It's not that you're not allowed to worry about google holding your data (of course it is!), but it's pretty unsafe to be on the 'net without being properly patched.
If I had to set about this, I would have an upstream fork of Chromium that would patch the various networking functions to blacklist known google domains, and then offer a flag to ignore the blacklist in the "obvious" spots (like when you go to google.com). Probably not perfect, but a bit safer.
If you're super serious, you could just 404 all access to google.
I haven't updated Chrome in quite a while. My computer's been running just fine. I'm pretty sure I would've died if I'd tried to cross highways as you mentioned all this time. So I think something about the comparison doesn't smell right.
The relative odds aren't quite right, but consider how many people you might know who lost their PCs to virii, compared to people compromised by their Google searches.... Maybe it's a wash ;)
I think your likelyhood of getting your PC messed up is pretty dependant on habits too. You're much more likely to get hit by drive-by adware if you're (on Windows and) going to those random illegal streaming sites to watch some show than if you're reading HN.
An example: I was on a less than stellar video hosting site, and a bunch of pop-ups got me to accidentally download "FlashPlayer.dmg"
I'm pretty well versed in this stuff! And they got me to download this right as I was going to watch this video. If I didn't know better, it would have been like all those other plugin updaters (of course you need root to install flash right?)
Of course, updated Chrome didn't prevent this case for me...
Indeed...
> You're much more likely to get hit by drive-by adware if you're (on Windows
Indeed I am on Windows... without security software, etc.
> and) going to those random illegal streaming sites to watch some show
Indeed I am not...
> than if you're reading HN
Indeed I am...
> An example: I was on a less than stellar video hosting site, and a bunch of pop-ups got me to accidentally download "FlashPlayer.dmg" I'm pretty well versed in this stuff! And they got me to download this right as I was going to watch this video.
Even if you downloaded that, you have to do some extra clicks to make it run. It's not something that I can see happening by accident to the average HN reader.
> If I didn't know better, it would have been like all those other plugin updaters (of course you need root to install flash right?)
But you did know better.
> Of course, updated Chrome didn't prevent this case for me...
Well there you go, I'm out of arguments.
I think you quite beautifully narrowed down where the real problems lie and proved my point, so I'm just going to leave it at that. ;)
On the other hand, looking over CVEs for chrome[0], I'd be a bit worried. Chromes before 47 included remote code execution via the MIDI subsystem! If someone could play a MIDI, they could compromise your system!
Yikes
[0] http://www.cvedetails.com/vulnerability-list/vendor_id-1224/...
Anyway, I came here for a tangent about those "less than stellar video hosting" sites: I have an idea how to kill two birds with one stone - getting rid of them, and fixing the Internet. Can we convince MAFIAA to go after ads on the web? After all, that's what keeps illicit streaming alive.
(Torrents will obviously survive, but at least right now, most people don't know how to use them.)
I'm currently doing work in an office of ~30 people where the IT support company (supposedly accidentally) set up this lovely policy https://i.ytimg.com/vi/rC4FQwYXIok/maxresdefault.jpg which was in place for about a year before I noticed it on a colleague's computer. Pretty terrible security-wise, but no-one's been hit by a car to my knowledge.
What data does Google own?
I mean if we're going to go to this level of paranoid; then we might as well look at attacks on Firefox (which have been suspected to be used by the NSA against Tor Browser).
It's less about being covert, and more about having multiple settings to send different types of data back.
(You can easily check this with an app like Little Snitch, look for the browser connecting to IPs 8.8.8.8 and 8.8.4.4)
I also just noticed that Little Snitch actually does NOT log the dns requests. Maybe this is caused by Chromium using ipv6 to access google-public-dns-a.google.com ?
Anyway, I then installed Vallum (1) and with this app, in the log i see many of these requests: https://i.imgur.com/lUR3Fd7.png
*edit: I'd genuinely be surprised if google made it that easy to not send anything back to them. Additionally, I'd be genuinely surprised if FF made it that simple to avoid sending things back to Mozilla.
Remove physical microphone from your computer, Chome will turn it on randomly and send recordings to Google.
1. While the Hotword module was downloaded at startup, the feature was not activated without the user explicitly enabling it via the settings menu. <https://crbug.com/500922#c6>
2. Downloading the module in Chromium was a bug, and it was fixed after being reported. <https://crbug.com/50922#30>
3. The Hotword feature was dropped from Chrome not too long after, because it was an experiment that never really panned out (and was enabled by very few people).