Skip to main content

When it comes to Chrome, there may not be a reason to expect privacy

Chrome OS

If you’re browsing the web anonymously in Incognito mode on Chrome and need to check your Gmail, you may want to use extra precaution. A new report released by trade organization Digital Content Next suggests that Google could use cookies to associate your Incognito browsing to your Google account if you log into a Google service during your anonymous web session, an assertion that Google disputed.

“This allows Google to connect the user’s Google credentials with a DoubleClick cookie ID,” Vanderbilt University computer science professor David Schmidt and the study’s author said. “While such data is collected with user-anonymous identifiers, Google has the ability to connect this collected information with a user’s personal credentials stored in their Google Account.”

When you begin a private browsing session in Chrome, websites use cookies to serve you ads based on your history. So when you log into a Google service in Incognito mode, Google could theoretically connect your Incognito web history to your Google account by associating cookies from the browser.

A Google spokesperson refuted Schmidt’s claims in a statement to AdAge but did not give a full denial.  “We do not associate incognito browsing with accounts you may log into after you’ve exited your Incognito session,” Google said. “And our ads systems have no special knowledge of when Chrome is in incognito mode, or any other browser in a similar mode (ex: Safari Private Browsing, Firefox Private Browsing). We simply set and read cookies as allowed by the browser.”

Schmidt said that it wasn’t clear if Google was connecting Incognito histories to a Google accounts, but he said that “if you read the fine print on ‘incognito’ mode it brings up a whole lot of disclaimers.” Given that Chrome is the leading web browser with more than 1 billion monthly users, Google has the capability to collect even more data if it did apply this practice. Google discredited the report, noting Schmidt is biased given that he was a witness for Oracle in that company’s lawsuit against Google.

Regardless, if you’re browsing in Incognito mode, it’s probably a good practice to not log into personal services, and you should refrain from logging into your Google account until after you have exited your incognito session.

This latest report follows a recent discovery that Google is still tracking users’ location on Android phones, even if they turn off location tracking in the Google Maps app. Google had subsequently revised its terms of service to note that location data may still be collected based on your web history. Schmidt confirmed this in his study, noting that Google will get a user’s location every time an Android phone connects to Wi-Fi or a cell tower. This helps Google identify, when combined with the phone’s sensor, if the user is walking, running, biking, or riding a bike, car, or train.

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
These Chrome extensions will put cash-saving coupons right in your browser
Woman shopping online for best Early Prime Day Deals

You can save time and money this holiday season with just a few clicks, and you don't have to hunt for those coupon codes on your own anymore, either.

If you know you're going to do your holiday shopping online this year via your Chrome browser, why not let a coupon code browser extension help you out? If you need help choosing one for yourself, read on to see our picks for the best Chrome extensions for holiday shopping coupons.
Rakuten

Read more
Half of Google Chrome extensions may be collecting your personal data
Google Chrome icon in mac dock.

Data risk management company Incogni has found that half of every installed Google Chrome extension has a high to very high risk of collecting personal data, showing a strong correlation to the number of permissions given.

After analyzing 1,237 Chrome extensions found in the Chrome Web Store, a study by Incogni has uncovered some troubling findings. Nearly half (48.7%) of the extensions were found to potentially expose users' personally identifiable information (PII), distribute malware and adware, and record passwords and financial information.

Read more
This Chrome extension lets hackers remotely seize your PC
A depiction of a hacker breaking into a system via the use of code.

Malicious extensions on Google Chrome are being used by hackers remotely in an effort to steal sensitive information.

As reported by Bleeping Computer, a new Chrome browser botnet titled 'Cloud9' is also capable of logging keystrokes, as well as distributing ads and malicious code.

Read more