Ruin My Search History
ruinmysearchhistory.com
ruinmysearchhistory.com
['how to appear funny', 'why are my thumbs uneven', 'am i lack toast and tolerant', 'your youre difference', 'why doesnt my poo float', 'midget google images', 'tall midgets??', 'homemade lube?', 'i hate my boss', 'what counts as fat', 'how to tell partner they fat', 'is it normal to still love my ex', 'how to get back with ex', 'penis remove dog how to', 'romantic ways to propose', 'engagement rings', 'sex shop in my city', 'how to tell if partner cheating', 'ways to kill someone hypothetically', 'undetectable poisons', 'how to delete search history in browser', 'ashley madison hack', 'view ashley madison list', 'ashley madison list my city', 'paternity test', 'mail order paternity test', 'attracted to mother why', 'is incest illegal in this country', 'latest laws incest', 'seduction guide', 'rohypnol safe dosage', 'smelly penis cure urgent', 'common STIs', 'STI test in my city', 'average penis size this country', 'do penis pumps work', 'best budget penis pumps', 'does liking men mean im gay', 'signs of being gay', 'how to come out as gay to dad', 'age of consent here', 'why is age of consent so old here', 'country low age of consent', 'flights philippines', 'isis application form', 'how to join isis', 'cheap syria flights from here', 'syria hotels with pool', 'bing', 'donald trump', 'OH COME ON DONT JUST COPY AND PASTE THE LIST FROM THE ARRAY YOU CHEEKY SCAMP']"
I live in the UK so I expect the police to knock tomorrow.
1) Go to https://history.google.com/history/
2) Select the offending searches
3) Click delete on the top right (then click delete again)
If the roles were reversed would you delete? Or would you just like and say you did?
I can happily endorse the company's public statements on this subject: personal data will be deleted within the timeframes specified (for obvious technical and that's-a-bad-idea reasons, it's not instant). Part of SRE's function is to arrange for SLAs to be met, including deletion SLAs.
Can confirm. Near the end of internships I use my browser history, and mostly the search history contained in that, to figure out what I've done so I don't forget anything in the report. It's a near perfect way to tell what I've been up to any day.
[citation required]. Google goes through great lengths to make sure that's not the case, both technically with legal defense against overreaching subpoenas.
Edit: grammar
History is important, but the site is called "ruinmysearchhistory.com". I visit websites I know with my normal window, the rest is mostly in incognito and if it's something I want to remember, I'll make sure to include it (i.e: visit it in normal mode, Evernote, Bookmarks, email to myself, etc).
IE has some kind of private browsing option as well, but I don't know what would be the equivalent way to invoke it.
I only googlog in to my association's "shared account" and log out straight away.
Also I mainly use DuckDuckGo and bang !g only when needed.
Privacy actually matter to me...
It can even become rather offensive, IMHO.
I don't always watch videos because I agree with the uploader or audience. I can watch a racist dude rant because it fascinates me, to laugh at them, or because I wanted a reminder that such people actually exist. When the (not logged-in) sidebar with related videos then is filled with more racist trash, I'm like "fine, makes sense. related videos. okay. not clicking, but there they are".
Another time I had been watching videos on my Android phone (afaik the YouTube app doesn't let you be not logged-in) on a subject related to feminism. I don't use the app that often and I can't recall what the clips had been about (but probably nothing very umm "high brow"). So, the next week I open the YouTube app, find a whole bunch of "suggested" videos about apparently people calling radio shows and "guy tells those feminists what's what!" or "this guy's reaction puts feminist in place!" trash. If it had been "related" to a video I had just watched, I'd be like "fine, makes sense". But in this case, whatever I did was a week ago and apparently made Google believe these are my interests. Notice how that's a bit more personal? "related to current video" versus "related to this guy's interests". So I'm really offended and think "fuck you and mind your own business". If your algorithm is that stupid, maybe you just shouldn't use it and don't even for a moment pretend that your prejudiced joke of a "profile" is of me and I don't want to be associated with it. Ugh.
In terms of Google search, the fact it retains context is actually useful most of the time, and the edge cases where it is harmful are easily avoided by countermeasures like logging out, using DuckDuckGo, installing Tor or switching to incognito mode.
And if the ads or results on subjects you're interested in just happen to take a line against what you personally believe on the subject, and instead happen to tout an agenda that benefits the (right-wing/capitalist/US-centric) corporate or political interests of Google and FB and the like, is it still just about improving your life?
With the possibility of a racist American president looming, search results which could signal one's ethnicity become a valid concern.
Google gets my approx location from my IP whether I like it or not, which is really all the targeted results I need.
What else is there? There is so little remaining of the actual web search engine that Google used to be 10-15 years ago, I only ever use it for the typical "local" queries that indeed benefit from knowing what city I'm in.
All the other stuff I need to find on the web, if I were to trust Google it might as well not exist. It used to be that any keyword-combination you could imagine that would (reasonably) appear on some website somewhere, would get you that website, some others and a bunch of spam. Google was good at sorting the spam downwards, but if you wanted, you could browse it (then about 10 years ago they limited this to max 1000 results even if they reported millions).
Today, you get nothing. You get a bunch of results that vaguely match the topic of your keywords. Your search keywords that happen to appear are bolded, but that's just a visual effect now, suggesting they tried looking for all your keywords and this was just the best they could find. Except bullshit because I remember the old web, it was smaller, but it was still incomprehensibly gigantic, and already everything was there, and Google could find it under half a second, with their old tech. (where did all the web go?)
So let's be honest, they're not really looking. It's like an annoying salesman, you enter a shop, ask for a specific thing (which they may or may not have), and the salesman tries to convince you that the thing they want to sell you is the thing you were really looking for.
This is what your "targeted" "suggestions" are doing to you. They're targeted to suggest you that you want that something which they want to show you.
Which is, admittedly, all sorts of useful for "local" searches, which is truly the only thing I use Google "web" search for nowadays. Otherwise it's DuckDuckGo which can send me straight to the websearch that has my answer (discogs, wikipedia, various image search engines..). It's not as good as Google used to be (although back then I had my own tools for the meta searches), but it's also not worse than what Google is now.
oh and I didn't even touch on the part where you said that better targeted relevant ads are less annoying. The idea that ads can be "relevant" comes from the ad networks, but there's no such thing. If it was relevant it'd be a search result. If it requires payment to appear between your results, then either it is less relevant than its paid position would suggest (at the cost of another, by definition more relevant, result), or it actually is relevant and the fact that you seen it only because it was paid for means the engine is not actually doing every simple thing to show you the most relevant results, but actively hiding some. Sure this is a business model, what gets me about it is that Google one day used to be so much better than this and used that credit to build something trashy like this. If they were a new search engine nobody would give it a second look.
http://thefutureisastephenkingnovel.com/badforensics/
You'll note in the search history that the referrer is still there so from a forensics perspective it's known the history was populated via CSRF. That can be bypassed. Google has indicated they aren't going to fix the problem.
>Your searches and browsing activity (paused)
Nice fallback (to just “my city”). It gets the intent across just fine, third-party failure (or client-side blocking) be damned :)
The code driving this is at: http://ruinmysearchhistory.com/ruin.js?1
It uses window.open to run the search:
window.open('https://www.google.com/search?q='+ encodeURI(ruinSearchQuery),'ruinmysearchhistory');
But the second parameter will set a name to the newly open tab. Calling window.open with the same name again will reuse the existing tab:https://developer.mozilla.org/en-US/docs/Web/API/Window/open
So it doesn't actually control the google site but keeps reloading it with new search urls. This may be obvious to everybody, but it did confuse me a little.
I've heard people complain after being subscribed to that subreddit that Amazon's relevance engine becomes unusable for them (and while unsaid, I imagine they can't browse Amazon with anyone else at their computer).
OP, take note. :P
I guess things are hard when you only have a single data-point to base recommendations off.
The reason is hypothesised to be because our brain is actively seeking confirmation of previous decisions.
That said, your case most definitely was because of indiscriminate retargeting. Also I guess the effect I mentioned is more visible for bigger purchases : )
Our systems have detected unusual traffic from your computer network. This page checks to see if it's really you sending the requests, and not a robot. Why did this happen?
IP address: *
Time: 2016-06-10T00:07:58Z
URL: https://www.google.com/search?q=donald%20trump
It appears Google is not too happy with Donald Trump.I've actually found that other search engines are actually better at technical searches than Google is nowadays: once, I was trying to search for Ketmax, a disassembler for DOS that could step both forward and backward in code. It was neat. But I couldn't find it.
No, Google, I don't want drugs; I don't want bikes; and I'm not Vietnamese (?!).
Trying a bunch of alternate search engines in rapid succession, ixquick quickly found a bunch of old FTP server index references: I forgot the "35.zip" on the end, and, in fact, just appending "35" was enough for Google to find it. (I'm not writing the concatenated string here so that I don't alter Google's index of the word.)
The Internet has gotten so big in recent years, and become completely overrun with useless information in triplicate; I can't help but wonder if it's forced Google search to take a more generalized approach to the way they sort and index information, with some loss of precision, in order to deal with the volume of fluff.
I was playing around with syllables a few months ago and discovered that the word "exikyut" appeared to be completely unindexed (except for a couple of junk "letter combination" sites), so I used it to make a few accounts. Then Google suddenly turned up a tweet from 2011 where someone had used my "new" username in conversation years prior. That was weird, being told it didn't exist then being told it did...
So yeah, Google's index is very imprecise. Great at sending you to StackOverflow for 1st year JavaScript questions, but nothing like Code Search used to be.
(Since we're apparently debating grammar in this sub-thread)
"Whoever makes or offers to make an expenditure to any person, either to vote or withhold his vote, or to vote for or against any candidate; and
Whoever solicits, accepts, or receives any such expenditure in consideration of his vote or the withholding of his vote—
Shall be fined under this title or imprisoned not more than one year, or both; and if the violation was willful, shall be fined under this title or imprisoned not more than two years, or both."
a is Spanish Spanish
por is Mexican Spanish
Problem solved.
https://security.googleblog.com/2015/03/maintaining-digital-...
This says Google does use HPKP, but I don't see headers myself. https://calomel.org/http_public_key_pinning_hpkp.html
in the reverse, it could fire the backup mechanism and start showing very generic ads.
While I expected the attempt to be flawed, according to mmastrac's analysis, this is a joke. (And a pretty 'meh' one, at that!)
I also wouldn't run this from an authoritarian country where local officials may not appreciate the joke.
1. There are proper ways to restrict activity without resorting to eavesdropping.
2. If they don't trust you enough to be responsible and use good judgement, you're probably stuck in a dead-end situation anyway.
3. In the more rare scenarios, where you might be operating live-saving or life-threatening equipment, or handling the salaries of many people, and dealing with monentary quantities in the many millions of dollars, guess what? You probably shouldn't be using an ordinary computer, with a web browser connected to the internet to perform those sorts of tasks, within the same operating system environment as ordinary web surfing to begin with.
Call centers, data entry, tier one support.
And I can't quite parse your sentence to know if you're implying that all companies do... (or just that I shouldn't be so naive as to assume none are), but I can see the cert chain for google.com in my browser at ${big_company} and it doesn't seem like I'm being MITM'd.
So again, how could I be MITM'd without being aware of it, given HSTS?
Yes, someone could have snuck in a hacked copy of Chrome Canary that exposes phony cert chain information... but that's not what we were talking about, and I don't think most IT departments have the sophistication required to pull that off.
http://security.stackexchange.com/a/2920
(Note: MITM is just one way companies monitor employees, but by no means the only way. If your company provided your work computer to you, or if they installed anything on your BYOD computer, I would treat everything you do on that computer as cc'ed to your boss by default.)
None of that speaks to HSTS/Pinning... which is the feature meant to protect against this sort of thing. I'm specifically asking about how a company can bypass HSTS/Pinning without modifying my local browser.
Everything I'm reading indicates that's not possible.
>Firefox (and Chrome) disable Pin Validation for Pinned Hosts whose validated certificate chain terminates at a user-defined trust anchor (rather than a built-in trust anchor). This means that for users who imported custom root certificates all pinning violations are ignored.
That last sentence is key. From Wikipedia: some browsers "disable pinning for certificate chains with private root certificates to enable various corporate content inspection scanners and web debugging tools. The RFC 7469 standard also recommends disabling pinning violation reports for such certificate chains."
(all this for Windows, I believe the same is true for OS X, Linux depends on your specific your setup)
Internet Properties -> Content -> Certificates -> Advanced
Certificate pinning, on the other hand, allows a client to refuse to connect to a TLS service that fails to prevent the correct certificate. This is generally a win, however it still doesn't give you what you want.
Firefox and Chromium (including Chrome) browsers will only validate certificate pins if the presented certificate is a public trust anchor (in otherwords, the certificates deployed by the operating system). If the certificate chains to a private trust anchor (a certificate installed by your admin), Firefox and Chromium based browsers will smile, wink, and play along.
So, yes, in theory these technologies could protect you, but the vendors that implemented Public Key Pinning opted to support the enterprise use case instead of protecting users.
That's the enterprise life
So yup this happens. Is it effective though? No, this took me 15 minutes and I wasn't even an employee with months if not years of time on their hands.
All the more reason to do it IMHO :)