5 ms·
Hmm, would it would be possible to actually detect if Google's got information about a visitor - by creating a web page with google ads and then snooping what t
by eggspurt 13y ago
Hmm, would it would be possible to actually detect if Google's got information about a visitor - by creating a web page with google ads and then snooping what targeted ads are getting shown (which is possible through DOM traversal)? This way, information can leak.
- yetfeo 13y agoIf the ads are shown in an iframe on a different domain you won't be able to traverse them due to cross origin restrictions.
- eggspurt 13y agoMalware that can hijack the users' cookies can do that, as described in https://news.ycombinator.com/item?id=6950758 https://news.ycombinator.com/item?id=6950758 at 15m40s (http://www.youtube.com/watch?v=xv6K2GqyijM#t=15m40 http://www.youtube.com/watch?v=xv6K2GqyijM#t=15m40)
- yetfeo 13y ago"Malware that can hijack the users' cookies" is a little different to "which is possible through DOM traversal" though. I wanted to address the point in case some got the impression just using the DOM via JS would allow it.
- lovemenot 13y agoThe browser itself and its installed plug-ins are not subject to same origin policy. You are thinking of the restrictions on the original site. If this were not the case then the browser woud be unable to download content from any site but the one in the browser's URL. I came here to say that this article is dynamite. I had not followed this story before, but it is at least as important as Snowden / NSA. However, the article loses its force from the middle and the call-out to US liberal politics towards the end is just pathetic. It is as likely that those who need to take action on the data industry are from the right, libertarians, or simply not aligned with parochial US political divisions. Edit: re-reading the thread, the SOP objection is right. A plug-in is required.
- throwaway_yy2Di 13y agoMaybe users could install browser extensions, and coordinate to gather datasets of which ads are displayed to whom. Cross-correlating this with personal information on the users (volunteered to a trustworthy third party, vetted by EFF lawyers), you could make inferences as to what Google probably knows about which user. And may provide a service to warn the user, in a privacy-respecting way, and give advice as to how to avoid further privacy invasions. Ironically enough, it might be illegal to do this, since it would injure Google's corporate privacy ("trade secrets").