Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

471–480 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#471
post #452

Earlier quoted context omitted.

I've been using Firefox for quite awhile as my primary browser. I'm now to the point that I only use Chrome for checking websites I'm working on. I've had no complaints about Firefox. For me it is fast and stable.

Does Firefox work with Gooogle Hangouts/Meet/“whatever it’s called now”? I know they were working on removing the need for plugins in other browsers. Ut last time I checked it was still a bit iffy. This is what’s keeping Chrom(e|ium) installed on my machines right now. (I have a customer that uses it extensively). If Hangouts works in Firefox I think I'll uninstall Chrome.

To answer my own question, yes Hangouts does work fine in Firefox. Not tried screen sharing yet but video calls work for me.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#472
post #295
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

I work at Google; opinions are my own. > I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. My impression is that this is the new norm at Google. It happens with everything, internal or external. The sad rea…

Thanks for that insight, it makes sense.

Big corporations usually pick some good rule of thumb (use data based decisions) and pervert it until it's a blind rule.

Now I can see some understand some of Google bad decisions, sentiment and grudges aren't easy to measure. I can find some aspect of a google product annoying but not bother me much. Still, annoying thinks add up and most users, like 99,9% users don't write complains publicly so they can't never tell. It's also harder to account for network effects like the family geek stop caring about chrome and moved the whole family and friends to firefox.

An estimated negative impact in 0,1% can really mean last push for 1% of users. Add several episodes like this and you can destroy a company.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#473

I can see why they thought this was a good change. It makes the UX for G-suite apps much more pleasant, almost like you get the full functionality of G-suite productivity stuff as part of installing Chrome. For most people, that's a good thing. I think as tech people we systematically tend to under-think the second-order effects of the systems we build. Case in point, Chrome and G-suite being that closely integrated…

> your account will get automatically downgraded to single factor authentication going forward. *your device If someone has access to my desktop PC, they also have access to my yubikey anyway.

Yubikey still saves you from a PC malware but I would suggest anyone not to store your yubikey besides your computer (or laptop bag) but to attach to your phone/keychain so it's on you all the time since it's safer that way.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#474
post #222
post #214

Earlier quoted context omitted.

I don't think that using this incident as a recruitment pitch is a good idea.

"Somebody should do a better job!" "Why don't you try yourself?" Seems like a somewhat reasonable train of thought. A lot of good things can come out of outrage, as long as people are willing to take action (no, I don't claim going through Google recruitment to be the optimal strategy, but it is an option)(I actually got my first job as a result of my technical complaints, obviously not in Google).

Even if any of us was lucky enough to be hired, we'd still have to follow what the leads say and not rip out every bit of intrusion and data gathering in chrome (harder than I can imagine) less we get reassigned or sacked. I bet there are plenty of devs there who already have their reservations but for obvious reasons not publicly vocal about it or had their views dismissed for again obvious reasons.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#475

Earlier quoted context omitted.

Except this doesn't actually "prevent surprises in a shared device scenario" for the web, in general; it does for Google sites and services only. Logging in to Facebook or Amazon or my personal blog does not show up as a browser indicator, nor does logging out of the browser also log one out of Facebook or Amazon or my personal blog. This makes Chrome less of a browser and more of gateway to Google services that happ…

Yes, but as I said, most people probably do consider it a single gateway to all of their Google services, browser included. The big difference is that your Chrome account is your Google account, unlike any of the other sites you mention.

> The big difference is that your Chrome account is your Google account, unlike any of the other sites you mention.

Then Chrome should be just a Google Services Client app. It shouldn't pretend to be a browser. It shouldn't allow one to log into "any of the other sites", in the first place.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#476
post #119

Earlier quoted context omitted.

Debian also has a privacy policy where they explain what kind of data they log and how long it is retained https://www.debian.org/legal/privacy However, I can't recall ever having seen this privacy policy before now. IANAL and don't know what kind of notice needs to be given for necessary data usage, if any, but maybe apt-get should display the privacy policy on first use.

I meant you're violating GDPR by letting that apache2 server run with its default config, not that the apt maintainers are violating it.

And I meant you're not violating GDPR by letting apache2 run with default config, as the GDPR allows you to capture these IP adresses for 2 different reasons.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#477
post #374

Earlier quoted context omitted.

It's about privacy and also about taking away functionality that worked all these years for me. At work we use Google Apps and I sign in as with my work address for Gmail, Calendar, Docs, Drive, etc. and am used to one click access to all these apps. But I like to sync my bookmarks, extensions and settings to my personal account - and that's it - I don't want to sign in to my personal Gmail, Docs, Drive in the browse…

Just. use. Firefox.

Be sure to turn off telemetry. Also, the other elements that can send browsing data to google, which are fortunately customizable in firefox.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#478
post #395
post #344

Earlier quoted context omitted.

It's not the case though. Google's privacy policy has two different "modes" for Chrome, one for being logged in and one for being logged out. By tricking people into logging in without their consent they are also tricking people into allowing that extra data to be collected. Their current argument is that they aren't actually collecting that data- just getting permission to- but that's kind of sketchy and still leave…

You're misreading the privacy policy. Google's privacy policy has two modes, one for sync on, and one for sync off. Logging into Chrome does not turn sync on, so you can be logged into Chrome and still covered by the "basic" privacy policy. They aren't actually collecting that data because you haven't turned sync on.

Yeah, well, but what keeps them from silently changing that, seeing that users are already logged in? The UI for the sync preferences is sketchy at best as it is right now and you're basically just one misclick away from handing all your browsing data over to Google.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#479

Earlier quoted context omitted.

> your account will get automatically downgraded to single factor authentication going forward. *your device If someone has access to my desktop PC, they also have access to my yubikey anyway.

Yubikey still saves you from a PC malware but I would suggest anyone not to store your yubikey besides your computer (or laptop bag) but to attach to your phone/keychain so it's on you all the time since it's safer that way.

If someone breaks into my apartment, I have more problems than losing my Yubikey. And my threat scope does not include agencies that would get my passwords AND be able to break in and steal my key. And if it did, I would think they could just take it from me.
Post reply on HN