4 ms·
> Incognito mode is supposed to not send your regular cookies so sites shouldn't be able to track you unless they use dubious stealthy tricks rather than the ex
by Kalium 3y ago
> Incognito mode is supposed to not send your regular cookies so sites shouldn't be able to track you unless they use dubious stealthy tricks rather than the explicit well-known and documented method (i.e. a cookie). While I know that it's possible, I think it's morally despicable and I expect better from established (and ostensibly honorable) companies like Google.
Yeah, that's what it does. Instead you get a new set of tracking cookies, because to Google and any other random website you look like a new browser they haven't seen before. By design, they have no idea that you're using "incognito mode".
With that in mind, what do you think Google and others should do differently?
- lupusreal 3y agoGoogle should 1) Set the Do Not Track header in incognito mode. 2) Respect it. Bonus 3) Lobby congress to make it illegal to disrespect the DNT header.
- Kalium 3y agoDo Not Track is a suggestion at best. In the best of all possible worlds where Google does exactly as you suggest in forcing it on and respecting it, every other server out there is perfectly capable of ignoring a polite suggestion. Your other idea is interesting. Google should lobby for regulations that would hurt their competitors far more than them. You wouldn't regard this as a big company engaging in regulatory capture?
- lupusreal 3y agoSo you object that clients requesting not to be tracked isn't something servers are required to respect, but also object to the idea of servers facing legal penalties for not respecting it. It sounds like you've already decided that the tracking free-for-all status quo is the best we can do.
- deleted 3y ago[deleted]
- oarsinsync 3y ago> Do Not Track is a suggestion at best No, it’s an explicit instruction. It’s treated as a suggestion, at best. It’s not “It’d be real nice if you didn’t track”, it’s “Do not track.” There’s nothing ambiguous about it. The defence of Google is “well everyone else is doing it”, which isn’t a particularly strong defence, for Google, nor all the other shady businesses engaging in this practice.
- Kalium 3y agoWhat's the practical difference between an unenforceable and unobservable explicit instruction and a polite suggestion? My point is not that Google is good or bad or that all the other kids are doing it. My point is that DNT is at current fundamentally incapable of delivering what we're asking it to do.
- oarsinsync 3y ago> unobservable explicit instruction It’s absolutely observable between the two parties that are engaged in the conversation, as it’s part of the HTTP header: DNT: 1
- Kalium 3y agoThe effects are, if any, are not observable. Let's go with a change of phrase, then. What's the practical difference between suggestion and a clear and explicit instruction that is unenforceable and where the user offering the instruction cannot tell if it is being executed faithfully?
- red_admiral 3y agoOn odd-numbered days, the EU tries to ban encryption. On even-numbered days, they do good things for privacy - like ruling that LinkedIn must respect the DNT header.
- ricardobeat 3y ago> to Google and any other random website you look like a new browser they haven't seen before Unless Google Chrome is still associating your incognito activity to your main account, and who knows which of their products feed off your browsing history…
- redcobra762 3y ago> Google is still associating your incognito activity to your main account Er, no…
- deleted 3y ago[deleted]
- Kalium 3y agoYour browser is doing that to the extent that it carries over information about downloads and bookmarks. That's not the same as Google associating those with the cookies used to track your Google account. I've yet to see anything so much as suggesting that Google is using that kind of Chrome user local data to track people. Did I miss that?
- deleted 3y ago[deleted]
- JeremyNT 3y ago> With that in mind, what do you think Google and others should do differently? I think the parent is suggesting that they reassociate the incognito tracking cookies with the users' other data from their logged in session by using other fingerprinting techniques. I don't know whether Google actually does this. Clearly they are capable of doing so, and anybody who cares about privacy should assume it happens, but it's not obvious to me that this kind of data association would be worth it for advertisers.
- jauntywundrkind 3y agoIn the actual case that got this change in messaging put in, the guy signed in to his Google account from incognito & is mad that Google kept the data from his incognito session. There's nothing in the court case Google is responding to about them using other tracking systems. People seem to want to believe very much there's lots of backchannel tracking & special privilege & self dealing going on at Google. But theres no evidence, there's people vehemently swearing Google does have strong internal information firewalling to prevent this abuse, and it's not what this court case is about. The court case is about users expecting incognito to be a magic cloaking shield where anything you do on the web in incognito magically doesn't stuck around after the fact.
- Doctor_Fegg 3y agoIf I go to maps.google.com in incognito mode, it opens directly on my hometown, presumably from my IP address. Google can use _at least_ the combination of this and my browser UA to track me should they so desire. (There may be other persistent cookie-like things, who knows.) This new prompt is them admitting that they do. I would rather that they chose not to.
- srj 3y agoDisclaimer: Google employee who doesn't work on this. My understanding is that incognito mode is a temporary and blank profile that is cleared when you exit. If it actually prohibited cookies a large number of websites wouldn't work as session information is used in all kinds of contexts (not just advertising). AFAIK there's no special treatment for incognito as the site owner shouldn't be able to tell an incognito user from a new never-seen-before user. Each time you exit and relaunch incognito you will get the same behavior as a new user. There have been tricks over the years for website owners to try and deduce the browser is incognito (e.g. testing available scratch space in the JS file API). In general this is a cat and mouse game where gaps are closed and new fingerprinting methods are developed. In terms of location tracking, websites are still getting your IP address which can be geo mapped. If they want the location from your browser, you should be getting prompted to allow/block.
- jsnell 3y agoAccording to the article the new text is: "Others who use this device won’t see your activity, so you can browse more privately. This won’t change how data is collected by websites you visit and the services they use, including Google." It's pretty clear that the text is not "admitting" what you claim it is, you've just made that all up.