23 ms·
Google has been testing a replacement for third-party cookies
- dessant 6y agoThis proposal coupled with phasing out third-party cookies inconveniences competitors, while allowing Google to continue gobbling up user data without disruption, because their tracking capabilities are way past needing any cookies, or this new cohort API.
- alisonkisk 6y agoThe article is about a non-tracking capability to collect less user data. Inconveniencing trackers is good for privacy, not bad. Anyway, mods, here's a much better article that has more than one line of vague content: https://github.com/WICG/floc https://github.com/WICG/floc
- dessant 6y agoGoogle only cares about privacy, when it disproportionately hurts the competition. Meanwhile they are using their leverage to infect web standards with a tracking proposal, and they market it as a privacy win. Features used exclusively for tracking have no place among web standards, cohort-based or otherwise.
- gnud 6y agoThis looks to me as a way for Google to drastically increase their reach and track even more data about their "users". They want the browser to "discover" the users interests automatically during browsing. For a page to be excluded from this, the page author would have to set a new policy header. And then your browser reports these interest to whatever tracker (for example Google) asks for the information. Suddently Google can learn about what you're browsing even if GA is blocked.
- tyingq 6y agoI think that's a good observation. That they don't need cookies or this proposal. So, anything that performs less well than cookies hurts them less than their competitors.
- dilap 6y ago"Serial killer may have found a life-friendly substitute to knives." No but seriously, does being in a group of "thousands" of people really preserve privacy particularly well? It seems quite likely that with groups that small, membership itself could be considered privacy-compromising, e.g., a group of people that all have some medical condition. At the most fundamental level, I feel like if you know which advertisments are targetted to me, and those advertisements are well-targeted, then my privacy has been invaded. It seems to me there is a fundamental conflict between good targetted ads and protection of privacy.
- f430 6y ago> The company said Monday that tests of FLoC to reach audiences show that advertisers can expect to see at least 95% of the conversions per dollar spent on ads when compared to cookie-based advertising. FLoC uses machine learning algorithms to analyze user data and then create a group of thousands of people based off of the sites that an individual visits. The data gathered locally from the browser is never shared. Instead, the data from the much wider cohort of thousands of people is shared, and that is then used to target ads. If I was an advertiser I would have serious doubts about this, especially after the fact that ad spend on popular platforms have had no impact on many firm's bottom line. I guess this is a response to all the pushbacks and dwindling PPC revenues from an increasingly wary advertisers who have quite possibly been duped into transferring their cash to Google & others over the decade.
- joshuamorton 6y agoWhat? No. It's a response to potential bans on same site cookie access. The thing you quote says that this is worse than conventional targeted ads.
- dataminded 6y agoGoogle isn't sharing your individual data but they are still collecting it and storing it. This feels like a non-improvement to me.
- ignoramous 6y ago
- PedroBatista 6y agoJust the same stairs but now with only one giant step and Google is the one with giant legs. Also there's no "privacy-friendly" tracking technology, it's an oxymoron an slick marketing/corporate strategy ( that works ).
- alisonkisk 6y agoRead this explainer: https://github.com/WICG/floc https://github.com/WICG/floc
- craftinator 6y ago"In a landmark decision, Google has decided to continue keeping the "Don't be evil" principal off of their Company Principles list"
- Medicineguy 6y agoThe problem is not the option to place cookies per se. The issue is its misuse which aims to de-anonymize users (in order to place ads). I don't see how saving the user data somewhere else (in a browser add-on or in the browser natively) is helping here. EDIT: The official description [https://github.com/WICG/floc https://github.com/WICG/floc], does a better job in explaining the point. They try to cluster (="cohort") users interests and exchange that with the ad-service. This could maybe help to increase transparency and authority over your data as it's saved locally. But I don't see a way to limit the access to the users cohorts (they even say that themself, see link above). Everybody could access my interests - not just Google and other ad services. And of course, if you have 1000 categories and some meta information (region based on IP address etc.), you will be able to track down individual users with pretty good accuracy.
- cestith 6y agoRather than giving the advertiser a list of my interests, it'd be nice if the advertiser gave me a list of keywords for the ads it might show next and my browser requests the ad for me. A default browser could then be configured to learn with a thumbs up / thumbs down / never show me again type of Bayesian training. Or a non-mainstream browser could request random ads.
- doytch 6y agoBut most people would never up/down the ad, which means the ad would be targeted more randomly, which means it wouldn't be as effective, which means the website/content owner wouldn't get as much money for displaying it. I don't think that solution works in the current environment, unfortunately.
- bluesign 6y agoIf I clicked the ad, thumbs up, if not thumbs down. With appropriate weights this can work. But.. Ad networks will never implement this, cause priority there : 1) ad network 2) advertiser 3) publisher 4) user This bumps user from 4th place to 1st place
- holtalanm 6y agohonestly the thing that bugs me the most about the article is cookies == tracking. Sure, cookies are used for tracking, but they are also used for authentication, which is something that nearly every webapp needs to do. I just think that, due to articles like this, cookies end up being viewed as nothing but bad, when they are an important tool for the web when used properly. More on-topic of the article: this doesn't look like it really changes anything, to me. Like, so instead of cookies being used to track your data, they use a _browser extension_?? that is potentially even _more_ invasive. Sure, if it does what they say it will do, it kind of obfuscates your personal data. Really, what people want is just....less ads. Less targetted ads. This doesn't achieve that.
- Spivak 6y agoFor basically everyone cookies == tracking. That is pretty much their only user-visible purpose. I think the best way forward would be to heavily restrict the persistent data that websites (that aren't installed as apps) can store in the browser to basically just an authentication token that is only sent by the browser and not accessible to JS. It's kinda silly that we can't manage our website logins via the browser without clearing all the cookies for a site.
- wyldfire 6y ago> Sure, cookies are used for tracking, but they are also used for authentication, which is something that nearly every webapp needs to do. What if we could move authentication or more specifically the state held in the client for authentication to some other mechanism? Could we pitch cookies? Could we make this switch without making it somehow possible for advertisers to switch to the new mechanism?
- kenniskrag 6y agoAlready exists. Custom HTTP Header with a JWT token for example. Also in the body of a post request can be the auth data. In the URL would also be possible but is a security risk due to e.g. browser history.
- alexfromapex 6y agoI think independent groups would be much better advocates for privacy technology than Google which has a huge conflict of interest
- fixmycode 6y agoI'm sorry but I fail to see the point of this. you can choose to disable cookies, will you be able to disable this new thing? if so, what's the big deal about it, other than the same principle with a different name, probably to avoid some EU legislation. Advertisers and trackers have been doing the same thing this thing is supposed to do for years. And where will they implement it? the only way would be at the application level, so every browser now also has to implement internal tracking services to aggregate all the data in their flocs, to then come back to the user to spice up their request? come on... I'll keep supporting efforts to make the Internet a more privacy focused place. Advertisers have been buying TV ads for decades and I my TV hasn't asked me what I want to share with it, yet.
- kag0 6y agoThis is related to my main question about this. What if browsers just... don't implement this? What makes Google think that Apple or Mozilla are going to add this to their browsers?
- baybal2 6y agoFYI this was already quietly shoved into Chrome 80
- m_eiman 6y ago"Hi early 2000s computer user, let's make a deal: I get full access to everything you do online, and get to do anything I want with the information. Perhaps I'll use it to maybe target ads slightly better in some cases, and put myself into every value chain you're involved with so I can get a cut at every step. Oh, and I'll do my best to move all computing online, so that 'everything you do online' equals 'everything you do with a computer'. In exchange you'll get a web browser that is at times more performant than the others. Hell, I'll even throw in a free email account (where I can gather all the best bits of info)! It's a pretty good deal, don't you think?"
- judge2020 6y ago"if it means I don't have to pay $20/year for more than 2mb of hotmail storage, i'm all for it!" https://www.pcworld.com/article/116657/article.html#drr-container:~:text=Microsoft%20is%20also%20readying%20a%20new,20MB%20attachments%2C%20for%20%2419.95%20yearly.%20Previously https://www.pcworld.com/article/116657/article.html#drr-cont... (250mb free increase was suspected to be a response to Gmail)
- interestica 6y agoWe live in the timeline where "Alphabet to replace cookies" is a legit headline. What is the public understanding/perception of cookies? The past couple of years since the implementation of the GDPR has probably been the biggest and weirdest public education campaign (done entirely through brief pseudo-consent popups).
- ocdtrekkie 6y agoIn addition to the whole fox guarding the henhouse issue, this doesn't address the primary harms of user tracking: That it's just bad for society that people are targeted and advertised to on this level, as it fosters filter bubbles and encourages unhealthy behaviors. Tracking a group of 1,000 people to cater bad political ads isn't meaningfully better than targeting 1,000 individuals with bad political ads. Targeted advertising needs to be treated like unfair gambling practices. Banned across the board, and the industry that remains needs to be heavily regulated and forced to be completely transparent about the process.
- maweki 6y ago> Targeted advertising needs to be [...] banned across the board You say that like an absolute that is enforceable. Advertising has been targeted since advertising exists. Advertisers have been choosing radio or billboard-slots for well over 100 years (well, radio for 100, print and billboards probably for centuries), using data or educated guesses to reach a target demographic. As advertisers now choose on which sites (or not) their ads should appear, in order to reach their target demographic. Of course, they can choose by a few more criteria now. How ubiquitous should a specific ad be, so that it would not be "targeted" advertisement? I think we need legislation, but it's not black and white. There's a huge grey line that spans all of advertising history. Edit: just to be clear, choosing whether to advertise in a newspaper (and which) on radio (and which channel), or on facebook, is already targeting for a desired audience.
- ocdtrekkie 6y agoI suppose I should clarify: User targeting should be banned across the board. Content targeting should not: Feel free to put ads next to particular news articles, sites, or TV shows.
- bseidensticker 6y agoIt's no so cut and dry though. If you've ever watched golf on TV you will notice that the most prominent advertising is for insurance companies (User) not golf equipment (Content). They are advertising to the cohort of users that watch golf on tv (rich business people). It's all user targeting.
- chovybizzass 6y agoNetscape should have them "herpes" instead of "cookies".
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- yalogin 6y agoThey did not find a replacement to cookies. Cookies have become too toxic and are harming them and so they found a way to not store anything on the device and yet be able to target users. This means it will be impossible to stop them from profiling and targeting users as users don’t control anything. They are using privacy preserving techniques, and even if we assume they are doing it well, it just means that we will never get rid of the profiling and paying to get privacy will not happen with google services
- jahewson 6y agoIf you read the 4th bullet point in the article you'd see that the data is actually stored on the device. Users will go from seeing only cookies, which are opaque ids, to their full behavioral profiles - basically, the opposite of what you just said.
- gnud 6y agoThis mainly looks like a push to remove even more user control over tracking. The spec says that the browser can return 'random' data, but I suspect that Chrome won't let you do that, or at least not for long. Instead of the user disabling third-party cookies, every single page author would have to set a new HTTP header to have their page excluded from the machine learning. It also looks like a massive GDPR pitfall. Say you track conversions to a campaign, and track what "cohorts" a user entered your sales pipeline through. The moment you connect this data to the customer, it's personal data IMHO. If you operate in Europe, the user should be able to retrieve/delete the data, and request it changed if they say it's wrong.
- mfer 6y agoPart of this is about the middle men. The NY Times cut off ad exchanges in EU and found it didn't kill their ad business [1]. One thing it did do was cut out the middle companies doing the brokering. Google has made A LOT of money just being a middle company. Like a car dealership. The proposed system deals with large groups and machine learning. It requires a browser ad on or changes to the browser. This is not approachable for startups, small businesses, or those who are independent. It's targeted at Google and further helps solidify their position. As people want to cut Google off from constantly monitoring them they are looking for ways to work around being cut off to keep the data flowing. Branding and marketing their work to make people want it. [1] https://digiday.com/media/gumgumtest-new-york-times-gdpr-cut-off-ad-exchanges-europe-ad-revenue/ https://digiday.com/media/gumgumtest-new-york-times-gdpr-cut...
- wombatpm 6y ago>Part of this is about the middle men. The NY Times cut off ad exchanges in EU and found it didn't kill their ad business [1]. One thing it did do was cut out the middle companies doing the brokering. Google has made A LOT of money just being a middle company. Like a car dealership. So NYT rediscovers publishing? Once upon a time, publishers had teams of sales people who had relationships with companies needing to advertise and coordinated theirs ads with the publishing schedule. Publishers then gave that advantage away to sell ads for a fraction of their current price on a per view basis and have been crying ever since.
- mfer 6y agoPublishers have been seeing their ad revenue decrease. This is why they complain. Companies like Google make billions on ads. A overwhelming majority of Googles income is from ads. It isn't just that Google served new markets or that publishers outsourced the work. Ad systems use a bidding system. Google controls both sides of the bidding system. The system is setup in a way where Google has benefited more than others. It reminds me of record labels and producers. They make the lions share of the money on record sales for most albums and music. The artists typically get a small share. Some artists have walk away with a medium income will selling millions of albums and having the label/producers making millions. The lower income to publishers has caused them to do more shock and awe type articles that aren't good for us. They pay more inexperienced people less so there is less mentoring. Overall it means the quality of the published stuff has gone downhill.
- acvny 6y agoSo they are now rebranding the fact that they are trying to monopolize the ad space?
- coldtea 6y agoWe wont solve this issue until we stop viewind advertising and increased consumption as healthy...
- up2isomorphism 6y agoGoogle has already lost the trust of being a company that remotely respects anybody's privacy, if any at all. I would rather spend time on some other privacy proposals.
- cookiengineer 6y agoWhat this means is not that google has found a privacy-friendly alternative. It means that Google has found out that among 1000 people, your browsing criteria with HTTP headers alone is unique enough to identify you with 95% accuracy, which is actually even more frightening.
- telesilla 6y agoWould an extension that sets random headers be a solution to blurring identity?
- k_ 6y agoIt might just be some easy to ignore noise. Worst thing is, unless this is used by a very large chunk of the population, it would even be another tool to identify you.
- whiw 6y ago> it would even be another tool to identify you How exactly? It seems like a difficult problem for a website to me.
- k_ 6y agoThey can use "headers include random things" as a filter like they do with other headers presence/absence/value already. I don't think defining "random things" would be too hard for them.
- whiw 6y ago1. Noise that looks like valid signal is the most difficult kind to remove. 2. They would have to track the noise over page requests to know that it was noise. The saving of and correlation of the saved state would be a pain.
- jvzr 6y agoRandom would be even more unique. The solution (to this particular problem) is for a majority of users to set the exact same headers, regardless of the reality Some browser vendors have started to remove the specific version from the User Agent string, for instance. Tor browser window is an actual square specifically to make that value (browser width & height) the same across all its users and improve their privacy (by making that value useless in finding uniqueness) Hope that makes sense, sorry if I mis-explained some things
- flerchin 6y agoIt's not clear to me why we need third-party cookies to be a technology that browsers support. Just axe them. No replacement.
- grishka 6y agoYeah. I don't understand why it's taking so much time and effort and debate when all it would really take is literally a single line of code to change the default value of the setting that blocks or allows third-party cookies. I'd bet most users won't even notice the difference. The original RFC that introduced cookies specifically said that third-party cookies aren't permitted. Then Netscape broke it. Then everyone else did. It's about time browsers become spec-compliant.
- t0mas88 6y agoBecause Google makes billions on selling ads on other sites through their DV360 / Google AdX products. Those ads need third-party cookies for targeting, otherwise the price drops by a factor 5. Google also happens to make the browser with by far the largest market share. So they're not going to axe third-party cookies as long as it drops their revenue 5x.
- topspin 6y agoThis is what EFF says about this scheme: "A flock name would essentially be a behavioral credit score: a tattoo on your digital forehead that gives a succinct summary of who you are, what you like, where you go, what you buy, and with whom you associate." https://www.eff.org/deeplinks/2019/08/dont-play-googles-privacy-sandbox-1 https://www.eff.org/deeplinks/2019/08/dont-play-googles-priv... BTW, Chrome users have been part of this system for nearly a year now.
- TameAntelope 6y agoEFF tends to... sensationalize things more than I'm comfortable with.
- jjcon 6y agoI wonder why that is cause I feel like they didn’t used to be as hyperbolic or dramatic
- TameAntelope 6y agoI’ve always chalked it up to fundraising strategy, but I admit my opinion is reactive, I haven’t done any research.
- jascii 6y agoI suspect part of that might be a reaction to us (as in the population in general) getting used to privacy violations. It takes a bit more drama to get our attention in a world where we are all willing to voluntarily carry a personal tracking device 24/7...
- notatoad 6y agoEFF has been taken over by privacy zealots. They used to be more focused on what their name says: freedom. That is, fighting censorship and regulation of the internet. And the privacy folks love their hyperbole
- 6y ago
- qwerty456127 6y agoI don't believe Google because it could have eliminated all the ways to track people without their consent long ago if it wanted. Almost everybody uses Chrome/Blink and agrees to everything they decide. They can define and deprecate almost whatever browser APIs and behaviors they want. But it doesn't because they are the single biggest actor making use of these ways. E.g. it is known Google Captcha doesn't simply tell them you are a human, it tells them which particular human you are.
- voicedYoda 6y agoCan you explain, or provide reference points for the captcha knowing "which particular human" i am?
- SquareWheel 6y agoIt's utterly untrue. reCaptcha gives you a score of "humanness", and you can decide to allow or deny an action. There's no way to get an ID from it.
- qwerty456127 6y agoThere's no way to get an ID from it for a client. But there apparently is for Google.
- downandout 6y agoIn 1997, I had a meeting with Netscape executives about a similar technology I had created out of concern for the privacy implications of cookies. I called it LAD (local advertising decision). The server would send a script down to the browser saying “if the user meets X criteria, show this ad, else show Y” and so on. It could use browser history, installed software, and other factors for targeting. At the time I was laughed out of the room. Turns out I was just 24 years too early.
- etxm 6y agoReading this article, which is targeted at advertisers, feels like how I imagine a cow would feel looking in the window of a butcher shop.
- kmeisthax 6y agoFLoC is an engineering solution to a political problem. The problem with targeted advertising isn't the use of cookies, the problem with targeted advertising is the targeting. It doesn't matter if you're using fancy machine-learning and on-device targeting to avoid technically collecting targeting data. People don't like seeing their web history funnel into their advertising.
- maria_weber23 6y ago> FLoC is an engineering solution to a political problem. Yes. > the problem with targeted advertising is the targeting Is it? The problem with advertisement is the advertisement. I don't like to see ads at all, but one thing I know for sure, I'd take targeted ads at all time over random ads. > People don't like seeing their web history funnel into their advertising. No. This is the problem YOU have with it. Most of the non-tech people I know have no idea what you are even talking about.
- gwbas1c 6y agoYou must have no shame. My wife buys diapers online, then ads for diapers show up on my computer. I go shopping for underwear on one device, and then when reading a technical forum with co-workers on a different device, there's ads with people just wearing underwear. The tracking is extremely excessive.
- IfOnlyYouKnew 6y agoThat’s just the algorithm telling you to be more involved in childcare.
- mhh__ 6y agoI assume it's already been written but I've said and I'll say again that the 1984 of the future will be set in or around some kind of algorithmic dystopia. I'm specifically thinking a corporate one although China... Maybe I should be the change and write it myself
- tpoacher 6y agoFederated means no "theoretical" access to the data. It doesn't mean no "practical" access.
- st3ve445678 6y agoSo if you just use Firefox or Safari instead this method wont work on you?
- st3ve445678 6y agoBut this technology only works if you use Chrome as your browser correct?
- Hnsuz 6y agoWhole Google should unfind them self
- cblconfederate 6y agoIsn't that what Brave browser is doing?
- zffr 6y agoThis just sounds like Google is building an API for browser fingerprinting. Advertisers send Google data, and get back a fingerprint of a user. This is only "privacy friendly" because Google limits the accuracy of the fingerprint provided to advertisers by bucketing users into cohort groups. These groups are supposed to be large enough to prevent advertisers to identify individual users. Google would still retain the ability to uniquely identify individual users.
- cpeterso 6y agoChrome’s “Privacy Sandbox” mentioned in the article will limit JavaScript’s access to APIs that expose fingerprinting entropy. Thus publishers will feel pressure to use Google’s advertising services and Chrome’s FLoC because other ad networks won’t monetize as well since they can’t use third-party cookies or fingerprinting in Chrome.
- zffr 6y agoGreat point. This would give Google's advertising services an unfair advantage over its competitors. This really only seems beneficial to Google, not to other advertisers, or to end-users.
- jahewson 6y agoI doubt it. Safari already blocks 3rd party cookies, so this situation already exists. Every ad network will implement FLoC, it's an open standard - they'd be crazy not to.
- jefftk 6y ago> Google would still retain the ability to uniquely identify individual users. In the proposal, the non-clustered data does not leave the user's device: https://github.com/WICG/floc https://github.com/WICG/floc (Disclosure: I work for Google, speaking only for myself)
- chopin24 6y agoI'm happy that HN has accepted a change in the article's title, which appears as "Google says it may have found a privacy-friendly substitute to cookies." This terminology -- "found" -- has been used by Google and others to imply that their capture of behavioral "exhaust" is somehow a natural phenomenon, rather than a conscious, deliberate, profit-driven choice. Google didn't "find" a substitute. They are developing it because they are getting pushback from users and companies who object to their tracking methods and they're desperate to find something that convinces users they've Really Changed This Time. Don't fall for it. Break up with Google. They are abusive.
- local_dev 6y agoAgreed. When I saw this title and read the article, the first thing I thought was "Ok, how to I block this/opt-out". It sounds like this is only in Chrome though, for now. One hopes that FF will continue to be privacy focused and not add anything like this.
- bmcahren 6y agoIf you read into the federated technology they've been deploying I'm fairly comfortable saying I agree with their decisions. Let's take a look at the "Now Playing" architecture available on Pixel devices. At first glance by a critic you think "You're crazy for giving Google permission to have your microphone always on and listening for songs you're hearing, privacy this privacy that". If you read into it, you'll be comforted to know they've built a model to generate signatures clientside which are able to be compared on-device to a list of signatures which are similar to it. Then as far as I understand, they are able to take signatures which contain no discernable audio data and use those to discover new audio trends. > On Pixel 4 and later phones, the counts of songs recognized are aggregated using a privacy-preserving technology called federated analytics. This will be used to improve Now Playing's song database so it will recognize what’s playing more often. Google can never see what songs you listen to, just the most popular songs in different regions. Privacy-preserving, user-beneficial, and useful for advertising targeting if you haven't opted out of interest based ads.
- jrochkind1 6y ago
- nelgaard 6y agoAlready most of our CPU cycles are eaten up by ad-frameworks in our browser. Now Google want to offload Machine Learning to our browser. That will be bad for battery life, electricity bills, and the environment. On the other hand I use free software. So I can make a version of their extension that just claims that I am obsessed with Ironing. That will also make it easier for the Ad-blocker to do its filtering.
- tomaszs 6y agoCookies work without any third party business involved. The proposed solution won't work the same way. It will work only when using a third party business servers. It is not a replacement. It is a proposal how to replace a free, standardized and open world wide web feature with a commercial service.
- masswerk 6y agoBesides usual privacy concerns: Dear advertisers, I do not want to be herded in a bubble (designed by you or anyone else), I actually like to know the world around me. (And this is even more valid for the things I'm not that familiar with anyway. How would I learn about those segments of reality, if not from your adverisment that you would prefer to rather not show me?)
- chopin24 6y agoLet's dispense with this fiction, once and for all, that "targeted" or "customized" advertisements were ever for the users' benefit. They are, and always have been, for the benefit of Google and the advertisers. Google wants you to believe that advertisements are an inevitable, unavoidable feature of the web, despite the fact that they didn't want to be in this business when they started the company. They even go so far as to tug at your heart strings to and say how "hard" they work to make sure their product is "safe, unobtrusive, and as relevant as possible," implying that capturing your attention to part you from your money effectively is the ideal outcome. [0] This is gaslighting. Interest-based advertising on the web is not an immutable feature, a naturally occurring phenomenon. It's a scourge invented to further surveillance capitalism and it must be abolished. All this is to say, I'd change your letter to say: Dear Advertisers: Stop tracking me or I'll block you entirely at every turn. Your business model does not concern me. My attention is not for sale. Change, or be regulated out of business. [0]https://policies.google.com/technologies/ads?hl=en-US https://policies.google.com/technologies/ads?hl=en-US
- gerash 6y agoWhoah, folks like you use free ad supported services but just don't like the ad part and don't want to pay either. Interest based advertising is simply optimizing ads for conversion rate. Slow down with all the philosophy.
- deleted 6y ago[deleted]
- deleted 6y ago
- bigsteve90 6y agoGood news for google shareholders: looks like google is returning back to its roots creating nightmarish ad tech tools to further their goal of turning the world into a digital panopticon. Bonus points for simultaneously crowding out competitors and further solidifying their ubiquity and monopoly.
- jrochkind1 6y ago> and would've been paralyzed without the ability to use some sort of anatomized data to target people with ads. anatomized? Is that a typo for anonymized? Or does this mean something?
- lemax 6y agoAxios really needs to bring on some literate technical advisory. "Cookies are considered third-party data, or user data that's collected indirectly from users via browsers or websites." This statement seriously requires qualification. This is exactly what contributes to unreasonable regulation and confused users.
- godelmachine 6y agoWhile we are discussing this, just wish HN readers to shed more light on a practice which I diligently follow. Whenever I visit any website, courtesy the GDPR laws, we are asked to request the terms and cookies. I make it a point to disable all cookies (barring the strictly necessary ones), partners and also the "Legitimate Interest" section, where I click "Object all", and then click "Save and exit". However, on many websites I don't see any option to "reject" or "object" to cookies, partners, vendors and especially legitimate interest. Particularly concerned about Legitimate Interest since the number of vendors there is humongous.A good example of a site where we cannot choose would be the BBC[1]. We get an option only to read their terms and conditions but no option to reject and object. 1) Can anyone please guide how to reject to cookies on such sites where they don't have a reject option present? Also, in my iOS, in Safari settings, I have chosen "Block all cookies" to yes. 2) How far will blocking all cookies safeguard me from unscrupulous cookies? If my blocking all cookies is enabled in safari settings and suppose I visit some malicious site and accept their cookies, would the owners of malicious site be able to do anything sinister or adversarial to my privacy and integrity? Will the be able to breach my security? Ref. → [1]https://www.bbc.co.uk/ https://www.bbc.co.uk/
- frongpik 6y agoAnything short of uBlockOrigin/uMatrix with JS disabled won't work. Not only you need to block cookies at the uBO level, you need to block JS because it can write cookie-like IDs to persistent storage such as indexeddb.
- godelmachine 6y agoThanks for your suggestion. But wouldn’t blocking JS make all websites dysfunctional for me? Also, how do I get rid of persistent storage like indexDB as you have highlighted? Does clearing cache and cookies from browser help?
- frongpik 6y agoWell, you'd selectively enable JS if you really need that site. Clearing the cache and storage should be enough.
- vorticalbox 6y agoIs this not how brave ads work, with a local profile that fetches ads you profiles says you should be interested in?
- ogre_codes 6y agoThis requires browser integration. What concerns me is this doesn't talk about how Google plans to track non-Chrome users. Because you know Google isn't going to just stop tracking the other 40% or so of web users. The other big thing that concerns me about this is how it still allows for some of the worst abuses. They are still going to possess entirely too much information about people and will continue to sell advertising that takes advantages of that information.
- lxe 6y agoThis doesn't seem to be at the same technology layer as "cookies", as this seems to be a Chrome-internal (local, which is good, but is this a guarantee?) API that uses your search history and other things to generate a 'cohort' which is an ID of some sort that you can send over as a part of requests to the advertiser URL's. https://github.com/WICG/floc https://github.com/WICG/floc
- devops000 6y agoWhat if the user opts out at browser-level? It looks Google business will be very dependent on chrome product.
- foxhop 6y agoAdditionally cookies are not bad, 3rd party cookies are not even necessarily bad. Tracking people is bad.
- danShumway 6y agoIt's possible to imagine an alternative system to FLoC that was actually privacy respecting. Say we had an Open, standardized, human-readable list of categories/groups that people could opt into (rather than a bunch of on-the-fly groupings determined by an AI). We could give users the ability to choose 0-X of those categories that they want to associate with. We could even let them choose on a site-by-site basis, so they could decide how ads would be targeted (or if they would be targeted at all) on parts of the web. We could build UIs that helped them with that. We could have easy ways to opt into or out of categories. We could allow them to turn on category suggestions, so with their permission if a user visited a site about a specific kind of product, we could show a one-click option in the browser to add themselves to an associated category and see ads for similar products. We could allow them to group sites together and say things like, "I want news sites that I visit to know that I'm looking to buy a specific brand of car, but I don't want any of the car dealership sites that I'm looking at to know what brand I want." For users that don't want that level of detail, we could still have a 'smart' system that consumers could run (clientside) that looked at the websites they visited, or even more personal data, and auto-placed them in categories without them needing to think about the system at all. They'd just need to select an option to let the browser handle all of their categories for them. But importantly, all of this would be based on consent. And instead of offering users a single choice to opt out, they would have an entire spectrum of choices that allowed them to decide how they presented themselves online, what specific data they shared, and who they shared it with. If users genuinely benefit from targeted ads, then they'll opt into the system and pick categories that are relevant to them and send them to sites. If they think Google's data collection is accurate, then they'll turn on the smart system in Chrome that locally categorizes them. But at any point, for any site, they could choose to turn off the data entirely, or to add themselves to a specific category, or to remove themselves from a specific category. In human-understandable terms, they would know exactly what data they were transmitting to websites. ---- For all that Google says they're working on data privacy, very few of their proposals, even their good proposals, approach privacy from an angle of giving users more control over their identities. Google is still stuck in a world where they think of data collection as something that has to happen without the users knowledge, without the user's ability to easily inspect what's going on, without the user's ability to form multiple identities or even to just opt-into the system at all. What I want is control over my data. And what Google (and companies like them) keep on saying is, "we'll be somewhat more responsible with your data, but only if we keep control of it." And this represents a general attitude that comes up in so many modern tech products, from Youtube, to social feeds, to modern UI design, to device security. These companies are like a controlling, overbearing parent. People want agency over their ads/recommendations/feeds/etc, but the companies think the problem is that they're just not good enough at controlling all of that for us. It's a way of thinking about UX/product/process that's divorced from user consent and agency as an ideals that we should strive towards.
- frongpik 6y agosudo apt install chromium-browser
- throw14082020 6y ago> The Sandbox isn’t about your privacy. It’s about Google’s bottom line. At the end of the day, Google is an advertising company that happens to make a browser. It's worse than that. Google is an advertising company that makes a browser (63.38% of browsers globally) and mobile operating system (72.48% of phones globally) to vertically integrate, controlling your privacy choices. They're also trying their hand at PC's (ChromeOS, 1.72% globally). They invent technology across the stack, providing software for free or paid, and open sourcing some to commoditise the technology and to starve competition. I'd be interested to see how many people use Gmail. https://gs.statcounter.com/browser-market-share https://gs.statcounter.com/browser-market-share https://gs.statcounter.com/os-market-share/mobile/worldwide https://gs.statcounter.com/os-market-share/mobile/worldwide https://gs.statcounter.com/os-market-share/desktop/worldwide/ https://gs.statcounter.com/os-market-share/desktop/worldwide...
- dang 6y agoRecent and related: https://news.ycombinator.com/item?id=25813601 https://news.ycombinator.com/item?id=25813601
- foolinaround 6y agoExtensions will spring up that will pollute the local storage to help in anonymity, increase the noise and reduce the real value.
- nousermane 6y agoWhile on the topic of third-party cookies - is there any legitimate use for those at all (outside of semi-covert user tracking)? I understand how first-party cookies are useful - you take a stateless protocol (HTTP) and make it aware of "sessions". And those in turn are a nifty block to build upon - login/authentication, "shopping cart", whatever... But having one website to be able to save state that is only accessible to a chosen different site - what's the use for that?
- acdha 6y agoThings like single-sign on or social networking where you toss some JavaScript from api.example.com on your page and it does things like automatically log you in or display messages you might have. I see this is as a tragedy of the commons problem: it's kind of nice to have, say, a counter of unread Disqus messages but the relative value of that compared to the use by tracking companies is hard to ignore.
- tootie 6y agoOauth and SAML use callbacks, not cookies.
- iooi 6y agoThat's if you're implementing SSO on your own, which most folks don't do. Most SaaS using SSO in their apps will use Auth0 or Okta. Dropping third-party cookies has implications for these integrations: https://support.okta.com/help/s/article/FAQ-How-Blocking-Third-Party-Cookies-Can-Potentially-Impact-Your-Okta-Environment?language=en_US https://support.okta.com/help/s/article/FAQ-How-Blocking-Thi...
- acdha 6y agoI didn't specify those protocols for a reason. While that's technically true at the API level, I was referring to things like the “Sign-On with <service>” widgets – you can make a completely static version of that which doesn't use cookies but there is a nice UI improvement if the button can load and say things like “Login as @tootie” or “@tootie, you have 5 DMs” anywhere you see it. Instead, I think we're going to recognize that this is too broad to be secured and either come up with ways to scope it down (e.g. requiring the third-party to have some sort of opt-in prompt) or that entire market category replaced with browser-controlled alternatives, which isn't great for companies other than Apple, Google, and maybe Microsoft but does have the appeal of not trusting an entity which the user isn't already trusting.
- dillondoyle 6y agoI don't understand how retargeting would work with this? Attributions is a big pain too. Without those two things this simply makes google more valuable while killing everyone else who doesn't have their own browser which tracks everything from your login, analytics on basically every website, and more.
- throwaway189262 6y agoI say this every time, but individual targeting should be illegal. The ad industry thrived for thousands of years without ads that follow you everywhere. Invasive targeting is only 20 years old, a blink in the history of advertising. If it was gone tomorrow these companies would just go back to targeting based on the ad placement rather than unique person viewing it. What we have now is the dystopian sci fi movie where ads shift as different people look at them. If you don't think it's dystopian, consider that every ad your coworkers see when you're sharing your screen is based on the best targeting data advertisers can find. Your screen is disclosing your interests, wealth, medical history, kinks, etc to anyone looking at it. It's fucked up.
- WhyNotHugo 6y agoHonestly, we don't need a _replacement_ for third-party cookies. They're not really necessary for anything. There's few websites that break without them (e.g.: logging into Atlassian), and that's mostly due to bad design (given that every other login flow out there works fine). Their main use has been to track people, hence, we don't really need them at all.