Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

431–440 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#431
post #428

Earlier quoted context omitted.

Not sure if this is a solution for you but you can have multiple Google account sessions in separate Chrome user sessions by clicking your user icon at the top then selecting to add people.

It becomes a game of “guess what user I’ll be logged in the next new window ?” Chrome also doesn’t respect window order in the menu, so it’s just a pain to track when switching. My solution to that was to switch to Safari for personal use.

I have like 3 accounts added and it always used default account

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#432
post #304

Earlier quoted context omitted.

Maybe the Chrome team is right about their larger user base? Maybe the Chrome team was wrong to introduce signing in to a browser at all?

> Maybe the Chrome team was wrong to introduce signing in to a browser at all? maybe, but that would mean that all browser vendors did it wrong. (including mozilla)

Safari doesn't do this (it's part of iCloud, which syncs all docs, not just Safari), and Mozilla doesn't tie signing in to website signing in. I do think this is quantitatively different, esp. considering Google's near monopoly on email accounts.

They are tying website login to browser login, with the intent of merging the two - that's the problem.

To users are Google who are fully invested in that corp having total control of their online life, this fuss will seem quaint and odd, but I do think it will have serious implications long term - people are turning away from search too for similar reasons - abuse your monopoly enough and people will actively seek out other options.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#433
post #417

Earlier quoted context omitted.

Yes. Acting evil is what makes you evil.

Then again, maybe we shouldn't be throwing around words like "evil", which we all know is hyperbole (even if invited hyperbole because of Google's own prior statements). Someone talks about Google being evil, and then other people push back because it's not really "evil", and they are both right, so neither ever gives an inch. Sure, there's less impact when statements are less hyperbolic, but there's also less bikesh…

You said it yourself, Google’s raison d’etre in some ways into these markets was that they were not evil anticompetetive Microsoft. Today, they very much are. Arguably they were always this way, but dark patterns like this is a new low.

And no you don’t need to be North Korea to be evil. That is a meaningless comparison. Coincidentally Google has started working with regimes similar to NK; The PRC. Is that not evil?

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#434

Earlier quoted context omitted.

Use checkboxes?

When you have a checkbox for every possible customisation option, you end up with a commercial airliner cockpit - hundreds of flashing lights and switches, that you need a comprehensive manual and years of experience to properly operate.

I wonder if we’re not already at this point though, and it might not be a bad thing.

Not everyone uses a browser the same, but a decent part of people here will spend their working life in the browser. I think for people here it won’t be rare to have dozen of windows with each dozen of tabs, some logged in different acconts within the site they show, some in incognito, some with in developer mode.

Even with just the browser filling multiple windows worth of buttons and stuff to interact with is easy, without even going to hidden preferences and configs.

I’d argue in complexity level we’re already on par with a airliner cockpit, it’s our job to deal with that, and we do it professionaly for years. Of course not everyone needs that complexity, but at least we do.

What I am getting at is, I think we should accept we’re not a t the point where it is simple anymore, embrace the complexity and give tools to effectively manage it.

Airliner cockpit are so because it’s efficient to have individual switches to important action and state indicators. We shouldn’t shy away from showing important info in the interface just because we’d end up with more stuff. Having it hidden can be a worse tradeoff.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#435
post #282
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

"I don't understand why the Chrome team is picking this hill to die on" Years of double digit percentage revenue growth sets lofty stockholder expectations. All the low lying fruit to sustain that trajectory is gone. So, anything (AMP, this, etc) that might boost their targeting ability or impressions is important for them.

This. Google's carrot stick is the privacy yard.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#436

Earlier quoted context omitted.

Yeah...and that thread says that the change is basically nothing, just a UI indicator: > Q: I don’t get, though — if you’re signed in to the browser but sync is off, then what does it mean to be signed in to the browser? What does it do besides sync? > A: Not much, you can think of it like a Gmail login state indicator. If that's fully the case, then there's nothing to see here and people are freaking out over nothin…

@__apf__ is being slightly disingenuous when she says "Not much ... like a Gmail login state indicator." Google logins are used across the web by a lot of sites. For instance here's what happens when you visit an Indian financial paper, the Economic Times, using Chrome 69: https://imgur.com/a/nFvxI0U (some personal info has been blurred out). I almost never visit the Economic Times, and I certainly never log in, but…

It all makes sense if the end goal is for the browser to push google login across the web, and make google accounts the preferred way to log in to websites. In that case they're doing you a favour, it's all in your best interests, as well as Google's of course. [/sarcasm]

I simply don't trust a single corporation that much.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#437
post #295
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

I work at Google; opinions are my own. > I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. My impression is that this is the new norm at Google. It happens with everything, internal or external. The sad rea…

I think that any decision, which impacts user privacy in any way, shape or form should be especially carefully vetted.

Unfortunately, and with a long list of "accidental" blunders Google is long beyond the point of deniable plausability.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#438
post #295
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

I work at Google; opinions are my own. > I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. My impression is that this is the new norm at Google. It happens with everything, internal or external. The sad rea…

I'm glad you're here talking. This is hard to navigate as an employee. A company as large as Google must make it nearly impossible to anticipate every downstream effect it may have on seemingly unrelated areas of the business.

As an example in this case, I am an IT decision maker for a small group of people, I'm not that active on social media as a contributor, and losing an Apps subscription because of a browser auth decision could be one of those impacts. Its likely not, but if it were it would be impossible to understand in the aggregate, and of infinitesimal impact.

Be that as it may, user PII is now on the liability side of the ledger, and some businesses just haven't adapted to start operating like that is reality. Beyond financial hazard, the moral harm of a leak, the risk of telling the secrets of millions to the world (or a dangerous few) should be of grave concern. The best way to be trustworthy is to not know the secrets in the first place.

Bulk data collection doesn't affect 0.1% of users, that is the only group of people that understand enough to be concerned about. It affects everybody who signed up as a user. Their secrets and their safety are now in your hands.

This IS an engineering problem. I have full faith that with the right will, Google could figure out a way to offer web scale services to all manner of users and still deliver on its ambitions to deliver intelligent experiences with provable privacy at the heart of it. It probably involves data living at the edge; it probably involves renting datums from customers; it definitely involves a radical shift in business models.

Engineering a solution to a privacy-at-scale repository of human knowledge cannot happen without leadership that truly sees privacy as profit, at every level of the company.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#439
post #433

Earlier quoted context omitted.

Then again, maybe we shouldn't be throwing around words like "evil", which we all know is hyperbole (even if invited hyperbole because of Google's own prior statements). Someone talks about Google being evil, and then other people push back because it's not really "evil", and they are both right, so neither ever gives an inch. Sure, there's less impact when statements are less hyperbolic, but there's also less bikesh…

You said it yourself, Google’s raison d’etre in some ways into these markets was that they were not evil anticompetetive Microsoft. Today, they very much are. Arguably they were always this way, but dark patterns like this is a new low. And no you don’t need to be North Korea to be evil. That is a meaningless comparison. Coincidentally Google has started working with regimes similar to NK; The PRC. Is that not evil?

> Coincidentally Google has started working with regimes similar to NK; The PRC. Is that not evil?

No, it's not, because evil is a negative ideal, but I don't think it actually exists in reality.

Even Hitler wasn't evil, he was insane, and the whole situation is a case study of what happens when people, regular people, are given an easy explanation for all their problems. Placing something in the category of "evil" is placing it apart from behavior that you expect normal people to be capable of, since I think most people thing the majority aren't evil. All that does is help us feel better at the expense of helping us be better.

Evil is for fairy tales, where things are black and white. Normal people rightly get defensive when called such, because the road to hell actually is paved with good intentions. Hyperbole isn't a useful way to communicate.

Sorry to go full Godwins on this, but if you can't pull out Hitler and Nazi's when talking about evil (even to counter the point), then when can you...

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#440
post #383

Earlier quoted context omitted.

Sorry to disappoint but I’m not American nor do I own any clothing from China (or any other countries that may rely on sweat shops for production). From a security and privacy standpoint though there are possible implications when a tech-product/service is owned/controlled by a Chinese company. China’s influence on it’s businesses (especially tech related) can’t be denied. It wouldn’t surprise me one bit if news woul…

i didnt mean to offend you either, it just seemed like more of a xenophobic than technical argument. apple is lauded for the security and privacy of the iphone but it is manufactured in china. could china have their hands in that "cooking pot"? if there were some kind of subterfuge occurring with opera at the hands of the chinese government, it would be newsworthy indeed.

I don’t even know why I’m still arguing with you but there’s a huge difference between something being assembled in China for a US company and a browser company with its jurisdiction in China. One can be compelled to aid the government the other not so much. You’re comparing two entirely different things here. It’s far easier to manipulate some lines of code than to modify the hardware of thousands of devices.

And I do take offense at being called xenophobic and won’t further participate in this ‘discussion’.

Post reply on HN