6 ms·
Same with Google Analytics. GA is the standard analytics for a huge % of websites - so even if a website doesn't use GA for tracking traffic, Google still has
by arb99 12y ago
Same with Google Analytics.
GA is the standard analytics for a huge % of websites - so even if a website doesn't use GA for tracking traffic, Google still has the referral data. And things like Google Adsense (i'm pretty sure that sends back the referral data too, for tracking click fraud).
There is no way really to avoid Google knowing a lot about you/your website anymore.
- regecks 12y agoIt's still possible to avoid leaking information to GA, by rewriting outgoing links to go through a redirector. Many sites do this (including Google Encrypted Search, but its not perfect). The email problem sucks though. We need end-to-end encryption, on all mail, today.
- pestaa 12y agoYou are right about the outgoing links on your site to avoid leakage (this is what well implemented search engines like DuckDuckGo does as well), but I think GP talked about the incoming links of your site. Your pages will appear as exit pages in Google Analytics which you cannot do a thing about.
- Sami_Lehtinen 12y agoUsing encryption still doesn't prevent massive leak of metadata, and wasn't it news just a few days ago that they do kill people based on metadata. Btw. I've been also running my own mail servers for ages and have been fed up with Gmail users.
- yuvadam 12y agoGoogle Analytics (and other tracking cookies/scripts) are actually very easy to evade, by using browser extensions such as Ghostery, Ad-block Plus and NoScript.
- Smerity 12y agoYou hit the nail on the head. Google Analytics is on a substantial proportion of the Internet. 65% of the top 10k sites, 63.9% of the top 100k, and 50.5% of the top million[1]. My own results from a research project I did using the Common Crawl[2] corpus estimates approximately 39.7% of the 535 million pages processed so far have GA on them. The real key to tracking is the referrer data. For the vast majority of clicks, you land on a site that has Google Analytics or you've just left one that did. As Google Analytics tracks your referrer, that means they still have your full browsing history if you jump from GA => !GA => GA => !GA => ... According to my research[3], Google gets activity information on 51.43% of the 42 billion links analyzed in the 535 million page corpus as either the start or end of the link uses Google Analytics. This activity means they can accurately track browsing history on most sites, even those that don't use GA, simply as timing information, referrers, and knowledge of the web graph end up leaking user activity. Used in an anonymized fashion, this is beneficial as it helps Google understand real world web traffic and hence rank search results accordingly (far better than simulated activity based upon PageRank or similar). In the theoretical situation you drop anonymization is where this gets troublesome. If you're interested, there are more details at "Measuring the impact of Google Analytics"[3], though much of the discussion is on Hadoop + Common Crawl. For a privacy focused write-up (primarily worried about the NSA using Google Analytics), refer to "Google, make Google Analytics HTTPS by default"[4]. P.S. Everyone who notes "Google Analytics is easy to evade" are correct but missing the broader point -- the majority of web users will never do that. [1]: http://trends.builtwith.com/analytics/Google-Analytics http://trends.builtwith.com/analytics/Google-Analytics [2]: http://commoncrawl.org/ http://commoncrawl.org/ [3]: http://smerity.com/cs205_ga/ http://smerity.com/cs205_ga/ [4]: http://smerity.com/articles/2013/google_analytics_and_nsa.html http://smerity.com/articles/2013/google_analytics_and_nsa.ht...
- MattHeard 12y agoCould a user "fake" additional site visits in between each real visit in order to obfuscate the actual visits to GA sites?
- Smerity 12y agoAs Google Analytics is "self reporting" (i.e. your browser tells the GA servers what it's doing) you can avoid reporting or erroneously report whatever you'd like. It'd likely be easier for you just to block Google Analytics though if that is of concern to you. In the unlikely event that fake activity became a problem, Google's well equipped to deal with it. They have a great deal of tech and brains in place to detect fake ad click activity, which is vaguely related.
- andreasvc 12y agoThat doesn't really help if $incriminating_website is among the real visits. I think obfuscation is a waste of time given the machine learning techniques at their disposal.
- atmosx 12y agoExcellent comments and links!
- tombrossman 12y agoIn the theoretical situation you drop anonymization is where this gets troublesome. Here's something even more troubling. Take an 'anonymous' crime reporting site[1] and put Google Analytics on it. Put it on every single page, even on the page with the forms to submit anonymously. Not bad enough? How about a similar site, only this one aimed at reporting corruption[2] and try the same thing. What could possibly go wrong? Both sites are well aware of the issue and have written me back when I pointed this out. This level of trust in an American ad company is curious. All I can do now is hope that whistle-blowers wanting to report corruption are savvy enough to avoid the web forms. Imagine you are a government worker somewhere and you see evidence of corruption and report it. From the same machine you signed in to GMail with. Now consider that your local government can order Google to secretly hand over tracking data and forbid them from notifying the crime reporting site(s). [1]: https://crimestoppers-uk.org/give-information/give-information-online/ https://crimestoppers-uk.org/give-information/give-informati... [2]: https://forms.theiline.co.uk/integrityline https://forms.theiline.co.uk/integrityline
- zerobyzero 12y agoWe should raise concerns about Facebook like buttons too. Its impossible to see a site without like button and it sends all our browsing info back to facebook.
- digitalengineer 12y agoI was under the impression FB also tracks all your other browsing even if you log out. So I use a different browser just for FB.
- us0r 12y agoWhile we are on the topic of FB - they don't delete data/pictures even when you delete them.
- zerobyzero 12y agoEven I keep hearing the same. I also noticed they they set 5 different cookies if you visit any facebook.com page, even if you are not logged in. The amount of tracking google, facebook does is insane. And I hate the fact that none of my non-techy friends even understand it.
- infinite8s 12y agoThis is why I only log into facebook through Chrome's "Incognito window" functionality. Of course, if they are tracking IP addresses then i'm screwed.
- eps 12y agoNot just GA. Next time you link to a .css with those wonderful free Google Fonts, ask yourself - what's in it for Google? Then take a look at all those ajax.googleapis.com links pulling down jQuery libraries and wonder the same.
- mike_hearn 12y agoI wouldn't read too much into that. Google Engineering has huge budgets and all kinds of random projects get paid for with no better justification than "this is good for the web, therefore it's good for us". I worked there for years. Seeing really deep, well thought out business plans there was a rarity especially for small projects like hosting web fonts or running DNS resolvers. Heck, even for very large projects sometimes the accounting was unbelievably carefree.
- eps 12y ago> I wouldn't read too much into that. Pfft.. What was I thinking? It's the original Dont-Be-Evil company, right? Of course they are giving away tons of freebies just because they are awesome. They just run a money printing press for an extra minute and those huge budgets will materialize out of thin air. Yay.
- mike_hearn 12y agoYes, that's pretty much how it is. Don't believe it if you like, but you won't convince me: I was there in some of these meetings, I read the design docs, I watched these sorts of projects get approved. They just give this stuff away because they're swimming in money and it's a place run by geeks.
- blueskin_ 12y agoBlock the .js file. Problem solved. Or, just, you know, disable javascript entirely.
- user24 12y ago> Problem solved. Except it's not because the problem's still there for everyone else. Do you really that being shielded yourself but allowing your non-techy friends and family to be tracked is a 'solved' problem?
- dan_bk 12y ago> Same with Google Analytics. I always use Piwik [0] - it's excellent, open-source and most of all: it respects your users' privacy by not letting any third party like Google track them. My advice: Use it too and let your users know that you do so because you respect them. [0] http://piwik.org http://piwik.org