Websites selling abortion pills are sharing sensitive data with Google
propublica.org
propublica.org
For 1) not everyone is tech literate. You're telling me that everyone you know also knows that companies like Google, Apple, Amazon, Netflix, etc are capturing your data across the web? That they can (almost) uniquely identify you? You've probably been living in SV your entire life and never traveled around the bay -- or further -- if that is an honest statement. This statement comes off as self serving, saying that _you_ know better. Maybe the article isn't for you, and that's okay. You don't have to comment. The comment section may not be for you either. Post if you can _contribute_ to the discussion, otherwise don't.
For 2) I understand the concern, but ProPublica has long worked with topics like these and legal issues. I guarantee you that their staff has enough expertise to understand what browser fingerprints are. That's really not a high bar so your screams for experts are falling short. They list the tool they used and the websites in question. Your calls for expertise will raise if you give reason to them by pointing out how a tool might be flawed and/or that websites are actually capturing fingerprints like the article claims (but that can change after the article's release). So if you want to disprove the article disprove it instead of making a call to authority. Otherwise you're just noise.
Ironically these two types of posts are in direct contradiction to one another. But can we please stop and actually discuss the article instead of you? This is a stupid flame war and most of us just want to discuss the actual contents of the article. Please don't even respond to this, just participate in the conversation to the actual contents of the article.
I worked in construction about a decade ago when the Snowden thing was big and I asked a construction worker with a grade 10 education from a rural part of Canada what he thought of it and he chortled before saying 'of course they're spying on us. They've always been spying on us.'
Meanwhile I have a friend who is a lawyer for the federal govt and this guy just can't seem to grasp anything regarding privacy law and why people care about itm. Meanwhile he's flabbergasted that Madison Square Gardens has the technical means and gall to kick out any lawyers tenuously related to legal action against them.
At some point people are responsible for their level of ignorance. I dont know where that point is but I'm sure that it exists.
The article is about __HOW__ the man spies on you.
> At some point people are responsible for their level of ignorance
Sure, but my point is that we shouldn't enable that ignorance by making people feel stupid for not already knowing. That's not helpful to anyone involved. I'd explicitly consider this a worse position, which is why I'm complaining.
To somebody not tech literate, how big a difference is there between COVID tracking chips and the Google tracking cookies in online pharmacies?
Why is this even a story?
We can't just wipe it away with "we already know this is happening" when its wrong in the first place.
Hell, now some websites even default to "non-required" tracking off, and literally do not require you to do anything to limit the data they harvest from you. And I'm pretty sure this is some third party's drop in solution.
GDPR doesn't specify UX.
But if they are headquartered outside the US like many online pharmacies are, likely they are going to just ignore any law enforcement requests for user data.
Putting myself in the shoes of an online pharmacy selling abortion meds, I would be crazy to headquarter in the US. I'd be surprised if even a few were US-based.
[1] https://www.techdirt.com/2017/03/17/judge-grants-search-warr...
This entire premise of this article advantage of people who aren't technically inclined and can't know well enough to realize that reverse engineering GA fingerprints is not even close to how the government would de-anonymize visitors.
If your local government decides to overreach and find out who's getting abortion pills, Google Analytics will not even be your 1000th biggest problem. ISPs will readily share which sites people visit, the stores themselves will get leaned on, your mail carrier with share where you get packages from.
I mean did you even read the article? "Abortion Ease, BestAbortionPill.com, PrivacyPillRX, PillsOnlineRX, Secure Abortion Pills, AbortionRx, Generic Abortion Pills, Abortion Privacy and Online Abortion Pill Rx."
What do you think HTTPS is going to do when one of these urls shows up in your traffic, email inbox, and a reverse mail address look up leads to one of these?
Putting words in my mouth has got to be the worst faith argument I've seen in a minute.
> If your local government decides to overreach and find out who's getting abortion pills, Google Analytics will not even be your 1000th biggest problem. ISPs will readily share which sites people visit, the stores themselves will get leaned on, your mail carrier with share where you get packages from.
And it's much easier for website operators to stop using Google Analytics than it is for them to educate their customers on using VPNs and mailing their packages to dead drops (let alone for their customers to actually do those things).
This ain't about dichotomies or the lack thereof. This is about what people can do now to mitigate low-hanging fruit. Nobody said the solution is only to stop using GA; literally all that was actually said is that not using GA is something that the operators of such stores can trivially and immediately do.
That is:
> What do you think HTTPS is going to do when one of these urls shows up in your traffic, email inbox, and a reverse mail address look up leads to one of these?
The existence of problems outside your control does not erase the existence of problems entirely within your control. Website operators cannot force you to use a VPN or a secure email or an anonymous address. They can minimize the data of yours they're sending to third parties.
> I mean did you even read the article?
I mean did you even read the HN guideline specifically prohibiting such a question?
"it's much easier to not use Google Analytics than it is to convince your government to clamp down on law enforcement search powers."
You literally wrote a one sentence comment that compares a decision for website owners to choose between not using GA and convincing their government not to clamp down on law enforcement search powers. I didn't put a single word in your mouth in stating what I did.
You wanting to walk back what you wrote doesn't make my comment put words in your mouth, they were the words you said.
> And it's much easier for website operators to stop using Google Analytics than it is for them to educate their customers on using VPNs and mailing their packages to dead drops (let alone for their customers to actually do those things).
GA is completely orthogonal to the entire discussion. That's the point that ProPublica (intentionally?) ignores, and apparently you're just unaware of.
It's doing literally nothing to protect or harm these people, because the government is not stooping to deanonymizing GA data when there are 1001 more direct and better established methods to achieve the same thing, it's a frankly absurd point.
Saying by not using GA they're even tangentially protecting customers shows a complete lack of understanding of why this government overreach is such a problem.
-
tl;dr/too technical;didn't understand: The government doesn't need your GA fingerprint they can get the things that the fingerprint is made and then some straight from Google... and your ISP... and the site's host... and the mail services.. and the list goes on.
They can literally ask for all people who searched for a given term in a 5 block radius and you're trying to talk about hashed fingerprints???
It's like worrying that the government is going to check for your DNA in the toilet at a local restaurant when the establishment can be compelled to give them a receipt with your card details, your bank will give them the transaction details, your search history with the restaurant name is up for grabs, the municipal security cameras that watched you drive up are up for grabs...
-
Once you understand that then the pointlessness of this line of reasoning comes up, and why ProPublica is doing this becomes more questionable.
By inventing some totally ludacris wrong, they're painting themselves as having uncovered some unique in-depth aspect to the dynamic between these abortion pill sites and their users, but to do so they're painting the sites as negligent with the most inane stretch of logic possible.
Instead of focusing more on the actual problem, the overreach, they create a new boogeyman because it gives their reporting a unique angle. But of course that boogeyman is serving the interests of people who are having their rights stomped on.
By completely misunderstanding the topic (and in ProPublica's case I'm not buying it was unintentional) both you and the article are just throwing FUD into the actual conversation that matters.
It's annoying to see supposedly creditable publications intentionally muddy things for their own benefit, and it's even more annoying to see people with a poor grasp of the situation just run with it blindly without taking 5 seconds to apply critical thinking and context to it all.
Right, and note what I didn't say:
- Whether or not those things are a dichotomy or otherwise mutually exclusive
- Whether or not those things encompass the complete set of privacy violations or the mitigations thereof
Your assumption that I've made or even implied answers to either of those within the words "it's much easier to not use Google Analytics than it is to convince your government to clamp down on law enforcement search powers" - and then arguing against that assumption - is where you're putting words in my mouth. It's also what makes you accusing me of bad-faith argumentation or a lack of critical thinking or context hilariously ironic.
There's nothing for me to "walk back". You blew up at me for merely suggesting that businesses which should be valuing their customers' privacy can take very easy steps to actually signal that. Whether or not they're siphoning a bunch of data to third parties is a rather strong signal of whether or not they take their customers' privacy seriously, and the fact that you are not only incapable of understanding that concept but feel compelled to resort to unwarranted hostility and personal attacks in response to it speaks volumes.
> GA is completely orthogonal to the entire discussion.
GA is literally the context of the discussion. Just because there are other ways for others to violate your customers' privacy doesn't mean it's okay to willingly and deliberately violate your customers' privacy yourself. That you not only fail to understand this but are needlessly hostile to those who do understand this speaks volumes.
If you'd like to have an actually intelligent and civil discussion instead of angrily flinging insults at me, I'd be happy to oblige. Until then, have a nice day - hopefully better than whatever tragedy you're choosing to take out on me.
By the time I got to the invention of "angrily flung insults", and projection about bad days I had my answer...
Either the writer or an editor who ultimately decided on the headline.
If you've ever seen any SaaS websites where they have...
- Our Product vs Competitor 1
- Our Product vs Competitor 2
- Our Product vs Competitor 3
- Our Product vs etc...
... then you can see why this is important from an SEO perspective.
The privacy implications here are totally different than for a travel blog.
When will people realize that surveillance capitalism is morally bankrupt (aside from also being a fraud), and that personally identifiable information is toxic waste?
This is so far beyond "Don't Be Evil" . . .
Online retailers selling marijuana products send fingerprints to Google Analytics overwhelming majority would not care
Brothels selling appointments online send fingerprints to Google Analytics overwhelming majority would not care
Online retailers selling firearms send fingerprints to Google Analytics overwhelming majority would not care
The reason you're hearing about of this is because HN cares a lot about abortion whereas all those other topics are of much less importance around here.
Breaking news: the business is a gym, and the area includes the showers.
It's a story because it's a privacy violation and also a HIPAA violation.
Very similar to the case where health care providers were using Facebook trackers which was sending PII and PHI (private health info) to Facebook which has triggered multiple lawsuits.
https://themarkup.org/pixel-hunt/2022/06/16/facebook-is-rece...
It's great that some light is being shined on these violations. You can't just put spyware tracking on sensitive websites.
The title in the article is more accurate: "...Are Sharing Sensitive Data With Google". Perhaps it was updated later. Or there was some misuse of the word "fingerprint" (i.e. browser/device fingerprint, opposed an actual scan of your finger).
HIPAA doesn't prevent law enforcement from acquiring data in the interests of a criminal prosecution. Meanwhile, the data as currently silo'd is not sufficient to figure out who somebody is (ad companies are real keen on that, because they don't want the sites they serve to harvest ad data on their users and side-step the ad services; as a result, the fingerprints are usually double-blinded in a way such that only the user's browser can aggregate enough data to "know" who the user is).
So, your bill from buying medical devices or drugs will be available as plaintext to Big Tech even if you block analytics third-parties.
Seems like it would be easier for LE to threaten a small pharmacy versus a big corp like google.
Not in general in this scenario. Google has made exceptions in the past (generally around an emergency with threat to life involved), but they're reluctant to make such exceptions for even federal LEO. State-level LEO, which is who would be making these requests, has far less leverage over Google; they could make it harder for Google to do business in their state, but (a) the states we're talking about are doing that already, so Google cares less about a lever that's already being pulled and (b) the states don't have higher authority to appeal to (what are they gonna do, try to make a Supreme Court case out of noncompliance with... A warrantless data request?).
They review, question, narrow, and reject requests for user info. They also notify users unless prevented by a court.
https://policies.google.com/terms/information-requests?hl=en