Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

41–50 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#41
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

[deleted]

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#42
post #6

I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…

> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.

The faux-progressive modern perspective is to consider ostensibly true things as literally true.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#43
post #2

So, it's bad because it doesn't sync your history by default? Even if the UI is confusing, the worst case here is thinking that your data is being synced when it's not. It's like the opposite of a privacy problem.

It's bad because it's by default signing you into a service you didn't ask to be signed into, and don't have an easy option of turning this off.

Sure, it doesn't automatically sync your browsing history now, but we all know change happens gradually. It's just a "feature" to be enabled later.

I've never once signed into chrome in my life (on purpose). I don't want anything synced between browsers, I like to try and limit what gets kept in the cloud, and with this change they've simply just taken the option away from the user.

Yes, I'm sure that I'm in the minority, but I'm taking this opportunity to start switching to Firefox, switching my mail provider, and am hoping to send them a GDPR request to delete all of my data.

It's not necessarily just this issue that made me do it, it's just the tipping point for me that says.. "ok, this company has gotten too big off people's data, and i no longer wish to be a part of feeding that machine"

Just my 2 cents.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#44
post #6

I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…

Yes, every website now asks for consent to "use cookies" because GDPR "requires us to to ask this". These are weasel words, there is absolutely NO NEED to ask for this. The word "cookie" occurs only once in the GDPR directive text, in a list of examples of personally identifiable data, next to "IP address". Yet no site ever asks me for permission to use my ip address, somehow.

The GDPR does have a requirement to ask for consent to do things like tracking my interests/behavior on a site and sending it to marketing data companies for specificly named purposes. I have yet to find the first website that uses plain language when asking for consent, and I can't wait for the first fines to be handed out.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#45
post #6

I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…

> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.

I'm not talking about ethics or business models.

I just say that pretty much every site, device and service out there violates the primary rule of the GDPR. They all store data about their users without the users consent.

One of the main points of the GDPR is that the user has to actively agree to storage of data. Making it very clear that storing can not be the default. Yet when you visit the New York Times today, they tell you:

    By clicking "I Accept" or "X" on this banner,
    or using our site, you consent to the use of
    cookies unless you have disabled them.
In one form or another every site, service and device out there is doing exactly this. Making it the default to store data about the user.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#46
post #15
post #11

Earlier quoted context omitted.

google seems too big to fail. what are you going to do? start searching with yahoo?

More like start searching with DuckDuckGo, use an alternate email service such as Fastmail, Protonmail, etc., and use Firefox. By the way, what's an alternate email service the HN users recommend?

DuckDuckGo doesn't really do it's own indexing, it's essentially just a reskin of Bing search.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#47
post #2

So, it's bad because it doesn't sync your history by default? Even if the UI is confusing, the worst case here is thinking that your data is being synced when it's not. It's like the opposite of a privacy problem.

It's bad because it's by default signing you into a service you didn't ask to be signed into, and don't have an easy option of turning this off. Sure, it doesn't automatically sync your browsing history now , but we all know change happens gradually. It's just a "feature" to be enabled later. I've never once signed into chrome in my life (on purpose). I don't want anything synced between browsers, I like to try and l…

What is (or was) the difference between signing in to Gmail in the browser, vs signing in to the browser without sync?

(You might feel that this is a tipping point but it's still not a GDPR issue as far as I can tell.)

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#48
post #6

I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…

> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.

Don't create the content if you have such poor ethics and imagination that violating people left right and center is the only way you can sustain yourself. How many people even realize the extent and repurcussions of the information you are taking from them?

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#49

Earlier quoted context omitted.

> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.

The faux-progressive modern perspective is to consider ostensibly true things as literally true.

Do you mind dumbing this down a bit for me? What you wrote has gone completely over my head here. What is "faux-progressive modern" and what is the thing being considered true even if it's only "ostensibly true"?
Post reply on HN