Google faces UK legal action for bypassing iPhone privacy settings to target ads
bbc.co.uk
bbc.co.uk
One was to send a POST request in a hidden iframe using javascript. This was supposedly what Google used to bypass Safari's blocking of third party cookies[1].
Another is (was?) to redirect to the third party domain, and then back again[2]. This would supposedly work since the restriction on third party cookies doesn't apply to already visited domains.
1: https://stackoverflow.com/questions/9930671/safari-3rd-party...
2: http://www.mendoweb.be/blog/internet-explorer-safari-third-p...
Google have recently rolled out a 'global tag' to replace the 'floodlight' tracking code they usually use, this was last week.
[1] https://support.google.com/dcm/partner/answer/7570440?hl=en
Google agreed to pay a record $22.5m (£16.8m) in a case brought by the US Federal Trade Commission (FTC) on the same issue in 2012.
It will be interesting how this one ends, here's hoping for a pro consumer verdict.
The firm also settled out of court with a small number of British consumers.
They should drop "Don't be evil" and change it to "You didnt need that privacy anyway".
Functionally, a company's max losses for violating a country's laws is loss of assets and business in that country, is it not? For an international corporation, very few countries have the ability to hold them to any sort of meaningful penalty, especially when a company like Google can simply withhold service to that country until the country begs them to restore it. (See Google News in Spain.)
I find the current case involving Google in Canada interesting: After losing a right to be forgotten case in the Canadian Supreme Court, the highest law of that jurisdiction... Google filed (and 'won') a case in the Northern District of California to injunct it's ruling. ...I don't know about you, but I don't believe a US court can invalidate the Canadian Supreme Court's order... so doesn't that just put Google in contempt of court in Canada?
Those restrictions or requirements need not be limited to their borders. (For instance, the US prohibits companies from doing business with certain entities or persons in foreign countries. That continues to be true even if the person is not inside US borders.)
So, insofar as Google, as a company that does business in Canada, has refused to obey Canadian law, I suspect that Canada would be entirely in keeping with the law to charge Google with any civil or criminal penalties for refusal to comply. A US court's ruling has no authority or interest in the matter of Canada telling a company in Canada what to do.
I presume the end cap of Canada's powers (similarly to any sovereign nation) would be the seizure of all assets and closure of any business in Canada proper. Of course, within the grounds of whatever Canada's own laws allow. So while Canada may not have the sovereign right to force a company operating in another country to comply, it could presumably shut down all of Google's Canadian offices, ban them from doing business with the country, and any other penalty they feel like inside the country.
If you want to do business in a country, you must follow that country's laws, even if you think it's unfair the country is imposing them. This is why Google decided to leave China.
> I suspect until there's a meaningful way for business executives to be extradited for violating another country's consumer protection laws
Why should executives, who are with Google USA, be extradited if they are not breaking any law in the USA? Whatever Canada wants to do should be confined to Canadian borders (so I agree with your current comment that only Google Canada's assets are within Canada's influence).
Also, US prohibits companies from doing business with certain entities only if they have certain leverage (like access to USD). Tomorrow, if some Chinese govt owned enterprise were to deal with Iran or North Korea, I doubt US can do much there.
I definitely think Canada has the right to require that Google obey it's judgement (because, again, as a sovereign nation, Canada can demand anything it wants of entities that do business there), but the cost of noncompliance isn't high enough in most cases. The Canadian Supreme Court has three Google offices worth of leverage to hold over Google to get them to comply, but most countries don't have that sort of power.
In many cases, corporations are currently more powerful than sovereign nations, and I don't think that's a good thing.
> In many cases, corporations are currently more powerful than sovereign nations, and I don't think that's a good thing.
Why not? Tuvalu has a population of 11,000 and a GDP of $34MM. Why should it have more power than Apple, who has 120K employees and $230B revenue in 2017? There are 140 other countries whose GDP is less than Apple, and 40 whose population is less than Apple. Why should they have more power than Apple?
Bragging about how they've done it before suggests that they don't think the publicity is likely to hurt them, either.
Although they're getting the first punches to the face because they're easy and obvious targets, companies like Google or Facebook, will trivially withstand it over time. They can afford whatever compliance cost and complexity is involved. It's everyone else that is going to suffer, including all start-ups attempting to offer an Internet-wide service (something that not so long ago could be mostly taken for granted). The effect will be to lock-in the position of the existing giants and protect them from new companies that might challenge their global dominance.
If I want to offer an Internet-wide service in the near future, I'll need to comply with dozens of different Internet-related legal/political frameworks to spread into dozens of nations. It'll be realistically impossible to accomplish for smaller entities, so start-ups will be stuck even more than they already are in struggling to reach beyond their local audiences. This will particularly harm start-ups in smaller countries in Latin America, Africa and Europe. Start-ups in the US and China will gain a further advantage (an advantage which they've already utilized to produce most of the Internet giants to this point), because they get to start out with massive home markets with heavily unified rules and then push to the rest of the world from their large base.
This process destroys the Internet as it has been known the last two decades and it appears nothing is likely to stop it from getting dramatically worse in the next 10-15 years.
On the other hand, if you start in europe and are thusly aware of the privacy laws it becomes much easier to design as service that complies with them.
The Netzdurchsuchungsgesetz in Germany even goes as far as only making big social networks responsible for content and small startups get a free pass.
North America, the EU+Eurozone, Australia/New Zealand, Japan, and as much of Latin America & Africa as possible, should come up with a common framework that gets you an extremely high degree of compliance out of the gate if you follow it (with some expected smaller issues that are likely to be unavoidable on a nation to nation basis).
WTO for the Internet. It's probably an inevitable outcome in some manner. The difficulty (cost, compliance and just plain frustration) will get great enough such that this will happen. The primary question is what form it'll take, what authority body/bodies it falls under, who initiates it, who the stragglers are, and so on.
China would never sign on to it, and several dozen other nations also would likely lag or refuse. In China's case, they've always operated their own Internet, so they're irrelevant to the context that's occurring.
If your system can cope with the most restrictive case, you can tag the data with the jurisdictions (easy), and then enable tracking / analytics / shared warehouses for more complex data.
It sounds like a reasonable startup idea to help manage this.
It has been like this since Google and Facebook became ubiquitous, which didn't start until the mid 2000's.
Before then, the internet was still the internet, only without most of the data hoovering.
I am totally in support of legislation that curtails this kind of thing. This isn't a case of the internet being made worse, it's a case of consumer protections catching up to technology.
The Internet has been globally widely open since the mid 1990s (except for a few countries like China), when it comes to commerce. That has only begun to slowly change in the last ten years.
Even now, the Internet is still widely globally open. Compliance challenges are still relatively modest. The point is, that's beginning to change at an accelerating rate.
The internet has been open for over two decades yes, but the ubiquitous surveillance of users and tracking and advertising across various websites and services is something that only really became a reality as Facebook and Google began to dominate.
Again, that seemed to start happening after the mid 2000's.
That said, I hope the legislation in this case will be sound. I hope that it at least leads to less invasive tracking. I hope it will be the combination of this legislation and the increasing amount of ad blockers that finally kill obtrusive ads and tracking.
When I use a computer without an adblocker(tracking blocking included) these days there's a major chilling effect. It's gotten so bad that I don't dare search for certain things on my mobile (andoid) because I know somewhere a model is being trained on what I do and type. It makes me uncomfortable and suspicious, and also angry at tech companies that are using my behavior to earn money. I already paid for your phone, you don't deserve anything more.
Cryptomining in a users browser, when not done through an exploit with hidden windows, is a perfect solution to website financing for larger websites. The smaller ones need to make up their mind about finding a balance between micro payments/subscriptions/patreon/free content.
Wasn't this always the case for businesses? If you are a physical company selling physical things then logistics, legal etc was always a huge barrier to expansion beyond your local market.
I think the misconception is that the "normal" state is that the internet is a single normalized market where anyone can grow from zero to global in a way that a physcal company can't. I don't think that's realistic. What happened was simply that regulators couldn't keep up, as is always the case in the beginning of something.
> This process destroys the Internet as it has been known the last two decades and it appears nothing is likely to stop it from getting dramatically worse in the next 10-15 years.
But wasn't the internet in the past decades just a wild west where things like privacy etc always took a back seat? Is this development really such a bad thing (for consumers, I mean)?
Before that, it was even more anarchic. Before that, the internet didn't exist. Global-scale many-to-many media and communications didn't exist.
I don't understand the desire to argue for an internet descibed by analogy to phone or radio or somesuch. The comparison isn't that strong, and the outcome is not desirable. The internet exposed the flaws in those, if anything has informed anything. Is this devils' advocacy?
I do understand incumbents. They're safer and more protected the more rules get made. I understand politicians who are trying to deal with some other problem (financing terrorism, child porn), and don't understand or care about side effects. I understand the naive public, who just want their leaders to just solve these problems they keep taalking about. I understand judges ruling on specific cases, without regard (not their job) for the delay facto policy implications. The HN-er who wants an internet rulebook, I don't get it.
Bulk data collection and massive privacy invasions weren't a problem, that's what I'm saying.
> I don't understand the desire to argue for an internet descibed by analogy to phone or radio or somesuch
Not sure that's what I did, but I'm definitely saying that states should be able to regulate/taxate all business, and internet business can't be excluded.
> The HN-er who wants an internet rulebook, I don't get it.
Not sure what your argument is, nor what you thought my argument was. The article is about a company (in this case Google) facing legal action for doing something that was (possibly) against a law somewhere. I think it sounds completely reasonable that this is possible.
>>It's going to become increasingly expensive and politically complex to operate an Internet company at Internet scale. ...something something, incumbents will be fine. Like financial services, old media and other markets, the internet is at risk of becoming inaccessible in large part to upstart initiatives, commercial or noncommercial.
That's quite debatable, from Stasi methods to NSA trying to collect bulk phone calls, there've been plenty of examples for bulk data collections and massive privacy invasions predating social media and the Internet.
20 years ago nobody cared much what information you shared about yourself on the www, as it wasn't monetized, barely anything was as many users back then had been hoping for something like a "post-privacy society" to emerge. The problems started when companies wanted to commercialize the www, que ad-revenue economy and massive aggregation of personal information on-top of that.
Creating a situation where monolithic companies and governments suddenly have a very similar goal: Categorizing and collecting "people" in every imaginable way.
Facebook is pretty much building a database of all the people of the world, governments have struggled to build something like that, on a national scale, for far longer and regularly failed.
At this point, I wouldn't be surprised about shady backroom deals along the lines of "We let you get away with breaking this immensely complex legal framework if you give us access to your database of phone numbers/selfies/whatever" actually being a thing.
Internet has become the dominative media in the past decade, it is naive to think the powers in real world will give it a free pass.
https://www.ftc.gov/tips-advice/business-center/guidance/can...
Each nation makes its own decisions about that, with a lot of overlap but also a lot of non-overlap. And internet businesses will more and more have to navigate all that, or opt out of foreign markets. Just like non-internet businesses.
It's everyone else that is going to suffer, including all start-ups attempting to offer an Internet-wide service (something that not so long ago could be mostly taken for granted).
If a startup violates the privacy of their users intentionally and witth gusto they deserve to get smacked in the face; hard!No, you don't. You'll have it a lot easier than Google or Facebook, because you don't have local offices in more than one country, and you should keep it that way as long as you possibly can. As long as you have offices in exactly one jurisdiction, you are only subject to the laws of that jurisdiction. You can generally safely ignore the attempted overreach of others.
But taken a step further it seems fair to ask:
- Has Google lost its edge? Why has nefarious replaced innovation?
- What else are they doing that we don't yet know about?
- Is it time for Google to update its biz model so it isn't so dependent on being so driven (to desperation)?
- Finally, is it time for the market to reconsider Google's role in defining our collective future?
On a personal note, if I can be fairly certain Apple isn't going to "pimp my data" I would give an iphone a serious consideration.
NOT giving Google my data is a good starting point IMO.
> The complaint is that for several months in 2011 and 2012 Google placed ad-tracking cookies on the devices of Safari users which is set by default to block such cookies.
Seems they used cookies for tracking despite Safari supposedly disabling those kind of cookies.
https://stackoverflow.com/questions/8048306/what-is-the-most...
http://alexanderhiggins.com/google-fined-22-5m-for-hacking-s...
Here, we're applying similar benefit to the consumer. The consumer has expressed they do not wish to be tracked. The application of a loophole does not make it okay.
Is it a little over-reaching? Possibly. But it's about time things were over-reaching in the consumer's benefit, rather than the corporations'.
That sounds like an international criminal act on a scale most malware authors would wet themselves over.
It's also not surprising that the public is getting fed up with the wanton criminality that seems to be embodied by modern capitalism.
It's definitely a problem in consumer culture that big companies can rip people off and break the law without facing consequences - so long as they are only jacking people a little bit at a time.
If Google was caught breaking the law, it would be appropriate if one of their officers went to jail over it.
or
so long as they are only jacking the little people.