Chrome records your Google ID without being signed in

Η πραγματοποίησε μια σημαντική αλλαγή στον τρόπο με τον οποίο λειτουργεί το πρόγραμμα ς Chrome, μια κίνηση που η εταιρεία δεν διαφήμισε στους χρήστες της και η οποία έχει σοβαρές επιπτώσεις στην ιδιωτική ζωή.

According to several reports [ 1, 2, 3], starting with Chrome 69, each time an application user visits a Google-owned Web site, the browser logs the user's Google ID into Chrome Sync.google chrome leak

Sync allows users to link to their Google Chrome accounts to upload and sync (optionally) local browser data (history, passwords, bookmarks, and so on) to Google's servers.

Ο συγχρονισμός υπάρχει στον Chrome πάρα πολλά χρόνια, αλλά μέχρι σήμερα το σύστημα λειτουργούσε μόνο αν είχατε κάνει  σε λογαριασμό της Google. Αυτό επέτρεψε στους χρήστες να πλοηγούνται στο διαδίκτυο ενώ ήταν συνδεδεμένοι σε έναν λογαριασμό Google (Gmail, YouTube), αλλά δεν ανέβαζαν τα δεδομένα περιήγησης του Chrome στους διακομιστές της Google, δεδομένα που προφανώς συνδέονται με τους λογαριασμούς τους.

With the latest revelations about the new auto-login mechanism, too many users are not at all happy with the insidious modification that allows Google to link each person's traffic to a particular browser and a device with higher precision.

This practice proved to be wrong, as Google technicians clarified in Twitter that this automatic sign-in feature does not start the local data synchronization process on Google's servers but requires a user click.

Furthermore, they also revealed that the reason why this mechanism was added was for reasons of private life. Chrome engineers stated that the auto-login mechanism was added to the browser because of shared computers – browsers.

When one or more users use the same Chrome browser, the data from these users could be sent by mistake to another person's Google account

However, despite the logic behind this move, users are still unhappy because they no longer have the option of deciding when to log in to their browser and secondly why Google did not say anything about the new feature.

Google Chrome 69 was released on September 5, about two weeks ago, and no one knew what the program did in the background.

All users who don't use Chrome's sync feature while running the latest version of the browser have sent data with their Google ID to Google if they're signed in to a Google account somewhere in Gmail, YouTube, or any other the company's.

Matthew Green, a well-known encryption expert and professor at Johns Hopkins University, said in a paper on his blog that Google has redesigned the Sync account interface in such a way that it is no longer clear to users that they are logged in or what they need to push to start synchronization.

He calls this change "dark pattern", A term we have described in older publications.

In its current form, the Sync account interface is actually misleading and a user can accidentally click on all of his browser's data on Google.

Chrome 69 was a major release with many new features, such as a new user interface. Some claim that Google hid this change in the version of Chrome 69, hoping that no one would see it among all the features of the new version, and so it took more than two weeks for Google friends to detect the behavior.

However, the influence of a few hot Twitter posts has helped push things forward on Google's HQ and Chrome technicians have announced that Google will update Chrome's Privacy Policy to reflect the new Chrome mode.

Of course this policy update can satisfy some lawyers but does not address the issue. Google has modified a Chrome feature without informing users, and this modification can lead to serious privacy violations.

_________________________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).