Live data from Hacker News

Google’s GDPR Workaround

brave.com

91–100 of 629 posts

Re: Google’s GDPR Workaround

#91
post #8

It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android. Then the Go modules proxy issue around the Go Programming language that raised suspicions about tracking usage statistics around downloading modules turned on by default without any consent and now this. I think there are some folks at Google who ha…

10 years ago you'd be called a privacy lunatic when you said that website owners who used google analytics were just selling their users' data to Google. Same reflexion about those using ad scripts.

Re: Google’s GDPR Workaround

#92
post #11

Snippets from the article: > The evidence further reveals that Google allowed [...] > Google has no control over what happens to these data once broadcast [...] Is it possible that Google does have "control" over the data after broadcast, albeit legal control via contracts with advertisers (as opposed to technical control)? Perhaps Google's GDPR compliance strategy relies on the participating advertisers to comply wi…

The article doesn’t appear to claim that the author has been tracked in violation of the GDPR, only that the described mechanism makes it technologically feasible to do so.

Indeed. I fully admit I’d need to sit down and diagram some of Brave’s claims, but the large identifier screams “cryptographic entropy” to me.

The GDPR has separate rules that effectively deal with whether you are the business with which the customer works or one of their contractors. I could imagine a world where google is the second party and needs a secure feature like this so the first party can perform (consented) tracking across multiple domains they own. This is just a devils advocate argument since I can’t guess intent.

Re: Google’s GDPR Workaround

#93
post #5

This some great work on tracking down all of these measures to track users. I really hope we get to the point where dumb ads rules the web once more. Hopefully this results in more than a slap on the wrist, but I doubt it.

Why should ads rule the web at all? Surely the cleverest engineers to walk the planet can come up with a new way of making money that doesn’t involve psychological manipulation.

Re: Google’s GDPR Workaround

#94

>I was branded as a 'privacy nut' Companies do actually employ shills to go on forums and try to sway public opinion. They call them something like public advocates, doesn't change the idea though.

I used to wonder if this was the case. Would you have any idea how their performance is measured by their employers?

Re: Google’s GDPR Workaround

#95
post #22
post #6

Earlier quoted context omitted.

And I'm very annoyed that your initial reaction to reading this article is to blame the GDPR instead of blaming Google for these shady practices. Boycott that crap, move to other services. This shouldn't be acceptable. I'm very happy that the GDPR exist, if only because it forced all these websites from explicitly giving me a list of the literally hundreds of partners they want to share my data with, along with a way…

- my initial reaction is to blame GDPR, yes, because it's just security theater that does so little to actually ensure privacy. Sure Google is at fault but GDPR was supposed to regulate this and it is clearly failing to do so. And if you want to boycott it you're welcome to but they've built an empire with their cloud, search, email, etc to the point where that would be pretty difficult and annoying to the average co…

Your reality differs violently from mine.

We're not four years into the GDPR becoming enforceable (it was just last year), and certainly not enough time to see real action for complex cases - regulators and courts move slowly.

Startups barely ever asked for consent, and collect way more data than you imply - including, as you mention, by using Google Analytics.

The GDPR requires zero banners and checkboxes if you are not processing data.

Re: Google’s GDPR Workaround

#96
post #37
post #17

Earlier quoted context omitted.

The Go module hash checking seems to be more about avoiding the problems encountered by other language repos integrity and versioning issues ( cough NPM), and in terms of tracking it seems about as invasive as Debian's popcon. Enabled by default can and should be the default for security-related features. I tend to agree about the rest of the creepiness, especially anything personally behavioral.

Debian's popcon is not enabled by default.

Debian's popcon is really irritating because Debian actually uses it as a source of evidence... systematically eliminating those of us who keep it off for privacy/security reasons.

Re: Google’s GDPR Workaround

#97
post #37
post #17

Earlier quoted context omitted.

The Go module hash checking seems to be more about avoiding the problems encountered by other language repos integrity and versioning issues ( cough NPM), and in terms of tracking it seems about as invasive as Debian's popcon. Enabled by default can and should be the default for security-related features. I tend to agree about the rest of the creepiness, especially anything personally behavioral.

Debian's popcon is not enabled by default.

It isn't, but it's installed by default, and I'm always amused when I get to that installation step. "Do you want to tell us about your system?" answer no "installing popularity-contest"

Re: Google’s GDPR Workaround

#98
post #90
post #8

It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android. Then the Go modules proxy issue around the Go Programming language that raised suspicions about tracking usage statistics around downloading modules turned on by default without any consent and now this. I think there are some folks at Google who ha…

"You know, that PATRIOT act really allows spying on everyone" "Come on that's just paranoia" Snowden leaks secret program that implements everything details in the patriot act. "WHO COULD HAVE SUSPECTED?"

If I remember right, after the leaks the faux-sophisticated take was "well of course, everyone knew this was going on, are you naive?".

Re: Google’s GDPR Workaround

#99

Earlier quoted context omitted.

That's the revenue, not profit.

That's also the point. Profit shouldn't have anything to do with fines. Redress and compensation should. A fine is supposed to make business-as-usual unpalatable.

Sure, I'm just pointing it out because "earnings" usually means "profit".

Re: Google’s GDPR Workaround

#100
post #13

What is sad is that the EU commission doesn't take real action against Google. At best we are to expect a slap in the hand, at worst, the investigations will drag on and nothing will happen.

Executives commit crimes and the company pays the fine. This way crimes are not prevented.
Post reply on HN