Google is facing a lawsuit for tracking people even when they opt out
businessinsider.com
businessinsider.com
I don't know what the right answer is yet. Manufacturer responsibility v. personal responsibility is an old question, and it's why we have court systems.
Just because you pay them doesn't mean they're not tracking you. Look at Windows 10.
And just because they promise not to misbehave doesn't mean they're not subject to secret coercion (e.g. from China) or to getting hacked.
The only solution is for them not to have your data at all. It has to stay on your machine and never be on theirs.
It's really not clear what this lawsuit is about from this article, either. Is the problem the Google Cloud integration? Is the problem Google Analytics being shipped with apps? All that we can really tell from the information given is that there is some conflict between non-Google apps and the Google privacy settings, which just sounds like a strange tension. Like, of course non-Google apps are not subject to Google's privacy policy. Still, this lawsuit may have some indirect effect where Google someday needs to rebrand, and the apps that it sends straight to you like Docs and Gmail continue to be “Google” while the platforms for other developers like Google Cloud carry some other name as part of a different subsidiary of Alphabet, Inc.
I don't want to speculate too much about that, it seems strange but that's why we have court systems to work through the stranger points of law.
In what sense?
The question remains if Tesla expected more goodwill from the common/popular imaginative view of the thing over the technical description, and I have no idea how "deliberate" that was.
I also probably should have put a sarcasm/irony tilde on mistake as my post above was intended more as a joke than an honest attempt at problem solving.
Firebase isn't that at all. It can be used to build such things, but so can PHP and CSV files.
https://firebase.google.com/docs/analytics
Of course Firebase is more than just analytics, but it sounds like it does offer much better tools for tracking than PHP.
You can use PHP and CSV for purposes unrelated to tracking. Firebase cannot be used without any tracking going on.
Firebase at its core is cloud functions, triggers, and storage.
Google would obviously never divest the Ads business, as it is a large revenue stream. Instead they would divest the non-Ads components of Chrome/Android/etc. Given that the larger purpose of those platforms is to create more surveillance subjects (commoditize your complements), this outcome would actually be somewhat sensible.
[citation needed]. Apple should fit that category, and while they have added features to throttle how users can be tracked they haven't exactly gone thermonuclear on tracking in Safari.
This is how browsers have increasingly implemented the feature as well, to match user expectations. Arguing that incognito mode is solely a "I don't want this in my history" feature ignores how it is perceived by pretty much everyone.
And as long as you don't log into Google, Facebook, Amazon, etc. accounts during that incognito session, third party sites really can't track you once the session ends. (Yes fingerprinting is a thing but I don't think it sees that much real-world use.)
Fingerprinting is such a pervasive problem on the internet that Safari and Firefox both advertise fingerprinting prevention as a core privacy feature.
It's also used heavily in endpoint security products and services, and was gaining traction in financial institutions as long ago as 2010.
They get the benefits of being a megacorp. They should get the drawbacks too.
Tech cooperation and infighting, like governmental cooperation and infighting, has its pros and cons.
"I'm sorry mister judge, the the rootkit happened to be owned by my company and written by my devs, but there's mere chance."
Here: the user turns off data collection from Google services, but third party apps use a Google Cloud offering to collect analytics (which Google cannot access).
Previously: I launched Chrome in incognito mode, but when I log into Google it records my activity.
Given the article's mention of Oracle as a client, it seems likely this is part of Oracle's continued smear campaign against Google. Keeping a stream of negative headlines regardless of substance, especially as the big Supreme Court case looms.
I was intentionally leaning away from linking the two cases too closely so as not to foment a conspiracy theory, but "Two cases from the same firm" isn't conspiracy; it's just strategy.
[1] https://support.google.com/firebase/answer/6383877?hl=en
The controls do not work.
If you're seeing targeted DLCK ads while visiting some site, it's because the site has semantic information on you and has told Google "This user looks like they like puppies; I know this because they read a lot of puppy articles or I have a social media arm and they joined a puppy message group that I manage accounts for. Get that user a puppy ad."
Now, how individual sites track you and unify their concept of your session with their concept of your ad targeting is up to them, but it's worth noting they're allowed to use basically anything (including first-party cookies, browser thumb-printing, and local store API) to do that. They can also share information with other sites (using mechanisms like image bugs to let an affiliated site know you visited their site and what your userID is on their site, so they can compare notes later and build a comprehensive ad profile for you). None of this requires Google's involvement.
I uploaded a picture to google maps as part of a review. About a month later I get an actual notification on my phone - hey do you want to share this picture you took in City Park last weekend? It creeped me out beyond belief. Google had been rifling through my personal pictures in the background while I was going about my life. It was an enormous breach of my personal space and it is just one example of many related to google.
>I uploaded a picture to google maps as part of a review
You uploaded a photo to a public service, cool:
>Google had been rifling through my personal pictures
Not sure how that follows. Did google take a different photo from your phone and I'm misunderstanding you?
> About a month later I get an actual notification on my phone - hey do you want to share this picture you took in City Park last weekend?
He took a picture and put it on a public service. A month later that service asks him if he wants to share a picture that he took last weekend. Since last weekend cannot be as far away as a month ago one can not conclude anything else then that we are talking about a different photo.
I'm pretty sure that's the local Google Maps client app rifling through the locally-stored photos (because it has permission to see the metadata for photos on the device). I can see how one could find that creepy, though I think it's relatively harmless. Is the specific issue that one doesn't want Maps to be able to infer you took a photo at location Y just because you once uploaded a photo at location X? Is the issue server-side Maps making the inference or client-side Maps (b/c client-side knows where you are and can see your photo metadata, so it doesn't actually need a server in the loop to ask that question)?
Other people may use it for other things— that’s fine, as long as it behaves itself on my device when I don’t use those features.
A corollary is that the app shouldn’t ask for a permission until the user has asked it to do something that will obviously require that permission.
Whatever, I don't care. I could infer now that my entire photo library has been uploaded to google and is in some database somewhere. Or that every picture has been scraped for location data and recognizable landmarks, and all of that data is somewhere on google.
Whatever it is, I'm freaking disgusted.
Seeking the balance point is an ongoing process.
So if Google runs analysis on your photos, in their cloud, in a manner that doesn't cross information with other users, then we could consider this functionally equivalent to a system that runs it entirely on your device.
In many ways this is similar to search indexing for gmail, and other 'assistant' behaviors such as "you didnt reply to this, do you want to?" prompts.
This is the entire underlying premise and promise of SaaS and "the cloud".
I do think the well has been poisoned here in HN, using conspiracy like thinking, poor reasoning, and generally doubling down on confirmation bias. Some people hold Google to a higher standard of proof than anything else in their life - while a sign of mistrust, it is often based on wild accusations and bad faith arguments, eg: in this case lawsuits from ORACLE of all companies (literally the poster child for bad corporate culture, sexism at the CEO level, and sneaky business practices!).
Arguably the big guys being at war with each other is one of the few saving graces for all of us little fish.
Sometimes the accusations they throw at each other will have merit, and other times not so much. Each accusation therefore deserves separate consideration.
Google doesn't have to rifle through anything; from the application's point of view, that information is as clear as the filename and the color of the top-left pixel.
* what app you used to upload the image to Google
* what Google app / service identified the image
* how you uploaded it (i.e. if you uploaded it via a smartphone with location services on, I imagine Google is allowed to say "Hey, this upload is being done at this lat/lon, which I've determined either from GPS or from cell and wifi triangulation").
I have mixed feelings about sharing my location with Google at all times, but this one feature is actually very useful to me, and provides real value.
The Web & App activity is described a help page article [1]. There are different settings for Android, Desktop and iOS. If you follow the dialog for the Desktop version you'll see another dialog that displays:
"Include Chrome history and activity from sites, apps, and devices that use Google services"
It's not clear what's being claimed in the lawsuit, but they mention Firebase, which is an app and web site framework. I would expect those opting in or our of the Web & App activity would cover signals from Android and Chrome, but not server-side components like Firebase and Analytics. I would expect those Android and Chrome signals aren't just hidden from the user and that they actually aren't transmitted or stored. From what I have seen Google tries to be transparent with everything in the My Activity portal [3].
It's not clear what they claim is being collected via Firebase.
[1] https://support.google.com/websearch/answer/54068?co=GENIE.P...
[2] https://myactivity.google.com/activitycontrols?pli=1&authuse...
> Web & App Activity
> (Paused)
> Used by Assistant, Google Maps, and others
> If you turn this setting on, Google will save your activity on Google sites and apps in your Google Account, including searches and associated info like location. You can also choose to save which apps you use, your Chrome history, and which sites you visit on the web.
(emphasis mine)
To me, that reads like a careful lawyerly declaration that they are already saving all my activity, but if I turn this on, it will also be saved in my Google Account where I can see it.
https://policies.google.com/technologies/retention
See also:
Is there someplace else I can explicitly delete that data?
The answer is that you don't. These companies estimate how many people block cookies or pie-hole requests to /dev/null or have ad blockers, etc. Their estimations are bad and they don't really know. It's a real problem.
Since you can't demote it past the last sentence, maybe they should change it to "Whatever sells" or something similarly mercenary.
Is anyone surprised at this point?
Web & App Activity tracking collects data on usage of apps and browsing and sends them to the Android project (for improving the OS). Firebase is a framework and service for third parties to build tracking like that into their individual products, and it has an entirely separate history from W&AA tracking. It happens to be owned by Google (as of recently), but the data isn't in the same hoppers as the Android hoppers and Google can't see it (it's part of the Cloud offering; Google offers the service and stores the data, but aggregating or using the data itself would be a violation of their agreements with Firebase customers). Firebase and W&AA tracking are two different subsystems owned and maintained by two different departments at Google (in fact, hypothetically, they could build W&AA tracking as a client project on top of Firebase, if they hadn't already built it).
Firebase was an acquisition; when the W&AA tracking feature was added, Firebase wasn't even part of Google. This is a lawyer recognizing that an acquisition has created a novel arrangement that could be interpreted as suspicious.