Google tracks individual users per Chrome installation ID
github.com
github.com
> We want to build features that users want, so a subset of users may get a sneak peek at new functionality being tested before it’s launched to the world at large. A list of field trials that are currently active on your installation of Chrome will be included in all requests sent to Google. This Chrome-Variations header (X-Client-Data) will not contain any personally identifiable information, and will only describe the state of the installation of Chrome itself, including active variations, as well as server-side experiments that may affect the installation.
> The variations active for a given installation are determined by a seed number which is randomly selected on first run. If usage statistics and crash reports are disabled, this number is chosen between 0 and 7999 (13 bits of entropy). If you would like to reset your variations seed, run Chrome with the command line flag “--reset-variation-state”. Experiments may be further limited by country (determined by your IP address), operating system, Chrome version and other parameters.
> This ... header ... will not contain any personally identifiable information
> a seed number which is randomly selected on first run ... chosen between 0 and 7999 (13 bits of entropy)
They are not including any PII... while creating a new identifier for each installation. 13 bits of entropy probably isn't a unique identifier iff you only look at that header in isolation. Combined with at least 24 additional bits[1] of entropy from the IPv4 Source Address field Google receives >=37 bits of entropy, which is almost certainly a unique ID for the browser. Linking that browser ID to a personal account is trivial as soon as someone logs in to any Google service.
> Experiments may be further limited by country (determined by your IP address)
They even admit to inspecting the IP address...
> operating system, Chrome version and other parameters.
...and many additional sources of entropy.
[1] why 24 bits instead of 32? The LSB of the address might be zeroed if the packet is affected by Googles faux-"anonymization" feature ( https://news.ycombinator.com/item?id=15167059 )
> They even admit to inspecting the IP address...
I don't think that sentence admits what you say? Chrome could be determining which experiments to run client-side.
Of course, when you visit a Google property, they needs must inspect your IP address to send a response to you, at a minimum. That goes for any site you might choose to visit. The existence of sufficient entropy to personally identify a site visitor is not a state secret. They do not need this chrome experiment seed to identify you, if that's a goal.
Now this is interesting. If without that 13 bits of entropy, what will Google lost? Is it because of this 13 bits then Google suddenly able to track what they were not? If the IPv4 address, user-agent string, or some other behavior is sufficient to reveal a great deal of stuff, we have a more serious problem than that 13 bits. I agree that 13-bit seed is a concern. But I am wondering if it is a concern per se, or its orchestration with something else. Of course, how/whether Google keeps those data also matters.
Except for everything you do on your browser. I'm so glad I haven't used Chrome for almost three years.
Wat? You mean to tell me they can identify you if you log into their service?
Am I missing something here? Who cares?
"If, statistics are disabled."
In chrome://version you can see the active variations. It seems to be pretty big numbers to be significant, and so far haven't observed duplicates.
Since this header is generated server-side, you have only to believe I guess ? Plus why Doubleclick would need it :)
13 bits of entropy is far from a uuid (but to get it to that you need to disable some more settings, which again very few people do), but it's still plenty good enough to disambiguate individuals over time.
I mean personally I think they should do client-side feature detection and be back to being standards compliant and not creepy. The only reason why I'd consider such a flag is because they optimize the payload server-side to return a certain a/b test, but even with that they could do the default version first, do feature detection, and then set a session cookie for that domain only that loads the a/b test.
My other Thought was that they test a feature that is implemented across Google's properties, e.g. something having to do with their account management.
I think it was around 2006 that I got the extension for Firefox; Google bought them about a year later.
What I'm seeing is an RFC for anonymizing parts of User-Agent in order to reduce UA based fingerprinting, which improves everyone's privacy, that's a good thing!
Then I see someone comments how that could negatively impact existing websites or Chromium-derived browsers, comments which are totally fair and make an argument that may not be a good idea doing this change because of that.
Then someone mentions the _existing_ x-client-data headers attached to requests that uniquely identify a Chrome installation. Then a lot of comments on that, including here on HN.
To me that's derailing the original issue. If we want to propose that Chrome remove those headers we should do so as a separate issue and have people comment/vote on that. By talking about it on the UA anonymizing proposal we are polluting that discussion and effectively stalling that proposal which, if approved, could improve privacy (especially since it will go into Chromium so then any non-Chrome builds can get the feature without having to worry about x-client-data that Chrome does).
Ads are a business, and they are Google's business. They are how they make money. And like all businesses, they are competitive. Tracking is a way to make more money off online advertising. By removing tracking from their competitors while keeping it for themselves, Google stand to make a lot of money off this change.
Their motivations are not honest, but they're pushing them as if this is the high road. It isn't. It's the dirty low road of dominating the online ad business, made possible by their dominance in the browser market. And it's always been the end-goal of Chrome browser.
First, they do some dirty thing to gain a competitive edge when the industry is still new and unregulated. Later they develop an alternative way to achieve the same competitive edge, and then criticize other players for doing an old way, saying they should be "mature and responsible".
So, this is a round about way of agreeing with the hidden dark patterns that Google are bringing to the web. It must stop.
Pretty sure that was their main reason for helping push https-everywhere. A good idea generally, but hurt every other entity trying to do tracking more than it hurt Google.
That's sort of a fragile assumption though. I mean, yes, there's enough specificity in this number that it could be used (in combination with other fingerprinting techniques) to disambiguate a user. And yes, only Google would be capable of doing this. So it's abusable, in the same way that lots of software like this is abusable by the disributor. And that's worth pointing out and complaing about, sure.
But it's not tracking. It's not. It's a cookie that identifies the gross configuration of the browser. And Google claims that it's not being used for tracking.
So all the folks with the hyperbole about user tracking for advertising purposes need to come out with their evidence that Google is lying about this. Occam says that, no, it's probably just a misdesigned feature.
EDIT I just wanted to point out that a load of people have poured their lives into making Google Chrome the amazing bit of software that it is and suggesting that the end-goal has been entirely about supplying ads does a great disservice to their personal contributions.
Except it does not affect Google, because Google has this install ID to use both for tracking and preventing ad-fraud.
Which means Google competitors are terribly disadvantaged, as they cannot use that.
Which not only reduces market diversity (contrary to TAG philosophy) but represents a significant conflict of interest for an organization proposing a major web standard change.
These issues are very relevant to the original proposal, especially in light of the fact that Noone outside of Google is terribly interested in this change. Any time a dominant player is the strongest (or only) advocate for a change that would coincidentally and disproportionately benefit its corporate interests, the proposal should be viewed very skeptically.
So when Apple releases a privacy feature, that doesn't affect them as a business, we praise the feature or we say "except it doesn't affect Apple" and somehow try to argue how the feature is less valuable because of that?
Google's reasoning that this is not personal data is meaningless in the face of GDPR, which considers an IP address personal data. Google has access to the IP address when they receive the data, therefore they are transmitting personal information without user consent and control, which is illegal.
Basically all users opening the browser will contact www.googleapis.com to get a unique "Protected Media Identifier", without opening any web page and even before any ToS/EULA is accepted (and there is no user consent either).
[0]: https://github.com/kiwibrowser/android/issues/12#issuecommen...
After many years of testing HTTP headers, IMO this really is a non-issue. Most websites return text/html just fine without sending any UA header at all.
What is an issue are the various ways websites try to coax users to download, install and use a certain browser.
Another related issue with Google Chrome is users getting better integration and performance when using Chrome with Google websites than they would if they used other clients. ^1 Some make the analogy to Microsoft where it was common for Microsoft software to integrate and perform better on Microsoft Windows whereas third party software was noticably worse to integrate and perform on that OS.
This leads to less user agent diversity. Users will choose what works best.
UA diversity is really a more important goal than privacy, or privacy in Chrome. The biggest privacy gains are not going to come from begging Google to make changes to Chrome. They could however come from making it easier for users to switch away from using Chrome and to use other clients. That requires some cooperation from websites as well as Google.
Those other clients could theoretically be written by anyone, not just large companies and organisations that are dependent on the online ad sales business. It would be relatively easy to achieve "privacy-by-design" in such clients. There is no rule that says users have to use a single UA to access every website. There needs to be choice.
For example, HN is a relatively simple website that does not require a large, complex browser like Chrome, Safari, Firefox, etc. to read. It generates a considerable amount of traffic and stands as proof that simpler websites can be popular. Varying the UA header does not result in drastic differences in the text/html returned by the server.
1. Recently we saw Google exclude use of certain clients to access Gmail.
Just thinking out loud.
What happens, let's say, if someone malicious buys youtube.vg and puts a SSL certificate on it ? Will they be able to collect the ID ?
I guess so ?
A country's government could also take over the TLD and grab its traffic overnight.
If that's true then Google should be called out for their poor behaviour.
I feel like it's time we "hold the Web back" again. Leave behind the increasingly-walled-garden of "modern" appsites and their reliance on hostile browsers, and popularise simple HTML and CSS, with forms for interactivity, maybe even just a little JavaScript where absolutely necessary. Something that is usable with a browser like Dillo or Netsurf, or even one of the text-based ones. Making sites that are usable in more browsers than the top 2 (or 1) will weaken the amount of control that Google has, by allowing more browsers to appear and gain userbases.
Developers who want to level the playing field need to develop sites that fully support Firefox and other browsers that are not based on Chromium. Users who want to see a more open web need to use Firefox and non-Chromium browsers, and complain to developers who don't properly support them.
The last decade or so has really reinforced to me that we all ignore or are ignorant of fundamental structural problems with most of the systems we rely on - with us wanting them to "just work."
We're all guilty of this, we just see it up close for the things that we're building and chide others who don't care. Meanwhile we ignore other fundamental structures of modern society.
My issue is with certain sites that typically either uses non standard Javascript apis that only work in blink or relies on non standard behavior of standard components (numeric form inputs was mentioned here yesterday).
The only thing that will make people who want to preserve the content-web happy is if we split the protocols somehow, and that will never happen. This is not likely to change ever.
suckless surf lest you enable js with a hotkey on a per-process basis if you really want it for something, but 90% of the time, I just close the tab that wants to waste my time.
Can you elaborate what exactly is abusive behavior?
> [...] reliance on hostile browsers, [...]
What exactly is a hostile browser?
You do realize/remember that Google is also a search-engine company, one that only stands to benefit (in terms of increased capability of advertising targeting) from a web that's simpler, and therefore more machine-legible.
[0]: https://github.com/Eloston/ungoogled-chromium
[1]: https://github.com/bromite/bromite/blob/79.0.3945.139/build/...
[2]: https://github.com/bromite/bromite/issues/480#issuecomment-5...
Previous discussion: https://news.ycombinator.com/item?id=21034849
I hope all these AGs suing google have some good tech advisors. It’s hard to keep track of all the nefarious things google has been up to over the past decade.
If there is a country TLD of X where Google owns google.X but entity Y owns youtube.X then entity Y gets the X-CLIENT-DATA header information. See usage of IsValidHostName() in code.
[0]: https://chromium.googlesource.com/chromium/src/+/master/comp...
And in a sick twist they have this comment for it:
std::string BrowserDMTokenStorageLinux::InitClientId() {
// The client ID is derived from /etc/machine-id
// (https://www.freedesktop.org/software/systemd/man/machine-id.html). As per
// guidelines, this ID must not be transmitted outside of the machine, which
// is why we hash it first and then encode it in base64 before transmitting
// it.Quoting from https://www.freedesktop.org/software/systemd/man/machine-id....:
This ID uniquely identifies the host. It should be considered "confidential", and must not be exposed in untrusted environments, in particular on the network. If a stable unique identifier that is tied to the machine is needed for some application, the machine ID or any part of it must not be used directly. Instead the machine ID should be hashed with a cryptographic, keyed hash function, using a fixed, application-specific key. That way the ID will be properly unique, and derived in a constant way from the machine ID but there will be no way to retrieve the original machine ID from the application-specific one.
This made me chuckle. "As per the rules, we'll put on a boxing glove before we punch your lights out". You wont get privacy, but at least there is some security!
--machine-id
Spoof id number in /etc/machine-id file - a new random id is generated inside the sandbox.
Example:
$ firejail --machine-id* http://jdebp.uk./Softwares/nosh/guide/commands/machine-id.xm...
https://www.google.com/chrome/privacy/whitepaper.html
And for ease of reading, a few others:
> On Android, your location will also be sent to Google via an X-Geo HTTP request header if Google is your default search engine, the Chrome app has the permission to use your geolocation, and you haven’t blocked geolocation for www.google.com (or country-specific origins such as www.google.de)
> To measure searches and Chrome usage driven by a particular campaign, Chrome inserts a promotional tag, not unique to you or your device, in the searches you perform on Google. This non-unique tag contains information about how Chrome was obtained, the week when Chrome was installed, and the week when the first search was performed. ... This non-unique promotional tag is included when performing searches via Google (the tag appears as a parameter beginning with "rlz=" when triggered from the Omnibox, or as an “x-rlz-string” HTTP header).
> On Android and desktop, Chrome signals to Google web services that you are signed into Chrome by attaching an X-Chrome-Connected and/or C-Chrome-ID-Consistency-Request header to any HTTPS requests to Google-owned domains. On iOS, the CHROME_CONNECTED cookie is used instead.
> Article 4(1): ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
If this chrome browser ID is matched against a (for example) google account, then they can track every single person. And that is just a couple of IDs, let alone all the quantity of data they have.
It's against GDPR to not be clear about this kind of ID. If my browser has an unique ID that is transmitted, then this ID can be coupled with other information to retrieve my identity and behavior, so it should be informed (in the EU).
EDIT: TD;LR, hiding behind "there is no PII in that ID" is not enough.
I'm sure there is someone out there who takes these kind of things seriously. Not me. I use firefox for that matter.
> And what if they put this in the browser's T&C?
Then the rest of GDPR applies: a clear message about the browser sending this info has to be shown, explaining why, with who they'll share it, the time they will keep this info, plus no auto opt-ins, the possibility of asking Google (or whatever) all the info relative to this ID and the option to cancel all the data, etc.
If I'm given a forced choice between "more privacy" and "better software quality" I'm going to lean towards "better software quality."
Programmers should stop pushing buggy or incomplete software as is, and start releasing software that works. Otherwise upper levels have an excuse to do all this "experience" telemetry, and we all are smart enough to see the consequences of a data breach.
And I consider it far too narrow.
> If I'm given a forced choice between "more privacy" and "better software quality" I'm going to lean towards "better software quality."
Fair enough. I would go for "more privacy", personally. There is no technical reason why both of our preferences couldn't be honored.
It really seems fishy and a lot of double speak. I really don’t trust Google here.
Privacy issues aside, this might not help an antitrust case if one is brought against them.
This comment was sadly written in Chrome, since I need it for testing...
edit: pretty much exactly 10 years ago they already tried their shit with a unique id. We should have learned from that experience.
You realize you can have multiple different browsers installed, right?
"We want to build features that users want, so a subset of users may get a sneak peek at new functionality being tested before it’s launched to the world at large. A list of field trials that are currently active on your installation of Chrome will be included in all requests sent to Google. This Chrome-Variations header (X-Client-Data) will not contain any personally identifiable information, and will only describe the state of the installation of Chrome itself, including active variations, as well as server-side experiments that may affect the installation."
While this header may not contain personally identifiable information, its presence will make every request by this user far more unique and thus easier to track. I do not see Google saying they won't use it to improve their tracking of people.
With an obscure white paper that allows Google to claim they comply with the law because "they totally offer a way to change that and they even published that information to the web for anyone to find"?
Gotcha.
Until we are deployed enough that users don't have a choice...
Now that Google has cornered the market for Internet browsing, they're using that foothold to change how it works to suit their dominance. This is why they are not concerned about per-site tracking that Google Analytics does, as long as THEY as a company have direct browser-based tracking, they no longer need to provide tracking services to other private companies to know what is trending everywhere. This is also probably why they're trying to kill ad blockers and certain browser privacy extensions.... But they won't really matter to Google if everything is done at the browser level to begin with from now on. :/
If they make moves to scale back [free] Google Analytics, which they probably will at some point, it will only highlight this ideal... They may turn to selling their privately collected metrics and qualitative studies to companies after Google Analytics is rendered useless, and then that's unadulterated monopolistic profit for them and shareholders...
Diabolical.
Google had already cornered the market back in 2012, when it surpassed every other browser, with an absolute majority dominance (>50% market share) achieved way back in 2015.
Google has been in control for a long time now.
"There’s no point acting all surprised about it. All the planning charts and demolition orders have been on display in your local planning department in Alpha Centauri for fifty of your Earth years, so you’ve had plenty of time to lodge any formal complaint and it’s far too late to start making a fuss about it now"
13 bits of entropy is not an extremely unique identifier.
The first three letters of your first name have more bits of entropy than that. It would be quite a trick to uniquely identify you by the first three letters of your first name.
[1] https://chromium.googlesource.com/chromium/src/+/master/comp...
There are exceptions I guess. Imagine 8000 households in which couples live. Both partners own the same MacBook model. In 1/8000 cases Google would think there is only one person.
Aside: It seems to me the realist punk / anti-the-man software one can work on is a user respecting browser. I don't work on these, but I am very grateful for those out there who do.
-------
- [1]: https://github.com/Eloston/ungoogled-chromium#downloads
- [2]: Brew install via: `brew cask fetch eloston-chromium && brew cask install eloston-chromium`
Enjoy old school browsing with new school development benefits.
sed -n '/headers\":/,/\]/p' example.com.har
While running Chrome, try ps ax |grep -o field-trial-handle[^\ ]*[0-9]
Handle to the shared memory segment containing field trial state that is to be shared between processes. The argument to this switch is the handle id (pointer on Windows) as a string, followed by a comma, then the size of the shared memory segment as a string.Also, can try typing "chrome://versions" in the address bar
https://superuser.com/questions/541466/what-is-the-variation...
https://www.ghacks.net/2013/04/05/field-trials-in-chrome-how...
Further reading:
https://chromium.googlesource.com/chromium/src/+/master/comp...
https://chromium.googlesource.com/chromium/src/+/master/comp...
GDPR is very clear about this data being personal information [1], since Google has access to the IP address on the receiving end, which has been repeatedly tested in courts as being personal data.
Google is engaging in personal data harvesting without user consent and control, and no amount of mental gymnastics presented in their privacy whitepaper [2] will save them in courts.
[1] https://ec.europa.eu/info/law/law-topic/data-protection/refo...
[2] https://www.google.com/chrome/privacy/whitepaper.html#variat...
Firefox and DuckDuckGo, folks. Today's Google is no more benevolent than yesterday's Microsoft.
Wow. I don't even know how I feel about it anymore.
Now that Edge / Chromium is out of beta, even better.
And for Google, it's arguably foolish to think that they don't.
What a tumor google has become.
I mean, this is probably not the holistic solution, but this is why we have a firewall, vpn, antivirus, filters to just keep DNS in check, yes?
doubleclick.com might not be terrible for most, though.
Interesting enough, it does not add headers when accessing a country specific google domain in the EU - such as google.de or google.fr. Is that GDPR kicking in - with a nod the the brexiteers given that google.co.uk gets these headers... ?
Caveat here is that in 99.99999% cases it's also the case that nobody ever looks at your individual file but the fact that they could is bad enough.
Irrespective of whether you use any other google products, if you use chrome google can now track you over any property that uses google ads, recaptcha, etc.
The header is inserted by the browser after any extensions run, and google pins google properties so you can have an intermediate proxy that strips the header, so they gain persistent tracking of all users across most of the web?
If it wasn’t a tracking vector why do they limit it to just google ads, etc? Why not other ad providers as well?
Another lesson don’t trust for profit companies with privacy protection especially advertising technology company like google with motto like don’t be evil or organize world’s information designed to mislead.
Google should be fined for this but they probably won't be.
In terms of strategic reasons, as a company that depends on people browsing on their websites other reasons are obvious: avoid lock in that could be pushed by third-party browser makers/competitors (say IE becomes the most popular and it implements proprietary extensions that work only on their websites[1]), ensure there exists a fast secure browser so that people can keep browsing even if everyone else stops making good browsers out there.
[1] Now before you go ahead and point out how Google proposes HTML/HTTP features that get implemented in their browsers and on the server side, all such features have public specification and source code, so anyone else could implement them too. This is very different from the IE days of yore, where MS was extending IE through ActiveX. ActiveX was developed in house and they were releasing binary plugins/SDKs to develop ActiveX plugins, effectively maintaining full control over it (one would have to develop ActiveX compatible technology from scratch if they wanted it open source, with Chrome all they have to do is fork the source code).
Google's worked on a number of technologies to make the web faster; Chrome (and V8), their own DNS, image and video compression technologies, AMP, HTTP/2 (SPDY), HTTP/3 (QUIC), webserver plugins (mod_pagespeed), benchmark tooling (Lighthouse), and extensive guides on website speed optimization.
The reason is simple; faster internet = faster browsing = more page views = more ad impressions + more behaviour tracking data points. And it's a win-win for Google as well, because it earns them goodwill (well, except for AMP); especially at the time Chrome was a breath of fresh air compared to Firefox, and it's taken a lot of time and effort just to keep up, with mixed results (to the point where a number of manufacturers have just given up and adopted Chrome's renderer).
GDPR only applies in Europe, and CCPA only applies in California. How is one meant to determine which set of laws applies inside a piece of software without being able to determine location?
A waste of time (don't bother) answer is : Just apply maximum privacy everywhere and you won't have to worry about it... The response is always going to be - Many free tools you use are funded by advertising etc and advertising depends on being able to know where someone is, at least to the country level. Cutting off location and therefore revenue is not going to give people the software they want.
Other facts that usually matter - only 1-2% of people want to pay for private software. Everyone else wants the free option. Source : my apps.
How is software meant to determine location?
Mozilla is the only internet entity I can say I trust, I am donating to it, and yet I am using Chrome and Brave on both Desktop and mobile.
Just follow the users and fork it!
https://www.theverge.com/2019/4/8/18300772/microsoft-google-...
Some don't like their model to tip content providers but they seem - and I've not made rigorous enquiries here (please inform!) - to be a relatively trustworthy mod of Chromium!?
If so, its incredibly consistent with Google's surveillance capitalist business model.[1] Wow. I'm thankful for Firefox.
--
[1] "The Age of Surveillance Capitalism", by Shoshana Zuboff, reviewed here: https://www.theguardian.com/books/2019/feb/02/age-of-surveil...
In which they sacrifice privacy to allow their ad network to target you better. https://www.blog.google/products/chrome/building-a-more-priv...
In which they explicitly track you more under the guise of protecting your privacy. https://github.com/jkarlin/floc
For every single claim Google makes about being pro-privacy, their definition of privacy ("data shared between you and Google and no one more") is implicit.
It's a surveillance company that makes proprietary software to sell you ads. As soon as you get that into your head, you'll be much less shocked.
"We personally get to track you" is not a unique stance, and it's far from a backdoor. It's just another vile move from a surveillance company that's pretty explicit that that's their goal.
From what I see many techies are now aware and upset, and hardly anyone seems to want to defend Google anymore.
I consider it more likely than not that Google will take some real beatings in the years to come. Kind of like Microsoft was fined by the US and EU, forced to advertise for competing browsers and ridiculed by Apple ads. On a case by case basis I think some of this will be well deserved, some less so, but few outside of employees and shareholders will cry.
I also guess a lot of people, including certain owners and many in management hasn't deciphered the writing on the wall yet, and in that case it whatever comes next will be surprising.
Meanwhile I'd hate to apply for them. Everything they do in terms of tracking, etc. has become so vile and almost evil that even Microsoft has a better standing among my peers..
Would love to hear some insight from ex employees on what changed on the inside of that company, but from the outside it doesn't even seem to be the same any more. Maybe they're just worse at hiding it..
The thing which changed is that Google operates on a much, much larger scale than anything imaginable back in the late 90s when they first started. In 1999, nobody had any inkling about the cloud and SaaS revolution that was about to come. Nobody knew that everything was about to move into web apps and cloud services, which permit and require(?) tracking in ways, and on a scale, no one had thought possible. (Require with a question mark because - ad tracking aside - what little I know of frontend development includes that they need to be able to see certain information, like your browser type, in order to provide effective services.)
The thing which didn't change is the mindset of the engineers building the services. On average, Googlers tend to be much less concerned with personal privacy than an equally educated consumer, and much more interested in the features and services they can build for themselves and others which happen to require huge amounts of personal information to function. In other words, a typical Googler is more likely to think, "Oooh, having a personal digital assistant is great! If I give Google access to my email inbox, it can suggest tasks, automatically add calendar invites, and do other cool things."
The problems we're seeing now come when the engineers working on advertising products have that mindset and access to Google-scale information. They don't consider it a problem or a violation because they don't mind targeted ads, they don't mind giving up their data in exchange for services, and they don't (want to) understand why people who aren't them might object.
It's a lot more complicated than that because Google, while the largest and arguably most effective, is not the only player in this game. There are a lot of other corporate and social influences at play. This is just to answer the question about what changed at Google.
We didn't consider that a greater evil would arise, and all it would take was a disregard of the sanctity of personal privacy.
Firstly, if tracking usage statistics or activity was actually evil then everyone would hate it, desperately try to stop it and have tons of stories about the horrors of it.
In fact what Google sees is:
1. Web apps are extremely popular although they all keep server side logs that reveal every button click, every message you type, every email you send, every search you do. Users routinely migrate from thick client apps that give great privacy to web apps that give none whatsoever without batting an eye.
Hacker News readers in particular should understand this. It's overrun with Silicon Valley types who build their entire livelihoods around "let me run this program for you as a service". There's nothing special about Google in this regard. The entire software industry has moved away from privacy in the last 20 years because ...
2. Users rarely if ever use privacy features when they're provided, even when they're heavily promoted. In fact, despite all the noise, hardly anyone cares. For the vast majority convenience wins over privacy every time. But not just convenience, also ...
3. Security trumps privacy. People say they like privacy, but they hate getting hacked and tend to blame the service provider if it happens. They have very little patience for explanations of the form "yes this attacker was obviously not you and yes we had enough data to know that, but we didn't use any of it ... for your own good!"
4. Users can't and won't give accurate feedback about what they value or what their actual experience of using an app is like. This means A/B testing is critical to avoid making bad business decisions. The heavy reliance on experiments and data driven decision making is one reason tech firms tend to steamroller their legacy competitors.
Google hasn't become evil over time. It's been doing A/B tests, keeping server logs and writing unused privacy features since the company first began. All that's changed is it got big and rich, so people - rightly - started to think about its power more. But the hypocrisy is strong. The world is full of companies collecting and using data for the benefit of their customers. It's really only Google and Facebook that get the vitriol.
To me, the explanation is simpler: people don't want to defend Google on HN because they'll get downvoted or shouted down because of it.
So, people who want to dislike Google will find everything they need to confirm their biases here.
I won't say that the current situation is perfect but I can see why. In my view Google had earned the current criticism by hard work:
- mismanagement of services people loved to the point were Google always running 3 different more or less incompatible message services, while closing services east and west has become a meme,
- shoving other ideas down people's throats (hi identity and real name part of Google+)
- etc
Be careful, most of us on HN are part of a very small echo chamber. "What you see" is a small, non-representative portion of "techies". If it wasn't Firefox wouldn't be at sub-5% in general usage surveys and AMP would've died years ago.
From what I've seen is it's like it's always been: people are upset for a day or two and then continue to not care, and continue to (directly or indirectly) support the evil they were upset about. It's incredibly difficult to get even geeks to support a cause if it requires more than pressing a like button or posting a comment.
Also, it's not like Google's wrongdoing are recent news. Anyone remember Google Watch (the site)? People have been warning and predicting things since very long ago, yet the geek crowd never seems to hesitate to embrace the next soon-to-be evil company and their proprietary offering.
These days I only use chrome for the g-suite tools that seem to require it to avoid mid-meeting crashes.
Not to mention the fact that iOS users are forbidden from using any competitive browser, including Firefox.
My biggest gripe is I can’t update it without updating the entire OS. Also, dev tooling is really bad. God help you if you ever need to unregister a service worker.
I second this; keep trying even if it isn't for you after a few times, it was worth it to keep trying, officially Firefoxer :)
Edit:
I didn't want to expand because I've already banged that drum too many times on HN.
See these other comments of mine:
... and if it doesn't, they're developing their browser with one hand tied behind their back on quality assurance relative to alternatives.
I tried this and my "x-client-data" header changed.
Donate to smaller developers of software you use, it'll go a lot further, and they'll probably put it to better use!
Does anyone object to this indirect way of funding Firefox? Does it cause indirect harm by making them prioritise pocket over Firefox?
What's the motivation? Is it simple laziness because they don't want to deal with wetware? Is it afraid that if people knew what was happening they wouldn't be happy? Google has eighty brazillion employees it can test new features on.
It's crazy to me to think about when I was in college (in the mid aughts), I was doing a lot of research into Native American cultures. The amount of releases, paperwork, and other hoops you had to jump through in order to just interview subjects was pretty daunting.
The fact we have become involuntary research subjects without any protections as a research subject or easy way to opt out of these companies data collection (which itself is an ongoing form of research) is staggering to thing about.
> involuntary, unpaid guinea pigs.
I don't see how this is involuntary. You are choosing to use the product. If you choose to use the product, yes, you may be exposed to features that the product has. If you don't want to be exposed to those features, the way to opt out is to not use the product.
> What's the motivation?
It lets the company incrementally roll out and test features in real-world network configurations at scale. As far as I know, almost all tech companies do this.
Let's say you're Fapplebooglezon and you have an idea to put kitten emojis on the "Buy Now" button. Before you ship that, you want to make sure that:
1. The feature works correctly. It doesn't crash or have significant performance problems.
2. Users, in aggregate, like the change. No one wants to ship a "New Coke" debacle. It's bad for the company (they lose money) and bad for users (they don't like the product).
3. Your servers and network can handle the consequences of that change. Maybe users will be so excited that they all click "Buy Now" twice as much. You need to make sure your servers don't crumble under the increased load.
These are reasonable things that benefit both the company and users. So the way features and changes are usually shipped is like:
1. The feature is implemented behind some kind of flag. [0]
2. "Fishfooding" [1]: The team developing the feature starts using it. This gives you some feedback on "does the feature work correctly" but that's about it. The team owns the feature, so they are biased in terms of its usability. And they are on a privileged network and not a large enough population to verify how this affects the distributed system.
3. "Dogfooding": The entire company starts using it. This starts to give you some usability feedback because now people who don't have a stake in the feature are being exposed to it. But it's still skewed since employees are likely not a representative user population.
4. "Canary": The feature is enabled for a randomly selected small population of external users. Now you start getting feedback on how the feature performs in the wild on real-world machines and networks. The percent of users is kept small enough to not crush the servers in case anything goes awry, but you can start getting some performance data too.
5. "A/B testing": Now you start collecting data to see how behavior of users with the feature compares to users without it. You can actually start to get data on whether the feature is good or not.
6. Assuming everything looks OK, you start incrementally rolling it out to a larger and larger fraction of users. All the while, you watch the servers to make sure the load is within expected bounds.
7. Once you get to 100% of users and things look good, you remove the flag and the feature is now permanently enabled.
> Is it simple laziness because they don't want to deal with wetware?
Google, like most other companies, also does lots of user testing and user surveys too. But that doesn't give you insight into the technical side of the question — how the feature impacts the behavior of your distributed system.
You may not be aware of this, but this kind of in-the-wild product testing is something almost all businesses do, all the time. Food companies test new products in grocery stores in selected cities [2]. Car manufacturers drive camoflaged prototypes on the road [3]. Restaurant chains tinker with recipes to see how sales are affected. There is absolutely no guarantee that the Coke you're drinking today has the same ingredients as the one you had yesterday.
You seem to think this is some nefarious scheme, but it's just basic marketing. You want to make a thing people like, so you make two things and measure which one people like more. People "opt in" and "consent" by using the product. If you don't want to be a "guinea pig" when McDonald's changes their French fry recipe, don't buy the fries. If you don't want to test out new Chrome features, don't use Chrome.
[0]: https://martinfowler.com/articles/feature-toggles.html
[1]: https://www.reddit.com/r/google/comments/3qpdnn/anyone_knows...
[2]: https://smallbusiness.com/product-development/best-u-s-citie...
[3]: https://www.cnbc.com/2017/01/20/camouflage-the-incognito-way...
2. See 1.
If you aren't paying for it; you are the product. Simple.
See the fiasco where they broke Terminal Services last year as an example of what can go wrong even when doing experiments on the whole user base.
Also consider how to measure the usage of web features Google's own websites don't use, but are popular on e.g. intranets in Korea.
A/B testing isn't bad, it's a good thing. People are notoriously not very good at giving feedback. Experiments and usage statistics let you get the ground truth about what they really value, and what's really working.
Although Window 7 may have been one of the most complex software deployments in history, needing to support decades of poorly written drivers, while making the system both stable and compatible.
Do you understand what licensing is? That's one of the underlying aspects that's important with software and why you can't treat it like other things you buy. I'd add it's also why things that adopt software-style licencing models are bad too.
A company creates a licence with terms and you agree to use the licence under those terms by using the software. The terms are difficult to change unless you have leverage. The only party other than the company is often the regulatory authority. Regulation is limited in the US at best when compared to the EU. If you are from the EU then you probably assume the US works similarly, but most Americans don't recognize issues like this one. When they do, it's hard to fight the incumbents and make something opt-in, or ban it outright.
> What's the motivation? Is it simple laziness because they don't want to deal with wetware? (the start of your first paragraph applies here too)
It's fairly simple. The motivation is making correct decisions based on the gold standards of decision-making that some people aspire to. The model is not dissimilar to clinical trials where a treatment is given to some individuals and not to others. The hope is that this form of experimentation removes bias and let's the product manager make the best decisions.
Based on this thinking it is not possible to test with just Google's employees. For many decisions, the bias will be significant, and ultimately the belief is that worse decisions will be made for users.
I'm trying to convey that in as neutral way as possible. I think this can be a useful technique, but I think that there is little discipline and accountability in the wider software world compared to medicine. You have PMs who'll routinely just run an A/B test longer to collect more data (that's better, right?), but invalidate their results, just to please management.
If anyone is going to implement this approach then I'd trust Google to implement it effectively to meet their needs. They do it on a large scale across their products and have many layers of people to ensure it's effectively meeting their needs. As stated in the previous paragraph, this doesn't mean that other people do it right, or that everyone in Google does it right every time. I'm sure they've had a fair share of failed experiments.
It's a bit odd to see this in every Google thread.
Btw, Firefox is too slow.
Ahh, the good ol' "Firefox is too slow for me to consider it" statement. Is there any evidence that Firefox is slower then Chrome other than old lingering memories of Firefox being slow ten years ago?
I have used both Firefox and Chrome and I can't subjectively tell that one is significantly faster or slower than the other. To be fair, I only have a handful of extensions and rarely have more than ten tabs open at a time, so my use case may be atypical.
U S E F I R E F O X
That is all.>Really curious about your opinion, especially after the GDPR explicitly forbidding such tracking.
>Moreover, it doesn't make sense to anonymise user-agent if you have such backdoor
Oh, but it does make sense because with this everyone _but_ google will have a harder time tracking people :\
...but inevitably, it will be used for tracking -- regardless of intent.
It might also get Google in trouble. Copying and pasting from the a comment in the OP's URL:
> Example: https://www.youtube.com - in network headers, look for x-client-data
> Now, go to https://ad.doubleclick.net/abc - and your browser also sends this magic x-client-data.
> It's a unique ID to track a specific Chrome instance across all Google properties.
> Really curious about your opinion, especially after the GDPR explicitly forbidding such tracking. Moreover, it doesn't make sense to anonymise user-agent if you have such backdoor.
Could you please remove the four-space indent? You can wrap each paragraph in * ... * if you want to italic them.
It's funny that the doubleclick URL was removed by my adblocker and I didn't get what the original message was about. Now I can see it, thanks :)
I meant that this will be rationalized and justified BY GOOGLE.
I don't know exactly what's going on with your wife's / your father-in-law's accounts though, are they sharing Google accounts, photo albums, or were the photos shared in the same whatsapp group?
Edit: If the mods are listening, I've come up with an alternative title for you:
"The Evil GOOGLE Has Installed a MALICIOUS BACKDOOR On All Chrome Users Machines To Sell PERSONAL DATA to RUSSIAN HACKERS on the DARK WEB".
This will surely get the clicks now. You can thank me later.
If you really want to help, suggesting an accurate and neutral title, preferably using representative language from the article itself, is a great way to do that. We don't know enough to get it right in every case, even when awake.