Google, make Google Analytics HTTPS by default
smerity.com
smerity.com
It's interesting that Google does not display the IP address to Google Analytics customers citing privacy concerns, but it does of course capture that data for itself. Put another way, Google believes displaying the IP address to analytics customers would be a privacy concern, yet you could argue that Google capturing that data for itself is a greater privacy concern because, unlike the indiviudal analytics customers, Google can aggregate all the phenomenal amounts of data it captures to build a much more detailed picture of online behaviour across multiple sites.
Google are not collecting this information for nefarious purposes, but no company should be allowed to collect such phenomenal amounts of data about users' online behaviour without scrutiny. For example, consider how little comment is made on the privacy implications of using ChromeOS where your online behaviour is not only captured by Google, it isn't even anonymous.
No other company has its digital fingerprints all over the web like Google. But Google gets an easy pass on matters of privacy and online tracking. Why?
Your other points are bang on.
None of these sites point out that Google, Facebook, etc can easily ID you and while you may be anonymous to the site operator you aren't truly anonymous. I've contacted Crimestoppers and the local police to ask about this and got nowhere. The bottom line seems to be that the police and Crimestoppers have absolute unshakable faith in Google and are comfortable outsourcing crime victims' privacy to an American advertising company.
[1] https://crimestoppers-uk.org/give-information/give-informati...
Security around this so-called anonymous data was thoroughly lax, and eventually someone is literally going to be murdered as a result of it.
There's one major problem that many people don't realize: The value in that data is immense and Google has corned the market in both analytics (recording the data) and advertising (using the data to profit). This profit comes directly at the expense of businesses - This means lower margins because they must pay higher ad prices to be competitive and attract or retain (see re-targeting on doubleclick) their existing customers who Google knows more about. The customers are worse off because the products they know and love get out-competed by similar knock-offs who invest less in the product/service development but more in ads. This tends to make prices for people higher over the long run and the benefit they get lower over the long run. It's like a Google tax which also reduces options.
Heh, and that's saying that the NSA isn't already paying Google for their https private certs and using the massive mountain of customer data already. I'm tending to think that the NSA has already though of that one.
But of course there are the usual dirty tricks, too, causing user confusion as you mention.
ga.src = ('https:' == document.location.protocol ? 'https://ssl' : 'http://www') + '.google-analytics.com/ga.js';
To this:
ga.src = 'https://ssl.google-analytics.com/ga.js';
While the Google Analytics JS is loaded over HTTPS, the tracking information sent back to Google inherits HTTP/HTTPS from the website itself.
That means if you're on a HTTP site, it'll send back the results over HTTP. You'd need to actually hand roll your own GA JS to have it send back over HTTPS and then I'm not certain if that'll cause issues with records at Google's end.
And for the newer analytics.js: https://developers.google.com/analytics/devguides/collection...
The HTTPS proposal might be expensive but it would prevent this. Every mainstream and beacon and CDNed JavaScript would have to be on board though.
... also whenever people use all those CDN-hosted jquery and other popular JS libraries. Which is - unfortunately - also widespread practice these days.
Somebody hijacked some servers from Movistar Peru / Argentina, and are serving a modified file for Google ads / analytics JS.
Here are some hijacked URLs: http://www.googletagservices.com/tag/js/gpt.js http://www.google-analitycs.com/ga.js http://pagead2.googlesyndication.com/pagead/show_ads.js
The LinkBucks script they serve instead: http://pastebin.com/mYYpYDkR
The script basically hooks mousedown on the whole page, and redirects you to http://dca14d4e.megaline.co/url/ORIGINAL_URL