Am I logged in or not? GDPR case study on the example of Chrome browser change
blog.lukaszolejnik.com
blog.lukaszolejnik.com
I really expect this change to push a lot of people away from Chrome, and frankly I wouldn't be surprised if it started opening up more antitrust possibilities due to how they're using their browser to give their services special functionality others can't get.
That's literally their jobs as Chrome evangelists. They're just doing what they're told.
Because they’re not “dying on a hill” at all, because nobody cares. Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this.
> I really expect this change to push a lot of people away from chrome
Care to bet on that? Because I would happily take the opposite side of that bet. I think the feature will stay and after a few months we will see absolutely no change in Chrome’s usage statistics.
A lot of people do not understand, but we do, we're the techies. It's our job to understand.
Don't mistake people not understanding for not caring.
Once people understand, they care.
They know what's happening is wrong. They don't know how to stop it. But they do still need to browse the web.
Everyone "understands" that Facebook collects user data. It's the contextual understanding that makes techies uneasy.
It's not the "contextual understanding" - or any kind of understanding - that makes some techies uneasy. It's their own opinions and personal comfortability with regard to data monetization. Many people understand their data is monetized in myriad ways and fully don't care. Asking if they actually understand is only going to patronize them.
The answer on all that is advocacy.
They may still not care, and that is fine. At least it is with eyes wide open.
Professionals do that sort of thing. It is consideration, not condescension.
There are countless things I understand the basics of but am not an expert in. That's why we specialize, because we can't be experts in everything all the time.
I don't mean it to be condescending, I mean to express that I can know that stars are powered by nuclear reactions and yet not have a firm grasp of what that really entails.
Most people, including myself, have a shallow understanding of a lot of things, and a deep understanding of very few things relatively speaking.
The only thing that’s different is that they can remain blissfully unaware of it.
Your comment basically implied "maybe they don't really understand which is why they don't care".
So I am refuting the original statement because I presumably do understand, and I still don't care.
Once people understand, they care.
Conversely, don't mistake people not caring for not understanding. Many people both understand and don't care. Reasonable people can disagree about how their personal data should be monetized.
Much like the slide from IE and FireFox to Chrome, by the time Mozilla and Microsoft reacted, it was already too late. Time will tell if this is the start of such a momentum flip or if it's just another blip.
Now computers are easy to use, and the massmarket does not need to rely on techies for guidance, and non -techies can be early adopters. The general public relies on mainstream popular culture / fashion influencers.
Ever since I updated to 69 I've been absolutely loving it. The most noticeable improvement is it feeling incredibly faster, but as someone who's been using 4-5 profiles on Chrome for over a year the new user management stuff just feels so much more intuitive/integrated.
I was super surprised to see people complaining about it on HN this morning, and I'm still not entirely sure what the problem is. FWIW, I also severely disagree with a lot of the implementations of GDPR, so maybe I'm just not the audience who cares here. To me, this update has been nothing but improvements so far.
Chrome 69 is simply the best. Not for me, but for the average user. The reading and work flow is incredible for casual browsing.
The negative reaction on HN is understandable, but it's not relevant for most people.
The goal of Google is merging the user experience of Android, Chrome, Google search and personal Google accounts into one, and it will get increasingly difficult for users to get out of this ecosystem.
Ive always loved google. Installed chrome when it was released. I'm writing this from a pixel 2 XL because I broke my pixel 1 XL. I've had a Gmail account almost since it's been possible (I have my firstnamelastname@gmail.com). I now use firefox. I don't know what mail I'll switch to, and I can't bring myself to an iPhone, but I'm leaving.
Google's increasing anti-user posture is enough, personified by the removal of their slogan "don't be evil". Legal move though it surely was, it's all too fitting.
Goodbye Google - you broke my heart.
That document has been reworded and the slogan is now at the end, but it's been there continuously. While I agree it's more of a passing mention than in the old wording, the end is one of the most prominent placements possible for such a statement other than the beginning.
The common Internet belief that they removed this came from the Code of Conduct of Google's new parent company Alphabet, which says "Do the right thing" instead, combined with the subsequent rewording. But Google's still applies to Google as well.
I'm thoroughly embarrassed to have regurgitated internet gossip without reading the source material.
However, as you mentioned, I stand by my sentiment. Google has clearly telegraphed their desire to put making money over users privacy and security (my definition of security being safe from Google, whereas Google's is safe from everyone BUT google)
To attack this issue from Google's side, the targeted ads I receive are straight garbage. The ads I get on my Google YouTube account from my signed in chrome Google account on my signed in Google phone are not in the least bit relevant to me or my interests. I don't use ad blockers of any kind. If I have to watch the ad about Dr. Gunter zolof solving Carmichael's toshent conjecture one more time, my phone might suffer an "accident" and I will take that opportunity to switch to a different provider (ANGRY SIDE RANT: I haven't watched that ad to completion or clicked on it a _single_ time. Stop showing it to me. 50 times. Consecutively)
The public needs to start changing their mindsets and begins to accept that all information in your private life is being recorded. The only important aspect that needs to be questioned is to what extend the data is going to be used. Are some companies not going to hire you simply because of something you did in your private life three years ago that they may not agree with? That would be unacceptable to me as it would definitely cross the line. It is what I consider similar to the "social credit" system being implemented in China, in which everyone is under surveillance at all times and given scores for activities such as grocery shopping. There are always two sides of the extremes, and the balance we should strive for is somewhere in the middle.
It's impossible to ask U.S companies like Google not to conduct data mining on their users. How do you expect them to compete with companies in other countries that monitor their users 24/7 and have access to larger and more accurate data? In the age of information and artificial intelligent, those companies will win the battles simply because they will have better insights that Google won't ever have. Companies in the West cannot readily admit what they're doing because the public mindset is not yet ready for this change. It's too drastic and against many values we have been familiar with our entire life. But our world is changing very quickly, it is not the same world as before, it's understandably very difficult for most people to wrap their head around this but we need to update our mindsets even if that means changing our values. Companies like Google cannot disclose what they do because of public backlash they will receive. If people are just going to switch to another company, all their investments will have been lost, and the next company will be forced to do the same anyway. Google's recent move was probably the best way to test out public water, and it is already not looking very good. I don't know if governments from the West will ever be able to crack this issue.
Also, why do companies need to "compete"? There's no reason that core software like internet browsers or operating systems need to be commercial in the first place. I will happily continue using Firefox.
Let me give an example, suppose no countries on earth had nuclear weapons. We all know how deadly and devastating its effects can be to humankind. Let's say initially all nations agreed that it's bad for all of us and nobody should pursue it. However, if ONE country broke the contract and started developing nuclear weapons on their own. Do you think the remaining countries can afford to stay at their same positions and not start developing it too? Once someone starts doing it, all bets are off! You can apply the same logic to any unethical technological experiment, such as cloning human. Google really had no choice, if they don't adapt they will be out of the game within the next 10 years.
Hop on https://www.gandi.net/, choose a domain name that looks professional (such as mylastname.me or some other clever variation) and never have to ask that question again.
If you ever want to go back to gmail, bring in your domain with gsuite (https://gsuite.google.com/).
As for an alternative UI&host recommendation, go for fastmail: https://www.fastmail.com/
It's always interesting to see how the most technical users seem to take such an irrelevant vague throwaway marketing line so seriously.
It's also still in the code of conduct but now moved to the end so it was never actually removed from anything anyway, if it actually matters.
At least for me, Google's behavior means that I can no longer recommend Chrome.
Fortunately it's not. On average people are only about 6 degrees apart, so in reality a relatively small number of people can get a surprisingly large amount of coverage in a frighteningly short amount of time, should they choose to apply themselves.
You are conflating "don't understand" and "don't care." Those are not the same things at all. This conflation seems to be a stable of Big Tech now where matters of privacy are concerned.
>"Nobody outside Hacker News and Twitter infosec people only followed by other Twitter infosec people cares about this."
Awareness of issues and a dialogue concerning them generally starts with people have domain-specific knowledge. The idea that this somehow detracts from an issue's importance is absurd.
Assuming this isn't fixed, the ick factor of being in-your-face followed across the web will be quite strong, I think.
I do not want synced browsers between my two environments.
This change makes it inordinately difficult to maintain that separation while utilizing other parts of the google ecosystem.
Google services are getting preferential treatment over the rest of the web on a browser with a market share big enough to be subject to an anti trust case. Vestager must be licking her lips right now...
"You're signing into Gmail. Would you like to link Chrome to joebloggs@gmail.com? This will enable automatic notifications in Gmail, sync passwords and web history, and also automatically log into other Google websites when you visit them".
"Yes / No / No, and don't ask again"
"Yes / Ask again later"
... We passed the point where dark UX patterns deserved the benefit of doubt a few years ago.
If it benefits the company, it's intentional.
Theres almost never a true choice.
"Update now / Update in 1 week"
I think you're being a little optimistic.
> This will enable automatic notifications in Gmail
> sync passwords and web history
Chrome 69 does not enable either of these things just by signing into Gmail. (Sync being a separate opt-in has been well discussed. I just tested notifications on a new profile: they're not automatically enabled, and if I try to enable them in Gmail settings, I still get the usual browser permissions dialog.)
> and also automatically log into other Google websites when you visit them.
...and this one would happen regardless of any browser involvement.
If I have chrome sync enabled in browser on desktop a, then login to gmail in chrome on desktop b — is the browser history on desktop b now synced ...?
Also curious whether sync implies that old browser history in desktop b is synced to my account or is it guaranteed to be the case that “only browser data collected while logged in” is eligible for being synced between devices ...?
Maybe the Chrome team was wrong to introduce signing in to a browser at all?
maybe, but that would mean that all browser vendors did it wrong. (including mozilla)
I think that's the case, and Mozilla is one of all your friends who are jumping off the proverbial bridge. (Posted from FF, not signed-in.)
They are tying website login to browser login, with the intent of merging the two - that's the problem.
To users are Google who are fully invested in that corp having total control of their online life, this fuss will seem quaint and odd, but I do think it will have serious implications long term - people are turning away from search too for similar reasons - abuse your monopoly enough and people will actively seek out other options.
Now I've done making an excuse for it, I think it's a shame that Microsoft fucked up so bad with IE that both Edge and Safari face an uphill struggle. They're both pretty decent browsers that are kind to your battery and aren't bloated with features you're unlikely to ever use.
The extension support is fairly poor for both but at the same time, that's not exactly a bad thing. You browse the web with them and that's more or less it.
Being able to make something with an extension have having a behavior turned on by default in the browser are very different things.
link to said threads?
> Q: I don’t get, though — if you’re signed in to the browser but sync is off, then what does it mean to be signed in to the browser? What does it do besides sync?
> A: Not much, you can think of it like a Gmail login state indicator.
If that's fully the case, then there's nothing to see here and people are freaking out over nothing. Am I missing an important element here, other than that people don't trust Google?
Their current argument is that they aren't actually collecting that data- just getting permission to- but that's kind of sketchy and still leaves them open to other changes that do start collecting things.
The other big issue people have with this is that the use case they're talking about- accidentally logging into a site and not logging out- is an issue with all websites, not just Google. Adding a UI for Google services explicitly is something only Google could do, which makes their browser less "neutral". This is why people keep bringing up antitrust. By taking advantage of their monopoly to further entrench that monopoly they are breaking the trust of their users.
They aren't actually collecting that data because you haven't turned sync on.
I almost never visit the Economic Times, and I certainly never log in, but now it gets a chance to log me in using my 'real' identity, and there's even a popup to nudge me in that direction. Any site that implements Google Logins can do this, as far as I can tell. I'm pretty sure most people who chose to enable browser sync in Chrome didn't opt for this.
I think the Chrome team really screwed up on this by not considering how Google IDs are used across the web. And for what? The rather marginal scenario of eliminating confusion in shared-browser situations?
Or they knew the full implications and did it anyway, which is even more disturbing.
I simply don't trust a single corporation that much.
I know they were working on removing the need for plugins in other browsers. Ut last time I checked it was still a bit iffy.
This is what’s keeping Chrom(e|ium) installed on my machines right now. (I have a customer that uses it extensively).
If Hangouts works in Firefox I think I'll uninstall Chrome.
I have noticed Xero doesn't work on Brave. Not my product so not so concerned but I'm going to investigate to see what Xero is doing that we are not. ie why my dev's stuff works and xero's does not.
I'm half thankful for the Chrome team doing this because it was just the push I needed to finally rid myself of Chrome once and for all.
I plan to do a clean re-install of the OS on my Mac as well to ensure that all vestiges of Google Chrome are indeed gone. I also took the opportunity to rid myself of Google Drive File Stream.
I've always used FF and Chrome, flipping back and forth as Chrome filled in where FF had issues and vice versa, but after a week or 2 on Quantum I just didn't need Chrome anymore and uninstalled it. Haven't regretted it once.
(also, I'm 90% FF now too)
Hopefully that'll be fixed soon...
You could look at it as silly, but in those 6 months it saved around 700 work hours after it had paid for its dev time.
Each container can load any page. If you want to toggle the current domain to load in the current container, you can opt for that. Then, it will prompt you to switch to that container when you browse to that domain, and at that point you can opt to make it automatic. If you don't make it completely automatic, you can just choose to use the default container for that domain, or stick with the current container (or source container, if opening a new tab from some other container).
What would make this better would be to be able to flag a domain as openable in multiple containers, but have one be default, so I wouldn't have to decline switching to my personal Google container every time I clicked a link on an email in one of the G Suite accounts, as they redirect to a google landing page).
[1] https://github.com/mozilla/multi-account-containers/issues/8...
Currently the global history is shared between all containers.
I've never signed into Chrome, but I am able to access 2 Google accounts... and Chrome still shows me the "Sign into Chrome" option.
Version 69.0.3497.100 (Official Build) (64-bit)
(I normally just use Chrome for development)
Years of double digit percentage revenue growth sets lofty stockholder expectations.
All the low lying fruit to sustain that trajectory is gone. So, anything (AMP, this, etc) that might boost their targeting ability or impressions is important for them.
> I don't understand why the Chrome team is picking this hill to die on- their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away as if the people upset about this are just not understanding what's going on.
My impression is that this is the new norm at Google. It happens with everything, internal or external. The sad reality is that most decisions will deeply upset at least some people, and those people likely don't have the context into the decisions but still complain loudly.
From my perspective what happens is that it doesn't matter whether a decision was a good or bad one, there will be people who complain (ESPECIALLY internally as Googlers can be very entitled) and so at some point you're just completely immune to this.
This is not helped by the fact that people externally often think Google is on some evil plan and speculate in wild ways which are completely wrong.
To give you an idea of how these things usually happen.. it goes something like this..
Someone finds a UX problem, and makes a plan to fix it. In this case I guess it's confusion among signed on accounts. Someone on the team probably raises some concerns, likely similar if not the exact ones being raised now, and they debate it but eventually they say well, the proportion of people who seem to care about this is only 0.1% of users (Because we are objective!).
Sadly, even though it's "only" 0.1% of users, those users are extremely negatively impacted in a way that's not really reflected by the small percentage, and 0.1% of a billion is still a considerable amount.
On the other hand, there are many other decisions which were released just fine and we would not be able to do anything if we were always afraid of negatively impacting some small proportion of users. To me this is a weakness of the attempt to have everything be objective and "measurable".
Let me state that I don't think this is good or even acceptable, but I'm definitely not smart enough to know how to solve this on a wider scale than my immediate team. However I hope this at least provides some insight into why these kinds of thing happen.
No, not the feature all other components do need so much you have to work around by adding another zillion lines of code in other places of your program to deal with the case it turned off.
It's not hard.
And you don't have to do every possible customisation options, just the ones that people are enraged about.
if you are operating something as complex and dangerous, you need the Comercial airliner cockpit! it's that way for a reason! or would you rather board a 747 with a huge colorful button "fly" and another "land"?
if you have something like a browser, that is your last line of defense accessing online banking etc, you need to see into the miriad of options. if you just browse facebook, use the default and be happy. Knowing about:config shouldn't be a gate keeper to anything! going to settings then advanced should be more than enough to communicate the concept of advanced options. anything different you are just being an entitled , incompetent UX designer.
about:config is lazy, but get some of the job done. your oh-so-perfect two options google chrome setting page, is lazy and useless.
Also, it's Boeing or I'm not going.
Agreed. But it's UX design for power users clearly.
But I was talking about the way to combine 'a regular users UX' with a ton of options you need for power users. The vast majority of the people who have Ubuntu on their laptops never recompile the kernel or even know about sysfs, the vast majority of the Windows and Office users never touch the registry editor - but removing them would be a huge mistake.
I won't say you cannot make toys but I'd be happy if ux designers everywhere could take a break and stop dumbing down working applications, thanks.
PS: they don't need to be flashing.
In fact, in modern aircraft, they're not flashing. The trend today is to not light a light unless it's important to pay attention to it. It's called "dark cockpit".
Not everyone uses a browser the same, but a decent part of people here will spend their working life in the browser. I think for people here it won’t be rare to have dozen of windows with each dozen of tabs, some logged in different acconts within the site they show, some in incognito, some with in developer mode.
Even with just the browser filling multiple windows worth of buttons and stuff to interact with is easy, without even going to hidden preferences and configs.
I’d argue in complexity level we’re already on par with a airliner cockpit, it’s our job to deal with that, and we do it professionaly for years. Of course not everyone needs that complexity, but at least we do.
What I am getting at is, I think we should accept we’re not a t the point where it is simple anymore, embrace the complexity and give tools to effectively manage it.
Airliner cockpit are so because it’s efficient to have individual switches to important action and state indicators. We shouldn’t shy away from showing important info in the interface just because we’d end up with more stuff. Having it hidden can be a worse tradeoff.
Most people don't give a shit, they just want to check their gmail and couldn't care less. They don't even read the alert boxes that do pop up. They just click almost anything blindly.
As a result, companies get away with dark patterns and privacy-compromising changes like this.
I'm somewhere in the middle. I don't want airline-cockpit controls, but I do want the ability to not sync to the cloud/NSA if I want.
I also don't want to be tricked into syncing by some dark pattern silent update that makes an ambiguous clickbox that doesn't clearly say what the privacy implications are either.
Chromebooks are in an interesting position, with a chance to have newer users. But then they will literally live their life in the browser.
In that sense, Chrome users are already set apart I think.
Put it on a screen called advanced options or something, even about:config, and let us decide!
That is, if you're really not just manipulating your users.
But will it be there forever?
Some other post on HN on this topic implied these options tend to vanish over time. (I'm not sure if they so or don't)
The total indifference to people's valid use cases is what really grinds my gears.
Chrome is still the only browser that ruins my UX by putting a profile picker into the title bar. A place it has no business being. I literally made a patch and compiled my own version of Chromium for a while to get rid of it. https://github.com/hparadiz/chromium-disable-profile-button-...
I'm so tired of the arrogance. Chrome used to be a beautiful simplistic browser. Now it's just bloat. I'm done. Get off my computer. You guys had your chance and blew it.
You can figure out the rest.
That’s not a problem or an indictment. Just an observation of how systems work st scale.
It's also part of the reason for the pace of the industry. You pump out as much money as you can from some space, and then move on to focus on the next thing.
I never wanted my youtube account tied to my business email.
Would you please read the site guidelines and follow them when commenting here?
If you don't want to be banned, you're welcome to email hn@ycombinator.com and give us reason to believe that you'll follow the rules in the future.
The real bad guys don't ever think they are evil. (consider Al Capone, hero of the people)
Sure, there's less impact when statements are less hyperbolic, but there's also less bikeshedding about the problem, so maybe something actually happens in the end.
I mean, if google is evil then what do you call North Korea? Super duper evil?
Google is evil in the same way now, that Microsoft was back in the day.
And no you don’t need to be North Korea to be evil. That is a meaningless comparison. Coincidentally Google has started working with regimes similar to NK; The PRC. Is that not evil?
No, it's not, because evil is a negative ideal, but I don't think it actually exists in reality.
Even Hitler wasn't evil, he was insane, and the whole situation is a case study of what happens when people, regular people, are given an easy explanation for all their problems. Placing something in the category of "evil" is placing it apart from behavior that you expect normal people to be capable of, since I think most people thing the majority aren't evil. All that does is help us feel better at the expense of helping us be better.
Evil is for fairy tales, where things are black and white. Normal people rightly get defensive when called such, because the road to hell actually is paved with good intentions. Hyperbole isn't a useful way to communicate.
Sorry to go full Godwins on this, but if you can't pull out Hitler and Nazi's when talking about evil (even to counter the point), then when can you...
I can’t even start to consider that it’s an appropriate analogy so Godwin point is dully granted.
PS: If it please your mind regexp replace "evil" by "ill intentioned" in Google related threads. But don’t forget that it’s Google that originated this terminology in the first place with their moto "Don’t be evil"...
> The real bad guys don't ever think they are evil.
At least seen from the inside, it's often funny (and sad) to see all kinds of crazy speculation about the greater evil goal of nefarious decisions made, all the while whatever is happening is usually a mixture of software bugs and incompetence on our side.
It's like a clown show, where the evil mastermind turns out to just be me incorrectly checking for a null value in some if condition, or my PM having no idea how to rationalize two features together.
I guess that comes with large corporation status, and a certain failure to communicate. Not sure if it's avoidable at all. It does teach you something about perception vs intent, I guess.
When I’m doubt, Google should err on the side of privacy.
That’s the safe way to go. And in this case you can clearly see that some people will freak out if their browser syncs their history to the wrong identity or that it syncs at all.
Unfortunately, and with a long list of "accidental" blunders Google is long beyond the point of deniable plausability.
As an example in this case, I am an IT decision maker for a small group of people, I'm not that active on social media as a contributor, and losing an Apps subscription because of a browser auth decision could be one of those impacts. Its likely not, but if it were it would be impossible to understand in the aggregate, and of infinitesimal impact.
Be that as it may, user PII is now on the liability side of the ledger, and some businesses just haven't adapted to start operating like that is reality. Beyond financial hazard, the moral harm of a leak, the risk of telling the secrets of millions to the world (or a dangerous few) should be of grave concern. The best way to be trustworthy is to not know the secrets in the first place.
Bulk data collection doesn't affect 0.1% of users, that is the only group of people that understand enough to be concerned about. It affects everybody who signed up as a user. Their secrets and their safety are now in your hands.
This IS an engineering problem. I have full faith that with the right will, Google could figure out a way to offer web scale services to all manner of users and still deliver on its ambitions to deliver intelligent experiences with provable privacy at the heart of it. It probably involves data living at the edge; it probably involves renting datums from customers; it definitely involves a radical shift in business models.
Engineering a solution to a privacy-at-scale repository of human knowledge cannot happen without leadership that truly sees privacy as profit, at every level of the company.
You and your colleagues could raise that these are there for a reason, approved by senior management, and there to help you respect your users' rights.
I like the sound of "Applications that affect or change your user experience should make clear they are the reason for those changes." or "It should be clear to you when you are installing or enabling software on your computer and you should have the ability to say no." or "We believe you should be asked explicitly for your permission in a manner that is obvious and clearly states what information will be collected or transmitted."
All of these sound relevant to the grievance of the OP.
[0]: https://www.google.com/intl/en/about/software-principles.htm...
Big corporations usually pick some good rule of thumb (use data based decisions) and pervert it until it's a blind rule.
Now I can see some understand some of Google bad decisions, sentiment and grudges aren't easy to measure. I can find some aspect of a google product annoying but not bother me much. Still, annoying thinks add up and most users, like 99,9% users don't write complains publicly so they can't never tell. It's also harder to account for network effects like the family geek stop caring about chrome and moved the whole family and friends to firefox.
An estimated negative impact in 0,1% can really mean last push for 1% of users. Add several episodes like this and you can destroy a company.
Really? That one is easy to understand. Google is a malware company and anyone that cares about privacy wouldn't work there in the first place.
I know the following is not welcome on HN, but I have to vent somewhere folks that think this was a good idea are reading, so here it is: A big fuck you to Chrome for forcing this feature on us!
Chrome also doesn’t respect window order in the menu, so it’s just a pain to track when switching. My solution to that was to switch to Safari for personal use.
My main browsing has always been done on Firefox which has sync much like Chrome does, but oh look it's encrypted, forgot my password? Too bad, they're going to nuke my data since they don't even know my password. As it should be. My browsing data being synched is cool but it's not that precious to me, and if it was I would just not forget my password.
Also if I need to use Google services I have a Google container, if I need to use Firefox, I have a Firefox container. Good luck containing Google or Firefox on Chrome that way, and the multiple account containers are amazing for testing multiple user roles on web development projects all on one browser with multiple taps opened.
In my case, I don‘t switch to Firefox because they don’t support AppleScript and it’s a feature I use every day.
Less than an hour ago, on another HN thread, I saw another macOS user claiming they won’t switch to Firefox because it doesn’t support Keychain.
Every time there’s this conversation, I see a bunch of macOS users complaining about performance.
In sum, a bunch of users (particularly macOS users) don’t switch to Firefox because it plain sucks for their needs.
I can ignore identity switchers provided by a site (google in this case) and just keep two gmail tabs, one for personal and one for work, open right next to one another. Firefox keeps each one sandboxed with its own session info like cookies etc.
Agree with you up until this point. The vast, vast majority of people won't even notice this has happened, or really care much.
Anecdotal of course, but I haven't heard a single complaint among my non-tech friends, and I'm usually the first person they talk to about this stuff (because I'm "in tech"). I also believe Google when they say this change results in a lot less confusion from users (and just so happens to be a strategic benefit for Google, too...)
I think as tech people we systematically tend to under-think the second-order effects of the systems we build. Case in point, Chrome and G-suite being that closely integrated brings up serious privacy concerns, and the part where the Chrome team doesn't seem to appreciate the nuance reflects poorly. I do cybersecurity now (didn't used to), and a good number of problematic things I run into just come from engineers like my previous self not thinking through the security implications of a specific design, mostly because not thinking about security means shinier UX delivered on less resources.
Just another example I encounter regularly: I use U2F to sign into my Google accounts. However, when you log in, the checkbox to "trust this computer" is checked by default, meaning that if you're not paying attention your account will get automatically downgraded to single factor authentication going forward. It's a clear nod to convenience, but done this way it makes you shoot yourself in the foot.
It's a good change only if you are permanently logged in to google services, which is probably why it seemed like a great idea to the Chrome team, who probably have no idea how much distrust Google has started to build up. It moves the browser closer to an app runner for google services - I'd understand that if this was on Chrome OS or a specific 'Google' app, but in a general purpose browser the browser chrome should never indicate login state about specific websites, nor should my browser be logging in to google itself. It was bad enough when that was a choice for users, now it is one policy change away from being obligatory.
This is how we end up living in a world where google has access to all your data. I've switched browsers due to the move, not just because of this specific action, but because combined with all the other dark patterns Google has engaged in recently, and their clear moves to abuse their monopoly in search, it tipped me over the edge.
I no longer use google search (have been using ddg for a while), and now no longer use google browsers as a result of their disregard for user privacy.
Copy that. Thats a serious privacy leak, Referrers, none of the adblockers handle today.
Also, it not just fonts, but jquery and other stuff. And two places to check: Referrers HTTP header and meta element Referrer Policy of the page
I'm hoping CDN's get the same privacy treatment as facebook and the like have been getting lately and we can go back to a self hosted world.
*your device
If someone has access to my desktop PC, they also have access to my yubikey anyway.
If Google switched it to not trusting by default, you could still trust whatever device you want, just without the risk of a default behavior working against you.
EDIT: Yes, IE was great in the beginning, but then it stagnated and earned the wide reputation of being terrible obsolete anchor that it is now known for. It's with this late-stage IE that I don't see the comparison since Chrome is still on the cutting edge.
It was IE who added XMLHttpRequest and invented AJAX.
Bill Gates wanted their browser to be the best, but also wanted it not good enough to replace desktop apps. However the right hand didn't know what the left hand was doing. The Outlook team was told to make a web version. They got the IE team to add XMLHttpRequest for their use, everyone implemented what they needed to, then went home and forgot about it.
Then Google recognized what the feature allowed, and used it in gmail and maps. The rest of the internet said, "Wait, what, you can DO that?" Studied it, popularized the technique as AJAX and the rest is history.
It's possible that Microsoft's style guide at the time set three characters as the limit.
Furthermore I remember gmail's keyboard shortcuts being a shock to a lot of people. Me included.
...in 1999. Then IE6 was released in 2001, and then Microsoft scrapped the Internet Explorer team and didn't release another browser for 5 years, leaving us with 90%+ of users stuck on IE6 bugs and non-standard features.
That's what the GP is talking about.
Dynamic HTML as it was called, CSS, encryption, and so much more stuff came to IE before any of the competitors.
Then it became the IE6 we all came to know. The analogy with Chrome starting as a trail blazer and progressively taking the same trajectory is perfect, really.
As far as I can tell, it's still on the bleeding edge and only recently met there by new advancements from Firefox.
For example, the FF team felt that flex/grid should become the new layout standard, and deprecated or accidental behaviors of the past could be sunset by doing it right on Flex/Grid. So, for example, margin-top: 10% would be percent of height instead of percent of width when on a flexbox or grid item.[1]
Chrome did it their way and wouldn't discuss the issue, and eventually FF caved because Chrome has a near-monopoly.
This idea of implementing bad design and forcing it on the world, won't end well for the user.
Not to mention the whole recent hullaboo about hiding the www / m / whatever prefixes.
[1] https://github.com/w3c/csswg-drafts/issues/2085 [2] https://news.ycombinator.com/item?id=17927972
That's a bad example. In technical progress,
Chrome is the complete opposite of IE
When IE started to _gain_ internet share it was a paragon of technological development. It was far faster then navigator, more reactive and performant.Only little-by-little did Microsoft start adding in features no other browser supported. By the time the mid-late 00's roll around and Chrome was released. IE was this red-headed step child, with a lot of unique Microsoft only extensions.
Chrome is walking the same path, a technological superior browser slowly breaking compatibility with the rest of the web. But in such a way that developers _arent too unhappy_, but enough that most business users, and home users keep using it.
Saying Safari is the new IE is a short sited look at only the tail end of the problem from IE7 or so out. When IE was this slow laggy thing people kept around from Windows XP. Instead you need to look at Chrome like somebody would look at IE4 compared to Netscape Navigator. Sure IE4 breaks standards, but custom webfonts, OpenSSL encryption, ActiveX containers! All these new tools developers can use to make a richer more interactive web experience!
This is directly out of the Microsoft playbook and is why IE became as despised as it is.
[1]: https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguis...
Meanwhile Safari and Edge continue to lag behind with basic features. Either way extinguish only works if there's no ready competition, which is not the case here for the majority of users.
I develop in Chrome because that's where the majority of our conversions come from.
I (my QA team) also tests Safari, Firefox and other browsers where a significant number of conversions come from. I never heard "just use chrome" in any professional environment.
Not at all. I used to start developing while netscrape was still a thing. Chrome is (and it was) a bless for developers. I try firefox like once a year and see no reason to switch.
THe actual case is also no reason to switch (for me) but ill watch it.
This. I get to hear this from my colleagues at work all the time.
> My teammates made this change to prevent surprises in a shared device scenario. In the past, people would sometimes sign out of the content area and think that meant they were no longer signed into Chrome, which could cause problems on a shared device
I can see why there is pushback against this, but the issue described above is also understandable. There are valid reasons why "average" users would rather have this, and having unsynced or completely mismatched logins between Chrome and Google sites can lead to confusion for many who don't really see or care about a difference between them.
However it would be best if Chrome kept the settings to disable this. It doesn't make sense to remove those flags when they also have a large technical user base. Seems like good intentions but misjudging the impact of the decision and forcing it on everyone without recourse.
In fact, it could also sign you in to local applications like Photoshop and Word.
They could call it the 'logon screen'.
In other words, the given motivation for this change rings hollow.
This makes Chrome less of a browser and more of gateway to Google services that happens to include a browser. Which will also trick non-technically-savvy people to accidentaly share their non-Google logins when sharing computers/"browsers".
The big difference is that your Chrome account is your Google account, unlike any of the other sites you mention.
Auto-signin only adds confusion. Many (most?) users have no reason to associate their browser with a Google account. This is something that Google is pushing unilaterally, just like Google+/YouTube integration. As an advertising company, they stand to benefit from more accurate user tracking.
Again, the Chrome account is your Google account so you're not associating anything, you're just logging in. It's different than any other example where the website has a different account. Signing in to Chrome and then into Gmail is not what most users would expect because for them the browser really is just another Google service.
There seems to a big (and sometimes willing) misunderstanding from HN/tech users about the mainstream population who just want things to work.
Then Chrome should be just a Google Services Client app. It shouldn't pretend to be a browser. It shouldn't allow one to log into "any of the other sites", in the first place.
That would follow the users expectation (based on their observation).
Logging the user into the browser, on the other hand, is not directly related. And potentially unexpected for the user.
They could have had one without the other.
Their excuse sounds like parallel construction, as I refuse to believe one of the top IT companies in the world can't see why this solution is so bass ackwards.
They know exactly what they're doing, and it's the reason I went from a huge fan of Google products and early-adopter/beta-tester of everything possible, to scrubbing their existence from my and my family's life.
This seems to be a confusion straight out of a five-stages of grief denial of GDPR principles.
Let's work this through:
Step 1: Are you collecting personal data?
Step 2: If so, are you obtaining consent prior to collecting this data?
Step 3: Are the instructions to the users transparent and understandable?
Step 4: Is your system designed to handle these?
Or is it hard, and since we haven't had to do it before, I would like to get out of this requirerment?
Additionally, the controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.
Thanks.
The chrome team is clearly in the wrong here, and it will take some time for them to realize that they screwed up and that they need to fix it.
This isn't "clear" to me. There are certainly complaints about this change within HN, but there are also people here saying that they appreciate the change, or that they're ambivalent.
But the more important part of things is that HN has what, maybe 10000 active users? Chrome has over a billion. Even if every HN commenter was vehemently against this change, that's less than 1% of 1% of Chrome's user base. If this change makes the browser better (using whatever metric you want, I'd argue the correct one here is privacy), even marginally, for the average user, at the cost of a few people believing that the browser is behaving badly, that seems like an overall good change, doesn't it?
And that seems to be what the Chrome team is arguing, that while some "abnormal" users might see this as an attack on privacy, it isn't, and it's a privacy increase for the uninformed user.
I think I've seen exactly one potentially compelling argument, which is that it may now be easier to accidentally enable syncing when you don't want to, since its a single click instead of entering a password. That might be true, although I'm not 100% certain, since I've logged into the wrong chrome window before, and that would have enabled syncing in a previous world.
Consider the case of two users, Alice and Bob. Alice has sync enabled, Bob does not.
Bob wants to check his email on Alice's computer, so he logs Alice off and logs into to his account. This syncs across all website he visits (due to shared auth cookies), but doesn't sync to the browser itself. Chrome is still logged into Alice's account, so Bob's browsing history is synced, but to Alice's history. This can have any number of unwanted consequences, from privacy consequences to Bob depending on whether or not you think Alice or Google are bad/compromised, to weirdnesses for Alice when she tries to check her history again.
Post this change, Bob logging in to Gmail on Alice's computer will log out of Alice on Chrome, and log in to Bob, meaning that Bob's history is no longer synced. So for Bob, this is a privacy increase (since now Google and Alice have less access to his browsing history) in that situation, and a usability improvement for Alice.
You could maybe get a similar effect by having account consistency be a thing that always logs the current user out and only also logs you in if you opt in, but that can also I think lead to weird situations for everyday users.
In other words, the point of signing in is to make sure no one else can accidentally (or intentionally) siphon away your browsing history.
To me that seems like a decrease in privacy.
Notably, synced data would have been visible in myaccount.google.com already, and if he had syncing disabled, I don't think there wouldn't be any data synced with his account to view.
In other words, assuming Alice was nefarious, yes this is still terrible, but I don't think it's just still terrible, not worse terrible.
Edit: I'm rate limited, but to clarify, yes syncing is an account wide setting, hence you need to be authenticated to a specific account to change it. The entire point of syncing is to sync data between browsers on different devices.
That makes no sense at all unless syncing is an account wide setting instead of a browser setting, and it's pretty clear that this is a browser setting. Bob could have syncing enabled on his primary computer, log into gmail on Alice's computer where it then logs him in to her browser but without syncing enabled, and then Alice can later on come in and enable syncing by hitting the blue button.
Frankly it sounds like what Google should have done is created a better security system rather than a better notification system. This solves nothing, creates more problems, and pisses people off at the same time.
Doesn't work. Between the cookie pop-ups, update notifications, and "you've got mail"s, people have learned to ignore pop-up notifications.
... of course, the real problem here started with "Bob checked his email on Alice's computer." There are so many ways it can go wrong, like Alice using a browser other than Chrome, Bob using an email service other than GMail, or Alice deliberately installing a keylogger on that computer...
Don't do that then.
There's a simple solution to this conundrum, but it involves google not hoovering up the browsing history of half the world by default. Unsurprisingly, the google team has decided not to implement that solution and instead has tied logins on a web page to logins in a browser ever more tightly, and this move is just another step on that road, until you can tell yourself that 99% of the world logs in to the browser, because it's just easier, so we'll make it opt out instead, and then by a series of small incremental steps, each of which seems reasonable, you're forcing users to log into google and send them your data to get any browsing done at all.
Logging in to the browser is the problem here, not the solution. You should log in to websites, not the browser, that separation is a good one and is there for very good reasons.
But I'll bite. In the scenario you just described, can't Alice still just look at her local history and get all of the same information? I just tested -- local history is accessible across accounts in Chrome 69.
So this change doesn't actually protect people who are sharing computers -- a private browsing session is what protects them. And this change doesn't make private browsing any easier.
Also in this scenario, if Bob isn't checking his email or something, he's very unlikely to go log Alice out of her account. So the extremely minor privacy boost that doesn't actually exist because all of Bob's history is still stored locally will still only happen if both Alice and Bob use Gmail.
Which makes it sound like this entire feature was the brainchild of some executive who genuinely can't comprehend someone borrowing a computer and not immediately signing into Gmail. A much better solution to the problem you're describing above would be to draw more attention to private browsing sessions in the UX, or to just have some kind of notification when the user signs out of Gmail.
Heck, you could have the same exact feature, except drop the auto-login part and only have the auto-logout. That would still be a useless feature because of the reasons above, but it would get rid of the vast majority of the privacy concerns the tech community is currently raising.
Auto-login is not necessary to fix the problem you're talking about.
How about this scenario:
Alice has Chrome synced to her Google account on her PC.
Bob uses Chrome on his PC but has no Google account and does not log in to Google services. He does uses bookmarks though.
Alice visits Bob and borrows his PC to check her gmail, which logs her in to Bobs Chrome. Then either Alice at that time or Bob at a later date accidentally triggers sync in Bobs Chrome.
TWO bad things happen at this point.
1) all Alice's synced data is downloaded onto Bob's PC. Including her bookmarks and passwords
2) all Bob's bookmarks are synced with Alice's account and Chrome on her PC will download them next time it's online.
I agree with you that this would upset Alice when she wants to check her personal browsing history. But isn't that the innate consequence of sharing your own computer with other persons? It is the same as Alice lending her MacBook to Bob without logging out herself first. Can't Alice simply log out her Chrome before giving to Bob?
Bob logging in to Gmail on Alice's computer will log out of Alice on Chrome, and log in to Bob
Why should Gmail (or any Google service) be so special? If Bob log in to his Outlook account, shouldn't the same treatment happen (which clearly indicate a persona switch)? It is clear that Google is using its monopoly power between Google services and Chrome to reinforce the bond between "average users" and itself. Imagine if Chrome dwindles at ~10% market share instead. Do you ever think the Chrome team would have done this feature?
I am sorry but "abnormal users" is just funny. Who is "normal" and cares about privacy?
As written this feature enables special privileges unavailable to other website developers via a direct integration with the browser. Imagine if some other company automatically added a feature directly to your browser without your consent. You would be rightfully angry if there was a yahoo/facebook/microsoft widget that you didn't approve being added to your toolbar. What's stopping the chrome team from adding more features to blur the line between the browser and google services?
There are boundaries between websites, browsers, and users that should not be violated. This is nothing more than google putting their thumb on the scale to unfairly influence user behavior in their interest.
First off, since it applies to people logged out of Chrome and it forces them to log in it increases, not decreases, the chances of someone accidentally leaving their account available to others on the machine. Since the sync button no longer requires a password this means someone can log in at a library to check their email, walk away, and someone else can step up, hit the sync button, and steal all of their information.
They've just made people less secure, not more.
But lets take your argument and assume it's right. You could apply the same logic to every website on the internet- Amazon, people's bank accounts, phone companies, etc. Google is therefore abusing their status as the browser developer to give themselves special functionality that other websites can't give. This should open them up to a variety of antitrust actions (particularly in the EU).
At the end of the day this could have been done by letting people opt-in to the login. Add a button on the google login sites that say "log into browser as well" and let the people who want it click it.
I'm still against this Chrome change for the same reasons, but I would hope other libraries do the same thing as we did. From my experience library tech people are usually really privacy focused.
In my experience, 9 out of 10 libraries, copy shops and internet cafés don't do this [properly].
As a public entity we had a mandate to protect user information and make sure it wasn't stored by us or accessible by others. This applied across the organisation from what books someone checked out to what websites they visited.
Maybe this was just more of a thing in Canada or even Alberta but the concept was definitely agreed upon with other libraries and people in the system I was in contact with. I have read other articles and such from American libraries about protecting information so I assumed it was more widespread.
Before, if you were logged into both Chrome and Gmail, you could log out of one and forget to log out of the other. Now, logging out of a Google site also logs you out of Chrome.
> Since the sync button no longer requires a password this means someone can log in at a library to check their email, walk away, and someone else can step up, hit the sync button, and steal all of their information.
If you have access to someone's email account, you can already steal quite a lot of information.
How does automatically signing me into Chrome improve my privacy?
More importantly, doing so without users clearly knowing and consenting to it is a clear violation of GDPR. This is an absolute, not a relative standard. Which means that it doesn't matter how it compares to what things were like before.
This for Google could be up to a $2 billion fine. 2% of worldwide annual revenue - annual revenue is around $100 billion. It would only take 13 fines per year of that size to reduce Google to not being profitable.
So you shouldn't think about it as a question of opinions about UI design. Instead think about it as a question of liability. Do you as an employee want the people working on Chrome to be subjecting your employer to this kind of legal risk?
If this change did that, I might be inclined to agree with you. But as far as I know, it doesn't. You still have to explicitly opt in to syncing. Which is a no-op compared to the old behavior.
Does this change your opinion?
>I think I've seen exactly one potentially compelling argument, which is that it may now be easier to accidentally enable syncing when you don't want to, since its a single click instead of entering a password.
Personally, though, (and I want to highlight that this is just my opinion as a person) I don't think it's a regression. But I can understand why others might disagree. From what I've read, the old behavior was that logging in enabled syncing by default. So accidentally logging in would immediately sync things.
I've certainly made the mistake of logging into the wrong account in the wrong chrome window, so I could absolutely see a user making the same mistake previously.
But even if you disagree, I think "you can synchronize by mistake, so they should add a confirmation dialogue" (which is a change I would support!) puts this firmly into the realm of imperfect UX and not an attack on privacy that should be totally rolled back.
And the aggravating (and potentially harmful) thing is that we can't even approach the discussion of "should we add a confirmation box", which would address the UX issue, if the accusation is that it's an attack on privacy. First we have to have this long tiring discussion where people throw around words like "Orwellian" and "GDPR" and we get to the reality that people are complaining about a whole host of not-really-harmful things, and that the one actually-maybe-harmful thing is a confirmation dialogue.
For a cautionary note, consider carefully how Microsoft got away with losing antitrust lawsuit after antitrust lawsuit and laughing about the consequences...until the EU decided to raise the stakes on them. And then read https://www.cnbc.com/2017/06/27/the-largest-fines-dished-out... to remind yourself how the EU thinks of Google.
Now I personally am opposed to the EU approach. (The upcoming copyright laws are particularly worrisome to me.) But at some point Google is going to need to leave the EU, or else to follow EU law. I don't believe that Google is willing to exit the EU. In which case you should really be worried about parts of Google that are putting the whole company at risk by violating EU law. No matter what you, personally, think of said EU laws.
> The personal information that Chrome stores won't be sent to Google unless you choose to store that data in your Google Account by signing in to Chrome.
If what you are saying is true- and will remain true for the future- why didn't they change that language to say something like-
> The personal information that Chrome stores won't be sent to Google unless you choose to store that data in your Google Account by signing in to Chrome and enabling syncing.
[1] https://www.google.com/chrome/privacy/#signed-in-chrome-mode
Seriously though, searched for "signed in" (like, ctrl-f). There's an epic ton of things that they are allowed to do for signed in accounts versus normal browsing even with sync disabled. These are all directly quoted from the privacy policy and do not require syncing to be enabled-
* If you are signed in to a Google site or signed in to Chrome and Google is your default search engine, searches you perform using the address bar in Chrome are stored in your Google account.
* Payments. If you are signed in to the Chrome browser and you have credit cards stored in your Google Payments Account, then Chrome will offer you the option of filling those cards into web forms. In addition, if you enter a new credit card into a web form, Chrome will offer to save your credit card and related billing information to your Google Payments account.
* Language. In order to customize your browsing experience based on languages that you prefer to read, Chrome will keep a count of the most popular languages of the sites you visited. This language preference will be sent to Google to customize your experience in Chrome. If you are signed in to Chrome, this language profile will be associated with your Google Account and, if you include Chrome history in your Google Web & App Activity, may be used to personalize your experience in other Google products. View Activity Controls.
Note the "or". If you're signed into Google and you do a Google search, that's stored in your account by default. The only reason signing into Chrome is relevant is that that also signs you into Google.
> * Payments. If you are signed in to the Chrome browser and you have credit cards stored in your Google Payments Account, then Chrome will offer you the option of filling those cards into web forms. In addition, if you enter a new credit card into a web form, Chrome will offer to save your credit card and related billing information to your Google Payments account.
This doesn't suggest any data being sent to Google unless you accept the offer to save a card to your Google Payments account.
> * Language. In order to customize your browsing experience based on languages that you prefer to read, Chrome will keep a count of the most popular languages of the sites you visited. This language preference will be sent to Google to customize your experience in Chrome. If you are signed in to Chrome, this language profile will be associated with your Google Account and, if you include Chrome history in your Google Web & App Activity, may be used to personalize your experience in other Google products. View Activity Controls.
Okay, this is one actual example of signing in causing more data to be sent to Google than would happen otherwise. It seems pretty benign, though.
> > * If you are signed in to Chrome and Google is your default search engine, searches you perform using the address bar in Chrome are stored in your Google account.
If you are signed into the browser but aren't signed into Google this states it will still save your search query.
Well what percentage of those billion users understands what's going on, versus the 10000 users here? Google's business model does depend on duping people who don't know any better, so maybe this isn't so surprising..
In any case, I don't think there'd be so much uproar if Google hadn't snuck the change in without telling anybody. There are release notes, why not use them? Why is that so hard to understand for a company that prides itself on hiring the best and brightest?
That's just how you make unpopular changes these days.
Maybe the EU will do something about it, but this will take years.
As a Googler, you should encourage your colleagues to read negative and critical coverage of your company and its products. It might be eye-opening to many of them what people actually like and dislike about the products they're building.
I imagine the internal mailing lists are going to be a fun read the next few days. I was on similar mailing lists in Nokia when the iphone launched. I'll spare you the details but Nokia suffered from a similarly bad case of confirmation bias and it was decision making based on that in the years before and after that ultimately led to them getting out of the phone business entirely a mere 7 years after being the dominant market leader (and not by any small margin). Confirmation bias kills companies.
Anyone from Google/alphabet still capable of making a difference reading this, here's some free advice: sort out your management ASAP. This is one of those issues that stems from a lack of leadership. Heads need to roll, especially the ones doing too much nodding. I'd start at the top. I've had my doubts about the current CEO for a while. Too invisible and stuff like this keeps happening on his watch. Also the product portfolio seems a mess lately. There's something wrong there and current leadership is part of the problem.
When you have 1 billion users, I think it's easy to say that "most of them are better off" with whatever, because there's no possible way that you'll ever have a majority of your 1bn users arguing for or against anything. This is why watchdog organizations exist, and why they're so important.
Doing the "right thing" for 99% of your users isn't actually the right thing if it does harm to your most vulnerable users.
But aren't the most vulnerable users the one who actually aren't tech savvy? And, arguably this change may actually make things simpler for them.
I'm not sure. Not one person in the entire chrome team raised their hand and explained that some users expect their browser to firewall web pages from the browser itself and to keep neutrality and not privilege some (first party) web pages?
I give them the benefit of the doubt on their intentions (although I'm less sure about upper management). But regardless of their intentions, they need to get better at thinking ahead.
Situations like this are always a little complicated, so I don't want to oversimplify or claim that they should have been psychic. But... it really shouldn't have been hard to tell that people would be upset. I kind of feel like if nobody on the Chrome team could have predicted this, then the Chrome team is seriously out of touch with users.
I mean, heck, the change contradicted Chrome's own privacy policy, which had to be updated after the fact. Is there seriously no process to check stuff like that before features ship? How is anyone supposed to trust Google's privacy policy when any team can break it inadvertently and it takes a Twitter thread weeks later for them to find out?
The Chrome team has a nasty habit of simultaneously saying, "just trust us, we're experts, we know what we're doing", and "there was no way we could have predicted that users would be upset by this."
Both of those things can't be true.
Unless you are actually offering a job at Google, it's not a reasonable train of thought, it's a (somewhat pissy) cop-out.
This argument makes sense when you're talking about a problem that one or two people control rather than a large system with higher stakeholders who may not have interests aligned with your own.
But I'll assume you're right for a sec. Let's assume that Google cares a ton about making sure their privacy policy is consistent, but it's just an insanely hard job and nobody could do any better.
Why does that matter? In that scenario, I still don't trust your privacy policy. I don't care whether it's inconsistent because people are incompetent or because the problem is hard. In either case, the privacy policy is unreliable. If I can't trust it in Chrome's case, how can I trust it in Gmail's case, or in Adword's case, or in any other product?
In a way, saying it's a hard problem is even worse. I would have felt better if you had come back and said, "oh, the Chrome team is just uniquely incompetent, but everybody else has got their stuff together."
But then again, I'm neither in privacy team, nor Chrome team, know no specifics of this case and can't really argue any position (note how I'm neither defending nor condemning the issue of OP). Just pointing out generalities that I don't see mentioned.
If Google itself isn't acknowledging the problem, or worse, if Google is actively thwarting or working against its own privacy team, then anyone who gets involved will also end up starved for resources or moved to other teams. Google is not a level playing field for people who want to change the system from inside.
So it's not wrong at all for you to bring this up during an incident. But if we take the premise that this incident is the result of one of the largest companies in the world starving its own privacy team, not paying enough to attract talent, or not giving them enough input into internal processes... well, that's honestly something that needs to be discussed company wide. That's a very serious situation.
And if that's the case, users should be distrusting Google's privacy commitments until it has that conversation. The first step to fixing a problem is acknowledging the problem -- you won't get anywhere trying to fix a system that doesn't want to be fixed.
From the responses that have come out of Google regarding this incident, it doesn't sound much like it wants to be fixed. Changing that is the first step. Hiring people is the second.
By all means, let's talk about Google's privacy team. I am all for that. Let's get productive. But let's get actually productive. Let's have an open, public talk about management and resource allocation, and why the team is understaffed. From Google's AI/self-driving divisions, we know what it looks like when the company gets serious about attracting talent. And we know it has the resources to do so.
And the feature might be fine, but the UI is not good. It's confusing whether the big "sync" button says you are syncing, or lets you start syncing. And as this article says, when you go into "options" instead of clicking "undo", it starts syncing...
Most of the discussion here is about why people don't like the new Chrome feature -- but is it actually in violation of the GDPR?
But, if I was responsible for GDPR in Chrome I would be very worried that they are conflating "signed in" and "syncing" some places in the code, since this appearently used to be the same concept, per the old privacy policy.
Confused, what do you mean? To me thinking that my data isn't being synced when it really is sounds much worse...
Edit: what I mean is, there's no way to get the interface into a state where it looks like you're not logged in, but it is syncing in the background. The only confusion here is in the other direction: you're visibly logged in, but it's not syncing.
Sure, it doesn't automatically sync your browsing history now, but we all know change happens gradually. It's just a "feature" to be enabled later.
I've never once signed into chrome in my life (on purpose). I don't want anything synced between browsers, I like to try and limit what gets kept in the cloud, and with this change they've simply just taken the option away from the user.
Yes, I'm sure that I'm in the minority, but I'm taking this opportunity to start switching to Firefox, switching my mail provider, and am hoping to send them a GDPR request to delete all of my data.
It's not necessarily just this issue that made me do it, it's just the tipping point for me that says.. "ok, this company has gotten too big off people's data, and i no longer wish to be a part of feeding that machine"
Just my 2 cents.
(You might feel that this is a tipping point but it's still not a GDPR issue as far as I can tell.)
> The personal information that Chrome stores won't be sent to Google unless you choose to store that data in your Google Account by signing in to Chrome.
That doesn't say "unless you enable sync", it says it changes "by signing in to Chrome". Since they're now forcing you to sign into chrome without your consent they are also forcing you to accept that they can send your data to their services without needing any additional permissions from you.
> Signing in enables Chrome’s synchronization feature.
This is no longer true, so it seems most likely that that entire paragraph is simply out of date.
At the jobs I've been in since browser syncing became a thing, where there were internal web tools, there has been an explicit policy against enabling it, out of security concerns. Regardless of how good the security might be at Google or Firefox etc. around their syncing stuff, if the content isn't there, it can't be compromised.
If that's really all it is, I don't really get what people are upset about. Specifically, if there's no additional data being stored connected to your account (which is what one of the devs seemed to be very explicitly claiming) until you deliberately connect Chrome to your account, this seems like a whole bunch of drama over a misunderstanding.
If I'm wrong, then that's a separate matter. Personally, I appreciate the syncing features, but I completely understand why people would be bothered, and it's definitely something they should roll back.
The turn on sync thing is already reported to be a dark pattern.
https://twitter.com/nikitab/status/1044314072706158593
Meanwhile: whatever color you want to shade in the "pattern" with, this subthread starts with a claim that is falsifiable, and also actually false. So please don't pretend like I'm arguing from abstractions here.
Still there are the claims of buybackoff that I linked above that options has been set without their consent.
So it seems to me there's either a muddy pattern or they even are tweaking things on behalf of users whitout even asking?
Edit: also this from the post we are discussing:
> However, by clicking on “settings” I was unable to click “undo” - the user interface happily assumed that yes, in fact I wanted to first upload my data. And suddenly, instead of “Last time synced in 2017” I saw the following: “Last time synced on Today”.
Wait, WHAT? Are you talking about locally or in sync? I don't believe Sync ever included cookies, and there's no indication on the Clear Browsing Data tool that Google cookies won't be cleared if "All Time" is selected.
My understanding is that there were two changes:
1. General responsibility for authenticating to Google services has been moved to Chrome, and being logged into Google is equivalent to being logged into Chrome. If sync is set up, logging back into Google also fixes your sync session, if it was broken (common — the warning in the toolbar is easy to ignore).
2. Sync has been separated from login as a Chrome feature, so that you can log into Google services without syncing Chrome’s data.
Confusion between being logged into Google (the Chrome new tab page looks a heck of a lot like the Google home page) and being logged into Chrome was a real problem. I’m not suggesting that this is the right solution… or the wrong one; this is weird territory.
It raises a question for both users and browser vendors: What does it mean to be logged into a web browser?
And who - exactly - ever asked for the ability to "log into a web browser"? And what benefits are there for the user?
There would be zero confusion about "Am I logged in to Google or logged in to Chrome?" without the unwanted and unexpected existence of a "logged in to a web browser" status.
This is privacy disaster over a feature nobody wants. Except for the people who actively profit from privacy disasters...
https://chrome.google.com/sync
I appreciate people have different concerns, but also just completely fail to grasp them in this case.
That's not to say I'd be miserable without it, but it's a nice convenience that almost immediately upon starting up a new machine, my browser is set up exactly the way I like just logging in.
For that matter, sync is a fantastic use of E2E encryption, and it will be interesting to see if using sync data for any purpose other than syncing it is a GDPR violation.
Which is a question so absurd that no user should ever need to ponder it. The question wasn't "raised." Your diction suggests it arose in some organic fashion and it did not. Let's be clear - the question was forced upon the user.
The existence of a gray area doesn't mean that everything is gray area.
Something like "User logs into Chrome, this automatically logs the user into ???. The user then visits ???. As a result Google learns ??? about the user. This was impossible before this Chrome change, and this sharing of information isn't clearly agreed to by the user."
If there are several materially different scenarios that can result in privacy violation, would be great to know.
Instead, because it's closed, it'll set the web identity conversation backward...hopefully it doesn't set it back too far.
The GDPR requires consent or some other legitimate reason to store data about a person.
I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine.
But cookies are not even the problem. Fingerprinting is. When I visit a hifi store with my smartphone, next day my Desktop PC will show me nothing but hifi ads. Even though I don't store cookies on any of them.
Additionally, the web turned into an arcade game. The user has to rapid fire click away 'OK', 'I AGREE', 'I CONSENT', 'I UNDESTAND' buttons. He is not giving consent. He is just trying to get through this pile of nonsense to reach the content.
I'm not trying to be snarky! It's just that I'm not actually sure I like the direction the web took, and I'm not sure these "content producing companies" are indeed a net positive.
Perhaps forcing a lot of (the more shady) commercial activity off of the web is actually the best thing that could happen. (Though they probably wouldn't leave quietly)
But let them compete without the distortion of (ab)using quite so much Personally Identifying Information, and see if you'd still be happy to!
Europe is playing a dangerous game with the internet right now and I don't think they have enough tech-minded people in power to keep things sane and in check.
*conditions apply: everything you say and do is tracked by a multitude of companies and poorly secured.
So yes, technically you're right. As Discworld's Vetinari said, you always have a choice, even if that choice is between agreeing to the deal or being thrown into a spiked pit.
It's pretty much the same story every time, there was a big scramble to fix any clear violations, but because GDPR was a bit vague, there are a lot of gray area violations that are still being cleaned up.
Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.
I just say that pretty much every site, device and service out there violates the primary rule of the GDPR. They all store data about their users without the users consent.
One of the main points of the GDPR is that the user has to actively agree to storage of data. Making it very clear that storing can not be the default. Yet when you visit the New York Times today, they tell you:
By clicking "I Accept" or "X" on this banner,
or using our site, you consent to the use of
cookies unless you have disabled them.
In one form or another every site, service and device out there is doing exactly this. Making it the default to store data about the user.Are you proposing that trying to make money using the internet is morally wrong? Or just that collecting user data is wrong? Or that collecting data without consent and a clear explanation is wrong? Because if the line is drawn at the latter, then that’s what GDPR is for, and so I don’t understand why people would be upset about having to click through a bunch of notices that try to make it clear how user data is being used.
Not inherently.
>Or just that collecting user data is wrong?
Yes, under any and all circumstances. The security implications alone are staggering.
It says: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract. "
It's like a butcher shop saying "the meat could be free if we could only reduce our cost by not caring about hygiene".
Edit: oops, the methaphor doesn't work at all :-D
The GDPR does have a requirement to ask for consent to do things like tracking my interests/behavior on a site and sending it to marketing data companies for specificly named purposes. I have yet to find the first website that uses plain language when asking for consent, and I can't wait for the first fines to be handed out.
https://en.wikipedia.org/wiki/EPrivacy_Regulation_(European_...
Not really, my website doesn't :-)
In case you're using Google Analytics, it's easy to make it compliant, you just activate IP anonymization, which you had to do anyway, out of common sense and because tracking by IP without consent was illegal anyway in countries like Germany.
[1] https://support.google.com/analytics/answer/2763052
[2] https://developers.google.com/analytics/devguides/collection...
> When I visit a hifi store with my smartphone, next day my Desktop PC will show me nothing but hifi ads.
Yes, I saw this behavior too, but I like to think that many businesses are not as unscrupulous. But I do take care of my privacy as an ongoing investment ... I'm Google free, I sandbox Facebook, I use privacy blockers, VPN, the works.
GDPR is IMO a godsend. I'm sure the cost will be high for many companies, but that's just karma.
What about for companies that do handle user data responsibly, but have trouble with the formal compliance costs?
There's also no such thing as responsible data handling for services tracking users without their consent. If no explicit consent was given, consent obtained with a layman explanation and with no dark patterns, then it shouldn't be legal.
The problem often isn't how the data ends up being used, the problem is that the data is collected in the first place.
(Argument hinges on the idea that GDPR does overreach in what it asks to be compliant, happy to be proven wrong)
re the aip=1 feature: https://news.ycombinator.com/item?id=17167346
why masking the least interesting byte isn't anonymous: https://news.ycombinator.com/item?id=17170468
As for you watching a video and autocomplete coming in with the same topic, could it be that there was a surge of interest of that battle at the time? Otherwise it may be url analysis from other people searching through chrome.
> In line with privacy policy, this could be the case. However, data synchronisation appears not to happen by default in practice (as also confirmed here). It seems this behavior is not accounted by the privacy policy, which means either the policy is obsolete (and needs to be updated, which suggests potential issues in the internal privacy program, and possibly the priorities), or the mechanic may be subject to change in future.
It may have been updated in the last few hours, but right now, the privacy policy clearly specifies that that section is for the "Signed-in, Synced Chrome mode", and that "Sync is only enabled if you choose". Just signing in does not automatically enable sync.
(Obviously Google would never do this.)
It really frustrates me when applications try to guess what I want, and do things without asking. Computers are fun and interesting because they do what you tell them to do! When they do what someone think 90% of people want without asking you, they are oppressive and depressing.
Lastly, it feels like Google wants to trick me into giving them my browsing history by mistake.
So, all in all, I'll uninstall chrome from my personal computer.
stuff like this are the primary reasons I:
1) use Chrome only for work - hey, it's new IE
2) don't use Android
and recommend against using these to all my friends and family, carefully explaining everytime that if they care about their data they should stay away from these services.
If we take all of googles privacy controls and privacy policies for the truth, they now have an additional way to track me and I can't disable this without completely missing out on any other google service. This propably also circumvents any installed cookie blockers (but only for google) which could be interpreted as not honoring the denial of tracking.
https://chrome.google.com/webstore/detail/incognito-filter/c...
This way I can log into Gmail and it won't log me into Chrome.
Obviously not ideal, and it doesn't excuse the deceptive and user-hostile malware Google just foisted on us, but it's a workaround.
By the way, what's an alternate email service the HN users recommend?
edit: to be clear i'm not knocking either option. im just supporting my original point -- that google's recent actions do not threaten its email dominance
I left ProtonMail because it was slow and lacking features. Their reason for their snail pace of feature releases seems to be "we put security first".
Edit: Also, with ProtonMail as a paying customer, by default my signature was set to "Sent from ProtonMail". How cheesy. I'm paying for their service, they shouldn't be using me to advertise.
> from a variety of partners, including Oath (formerly Yahoo) and Bing
https://duck.co/help/results/sources
I remember Yandex being one of the sources as well.
So unless you're searching in Russian, DDG is essentially a reskin of Bing search.
https://posteo.de/en (I'm not affiliated with them except as a customer)
"Google simplifies the login experience in Chrome", is essentially what's happening here and it's far from obvious how to sell it as a doomsday scenario as I read the mood correctly of many HN users.
Even inside of this tech bubble there are people like me that think this change is fine the way it is and that it's actually a good idea for convenience. The vast majority of people are using Chrome to go to Google websites using their Google account and having one less step to sign in to Chrome Sync is just a good thing from a usability perspective.
The people who think they can speak for their parents or the less technically inclined are being too presumptuous in my opinion. YOU may have a problem with these methods, but not everyone does. Heck, there's people as technical as you that still don't have a problem with it.
But I also wish we lived in a utopian society where all information, people, companies, govt. was public and there was no weird illusion of privacy that everyone is clamoring for.
I long accepted privacy on the internet doesn't exist, and mostly privacy off the internet is minimal, especially with all the technology around. If you want privacy, you need to live like the Amish.
So, I just accepted it, and now don't care about privacy breaches, giving all my data to google. I willingly give more data to google so they can make my life easier.
I get hopefully 100 years on this planet, I am not going to worry about privacy when I got better things to use my limited time and energy on.
The same thing is happening with surveillance and spyware and the self serving 'users don't care' that many tech apologists use to distract from their stalking and lack of ethics is already out of touch and disconnected from increasing mainstream awareness and disgust with surveillance.
Just yesterday Craig Newmark announced a $20 million donation to a new publication modelled on propublica to examine tech surveillance. It's only a matter of time before surveillance implementors and apologists begin to look like the sellouts that they are in the public eye.
Unless there's a compelling benefit for me as a consumer, then I think Google wasted a lot of engineering hours and talent building something that majority of people would want no part of.
$250,000 - Chrome RCE + SBX (Windows) including a sandbox escape (previously: $150,000)
Whereas it's up to $100k for Edge RCE+SBX, $80k for Firefox RCE+SBXYou obviously need to factor in other things such as how popular the product is compared to competitors, etc., but such a drastic price difference such as this is quite telling.
Another thing to take in consideration is the number of people that the exploit could be used against. For example, following this: http://gs.statcounter.com/browser-market-share/desktop/world..., Chrome would have almost 68% of the browsing share whereas Firefox is only close to 10% and all the others even less. It'd be surprising this isn't taken account by Zerodium in their price calculations!
______________________
we did the cost analysis of the later and decided it was too expensive at the time. a few months later google dropped firefox support and invested heavily on chrome.
I guess someone there did the same analysis. because everything to this point is right on the plan. they block auto play video ads, just not theirs. they block flash ads, just not theirs. they will implement tracking protection like firefox rolled out last month, but before they will keep you logged on their ad systems forever.
Let me just spell out, for emphasis, what the article actually says:
* Logging in to a Google service via its website will now automatically show you as logged in to Chrome in the top-right corner. This will provide you with the OPTION to explicitly opt-in to syncing your browser data with the Google cloud by clicking a big blue button that clearly says "Sync as <firstname>" and then clicking through one of the two clearly-labelled options to confirm that you do indeed want to turn on sync in the following dialogue (which does in fact have a prominent "Undo" button in case you clicked by mistake).
* The entire extent of the alleged practical user privacy issue is that a user might accidentally click the first button, and THEN mistakenly click on the small "Want to manage sync and personalisation before they're turned on? Visit Settings." link instead of the larger, more prominent "Undo" button. This, the blog alleges, will turn on syncing without a chance for the user to undo. (Although, at least as of 69.0.3497.100, this is just plain false - there's an "Undo" button even on the settings page. It may have previously been true; I have not checked.)
* The entire extent of the alleged GDPR violation is that the privacy policy erroneously says that when you sign into Chrome with your Google Account, data is synced with Google's servers, when in reality it isn't unless you explicitly consent. (This was true at the time that the post was written, but the privacy policy was tweaked to correct the factual error - compare https://web.archive.org/web/20180924020748/https://www.googl... vs https://web.archive.org/web/20180924123556/https://www.googl...) For what it's worth, I see no reason why briefly and accidentally claiming to process some data in a consent-ignoring way when you don't actually do so would be a GDPR violation, and the article does not elaborate on this particular legal theory.
Other commenters here have already explained that this change offers security/privacy benefits to some users by protecting them from a failure mode in which they wish to sign out of Chrome on a shared computer (in order to not sync their browsing history to a friend's or family member's account), but instead they only sign out of, say, Gmail, and thereafter end up inadvertently syncing their browsing history and passwords to their friend's Google account instead of their own. Connecting the browser login and Google web service login eliminates that privacy-violating failure mode. That seems like a real gain to user privacy and security to me, and it seems plainly absurd to argue that it's actually a loss on the basis of a hypothetical in which the user accidentally clicks through clearly-labelled buttons in two different dialogues and therefore accidentally enables syncing. That seems doubly true given that even in that hypothetical scenario, syncing can, per the article's own admission, then be immediately disabled (and all synced data deleted).
I'm not an uncritical fan of Google, but criticising them for this is bullshit.
That may still enable undesired cross-website tracking for Google Analytics or whatever?
- screen resolution,
- browser add-ons installed,
- ip localization
- etc
It is called digital print i belive.
From a security and privacy standpoint though there are possible implications when a tech-product/service is owned/controlled by a Chinese company. China’s influence on it’s businesses (especially tech related) can’t be denied. It wouldn’t surprise me one bit if news would break that the Chinese government has it’s hands in Opera’s cooking pot somehow.
Sorry if I have offended you but that’s just reality. I don’t trust Chinese tech companies.
apple is lauded for the security and privacy of the iphone but it is manufactured in china. could china have their hands in that "cooking pot"?
if there were some kind of subterfuge occurring with opera at the hands of the chinese government, it would be newsworthy indeed.
And I do take offense at being called xenophobic and won’t further participate in this ‘discussion’.
> “Processing shall be lawful only if and to the extent that at least one of the following applies: […] (f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”
And
> “The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems, […] by providers of electronic communications networks and services and by providers of security technologies and services, constitutes a legitimate interest of the data controller concerned. This could, for example, include preventing unauthorised access to electronic communications networks and malicious code distribution and stopping ‘denial of service’ attacks and damage to computer and electronic communication systems.”
Are you storing IP's for a certain time, so you can discover and investigate attacks?
> include preventing unauthorised access to electronic communications networks and malicious code distribution and stopping ‘denial of service’ attacks and damage to computer and electronic communication systems.
Are you storing IP's for a certain time, so you can run analytics?
> Further processing for [...] statistical purposes should be considered to be compatible lawful processing operations.
Are you doing direct marketing to your customers?
> The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest. [Legitimate interest] There is a relevant and appropriate relationship between the data subject and the controller [...], such as where the data subject is a client or in the service of the controller.
If you are not big enough to have a law department look at this, you don't need to worry so much about a weblog.
Put in a blunt way - Looking at my logs, I am not trying to identify Mr William Butterscotch living at 22nd tower street, third floor, second door on the right. I'm trying to figure out if a set of IPs is actively scanning or ddos'ing my systems. Especially because these IPs might actually not be connected to any human at all - think of botnets just roaming the ipv4 space.
Is the IP personal data for the GDPR? If I read the GDPR, the Debian foundation is not capable to pinpoint 1 person so it seems to me it is not (An ISP or someone receiving an IP to person mapping from them is something different):
‘personal data’ means any information relating to an
identified or identifiable natural person (‘data subject’);
an identifiable natural person is one who can be
identified, directly or indirectly, in particular by
reference to an identifier such as a name, an
identification number, location data, an online identifier
or to one or more factors specific to the physical,
physiological, genetic, mental, economic, cultural or
social identity of that natural person;
Furthermore, the Debian foundation has a legitimate interest in monitoring their machines and protecting them against attacks. Logs containing IPs are a common practice, so there is a legal base for processing IPs even if they would be personal data: processing is necessary for the purposes of the legitimate
interests pursued by the controller or by a third party,
except where such interests are overridden by the
interests or fundamental rights and freedoms of the data
subject which require protection of personal data, in
particular where the data subject is a child.
All of this assuming they use the IP for apache logs only, and don't send these logs to third parties for data mining or whatever.However, I can't recall ever having seen this privacy policy before now. IANAL and don't know what kind of notice needs to be given for necessary data usage, if any, but maybe apt-get should display the privacy policy on first use.
https://blog.lukaszolejnik.com/am-i-logged-in-or-not-gdpr-ca...
Please update the submission URL.
If they are, all this brouhaha is from the technophile echo chamber of opinions. The average joe gives a rat's ass for this, as evident from all the non-noise coming out of the regular world. Techonopiles have made an art of outrage - typing on their $3000 laptop or $1300 iPhones built by slave-grinded employees toiling 16 hour days in China - NO HN COMMENTING ALLOWED AT WORK FOR THEM, BTW
Please go use FF & pretend to have privacy online or be better humans. Mozilla - the world leader in disappearing money [1]. Does it really take $225M to build & maintain the quantum browser? And why $135M for 'marketing'?
Mozilla 2016 revenues: $520M
Mozila 2016 R&D: $225M
Mozilla marketing: $135M
Remaining $160M - ???
[1] https://assets.mozilla.net/annualreport/2016/2016_Mozilla_Au...
Yet, the same exact thing just happened world wide in Chrome 69.
The problem is that I can't help shaking the feeling that those comments are either written by people who do not consider privacy to be a right, or fail to understand GDPR, or are Google paid shills / fanatics.
Ultimately the changes represent dark patterns and I fear the worst is yet to come for the darling browser of the web. Someone somewhere at Google made the decision to turn Google Chrome in to AOL v2.
I take solace in the fact that AOL's walled garden approach ultimately failed.
See thread: https://twitter.com/__apf__/status/1044109217903198210