Does anybody else know your search history? Besides the NSA, whom I assume have access to all US-hosted data, no. And not even Google knows my most sensitive searches, because my private mode is a Tor Browser connecting to DuckDuckGo, answering for my porn needs mostly.
And I trust Google to keep my data safe more than I trust shady AV companies, because Google has hired a lot of security researchers, at their size all eyes are watching them and their behavior has been acceptable compared with that of others like Facebook.
Information security is all about compartmentalization ;-)
If you have the time, would you mind expanding on why you consider Google's behavior better than Facebook's? I find myself very wary of FB but much less so of Google, but I can't really explain why.
I think Google only better markets its intrusions than Facebook... Something to do with the public sentence "don't be evil". Indeed "evil" is like "common sense": everybody has its own and understands what comforts him/herself. Seems like pure marketing.
Maybe someone has any argument about the reality of this different Google/Facebook privacy intrusion/protection feeling?
Facebook manipulates the emotions of its users: http://www.forbes.com/sites/kashmirhill/2014/06/28/facebook-...
MasterCard to access Facebook user data in order to make you spend more: http://www.theage.com.au/it-pro/business-it/mastercard-to-ac...
Facebook ads use your face for free: http://www.itworld.com/article/2746556/networking-hardware/f...
Facebook is inventing phony likes to promote stories you've never seen to your friends: https://web.archive.org/web/20161215092610/http://www.forbes...
Facebook guesses your race and uses it for targeting: https://arstechnica.com/information-technology/2016/03/faceb...
Facebook has been the main promoter of bogus news and misinformation in 2016: https://www.theguardian.com/technology/2016/sep/09/facebook-...
Facebook has started to collect WhatsApp data, in spite of the app's original policy: https://www.theguardian.com/technology/2016/aug/25/whatsapp-...
Facebook collects the texts that you don't send: https://arstechnica.com/business/2013/12/facebook-collects-c...
Facebook tracks and builds user profiles for people without accounts: https://www.theguardian.com/technology/2015/mar/31/facebook-...
Facebook's privacy settings have been designed with black patterns, making it easy to publish by mistake: https://www.theguardian.com/technology/2016/jun/29/facebook-...
Facebook makes it easy to tell when you're asleep: https://www.washingtonpost.com/news/innovations/wp/2016/02/2...
I used a fake name on FB since the first day I signed up along with a photo of my favorite rock star. About a year ago, someone outed me and FB locked my account and said unless I emailed them a copy of my drivers license or some form of identification that proved who I was, they would keep my account locked.
I thought, "Whatever, I'll just fire up a new one."
This past month I signed up a new account under a very generic name like "John Johnson". No problems. I never uploaded a photo, just connected with the handful of people (less than 5) and felt like, "ok, we're cool now".
Yesterday, I got the same message and now the links you provided make a lot of sense as to why. FB really is after all of your data and essentially force you to give it to them, otherwise they hold your account hostage. Both times, I really felt like my privacy was being stampeded and this was a big intrusion to get at my personal information. No way am I going to give you an identifiable information about me. I already gave up an account I had used more or less for a decade instead of coughing up my personal information and photo.
So yeah, I'm done with FB - not that I was ever a huge fan, but this past week just confirmed what I always suspected.
Have algorithms that detect spam? Let users report on accounts being used to spam other users?
Sure, if I'm someone abusing the system, this should be easy to ferret out without having to surrender all your personal information and identifying markers just to make a SOCIAL MEDIA platform free of spam.
Of course there are some other less intrusive search engines (DuckDuckGo, maybe Qwant), but unfortunately they still are less efficient than Google for fine or rare searches.
But for the average user, until a better Google comes along, I think it's OK to trust Google with their searches. And compartmentalization is paramount to information security, my point being that trusting some other company besides Google with that data is not acceptable, which is why I find that intercepting HTTPS connections is simply wrong and evil, regardless of reasons. This besides the fact that intercepting HTTPS traffic increases the attack surface, making users less secure.
We know Google does what it does. DDG's reason for existence is predicated on not doing so.
If DDG were found to be lying, I'd guess >80% of its customer base would evaporate overnight. It would mean destroying many years of branding, trust and relatively difficult cultivation of user browser defaults.
But that's worth gaming out - what would make it worth it to light all that on fire? About the only thing I can think of is a Lavabit-style conundrum, wherein our intelligence-overlords threaten someone's freedom. So, absolutely could happen, absolutely would come out.
So that's why I trust DDG to be less forthcoming with their logs.
Any tracking that isn't announced to the user is not a cost, but is espionage.
And the "not even anonymous" is not an option: to be able to have a fully functioning phone, I hardly can escape declaring my full details to Google.
And this is clearly an "evil" choice of Google: I never created a Linux, Debian, Ubuntu or Mint account to keep my desktop computer up-to-date and featured by additional apps.
Not because there are no potential issues to discuss around ad-funded free services and data aggregation, but more because it's like clickbait (in that it oversimplifies a complex issue for emotional effect and makes discussion of actual issues more difficult).
Using algorithms to build a general profile in order to increase relevance is not the same as "selling your data". They sell access to your eyeballs in much the same way as a broadcast TV station or free alt-weekly does. The main difference is that by getting some sense of who you are and what you might be interested in, they can decrease (in theory) the amount of irrelevant ads that end up on your screen versus the traditional methods of just blanketing things with general ads or using cruder demographic info.
Lots of companies flat-out do sell your data, either in aggregate and somewhat anonymized or in full. I've not found anything yet that leads me to believe this is how Google runs their advertising business. To this day, my main concern with Google isn't so much with Google as it is with a malicious third party somehow gaining access to the info Google has on me.
That's not the point. The point is there is a dark market trade in your personal identifying data and metadata, with the ultimate goal of knowing everything about you. The more they know about you, the better they can advertise to you.
Advertisements on the Internet are bought and sold algorithmically on high speed marketplaces. Omniscience leads to better decisions in this environment. Therefore your data is precious to whomever owns it.
I totally agree with that part, including the last sentence of your post. However, I don't quite see the difference between "you are the product" and "access to your eyeballs is the product", it's just describing the same thing differently. That others are worse doesn't really change that, the ones who are better are the standard as far as I'm concerned.
As the target of such surveillance and data collection, you just never really know how that data will be used or who by. It's optimistic, to put it mildly, to expect that data will only be used for purposes you don't object to by good people with the best intentions.
Also note that while Homebrew may be open-source, it is not "free software".
I confirm that he is probably right about _____collecting____ data. Yes, this most definitely includes FOSS software. If your qualifier for FOSS is not using GA or anything like that than your are right, however, most of probably still count brew as FOSS. Hope that helps.
There are probably lots of smaller examples; especially in Android.
It connects on-line and off-line searches, so it shows you the result in on-line locations. The underlying assumption was that users increasingly see on-line and off-line content as all part of the same world ("their content").
The commercial aspect was that it connected to places like Amazon. It made money for Canonical by using affiliate links if the user chose to make a purchase.
That is not the same as collecting all the history of the user and (anonymising) then selling that to a third-party or presenting adverts based on that data.
The default is off as users felt searches by default connecting to external services was an invasion of privacy - that's different to "selling searches".
Frankly, this closed-off the last viable manner for desktop Linux to secure a wider revenue stream of sufficient size to drive employing enough full time developers to keep up with the other platforms, in my personal opinion. FOSS doesn't change the dynamic that full-time developers cost real money.
Source: I worked at Canonical from the early days of the desktop, for ~10 years.
"Unless you have opted out, we will also send your keystrokes as a search term to productsearch.ubuntu.com and selected third parties so that we may complement your search results with online search results from such third parties including: Facebook, Twitter, BBC and Amazon. Canonical and these selected third parties will collect your search terms and use them to provide you with search results while using Ubuntu."
Source: Ubuntu's third party privacy policy.
* The default was not off in 12.10.
I'm fine if you want to make money this way! That's why you're a company, people need to make money. My argument was that some OSS software sells your search results, one way or another. I didn't take a position in this argument (but you can hopefully guess my position).
Now, you mention that your users complained, which was true. It caused a huge amount of backlash from your established user-base, many of which contributed to OSS themselves and have seen their contributions being monetized by Canonical (which is fine too, no worries). But besides the users, it was the pressure from EFF which caused Canonical to buckle to the pressure [1].
So, I don't care what Canonical underlying assumptions were, I don't care whether it is disabled now, I don't care whether Unity showed affiliate links or not. It's all just distracting from the main point: search terms entered in Unity were send, by default, to third-party servers!
[1] https://www.eff.org/deeplinks/2012/10/privacy-ubuntu-1210-am...
Which was four years ago. It's off now, and has been since 16.04 (the most recent LTS release, which shipped last year).
I agree the Amazon integration in the Dash was a mistake, but it's a mistake that has been fixed. It's simply not true anymore that "Ubuntu unity sells your searches in the desktop environment by default," and continuing to tell people so is deeply misleading.
The rest of your points are personal opinions on users and data privacy, I shouldn't have commented on that area, I apologise. I see no value in getting drawn into discussing the strong emotions associated with this area as it never ends well :-)
It's a personal frustration and professional regret that desktop Linux is under-funded to compete on an equal footing - the business model challenge feels intractable. RedHat/SUSE, Mandriva and Canonical have tried different options. But, there's been no sustained success that can get desktop Linux over 5% of market. Perhaps Google will have more success with ChromeOS.
Observe by contrast the efforts Google goes to with the Android APIs.
You're clearly angry, but I don't deserve the implication of being called stubborn, arrogant or aloof.
I've already apologised to you for pushing your comment side-ways in the other thread - I'm not sure what else you'd like from me at this point.
http://linuxbsdos.com/2015/10/28/first-things-to-do-after-in...
Canonical have tried to do some very good things to, and deserve some credit for successfully making Linux more end-user-friendly. They're not terrible people, just folks with a different set of perspectives & incentives from me.
There's Microsoft, Google, and/or Apple have that. The profit models of these big companies create some disincentives on onselling this data.
AV providers are often on much smaller margins and the return from selling this data or building their own products on it is much higher.
I wouldn't be surprised if ISPs and VPNs also sold on data.