4 ms·
Combined with Privacy Sandbox [0], this means the browser can track you directly without cookies, but websites can't track you via IP address. So it has the ef
by diroussel 3y ago
Combined with Privacy Sandbox [0], this means the browser can track you directly without cookies, but websites can't track you via IP address. So it has the effect of centralising the tracking to google only.
I haven't used Chrome since this rolled out, since I didn't see a way to object to the new tracking. This is what the linked article [0] says:
> It’s unclear if toggling these features off will stop Chrome from collecting these data altogether, or if it just won’t share the data with advertisers.
[0] https://theconversation.com/google-chrome-just-rolled-out-a-new-way-to-track-you-and-serve-ads-heres-what-you-need-to-know-213150 https://theconversation.com/google-chrome-just-rolled-out-a-...
[1] https://developer.chrome.com/en/blog/shipping-privacy-sandbox/#whats-shipping https://developer.chrome.com/en/blog/shipping-privacy-sandbo...
- jwells89 3y agoDepending on the user’s aims, that could still be a net win… limiting tracking to a single party versus N parties. Obviously not ideal as no tracking at all though.
- mindslight 3y agoNormalizing VPN/proxy use is a fantastic development for the entire market. Sure, I can see a future where websites only allow traffic from naive connections, Apple proxy, or Google proxy. But I can just as likely see a future where many more "normie"-appearing providers spring up and website managers move on to some other feel-good check box besides IP discrimination.
- pixl97 3y agoThe particular issue here is where many people have the same complaint about Cloudflare. You're concentrating that single party to a single provider for a massive number of people. Hence now governments have a one stop shop for all the information they need.
- kevingadd 3y agoThat's assuming you can trust the single party not to pick winners to share data with and losers to keep out. With Apple we know they have a bunch of revenue streams based on selling actual products to users, so there's much less of a hazard there. With Google... who knows what they'll do to juice their next earnings report?
- halJordan 3y agoIt's not meaningfully different. Nobody actually wants the data. They want to do stuff with the data and take actions based on get data. Google will collect all the info and then process it any way the 1st party asks. And the 1st party will still take the same action whether google or themselves processed it because they still get that actionable insight. That actionable insight being actioned is what's detrimental to you.
- cscurmudgeon 3y agoDepending on the user’s aims, Standard Oil's monopoly could still be a net win. - Some HN commenter in 1890s (probably)
- wkat4242 3y agoIt makes that one party much more powerful and difficult to deal with in the future. Google is already at the point of too big to fail.
- lelanthran 3y ago> Depending on the user’s aims, that could still be a net win… limiting tracking to a single party versus N parties. It's actually worse in every way regardless of the user's aims. Having individual sites track you across their affiliates is much better than having a single party track you across everything for commercialisation purposes. TBH, the tech community asked for this. The support for google chrome over firefox is driven primarily by technical folk. The majority of people really don't give a damn what browser they use.
- somat 3y agoCertificate transparency has the same problem. It has the side effect of sending every domain you visit to the certificate log server. An advertisers wet dream. If you are using chrome this is google. Now if you are using chrome I always assumed it was sending everything you viewed to google anyway. So I guess this is... OK, or at least, not worse than the status quo. https://en.wikipedia.org/wiki/Certificate_Transparency https://en.wikipedia.org/wiki/Certificate_Transparency
- aaomidi 3y agoWhat? > It has the side effect of sending every domain you visit to the certificate log server. No? It means that if a certificate is to be trusted, it needs to enter a public append only log server. It does not "send every domain you visit to CT." The certificate simply has to be in CT before chrome trusts it. CT logs are public, you can (and many do) make archives of it. The idea is simple, if a website is to be _publicly trusted_, it needs to also be publicly logged. You have heavily misunderstood what CT does, and the paradigm of control around it.
- salawat 3y agoUh huh. And if I log what addresses reach out to me to check for the presence of a particular certificate in the logs? You're not thinking about it hard enough. Your CT's would effectively have to be implemented in a way where everyone had a locally cached copy of the log to check against. That at least shuts down an browsing activity leak vector. If you centralize it, the abuse is a matter of when, not if.
- aaomidi 3y ago> Uh huh. And if I log what addresses reach out to me to check for the presence of a particular certificate in the logs? Again, misunderstanding of how it works. Logs are checked using the SCT in the certificate. It's a signed "promise" from the CT that the pre-certificate will eventually be appended to the logs in a few hours since submission. The various root programs monitor to ensure that the promise does in fact happen. Your browser process does *not* reach out to the CT log on its own.
- abraham 3y ago> The Google-run proxy can observe the user's IP address but not the websites being visited and the third-party proxy can see the web servers being visited but not the IP address of the visitor. Google will likely already have the user's IP from sync, safe browsing, etc, if Google's proxy doesn't know what sites are visited it doesn't sound like this increases Google's access to any user data.
- diroussel 3y agoIndeed that was my point it doesn’t hurt Google just their competitors. Thus concentrating power and increasing their monopoly grip on the web.
- deleted 3y ago[deleted]
- jgalt212 3y ago> Combined with Privacy Sandbox [0], this means the browser can track you directly without cookies, but websites can't track you via IP address. So it has the effect of centralising the tracking to google only Definitely not the actions of an org trying to exert monopoly power.
- Thorrez 3y ago>So it has the effect of centralising the tracking to google only. I thought privacy sandbox could be used by any website, just the same as Google can use it. Am I wrong? Disclosure: I work at Google, but as can be seen from my comment, I don't have much knowledge of privacy sandbox.