Companies need to start thinking of this less in the lens of "evil" and more principle of least astonishment. Would users be surprised and angry to learn you do this? Then don't.
Companies need to start thinking of this less in the lens of "evil" and more principle of least astonishment. Would users be surprised and angry to learn you do this? Then don't.
Not Google does X, but there is a market that sells X, and X can be linked to you personally by Y, Z
So
* A market exists for reselling credit card transaction data. Your card provider (ie Barclaycard) sells to companies such as $FOO who will aggregate same data from different providers and sells it for marketing purposes. The size of the market is $Billions
* Google can link the purchase history to you personally by multiple means including - reading your gmail, and looking for purchase confirmations using last 4 digits
* There is a market for reselling your mobile location and call history. your cell provider ...
I would love to see this - I honestly need reminding of this and it seems like a great press expose.
How do they connect my credit card data to my Google activity? My Google account isn't connected to my personally identifiable information in any way. I.e. they don't have my phone number, nor do I use Google Pay.
Most people have a phone number with google for gmail (you didn't need one in the beginning, but do now). There's also their wallet, app store, voice, broadband, phone plan, etc.
Some people will dodge all of that, but most won't.
> Since 2014, Google has flagged for advertisers when someone who clicked an ad visits a physical store, using the Location History feature in Google Maps. Still, the advertiser didn’t know if the shopper made a purchase. So Google added more. A tool, introduced the following year, let advertisers upload email addresses of customers they’ve collected into Google’s ad-buying system, which then encrypted them. Additionally, Google layered on inputs from third-party data brokers, such as Experian Plc and Acxiom Corp., which draw in demographic and financial information for marketers.
I just created a new Google account without a phone number 10 seconds ago. Phone number was optional and of course I didn't provide it.
If you try to sign up using Tor, for example, it's not optional.
Google makes sure that if you don't hand over your data to them, someone else will.
I guess I would need enough people to do a sybil attack on Google.
I bet this is how Places data and other stuff is hacked. How does one prevent a coordinated attack like this? Machine learning ensuring voting rings can only be used once or twice?
Linking offline purchases is harder but still doable if they buy CC data in bulk.
There are 2 pieces of information that need to be joined.Google have your cookie and email and MasterCard have your address and probably email. If both sides have your email then job done. If not then they can use your physical address via a data broker. All it needs is some e-commerce sites that allow cookie syncing and have a privacy policy that allow them to sell that part of your data.
Which personally identifiable information?
The time of day you use your devices? Which languages you use? Which websites you visit? The type of medical conditions you search for?
Information being PII or non PII isn't binary. It's relative shades of how shannon entropic it is. You need about 33 bits to identify someone, you likely have leaked 33 bits of entropy.
EFF's Panopticlick help show this: https://panopticlick.eff.org/
It is binary in Google's data structures (marked as annotations on protobufs), and in law. Things you listed aren't considered PII.
I'm pretty sure they use that to feed their models.
And 4 data points would be a lot more than usually required.
Doesn't this already exist since nobody wants to piss off shareholders?
We'll eventually have regulations cracking down on the privacy shitshow the web is today. But how many billions of dollars were made on the abuse to date, and how many more will be made still?