Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Genuine question. Is it reasonable as a user to expect data collected by Google via maps.google.com to not be shared with other Google applications e.g. mail.google.com?

I'd have thought data collected on any of their domains would be meshed/merged behind the scenes where it suits them to do so?



I think the concern is less about other Google businesses having access to maps data as you suggest.

It’s more about the fact that using non map Google services on google.com will not prompt asking for location service permissions, if they’ve been granted when prompted on google.com/maps already.

Users may not want location to be collected for searches, but are okay with the privacy tradeoff for it being collected when using maps.


I think the concern is more about when Google is able to collect said data, not whether it's shared or not.

I don't have location enabled for Google maps in the browser, but if I did, then presumably Google could collect that data also when I'm just searching for a website.


But isn’t collected/shared inherently the same thing here?


No, what they are talking about is all Google properties (eg Google search) now being able to collect your location every time you use them, if you granted permission for maps to get your location.

So it’s now not possible to block location for search, and grant it to maps (at least using the standard browser domain permissions model).

https://support.google.com/chrome/answer/114662?hl=en&co=GEN...


But they could've been doing that all along because they control both sites, they would've just needed to use an iFrame. What changed beyond "it's a little easier now"?


Is that how browser permissions work? Naively I’d assume the browser grants only search.google.com permissions on that url, even if maps.google.com is opened as an iframe.


It's been ages since I've played with iframes, but I'm pretty sure it does (or at least did?). You might have to specify an allow policy [0] but that's no problem if you control both sides. Since iframes are secure, data wouldn't leak unless the iframe explicitly posts it.

I don't know if you can request permissions from the iframe (might confuse people), but if you already have them, it ought to be fine.

[0] https://github.com/w3c/webappsec-permissions-policy/blob/mai...


Thanks for the docs. The examples (2 & 3, https://github.com/w3c/webappsec-permissions-policy/blob/mai...) seem to me to say that search.google.com can’t grant location permissions to an iframe if the parent was forbidden them, but I didn't find an explicit example for what happens if the iframe domain already got permission previously.

As you say the UI for requesting in this case would be weird, and this seems like a big security hole to me, but I can’t see a bit of the spec that explicitly forbids (though I only scanned the doc.)


Do you mean:

- is it reasonable for a user to expect that Google will collect all bits of information about them, because Google isn't prevented from doing that?

or

- is it reasonable for a society to allow Google (and competitors) to do this?

I think the answers are respectively yes and no.


The different Google Apps surely rat you out to each other.

But now google.com will know where he is when he browses it, not just when he uses Google Maps.


They can already join your activity across everything. This is about access and collection. So if they move store.google.com to google.com/store, they will have access to all browser permissions you gave google.com/maps or google.com/flights.


I'm ok with sharing my location with maps (and therefore google) WHILE USING MAPS. Not when I'm reading my emails, or searching for something on the web.


It could be tricky with permissions on different users: for instance you authorize google.com/maps to track your location while logged as user A.

You logout and switch to user B to look at another Google service, but google.com is still allowed to get your location, and will stick it to user B, which is something you might not have wanted. This didn't happen with the previous domains, so could be a surprise.


I think it is reasonable to expect Google to share the data and get sued for it, because it isn't reasonable.


Oh having though about it I agree, I just think we're probably a minority.

As others have pointed out the line has been blurred between search and maps so far that maps has search embedded, and search has maps embedded. A lot users of Google search likely expect results to be location aware without realising what privacy has been eroded to enable that.


Applications are not juridical entities, so at the absolute best it is debatable.

Most probable version is that they share as much data as their internal regulations say, or a bit more. They definitely have some form of internal regs on this, for basic security hygiene, but they write it.


FWIW, there's an EU regulation coming that prevents companies from using data necessary for a product (like maps) to be used to improve a different product (like search).


I'd be interested to find out whether this works as intended. There's a good argument that maps is a subset of search. Most people don't open Google maps just to look at a map, they search the map for a place.


IIUC, maps would send your location to search if-and-only-if you make a search from inside maps, since that is necessary to do the precise location-based search.


Ask your local Information Commissioner whether this is GDPR-compliant.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: