7 ms·
And have fun telling Google all about where you get your porn. Chrome's sync is not a reasonable option for anyone who cares about his privacy enough (which sho
by sid0 15y ago
And have fun telling Google all about where you get your porn. Chrome's sync is not a reasonable option for anyone who cares about his privacy enough (which should be everybody on Hacker News).
you need to use an (unretrievable) sync key to add a browser
No you don't. You need a 12-character weak secret that shows up on one of the computers.
- Pewpewarrows 15y agoYou seem to be horribly mis-informed about Chrome's sync features. The data being synced is completely encrypted end-to-end, and you can provide a personal passphrase aside from your Google credentials as an added level of security if you'd like.
- sid0 15y agoThe data being synced is completely encrypted end-to-end, and you can provide a personal passphrase aside from your Google credentials as an added level of security if you'd like. I'm having trouble parsing this comment -- part of any "end-to-end" encryption would be an additional passphrase not known or accessible to Google in any form. Obviously Google knows about your Google credentials, so merely the credentials are not sufficient to get "end-to-end" encryption. Also last I checked the personal passphrase only encrypted passwords. I haven't used Chrome in a long while, so has that been extended to all your data yet?
- Pewpewarrows 15y agoIf you think Google has access to your raw, plaintext credentials logged somewhere on their servers, I have a Nigerian banker to forward your way who'd love to give you a million dollars if you help him up-front with a little cash.
- scrod 15y agoNope, you're wrong. Google will always be in a situation where they can read your password. Otherwise authentication to the rest of their services would be impossible.
- Pewpewarrows 15y agoAgain, it's sad if you think they're actually logging everyone's plaintext credentials. Which is besides the point, because in the latest versions the additional non-Google account passphrase extends to all the encrypted data it syncs.
- nknight 15y agoI seriously doubt Google is dumb enough to store user passwords in plaintext. There is absolutely no reason to. Passwords get stored as non-reversible hashes.
- scrod 15y ago>I seriously doubt Google is dumb enough to store user passwords in plaintext... And who said they'd need to store anything? The only need access to them once in order to defeat any kind of local encryption scheme based on your Google account password.
- sid0 15y agoIf you think Google has access to your raw, plaintext credentials logged somewhere on their servers I don't think that. Read my comment again, paying special attention to the phrase "in any form".
- Pewpewarrows 15y agoExactly. For it to be any less secure, they'd have to be logging your plaintext credentials. And if you're that paranoid, there's the additional passphrase.
- deleted 15y ago[deleted]
- SeoxyS 15y agoPeople don't care about privacy. I'll gladly tell Google about youporn.com in exchange for its great user experience. Also, people who know or care about sync keys also know how to use private browsing.
- sid0 15y agoPeople don't care about privacy. I find this kind of thought process philosophically unsound. People might not care about privacy enough today -- that doesn't mean that software developers should follow them off the cliff. At some level, programmers have a moral imperative to guide users into doing things that are better for them. That includes ensuring privacy, even at the cost of a slightly more involved UX. Also, people who know or care about sync keys also know how to use private browsing. I don't use private browsing because I'm the only one who uses my devices, so I don't care about the contents of my history. I do care about Google knowing about it though, which is why I use Firefox.
- cema 15y agoFirefox has the "private browsing" mode.