Google – My Activity
myactivity.google.com
myactivity.google.com
One example - have you ever noticed how Google Maps has barely any street names any more? And the streets that are named are random tiny side streets, no matter how far you zoom in or out. It's because it's designed to be used in Directions mode with location services enabled, and only in Directions mode with location services enabled. You don't need street names if you're a dot following a blue line. Just coincidentally, this is the mode where they get full information about your journey.
If you don't provide a source for this, I'm going to call bullshit.
Screenshot of desktop Google Maps without sign-in: http://prnt.sc/d4j744
Screenshot of Android Google Maps without sign-in: http://prnt.sc/d4jwdy
Both look full of street names to me.
https://www.justinobeirne.com/essay/what-happened-to-google-...
it was on HN a few months ago
(Disclosure: I work for Google, on unrelated stuff.)
Google Maps has the whole download area features[0]. If you have an area downloaded, you can see the entire area rendered at (any/most?) zoom levels, see street names, and even get directions.
As for information density, it seems to be a choice of the Google Maps team to show less data at various zoom levels. That has little to do with talking to their online services and more about how the maps team wants to present data to their users.
[0] https://support.google.com/maps/answer/6291838?co=GENIE.Plat...
Just how long will it take for google to ask you to long it to do all those useful things that it does? Ability to escape googles panopticon is one of the reasons it's important to support OpenStreetMap https://donate.openstreetmap.org/
You prefetch the list of locations in the area of interest (there won't be that many compared to the humongous amounts of space Google apps consume already), you keep your user's "personality matrix" synchronized, and then when user asks, e.g., for a restaurant nearby, you display them from off-line cache, sorted by distance, characteristics and by how well they match user's personality matrix.
It would be that simple, if it was about actually suggesting places. But it isn't. It's about suggesting places that pay for advertising and successfully billing them, while also collecting as much data about the users as possible. It's a common occurrence on mobile (and also increasingly common in hardware and desktop software) - things that don't need to be on-line are put on the Internet nevertheless, to facilitate a specific business model.
I run tech for a few websites, and we could design for the "no JS" user, there are likely MINOR changes needed for much better support, but it's simply not something that we consider at all. I imagine it's similar with Google, they're designing for the logged in user, with maybe automated testing on the logged out user.
I wrote more on this and how to disable it here: https://unop.uk/on-google-maps-geotagging-and-privacy
Edit: looks like they have pushed out at least two new on-by-default features since I wrote this (not that long ago); 'photo view count opportunities' and 'new and popular places'.
I still think that this is unexpected behaviour. It belongs in the camera app, not the maps app. The expectation is that apps are sand-boxed and separate from each other.
I have anecdotal evidence from friends who don't normally care about issues like this. Yet they felt compelled enough to pro-actively share this with comments similar to "NO GOOGLE!", which suggests it's not just me.
Since you don't pay for most Google services, I doubt you could recover any damages.
They would lose credibility, which would make them lose (a lot of) money indirectly.
It's probably just for their Location History thing. Which I actually really enjoy using, since I can see all of my past days and where I went. It's pretty neat.
I've been using this feature for so long I assume it's opt-in (I don't remember), but I fully recommend it to anyone that has an inkling of a thought that they _might_ want it later, since you can always delete[4] your location history if you decide you don't.
It's also really cool if you go on a lot of trips or take a lot of photos, because it'll map them out in a timeline view of where/when you took them throughout the day[5].
[1] http://i.imgur.com/gWzMgUp.png [2] http://i.imgur.com/Eq7IGnK.png [3] http://i.imgur.com/HEeZupJ.png [4] https://support.google.com/accounts/answer/3118687?hl=en [5] http://i.imgur.com/dF5TI3q.png
Get rid of your toys before your toys get rid of you.
Your phone becomes basically a giant google-keylogger, with geo capabilities.
Worth donating to OSM if you use it: https://donate.openstreetmap.org
Also, you cant know how much Apple stores about you.
However, I don't use a VPN or spoof my User Agent. Google 100% knows who I am without using any fancy tricks. I've wondered -- wouldn't I be better off logging in everywhere, with my Google privacy settings flipped to maximum? While it's certainly possible for them to map my fingerprint back to my account(s) and opt-out preferences, I think that's a bit much to expect for them. I might be shooting myself in the foot by always being logged out!
> the wording made it sounds creepy, like they can keep
> track of where I am whenever they have it, not just the
> destinations I ask for navigation to
This is actually the case, as far as I can tell. Check it out for yourself by going to Google Maps (doesn't matter if it's the web client or the app), open the hamburger menu from the button in the search box, then click "My Timeline". From there enter any date (in the app, first click the calendar icon) and it'll show you where Google knows your phone was at on that date.No local / device only search history is a joke.
But place suggestion is just ads, and unless they've improved it, not even for places that are open. Who needs that?
Edit: Also I've found it useful to check actual driving times for commuting and other trips. "Last tuesday I left home at 08:35 and took the tram and it took me 17 minutes."
I would love to data mine what Google has on me. I'm sure I'll get a copy someday. Almost everything on the internet eventually is released via acquisitions, subpoenas, hackers, etc...
"We will not combine DoubleClick cookie information with personally identifiable information unless we have your opt-in consent."
So you can't really expect them to be able to cough up the contents of profile 0x3f47d0387acb94857 when asked for the history of your account, if they are forbidden from joining the two domains together.
You should read this and reconsider. From the article: "The change is enabled by default for new Google accounts. Existing users were prompted to opt-in to the change this summer." https://www.propublica.org/article/google-has-quietly-droppe...
Maybe they've just not got enough data on you?
Your comment makes me assume you are very young or you work at Google. I don't mean that snarky, but your comment is a very different response than the rest of this thread.
I'm late 20s and I don't have any affiliation with Google.
It is nice because I can go back to 10 years ago and see what I searched, essentially taking me back to that time and loads of memories come back. "Why was I searching for cheat for this game? Oh yeah because this was the summer when I was playing with person X, Y and Z while doing A, B and C".
It's just kinda.. nice.
Sure, you can acquire this info via some other means, but that would mean someone else having it.
It would continue to be backed up on Google's servers.
1. The snooping doesn't buy much ad placement benefit. That from Roberto Bayardo, Google advertising engineer.
2. The idea is not to cram ads down people's throughts all the time, but to not skeeve people off so much that you're not wwhere they go for purchase recommendations. If that means services which are mostly privacy-aware but that this means that you're where maps or shopping or search queries happen, that's a win.
A counter might be that Google's primary aim now isn't ads but AI and training data. I still think that not annoying or alarming people is preferable. Some data are better than no data, or intentionally distorted data, or massive regulatory burden.
Short answer: because privacy-promoting would be the better business choice.
Are you saying Google should drop Maps, Gmail, Drive and all the rest because they are not valuable from a business perspective? Their business is ads after all (today at least).
Which means that when I am open to suggestion I am on other services.
By not maximising the short-term ad-impressions (or other short-term) metric, Google increases odds of being there when people are interested in its money-maker: quality suggestions for commercial goods and services.
They've lost me. I suspect they'll lose others.
>>> By not maximising the short-term ad-impressions (or other short-term) metric, Google increases odds of being there when people are interested in its money-maker: quality suggestions for commercial goods and services
Google is already 18 yo, they are clearly not playing the short term game.
And they are offering quality suggestions for commercial goods and services. People are arguing whether or not they collect too much data for said services, but I haven't heard anyone complain that their ads are obtrusive. Including yourself.
I do not want to do that in my off time.
I know "do it locally" is often repeated here, but do you really expect a local solution to be able to get this kind of information and keep it safe, secure, and constantly working for this long? And how much time, money, and effort should you spend maintaining such a solution?
I have data in my Google account going back 10 years! That's impressive as hell!
Personally I actually do track some "hourly" data, maybe 2-3 hours in total to set it up and it's running for 2-3 years. I suppose you could add some time to run it through some encryption software and put it in Dropbox without too much of a hassle.
And, as people get older and their biological memory starts to suffer, this sort of external memory jogging feature will only get more and more useful, I suspect.
However the UI is a bit awkward for that usage. It seems to definitely be designed more for the average user who is using it exclusively for history deletion, like the activity log on facebook. The default grouping of entries makes deleting them in chunks easy but scanning through them hard. The UI also makes it easy to spot what site an entry is for at a glance but chooses not to show the url despite having plenty of space to.
I think it's because I block ip addresses, that track your data, on the laptop.
Accessing Your Personal Information
How can I see what information a body or company holds about me? Under Section 3 of the Data Protection Acts, you have a right to find out, free of charge, if a person (an individual or an organisation) holds information about you. You also have a right to be given a description of the information and to be told the purpose(s) for holding your information.
You must make the request in writing. The person must send you the information within 21 days.
Under Section 4 of the Data Protection Acts, 1988 and 2003, you have a right to obtain a copy, clearly explained, of any information relating to you kept on computer or in a structured manual filing system or intended for such a system by any entity or organisation. All you need to do is write to the organisation or entity concerned and ask for it under the Data Protection Acts. Your request could read as follows:
Dear ... I wish to make an access request under Section 4 of the Data Protection Acts 1988 and 2003 for a copy of any information you keep about me, on computer or in manual form in relation to.... (Fill in as much information as possible to assist the organisations to locate the data that you are interested in accessing e.g. customer account number, staff number, or PPS number (if you are writing to a public sector organisation such as the Revenue Commissioners or the Department of Social Protection)).
Do you know of anyone that has previously requested access to their info? I'd be extremely curious of what the response looks like (even if it had to be anonimized to protect the requester's privacy).
That's because you used Google Maps to track your location history (which, at least when I first discovered the feature, had to be manually enabled), then took pictures which you uploaded to Google Photos. As a HN user, I'm sure you know that images often have location metadata. Google simply connected the two bits of information you provided to them by using their services.
Honestly, of all things that google does, this is probably the least creepy.
I thought it was a carefully formed bit of magic. It looks like I make it easy for them.
If I could do any one useful thing with this data, is recommend people I can connect with who are domain experts in the things I search for. Like if there's a Vagrant/Chef wizard with a fairly prolific web presence, I'd like to know about them.
Even more interesting, I now disabled the Youtube activities there, but the new things I've watched and searched after the change are still showing up in Youtube's history (but not on the myactivity page, thankfully).
Google, you of all can do better.
Does this not work for you? You can delete by any time range, for any service.
>Sie können ganz einfach einzelne Einträge oder ganze Themenbereiche löschen. Außerdem können Sie in den Einstellungen festlegen, welche Daten mit Ihrem Konto verknüpft werden sollen.
In two out of three occurrences I read "Sie" as "They" )) Fun!
Web & App Activity
Voice & Audio Activity
YouTube Watch History
YouTube Search History
Perfect!
Has anyone in this company actual had an encounter with a REAL person not a Google employee in the past few years?
I only use Chrome for development.
Best of both worlds.
[0]: https://support.mozilla.org/en-US/kb/how-does-phishing-and-m...
What Firefox does, is that it downloads a complete list of hashes from Google's Safebrowsing server. Every instance of Firefox does this every 30 minutes. Nothing identifying about this.
Firefox then stores only the first 32 bits of those hashes to save on space (as the list is unsurprisingly gigantic). Then Firefox does a lookup against this locally stored list whenever it loads a webpage. If a webpage's first 32 bits should be on that list, then it obviously has to check if it's actually the complete hash that matches. But for that, it requests all hashes with same first 32 bits from Mozilla's server. They proxy the list for that purpose.
So, it's at best Mozilla which can guess that you browsed to one of the many pages that share the first 32 bits of the hash. Google will have no clue about it.
And in fact, they even throw in a few noise entries when requesting the full hashes from their server, so even Mozilla actually doesn't know for sure which first 32 bits you browsed to.
https://feeding.cloud.geek.nz/posts/how-safe-browsing-works-...
Let's say you are interested in knowing which people watch a lot of cat videos. And let's pretend these people don't want to publicly share with everybody that they like cat videos. To find these people, you simply start a Google Ad campaign targeted at people who like cat videos. But the ad will be for an unrelated product, for example, coffee pads. Now every time somebody clicks on your ad and perhaps orders your coffee pads, you know that this person likes cat videos.
Ergo, your data is not compeletely safe with Google and it can leak, contrary to what they make us believe.
In your hypothetical, Cat lovers who want to keep that information private can remove 'Pets & Animals - Pets - Cats' from their account targeting. Now they won't see the coffee pad ads.
And no, coffee pad advertisers can't target you based on your pornography viewing habits, HSV cream purchases, or any number of slippery slope examples.
Also, the topic "Cat videos" does not appear, so I have to create it myself? How do I know if Google matches e.g. "Cat" with "Cat videos"?
Further, my other interests may correlate with being a cat video fan, so I have to blank them out as well. But how do I know which they are?
Sorry, but this solution is clearly broken.
(Btw, how does Facebook handle this?)
If you think a topic is correlated with one you want to keep private, then you can also keep that topic private by removing it as well. It's well within your own judgement and control, so no, it's not broken.
Facebook lets you do exactly the same thing: https://www.facebook.com/ads/preferences/
"Ads you see may still be based on your general location (such as city or county) or recent searches"
Hence, broken.
Also, how about AdWords? As far as I know, you can link any search term (even a competitor's name) to any type of ad you want.
You're thinking of keyword advertising, not display. AdWords can do both display and keyword advertising, the latter of which is different. Advertisers don't see demographic information about who clicks on their search ads because they can can only target by keywords, so your theory of leaky data doesn't apply there either.
That's also the second time you've moved the goal posts as you've learned more about how online advertising works. Kind of reminds me of this: https://en.wikipedia.org/wiki/No_true_Scotsman
Emphasis is on "recent searches", not on the location.
> They can can only target by keywords, so your theory of leaky data doesn't apply there either
Yes, you are more right here (and here only). If ads are only shown when you are actively searching for their keywords, then whether there is a leak is questionable. But an advertiser could still trick one to reveal information, like in a phishing attack, by using keywords unrelated to the ad.
> That's also the second time you've moved the goal posts as you've learned more about how online advertising works.
Thanks for educating me, but my argument still stands. In fact that second time, I placed the goal post back at its original place, since apparently, Google's ad controls do not allow one to turn off ads based on recent searches.
Google will also never tell you what they've inferred about you, what ads have been tailored for you, and why. Their real gold is still hidden.
I'm pretty sure Google has plenty of users willing to share their data that they wouldn't risk the legal and political shitstorm that would come out of secretly storing data about you...
The models are very complex and often not something that can be meaningfully represented, especially when you're a data point inside a neural network.
I have no idea why I'm being downvoted... anyone who has done any machine learning can attest to these basic facts, not to mention I've worked at Google.
If you are worried because they are making "hidden associations" from this data, my question would be how to display that? How would they possibly show you all of the assumptions, associations, interpretations, and calculations they did, do, or will gather from your data?
If you are going to fault them for not displaying that data, shouldn't it be possible to display it in the first place?
Existing models can be depicted in a wide variety of ways. They could either be the results of previous decisions (description through action), they could be expressed as is should the model be more human-readable (e.g. text clusters), they could be visualized somewhat directly [1], or they could visualized indirectly [2].
"My activity" seems like a nice idea, but the execution ends up providing little value to few people. If the idea is transparency over Google's personal data on you (how they framed it in an email to me), it does a poor job. If the idea is a better understanding of yourself (quantified life), it does a poor job. If the idea is finding some youtube video you watched recently, then it's mediocre depending on how long ago it was. In what scenario is it some spectacular & useful product?