5 ms·
If I am reading this right (and you seem to have read it the same way) it ends up creating a browser fingerprint. Visit 1 FLoC and they have no real idea who
by sumtechguy 5y ago
If I am reading this right (and you seem to have read it the same way) it ends up creating a browser fingerprint. Visit 1 FLoC and they have no real idea who you really are. But if you visit several they could easily tell. Which is similar to how they use your installed list of fonts to identify you. But more formalized?
- munk-a 5y agoThat compromise would require knowing who someone actually is between site and site - you could collect the full list of cohorts but you'd need additional information to be able to marry all that data together - let's say something like facebook injecting JS into every page on the internet to harvest cohort information and then gleefully reselling that information.
- joshuamorton 5y agoNo, this isn't correct. You only ever belong to a single FloC. So let's for a second assume the non-adversarial use case. The advertiser isn't using any additional tools to track you. Then the only thing the advertiser has is your FloC. This doesn't identify you individually, but it might correlate with various interests. If your FloC changes, which it will periodically, the advertiser doesn't have any history, so the correlation changes and you're given different ads. Now let's assume that they have some additional information, like an IP address. Then they can say ah you had this FloC on this date, and this different FloC later. Its not more identifying (they already have your IP, which we assume is identifying enough). The FloC might let them infer things about your interests on other sites, so they have precise information on your browsing interests on this site, but only partial information on other sites. As opposed to today, where 3rd party trackers mean they have full information on the other sites too.
- alerighi 5y agoIt's not the same as third party cookies! Third party cookies works only if: a) every site you visit loads some Google/Facebook/whatever JavaScript to track you. That are not all sites. b) you didn't disable these scripts with extensions like UBlock (that to me is essentials these days) or use a browser that value your privacy (like Firefox) that blocks them by default. This system not only is deeply integrated in the browser and thus impossible to block with extensions (without modifying the source code of the browser, that in case of a proprietary browser like Google Chrome you can't), but also track all your browsing history, meaning that they catch even sites that doesn't include Google trackers inside. Another bad thing about this system is that is integrated inside the browser, meaning that for a closed source browser like Chrome only Google knows how it works and what exactly it does. While classical tracker scripts that uses third party cookies are implemented in JavaScript, minified and obfuscated, but still you can in theory read the source code and understand what they do. This is far worse for privacy than how things are now!
- joshuamorton 5y ago> a) every site you visit loads some Google/Facebook/whatever JavaScript to track you. That are not all sites. Right, but it is, to a first approximation, all of the sites that are going to be showing you personalized ads. > Another bad thing about this system is that is integrated inside the browser, meaning that for a closed source browser like Chrome only Google knows how it works and what exactly it does. While classical tracker scripts that uses third party cookies are implemented in JavaScript, minified and obfuscated, but still you can in theory read the source code and understand what they do. I'm not quite sure what you're getting at here. The setting and reading of a cookie by a client, yes, will be written in JS. That doesn't mean that you can know what its doing (there are likely cookies on your system that contain encrypted payloads that you can't read). The system that "actually" reads those cookies is hidden behind an API, so you don't have access to even the binary code. From that perspective, FloC is no worse, and is usually better, as the payload itself is generated and managed on your machine. Tangentially, FloC is similar to but probably more privacy preserving than the way Brave Browser does advertising today, and that was heralded by many on HN as a huge privacy improvement.
- tmottabr 5y agoyes, but i can have addon that will clean that cookie everytime i leave that sit and that cookie is only relevant for that site that set it.. i also can disable third party cookie at all so a site cannot see cookies for other sites.. and they can only track what sites you go that have their ad or their social media buttons.. afaik you cannot disable floc with an addon and you do not have any control over the floc id is assigned to you.. the floc id is calculated once a week based on the sites you visit on the previous 1 week.. so it leak information of what sites you have being visiting if anyone is able to reverse the sites that generated that floc id even if the site does not have adds or social media button on then or you use add blockers.. and i bet all the major tracking players will have farms calculating all possible floc ids from all the popular sites.. maybe do an addon that load randon stuff from randon domains in the background to taint the floc id so it makes harder to reverse the actual sites you are visiting.. or just use an browser that does not have it.. but beside floc, browser fingerprinting already allow tracker to identify people almost uniquely even without using cookies, there is already work on how to fingerprint someone without using either cookies or client side scripts, just by analyzing the timing when accessing several random subdomains using hundreds of redirects.. floc is just one more info they will have on you with no added benefit..
- kerng 5y agoInstead of fingerprinting out of millions of browser users a company now just has to have a rather small set (Floc) + old school finger printing to 100% uniquely identify a user. I wonder how this feature even passed an internal Google privacy sniff test...
- joshuamorton 5y ago> Instead of fingerprinting out of millions of browser users a company now just has to have a rather small set (Floc) + old school finger printing to 100% uniquely identify a user. A company can already fingerprint you with 100% certainty with a third party cookie. The idea is to replace those with FLoC. It's at worst a lateral move, and usually an improvement.