Stanford researcher: Google Circumvents iOS Privacy protection in AdSense ads
eff.org
eff.org
Deliberately exploiting a loophole to circumvent privacy controls is scummy behaviour, the sort of thing you expect from the industry's bottom feeders, not from one of the biggest companies in the game and certainly on that professes some sort of conscience.
You can argue its not really evil but it's hard to say its not another step towards that, and this time it seems hard to suggest that it's contractors or some peripheral part of the company.
It may be as little as a shifting set if priorities so don't be evil is less important and other things a little more and with that the cracks appear.
I'm not suggesting that they're now spending their days plotting how to enslave us all but I similarly can't believe that there hasn't been some shift, conscious or unconscious.
In the same way reporters are always on the lookout for political gaffes instead of substance from our candidates because that's what viewers watch, statements like this are really just calls for more marketing and fewer frank answers.
A good example is the Target profiling that was on HN yesterday. Google collects your personal information to target ads to you, but they don't hide that fact. They run ads on TV and in the subway to tell you what they do, why, and how it affects you. They let you opt out of targeting. They rewrite their privacy policy to be as readable as possible. They change their privacy policy and notify you, logged in or not, on all their sites. Basically, Google wants you to use information to make an informed decision about whether or not you want to give Google your data. Compare this to Target, where they deliberately hide their targeted ads so you don't realize you're being targeted.
In the end, both Google and Target do the same thing: profile you to make advertising dollars more effective. Google tells you what they do and why. Target lies to you so you don't know you're being profiled. And then people get outraged at Google for becoming evil, even though they're the only ones that don't lie to you!
The full quote is
Q: People are treating Google like their most trusted friend. Should they be?
A: I think judgement matters. If you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place. But if you really need that kind of privacy, the reality is that search engines including Google do retain this information for some time, and it’s important, for example that we are all subject in the United States to the Patriot Act. It is possible that that information could be made available to the authorities.
Like, you should quit being gay, or a woman in a tech forum, or a person of color, or a jew, or having leftist opinions while working for a conservative boss, or vice-versa after you changed jobs, and quit having an address your abusive ex can discover, and quit secretly liking Lady Gaga.
Okay. Got it.
As for protecting your information from your friends, I think Google does a pretty good job in the situations you mention. Google doesn't share your search history with anyone. You don't have to pick a gender to use Google+. You don't have to list your race, ethnicity, or religion. And, Google+ provides a number of privacy controls so you don't inadvertently share your leftist feelings with your conservative boss.
The absolute safest way to protect information is to not disclose it to anyone. That's all Schmidt is saying. If you're planning to overthrow the government, don't post your plans to Google Docs. If you're just worried that your boss won't like you, though, then you can be a little more relaxed, and share things via Google+ with close and trusted friends. Then, the main attack vector is no longer through Google; the risk is that your friends will re-share something (offline or otherwise) that you didn't want them to. And that's just life as usual.
The whole point is that no-one should be able to say "this is important that it stays private, this isn't important".
For one thing it's none of their business, for another historically the most unusual things have been used for discrimination or oppression. What may be seen as acceptable today may not be so tomorrow. What may be the folly of youth now may be seen as a clear lack of judgement tomorrow.
Everyone is waiting for Google to become evil, but the infrastructure is just not in place for that.
As I think I said, I don't think anyone is suggesting that Google senior management are actively plotting how to enslave us all, but there does seem to be a pattern of things which suggest a shifting of priorities.
If (scummy < creepy){console.log("film@11")};
else google = evil;
Tracking users is Google's core business. I'd be surprised if they were the only people who have figured out how to do this sort of thing.Holding Google to some higher standard than other companies is naive at best. Its management has the same duties to the stockholders as any other company.
Don't be evil isn't the standard I set for them, it's the standard they set for themselves.
Last time I checked, JSONP is a workaround for Single-Origin-Policy. If a site A uses JSONP to consume service from B, then A bets its money on B's good will. I don't see B can steal anything other than A's in-browser data.
> How so? ... JSONP is a workaround for Single-Origin-Policy
That's how so.
I know I know.. the services are laid out and people know that their information is being sold. But does that mean it's right? Sub-prime mortgages were legal and led to a disaster. My fear is that not having a set of guiding principals in regard to privacy will result in over-regulation or some other bad scenario.
(But what if Debian ships me a version of gcc that embeds secret tracking code into any version of Chromium I compile? Oh the fear, uncertainty, and doubt!)
Yes, that's hard, but that's the price of freedom. I appreciate that Google at least lets me choose how I want to use their code, where Apple and Microsoft make the decisions for me and never let me double-check them. (As it stands, I trust Google with my personal information and I think the places where Chrome/Chromium communicate with Google are appropriate and make my browsing experience better. But it's 100% fine if you don't feel the same way.)
I think, rationally, I should be more afraid of what Google knows about me than a random person. I've used Google to search for things I wouldn't exactly want to bring up in a meeting with my coworkers. But I know what the procedures are for accessing personal information, and I trust my employer with my most private searches. (It takes a leap of faith to trust me on this, so I don't expect you to. But really, Google cares about privacy.)
When I worked at Bank of America, I always felt weird buying stuff with my Bank of America credit card because I knew someone at the company would have access to that information. But I don't feel that way when using Google Checkout / Google Wallet at all. I don't know why it is, but that's how I feel.
yeah because Webkit isn't open source...
In normal use, I think you will have to disable "use a web service to help resolve navigation errors" and "enable phishing and malware protection" to prevent all connections, but I'm personally ok with those (and find them sufficiently well documented)
your very shallow analysis.
they update the browser hourly. you do not have access to the build environment they use. and there's no authority linking the source you can read and the binary you allow google to install. so unless you build it yourself, not a valid argument.
and even if there's no evil doing in all that (i too believe there isn't. but again, only believe) there's still the issue of new features being added, and the bad defaults being to agree with all data sharing. So even if its all good, after each update you will be inadvertently sharing your information until you take time to review all settings.
And, there's also the cases when google simply decide agains some feature that may hurt them. They removed the options to not send referrer. it was added back several times. and removed again several times. first in command line argument, then hidden setting. when i stopped caring it was completely gone if not from compile time.
To Chrome's credit, I believe it is the only browser that allows users to delete flash cookies.
* removes tin foil hat
Just go to the Privacy pref pane and click on Details under Cookies and other Web Site Data. For example, for kongregate.com, I see that I have Cache, Cookies, Plug-ins and Local Storage holding potential tracking data, and I can delete it all with one click.
# Remove Flash cookies and everything to do with Flash,
# including left-over Flash files in /tmp
15 13 * * Wed /usr/bin/rm -rf /home/nick/.macromedia/Flash_Player/*
16 13 * * Wed /usr/bin/rm -rf /tmp/Flash*edit: to be clear, whether or not is was an intended side effect, it is a side effect of a (potentially) legitimate use case (setting the value of +1-ing an ad aside).
Seems tome that you have more to worry about in Apple than Google as there many others using the same exact hole.