15 ms·
Stanford researcher: Google Circumvents iOS Privacy protection in AdSense ads
- drp4929 15y agoGoogle, what's wrong with you? Do what Path did.
- Bud 15y agoToo late to do that. Apple is patching it in the next iOS update.
- myko 15y agoYou mean they're updating Safari with a patch created by Google engineers months ago to fix the issue: http://trac.webkit.org/changeset/92142 http://trac.webkit.org/changeset/92142
- Tyrannosaurs 15y agoThat's a pretty poor justification. If Google were serious about protecting users from this loophole thy wouldn't exploit it.
- YooLi 15y agoWhether the bug is fixed by the Chromium team or not, Google should not have been exploiting it to track users.
- magicalist 15y ago"This tracking, discovered by Stanford researcher Jonathan Mayer, was a technical side-effect — probably an unintended side-effect — of a system that Google built to pass social personalization information (like, “your friend Suzy +1'ed this ad about candy”) from the google.com domain to the doubleclick.net domain." edit: to be clear, whether or not is was an intended side effect, it is a side effect of a (potentially) legitimate use case (setting the value of +1-ing an ad aside).
- Tyrannosaurs 15y agoThe whole is "Don't be Evil" history thing is asked too often, frequently around things which probably aren't even borderline but this feels a valid case of calling them on it. Deliberately exploiting a loophole to circumvent privacy controls is scummy behaviour, the sort of thing you expect from the industry's bottom feeders, not from one of the biggest companies in the game and certainly on that professes some sort of conscience. You can argue its not really evil but it's hard to say its not another step towards that, and this time it seems hard to suggest that it's contractors or some peripheral part of the company.
- Symmetry 15y agoI don't see any reason to think that upper management is any less committed to "Don't Be Evil" than they've ever been, and as long as Larry and Sergey are in charge it'll probably remain that way. But the larger a company gets the harder it is to impose that sort of thing on everybody, and the more stupid and random stuff a company will do, and some of that will end up being intentionally or effectively evil. Growing by acquisition rather than organically is probably making it worse than it has to be, too.
- Tyrannosaurs 15y agoCompany culture and values always come from the top. If you have an arsehole CEO he or she tend to recruit those with similar characteristics and create a culture where that behaviour thrives. That's repeated at he next level, the level below that and so on. It may be as little as a shifting set if priorities so don't be evil is less important and other things a little more and with that the cracks appear. I'm not suggesting that they're now spending their days plotting how to enslave us all but I similarly can't believe that there hasn't been some shift, conscious or unconscious.
- SoftwareMaven 15y agoGiven that much of Google's growth was shepherded by Eric Schmidt, who seems to think privacy is orthogonal to evilness, I think you've hit the nail on the head.
- cpeterso 15y agoIf Google uses security holes in Apple's browser to "enhance" user tracking, what might Google do if they had their own browser?
- emehrkay 15y agoYeah, I dont understand the Chrome love from the typical "hacker." I personally use Webkit Nightly.
- jrockway 15y agoI use Chromium. That way, I can read the code and still get a really good browser. My analysis is: they only send information back to Google when you explicitly request it. (But what if Debian ships me a version of gcc that embeds secret tracking code into any version of Chromium I compile? Oh the fear, uncertainty, and doubt!)
- 160162172 15y agoUnfortunately Chromium connects to Google just as frequently as Chrome does, vide - http://www.freesmug.org/forum/t-433541/chromium-chrome-and-mysterious-server-connections http://www.freesmug.org/forum/t-433541/chromium-chrome-and-m...
- jrockway 15y agoSure, but you can easily delete the code that does that. The point of Chromium is not that it doesn't talk to Google. The point is that you can read the source code to determine exactly when it does, and you can edit the source code to ensure that it doesn't do anything you don't want it to. Yes, that's hard, but that's the price of freedom. I appreciate that Google at least lets me choose how I want to use their code, where Apple and Microsoft make the decisions for me and never let me double-check them. (As it stands, I trust Google with my personal information and I think the places where Chrome/Chromium communicate with Google are appropriate and make my browsing experience better. But it's 100% fine if you don't feel the same way.)
- shareme 15y agoa question why is no one concerned about the Safari hole in context of Apple? Seems tome that you have more to worry about in Apple than Google as there many others using the same exact hole.
- emehrkay 15y agoThis makes me think that Google had ulterior motives when bundling flash with Chrome. Having the latest, most-secure version of flash is a win for Google, its users, and the web in general, but having flash installed allows for usage of flash cookies which can read your info across browser sessions -- info that they'd probably want. To Chrome's credit, I believe it is the only browser that allows users to delete flash cookies. * removes tin foil hat
- joejohnson 15y agoKnowing that a large percent of the user base won't use it/know about it, maybe they include the ability to delete flash cookies so that later they can say, "you can opt out at any time!"
- eyeareque 15y agoYou can delete flash cookies with other browsers too, but you need to visit a adobe site in order to do so: http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html http://www.macromedia.com/support/documentation/en/flashplay...
- othermaciej 15y agoYou can delete Flash cookies and in fact all data that a site could use to track you in Safari, including plugin-related data, cache, etc. Just go to the Privacy pref pane and click on Details under Cookies and other Web Site Data. For example, for kongregate.com, I see that I have Cache, Cookies, Plug-ins and Local Storage holding potential tracking data, and I can delete it all with one click.
- Nick_C 15y agoI've said this before, but for others who missed it, here's one of my crontab entries: # Remove Flash cookies and everything to do with Flash, # including left-over Flash files in /tmp 15 13 * * Wed /usr/bin/rm -rf /home/nick/.macromedia/Flash_Player/* 16 13 * * Wed /usr/bin/rm -rf /tmp/Flash*
- emehrkay 15y ago
- drunkenmasta 15y agoI'd like to thank Jonathan Mayer and others like him that go through code and find these secrets and then release them for the public good. You make a great difference.