Live data from Hacker News

Massive spying on users of Google's Chrome shows new security weakness

reuters.com

51–60 of 270 posts

Re: Massive spying on users of Google's Chrome shows new security weakness

#51

The other side of this is the many complaints in HN threads about restrictions on what extensions can do and which ones are allowed. I can't say whether chrome's extension library strikes the right balance, but I think it's a difficult tradeoff.

Instead of just outright limiting extensions you could give users the choice. Give us an option to make it impossible for extensions to send out data for example.

I do notice that almost all of the extensions I use have no need to make http requests nor modify the dom (e.g. to add tracking or css url()). I wonder what other methods there are to exfiltrate info beyond that.

Re: Massive spying on users of Google's Chrome shows new security weakness

#52
post #31

Earlier quoted context omitted.

Chromium, but they're effectively the same. The average user doesn't know what Chromium is. https://chromium.googlesource.com/chromium/src/+/e51dcb0c148...

I see, thanks. I'm looking at that source and confused what it's actually doing though. What is the "tracking" aspect? I see ShouldAppendHeaders() returns true on doubleclick.net, but on the face of it, it seems to just be saying: "Should we send experimental headers to this URL? If it's doubleclick.net, then yes." But they claim [1] this X-Client-Data header is used for experimenting with Chrome, not for tracking. B…

Because the statement is deliberately ambiguous, and doesn't say they do not use it for tracking.

"The X-Client-Data header is used to help Chrome test new features before rolling them out to all users. The information included in this header reflects the variations, or new feature trials, in which an installation of Chrome is currently enrolled. This information helps us measure server-side metrics for large groups of installations; it is not used to identify or track individual users."

Okay, so they're saying it is not currently being used to track individual users.

This means they can:

- Track individual users in the future.

- Track devices at any time, for differentiation of individual profiles.

- Track installs at any time.

- Derive information about the individual using this data (for example how often they update their browser, how often they use that device etc)

All of those things are extremely valuable from a data standpoint.

Unless Google explicitly stated that it was not being used to track, differentiate or profile users or devices and will not be used for that purpose in the future, it's extremely suspicious.

Most ad networks collect bulk information from browsers to fingerprint devices and users. Google has a step up on the competitor networks because they own the browser.

Do not forget Google was sued just this month for tracking users while they were using incognito mode.

Re: Massive spying on users of Google's Chrome shows new security weakness

#54

What extensions do you primarily use on Chrome (if you do)? My list (on brave) includes: >uBlock Origin >Decentraleyes >Stylus

Stylus is the only one I had installed in Brave at the time you asked.

I have several in Chrome but the thing is I no longer really use Chrome for general browsing. Chrome has been relegated to development activity; I isolate developer tools to that browser and leave them out of my day-to-day browser (Brave.) It's a nice arrangement really.

Decentraleyes is interesting. Thanks for pointing that out.

Re: Massive spying on users of Google's Chrome shows new security weakness

#55

Is Chromium safe to use, or at least safe to use as packaged with Ubuntu's snaps? I know, I know, snaps are a difficult topic on their own, but my point is that, if Chrome's (and Edge's AFAIK) general hunger for data is a generally accepted fact at this point, then wouldn't employers/enterprises advising to use Chrome in their corporate networks not put themselves under risk of being sued for gross neglect in case cu…

"It's Google. Everyone uses it. The defence rests."

No-one gets fired for choosing IBM.

Re: Massive spying on users of Google's Chrome shows new security weakness

#56

What extensions do you primarily use on Chrome (if you do)? My list (on brave) includes: >uBlock Origin >Decentraleyes >Stylus

> I don't care about cookies

You can hide all cookies popups with uBlock Origin and the annoyances filter.

Re: Massive spying on users of Google's Chrome shows new security weakness

#57
post #24

Earlier quoted context omitted.

Wow talk about revisionism! Chrome was meant as a hedge against IE and lesser so against Firefox. Microsoft owned the desktop with Windows and could easily shut Google out. See the reason surrounding the creation of the Google toolbar. Similarly Android is a hedge against IOS and mobile search.

IE had bad standards support and bad defaults, while Chrome will actively track you on practically every site by sending an identifier to a whitelist including DoubleClick. Would you be defending it if it was called "DoubleClick Browser"? Google wants to secure the status quo with their own browser. What is the status quo? Massive spying, surveillance and tracking. This is why Safari and Firefox implemented strict me…

DoubleClick is owned by google. Seems reasonable enough that its one of the run experiments domains.

Re: Massive spying on users of Google's Chrome shows new security weakness

#58
post #36

There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…

Why is this business model usually from Israel?

Israel is in a state of permanent war, and they can't even trust their traditional allies. It's in their best interests to invest heavily in traditional and cyber warfare, and try to be a step ahead the rest in terms of intelligence.

Re: Massive spying on users of Google's Chrome shows new security weakness

#59
post #41
post #36

Earlier quoted context omitted.

Why is this business model usually from Israel?

Because historically Israel heavy uses blackmail as a foreign policy tool.

Argentinian here, can confirm. Just look up Nisman death AMIA bombing.

Re: Massive spying on users of Google's Chrome shows new security weakness

#60
post #33

Earlier quoted context omitted.

This would make sense if they needed to collect that information organically, but there's already requests made to Google as soon as Chrome launches. So, no, it's not required for analytics. [1] That leaves... ad tracking. Chrome will send a tracking ID to DoubleClick with every request to that host. Doesn't this prove that Chrome is a trojan horse used for ads and tracking purposes? [1] https://twitter.com/jonathans…

> This would make sense if they needed to collect that information organically, but there's already requests made to Google as soon as Chrome launches. So, no, it's not required for analytics. Wait what? You don't think there's analytics that can be done about the browser itself? Let's say chrome ships a new experiment, that when enabled on certain devices uses 100% of the CPU until chrome is closed. Analytics sent o…

Let me put it another way. Do you think the average user knows of or would approve of Google Chrome itself sending information to an advertising network that could be used to track their behaviors and identity?

Do you think this "feature" is adequately disclosed to customers downloading Google Chrome, that it includes a DoubleClick tracking backdoor that no other ad network or website receives.

Post reply on HN