Google +1 Chrome extension tracks https traffic
plus.google.com
plus.google.com
"In addition to the practices described in the Google +1 Button Privacy Policy, by installing this extension, all of the pages and URLs you visit will be sent to Google in order to retrieve +1 information. Examples of this information include whether you’ve previously +1’d the page and how many people have already +1’d the page. Google’s use of this information is described further in the following help center article (http://www.google.com/support/profiles/bin/answer.py?hl=en...). "
Tracking HTTPS traffic is really the big deal and it will probably be patched. For the rest, it is just like Google Toolbar, Internet Explorer, Bing Toolbar, etc...
Search engines need desperately this kind of data, it is not surprising that they try sneak "trackers" in any browser/extension, it is just unfortunate that they are not clear about it.
This isn't some sneaky side effect of the button, it is literally just the only functionality of the extension. They will probably still patch this to at least have a setting to not display +1's on https websites, but I don't really see where all this tracking talk came from.
If you are saying that they should have a database where the columns are (url, hash, count) and just have the browser send the hash, that is exactly the same as just encrypting the url, and the request is being sent of https. What sort of security do you think you would have from hashing that is lacking in SSL?
http://jimcofer.com/personal/wp-content/uploads/2009/08/tool...
Aren't these kind of extensions all about tracking you anyway? If there's a page or website you think is valuable then bookmark it. If you want to share it among multiple computer systems email the link to yourself.
Additionally, these extensions take up minimal space in Chrome. The screen real estate each one gets is the same size as the settings (wrench) icon. Sure, you could fill up your browser UI space with them, but it's much more difficult than it is with IE and there are more hoops to jump through in order to get them there. IE users were (are?) plagued by toolbars because they can be installed externally from the application. As far as I know, Chrome extensions can only be installed from within the application after several prompts and confirmations.
It shouldn't track the way it does, and it certainly shouldn't track HTTPS. It is not even an issue of privacy, it is simple courtesy and common sense.
Granted, it doesn't know if the visitor has friends that shared it. It still doesn't excuse them for sending all url's.
Facebook received a lot of flack for doing this and I don't see why Google should be excused for this intentional "gaffe".
I have to wonder if this is an unintended side effect of the recent push to have site move to HTTPS - it used to be that HTTPS requests were mostly unique to a user, but now lots of "regular" pages are being requested using HTTP and if you want to make any kind of extension that return data about pages (+1, anti-phishing, etc) you're probably going to to want to send HTTPS URLS as well.
Or make the +1 a two-gesture event: click the extension button (which is when "tracking" occurs) which opens a balloon, then click a +1 button within the balloon.
For now, I'm using "disconnect" - downloaded it, read the whole sources and installed it from a local directory. That's my level of paranoia right now.
Secondly, a lot of addons/extensions are actually asking for permissions to all visited pages - it should not be hard to figure out who the current logged in person is, if you do have malicious intent (Scraping opened FB/Gmail web pages) . There is inherent privacy risk in using extensions with a lot of permissions!
[1] http://www.quora.com/Google-Bing-Controversy-February-2011/D...