34 ms·
This is Google not only intercepting people's smartphone traffic, but a lot more: - Google will send you a router to intercept your entire household's internet
by sidewaysloading 8y ago
This is Google not only intercepting people's smartphone traffic, but a lot more:
- Google will send you a router to intercept your entire household's internet traffic on all devices with a browser (https://support.google.com/audiencemeasurement/answer/7574391?hl=en&ref_topic=7573819 https://support.google.com/audiencemeasurement/answer/757439...)
- Google will send you a device that listens 24/7 to audio in the room to figure out what you are watching on TV and listening to (https://support.google.com/audiencemeasurement/answer/7574764?hl=en&ref_topic=7562482 https://support.google.com/audiencemeasurement/answer/757476...)
- Google's project includes tracking of desktop and laptop internet activity via a browser extension that can basically read literally anything you do online (https://support.google.com/audiencemeasurement/answer/7574481?hl=en&ref_topic=7573811 https://support.google.com/audiencemeasurement/answer/757448...)
This isn't just trying to figure out what new up-and-coming apps are going to be the next big thing, this is Google building out very far-reaching profiles of your entire household, in return for some gift cards. This is signing away your family's entire digital life (and a significant part of anyone they interact with in a browser).
- deleted 8y ago[deleted]
- mont 8y ago> Google's project includes tracking of desktop and laptop internet activity via a browser extension that can basically read literally anything you do online What browser extension is this?
- ppeetteerr 8y agoI "love" how the reward are gift cards, not actual money. How much more insulting can they be: your privacy is not even worth liquid currency. Some people probably need the gift cards, but it's as upsetting as people selling blood for gift cards.
- aaaaaaaaaaab 8y agoGiftcards can be tracked. Money can’t :)
- saagarjha 8y agoPresumably, this allows for sending money to children who are unlikely to have a bank account.
- roywiggins 8y agoPrepaid debit cards are totally a thing though.
- Domenic_S 8y agoDon't know why you're downvoted - sending prepaid debit cards has taken the place of cutting a check in a lot of instances. When I cancelled DirecTV years ago, they sent my refund as one.
- HillaryBriss 8y agoi wonder why they didn't insist on paying people via Google Wallet
- tzs 8y agoAre they physical gift cards, or e-gift card codes. If the later, one obvious advantage over other payment methods is that they can be delivered by email or by a web page. I think most people would prefer that to receiving a check in the mail, or cash in the mail, or supplying banking details for a direct deposit. They seem to have cards available for multiple merchants. If they have a decent selection there should be something available from a merchant a given subject actually buys things from. If so, a gift card is pretty much as good as cash.
- magicalist 8y ago> Google will send you a router to intercept your entire household's internet traffic on all devices with a browser () Yes, shocking that requesting a router that will report "the sites you visit, device IP address, cookies, and diagnostic data" for market research will take a look at my household's internet traffic... It's just Nielsen but from Google (Nielsen these days literally works by putting a microphone in your house and collecting all your internet activity). The novelty of this story doesn't have anything to do with these things, just the iOS app.
- stefan_ 8y ago> Cookies Yessir, how could there be a problem here? And all those third-parties consented to their communication intercepted and stored by, well, another third-party? No, this is some CFAA federal crime trojan stuff.
- whiskeykilo 8y agoAnyone on HN understands the implications of this. But does your average user? I doubt it. They just know they can install a little box and get paid. Digital privacy means nothing to far too many people
- bearmcbearsly 8y agoI'd argue that the average person probably understands the actual implications better than the typical HN user.
- mynameisvlad 8y agoWhat? How can you make that argument? The average person has absolutely no clue of the various ways websites are tracking them already, let alone the potential amount of data Google would be getting by aggregating all this through their router.
- basil-rash 8y agoI don't think so. For instance, people I spoke with on reddit who installed the FB app thought that due to SSL, all their communications would be encrypted, and FB would only see who they were talking to, not what. Of course, the entire point of the root cert is to break SSL.
- da_chicken 8y agoAnd people wonder why I didn't want Nest. I was already skeptical before it was bought out and I learned that without an Internet connection it wouldn't work.
- 52-6F-62 8y agoMy girlfriend has a Nest at her work which saved her last week when the power cycled and the heating system turned off. She was able to restart it from home. I wouldn't be so thrilled to have a thermostat that requires internet to function at home. Or is that only for those networked features?
- buckminster 8y agoA dumb heater with a dumb mechanical timer connected to a dumb thermostat would have restarted too.
- 52-6F-62 8y agoIt wouldn't have been sufficient to save the buildings pipes in -30°C in a restaurant full of embedded draft lines, however. Nest did give her control over the entire building's system. IIRC it was actually an employee that shut the system off after a power cycle/outage thinking they were protecting the equipment, but failed to restart it. If she hadn't had the insight the system would have been off all night. I think it has its perks.
- mherdeg 8y agoIs it a little baffling to anyone else that Facebook's entire plan if Apple killed their research-app Onavo iOS workaround was "loudly point out that Google does it too"? Surely there must have been more to their contingency plan? They have great engineers and I'm surprised there wasn't more than a PR response up their sleeve. Just for example, in retrospect, why did they use the mainline Facebook iOS enterprise certificate to sign this app rather than a cert from one of their subsidiaries or acquisitions -- wouldn't that have de-risked a bit?
- politician 8y agoI'm pretty happy the way that Facebook is signaling the security of iOS by complaining that they have no other way to break into phones except by social engineering people to install root certificates. This episode is a win-win.
- alanlamm 8y agoSorry to disappoint, but I think this is just one of many ways. example - as an iOS dev u want to advertise on fb. for that to be effective u want to track conversions. easiest way to do that, esp. for a small dev - add the facebook sdk to the app. and you're done - facebook can potentially hoover a lot of data from an app that has no obvious relation to it.
- reaperducer 8y agoIs it a little baffling to anyone else that Facebook's entire plan if Apple killed their research-app Onavo iOS workaround was "loudly point out that Google does it too"? Not to me. That’s pretty much how I expect Facebook to operate these days. Sadly, it’s not just Facebook. Pretty much every time any article posted on HN points out how Company X is misbehaving the thread is flooded with “But... but... Company Y does it, too!” It’s like the SV bubble falls back on the logic of a five-year-old whenever they get caught with their hands in the cookie jar.
- pertymcpert 8y agoYes, Same thing with any criticism of China.
- kakarot 8y ago> TV Meters also come with a camera, but that camera isn’t used, and doesn’t collect data. I, too, like to add unnecessary sensors to devices which considerably increase their value, despite never using them.
- colinnordin 8y ago> The TV Meter needs to hear the TV clearly so it can work, and people watching TV will need to see the screen while they’re watching TV. And for some reason it's important that you can see the device even though the camera is turned off?
- sanbor 8y agoIt could also be that right now the camera is not used but in a future it will. It would just require updating the terms and conditions. No need to send new hardware.
- kakarot 8y agoChances are such an update will not be cognitively registered for many of these consumers, who originally read that the camera would not function when signing up for the product. It's shady as shit no matter how you slice it.
- srkmno 8y agoSo what? it's opt-in, is consent not enough anymore? does a privacy maximalist mentality needs to be imposed on everyone?
- Jare 8y agoScams are opt-in.
- dictum 8y ago> does a privacy maximalist mentality needs to be imposed on everyone? I see you follow Google closely; close enough to know that privacy concerns have hardly impeded its growth and dominance. Same with all other major tech companies. Does a privacy minimalist mentality need to be imposed on everyone? (I'm asking rhetorically. In either form, it's not a substantial argument: it's a strawman. Privacy isn't a measurable quantity, and each person or community cares about protecting or revealing different things.) Edit: Q.E.D. https://news.ycombinator.com/item?id=19039593 https://news.ycombinator.com/item?id=19039593
- srkmno 8y agoWhat does any of that mean? my point is against imposing one's POV on others and that people are free to consent to stuff you might not like.
- orblivion 8y ago
- curiousgal 8y agoI'll go ahead and play the Devil's advocate because every constructive conversation needs one. People who signup for this already know what they are doing and the program has a privacy section[0] saying that the data is only shared with Google which is pretty much akin to having any Smart Speaker. Not only that but it also says that the data wouldn't be used to "advertise to you or sell you anything" which is not the case with Smart Speakers. In essence, from a privacy point of view, when compared to having a Smart Speaker, this is better I'd say. 0.https://support.google.com/audiencemeasurement/answer/9028740?hl=en&ref_topic=7563962 https://support.google.com/audiencemeasurement/answer/902874...
- floatingatoll 8y agoUser opt-in does not excuse violating Apple’s terms of use. Google _likely_ did not get Apple’s opt-in for this approach. If they did not, they will _likely_ see their enterprise certificate terminated for precisely the same reason.
- on_and_off 8y agoStill playing devil's advocate : I am more perplexed by the necessity to have Apple's approval than anything else here. Sure this particular app is debatable.. but I have also worked in the music streaming industry. While being super respectful of the users, we still have sometimes had to wait for months for Apple's approval. Having a single agent being able to gatekeep what you can install on your phone at their own discretion is an issue since there will always be the temptation to prevent any competitor from getting in your space.
- reaperducer 8y agoI am more perplexed by the necessity to have Apple's approval than anything else here. As I understand it, it’s because the apps were being distributed using a method that is supposed to be used only inside the company. Like for beta testing software, or for in-house applications used by employees only. Anything going to the general public is supposed to go through the App Store under Apple’s terms and conditions.
- shittyadmin 8y agoSounds quite similar to the way TV ratings are done - is this really such an issue? It's very much an opt in service designed to measure audiences. Unlike hidden terms in privacy policies it's made quite clear what's going on here.
- zaksoup 8y agoYour cable box isn’t decrypting your entire household’s tls traffic when it reports episode watch statistics.
- gaius 8y agoThis means that Google has the login details for your bank. You are almost definitely in violation of the bank’s ToS by divulging them
- shittyadmin 8y agoIt's most likely targeted only at relevant sites.
- x0x0 8y agoCan you actually do that from a router? Wouldn't you have to put that tls cert on every laptop and phone?
- notatoad 8y agoNot only can you not do it from a router, Google's chrome browser is one of the leading reason's why you can't. however, with the browser extension installed you don't need to - they just read the content after your browser decrypts it.
- prepend 8y agoRouter could mitm and chrome could allow it since they have google CAs in their chain. Don’t know if they are doing this, but it’s certaibly possible to do this at router (or router dumps traffic to google to decrypt). It’s much easier for google to do this since they make chrome. Another company would have to adjust the cert trust on each machine.
- amq 8y agoI wonder why a router is really useful to them. With most sites using https, not much beyond DNS requests and plain IPs can be captured, without forcing users to install a CA.
- freedomben 8y ago> With most sites using https, not much beyond DNS requests and plain IPs can be captured Agreed, but don't minimize the value of logging all DNS requests. You can get an unbelievable amount of deeply personal information from having a list of every DNS lookup. As an experiment, fire up a pi-hole and look at the logs of your own requests. There will likely be a lot of info in there you wouldn't want public.
- numair 8y agoOkay, so this is a throwaway account whose only posts are in defense of Facebook. Readers on HN, you’re supposed to be far more skeptical and employ your Young Reaganite “Trust But Verify” glasses before upvoting blindly like this. Even if the facts are correct, the talking points are clearly presented as (in the favorite words of so many on here) “submarine PR.”
- chillacy 8y ago> Please don't impute astroturfing or shillage. That degrades discussion and is usually mistaken. If you're worried about it, email us and we'll look at the data. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- propogandist 8y agobetter still, the router hardware google sells as a product (onHub) requires a Google account to work [0- So consumers are paying to buy a router that will allow google to mine and link all browsing behavior to their google account. Also, if you own a google home, it won't work without all sorts of permissions being enabled at the account level, including web activity and app history [1] Both of these fantastic privacy violating products are available for Purchase at an electronics retailer near you. [0]https://on.google.com/hub/support/ https://on.google.com/hub/support/ [1]https://twitter.com/benthompson/status/864293485439893505 https://twitter.com/benthompson/status/864293485439893505