Google sued for secretly amassing vast trove of user data
bloomberg.com
bloomberg.com
I go through hundreds of disposable browsing profiles every day.
> Disables 3D APIs / WebGL, GPU acceleration by default while allowing them to be re-enabled through command-line switches.
WebGL is a fast path to direct hardware execution and kernel space execution.
It’s difficult to patch when things go wrong often requiring driver or kernel coordination.
There might be issues with cross site memory leaking, but I’ve only seen white papers on how this might be an issue.
Fingerprinting avoidance is a complex issue and it's reached the point where you can't simply disable JavaScript / WebGL and assume you're ok. One needs to run additional extensions to project a browser-view that blends in. You can use chrome-private.sh as a base layer you can build on to get there, but you are not going to get it by default (which is why I'm not making any anti-fingerprinting claims in the README).
https://addons.mozilla.org/en-US/firefox/addon/temporary-con...
https://addons.mozilla.org/en-US/firefox/addon/multi-account...
Edit: See below with a warning about using this with profile sync.
It's far simpler to treat the profile directory as contaminated waste and nuke it at will. The only assumption you're making is that the browser implements a profile in a given directory properly.
[1] https://github.com/stoically/temporary-containers/wiki/Isola...
So far in practice I've never seen the isolation fail. The combination of the two plugins seems to counteract each one's failures.
And Mozilla makes the multi-account-container plugin. I trust them a lot more than I trust Google to make Chrome not leak information across profiles.
Even if I did move to Firefox however, I would still implement a directory-based profile segmentation strategy.
Chrome offers both. Firefox offers nothing. Of course applications can additionally offer their own scripting APIs (Chrome has DevTools, I'm sure Firefox has something equivalent) but a major advantage of OSA is its stability and uniformity. It's a hidden treasure for power users and obsessive feedback loop minimizers. Alas, when it comes to regular users, the most Apple managed to do with it was Automator.app, a very constrained experience that did not really take advantage of the underlying power.
https://developer.apple.com/library/archive/documentation/La...
- Containers are a feature built into Firefox, these extensions just expose a UI for it. The Multi-Account Containers plugin [1] is published by Mozilla. You don't need to trust anyone but Mozilla to use that base set of functionality.
- The container functionality in Firefox is the result of some work from the Tor Browser being upstreamed into Firefox [2]. It seems reasonable to assume that it's well-implemented.
- The limitations of the extension that you linked to don't seem any worse than your profile-segmentation approach. It's just saying that it's possible for multiple websites to get opened in the same container, which is similar to how you could end up opening multiple websites in the same profile.
[1]: https://addons.mozilla.org/en-US/firefox/addon/multi-account... [2]: https://blog.torproject.org/tor-heart-firefox
With segmentation enforced at instance boundary (rather than in-instance), there is no unexpected behavior of this sort. All links open in the segmented instance that the browser window/tab you're using belongs to. If you want a new container, you start a new instance and you know that's exactly what you will get. There is no possible "fail open" result. Note that I'm not saying the Firefox behavior you described is a major issue, just that it proves you can have unexpected scenarios.
Moreover, jedberg is correct in that cross-profile data leaking is possible (partly what I meant by "implementing profiles" properly), except that it's very easy to see if that's happening without auditing Chrome. Use a tool that records all filesystem operations (e.g. dtrace on macOS).
At the end of the day, I choose one set of trade-offs over another.
[1] https://github.com/stoically/temporary-containers/wiki/Isola...
The issue you are quoting is about opening new containers while following links. That's something your solution doesn't support at all.
Your solution is akin to manually opening a new container. That will always work in Firefox.
It seems it's currently impossible to recover your profile once you reach "Maximum bytes per object exceeded" - the remote end won't even let you delete the offending data.
[1] https://github.com/stoically/temporary-containers/issues/371
[2] https://github.com/mozilla/multi-account-containers/issues/1...
I.e if you use the same container to read news, google knows your news preferences.
I'd really appreciate some more technical details here.
Does this include web server logs that record incoming IP addresses?
Is the expectation here that Chrome would set a DNT header in incognito mode and Google properties would then obey that header?
So practically: logs are fine, delete them after a while. If you store the same information in a permanent database and use it for analysis you're in trouble and should have asked permission.
The fact that the user uses a private window or other means to indicates they don't want to be tracked probably makes this a more clear case.
That’s a very confusing statement. My server logs don’t filter incoming log entries based on user agent, and certainly not on whether you’re using a “private window” or not.
In addition, the goal of a private/incognito session is to be indistinguishable from regular sessions, otherwise websites can easily discriminate against private sessions (which they’re already trying as hard as they could).
Edit: Wow the number of people on this thread claiming websites should be able to opt people out of logging based on whether they’re using a “private window” (which websites should have absolutely no idea about) makes me question if I’m even on Hacker News.
Edit 2: Chrome sends an X-Client-Data header (which in a sense includes an installation ID, but allegedly has limited entropy) to certain Google properties, and rightfully got a lot of flak for it. It does not do so for incognito sessions. And now we have people arguing that Google should de-incognito incognito sessions to their analytics properties. Crazy stuff.
How is it circumventing a "decision of the user not to be tracked" when "private" modes usually explicitly state they can't/don't stop websites from logging information.
Because it's not about the logging, it's about the linking to a cookie/information they do not have access to in incognito?
https://nakedsecurity.sophos.com/2019/07/22/chrome-76-blocks...
Especially since "Websites shouldn't be able to tell if you're in incognito mode" has been highlighted in the past as a privacy ask, yes.
People can at least agree "website shouldn't be able to tell if you're in incognito mode" and "website should not track you if you are in incognito mode" are two mutually exclusive features, right?
And yes, this does mean that if it comes to litigation, a lot of this will depend not just on what you did but why you did it.
If you write analytics, unaware of incognito mode, you're probably okay.
If you write that same exact code because your boss comes in and says "shad, we're losing A LOT of user data to users in incognito mode. Could you do some kind of digital fingerprinting so we can still track them?" then you might be criminally liable for digital trespass -- you've intentionally bypassed my security mechanism.
If the exact same action does the exact same harm and is legal or illegal based on intent, enforcing that law is going to enrich a lot of lawyers but isn't going to practically rope in many company's behaviors.
And yes, it does enrich a lot of lawyers.
Look up the CFAA cases, for a great set of example of how these laws can explode in this exact domain -- people charged with digital trespass who bypassed no or minimal technical measures. And it doesn't feel good either in most of those cases.
To be frank, though, if this gets applied to Google, it will feel pretty good.
I think that it should do more, but it doesn't (a VPN or Tor would be nice in incog. mode)
It's not me who doesn't know how it works; it's the people who think "New York Times shouldn't be able to whine at you if you're in incognito mode to go buy a subscription" and "servers should be required to modify how they handle your traffic if you're in incognito mode" are compatible protocol features.
What about the fact that Incognito is so that "other people who use this device won't see your activity" and it doesn't do anything about tracking?
I switched back to Firefox last year, and it's been a good change. uBlock Origin can do all of its job and not just some of the job.
It looks like this is mainly about the fact that Google Analytics still works even if you are in Incognito mode.
Maybe instead calling it "incognito mode", which is totally inadequate, they should call it "temporarily disable browsing history" instead.
Onion addresses work, and Firefox refuses to connect if the Tor daemon isn't running.
Paired with Firefox actually honoring my requests to purge all information upon exit (instead of chrome only "kind of" doing it), it certainly works out quite well for me.
Personally, I always took Incognito/In-Private browsing to be just a "delete cookies and history on exit" mode. But the way it is presented may suggest to many people that it is significantly more than that, even with the disclaimers in Chrome. I would not hold my breath for a successful suit based on that, though.
Modern day websites use readily available modules to build out functionality. Just because those modules were originally built by someone else doesn't mean that it's not part of the website you visit.
Full disclosure: I work at Google.
Basically, this is one of the key ideas behind the GDPR: that I should have a legally-enforced expectation that when I'm agreeing to share my data with X, I'm not implicitly agreeing to also share it with Y and Z; and that it is X's responsibility to see to this.
So sure, X is free to use GA, but as a User I shouldn't have the expectation that Google knows I've visited X's sight.
And comparing GA to React is really disingenuous, especially in this context. One is an active monitoring solution that hoovers up data and sends it to a 3rd party, the other is a static library that is entirely run in my own browser, or sometimes on the origin server as well.
Another commenter said that this wording implies that it DOES prevent Google Analytics, since it is not part of the site.
My argument was that drawing a distinction between a "site" and modules that are part of that "site" but are from other parties is dubious.
It is not only not dubious, it is in fact enshrined in law. I brought up the GDPR explicitly to highlight this. Specifically in the context of tracking and personal data, there is a distinction between the site I am visiting and the legal entity that is controlling it on one hand, and other entities that it contracts to achieve its purposes.
If your understanding of 'a website' includes all of the 3rd party trackers that it may be using, then the wording becomes obviously correct. I would venture though that this is not the common connotation of the phrase 'you may still be tracked by the website you are visiting', which I believe most people would take to mean more 'the origin server', i.e. 'I may still be tracked by the 1st party entity who owns the site I am directly visiting, but I will no longer be tracked by other parties'.
In fact, by your definition of 'the site I am visiting' , incognito mode offers no more tracking protection than regular browsing, as I can never be tracked by anything but the site I am visiting, including Google analytics, Facebook, and any other ad networks that they chose to use; I am never tracked by any site that I am not currently visiting, obviously.
Uh, no.
Using a web framework is very different from using a third party data collection tool that gives the third party access to the data.
Unless the React devs are also tracking user behavior on third party sites. But that would be a separate lawsuit.
Full disclosure: I buy ads from Google.
Another commenter said that this wording implies that it DOES prevent Google Analytics, since it is not part of the site.
My argument was that drawing a distinction between a "site" and modules that are part of that "site" but are from other parties is dubious (also, likely impossible).
I mean, if nobody really cares, why not be more direct about it?
This is how I've always interpreted it and the reason uBlock Origin is the only extension I've allowed in incognito/private mode
The point of digital trespass laws is very similar. Just because your technological measures are imperfect (as the bullets say) doesn't authorize you to circumvent them.
What's damaging in this case is that Google created the signalling mechanism, gave it to users, and then intentionally chose to circumvent it.
Courts are also not machines. A lot of this comes down to intent and reasonableness. If you're fingerprinting my browser when I'm in incognito, that feels like an intentional digital trespass which courts would probably recognize. If you're incidentally collecting my IP in your server logs, that feels okay. Programmers get caught up in this all the time -- they read laws and contracts like code (strict literal meaning). Lawyers read them looking at things like impact, intent, whether things are substantially similar, and so on.
Absolutely not.
Incognito mode, as in every browser, means you're history isn't recorded on your machine. And as GP said, Chrome even explicitly explains your ISP or websites may still track you.
And Chrome isn't doing anything to circumvent it.
Intent and reasonableness here is perfectly fine on Google's part. Incognito mode successfully prevents storing history on your machine. Analytics successfully track you. And nobody's being misled. Incognito mode has never been advertised or marketed as anti-tracking, because it's not supposed to be. It's just a convenience to clear cookies and history, nothing more.
But there is no such law against collecting browsing data. So there has to be some other legal theory under which Google would be liable. One example would be deceptive practices or fraud, where Google says one thing then does another. Unfortunately, we don't have the full text of the complaint yet as far as I can tell. But your "that's not how the law works" dismissal is actually going to be totally irrelevant to the complaint, because there's no legal comparison between trespassing and collecting browsing data.
There are equivalent laws for technology. For example, you have the confusingly vague CFAA. If I've indicated to you that I don't want you grabbing files from my computer, and you do, you've likely broken it. It's even called digital trespass. On the other hand, if you have a public FTP server up, I can grab files. If you have a public FTP server up, and you've told me I'm not permitted to access it in person, or in an automated banner, or in an automated banner which my browser never shows me, things get legally complex.
Pretending "private browsing" or "incognito mode" doesn't act like such a sign isn't very honest. Google disclaims this information might be visible to web sites, which is honest, but most indications are given that it's intended to help screen some of that. Intentionally working around incognito mode is almost certainly at least somewhat illegal.
The other possible complaint could be that websites still can collect information on user behavior on the website, even if it is more anonymous in incognito mode. This is expressly what incognito mode says on the tin. You can use it to avoid saving your weird porn history locally, but not prevent websites from knowing what anonymous visitors are doing on their website. If the average consumer isn't tech-savvy enough to get this distinction, I'm not sure what Google could do besides putting this explicit warning in every new tab.
Summary: seems like this case will go nowhere, but still makes for soundbitey headlines and gives people an excuse to rehash their usual gripes that "my data is the next oil"
(IIUC, most ad targeting is still based on you explicitly searching for something you want to buy and ads matching those keywords, or retargeting from a website you've already visited but abandoned your shopping cart at, not some all-knowing profile of your deepest wants and desires).
Disclaimer: I work at Google but nowhere near the Analytics or Ads teams.
And while I have no big conspiracy theories at the moment about how Google is doing anything evil, there is certainly no guarantee that something in the future could impact me. For example there could be some bad players working inside Google, Google could be acquired, or the government could take control in some way. these are all things that could be dangerous to me in the future if Google continues to preserve large amounts of my personal information.
WARNING! We use your personal data to improve your experience using Google products. We believe this will lead you using the service more often and, in doing so, see more ads which we profit from.
But what am I talking about! Google KNOWS scale, I’m sure it’ll come together eventually.
Side note, we are spinning out Google into a separate entity, because we are growing so big. The new conglomerate is called Alphabet. It's just a silly accounting action, nothing to see here.
We're like a metaphorical frog slowly being boiled alive.
FYI - Google does offer a series of tools for you to manage your data. If you are signed in there is my activity[1], and takeout[2]. There are options to control targeted ads[3] and auto-delete location and activity data older than 3 months[4].
[1] myactivity.google.com [2] takeout.google.com [3] https://support.google.com/ads/answer/2662922?hl=en [4] https://www.blog.google/technology/safety-security/automatic...
Google is really good about takeout. It's really bad about maintaining my privacy. The opt-outs are limited in scope to the point of being almost meaningless. I don't mind ads being targeted as data being collected about me. Google's privacy tools are a joke.
Google's security tools are a joke too. Google silently drops security support for Android phones after two years, and people unwittingly walk around with zero-day exploitable phones. Chromebooks are similar. If you want to maintain a secure Google Apps domain, you need to pay Google huge bucks. It benefits everyone, especially Google, if the Internet is safe, and Google's attitude here will come back to bite it.
I'm still waiting for the recommenders, personalizers which help me.
Not boost engagement. Not amplify tiny differences. Not catalysts for virality.
I was on the recommender, personalization team for a high end fashion retailer. Joining, I thought "Woohoo! Teach the computer tell me which dress shirt to buy! Pick the right t-shirts! Find tasteful but understated socks! Finally!"
It took me a while to peel back all the layers to reveal the team's secret sauce. Turns out there isn't any. The most performant algorithm was "stuff you've looked at before" (~70%), followed by "what's hot" and "what's new".
While most of our effort was put into all the Big Data Machine Learning Booyah stuff, I'd characterize the attributable "lift" as little better than noise. Terrible ROI. We would have been MUCH BETTER off improving the data quality, search features, and browsing experience.
(I had some other more radical ideas. A whole thesis built around authenticity and actual engagement. Way past StitchFix. Alas, too weird for the brick & mortar types. Imagine explaining TikTok influencers to your great aunt. But I'd be happy to have someone pay me for a brain dump.)
In conclusion, nothing this last decade has shaken my hunch that digital ads are a giant con job. At least outside of political advertising. (My bro has worked in ad tech for 15+ (?) years. Our spirited debate has never stopped.)
Something has been on mind for a while.
I see lawsuits against Google collecting / selling personal data and ideas to combat its monopoly in search. What I don't see is a discussion about regulating companies that have data on the majority of the population.
I know for a fact that Google used search insights to inform strategy. By knowing what people search for and modeling our behavior, they have an unprecedented ability to forecast future events. I expect that Facebook and other, lesser-known companies do the same. I believe it is dangerous for a company to have this ability.
I am not an expert in public policy and politics. Would it make sense to have regulatory oversight over all companies that have data on, e.g., over 50% of a country's population?
I have thought of this as "search-based front-running". How much of it goes on, I would like to know.
Per Matt Levine's "anything can be securities fraud if you don't tell your shareholders about it", then having the "unprecedented ability to forecast future events" and not informing your shareholders about it could be argued as securities fraud in court. Something to think about.
https://www.reuters.com/article/us-sec-capitalone-insidertra...
Key quote: The Huangs, who are not related, began with a $147,000 investment and together made more than $2.8 million from the trades, a three-year return of 1,819 percent, the SEC said.
In fact, it's more likely Google will use the regulation to corner the market with regulatory capture.
Today they are on top, but if Automotive is any indication, Google will soon struggle
Is having an email or phone enough to qualify?
Maybe yes.
In that case, think of a rapidly growing startup, which breaches that mark (50% or whatever the law says) - and now has to comply with the law.
But the startup is not capable of compliance, because the law was made for behemoths like google.
This startup will go belly over and die soon.
Google's monopoly saved.
Alternatively, leaving it in the public domain for civil suits to be filed has a tendency of natural selection. If a company is TRULY big enough, and has that kind of data, someone WILL sue.
The answer here depends a lot on what the hypothetical regulation would be.
Does anyone know how many consumer oriented startups reach 30 million customers?
> But the startup is not capable of compliance, because the law was made for behemoths like google.
If I were 'king of the world' I would consider something like this, but would not have it be a binary 'must comply or exempt' but a spectrum of ranges from 'totally exempt' to 'totally regulated' depending on what percentage of 50% you had.
If you have 5% of user emails, you are responsible for the bottom 10% of regulations and/or you need to fully comply with the regulations for a sample size of 10% of your users.
IDK I need to give it more thought, but first, another zoom meeting awaits.
Regulation and civil lawsuits don't serve the same purpose. Regulation is making the rules. Courts interpret the rules in light of a specific situation.
I agree that regulation can be counter productive. It can create a level playing field or cement dominant positions of encumbants. So let's have good regulation.
Anyone who has read Bad Blood [1] should have no doubt about this fact. They destroyed this man and lead him to suicide in order to try to save their house of cards.
[1] https://www.amazon.com/Bad-Blood-Secrets-Silicon-Startup/dp/...
He tried to warn his grandfather, a member of the board, that something was wrong at Theranos. His grandfather said "Tyler, they can't convince me that you're stupid, but they _can_ convince me that you're wrong." His grandson turned out to be right.
[1] https://en.wikipedia.org/wiki/George_P._Shultz#Theranos_scan...
Other websites or services may be able to say they can't control how those browsers in such modes communicate that intent. Google cannot.
Google is one of the biggest companies in the world. Do they really need to be wringing their users as hard as they can to milk out every last drop of ad revenue potential?
I don't trust Google, but I certainly don't want Google to trust random websites on my behalf.
Also where does this end? Should car dealerships be allowed to analyze your data? Cars you've bought, cars you test drove etc.?
If you have a car with a broken lock, that's not some kind of open invitation to burglars to steal whatever they want from your car.
It's really not that hard. Google and Facebook just don't want to understand it.
Enabling incognito mode in Chrome and Firefox even explains that it doesn't stop server-side tracking, so it's not even misleading.
How? Incognito is meant to keep your history clear from other people who use the computer. It explicitly does nothing about websites tracking your activity.
>Your activity might still be visible to:
> - Websites you visit
> - Your employer or school
> - Your internet service provider
I was really hoping this would be a lawsuit about Google collection of information period, rather than a quibble like this. Please too remember that Boies etc are the same scumbags (and that's the correct term) who defended Theranos, harassing those who informed the government.
A Privacy mode that post the links you visit on twitter. ;)
DNT is a header, but it's a preference and not legally binding.
The only thing Google did that was "wrong" is that incognito gave uses the impression that they weren't being tracked externally, when in reality the only thing it does is not save your history and start with no cookies.
> Your activity might still be visible to: Websites you visit Your employer or school Your internet service provider
If you start from the axiom that Google should be broken up, this is a reasonable conclusion. But punishing a company for keeping separate products separate would actually undermine most anti-monopoly law.
There is even small subcultures on the web dedicated to avoiding Google by doing things like running 'degoogled chromium' and blacklisting various Google domains in their /etc/hosts file. Sadly all these mitigations don't work because Google already has a dossier on many people and even if you don't have a Google account, Google keeps tabs on you via fingerprinting or other means and knows who 'you' really are (using simple correlation and heuristics).
Then this raises the issue of: what can be done? I prefer to just be nihilistic about it and accept that Google already has dirt on me, despite my mitigations (I have a bit of history blindly handing over personal data to Google for a number of years). I think young people these days in 2020 have a great opportunity to implement mitigations and are better suited than me to browse privately, since I'm already contaminated by Google. (I still mitigate however, but it's not enough).
a billion bits is only like 130Meg a day, seems like google is doing pretty good.
I guess it doesn't make a difference to them, as long as they get the ad revenue from Pampers
Interestingly my instagram ads are incredibly on point a lot of the time. You cant really hide your behavior in the app so the get a really good picture, probably.
I wonder what it is they actually dispute, when the claims are so basic? Most popular websites use GA, so of course Google is watching every single user action across the Internet, regardless of if they have tried to 'opt out' via any methods, laws, processed, etc.
> The suit includes claims for invasion of privacy and violations of federal wiretapping law.
The claims Google disputes is that they are breaking the law.
> I wonder what it is they actually dispute, when the claims are so basic.
The claims can be summarized basically, but proving that someone has broken the law in court is not basic. This basic overview of federal wiretapping laws is over 70 pages[1]. Laws are filled with specific minutia. Here is another good overview of privacy law[2]. Even though the statement "Google violated my privacy" seems simple and self evident, to prove it in a court of law there are tons of very specific criteria you have to prove.
[1] https://epic.org/privacy/wiretap/98-326.pdf [2] https://www.stimmel-law.com/en/articles/legal-right-privacy
Deterministic = I specifically say I'm person X and am logged-in. Probabilistic = I am not logged-in on this browser, but am on the same computer, same IP, and am logged-in on a separate browser at the exact same time under name X. Therefore I'm very likely person X.
Nothing coming from PV can ever again be taken with a single grain of salt.
It's _very_ frustrating when people immediately discredit someone or something because they don't agree with them, even if they don't have the full story.
Project Veritas does some good work, even if they're blasted in popular culture/mainstream media for being 'biased', 'alt-right', 'etc'. I bet you the downvotes you're getting are just because you mentioned Project Veritas.
They have some very out-landish views, but when they actually put people on the street or go undercover, they've revealed dirt on a lot of companies and people.
It's shocking to me to see society go from "let's look at ALL sides of the coin, no matter how egregiously offensive they are to me" to "fuck 'em, they're trash media, they suck, they shill and are racist, alt-right losers and I'm not going to look at anything they post because in my mind everything they do is bad!"
I don't even go to Project Veritas outside of what I hear in the media, but I still give it a fair look and make my own opinion.
We can talk about tech surveillance without playing into the modern fascist agenda.
Even a single one of these incidents is enough to completely throw every thing you've done and said into doubt, let alone the half a dozen that PV has behind it. There is absolutely no way you can take anything they say or do serious after they've been caught times and times again lying and misleading.
It has absolutely nothing to do with how outlanding their views are, and everything to do with the fact that what they say or do cannot be trusted. I used to in the beginning, but they are way past being given a "fair look".
[0] https://www.bbc.com/news/world-us-canada-42150322
[1] https://www.theverge.com/interface/2019/6/27/18760463/projec...
In my experience in adtech, not only can Google do this pretty accurately, but other third parties as well (e.g. DMPs and the like.) Even if they couldn't make a deterministic association, they have enough data points to make a probabilistic association with high likelihood (ex: "Given all these data points, we're 95% confident that these two people are the same. Therefore we're going to attribute the actions to the same person.")
Now, to qualify my response a bit, this isn't necessarily for security / law enforcement, but mainly for better targeting parameters. Example: frequency capping of ads (buyer specifies that you only see an ad X number of times in a given time period) or more relevant targeting (you don't see completely different ads in different browsers as if you're from two non-overlapping demographic groups.)
It’s against the practice of fingerprinting users across products and services.
I've seen this _exact_ phrasing so many times in responses to lawsuits that I'm now starting to wonder if future lawyers receive this template as a graduation fair well package.
A lot of oddball conventions, such as THE USE OF ALL-CAPS in specific places, which have no reason to be legally meaningful, but are always done.
Some of them do turn out to be important. Standard clauses build up over time.
I think plaintiffs are right in this case. Google is openly breaking a number of laws, including CFAA. This constitutes unauthorized access. CFAA is a broken law with an overly-broad definition of unauthorized access, which the tech industry abuses all the time. It will be nice to see them get abused back. Perhaps they'll have incentive to fix it.
I think it's worth noting the class-action lawsuit is asking for at least $5 Billion
I'll also encourage the use of DuckDuckGo.com for your search and [1] uBlock Origin, [2] Searchonymous (it prevents google from tracking your searches if you're logged in to an account), and [3] Google Search Link fixer (removes link tracking from Google Search links) in Firefox, but would happily update if anyone has better recommendations.
[1] https://addons.mozilla.org/en-US/firefox/addon/ublock-origin...
[2] https://addons.mozilla.org/en-US/firefox/addon/searchonymous...
[3] https://addons.mozilla.org/en-US/firefox/addon/google-search...