Joe :fedora: :debian: :ferris: (@Joe_0237@fosstodon.org)
fosstodon.org
external-link
Today I found out that google docs infects html exports with spyware, no scripts, but links in your document are replaced with invisible google tracking redirects. I was using their software because a friend wanted me to work with him on a google doc, he is a pretty big fan of their software, but we were both somehow absolutely shocked that they would go that far.

@Joe_0237@fosstodon.org wrote:

Today I found out that google docs infects html exports with spyware, no scripts, but links in your document are replaced with invisible google tracking redirects. I was using their software because a friend wanted me to work with him on a google doc, he is a pretty big fan of their software, but we were both somehow absolutely shocked that they would go that far.

Google would argue that this is a security feature.

Many business intentionally do this in google hosted email. It allows google to display warmings about links to malicious websites

removed by mod

I was skeptical about this, but yeah, I tested it, and can confirm.

Sha'ul
link
fedilink
107M

How are people surprised? How is this news?

The second you mentioned Google you’re talking about an all-seeing totalitarian state. Nothing you said about imbedding tracking links in docs is surprised. As a corporation they are always developing new ways to pimp you out and make you turn tricks for Google without you knowing while they keep all of the pay from your actiities.

Google tries to turn every human on the planent into their personal money making whore.

you absolute fucking nincompoop! You’ve never fully fleshed out every single possible vector that Google could use to track and catalog you? Moron!!

-You, just now

nincompoop

Now there’s a term I haven’t heard in a hot minute haha

Of course it’s not at all surprising but it’s still particularly egregious and should be called out.

Can someone eli5 this please? What’s going on here?

I have a Google Doc that’s a statblock for an RPG. It has a link to the mage armor spell, which goes directly to https://www.d20pfsrd.com/magic/all-spells/m/mage-armor/.

I just downloaded that statblock as an html. Then I opened that html file. The statblock is there and it all looks pretty much the same.

But then I hover over the mage armor link and it instead goes to https://www.google.com/url?q=https://www.d20pfsrd.com/magic/all-spells/m/mage-armor/&sa=D&source=editors&ust=1696552528610887&usg=AOvVaw1Wgq9wmajthwTbYmk1EmHx.

This page immediately redirects to the proper destination in a fraction of a second. Blink and you’ll miss it. However, it does allow Google to track that I clicked the link, and probably associate it back to me and/or the original document.

So if there’s only a few links, you could manually replace them?

Yes. You could probably also write a simple script that scrubs the Googles out.

Thanks. Got it. Could a pihole potentially block this?

Edit: nvm then you just simply couldn’t open the links.

Afaik there are browser extensions that find and replace these kinds of tracking links with the original ones.

Oh, right. Like clearURL and certain ublock origin lists?

It’s probably easy enough to write a script that will go through the generated HTML and just scrub out the Google.

deleted by creator

It’s not that shocking. Spyware companies have been doing this stuff since the 90’s, and Google is basically just a really rich spyware company now.

They’ve been doing the same with all hyperlinks in the gmail web frontend. Not when you fetch the mails via imap/pop, though.

@tavu@sopuli.xyz
creator
link
fedilink
27M

Hi! I’m over here on lemmy, and created this post as a link to your post. I don’t think there’s a mutually compatible way to repost/boost a mastodon post into a lemmy community, but this seemed close enough.

Write your own exporter in Apps Script if you have to keep using Google workspace

What’s layman words for this please?

Google has a thing called Apps Script that lets you write code to run on documents. You could write one that creates an HTML file from your doc without including Google’s redirects.

Maybe I’ll just fire up Frontpage instead lmao

@IWantToFuckSpez @tavu another option would be to parse the file and urls and remove the trackers from the formal export. Or to do it by hand if you don’t to it much.

Are there any beneficial side effects? If they discover a URL is malicious after it’s been exported, would this allow them to intercept the click and stop someone from reaching the malicious site?

That’s how Microsoft markets their “safe links” in Outlook, which is more or less the same behavior of wrapping all links with a redirect. Whether they actually do anything with that to save you from phishing attempts or whatever… who knows. Even if there is a safety feature, it’s still an easy way to mine url query params for data or learn about the user for other purposes (which they may or may not be doing)

IMO if you can’t turn it off, there’s a secondary motive to the feature. Especially when the feature is marketed from a place of fear rather than aid.

The MS security feature does work quite well (at least for Enterprise).

I’m not sure I would categorize it as working “quite well”. At least not in my experience. It’s better than nothing.

Ya, I would tend to agree and left out the context. It’s not our only URL filtering tool, we have a full proxy and URL rewrite in email for that but it does help fill in gaps when people click links from devices we don’t manage.

While I would be sceptical that this is the main reason, this might be a valid argument. Google can track users and protect the stupid users at the same time, who otherwise would endanger the public image of Google Docs(‘i GoT sCaMmEd oN gOoGlE dOcS’)

p_consti
link
fedilink
217M

It’s the same thing in emails, if you use the web application. All links are redirect links over their servers.

Id say this is a new low, but they might have gone even lower already

See also: the entire chrome browser clusterfuck

Definitely gone lower.

Literally went from being my favorite company to just an unethical bag of poo for me. Hope whoever’s forcing these engineers to create privacy invading spyware eats a bag of dicks.

deleted by creator

Nik282000
link
fedilink
167M

Having 1gb of mail storage in 2004 was epic, having a 25gb profile in 2023 that I can never see is less so.

Same, dude… same.

Google also replaces your Google searches with different searches behind the scenes to things they can make money off kf. Found that out the other day, and switched to duckduckgo instead. Google has become a Spyware nightmare.

That’s really obvious based on how fucking terrible their results are now. Google was the most useful tool in the world for a long time. Now they’re just a really rich spyware farm.

Heresy_generator
link
fedilink
104
edit-2
7M

If anyone isn’t familiar with this here’s the Wired article

Here’s how it works. Say you search for “children’s clothing.” Google converts it, without your knowledge, to a search for “NIKOLAI-brand kidswear,” making a behind-the-scenes substitution of your actual query with a different query that just happens to generate more money for the company, and will generate results you weren’t searching for at all. It’s not possible for you to opt out of the substitution. If you don’t get the results you want, and you try to refine your query, you are wasting your time. This is a twisted shopping mall you can’t escape.

Why would Google want to do this? First, the generated results to the latter query are more likely to be shopping-oriented, triggering your subsequent behavior much like the candy display at a grocery store’s checkout. Second, that latter query will automatically generate the keyword ads placed on the search engine results page by stores like TJ Maxx, which pay Google every time you click on them. In short, it’s a guaranteed way to line Google’s pockets.

It’s also a guaranteed way to harm everyone except Google. This system reduces search engine quality for users and drives up advertiser expenses. Google can get away with it because these manipulations are imperceptible to the user and advertiser, and the company has effectively captured more than 90 percent market share.

It’s unclear how often, or for how long, Google has been doing this, but the machination is clever and ambitious. I have spent decades looking for examples of Google putting its enormous thumb on the scale to censor or amplify certain results, and it hadn’t even occurred to me that Google just flat out deletes queries and replaces them with ones that monetize better.

Article removed because it doesn’t meet their editorial standards.

How did they uncover and confirm this?

The information provided in the public hearings.

Atemu
link
fedilink
67M

Wow, that’s peak enshittification.

Google can get away with it because these manipulations are imperceptible to the user

Dude, it’s blatantly obvious to the user. Idk why they think they’re being clever, but when I search for “Pioneer SC71 user manual” (a home theater amp), and all it shows me are cheap car stereos listings from Walmart and Amazon (with affiliate tracking of course), I know they’re not showing me what I’m looking for. It’s a worthless service for anything except products and heavily filtered news (they only show what aligns with their agenda). I went from totally loving Google, to not when using them anymore. They’re a disease.

That’s clever as fuck. And ridiculous. And crazy evil.

It’s not that clever.

Is that why no one figured out out until now?

We’ve suspected they were ignoring our terms for years now, and had hard proof they were ignoring our search operators. There are hundreds of Reddit threads discussing it. But people noticing or not isn’t what would make it clever. Some bullshit executive suggesting they serve whatever is most profitable doesn’t seem clever to me, it seems greedy, hostile, and short sighted. What would be really clever is figuring out how to still give people what they’re looking for, and still increase their income.

Everytime I try to google anything that might be remotely related to a product every result will be a store.

I’d never have assumed that they just replaced my query but in hindsight it’s kinda obvious

Yeah I noticed they got very shopping oriented in the last year or so, but I didn’t anticipate this. Yikes.

I figured this out when I searched for my gaming web page on itch.io, and it wouldn’t come up. But then I went to duckduckgo and did the search, and every game I’ve made was in the search result. Pretty scummy if you ask me. Needless to say I changed all my browsers to duckduckgo instead of google.

By browsers do you mean search engines in the browsers? I use DDG for search. Firefox is king, browsers wise.

Yes, I meant search engine. I also use Firefox as well :)

I thought DDG was some kind of front end for Google search. How wrong am I, and if I’m right, does this mean it’s the Google search in, e.g., Chrome browser that’s doing this? Otherwise how would DDG be avoiding it?

I thought it was Bing? I’m not sure lol. I’ve noticed the drop in Google searches quality lately and switched to DDG.

Seems much better now imo.

You are correct. Bing.

I could be completely wrong, may the gods of the Internet forgive me.

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 84 users / day
  • 537 users / week
  • 1.5K users / month
  • 6.58K users / 6 months
  • 1 subscriber
  • 2.31K Posts
  • 53.4K Comments
  • Modlog