4 ms·
Iridium's website makes a selling point of the fact that Chrome contacts Google servers, but fails to mention that it may phone home to servers of its own. Havi
by skymt 11y ago
Iridium's website makes a selling point of the fact that Chrome contacts Google servers, but fails to mention that it may phone home to servers of its own. Having to search the source to discover that large a privacy difference isn't proper disclosure to my mind.
I don't claim it's necessarily malicious. The explanation given in the git log makes sense, though there are better ways to accomplish the stated goal, such as replacing Google's tracking URLs with invalid ones. But leaving those changes in public releases of software supposed to increase privacy seems negligent.
- bigiain 11y agoFWIW, whatever Iridium might be doing with "phoned home" data, it's spectacularly unlikely they're capable of getting anything like the datamining utility out of it that an assumed-currently-doing-evil-Google could do. Google Analytics across 60% of the web, Adwords, the other end of a large proportion of my email content even if I don't use gmail (because it's sitting there in my correspondents Google hosted mailboxes) - Iridium don't have any of that to correlate my browser's behaviour with. And from a person assumed to have no privacy rights by the NSA (since I'm not an American citizen) there's some benefit of that phoned home data existing in a non US legal jurisdiction too... Even if you _don't_ assume Google is currently doing evil, we _do_ know they're subject to PRISM and NSLs...
- bigiain 11y agoI'll also mention that - in a completely unfair-to-you way - I just went and scanned through your comment history to see if I could quickly identify NSA shilling... Such is the nature of the discourse these days. Sorry. (Or, if you _are_ an NSA stooge, congratulation, you do a reasonable job of hiding it...)
- socceroos 11y agoHahaha, distrust goes both ways though! Suppose you're trying to coerce people into using this browser knowing that you've (NSA) already snuck in some backdoors? They used to say that you have to trust the compiler. But not even that is true these days. Perhaps you've read about the secret hdd partitions that the NSA were using. These days it goes like this: open-source hardware, open-source firmware, open-source compiler, open-source software. Only when an entity can follow this path to build their own trusted stack can we begin to move with high confidence.
- bigiain 11y agoEven open source hardware isn't sufficient against an attacker as seriously resource rich (both cash and technical ability-wise) as the NSA. You can't trust the supply chain any more, you can't even trust the silicon unless you made it (and all the machines you used to make it) yourself. Are you _sure_ that network chip, usb controller, or flash ram you built your open source hardware out of isn't exploited? If you're on the fence about whether you're "too paranoid" or "not paranoid enough", make sure you've read what some people do for free, just for fun/curiosity/geek-cred/reputation: http://travisgoodspeed.blogspot.com.au/2012/07/emulating-usb-devices-with-python.html http://travisgoodspeed.blogspot.com.au/2012/07/emulating-usb... http://www.bunniestudios.com/blog/?p=3554 http://www.bunniestudios.com/blog/?p=3554 Then imagine what their grey-suited counterparts on 200K salaries at the NSA with (for all intents and purposes) unlimited research budgets might be up to.
- socceroos 11y agoI wholeheartedly agree, but that is what I meant by 'own trusted stack'. From the ground up (literally), you have to control each part of the process.