284
post #118

Earlier quoted context omitted.

You're on the right track but it'd probably be a modal popup with "Google is making things better by inventing foo and elevating bar to the height of technology, as part of this change we'll be cloudifying some technical data. [Accept and Continue?]" with a teensy tiny little x in the corner... possibly burying all these in a EULA update.

I’m thinking just a banner along the top of the viewport with “Dismiss” and “Learn more…” buttons. The latter pops up a window with a small gray “More options…” link at the bottom, which invokes a modal with the options “Continue signed in as Alice” and “Manage Profiles…”, the latter of which allows you to disable syncing while simultaneously deleting all your local bookmarks and browser history.

These last couple of comments were probably some exaggerating pun... But after this story I was running privacy checkup, surprisingly found that my location history was on (after turning it off several times long before, which is a separate question why it turns on), turned it off again and then got 404 when trying to delete it. All this in a labyrinth of often circular links without much clue where the actual switch is.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#286
post #182

Earlier quoted context omitted.

This is some real Orwellian stuff here. First off, since it applies to people logged out of Chrome and it forces them to log in it increases, not decreases, the chances of someone accidentally leaving their account available to others on the machine. Since the sync button no longer requires a password this means someone can log in at a library to check their email, walk away, and someone else can step up, hit the syn…

Just anecdotally since I used to manage the computers at a public library, we did have time software that would reset the computers back to a clean state after they either were done and clicked "end session" or they left it unattended for a minute. I'm still against this Chrome change for the same reasons, but I would hope other libraries do the same thing as we did. From my experience library tech people are usually…

> but I would hope other libraries do the same thing as we did

In my experience, 9 out of 10 libraries, copy shops and internet cafés don't do this [properly].

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#287

Earlier quoted context omitted.

Nobody really cares outside this tech bubble. There won't be a PR fiasco, because it's hard to explain why it's bad for a non techie end user. "Google simplifies the login experience in Chrome", is essentially what's happening here and it's far from obvious how to sell it as a doomsday scenario as I read the mood correctly of many HN users.

Maybe I'm just crazy, but if I didn't like Google Chrome (or if I was a privacy hawk), I wouldn't use Google products. Why do so many people complain about "privacy" and still use Google products? The people who think they can speak for their parents or the less technically inclined are being too presumptuous in my opinion. YOU may have a problem with these methods, but not everyone does. Heck, there's people as tech…

Super technical person who doesn't care, reporting in.

But I also wish we lived in a utopian society where all information, people, companies, govt. was public and there was no weird illusion of privacy that everyone is clamoring for.

I long accepted privacy on the internet doesn't exist, and mostly privacy off the internet is minimal, especially with all the technology around. If you want privacy, you need to live like the Amish.

So, I just accepted it, and now don't care about privacy breaches, giving all my data to google. I willingly give more data to google so they can make my life easier.

I get hopefully 100 years on this planet, I am not going to worry about privacy when I got better things to use my limited time and energy on.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#288
Google search is great. The rest of stuff and all the tracking and personalisation crap is just ridiculous.

stuff like this are the primary reasons I:

1) use Chrome only for work - hey, it's new IE

2) don't use Android

and recommend against using these to all my friends and family, carefully explaining everytime that if they care about their data they should stay away from these services.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#289
post #182

Earlier quoted context omitted.

I also work at Google though have nothing to do with Chrome. This isn't "clear" to me. There are certainly complaints about this change within HN, but there are also people here saying that they appreciate the change, or that they're ambivalent. But the more important part of things is that HN has what, maybe 10000 active users? Chrome has over a billion. Even if every HN commenter was vehemently against this change,…

This is some real Orwellian stuff here. First off, since it applies to people logged out of Chrome and it forces them to log in it increases, not decreases, the chances of someone accidentally leaving their account available to others on the machine. Since the sync button no longer requires a password this means someone can log in at a library to check their email, walk away, and someone else can step up, hit the syn…

> First off, since it applies to people logged out of Chrome and it forces them to log in it increases, not decreases, the chances of someone accidentally leaving their account available to others on the machine.

Before, if you were logged into both Chrome and Gmail, you could log out of one and forget to log out of the other. Now, logging out of a Google site also logs you out of Chrome.

> Since the sync button no longer requires a password this means someone can log in at a library to check their email, walk away, and someone else can step up, hit the sync button, and steal all of their information.

If you have access to someone's email account, you can already steal quite a lot of information.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#290

Earlier quoted context omitted.

I sort of want Google to go further with this change, and simply have a "Sign in to Chrome, Google Sites, Amazon, and everything else" button. In fact, it could also sign you in to local applications like Photoshop and Word. They could call it the 'logon screen'.

I'm assuming you're joking. But you can use Chromebooks if you want to remove the separate OS layer for simpler uses.

Yes, it's a joke. The problem of multi-user devices has already been solved, and in a manner that works for all applications and sites, not just Google's.

In other words, the given motivation for this change rings hollow.

Post reply on HN