7 ms·
Google Chrome browser privacy plan investigated in UK
- Tepix 6y agoThe article says: [Google] wants to replace [3rd party cookies] with new tools that give advertisers more limited, anonymised information such as how many users visited a promoted product's page after seeing a relevant ad - but not tie this information to individual users. Here's the Chromium page about the "Privacy Sandbox": https://www.chromium.org/Home/chromium-privacy/privacy-sandbox https://www.chromium.org/Home/chromium-privacy/privacy-sandb... Quote: We believe ... the web’s users can access that information freely because the content creators can fund themselves through online advertising. That advertising is vastly more valuable to publishers and advertisers and more engaging and less annoying to users when it is relevant to the user. In other words, they still want to know as much as possible about the users.
- gregasquith 6y agoThere are various proposals they are working under the umbrella of the Privacy Sandbox project, couple of key ones here: https://github.com/google/ads-privacy/tree/master/proposals/dovekey https://github.com/google/ads-privacy/tree/master/proposals/... https://github.com/WICG/turtledove https://github.com/WICG/turtledove
- philliphaydon 6y agoIt sounds like a good thing but I just can’t trust Google to not be evil and give themselves more of a monopoly. They prob want to replace cookies with something that gives them the same functionality but not have to deal with cookie policies in the EU.
- capableweb 6y agoGoogle for some owns the full pipeline of websites, from where the website is being served from (Google AMP), scripts where the website does client side stuff (Tag Manager + Analytics), to the browser that reads it (Google Chrome / Chromium) and in some cases even the OS (Chrome OS). Is not hard to imagine that they are getting rid of Cookies because they now have other ways of getting the data, and getting rid of Cookies would make things harder for competitors that don't own the full pipeline. Even with that, I'm sure that the engineers working on Chromium/Google Chrome are being told that they are removing Cookies for the greater good and don't have insights into the longer pipeline that we're now seeing the middle off.
- vermilingua 6y agoDon’t forget, they often control the domain registration, have had huge influence in the formation of the languages sites are written in, in some cases the languages the server is written in, even the backbone and last mile delivery of those bits to the user, etc. Most of that can be leveraged by google to replace cookies.
- gnud 6y agoWell, the cookie policies in the EU are sort of weird, but they're not from the GDPR, but from an older directive, 2009/136/EC, the "cookie law". And this directive only uses the word once, in the parenthetical "(such as certain types of cookies)". Even if you replace cookies with something else (localstorage or whatever), you're still on the hook for all the rules both here and in the GDPR with regards to personal information and informed consent. Remember that the 'cookie law' says > Exceptions to the obligationto provide information and offer the right to refuse should be limited to those situations where the technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user. So you don't need a cookie banner for a login session cookie, or a cookie that stores preferences the user actively selected. But you _do_ need a cookie banner, and a way to opt out, for all kinds of user tracking, both first- and third-party. Of course, IANAL. Just angry at advertisers for muddying up this issue.
- raxxorrax 6y agoI often hear that but I don't think this is good at all. To be honest I am not subjected to a lot of ads today, but I don't want personalized ads because it always means the advertiser has incentive to collect info on me. Ads aren't worth that, not even close. You might think otherwise, but for these cases I think there should be opt-in mechanisms instead of the assumption what people want. If they are that off with their ads...
- pdpi 6y agoThere are no cookie policies in the EU. What we do have is a policy around personal data and identifying users, and cookies are mentioned in passing as a particular way this is achieved in practice.
- lmkg 6y agoThere are cookie policies in the EU. GDPR covers personal data, of which cookies can be one particular way. The ePrivacy Directive is a separate law, modified but not repealed by GDPR, which addresses cookie data. The difference and interaction between those two laws ends up being extremely significant.
- pdpi 6y agoEvery single instance of the word "cookie" in the ePrivacy Directive[1] is qualified with either a "for instance" or with "or similar devices". 1. https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32002L0058&from=EN https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE...
- lmkg 6y agoMy point is that cookies have additional regulations beyond just being personal data covered by GDPR. You are correct that cookie-equivalents are similarly regulated (including most fingerprinting techniques!). But they're not just a special case of GDPR. Most importantly, the ePD applies to cookies even when they are not personal data. Your post made it sound like the only concern is identifying users via cookies. That is not the case. Non-identifying cookies would not incur obligations under GDPR, but they do incur obligations under the ePD.
- lmkg 6y agoThis isn't exactly a mystery. Google is doing this. Several of the pieces are already in place. If you log into a Google account in Chrome, you log into Chrome itself with that Google account. Then Google tools can use your account as an identity signal. This is already available as a feature in Google Ads and Google Analytics. The name of the feature is "Google Signals" - they've posted documentation on how it works and what it does. This identity signal works cross-domain and cross-device. Google is working to kill off other identity signals with those capabilities that would be available to competitors, such as third-party cookies. (This is also why I believe them when they say they're actively working against browser fingerprinting.)
- zaroth 6y agoThis is a very good reason in and of itself to stop using Chrome. What you're describing is a very real attack by Google through a kind of regulatory capture on any possible competitor. Basically, the only tracking solution that becomes viable is their own.
- HPsquared 6y agoIf they become a monopoly by simply providing the best service available, who is harmed? To me it looks like "won't someone please think of the poor advertisers"
- thewebcount 6y agoAnyone who wants to avoid their services. I don't care if they provide a better experience on the web. I don't wish to do business with them because I don't trust them. No matter how good their experience, I want to use someone else.
- Lio 6y agoThere seems to be a real conflict in interests between Google, effectively a surveillance company, setting new standards for user privacy. It's not the targetted advertising I object to it's the tracking. I don't want Google to solely access to all my personal data which they then use to provide anonymised information to others. I want to have enough control to stop Google tracking me in the first place rather than anonymising things after the fact. Something like Brave's approach to BATs is what I'd like to see them adopt.
- arexxbifs 6y agoThat part is just smoke and mirrors, of course. They don't give a crap about that and "privacy" is becoming yet another marketing buzzword that rarely stands up to scrutiny but is very convenient to hit your opponents over the head with. Google just wants a monopoly on advertising.
- kyrra 6y agoGoogler opinions are my own. I'd disagree. There is a trend in HN comments to remind people that a company is a collection of people. Google is a collection of people. There are those of us who care deeply about privacy at Google. First: it's interesting talking with googlers or reading their thoughts on how Google does ads and data collection. Many people definitely feel the same way as commenters on HN feel. Lots of people are torn on the fact that ads lets us build lots of other cool products for people. I would say this helps motivate other teams, like cloud, do you find other revenue sources for the company so you don't have to be as dated collection focused. Second: I have seen googlers fight the privacy of users even within my division (payments). Many of us want to do right by our users, and be as privacy focused as we are capable given our constraints. We also know there is a general thought that Google is data collection focused, and one slip up will cause a big drama out on the internet and in the news (Google would likely receive more scrutiny here than some other companies). This helps remind us that we need to treat user data as best we can and minimize what we do collect.
- CivBase 6y ago
- blindm 6y agoThe thing about Cookie-law and cookie privacy issues is: it assumes everyone has this centralized browsing session that they use for /all/ their browsing. There would be a good number of people who use incognito mode or private browsing mode. I don't know the stats, but I imagine a good chunk of people use incognito mode for NSFW surfing sessions. And whilst cookie banners are annoying, they are a small price to pay if it means you have the choice to wipe cookies after a browsing session. For me personally I use different browsers for different things, and if I don't want to be tracked and have browsing artifacts like cookies correlating data together and tracking me, I just go incognito and call it a day. Google's attempt to re-design how browsers work at this fundamental level is welcomed, but that means other browsers have to do the same, which I don't see happening. Firefox rarely copies Chrome features (or Chrome's anti-features).
- inops 6y ago>Firefox rarely copies Chrome features (or Chrome's anti-features). In so far as web technology goes, it certainly does. Lots of half-baked, non-standard features get added to Chrome, sites start using them, and then Mozilla has to follow suit in order to maintain web compatibility.
- azalemeth 6y agoI use incognito mode _almost exclusively_ for SFW content. Heck, I use at least five browsers, container tabs, private modes, etc, and have rotating external IP endpoints as well as using Duck Duck Go. I have a pihole, and OS level application firewalls. I've got a PhD and I find the lengths required to have some modicum of privacy on the internet truly insane, and at times, a little technologically annoying (especially when you have to debug which random script broke a particular page). The other trouble is of course apps: android is just a _dumpster fire_ and every MS product causes an awful lot of blocklist entries to mobile.pipe.aria.microsoft.com. _Something_ new would be nice, but I fundamentally think that Google is the most conflicted company possible to deliver it.
- toper-centage 6y agoAs a user of tab containers and cookie auto deletion, cookie notices and sign up prompts are the bane of my existance. I audibly growl each time I open YouTube.
- cm2187 6y agoDo you need to ban third party cookies? I would have thought that limiting the scope of third party cookies to the primary site visited would be sufficient to prevent tracking across websites (save for browser fingerprinting).
- iamacyborg 6y agoThird party cookies are often made first party through CNAME records, so those are problematic, too.
- ejj28 6y agoI'm very skeptical about this, as it seems like Google's just trying to pull another AMP and take control of how advertisers are able to advertise, and since they're a major player in the ad business that should be a big no no. No user-agent strings is interesting to me, to me they seem like a minor concern privacy-wise, and doesn't a large portion of the web use them to maintain compatibility between browsers, detect your OS for downloads, and etc?
- nebulous1 6y agoYou may find this interesting: https://amiunique.org/ https://amiunique.org/
- roblabla 6y agoUser-agent, in my experience, is mostly misused as an attempt for compatibility, but it really shouldn't be used that way. The proper way to do cross-browser compat is feature testing, as browsers keep adding more features. Google until recently was distributing a different, inferior (at least IMO) version of Google Search to Android Firefox users, based on user-agent. To detect the OS for download, either JS will have to be used, or the new granular Client Hints[0], specifically User-Agent Client Hints[1]. You can use Sec-CH-UA-Platform and Sec-CH-UA-Arch to figure out the OS and CPU Architecture of the client. However, browsers may refuse to honor this, depending on the privacy budget. Seeing User-Agent go away will be a net positive for web compatibility. That it also improves privacy is just a nice-to-have. [0]: https://developer.mozilla.org/en-US/docs/Glossary/Client_hints https://developer.mozilla.org/en-US/docs/Glossary/Client_hin... [1]: https://wicg.github.io/ua-client-hints/ https://wicg.github.io/ua-client-hints/
- afrcnc 6y agoAm I the only one reading this as "some less tech-savvy advertisers can't adapt and are now lawyering their way around?" Cause it sure looks like so. If I remember correctly, other browsers have also removed support for 3rd party cookies too
- gregasquith 6y agoA lot of advertisers didn't care when Safari etc. did it, such is the scale Chrome has - they just stopped targeting users not using Chrome. Now it's affecting everyone there's an outcry
- afrcnc 6y ago"affecting" isn't the word I'd use there. "protecting" would be better
- gregasquith 6y ago100% agreed!
- toper-centage 6y agoI couldn't care less in the adtech industry collapsed overnight, even if that meant I lose my job, but what's happening with Google and Facebook trying to push for privacy regulations is effectively raising the bar for competition and new comers.
- drawfloat 6y agoSort of. The investigation is because there may well be a competition issue here, where Google is leveraging its dominant position in browser to the benefit of its ad business, removing the ability for its competitors to compete. Google identifies users using Chrome via other means than cookies (Google Signal etc) in a way that no other competitor can or is able to access, and therefore is now pushing to remove the ability for anyone else to do it who doesn't control the browser. Guarantee you if Google was forced to stop sharing data from its browser business to its ad business, it would not be pushing to remove cookies. Edit: One final note is that it's a shame because there really is an opportunity to create a new alternative to cookies, better suited to the risks posed by modern tracking methods. But Google leading the charge to dictate how you can be tracked should be a huge red flag for you.
- acvny 6y agoThese sentences summarise it all: "Google will effectively control how websites can monetise and operate their business," "This means that any business that buys or sells advertising will be reliant on Google for a part of the process, whether they like it or not."
- trendywebz9 6y ago100% agreed.
- ScoopWitch 6y agoagree at the point it seems like marketing monopoly
- pixelpoet 6y agoI very much wish someone would investigate this "legitimate interest" crap that I have to always turn off now (one by one usually). Find me just one person who is legimitately interested in these "legitimate interest" tracking things.
- hardlianotion 6y agoI occasionally read these, but I am still not clear in what the difference between these permissions I am about to deny and the others.
- Digit-Al 6y agoUgh. Tell me about it. I tried reading the GDPR stuff regarding legitimate interest but couldn't work out how it was relevant to what they are doing. It appears to be just two different switches for the same thing with one switch defaulting to off and the other to on. At least a lot of places do allow you to "object all", but it's just another thing you have to remember to select. Super annoying!
- potench 6y agoI didn’t see it mentioned but a common use case for 3rd party cookies is correlating session data across your own multiple domains (if your company owns multiple domains). Publishing companies typically own multiple domains/verticals and can increase ad revenue / seo / traffic quality by linking properties together. It’s important to be niche as a site (verticalization) but also broad as a publishing operation (own many verticals and shift your marketing spend daily). Anyways, google has been writing a spec for “first party sets” to help replace the use of a 3rd party cookie to connect domains you own. https://github.com/privacycg/first-party-sets https://github.com/privacycg/first-party-sets I believe this will need to be implemented before Chrome moves aggressively against 3rd party cookies.
- cookiengineer 6y agoRemember the discussion about Manifest V3, eliminating webRequest API [1] which results in Adblockers being thrown out of the Chrome ecosystem? Guess what the state is, now, 1 year later ... the declarativeWebRequest API is still on hold; and it's not supported outside of Beta Channel, and there are no plans to move it to stable. [2] Its documentation still states the same as it did half a year ago: "Note: this API is currently on hold, without concrete plans to move to stable. Use the chrome.declarativeWebRequest API to intercept, block, or modify requests in-flight." ... which effectively means that there's no way to block or modify request/response headers in Manifest V3, which is essential for Adblockers because they tend to override the Content-Security-Policy and remove headers like "Cookie" or "Set-Cookie" etc. And now we have the Chrome Web Store moving ahead with the Manifest V3 rollout. [3] [1] https://developer.chrome.com/docs/extensions/reference/webRequest/ https://developer.chrome.com/docs/extensions/reference/webRe... [2] https://developer.chrome.com/docs/extensions/reference/declarativeWebRequest https://developer.chrome.com/docs/extensions/reference/decla... [3] https://blog.chromium.org/2020/12/manifest-v3-now-available-on-m88-beta.html https://blog.chromium.org/2020/12/manifest-v3-now-available-...
- lima 6y ago> Remember the discussion about Manifest V3, eliminating webRequest API [1] which results in Adblockers being thrown out of the Chrome ecosystem? The whole point of declarativeNetRequest is to make it safer and faster to use adblockers. The tradeoff is fewer rules and less expressivity. As someone who couldn't live without an adblocker, I appreciate it and look forward to it because it removes a massive security risk (image the carnage if one of the major adblocker extensions get compromised). Your citations do not support the claim that "It's only a matter of months before Adblockers won't work anymore.". There's plenty of reasons to not like Chrome, but this is not a justification for spreading FUD. In fact, the very blog post you cite states that "There is not an exact date for removing support for Manifest V2 extensions" and has a quote from the Adblock Plus team, praising the collaboration with Chromium.
- cookiengineer 6y ago> Your citations do not support the claim that "It's only a matter of months before Adblockers won't work anymore.". Yes, I agree. I removed that part of my statement. Still, the declarativeWebRequest API does not allow to filter out tracking-related headers from incoming responses or sent requests. I mean, you cannot declare the rules via the RequestMatcher and know what headers are going to be sent or received in advance, as the API expects full declaration of all protocol schemes and host suffixes; which is very bad if a website can pretty much do whatever it wants when it executes js code. > In fact, the very blog post you cite states that "There is not an exact date for removing support for Manifest V2 extensions" and has a quote from the Adblock Plus team, praising the collaboration with Chromium. You know that eyeo GmbH were the ones with the "Acceptable Ads" initiative that are literally forcing websites to pay them money so that their ads continue to work, right? Personally, I would take their comment with a grain of salt. For their whitelisting-ads use case the API works; for the use case of uBlock Origin et al - it doesn't.