Google's Plan to Protect Users from IP Tracking and Why You Should Be Concerned

· 3 min read
Google's Plan to Protect Users from IP Tracking and Why You Should Be Concerned

Google recently announced plans to incorporate their own IP protection feature into Chrome by default in future releases. This IP protection will work by routing users' traffic through Google-run privacy proxies. On the surface, Google claims this is to protect users' privacy by hiding their IP addresses and preventing them from being tracked across websites. However, some have expressed valid concerns about Google essentially inserting themselves as the middleman for all Chrome users' web traffic.

What are Proxies, and how do they work?

A proxy is a server that sits between a user's device and the websites they are visiting. All web traffic passes through the proxy server first before reaching its final destination.

When a user makes a request to a website without a proxy, the website can see the user's actual IP address. This IP address can potentially be used to track a user across different sites over time. It allows websites to build a "unique, persistent user profile" of someone's online habits and behaviors.

A proxy aims to prevent this type of tracking by hiding a user's true IP address. Instead of the website seeing the actual client IP, it only sees the IP address of the proxy server. This obscures the unique digital fingerprint that IP addresses provide and makes it more difficult to tie a user's activities together across multiple sites.

Proxies are commonly used by individuals, organizations and even entire countries to achieve greater anonymity and privacy online. They're also useful for bypassing geo-restrictions so you can access location-specific content from anywhere. Google's goal with its built-in "IP Protection" proxy is to add this level of privacy for Chrome users by default.

Proxies are not to be confused with VPNs. There are a few key differences between proxies and VPNs (Virtual Private Networks). VPNs encrypt all your web traffic into an encrypted "tunnel" between your device and the VPN server. Proxies on the other hand forward traffic without encrypting it.

Google's Privacy Proxy Proposal

On the surface, Google claims this is to protect users from cross-site tracking via their IP addresses. According to their documentation, an IP can be used over time to build unique profiles of users and track them persistently across the web.

Currently, in Chrome, there is no way for users to opt-out of this kind of covert IP tracking. So Google proposes introducing privacy proxies to hide users' true IP addresses when surfing. They aim to fulfill two main goals - improve privacy and minimize disruption to normal server operations/anti-abuse protections.

To accomplish this, Google's initial plan involves running their own privacy proxy that all Chrome traffic would be routed through. There are plans of using a second proxy hop run by an external CDN for improved privacy, while Google handles the first hop. On paper, this two-hop approach does seem to strengthen privacy by preventing either proxy from seeing both the client IP and destination.

Why Should You Be Concerned?

There are major concerns with Google essentially inserting themselves as the gatekeeper for all Chrome users' web access:

  • Single point of failure - If Google's proxy servers were ever compromised or taken offline (e.g. via a DDoS attack), it could significantly impact internet stability and accessibility for many users.
  • Privacy risks and data collection risks: While Google claims the proxy can't correlate traffic to users, their business model depends on data collection. Having a direct line to all traffic raises privacy concerns. Even with encryption, they could profile behavior.
  • Disruption of existing defenses - Rerouting all traffic uniquely through Google's proxies could undermine current protocols for detecting malicious traffic and online attacks. Mass data collection by one company concentrates power and control.
  • Circumvention of content controls - Unlike independent proxies, Google may be legally compelled to restrict access to content based on geo-IPs to comply with local laws in each country/region.
  • Technical concerns: Google will need to balance privacy, abuse prevention and legal obligations - all while maintaining performance and reliability at global scale. This brings considerable technical challenges.

Making an Informed Choice

As with any new privacy-related feature, it's important users carefully consider Google's proposed built-in proxy solution with open and skeptical minds. While the stated goals seem well-intentioned, the company's broader interests merit valid concern about the centralization of network infrastructure and risks to user data.

An open internet relies on decentralization, transparency, choice and user control. By boosting your own online privacy knowledge and defenses, you uphold these principles even as major platforms evolve their approaches. An aware and empowered public remains the best guardian of online civil liberties for all.

Setting Up Your Own Personal Proxies

The best way to gain the privacy benefits of proxies without relying on Google is to set up your own personal proxy servers. You can follow NetworkChuck's video for a step-by-step guide.