No they don't. Nothing in your comment sounds anything like Google claiming to be tracking people. And as mentioned elsewhere in this thread, they explicitly claim to not be tracking individuals.
No they don't. Nothing in your comment sounds anything like Google claiming to be tracking people. And as mentioned elsewhere in this thread, they explicitly claim to not be tracking individuals.
>> "The information included in this header reflects the variations, or new feature trials, in which an installation of Chrome is currently enrolled. [...] it is not used to identify or track individual users."
I believe this statement is true. They are not using the X-Client-Data HTTP Header to track "individual users". As they state in their "Privacy Whitepaper"[3], a "low entropy variation" is
>> randomized based on a number from 0 to 7999 (13 bits) that's randomly generated by each Chrome installation on the first run.
This per-installation 13 bit id number is sent in HTTP requests to certain Google domains:
>> [...] a subset of low entropy variations are included in network requests sent to Google. [...] These are transmitted using the "X-Client-Data" HTTP header. [...] This header is used to evaluate the effect [of the variation (presumably?)] on Google servers [...]
Google is explicitly saying they are tracking the new 13 bit id number. This particular id number is somewhat low granularity, due to the limited bit length, which - as Google correctly claims in their statement to the press - is too small to "identify or track individual users". Regardless, they are still claiming they track a 13 bit identifier tied to "each Chrome installation".
I never said the X-Client-Data header was enough to track individuals. An IP address doesn't uniquely identify individuals either. Google's use of language is hoping you stop there. The header is too small to be identifying, so it doesn't matter! This framing is only true if you limit your questioning to considering the "low entropy variation" number in isolation. If that was the only number Google was able to track, it indeed wouldn't be concerning. However, that number is probably transported to Google over the internet in an IP Protocol packet, meaning they are at a minimum also receiving either a 32 bit (IPv4) or 128 bit (IPv6) identifier in the Source Address field of each packet's IP Protocol header.
Google doesn't need to use the X-Client-Data header to "identify or track individual users". They can simply use it to disambiguate different Chrome installs that share the same public IP address. This usage of the number isn't identifying users; it's only identifying the different Chrome installs e.g. behind a typical household stateful NAT router. Both the X-Client-Data header and the IP address are both not unique personally identifying IDs. However, the tuple {X-Client-Data, IPv4 Address} is probably unique for most people. In the rare instance where it isn't unique, one of the related tuples like {X-Client-Data, IPv4 Address, User-Agent} will be.
The doublespeak is pretending the header "will not contain any personally identifiable information" when the stated purpose of header is to create a new tracking identifier that accomplishes the same thing as a personally identifying identifier when you combine it with the other data that Google already tracks (such as the 24 bits of "anonymized" IP address (they zero the LSB) that they store with each GA record.
[3] https://www.google.com/chrome/privacy/whitepaper.html#variat...
> when the stated purpose of header is to create a new tracking identifier that accomplishes the same thing as a personally identifying identifier when you combine it with the other data that Google already tracks
This is not stated anywhere except by you. The stated purpose of the identifier is to track analytics around chrome experiments, and only that.
The tuple (IPv4 Address, User-Agent) is already unique for almost all, so why go to all the effort?