Hacker News new | ask | show | jobs
by rectang 3062 days ago
I use gmail and don't wish to give it up for now. I launch gmail in a site-specific browser process so that my login is isolated. This makes it so that in my main browser, I'm not logged into my Google account and they don't see where I go. As a bonus, the "filter bubble" effect is diminished for my Google searches.

That's not a reasonable approach for non-techies, but I thought it might interest the HN audience.

11 comments

I'm not logged into my Google account and they don't see where I go.

If they see activity from one IP to say search, then activity from the same IP to visit the top result of that search, they don’t need a cookie to track you.

Anyone who shares an IP has seen ads actually targeting another member of their household...

Usually that's not a reliable way to identify a unique user. Given the prevalence of NAT, re-using IPs by ISPs with DHCP, and a host of other reasons. (That's not to say there aren't ways to fingerprint users across devices and browsers.)
A service ISPs should offer as standard is regularly randomising your outbound IP from their pool for all but a whitelist you specify. So you can have a static IP for say you work firewall, but are harder to track otherwise
Most ISPs are in bed with the advertisers and tracking. That's one reason I don't use my ISP's DNS.
Do you use googles?
Yes, that is possible -- and I'm sure that other trackers are doing their best with fingerprinting, etc and that they manage a certain amount despite my having Privacy Badger and uBlock Origin enabled in my main browser.

However, IP based associations do not show up in the user history that Google allows me to see, and as far as I can tell Google does not change my experience based on it.

I'm still subject to some filter bubble effects because I only zero out my main browser every few days.

> I use gmail and don't wish to give it up for now.

Well, that's your choice, isn't it?

> That's not a reasonable approach for non-techies, but I thought it might interest the HN audience.

Non-techies can just go the good ol' way and pay for an ad-free, tracking-free email service, mapping service, storage service, etc.

I’m not a google fan, but can you name one free service that is par? I think many people would en pay if there was an alternative
Two of the replies mention FastMail, which for all I know might be nice, but FastMail still seems to be in its infancy (though perhaps growing fast) when it comes to securing customers' data. See the recent https://news.ycombinator.com/item?id=15853477

I've been using Gmail for over a decade. I've been getting in the habit of using a purpose@mydomain email for as many signups as I can (that for now all forward to my gmail) so that the impact of a random Google mess up that disables my access to my account is lessened, but there's still no service I trust more for my email's security and privacy apart from Google's algo-eyes (that offer me some features I appreciate anyway). Maybe that trust is misplaced and we're only a few years away from a Yahoo-level incompetence reveal, but I doubt it.

If there was a way to setup a local mailserver that can peer in a hierarchy with more trusted mailservers (so that I can send email with reasonable confidence it won't end up in a spam folder), and have encrypted buffers stored at those peers for when my local machine is offline and can't accept deliveries, I'd do that. Maybe it's possible with Urbit.

I am paying for FastMail for a few years now. It's a very good alternative, and it's really not expensive. Also, I know that my money goes into building an alternative with a viable business model.

Plus, GMail isn't free. You pay for it with your data.

I switched to FastMail about 6 months ago, and I like it. I actually like FastMail’s webapp more than Gmail’s. There aren’t any features from Gmail that I miss, and FastMail offers a very easy option to migrate your emails from Gmail.
If the time comes when you are ready to move on from Gmail, I can recommend Fastmail and ProtonMail. Both use a webmail interface that is very similar to a desktop client. ProtonMail is free for a single address with low volume, Fastmail is $50/year. ProtonMail is based in Switzerland and Fastmail in Australia.

I'm not affiliated with either company but I've evaluated both and settled on Fastmail as my Gmail replacement, mostly because of the added features like file storage, static web hosting, and notes, all of which I've used extensively.

Based on resolution of browser, user agent, list of plugins and all sorts of other seemingly unproblematic pieces of information one can build a unique fingerprint to track you without cookies. Most of it relies on JavaScript of course but if you use gmail you do run JS.

Go to this site and perform the test to see for yourself: https://amiunique.org/

Or the EFF one: https://firstpartysimulator.org/

I think you're overestimating the privacy benefits afforded by using two browsers. Both browsers are using the same IP address which means that google can identify you in the other browser with high certainty. I also have two browsers and use only one to log into google. Yet, google firmly places me in my filter bubble even in the other browser.
or look at the unique fingerprint of your browser anyways :)

https://panopticlick.eff.org/

I launch Google in it's own Firefox container. Thank you Mozilla.
I register all my accounts using Gmail because I feel DNS/domain security is a joke (this was debated here in the past but I don't have the technical knowledge to explain it any better). I'm saying that because IMO using your own domain is crucial for privacy and control.

I choose Google one day randomly blocking my account over losing it to some random person from the web. At least I can make a blog post and try to make to HNs frontpage to get some customer support.

Maybe I am missing something here, but how does this help against being tracked by google through google analytics and/or their ad-network?

Sure they cannot 1:1 link your {analytics, ad} identity to your actual Google identity, but I am reasonably sure that they have all the data necessary to do it via (not too many) connecting dots.

yea.. you can use something like Privacy Badger and block analytics

https://www.eff.org/privacybadger

Slowly moving away from google what my personal email concerns - to protonmail, btw; I do use G+ as an excuse for social media, though, mostly for being able to stalk Linus on his scuba diving trips.
Additionally, consider that google has some advanced machine learning shit that can likely analyse your writing style. Even an antipattern is a pattern.
Though they actively scan your email for targeted ads and correlate them to you outside of your jail through GA, which doesn't really require login. Unless you connect through a different VPN and browser/etc.

Seriously though - who cares? You use a credit or card? Your purchase history has been sold to advertisers and similar for decades, it's just more transparent now.

OP here is simply fomenting mistrust of the more obvious players to draw traffic (and advertising bucks) to their own website (duckduckgo).