Hacker Newsnew | past | comments | ask | show | jobs | submit | eh78ssxv2f's commentslogin

There are many cases where Google has used dark patterns to gather data from users. Now, the ToS may mention those cases clearly, but that's not an excuse for the Google's behavior.

Recent examples: Google tracking users per Chrome installation ID [1], Chrome exempting Google sites from user site data setting [2], Chrome experimenting with silently proxying user traffic through their servers [3].

[1] https://news.ycombinator.com/item?id=22236106 [2] https://news.ycombinator.com/item?id=24817304 [3] https://news.ycombinator.com/item?id=25337995


Do we know the reasoning behind the bias?


I don't understand how gnucash is more critical than Arduino, wine or nginx. Is gnucash very widely used?


It does seem to be popular w.r.t user downloads and other github metrics. E.g. https://sourceforge.net/projects/gnucash/files/stats/timelin... Wikipedia - "As of July 2018, SourceForge shows a count of over 6.3 million downloads of the stable releases starting from November 1999[24] Also, Sourceforge shows that current downloads are running at ~7,000 per week.[25] This does not include other software download sites as well as Linux distributions that provide download from their own repositories."


> This does not include other software download sites as well as Linux distributions that provide download from their own repositories.

Isn't that a pretty significant difficulty for the interpretation of this number, though? Couldn't there be some package that is installed by default in, say, Ubuntu (and that Ubuntu can't boot without), so therefore millions of users are using it -- but perhaps the "downloads" seen by GitHub or SourceForge are mostly by OS packagers or by developers contributing to that package. Whereas if there is something where, for some reason, end-users customarily or commonly get it from GitHub or Sourceforge, it might look more widely used even though it is actually less used overall, potentially even by orders of magnitude.

(Like GNU coreutils, at an extreme, is probably not that popular at all for end users to download from a source control system, yet it might be running in tens or hundreds of millions of devices, which could not even boot without it.)


coreutils is in the top 200 list, c_top_200.csv:coreutils,https://github.com/coreutils/coreutils,C,90,0,240,5,2.2,50,1...

There will always be edge cases and scenarios we are not taking into account, please provide feedback on issue tracker and provide any suggestions so we can account these.


Man... that’s 700 downloads a day. 29 downloads an hour. That’s by no means “popular”. At least not in the scale you should be looking at.


7000 downloads per week is almost nothing.


Even if it is widely used, there are tons of replacements.

This ranking is very flawed if I can literally go to Best Buy and get a replacement for "critical" software.


Exactly.

Besides privacy and obvious web-centralization issues, there are bunch of security issues associated with proxying the traffic. Apple and Mozilla brought these issues to the attention of Google during SxG spec discussions. At that time, Google's rebuttal was that SxG is a opt-in feature for sites.

Quoting from [1] (Mozilla's official position on SxG): "Sites opt-in to using this mechanism, and in doing so need to be aware that this comes with some risks, but in doing so they enable a new feature".

This time, Google really did not handle any of the previously discussed security/privacy concerns. Instead, they just went ahead and started proxying the user's traffic without the opt-in from the users or the sites.

[1] https://docs.google.com/document/d/1ha00dSGKmjoEh2mRiG8FIA5s...


I commented on [1] too, but it's worth mentioning here as well as it clearly shows the stark difference between Google and Apple/Cloudflare.

Apple/Cloudflare are working on privacy-friendly protocols that reduce the amount of information exposed to them [1].

At exactly the same time, Google here is working on proxying non-Google browser traffic through them without consents from either the user or the publisher.

[1]: https://news.ycombinator.com/item?id=25344358


What a stark difference between Google and Apple/Cloudflare.

Apple/Cloudflare are working on privacy-friendly protocols that reduce the amount of information exposed to them.

At exactly the same time, Google is working on proxying browser traffic through them without any consents [1].

[1]: https://news.ycombinator.com/item?id=25337995


I guess all the user "consent" for Google proxying (spying) users are included in the ocean of ToC text

Thus I am using Google Chrome only for Web Dev


How do you guarantee anonymity to the users filling out the survey? The surveyor could send different increment URLs to different users.


It's a soft deterrent based on effort (to create individual topics) currently - and will be made tougher when the private beta ends because there's likely a pricing/cost impact tied to topics. Have yet to see anyone attempt this, and it is against the general ethos - so it's a situation that would get more actively discouraged if it actually started to happen. Thanks for sharing your thoughts on it.


For Enterprise Android devices (i.e., the one owned by the employer), the employers always had the option to install device management policy and disable parts of the phone based on those policies (e.h., remotely disable phone of an employee that was terminated). The other evergreen use case is for the parents to remotely disable/control/set policies for the phone for kids.

In this case, the telcos are just using the same device management policy. They can do so because they own the phone (have physical access to it and their legal contacts allow them to do it). I don't think Google did something specific here to enable this feature for telcos.

Note that the iPhones also has similar feature. So, switching is not going to help.


> A search engine from a non-advertising-supported company is great news.

Currently, Apple actually gets money from Google for selecting the latter as its default search engine. Not only Apple will lose that money but would also need to dump money in developing + maintaining the search engine.

May be their goal is to just provide a more privacy-sensitive search but I'm a bit cynical about that motivation. So, the economic model is still unclear to me.


> No the concern is they aren't subject to the laws of our land

What specific laws of the US land are they not subject to?


I assume you're being pedantic, because the answer to your question is obvious, but I'll explain what he meant anyway. Once the data is in China, in the hands of the Chinese government, their use of it might theoretically still be "subject" to US law, but as a practical matter, nobody could do anything to stop them from doing anything they wanted with it.


But what is this "whatever they want with it" that would be illegal in the US?


I was just explaining the poster's point. Personally, I think that most data produced/collected by social networking applications is worthless. All of these draconian privacy laws that have been passed, in my opinion, are nothing more than political theater and make little to no difference to 99.99% of the population. GDPR, for example, has produced nothing more than lots of annoying popups that nobody pays attention to, and billions of dollars in fees for compliance consultants. I can understand the government banning people that have security clearances from using certain apps, but blanket banning an app seems like an overreach.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: