Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> In order to access the proxy a user must be logged in to Chrome. To prevent abuse a Google run authentication server will grant access tokens to the Google run proxy based on a per-user quota.

How does this protect user privacy, overall?



Presumably it uses a blinded token system rather than sending your google id. The token system ensures that each user can't go over their quota, because google will only sign a certain amount of tokens per user, but the proxy server doesn't know the identity of the user because all they get is a blinded token.


That seems indeed very likely, given that it's what Google is already doing for their VPN: https://one.google.com/about/vpn/howitworks

A proxy (i.e. the same approach Apple uses for iCloud Private Relay) would be much better, though since their VPN seems to be using a single, fairly static IPv6 address per user and connection, which allows trivial cross-site tracking of a given user.


It protects user privacy from being violated by Google's competitors.

I think it would be more useful if Google contributed nodes to Tor rather than creating their own (confusingly) centralised, decentralised alternative.


Absolutely not. Tor is chock full of stuff I don’t want to be associated with from spam to worse. Where possible you can block tor traffic, abuse management on tor is pitiful


Couple of things:

- If Tor was 'easier' for the end-user or better supported by the centralised pillars of the Internet (such as Google), maybe "spam or worse" traffic would be made a much smaller percentage and improve Tor's reputation

- Does this mean different scales of anonymity/privacy? Tor for the "spam or worse", and this solution of Google's for the casual, not-quite-as-paranoid, private individual?

P.S. You're absolutely right in your paranoia regarding "I don’t want to be associated with". I've had a member of law enforcement accuse me of, basically, being worthy of suspicion (up to and including legal violation of my rights), because I've "got tor on my computer" (yes, that's their level of understanding). They also said that running Virtual Machines and downloading things from Mega will also get you put on a list.

I'd rather Google assist to improve Tor (and it's associated reputation) than "create my own amusement park with blackjack and hookers". In this case, I think one big pool is better than numerous small ones.

P.S. Mega seems to host a number of Android ROMs, which is my primary, and possibly singular, use case.


You should see the things available on muggle internet, it's horrifying!


Maybe some people want to hide their web traffic from their ISP, but can't be bothered with setting up a real VPN. It seems pretty niche, though.

Perhaps there's a business use for this?

There was an Android-only data saver mode, but it was discontinued [1].

[1] https://support.google.com/chrome/thread/151853370?sjid=4132...


A "real" VPN is actually a pretty poor way to increase privacy when browsing the web. It essentially just swaps out the (often moderately trustworthy) ISP with an often even more dubious VPN provider.

MASQUE (which iCloud Private Relay already uses, and Google could use too) can do significantly better.

Of course, having a choice of more MASQUE providers than just Apple and Google is important.


Maybe like buying a drink ticket on credit card, but then the ticket isn't tied to identity when you buy a beer at the festival.

Authenticated, but not identified, by the end-provider.


Users choose who to be their vpn. The same goes for if they want to enable this feature.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: