7 ms·
yikes, not a fan of that argument as a matter of principle.
by TearsInTheRain 6y ago
yikes, not a fan of that argument as a matter of principle.
- ocdtrekkie 6y agoWhen it comes to privacy, you can safely assume whatever side Google is on is the wrong one, and the one everyone else is on is probably costly to Google's web domination plans.
- 3np 6y agoDepends. When they were struggling with the CCP, eventually getting all their services blocked in Mainland China, I don't think so. There are more examples of situations were Google really does take the other side of the table. It's not helpful to reducing it to these extremes.
- deleted 6y ago[deleted]
- orestarod 6y agoIf they really wanted to fight for freedoms instead of searching a viable way to have profits in China, they wouldn't secretly start Dragonfly, which was only halted after its employees demanded it. So, they really really did want to operate in China, no matter the human rights situation there, they just did not think it through to concede enough things back then. They were ready later, hence Dragonfly happened.
- 3np 6y agoSure, but that does not mean that their side is always the wrong one on every issue. They can do evil and good at the same time.
- ocdtrekkie 6y agoNot really. They're always evil, it's just occasional their evil coincides with interfering with another evil. Google's issue with China has never really been human rights. Google's issue with China is that it insists on access to data and algorithms, and while Google does not care about your privacy, Google cares a great deal about it's own privacy.
- ogre_codes 6y agoI think current Google would have made a significantly different decision than past Google. It's been a while since I've seen them make an altruistic choice that has cost them significantly the way losing China did.
- bawolff 6y agoSo you're opposed to TLS strengthening measures like certificate transparency? Because i think its pretty good for privacy. Blind google hate is just as bad as blind google fanboyism. Google does plenty for internet privacy, especially in the parts that don't affect its underlying business model, which is a big part of the privacy space.
- vaduz 6y ago> So you're opposed to TLS strengthening measures like certificate transparency? Because i think its pretty good for privacy. Considering that the cost of getting CT was the removal of RFC 7469 HTTP-based PKP "dynamic pins" (aka HPKP), I am not sure if there was a net benefit to privacy - without hate or love for Google. I can't fail to notice that intent to removal was to also remove "static pins" (i.e. pins harcoded into the browser) after CT requirement for all certificates was implemented [0], Chrome started checking CT for new certificates [1] and CA Forum has limited the maximum validity of certificates issued to 39 months (2016) -> 825 days (2018) -> 398 days (2020) [2] (which means pretty much all certs from 2017 would have been reissued by now!), yet static pins for certain "favoured" organisations remain in the Chromium code [3]. That list of favoured orgs? Google, Tor project, Twitter, Dropbox, Facebook, Spideroak, Yahoo and Swehack. CT is great for transparency and tracking rogue certs - but privacy could have used a stronger model than current blind trust in the CAs (and only acting afterwards if the trust proves misplaced). [0] https://groups.google.com/a/chromium.org/g/blink-dev/c/he9tr7p3rZ8/m/eNMwKPmUBAAJ https://groups.google.com/a/chromium.org/g/blink-dev/c/he9tr... [1] https://chromium.googlesource.com/chromium/src/+/master/net/docs/certificate-transparency.md#Chrome-Policies https://chromium.googlesource.com/chromium/src/+/master/net/... [2] https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-1.7.3.pdf https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-... [3] https://raw.githubusercontent.com/chromium/chromium/master/net/http/transport_security_state_static.json https://raw.githubusercontent.com/chromium/chromium/master/n...
- bawolff 6y agoA standard used by nobody does nothing for privacy. I also dont really see the connection - we could have both if that was desired, they solve similar problems but they don't conflict with each other. HKPK wasn't removed to make way for CT, it was removed because it did not work in practise.
- deleted 6y ago[deleted]