Forget Chrome—Google Starts Tracking All Your Devices In 8 Weeks

2 years ago by raqqed to c/privacy

MajorHavoc 186 points 2 years ago

TL;DR - Google makes (arguably insane) claim that it previously acted responsibly with regards to fingerprinting, and says they will begin acting irresponsibility with fingerprinting in February.

Practical take-aways you probably already knew:

  • Today's Google may do or say anything to make an extra nickel.
  • Today's Google, while it employs some excellent privacy minded engineers, has not demonstrated an organizational commitment to user privacy.
  • It is probably wise to assume that the next serious data breach at Google will end marriages, get politicians arrested, get famous people canceled, fuel successful scammers, and have every other privacy impact you can imagine. We know the Google data pool is massive, and we have reason to believe it is incredibly personal. I'm aware that Google has anonymozation solutions in play, and I do not believe those solutions will be effective in a breach scenario.
  • I believe that the average person will likely be better off ten years from now if they interact less with Google services.
path: 0 14095156, hotness: undefined, score: 186, children: 7
Reddfugee42 111 points 2 years ago

Like Google maps:

we anonymize your data before selling it. So it leaves your address every morning and goes to your office every morning but it's completely anonymous.

path: 0 14095156 14096727, hotness: undefined, score: 111, children: 2
MajorHavoc 37 points 2 years ago

Exactly. I don't think I'm alone in feeling that Google's clever privacy engineering isn't enough to keep any of us safe.

Google's expectation that we be okay with these practices feels like corporate gaslighting, to me.

path: 0 14095156 14096727 14098748, hotness: undefined, score: 37, children: 0
Jolteon 3 points 2 years ago

Huh, it's a good thing there is no way to easily determine who someone is from that information.

path: 0 14095156 14096727 14119631, hotness: undefined, score: 3, children: 0
ryan213 21 points 2 years ago

Thanks! The article was a bit of a tough read for me. Lol

path: 0 14095156 14095230, hotness: undefined, score: 21, children: 1
LoganNineFingers 8 points 2 years ago

Ditto!

path: 0 14095156 14095230 14096399, hotness: undefined, score: 8, children: 0
DankOfAmerica 5 points 2 years ago

It is probably wise to assume that the next serious data breach at Google will end marriages, get politicians arrested, get famous people canceled, fuel successful scammers, and have every other privacy impact you can imagine. We know the Google data pool is massive, and we have reason to believe it is incredibly personal. I'm aware that Google has anonymozation solutions in play, and I do not believe those solutions will be effective in a breach scenario.

That would be an interesting experiment. Maybe cancel culture and public shaming will cease when everyone realizes no one is perfect and most people do shitty things from time to time.

path: 0 14095156 14105068, hotness: undefined, score: 5, children: 1
douglasg14b 3 points 2 years ago

It won't only a few will be targeted in the media and the same cancerous culture will continue.

path: 0 14095156 14105068 14114135, hotness: undefined, score: 3, children: 0
sakuragasaki46 47 points 2 years ago

So the e-mail I got with them claiming they will delete my location history is a lie?

path: 0 14098506, hotness: undefined, score: 47, children: 3
MajorHavoc 87 points 2 years ago

To the best of my knowledge - from a spirited but doomed attempt to read Google's privacy policies - Google is committed to deleting your location history after sharing it with 10,000 or so vendor partners.

Each of those vendor partners have pinky promised to comply with the rules outlined in the same privacy policy that I failed to read.

For context, I'm not convinced any living person has read the entirety of Google's privacy policies.

Sadly, I'm quite confident - by the law of averages, human nature, and corporate corruption - that not all 10,000 trusted partners also deletes our location data history.

Google does take privacy preserving steps to anonymyze what it shares.

My educated opinion is that no amount of attempted anonymozation is sufficient for the breadth, scope and quantity of data that Google collects.

Shorter answer for you: yes, I believe that is a corporate lie. True only in technicality, but likely false by any reasonable persons expectation of what "delete" means.

path: 0 14098506 14098682, hotness: undefined, score: 87, children: 2
0x0 6 points 2 years ago

For context, I’m not convinced any living person has read the entirety of Google’s privacy policies.

Their own lawyers, maybe.

path: 0 14098506 14098682 14108012, hotness: undefined, score: 6, children: 1
MajorHavoc 9 points 2 years ago

Yeah. Their own lawyers have the best chance, but there's so many pages, combined, I wonder if even one of their lawyers has read everything

path: 0 14098506 14098682 14108012 14109695, hotness: undefined, score: 9, children: 0
catloaf 33 points 2 years ago

What exactly is the change being made? I don't see that the article actually explains it anywhere.

path: 0 14105129, hotness: undefined, score: 33, children: 1
BaumGeist 14 points 2 years ago
path: 0 14105129 14114736, hotness: undefined, score: 14, children: 0
Yingwu 29 points 2 years ago

I didn't see anything about the implications of this on the EU and GDPR?

path: 0 14096889, hotness: undefined, score: 29, children: 0
Zerush 26 points 2 years ago

The worse, it does not only using Google Apps or Services, but more than the half of existing webpages use one or another Google API (at least googleanalytigs and google-tagmanager.which log and spy the visitors and users.

Hard, very hard to avoid it, Googles eyes are everywhere, even in FOSS.

path: 0 14110549, hotness: undefined, score: 26, children: 2
Luffy879 3 points 2 years ago

You can pretty much block those domains in noscript without breaking the Website

path: 0 14110549 14115538, hotness: undefined, score: 3, children: 1
Zerush 8 points 2 years ago

Yes, you can easily block the tracking crap being downloaded to your HD and added to your browser, almost everyone do it, but you can't blck the logging of websites which use the Google (mostly) and other APIs. They store your PC and browser data in their server, which you can't access. The only possibility is using a VPN and other which spoof or fake your data, so that is don't have a real value. To use a mail which permits to mask your real mail direction, because your mail is an unique identifier which can be tracked all over the web. Using Image share which delete the EXIF data (vgy.me eg., Read always PP to see with which companies are shared your data, and some protections more to patch the worst privacy holes, but forget 100% privacy in the moment you goes online, it's only a myth to calm the people which intent to stay private with their shitty PC against the tech of the big ones.

path: 0 14110549 14115538 14116109, hotness: undefined, score: 8, children: 0
hellfire103 23 points 2 years ago

*laughs in LineageOS

path: 0 14096345, hotness: undefined, score: 23, children: 7
FrostyPolicy 50 points 2 years ago

Laughs in GrapheneOS.

path: 0 14096345 14096685, hotness: undefined, score: 50, children: 5
techt 8 points 2 years ago

Pretty sure Graphene doesn't do much about fingerprinting on its own, it's nearly entirely up to the browser. They mention some of their plans to address that with Vanadium, but make no claims as to how effective it is now (at least on the features page).

path: 0 14096345 14096685 14102026, hotness: undefined, score: 8, children: 4
FrostyPolicy 3 points 2 years ago

No google on device no tracking, and I don't use google services anyhow (with first party clients anyhow). I do have google play services installed but no google account so they don't have an identity to connect the data they might be able to collect from the phone. Only google service I use is youtube but that's with third party clients only (FreeTube & NewPipe) over vpn of course.

path: 0 14096345 14096685 14102026 14106112, hotness: undefined, score: 3, children: 2
techt 9 points 2 years ago

Right -- all privacy-positive methods to employ, but not helpful for fingerprinting. In fact, some things can make you more susceptible to fingerprinting because they make you more unique (like using a custom OS). It's all about your browser and what it chooses to send with HTTP requests, how it responds to queries for you device/browser specs (via Javacript). Your OS, system architecture, hardware details, browser type and plugins, etc combine to make a very unique profile tied to your device. It's especially nefarious because all those bits are cross-referenced over all accounts and devices to make a global profile on you. Even if you've never used Facebook, you probably have a shadow profile. If you've ever logged into the same service or website account on your de-Googled GrapheneOS device as another machine that does have Google services tracking, then your new device is likely already tied to your identity.

Try this with different browsers -- it tests the uniqueness of your device.

path: 0 14096345 14096685 14102026 14106112 14106509, hotness: undefined, score: 9, children: 1
jagged_circle -1 points 2 years ago

It doesn't have gapps, so you're good

But, of course, use Tor Browser

path: 0 14096345 14096685 14102026 14109472, hotness: undefined, score: -1, children: 0
squid_slime 2 points 2 years ago

*laughs in CalyxOS

path: 0 14096345 14104388, hotness: undefined, score: 2, children: 0
DieserTypMatthias 15 points 2 years ago

Time to root and degoogle for the unfortunate.

path: 0 14109000, hotness: undefined, score: 15, children: 0
bradboimler 13 points 2 years ago

Glad I don't use any Google services and no apps on graphene OS then for my main computers I run Fedora silverblue with no Google once again.

path: 0 14097009, hotness: undefined, score: 13, children: 7
Hector 10 points 2 years ago

Yes but do you use PiHole and a solid VPN? Do you spoof your browser's useragent? Even then, some would argue that you are not safe enough from Google's prying eyes.

path: 0 14097009 14099516, hotness: undefined, score: 10, children: 6
GenosseFlosse 7 points 2 years ago

Doesn't matter, your browser will be fingerprinted with some embedded JavaScript that works in all modern browsers. Detecting VPNs is also trivial.

path: 0 14097009 14099516 14102260, hotness: undefined, score: 7, children: 3
jagged_circle 1 point 2 years ago

It doesn't matter if they detect you're on a VPN when that VPN is shared by tens of thousands or millions of others. Thats literally the point. It prevents fingerprinting by IP

path: 0 14097009 14099516 14102260 14109504, hotness: undefined, score: 1, children: 2
GenosseFlosse 1 point 2 years ago

"User connects via VPN XYZ" is part of the fingerprint. It doesn't protect you from identifying you, instead it ads to the number of unique properties of your computer and connection, adding to the size of your fingerprint. Besides, a lot of VPNs and proxies add another header x-forwarded-for with your original IP. Source: I worked on multiple e-commerce platforms that use fingerprinting as part of their fraud protection. Also see https://coveryourtracks.eff.org/learn for a more detailed explanation.

path: 0 14097009 14099516 14102260 14109504 14118243, hotness: undefined, score: 1, children: 1
datavoid 1 point 2 years ago

Map car retreats around corner

path: 0 14097009 14099516 14100728, hotness: undefined, score: 1, children: 0
jagged_circle 0 points 2 years ago

TorBrowser does all of this for you.

path: 0 14097009 14099516 14109509, hotness: undefined, score: 0, children: 0
Fusty 6 points 2 years ago
path: 0 14097579, hotness: undefined, score: 6, children: 0
autonomoususer 4 points 2 years ago

What's a Chrome?

path: 0 14097515, hotness: undefined, score: 4, children: 4
QuazarOmega 13 points 2 years ago

I think you put that on your motorbike's tubes and stuff

path: 0 14097515 14098910, hotness: undefined, score: 13, children: 0
archy 6 points 2 years ago

Google it

path: 0 14097515 14097946, hotness: undefined, score: 6, children: 0
rcbrk 4 points 2 years ago

still from mad max furiosa or something showing a character with chromed mouth area

path: 0 14097515 14105803, hotness: undefined, score: 4, children: 0
sakuragasaki46 3 points 2 years ago

Chrome

path: 0 14097515 14098524, hotness: undefined, score: 3, children: 0
jagged_circle -2 points 2 years ago

Just install a ROM without gapps and no they won't

path: 0 14109455, hotness: undefined, score: -2, children: 0
privacy
privacy

@lemmy.ml

login for more options
50486
5111
5185

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
  • Don't promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

go to feed...