Live data from Hacker News

The Many Ways Google Harvests Data

wsj.com

61–70 of 189 posts

Re: The Many Ways Google Harvests Data

#61
post #32
post #5

Earlier quoted context omitted.

> controls that I trust. I think this trust might be misplaced. > Example: Location history. It is turned off by default. Displaying your location history to you is turned off by default. Google's own recording of your location, for their purposes, cannot be turned off.

This is not true.

It is true.

Firstly, I was pointing out one small example of Google's privacy settings being non-obvious, which the GP mentioned in their post. There are many, many others one could go into, but we'll stick with just user location privacy for now.

Also, minor disclaimer: What Google does or doesn't collect varies over time (as their policies and regulation changes, and in response to various court-cases). What they might have done according to one source a certain number of weeks/months ago they might have since stopped doing. But my point is that they cannot be trusted to follow the implied behaviour of high-level settings.

However, since you've refuted my statement, some examples:

1. Google's own terms at [0]

> some information (such as the association of your Google Account to your Google Wifi network) is stored by Google even if all privacy controls are turned off.

This is bundled with Google's tracking of the geographic location of each Wifi network to feed their WiPS/WFPS services.

2. As @lern_to_spell has alluded to, "Location Reporting" and "Location History" are separate settings; the former does allow you to turn off some (though not quite all) location recording for your Android device at least, but the latter setting is still very misleading, and the former setting comes with a sacrifice (some apps become unusable). See [1]

3. Even with all of the above granular settings and admissions in terms, Google still have demonstrated in the past that they cannot be trusted to follow even their own loose promises w.r.t. respecting user privacy. e.g. [2] [3] [4] - note these articles are spread over 3 years, and are about events from 6 years previous; not exactly a promising sign of Google's policies being corrected by the court actions.

- [0] https://support.google.com/wifi/answer/6246642?hl=en

- [1] https://www.howtogeek.com/195647/googles-location-history-is...

- [2] https://www.theguardian.com/technology/2010/may/15/google-ad...

- [3] https://www.wired.com/2012/05/google-wifi-fcc-investigation/

- [4] http://www.bbc.com/news/technology-24047235

Re: The Many Ways Google Harvests Data

#62
post #2

https://duckduckgo.com https://protonmail.com https://apple.com

One of these things is not like the other. DuckDuckGo and Proton were founded on the basis of protecting privacy and not sharing personal data. The other is part of the cabal.

Or is that more marketing? How do we really know what they are doing with our data?

Re: The Many Ways Google Harvests Data

#63

Why is Apple given a pass? They gave all their China user data to the China government so they could stay in China to make a buck. Is that not selling users data? Versus Google chose to leave China instead of handing over the data. https://www.amnesty.org/en/latest/news/2018/03/apple-privacy... Campaign targets Apple over privacy betrayal for Chinese iCloud ...

They make an effort to design their products and services with privacy and security in mind, and are much more transparent about what data is collected and how it's used.

The iCloud-China situation is unfortunate. The situation is very different from Google, both in the opportunity costs, and the fact Apple's products are dependent on China to be manufactured.

Additionally, if you forego iCloud services (namely iCloud backup), then the data that the CCP can access is actually quite limited. All of their phones since the 5s in 2013 have been leaders in security, and if you use a passphrase or 10-digit pin as a passcode then not even the most recent iPhone cracking tools could brute-force your phone (within a dozen years, within a century for 11-digits).

I'm miffed about China, but I still believe Apple is the best option because I don't think there's much that can be done in their position and the impact is limited. For me that would change the instant an actual iOS backdoor is made for any gov't.

Re: The Many Ways Google Harvests Data

#64
post #60
post #39

Earlier quoted context omitted.

They do track it and will prevent logins from unusual locations. Happened to me when using a VPN.

Yes, but not through GPS, or the location information compiled about my logins would be way more accurate than it is (often off by 100-200 km in any direction). Probably IP based geo location (that would naturally trigger with VPNs that give you an IP in $whereever). That has nothing to do with the GPS setting of your phone.

I don't think anyone mentioned anything about GPS until now. We're talking about Google recording your location, which can be inferred from a number of sources, including GPS, WiPS/WFPS, IP, and others. WiPS/WFPS is the most commonly used by Google.

Re: The Many Ways Google Harvests Data

#65
post #14

Earlier quoted context omitted.

One of these things is not like the other. DuckDuckGo and Proton were founded on the basis of protecting privacy and not sharing personal data. The other is part of the cabal.

What makes you believe Apple sells their customer’s data?

Facts? I mean we have.

https://www.amnesty.org/en/latest/news/2018/03/apple-privacy... Campaign targets Apple over privacy betrayal for Chinese iCloud ...

Apple gave up their user data in China so they could make a buck and Google instead chose to leave China instead of giving up the data to make a buck.

Apple it is more data and more money made and therefore believe the largest selling data example we have had in my lifetime? Do you know any examples that are bigger?

This is also actually giving the data instead of targeting an ad.

Re: The Many Ways Google Harvests Data

#66
post #56
post #45

Earlier quoted context omitted.

A more egregious way Google collects data on internet users is through their hosted libraries service. You visit some completely unaffiliated site which happens to use jquery or some other library and instead of hosting it themselves they have a script tag with a src=ajax.googleapis.com/...

For that, see https://developers.google.com/speed/libraries/terms That stuff is kept separate from all account data (like with Google DNS[0] and fonts[1], too): no common cookies, "unauthenticated" (ie. no cross-referencing with Google accounts), logs retain no referrers [0] https://developers.google.com/speed/public-dns/privacy [1] https://developers.google.com/fonts/faq#what_does_using_the_...

I don't read it as stating that the data is kept entirely separate. In fact it references the general privacy policy making it quite clear that whatever data is collected is governed by the same rules as everything else.

Re: The Many Ways Google Harvests Data

#67
post #60
post #39

Earlier quoted context omitted.

They do track it and will prevent logins from unusual locations. Happened to me when using a VPN.

Yes, but not through GPS, or the location information compiled about my logins would be way more accurate than it is (often off by 100-200 km in any direction). Probably IP based geo location (that would naturally trigger with VPNs that give you an IP in $whereever). That has nothing to do with the GPS setting of your phone.

That's picking a nit. GP or whatever said "GPS", but does it matter which technology is used to track your location? Clearly not. And many users say "GPS" to mean all location technologies too, so this doesn't seem like a useful nit to pick, honestly.

Re: The Many Ways Google Harvests Data

#68
post #53
post #45

Earlier quoted context omitted.

A more egregious way Google collects data on internet users is through their hosted libraries service. You visit some completely unaffiliated site which happens to use jquery or some other library and instead of hosting it themselves they have a script tag with a src=ajax.googleapis.com/...

The solution to this is here: https://decentraleyes.org

Pretty cool looking service. Since I've never heard of it, I wish the down voters would explain the problem with it (at the time of writing it's a dark gray, so only a little negative).

Is it simply that people don't seem library CDNs as a source of privacy piercing data?

Re: The Many Ways Google Harvests Data

#69

Haven't read the article because it is behind paywall, but it is not that hard to stay away from Google if you really care for it. Search - Use DuckDuckGo or startpage. Use Fastmail or any other email provider that is not Google. Watch Youtube videos without creating an account and clear out cookies regularly. Use Vimeo or some other service to host your videos for private use. Use Google Translate without a Google A…

You might be able to dislodge yourself from certain datasets, but good luck getting out of all of them. For example: https://www.inc.com/emily-canal/google-credit-card-purchases...

Re: The Many Ways Google Harvests Data

#70
post #56
post #45

Earlier quoted context omitted.

A more egregious way Google collects data on internet users is through their hosted libraries service. You visit some completely unaffiliated site which happens to use jquery or some other library and instead of hosting it themselves they have a script tag with a src=ajax.googleapis.com/...

For that, see https://developers.google.com/speed/libraries/terms That stuff is kept separate from all account data (like with Google DNS[0] and fonts[1], too): no common cookies, "unauthenticated" (ie. no cross-referencing with Google accounts), logs retain no referrers [0] https://developers.google.com/speed/public-dns/privacy [1] https://developers.google.com/fonts/faq#what_does_using_the_...

What's the meaning of the data being kept separate when these databases could be linked with minimal effort (e.g. via IP addresses), for examples at the request of law enforcement (US or other).
Post reply on HN