Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

81–90 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#82
post #23

Well if the EU wanted to make an example, Google just handed it to them.

Hopefully that battle comes sooner than later. Either the EU will fold, or we would get some real guidance about what honoring this GDPR legislation actually means. Clearly nobody has any frigging idea what is and is not in compliance.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#83
post #15
post #11

Earlier quoted context omitted.

google seems too big to fail. what are you going to do? start searching with yahoo?

More like start searching with DuckDuckGo, use an alternate email service such as Fastmail, Protonmail, etc., and use Firefox. By the way, what's an alternate email service the HN users recommend?

I pay for a Posteo account and am quite satisfied with it. The webmail is just your standard run-of-the-mill webmail without any fancy features like Google Inbox, but since IMAP is supported, you can just put whatever frontend you like in front of it.

https://posteo.de/en (I'm not affiliated with them except as a customer)

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#84
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

I think they hired a very, very incompetent person who has been screwing up a lot more than just this since M69. Anyone who has tried the new Chrome OS Beta channel is wishing they hadn't installed this heaping pile of hot garbage. They would be better off reverting all the merges they've taken since M68, just to cut their losses.

I mean no deep offense to the people involved, but the last couple months of Chromium changes are about a hundred times worse than just twiddling their thumbs.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#85
post #16

Earlier quoted context omitted.

> I don’t understand why the Chrome team is picking this hill to die on Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this. > I really expect this change to push a lot of people away from chrome Care to bet on that? Because I would happily take the opposite side of that bet. I think th…

Sad but true. People don't care about this stuff, in general.

Why would they? Who outside our paranoid bubble is doing anything other than being signed into their accounts all the time?

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#86
post #81

This is the second time I've seen the reference to Chrome being the most secure browser. What's that based on?

Exploit prices and complexity usually accurately reflect the security of a product when compared to their competitors. Take a look at how much Zerodium pays for full-chain exploits here: https://zerodium.com/program.html

  $250,000 - Chrome RCE + SBX (Windows) including a sandbox escape (previously: $150,000)
Whereas it's up to $100k for Edge RCE+SBX, $80k for Firefox RCE+SBX

You obviously need to factor in other things such as how popular the product is compared to competitors, etc., but such a drastic price difference such as this is quite telling.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#87
post #52

"apt-get install apache2" violates GDPR (logs IPs). It's not a difficult line to cross at all.

Why would it violate GDPR? Logging IPs, especially short-term, is pretty easy to justify

There's debate on if it's PII.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#88
post #65
post #3

I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilit…

>I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on. link to said threads?

Here's one:

https://twitter.com/__apf__/status/1044109217903198210

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#89

Earlier quoted context omitted.

I personally know people who think they are signing into Chrome when they sign into google.com. Maybe the Chrome team is right about their larger user base?

I expect this is the case... I know I myself was thinking a few months ago why Chrome doesn't have the ability to keep the logins in sync. However, why in the world did they enable this by default for people who didn't want their browser to do anything with their Google accounts? It would make sense to keep them in sync when users request to connect their browsers to their accounts, but not when people don't want the…

Because almost every user in the world wants it connected.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#90
post #27

Earlier quoted context omitted.

> I don’t understand why the Chrome team is picking this hill to die on Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this. > I really expect this change to push a lot of people away from chrome Care to bet on that? Because I would happily take the opposite side of that bet. I think th…

> because nobody cares A lot of people do not understand, but we do, we're the techies. It's our job to understand. Don't mistake people not understanding for not caring. Once people understand, they care.

I understand, and I don't care.
Post reply on HN