back

by rvz·7y ago·view on hn ↗
It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android. Then the Go modules proxy issue around the Go Programming language that raised suspicions about tracking usage statistics around downloading modules turned on by default without any consent and now this.

I think there are some folks at Google who have just read too deep into both 1984 and The Google Book to go on to think that privacy violations like this is a normal thing. But what do I know? I'm just another 'privacy lunatic' on the net that wears a metal helmet (tinfoil hats are just not good enough) trying to protect my privacy.

13 comments
The Go module hash checking seems to be more about avoiding the problems encountered by other language repos integrity and versioning issues (cough NPM), and in terms of tracking it seems about as invasive as Debian's popcon.

Enabled by default can and should be the default for security-related features.

I tend to agree about the rest of the creepiness, especially anything personally behavioral.

On HN it is taken as gospel that any information sent to a server will absolutely compromise your privacy. If anyone points out that the information is trivial or useless the rebuttal is instant - it can be cross referenced with other sources to build a complete profile of you.

If you want to know which Go modules I use, go check out my github. They're listed right there in import statements. If I'm hacking on a project that I want to keep private, I'll disable this feature with a command line flag - easy.

My issue with the paranoid folks in that thread is not that they made no sense (they can't help that), it was they were attacking the person who implemented the feature viciously. He had implemented a feature that a majority of Go developers had been requesting for 5+ years, had done it in a way that improved clean build time, improved security and could easily be disabled or replaced with a private DB. Literally what else could that man have done?

Even though all his work could be verified trivially (Go is open source!), they still chose to attack him.

> Literally what else could that man have done?

He could have not sent all build-time network accesses to Google by default. It's that simple.

No it isn't. Please tell me how you achieve security without storing hashes in a DB? The default is only for those who'd prefer not to run their own DB. You are welcome to run your own DB if you want.

Why are you so upset that other people will be using a feature you obviously won't? Why are you upset when this leaks literally no info that your github repo doesn't already?

Is there any meaningful difference between what google knows about your modules and what npm knows about js modules? Or what a Debian mirror operator knows about your packages?

I get that Google changed the way go packages work, but I don't understand the difference between that and literally every package manager in existence.

> not that they made no sense (they can't help that)

Try being a little less rude to the other folks on this thread.

Google (as well as surveillance states) use security arguments conveniently a bit too often to try and justify their actions.
Debian's popcon is not enabled by default.
It isn't, but it's installed by default, and I'm always amused when I get to that installation step. "Do you want to tell us about your system?" answer no "installing popularity-contest"
Debian's popcon is really irritating because Debian actually uses it as a source of evidence... systematically eliminating those of us who keep it off for privacy/security reasons.
Let me get this straight. You have an opt-in way of telling them what you use, which you don't use and then get upset because your use isn't considered? What should do they do, send a surveyor to your house?

Sound decision making requires metrics. If you opt-out of metrics, you don't get to participate in decisions.

> If you opt-out of metrics, you don't get to participate in decisions.

Would you agree to a Democracy where the government put sensors in your house, then told you which candidate your vote would be counted towards from your behaviour?

And if you opted out of that, you don't get to participate at all?

Sound decision making requires reasonable metrics. To quote the lead dev of popcon when someone said that they couldn't recommend it due to specific concerns:

"If you deal with people with strict security/privacy requirement, you are correct to do so. I would do the same."

> Enabled by default can and should be the default for security-related features.

Not since Google uses the argument of increased security to justify data collection for quite some time in the interest of itself.

You are free to setup your own DB if that's a concern for you. It's a totally justified concern, but this is just concern-trolling. Most people would use this either way. People with strong privacy concerns may setup their own DB, but they represent the minority (despite the heavily privacy-biased stance of HN users).

If you're in the minority, you should expect to have to do more work to get the right balance of security and privacy.

I am just criticizing collecting data under the veneer of security or creating a dependence at this point. These are two completely separate issues and the argument for security is used to justify questionable practices.

> If you're in the minority, you should expect to have to do more work to get the right balance of security and privacy.

It is exactly this false dichotomy that I am criticizing here, because it is completely baseless.

You are reading an article that hints to privacy violations.

You can only be secure if your privacy is protected. That is the causal relation between these two needs.

> in terms of tracking it seems about as invasive as Debian's popcon.

How do you figure?

A reasonable debate about your privacy concerns cannot be had if you take the most extreme response and pretend it represents what you are or what everyone thinks you are.

You are assuming you were branded by a large swath while similarly branding an entire company that is clearly represented by many diverse opinions on diverse products. The debate needs more nuance lest everyone pulls out their broad brushes while also taking offense to receiving a fleck of paint. Conflating the Go proxy w/ Google's ad business is a perfect way to ignore nuance in the debate downplaying the real, tangible effects.

"You know, that PATRIOT act really allows spying on everyone"

"Come on that's just paranoia"

Snowden leaks secret program that implements everything details in the patriot act.

"WHO COULD HAVE SUSPECTED?"

If I remember right, after the leaks the faux-sophisticated take was "well of course, everyone knew this was going on, are you naive?".
I think some commentators were sophisticated enough to deposit both of these stinkers on the same thread...
There were two faux-sophisticated takes. "See, I told you they were spying on everybody!" and "Everyone already knew they were spying on everybody!" Both were from the same group of conspiracy theorists who believed the US government was spying on everybody even after Snowden's massive leak showed they weren't.
"Faux sophisticated" my ass.

EU was warning about Echelon since before 9/11. The Patriot act detailed everything Snowden "revealed" (we basically only learned the actual names of the programs).

There was genuine shock in Europe that Chirac, Sarkozy, Hollande, Merkel were all spied on by NSA. Yes, we were naive conspiracy theorists when we were saying "you know, they gave them the right to do it, so they are probably doing it". But it all fell on dead ears.

> There was genuine shock in Europe that Chirac, Sarkozy, Hollande, Merkel were all spied on by NSA

The USA (and all major powers) has spied on foreign diplomats and leaders since its inception. This should come as a surprise to nobody. You had earlier claimed that the NSA was spying on everybody, which clearly isn't happening.

I probably saw those movies at an age where I was too impressionable, but growing of with portrayals of US intelligence units like in Enemy of the State, I always assumed that they did spy on everyone (and didn't even think that this would be some absurd view, or that I was being clever with that thought).
What program did Snowden leak that shows the US government spying on everyone?
You were branded a privacy nut for https://news.ycombinator.com/item?id=20868489 because you didn't note any actual privacy issues in Android.
"Then the Go modules proxy issue..."

https://sum.golang.org/privacy

This links to the Google Privacy Policy which is an additional 27 pages.

"I think there are some folks at Google who have just read too deep into both 1984 and The Google Book..."

Is this The Google Book?

http://blog.outer-court.com/googlebook/

10 years ago you'd be called a privacy lunatic when you said that website owners who used google analytics were just selling their users' data to Google. Same reflexion about those using ad scripts.
FWIW, it is very easy to setup the athens proxy and run it. You could even have it route traffic through Tor if you were so inclined. We use it and are a fan as is works nicely:

https://github.com/gomods/athens

> It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android.

What are the privacy issues in Android 10? Anything new compared to previous versions?

I think the biggest one is some bad wording on the marketing around the "share your wifi" feature, where it mentions that you can share "secure" passwords with QR codes now but doesn't mention that the QR code has the plaintext password encoded in it.

Other than that, it seems that privacy controls have been generally improved in Android 10.

My Honor 7 has been doing that for 3 years, Android 6.

It's called a pre shared key for a reason.

Different types of Hacker News article trends to attract slightly nonoverlap different subgroups of people. You'll sometimes find different sentiments over the same topic under, e.g. U.S. politics, silicon valley startups, cryptography, or urban life.
I’ve noticed this as well. Would love to see some analytics on this.
> I was branded as a 'privacy nut' after the release of Android 10

You were doing baseless accusation on something you don't know anything about. Your comment was basically "they market it as being better to handle privacy thus they clearly are worst with your privacy!".

You didn't raise anything substantial at all in that comment.

Obligatory post:

https://cryptome.org/2012/07/gent-forum-spies.htm

It's just as valid a technique for large organizations as it is for governments.

Active Perception Management is most definitely a thing. Of course it only works because most people aren't aware it is a thing.

https://en.m.wikipedia.org/wiki/Perception_management

I've found that whenever I post anything anti google on hackernews I'm downvoted and people call me names.
> branded as a 'privacy nut'

Only the Paranoid Survive. A book by The President and CEO of Intel.

https://en.m.wikipedia.org/wiki/Andrew_Grove

Wide-ranging thoughts and examining what-ifs makes you a curious individual. Failure to counterbalance confirmation bias by critically examining and deconstructing your own hypotheses makes you a crackpot.

The main difference between the two is just which paranoid thoughts you give credence to.

What?
It appears he differentiated being paranoid, and being a critical thinker.
Obviously a good thinker checks all possibilities, being paranoid in scientific sense.
Great book! Read it prob 20yrs ago.