On the other hand leaking the list of apps on your local computer, and to a third-party to top it off, is unexpected and thus more harmful.
Given that the Wacom utility is full of app-specific references and "customize your tablet, per app", I'd say that this is on par.
Ask random person, "Hey, do you know that when you visit John's blog, he sends your information to Google, too, not just himself?" and I guarantee you the answer is probably closer to 7% than 70%.
> Has this investor got a beta build from that new startup everyone's talking about? Their bets are always winning, I better frontrun them if that's the case.
> What apps could I exploit to get into this guy's computer?
> Wait why is my employee suddenly running tor browser after I involved her into this new secret deal? Better be careful with her, she might be talking to someone.
> Damn, our competitor's engineers are all running our app. Let's correlate the timestamps with our own backend to discover their accounts and push a special update to them.
HTTP Log analysis is slow, and requires a lot of server side setup. Also, it will not give you navigation events in a SPA.
Using GA... just drop a line of JavaScript and you are done, with near real-time insights that are more detailed than an access log. You don’t need any server conf, or extra knowledge (not even JS knowledge: copy & paste the embed code). And Google gives you that for “free”... that’s why tons of sites doesn’t care about Http access log analysis anymore.
For desktop apps is easy too. The GA API is very simple: send the app id, event + any event data you want. Your dev team can do that with self service (no need to setup a service, no extra costs to handle data).
Google receiving browsing histories for a single website is rude, but it probably isn't a serious problem for many websites (although the risk will depend on the nature of the website). In isolation, the fact that Alice read Bob's webpage isn't isn't very interesting, but Google can aggregate that data into s very accurate pattern of life[1].
> Is it not anonymised?
Not for any meaningful definition of "anonyms". At best GA will zero the low 8 bits of the IP address by request of the website. (The opinion of the person visiting the website apparently isn't worth considering) See this[2] post for a more detailed explanation of GA's perfunctory "Anonymize IP" feature.
I block it because the data it collects is none of Google's business. Being "anonymized" doesn't make it any better.
GA is used by countless websites. It's likely hooked into the adwords codebase so that they can track websites you visit even if that website does not have Adwords ads on it.