> Google Chrome contains a key logger that sends Google every URL typed in, one key at a time
They are describing the auto complete feature...
I get that people should be making informed choices about what data they share, but for the FSF to so intentionally mis-describe what is going on does not help inform anyone.
I agree with the criticism that they should draw a clearer line between the cost and the benefit but there's nothing to be gained by softening the language used to describe the cost.
I use Firefox and have search suggestions disabled there so I am somewhat sympathetic to their point.
That said, calling server-side autocomplete on a field you explicitly are typing in strikes me as about as sensible and forthright as calling an Amazon text field that takes my credit card number a card skimmer.
I think the description of autocomplete as a keylogger is a good fit from the security perspective.
Exactly, and waters down the impact of the termminology. If "card skimmer" is anything that can read a credit card, than the term is meaningless for security.
If "keylogger" is anything connected to the web that responds to a keypress...
GNU is risking turning into the boy who cried wolf here.
As with a lot of the FSF's messaging, I think the substance of the message may be correct, but the way they convey it just isn't effective.
If this is for a general audience(!), no-one was ever convinced by the 48th item in a list who wasn't already convinced by the 47th. You don't persuade people just by being right, and certainly not by banging on about the very many subtly-different ways in which you're right. Pick few strong examples and prosecute those decisively.
If this is a resource for campaigners, set out the audience and intent before you start. Preface it with something like “Here are various ways that certain aspects of Google's software can be seen as indistinguishable from malware. They may be useful counterarguments if someone suggests Google's software is trustworthy.”
There's no warning that a text field autocompletes, and no reason to assume all users are tech savvy enough to realize that google has to see every character typed to send back recommendations.
Autocompleting doesn't change that.
The Amazon text field would have to send your credit card number for a credit check without telling you to compare.
It can also be turned off extremely easy, not exactly what we know as "malware" if it allows you to turn off its "malicious" activities.
On Windows asking for a handler for all key presses will often trigger the antivirus, while asking for a single application often will not.
And if you say bandwidth you're fired. It's privacy the FSF is grumbling about. And for that it's been rhetoric and theoretical suffering, but no actual real-world damage. And not for lack of adoption.
Put that cost in your pipe and smoke it.
At the end of the day, serverside autocomplete is useful, and coal is cheap!
If you're not logged in, as I'm sure FSF people are, then this is a much bigger deal, but it doesn't apply to the vast majority of people.
All that said, the keylogger would take a good deal of interpretation to get a complete or even partial history, since autocomplete choices would likely be chosen anyways, not fully typed out URL's. If they send that history anyways on any time you press enter, the autocomplete feature again doesn't matter because they have it with our with.
Also, your aggregate value argument is quite apt: It's valuable to know what percentage of a city speaks English, but the fact that you personally do or don't is of no real value at all, specifically because it's "your" individual data, not despite the fact. And insisting that you've been hypothetically robbed of your entitled half penny for disclosing your language preference to the McDonalds cashier is precisely as sensible as complaining about the value of your half-typed URLs.
Type "p" in the address bar at work?
Don't visit sites on work computers you don't want others to know about!
You've never accidentally typed a password in a URL bar? You've never accidentally focussed the browser window when typing something you don't want Google or anyone else to know?
That's basically holding my privacy hostage for what is stupidly basic UX functionality.
And it's not like I was given a choice about it. Maps used to remember your search history just fine, until they pulled that a few years ago, and I "just" had to give them my location history, so they would remember my fucking search queries.
You might recognize these tactics from heroin dealers and similar scum.
It's amazing how unnecessarily less useful Maps is, if you have to retype the addresses every. single. time. But you don't want Google to keep a log of everywhere you've been.
The Overton window has moved so far in the last ten years.
A while back we (and by we I don't mean me, I mean hackers collectively) would consider a piece of software that opened a TCP socket unless it had a real reason to malware.
Now? It's fairly common for like, webpages to send back every keystroke you might accidentally make whilst a tab is focused.
The fact that this is frequent, possibly even 'normal' behaviour does not make it sane.
You're free to disagree with the rest of the world, of course. But you might want to focus on trying to shift the Overton window. What you're doing in this comment is simply asserting that you disagree with everyone else.
Because you seem to be asserting what "everyone else" thinks.
If I ask non-technical people about this autocomplete feature and whether they would like to disable it (assuming they have this option), after explaining it sends every keystroke to Google, they (generally) will reluctantly agree to have it enabled, why?
It's not because they believe sending every keystroke to Google is a super reasonable sacrifice for having the benefit of autocomplete on search queries.
No, ask them, they will invariably sigh "Well, Google knows everything about me already, anyway, so ...".
That's NOT the reasoning of someone making a well thought-out decision, it's the reasoning of someone beaten into submission. And we know this is true, because we feel it too, every time you read a comment about somebody trying to escape the Google Ecosystem, but not yet having a satisfying replacement for this one service .. You don't get to make a fair choice about it.
That is why they say Google mistreats their users, because they made them give up, not just giving up their privacy, but giving up on their belief they even have a choice about it.
If Chrome is sending to Google every character typed into the URL bar, that's literally a networked keylogger and can presumably be used for all the same nefarious purposes as a "malicious" keylogger. The perceived value this feature provides is meaningless in the context of privacy/security.
I bet all those keypresses are stored permanently, associated with your Google account, but that's another issue altogether.
It's questionable whether Google deserves similar trust as a bank since they aren't regulated in a similar way. But it isn't unusual for people to trust companies over friends for some things, such as their life savings.
The other thing to remember is that trust can be partial. For example, I wouldn't trust a bank not to be looking for legal ways to charge me fees and I wouldn't trust their investment advice, but I'd trust them to keep their ATM's working and not to lose my money.
I do not believe that this is a thing that is true. There is no well-known history of ethical unregulated banks.
I expect we will see more regulation of the companies storing personal data, along the lines of the GDPR. I don't expect people will stop using the big tech companies to store personal data.
If you start an argument with a false premise (like the above), then sure, you can come to just about any kind of conclusion you want.
The GNU perspective is very distrustful of the idea that anyone else should be administrating their devices [etc etc]
Which is a perfectly reasonable position to have, and no one takes issue with GNU for having it.
What one takes issue with is the consistent use of manipulative language, egregious omission of context (e.g. like what was just said about Google in the post above) and other generalized mindfuckery that GNU folks seem to routinely resort to in order to get you to buy into their shtick. As exemplified in the article referred to in the original post for this thread.
And which has gotten to be way beyond old. For like, multiple decades now.
I'll never ask my friends to memorize my schedule and remind me on time. I'll also never ask Google to take care of my cat. Sounds pretty straightforward to me.
- Multinational corporations care little about their reputation - the public has very short memory, and it's rare that a reputational issue outweighs considerations like sunk costs, network effect, or lack of better alternative on the market. See literally almost every scandal involving a corporation ever.
- The larger the organization, the less individual ethical and reputational concerns of bottom-line workers matter. See literally every corporation. For particular recent examples, see e.g. Volkswagen emissions scandal or Boeing 737 Max fiasco, both cases involving actual engineers with actual careers on the line, and not just software devs risking unemployment for 10 minutes.
Note that both statements are explainable even without attributing malice to any corporation. They're side effect of scale and market power.