Google docs infects html exports with google tracking redirects.

@Joe_0237 wrote:

Today I found out that google docs infects html exports with spyware, no scripts, but links in your document are replaced with invisible google tracking redirects. I was using their software because a friend wanted me to work with him on a google doc, he is a pretty big fan of their software, but we were both somehow absolutely shocked that they would go that far.

library_napper,
@library_napper@monyet.cc avatar

Google would argue that this is a security feature.

Many business intentionally do this in google hosted email. It allows google to display warmings about links to malicious websites

BakedGoods,

There’s a reason both Google and Microsoft have been hirering from India lately. No competent person would work for them.

Sotuanduso,

I was skeptical about this, but yeah, I tested it, and can confirm.

Shaul,

How are people surprised? How is this news?

The second you mentioned Google you’re talking about an all-seeing totalitarian state. Nothing you said about imbedding tracking links in docs is surprised. As a corporation they are always developing new ways to pimp you out and make you turn tricks for Google without you knowing while they keep all of the pay from your actiities.

Google tries to turn every human on the planent into their personal money making whore.

ubermeisters,

you absolute fucking nincompoop! You’ve never fully fleshed out every single possible vector that Google could use to track and catalog you? Moron!!

-You, just now

01189998819991197253,
@01189998819991197253@infosec.pub avatar

nincompoop

Now there’s a term I haven’t heard in a hot minute haha

insomniac,
@insomniac@sh.itjust.works avatar

Of course it’s not at all surprising but it’s still particularly egregious and should be called out.

FeelzGoodMan420,

Can someone eli5 this please? What’s going on here?

Sotuanduso,

I have a Google Doc that’s a statblock for an RPG. It has a link to the mage armor spell, which goes directly to www.d20pfsrd.com/magic/all-spells/m/mage-armor/.

I just downloaded that statblock as an html. Then I opened that html file. The statblock is there and it all looks pretty much the same.

But then I hover over the mage armor link and it instead goes to www.google.com/url?q=https://www.d20pfsrd.com/mag….

This page immediately redirects to the proper destination in a fraction of a second. Blink and you’ll miss it. However, it does allow Google to track that I clicked the link, and probably associate it back to me and/or the original document.

FeelzGoodMan420,

Thanks. Got it. Could a pihole potentially block this?

Edit: nvm then you just simply couldn’t open the links.

Sotuanduso,

It’s probably easy enough to write a script that will go through the generated HTML and just scrub out the Google.

shrugal,

Afaik there are browser extensions that find and replace these kinds of tracking links with the original ones.

FeelzGoodMan420,

Oh, right. Like clearURL and certain ublock origin lists?

someguy3,

So if there’s only a few links, you could manually replace them?

Sotuanduso,

Yes. You could probably also write a simple script that scrubs the Googles out.

ReversedCookie,

I tried it myself… it’s just shocking of Google secretly rewrites your links. Scary.

Anticorp,

It’s not that shocking. Spyware companies have been doing this stuff since the 90’s, and Google is basically just a really rich spyware company now.

_cnt0,

They’ve been doing the same with all hyperlinks in the gmail web frontend. Not when you fetch the mails via imap/pop, though.

Joe_0237,
@Joe_0237@fosstodon.org avatar

@tavu my post is also here on mastodon https://fosstodon.org/

tavu,

Hi! I’m over here on lemmy, and created this post as a link to your post. I don’t think there’s a mutually compatible way to repost/boost a mastodon post into a lemmy community, but this seemed close enough.

IWantToFuckSpez,

Write your own exporter in Apps Script if you have to keep using Google workspace

Joe_0237, (edited )
@Joe_0237@fosstodon.org avatar

@IWantToFuckSpez @tavu another option would be to parse the file and urls and remove the trackers from the normal export. Or to do it by hand if you don't to it much.

itwasawednesday,
@itwasawednesday@lemmy.world avatar

What’s layman words for this please?

Sotuanduso,

Google has a thing called Apps Script that lets you write code to run on documents. You could write one that creates an HTML file from your doc without including Google’s redirects.

ubermeisters,

Maybe I’ll just fire up Frontpage instead lmao

mspencer712,

Are there any beneficial side effects? If they discover a URL is malicious after it’s been exported, would this allow them to intercept the click and stop someone from reaching the malicious site?

d0ntpan1c,

That’s how Microsoft markets their “safe links” in Outlook, which is more or less the same behavior of wrapping all links with a redirect. Whether they actually do anything with that to save you from phishing attempts or whatever… who knows. Even if there is a safety feature, it’s still an easy way to mine url query params for data or learn about the user for other purposes (which they may or may not be doing)

IMO if you can’t turn it off, there’s a secondary motive to the feature. Especially when the feature is marketed from a place of fear rather than aid.

foksmash,

The MS security feature does work quite well (at least for Enterprise).

01189998819991197253,
@01189998819991197253@infosec.pub avatar

I’m not sure I would categorize it as working “quite well”. At least not in my experience. It’s better than nothing.

foksmash,

Ya, I would tend to agree and left out the context. It’s not our only URL filtering tool, we have a full proxy and URL rewrite in email for that but it does help fill in gaps when people click links from devices we don’t manage.

Linus_Torvalds,

While I would be sceptical that this is the main reason, this might be a valid argument. Google can track users and protect the stupid users at the same time, who otherwise would endanger the public image of Google Docs(‘i GoT sCaMmEd oN gOoGlE dOcS’)

p_consti,

It’s the same thing in emails, if you use the web application. All links are redirect links over their servers.

NabeGewell,
@NabeGewell@lemmy.world avatar

Id say this is a new low, but they might have gone even lower already

LilDestructiveSheep,
@LilDestructiveSheep@lemmy.world avatar

Definitely gone lower.

ubermeisters,

See also: the entire chrome browser clusterfuck

guckfoogle,

Literally went from being my favorite company to just an unethical bag of poo for me. Hope whoever’s forcing these engineers to create privacy invading spyware eats a bag of dicks.

Anticorp,

Same, dude… same.

nik282000,
@nik282000@lemmy.ca avatar

Having 1gb of mail storage in 2004 was epic, having a 25gb profile in 2023 that I can never see is less so.

NocturnalMorning,

Google also replaces your Google searches with different searches behind the scenes to things they can make money off kf. Found that out the other day, and switched to duckduckgo instead. Google has become a Spyware nightmare.

Heresy_generator,
Heresy_generator avatar

If anyone isn't familiar with this here's the Wired article

Here’s how it works. Say you search for “children’s clothing.” Google converts it, without your knowledge, to a search for “NIKOLAI-brand kidswear,” making a behind-the-scenes substitution of your actual query with a different query that just happens to generate more money for the company, and will generate results you weren’t searching for at all. It’s not possible for you to opt out of the substitution. If you don’t get the results you want, and you try to refine your query, you are wasting your time. This is a twisted shopping mall you can’t escape.

Why would Google want to do this? First, the generated results to the latter query are more likely to be shopping-oriented, triggering your subsequent behavior much like the candy display at a grocery store’s checkout. Second, that latter query will automatically generate the keyword ads placed on the search engine results page by stores like TJ Maxx, which pay Google every time you click on them. In short, it's a guaranteed way to line Google’s pockets.

It’s also a guaranteed way to harm everyone except Google. This system reduces search engine quality for users and drives up advertiser expenses. Google can get away with it because these manipulations are imperceptible to the user and advertiser, and the company has effectively captured more than 90 percent market share.

It’s unclear how often, or for how long, Google has been doing this, but the machination is clever and ambitious. I have spent decades looking for examples of Google putting its enormous thumb on the scale to censor or amplify certain results, and it hadn’t even occurred to me that Google just flat out deletes queries and replaces them with ones that monetize better.

fuzzzerd,

Article removed because it doesn’t meet their editorial standards.

NocturnalMorning,

I figured this out when I searched for my gaming web page on itch.io, and it wouldn’t come up. But then I went to duckduckgo and did the search, and every game I’ve made was in the search result. Pretty scummy if you ask me. Needless to say I changed all my browsers to duckduckgo instead of google.

CrypticCoffee,

By browsers do you mean search engines in the browsers? I use DDG for search. Firefox is king, browsers wise.

CherenkovBlue, (edited )
@CherenkovBlue@iusearchlinux.fyi avatar

I thought DDG was some kind of front end for Google search. How wrong am I, and if I’m right, does this mean it’s the Google search in, e.g., Chrome browser that’s doing this? Otherwise how would DDG be avoiding it?

ebits21,
@ebits21@lemmy.ca avatar

I thought it was Bing? I’m not sure lol. I’ve noticed the drop in Google searches quality lately and switched to DDG.

Seems much better now imo.

CherenkovBlue,
@CherenkovBlue@iusearchlinux.fyi avatar

I could be completely wrong, may the gods of the Internet forgive me.

nixchick,
@nixchick@lemmy.ml avatar

You are correct. Bing.

NocturnalMorning,

Yes, I meant search engine. I also use Firefox as well :)

somePotato,

Everytime I try to google anything that might be remotely related to a product every result will be a store.

I’d never have assumed that they just replaced my query but in hindsight it’s kinda obvious

CherenkovBlue,
@CherenkovBlue@iusearchlinux.fyi avatar

Yeah I noticed they got very shopping oriented in the last year or so, but I didn’t anticipate this. Yikes.

WarmSoda,

That’s clever as fuck. And ridiculous. And crazy evil.

Anticorp,

It’s not that clever.

WarmSoda,

Is that why no one figured out out until now?

Anticorp,

We’ve suspected they were ignoring our terms for years now, and had hard proof they were ignoring our search operators. There are hundreds of Reddit threads discussing it. But people noticing or not isn’t what would make it clever. Some bullshit executive suggesting they serve whatever is most profitable doesn’t seem clever to me, it seems greedy, hostile, and short sighted. What would be really clever is figuring out how to still give people what they’re looking for, and still increase their income.

Atemu,
@Atemu@lemmy.ml avatar

Wow, that’s peak enshittification.

wild,

How did they uncover and confirm this?

online,

The information provided in the public hearings.

Anticorp,

Google can get away with it because these manipulations are imperceptible to the user

Dude, it’s blatantly obvious to the user. Idk why they think they’re being clever, but when I search for “Pioneer SC71 user manual” (a home theater amp), and all it shows me are cheap car stereos listings from Walmart and Amazon (with affiliate tracking of course), I know they’re not showing me what I’m looking for. It’s a worthless service for anything except products and heavily filtered news (they only show what aligns with their agenda). I went from totally loving Google, to not when using them anymore. They’re a disease.

Anticorp,

That’s really obvious based on how fucking terrible their results are now. Google was the most useful tool in the world for a long time. Now they’re just a really rich spyware farm.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • privacy@lemmy.ml
  • GTA5RPClips
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • osvaldo12
  • ethstaker
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • ngwrru68w68
  • kavyap
  • normalnudes
  • cisconetworking
  • JUstTest
  • InstantRegret
  • khanakhh
  • cubers
  • everett
  • Durango
  • tacticalgear
  • anitta
  • modclub
  • Leos
  • tester
  • provamag3
  • megavids
  • lostlight
  • All magazines