8 ms·
Google faces UK legal action for bypassing iPhone privacy settings to target ads
- comstock 9y agoArticle just says they used cookies for tracking. Does anyone have a better article, indicating why this work a workaround, and they it affected iPhones in particular?
- strawcomb 9y agoFrom the article: > The complaint is that for several months in 2011 and 2012 Google placed ad-tracking cookies on the devices of Safari users which is set by default to block such cookies. Seems they used cookies for tracking despite Safari supposedly disabling those kind of cookies.
- abdullahi1 9y agoHow were they able to set tracking cookies, if the browser had them disabled?
- lozenge 9y agoWith a technical workaround. The thing is, when does improving browser compatibility count as hacking? Most major websites "hacked" IE with a fake P3P header. This is not that different. https://stackoverflow.com/questions/8048306/what-is-the-most-broad-p3p-header-that-will-work-with-ie https://stackoverflow.com/questions/8048306/what-is-the-most... http://alexanderhiggins.com/google-fined-22-5m-for-hacking-safari-to-track-you/ http://alexanderhiggins.com/google-fined-22-5m-for-hacking-s...
- nl 9y agoI remember commenting long long ago about how the fake P3P header thing will get people in trouble one day. Not sure that one has happened yet though.
- taneq 9y agoBy your definition here a buffer overflow exploit is a "technical workaround". >.>
- soneil 9y agoI see it this way; in the US, if a content publisher chooses to apply DRM, this provides them additional legal protections - whether the DRM is broken or not. Even if stripping DRM is "click Next" simple, it's still illegal. Here, we're applying similar benefit to the consumer. The consumer has expressed they do not wish to be tracked. The application of a loophole does not make it okay. Is it a little over-reaching? Possibly. But it's about time things were over-reaching in the consumer's benefit, rather than the corporations'.
- Too 9y agoThe way I read this is that so called "supercookies" are illegal? That would be great.
- adventured 9y agoIt's going to become increasingly expensive and politically complex to operate an Internet company at Internet scale. That process of country to country division (legally/politically), will continue to accelerate. Although they're getting the first punches to the face because they're easy and obvious targets, companies like Google or Facebook, will trivially withstand it over time. They can afford whatever compliance cost and complexity is involved. It's everyone else that is going to suffer, including all start-ups attempting to offer an Internet-wide service (something that not so long ago could be mostly taken for granted). The effect will be to lock-in the position of the existing giants and protect them from new companies that might challenge their global dominance. If I want to offer an Internet-wide service in the near future, I'll need to comply with dozens of different Internet-related legal/political frameworks to spread into dozens of nations. It'll be realistically impossible to accomplish for smaller entities, so start-ups will be stuck even more than they already are in struggling to reach beyond their local audiences. This will particularly harm start-ups in smaller countries in Latin America, Africa and Europe. Start-ups in the US and China will gain a further advantage (an advantage which they've already utilized to produce most of the Internet giants to this point), because they get to start out with massive home markets with heavily unified rules and then push to the rest of the world from their large base. This process destroys the Internet as it has been known the last two decades and it appears nothing is likely to stop it from getting dramatically worse in the next 10-15 years.
- zaarn 9y agoI doubt it. The GDPR and other european privacy laws are a problem if you operate from overseas. On the other hand, if you start in europe and are thusly aware of the privacy laws it becomes much easier to design as service that complies with them. The Netzdurchsuchungsgesetz in Germany even goes as far as only making big social networks responsible for content and small startups get a free pass.
- hnarayanan 9y agoEven if this is so, could you think of a better alternative for some modicum of consumer protection?
- ConfucianNardin 9y agoIt seems there were/are a couple of workarounds for setting third party cookies in Safari. One was to send a POST request in a hidden iframe using javascript. This was supposedly what Google used to bypass Safari's blocking of third party cookies[1]. Another is (was?) to redirect to the third party domain, and then back again[2]. This would supposedly work since the restriction on third party cookies doesn't apply to already visited domains. 1: https://stackoverflow.com/questions/9930671/safari-3rd-party-cookie-iframe-trick-no-longer-working https://stackoverflow.com/questions/9930671/safari-3rd-party... 2: http://www.mendoweb.be/blog/internet-explorer-safari-third-party-cookie-problem/ http://www.mendoweb.be/blog/internet-explorer-safari-third-p...
- zencash 9y agoI work in adtech. Google have recently rolled out a 'global tag' to replace the 'floodlight' tracking code they usually use, this was last week. [1] https://support.google.com/dcm/partner/answer/7570440?hl=en https://support.google.com/dcm/partner/answer/7570440?hl=en
- dreamcompiler 9y agoThanks for that! Always good to know how to block new trackers.
- a_imho 9y agoGoogle told the BBC: "This is not new - we have defended similar cases before. We don't believe it has any merit and we will contest it." Google agreed to pay a record $22.5m (£16.8m) in a case brought by the US Federal Trade Commission (FTC) on the same issue in 2012. It will be interesting how this one ends, here's hoping for a pro consumer verdict.
- tomalpha 9y agoLikewise. The line immediately after your quote also looks interesting, though clearly not precedent-setting in and of itself: The firm also settled out of court with a small number of British consumers.
- chiefalchemist 9y agoTranslation: We've paid before. Haven't learned our lesson. And consider such fines as the cost of doing business. They should drop "Don't be evil" and change it to "You didnt need that privacy anyway".
- karimdag 9y agoActually, they did drop it.
- freeflight 9y ago"Do the right thing" just gives that much more wiggle room.
- AlphaSite 9y agoYeah, for example, for whom?
- lern_too_spel 9y agoNo, they didn't. https://abc.xyz/investor/other/google-code-of-conduct.html https://abc.xyz/investor/other/google-code-of-conduct.html
- SomeStupidPoint 9y agoSo Google deployed malware against... tens of millions of people?... in order to steal confidential data for profit, by bypassing security mechanisms on those devices as they interacted with Google servers, exceeding authorized access, and using installed code to track the activities of people against their efforts to raise technical barriers? That sounds like an international criminal act on a scale most malware authors would wet themselves over. It's also not surprising that the public is getting fed up with the wanton criminality that seems to be embodied by modern capitalism.
- pmlnr 9y agoI don't know why this is getting downvoted. They did, in fact, acted against someone's setting not to do this, and I completely agree, this is a criminal act, not just a technical glitch.
- JorgeGT 9y agoIMHO storing cookies in a machine explicitly configured to block them seems to fit the "exceeds authorized access" language of the Computer Fraud and Abuse Act.
- briandear 9y ago..as opposed to the lily-white lack of criminality of communism or socialism? Criminality occurs everywhere within every system, the only difference is who is committing it and the degree of which it it reported.
- Cthulhu_ 9y agoYeah uh, it's pretty obvious this guy doesn't really care about the privacy thing, but cares about getting a lot of money from Google. How many people does he even represent that want to be compensated?
- alexasmyths 9y agoIf he's a lawyer he's acting on behest of his clients. It's definitely a problem in consumer culture that big companies can rip people off and break the law without facing consequences - so long as they are only jacking people a little bit at a time. If Google was caught breaking the law, it would be appropriate if one of their officers went to jail over it.
- dmoo 9y ago'so long as they are only jacking people a little bit at a time.' or so long as they are only jacking the little people.
- rahoulb 9y agoHe's the former director of the Consumer's Association - a charity dedicated to protecting consumer rights across the UK and that runs Which? magazine. There's a few things I disagree with about Which? but if there's anyone with impeccable credentials to run this type of lawsuit, it's him.
- chiefalchemist 9y agoOn the surface this new incident says Google doesn't care about privacy. Most agree with this assessment. But taken a step further it seems fair to ask: - Has Google lost its edge? Why has nefarious replaced innovation? - What else are they doing that we don't yet know about? - Is it time for Google to update its biz model so it isn't so dependent on being so driven (to desperation)? - Finally, is it time for the market to reconsider Google's role in defining our collective future? On a personal note, if I can be fairly certain Apple isn't going to "pimp my data" I would give an iphone a serious consideration.
- pdimitar 9y agoThe only non-Apple tech I now use is my PC that I use for work and gaming. I also use DuckDuckGo 99% of the time for web search. NOT giving Google my data is a good starting point IMO.
- lumisota 9y ago"UK" is a bit misleading -- the representative action applies to residents of England and Wales only.
- coldcode 9y agoIn 2011-2012
- danschumann 9y agoThe fact that it was for ads and not for a more legit app, makes me bias against them. Normally, it wouldn't matter at all. There's an app, it doesn't work in safari for some reason, and you figure out a workaround.
- LeeHwang 9y agoGood. It's time for the us government to also start regulating Google at home for this kind of nonsense.
- rubyfan 9y agoIs this why I can’t sign out of Google on my phone? I never sign into Google and never sign into their apps. After I began using a Google Home I began noticing Google maps is automatically signing me in.