As a totally non-web example of this, as of 2017, "Google’s third-party partnerships ... capture approximately 70% of credit and debit card transactions in the United States." https://adwords.googleblog.com/2017/05/powering-ads-and-anal...
When you buy something with MasterCard, in person, with a magstripe or even an old-school carbon-copy imprinter, MasterCard can go give that data to Google.
I think the incognito warning could say "Websites you visit, and anyone those sites share data with" to draw attention to this, but I'm not sure if that's quite enough. I'm leaning towards the argument from this article that "incognito" itself is simply a poor name.
Google's TOS (as you can see linked there) seems to apply to both Chrome and Google Analytics. By downloading Chrome and agreeing with their EULA, you already acknowledge that this data is being collected. I don't really get what people are objecting to, here.
And Google's Privacy Policy linked to off of there is one of the subjects of the lawsuit and that it is deceptive.
I don't see the difference between that and, say, Coke selling a product called "Diet Coke" that just has regular coke in it. A disclaimer reading "Warning: this is just regular coke," might make it legal but it's still messed up, and I wouldn't blame someone for trying their luck in the courts over it.
That's something which should be adequately disclosed by the websites you're visiting, which the problem that GDPR tries to solve (and currently fails to solve due to poor guidance and enforcement). Ideally a GDPR "cookie banner" should simply say "This site uses Google Analytics, <other services> to track you across the web. [Allow] [Deny]" instead of the current dark patterns.
There is ONE simple answer here that is in the best interest of your user, and that's rip the invasive 3rd party analytics out of your website.
Anything else is failing to put your users first, and eventually those users will go to a competitor who does. There's so much opportunity out there right now for startups that prioritize decency.
That's kind of the point of GDPR. But they're not enforcing the main requirements under the law - that the consequences are clear and that choosing to allow or disallow are equally as simple.
> alleges the Silicon Valley giant misled the public about how much data it collects from users even when they're in its Chrome browser's "Incognito" private browsing mode.
The accusation is that Google is leveraging Chrome to track you even in incognito mode, and it does not give any notice that it is doing so. It warns about the websites you visit, about who owns your local network, and about the ISP, it doesn't warn that Google is still actively tracking you in incognito.
So not using Chrome. They’re arguing that Google is collecting the usual web tracking and that other Google apps a user might have collect user data.
> Plaintiffs allege that Google collects data from them while they are in private browsing mode "through means that include Google Analytics, Google ‘fingerprinting’ techniques, concurrent Google applications and processes on a consumer's device, and Google's Ad Manager." Id. ¶ 8. According to Plaintiffs, "[m]ore than 70% of all online publishers (websites) use one or more of these Google services."
> Specifically, Plaintiffs allege that, whenever a user, including a user in private browsing mode, visits a website that is running Google Analytics or Google Ad Manager, "Google's software scripts on the website surreptitiously direct the user's browser to send a secret, separate message to Google's servers in California." Id. ¶ 63. This message includes six elements, each of which is discussed below.
[...followed by a lot of detail on what gets tracked...]
https://casetext.com/case/brown-v-google-llc
So there is client-side telemetry which completely de-anonymizes and geolocates you and Google tracks you in incognito mode everywhere that Google Analytics is deployed (~70% of the web). If you use incognito mode and visit porn sites that use Google Analytics, then Google has your complete de-anonymized porn surfing history in their databases. This is not what people are led to believe is happening by the incognito warning message.
This is not supported by the quote you posted.
- Google Chrome won't track you in Incognito mode.
- Google Analytics javascript (if added by the webmaster to their site) will track you in any mode.
So the lawsuit is saying, "Google promised us that Incognito would let us browse privately, but Google is still tracking us". To me, they're really muddying the waters here, because clientside Chrome doesn't track you, but, doubleclick on a website, will still track you.
According to this lawsuit, Google's biggest sin is saying "Now you can browse privately..." but when you open Chrome Incognito it clearly says "Your activity might still be visible to websites/employer/ISP"
Kind of a weak case for the plaintiff, and a weak article (engineers joked about the icon? and wanted to change the name? It's definitely a shitty name but this article makes it sound like this a smoking gun.)
Why the hell wouldn't anyone? I mean, expectations of privacy have eroded, but "you used this company's product, so you must be giving them permission to see everything you do with it" is an argument that, despite many companies' attempts to push it as just common sense, doesn't and shouldn't fly.
VSCode collects telemetry these days.
I completely agree that it is the status quo, but it shouldn't be. It's unreasonably for people to be surprised by violations of privacy, but I don't think that it's unreasonable for people to expect respect for their privacy.
In that context, companies do their best to guess what their users want and ask for explicit consent when they can't. In Google's case, once we actually dig down and unravel the complaint that was filed by the Texas AG (https://www.texasattorneygeneral.gov/sites/default/files/ima..., page 55-ish), the claim is Incognito mode doesn't stop targeted advertising based on browsing behavior because the fact that browsing occurred is known by the servers. Well, duh. Of course servers have a history of access to them; expecting them to not is like expecting Amazon to not have a list of people that ordered from it (how are they supposed to ship you what you ordered if they don't know that?).
And in the cases where people have gotten retargeted ads because they went incognito and then logged into Google... how the heck do they figure they're in any sensible way "incognito" when their name and face are at the top of the page they're viewing?
Cloud Word and Cloud Excel obviously do, but "online services are online" had better not be surprising.