21 ms·
Proposal: Treat FLoC as a security concern
- meattle 5y agoWordPress is 41% of the web. If this goes through and FLoC is disabled by default by WordPress, will FLoC be dead on arrival?
- ocdtrekkie 5y agoBetween large web publishing platforms and all alternate browsers blocking FLoC, I think we could kill it, yes. WordPress is used by a lot of marketing focused folks though, so we'll see if WP is able to land this.
- llarsson 5y agoThe ones in marketing will rather immediately request that it is turned on instead.
- ceres 5y agoExactly. A big part of the WordPress community are publishers, bloggers, affiliate marketers, etc who rely on ads to generate revenue. I'm not sure they'd be too thrilled with this proposal.
- sircastor 5y agoSure, but this doesn’t mean no advertising, it means no default supporting FLoC. I know advertisers aren’t going to like it, but I doubt it means they’ll give up advertising altogether. I wonder if AdWords will require use of floc headers
- asdfasgasdgasdg 5y ago> I wonder if AdWords will require use of floc headers I don't know, but I guess they won't. Instead, you'll just get worse targeting on your site if your users don't send the headers. Which I think may also not be very popular with WordPress users, but I guess the proof will be in the pudding.
- nonbirithm 5y agoIt's staggering how much leverage WordPress has. They were going to stop using React because of the patents clause, and only a week later Facebook caved and relicensed it as MIT.
- l00sed 5y agoThis is very interesting. My web development role right now is at a marketing company that works pretty exclusively with Wordpress. I've always been so interested in learning about the next best thing that I hadn't given Wordpress much thought. Now, using it all the time, it's popularity is very understandable as an interface for people who are not technically savvy to maintain their own website. I feel like the Wordpress community isn't the loudest, but it is certainly a force. I think, as a brand, this move definitely has me more excited about working with their software.
- abhinav22 5y agoGoogle has such a monopoly that it will take a lot to overcome their plans. Glad to see WP taking a stand - I never knew that FLOC would be so bad. The WP proposal made it clear that it’s a discriminatory technology.
- markovbot 5y agoMost likely google will just turn off that silly opt out functionality. It's not like anyone's going to stop using their spyware browser.
- feanaro 5y agoI'd like to see them try that and see how that flies.
- karaterobot 5y agoI wonder whether, if WP takes the stance that FLoC is a security risk, whether they'd also consider a version of Chrome that doesn't allow opting out of it a security risk as well. And, if not, why not?
- Silhouette 5y agoSurely that depends on what their experience using it is, just like every other "winning" browser before that is no longer winning? If FLoC generates so much hostility within the web dev community that a few major sites/platforms start actively blocking it, and if Google responds by ignoring the opt-outs in Chrome, and if the community responds with a SOPA-like "no access using Chrome for the next 48 hours then, here are some other fine browsers you can use instead that don't invade your privacy in this way", Google will simply be outgunned. However, you probably need platforms on the scale of WP and/or some sites with huge audiences like Facebook/Wikipedia/Netflix/Reddit to be on board for the effect to be fast and powerful enough to make a difference.
- markovbot 5y ago>and if the community responds with a SOPA-like "no access using Chrome for the next 48 hours then, here are some other fine browsers you can use instead that don't invade your privacy in this way" that seems unlikely.
- Silhouette 5y agoIs it, though? It appears that Google is trying to rewrite the rules of how browsers and the Web work, with the appearance of being on the side of privacy, but actually introducing an alternative method of surveillance that is going to be less favourable to almost everyone except Google. How many of the huge-audience sites are potentially going to lose out from that, not least because they rely on advertising themselves for the lion's share of their revenues? This whole discussion started with a proposal from a platform that is supporting nearly half of the sites people are visiting. That puts WP in a unique and potentially very powerful position here as well, and evidently they're interested in trying to force the issue. And finally, the SOPA experience has shown that it is not entirely implausible for large numbers of sites to collaborate in this way if they feel the threat is serious enough. So if FLoC is as bad as the critics are suggesting, it doesn't seem entirely out of the question. There seem to be quite a few powerful organisations that would have a variety of motivations for wanting to give Google a bloody nose over this one.
- enlyth 5y agoThis assumes the majority of these Wordpress websites will update to the latest version in a timely manner
- deleted 5y ago[deleted]
- ocdtrekkie 5y agoA key point of this is that if they consider it a security flaw, they will backport it into point releases for WordPress blogs that haven't done major upgrades in years.
- codegeek 5y agoIf added as a security patch, lot of websites will auto update.
- spockz 5y agoI’m not sure whether that would be wise to do for WP. It will show that WP can and is willing to basically push any update to sites running WP just to further a cause of the company. Mweh if it doesn’t break anything. But terrible if it breaks something.
- withinboredom 5y agoIt's the WordPress Foundation and the code is driven by a community, not really a company with a chain of command...
- codegeek 5y ago"WordPress is 41% of the web" This blows my mind every time. Even though I know it.
- skybrian 5y agoI don’t know it. Where did you learn it?
- itcrowd 5y agohttps://w3techs.com/technologies/overview/content_management https://w3techs.com/technologies/overview/content_management 41.1% of websites
- skybrian 5y agoOkay, thanks! It looks like it’s based on the top ten million websites by traffic, but weighted equally. Maybe there are lots of low-traffic WordPress sites?
- withinboredom 5y ago> Maybe there are lots of low-traffic WordPress sites? And many, many more high traffic websites. There's even some Facebook landing pages running WordPress and other many high profile sites[1]. 1: https://wpvip.com/ https://wpvip.com/
- gruez 5y ago>WordPress is 41% of the web By domains or by visits?
- redwall_hp 5y agoAs far as I'm aware, it's flawed in the same way as the PHP popularity stat: domains that report it in an HTTP header. I don't know about you, but I don't put a header advertising that I built a site with Python and Flask or whatever.
- neolog 5y agoI guess those go in the "None" bucket, so I think they are counted. https://w3techs.com/technologies/overview/content_management https://w3techs.com/technologies/overview/content_management
- BiteCode_dev 5y agoWell, FLoC is implemented on Chrome, you don't disable it, you opt out with a Header. So if Googles find that too many people uses the header, they can just decide to ignore it from now on. Who is going to prevent them to do that ?
- ahartmetz 5y agoPossibly GDPR? As an explicit no-consent to tracking? Not rhethorical questions, I know too little about the details.
- BiteCode_dev 5y agoWhen you use Chrome for the first time, it makes you accept its ToS which tells you they are going to track you.
- cseleborg 5y agoIANAL, but my understanding is that this is not in line with GDPR. You are not allowed to force the customer into tracking, which effectively happens in the scenario you describe since the user can't use the browser without accepting the ToS. Also, you have to be quite explicit: simply burying tracking in 52 pages of unrelated legalese is not compliant with GDPR. Someone please chime in if I'm wrong here. I'm no lawyer but do take these things seriously (I'm trying my best to provide a tracking-free website.)
- t0mas88 5y agoThey will lose that case under GDPR, you can't hide the details in ToS and hope the user doesn't see it. You must get informed and freely given consent. Google is violating both, because I can't click "No" and the information is so hidden you can't expect a normal consumer to find it. It will take a few years but they're going to get hit very very hard by EU privacy regulators.
- BiteCode_dev 5y ago
- ognarb 5y agoMy fear is that it will end up exactly like the do not track headers and that at some point Google won't listen to the disable Floc header.
- oh_sigh 5y agoWhy is that a problem? If I visit ognarb.com, what right do you have to tell me "You aren't allowed to use that fact for developing a profile about yourself"? You send me a bunch of data, including headers, and I'm more or less free to do with that what I want within the privacy of my own browser. I don't have to listen to any of your headers if I don't want to.
- tootie 5y agoI think that stat is more like 41% of servers, not 41% of traffic.
- nightpool 5y agoFLoC is designed to be opt-in, so uh...... no? Currently, for A/B testing, FLoC is automatically opting-in 0.5% of sites that serve ads, but that's only for a small testing population, the idea is that FLoC history contribution will be opt-in exclusively. (There's a proposal that you have to contribute to FLoC history calculations to get access to a user's FLoC identifier)
- blakesterz 5y agoI am hopeful that this will help get rid of FLoC but I worry about two things. One, this will end up being treated like the "no track" headers. That's just totally ignored after IE (was it IE?) enabled it be default. That gave all the trackers a reason to just ignore it and track everyone. I don't know if that exact same thing can happen here, but something similar maybe? The other thing I worry about is that FLoC 2.0 or whatever might replace it, will be worse. "Kill it before it lays eggs." but do we worry about what evolves from this if it dies?
- ocdtrekkie 5y agoWe're already successfully killing third party cookies and most browser fingerprinting strategies. This is an attempt by a browser to build an intentionally user hostile mechanic to compensate, but we can kill this too. We just need to continue to make it increasingly impractical and expensive to track users until it stops being considered a viable business strategy.
- skybrian 5y agoWhat do you mean? They are widely used, which seems far from dead. Aren’t you declaring victory too early?
- ocdtrekkie 5y agoThese are strategies that are being aggressively restricted. Chrome has not started preventing third party cookies yet, but they're the last holdout and have already stated they will kill them shortly. If you're using a non-user-hostile browser, these strategies are already heavily limited by default and are already not a concern. Every Firefox release is making significant improvements on reducing the fingerprinting footprint of the browser, and several user-hostile API features proposed by Google have been rejected by them and Safari to prevent expanded fingerprinting.
- skybrian 5y agoOkay, I still think it’s too soon to declare victory until Chrome actually does it. It could be delayed.
- geocrasher 5y agoIt would appear that there are already at least two plugins that take care of this for those who'd like to do so before it's rolled into the WordPress core: https://wordpress.org/plugins/search/floc/ https://wordpress.org/plugins/search/floc/
- mritzmann 5y agoYou don't need a plugin for this (every plugin is a security risk). You only need to send one single http header.
- geocrasher 5y agoTrue, but modifying core files to send the header isn't good either because you'll have to redo the change at every update. Also, most security plugins such as Wordfence will choke on a modified core file, and rightly so.
- redwall_hp 5y agoYou can chuck the same hook (as seen in the original link) into your theme's functions.php file. Or make your own plugin to hold miscellany.
- mritzmann 5y agoOr you can set the header in your web server configuration.
- deleted 5y ago[deleted]
- SpicyLemonZest 5y agoI think this is starting to get to the level of a moral panic. I respect that these developers think FLoC is bad, but what does it have to do with the WordPress project?
- gman83 5y agoIt's just HN. It's just like the reaction to AMP on this board. Most clients like the feature if it speeds up the site and brings more visitors to the site. Here, you'd think it represents the end of the internet or something.
- slver 5y agoIf we have to be fair, Google didn't build a browser, an email service, a free DNS service, and free hosting/optimization service (AMP) just because, y'know, whatever. I tend to roll my eyes at the blind hatred of corporations, but we also have to have both feet firmly on the ground, that these products and services are strictly tied to long-term plans for ROI. What kind of a ROI would the biggest advertising network have? Tracking, profiling and serving profiled ads.
- x0x0 5y agoLook at gmail: I pay $60/year-ish for Fastmail. Gmail is at least that good. So is the purpose of gmail to have a cross device stable identifier? Absolutely. Are people realizing tons of value from it for free? Also yes.
- alkonaut 5y agoI expect to get a gmail type service paying only the "price" of having some unobtrusive ads when I'm on the gmail site, nothing else. I absolutely do not agree to google using anything from gmail to generate a stable user id for advertising, or e.g. show me ads in google search results or youtube videos, based on analysis of email content. If Google can't provide what I expect (a free mail service paid only by ads on gmail dot com) they should tell me that they want $X per year and I'd happily pay it. It's not that I don't want to fund the operations of services, it's that I'm always assumed to rather pay with my information than with dollars.
- Flocular 5y agoCan't privacy concious browser defeat FLoC simply by sending random cohort IDs on each request?
- izacus 5y agoThat would require admitting that moving the tracking process to client-side actually improves on status quo (by not collecting data on the server). While the whole framing of EFF et. al. is put in a way that does not allow for even a small doubt that the proposal is just the worst thing ever with no redeeming qualities. That framing disallows working within this feature to modify browsers to send the required headers.
- Flocular 5y agonot at all if you're not taking part in the data collection at all and are just sending noise on the channel. I guess chrome could counter DRM-signing the cohort-id or something
- speedgoose 5y agoI would believe that random noise is easy to filter when you are Google.
- NotEvil 5y agoDepends upon the noise, But even if they filter it out it will get the desired result of not having a cohart id. In case of opting out you are in the default don't like privacy invasive cohart
- outside1234 5y agoFrom my surface level reading of FLoC - would it be possible for Edge or Mozilla to implement FLoC - but to send noise / random / incorrect data up in a way that essentially wrecks the algorithm?
- gruez 5y agoThen advertisers will fingerprint the browser as well, to see whether the FLoC data can be trusted.
- outside1234 5y agoJust have everyone spoof Chrome then
- SpicyLemonZest 5y agoA substantial amount of modern Internet infrastructure relies on the fact that major actors are behaving in good faith. This isn't a chain of escalation anyone would benefit from going down.
- mindslight 5y agoThe surveillance companies have started us down the path of bad faith by nonconsentually tracking us via protocol and implementation bugs that leak identifying information. IMO Firefox et al need to keep working towards a better-specified JS runtime without these security vulns, so that when the layperson complains about big tech surveillance an easy answer is "Stop using Chrome".
- gruez 5y agoFor firefox this is nearly impossible because of the different quirks it has in its javascript/layout engine. It might be easier to do with all the chromium forks, but it's unknown how the proprietary bits in chrome affect browser behavior. At worst they can use something like have obfuscated code (eg. widevine L3) for attestation.
- 5y ago
- cblconfederate 5y agoI mean if we are going to be subject to mandatory profiling, why not take brave's approach of paying users directly for the apps they see cutting out the middlemen
- SimeVidas 5y agoThe real solution is to make everyone stop using Chrome.
- busymom0 5y agoI am a bit uneducated at this but does Brave browser which is based on chromium also have the same problem?
- SimeVidas 5y agoNo, Brave removes everything that has to do with Google from the browser.
- danuker 5y agoIt does ping static1.brave.com every now and then, which seems to use Google gstatic, which in turn uses Cloudflare: https://spyware.neocities.org/articles/brave.html https://spyware.neocities.org/articles/brave.html
- sseneca 5y agoThey've said they're going to disable FLoC. Still, this is one of the benefits of Firefox, it's not based on Chromium at all so it's out of the question.
- foobiter 5y agoBrave has already said they won’t support FLOC
- dang 5y agoThe submitted title was "WordPress Proposal to Treat Google's FLoC as a Security Concern". That makes it sound like Wordpress itself is officially making this proposal. Is it? The page doesn't look like that to me. We've reverted the title in keeping with the site rule: "Please use the original title, unless it is misleading or linkbait; don't editorialize." (https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html).
- r1ch 5y agoThe page does seem to be the official wordpress development blog, linked from wordpress.org's "get involved" page. "The WordPress core development team builds WordPress! Follow this site for general updates, status reports, and the occasional code debate."
- neolog 5y ago> That makes it sound like Wordpress itself is officially making this proposal. Is it? Seems like it is to me.
- dang 5y agoIt looks like it to some and not to others, which is already confusing if it's an official proposal.
- 5y ago
- takeda 5y agoI just love the Google's way of thinking. Users: We hate cookies, because they are abused to hurt our privacy by allowing advertisers to build a profile about us Google: We have a great idea! We can get rid of 3rd party cookies and instead make your browser build profile about you and share it with everyone.
- pm90 5y agoIIUC while floc does indeed build a profile browser side it isn’t something that advertisers can track with the same precision as they can with 3p cookies. So while it’s not the holy grail it does appear to be a small step in the right direction from the status quo. Do I understand the situation correctly? Genuinely curious.
- NotEvil 5y agoTrue, but the FLoC implementation comes with its own sack of worms look eff excellent post on it.
- nabakin 5y agoThat's what I've been wondering. If FLoC is better for privacy than current tracking methods and Google intends to switch to using FLoC instead of current tracking methods, wouldn't it be better for FLoC to succeed?
- vimda 5y agoEven if we assume that FLoC is entirely good, it's a false choice - why do we need _any_ tracking at all?
- bagacrap 5y agoThe web survives by serving ads. Targeted ads earn content creators more. They earn more because of higher conversion rates, so presumably users like them more (ultimately if an ad makes me buy something, I probably appreciate having seen it).
- hirsin 5y agoA comment in the WP post brings up the malicious nature of FLOC opt-out - it requires base layer changes to your site. Google knows from Samesite that it requires "your app is going to break" levels of urgency to get old sites to update, and can likely follow the dots to how an opt-out is much less likely to be used than an opt in. This feels like something that should get more attention/discussion. It flew for Samesite because "better security defaults" is a good argument. Not sure it works that way for FLOC. Despite being involved in the Samesite rollout I hadn't quite made the same connection as that commenter, as I am not as connected to the FLOC work.
- mark_and_sweep 5y agoFLoC cohort computation only triggers on websites which call the document.interestCohort API or load ads. So your average website does not have to opt-out. It's not opted-in in the first place.
- josefx 5y agoHow likely is it that any third party script would call the API? Most sites I know try to pull in at least one Google hosted script.
- mark_and_sweep 5y agoYou may have to audit third-party scripts before using them (which is not a bad idea regardless of FLoC). If you load Google Analytics on your site, I feel like you have no right to complain that it may track users...
- dogman144 5y agoIt’s a opportunity to put priv engineering techniques to the test in prod, at least. That’s 100% the main thing that stands out here. In the raw browser history, prior to ~hashing it to a FLoC ID, can Google anon PII while still maintaining good data analytics from the rest* of the dataset’s fields? Priv engineer, as an engineering discipline, would argue yes. If this is what Google does and the privacy is put through its paces (can a FLoC ID de-anon into a user?), then yeah this isn’t a bad trade off. Use case: Google has to make money, I love Chrome’s and GSuite’s UX, priv eng’ing lets them use my data to pay for that UX while moving all the tracking in-house and ending 3rd party cookies.
- livre 5y ago> can a FLoC ID de-anon into a user? Currently yes and seems like a though problem to solve (there are trade offs but it's likely that this will never be fully solved, like encryption, you can only make it so difficult that it isn't worth doing it but not impossible to do): https://github.com/WICG/floc/issues/100 https://github.com/WICG/floc/issues/100
- dogman144 5y agoVery cool I’ll check it out. I’ll push back on it being tough to solve — unless you’ve looked into privacy engineering and have some further data in that direction. Whole field exists to de-link PII to data that supports business analytics, and the tech is there at a non-tough level for Google to achieve.
- tacticalblue 5y agoCan someone explain how FLoC works like I am five ?
- McDyver 5y agoLately the loss of security, increased tracking, etc are very pressing issues, which the "general public" is not aware of. Would it be feasible, or actually doable, to create an wareness month - a la Movember? This would help to shine some light on what is being done by major corporations, and which affects everyone.
- adfauke 5y agoSectember?
- qyi 5y agoI mean yes, web ads have been used to hack people for decades. Just put your code in the ad and steal his cookies (and the next 10 issues after that gets patched by the ad service). It was a favorite topic in blackhat presentations. At the end of the day there is no way to do ads securely, aside from maybe JPEG ads. People don't seem to understand that adding more bloat to the web (which is already a terribly insecure and inefficient way to implement software) directly reduces the security of online banking and e-commerce. disclosure: I don't know what FLoC is, and the OP page doesn't load. Seems to be something about web ads security.
- Google234 5y agoNope.
- toomim 5y agoThe intro lost me: > WordPress powers approximately 41% of the web – and this community can help combat racism, sexism, anti-LGBTQ+ discrimination and discrimination against those with mental illness with four lines of code:" function disable_floc($headers) { $headers['Permissions-Policy'] = 'interest-cohort=()'; return $headers; } add_filter('wp_headers', 'disable_floc'); If you seriously think this is going to make a difference in racism, of all things... I mean... do people seriously think that? Do you know what racism is anymore?
- notatoad 5y agoI mean I'd be willing to listen to an argument that FLoC will contribute to systemic racism. I accept that it's plausible. But it really makes me distrustful of the whole proposal when people make wild claims like that and don't feel like they need to make even the briefest attempt to back it up. It seems a lot more like they're just taking the currently trending social cause and co-opting it to support their own unrelated agenda.
- kevingadd 5y agoFLoC exists to group users down into behavioral targeting categories, it should be obvious that some of those will end up corresponding to gender or race or other traits that are protected statuses. We've repeatedly had incidents where big companies were caught accidentally letting (for example) landlords filter advertisements by race or recruiters filter listings by age, both of which are illegal.
- dstaley 5y agoYup, from the linked EFF article: > Observers may learn that in general, members of a specific cohort are substantially likely to be a specific type of person. For example, a particular cohort may over-represent users who are young, female, and Black; another cohort, middle-aged Republican voters; a third, LGBTQ+ youth. This means every site you visit will have a good idea about what kind of person you are on first contact, without having to do the work of tracking you across the web.
- mark_and_sweep 5y agoFLoC cohort computation only triggers on websites which call the document.interestCohort API or load ads. This is not quite an opt-in. But a blanket opt-out isn't necessary either.
- lolinder 5y agoThis is an important point if true, do you have a citation for that? I can't find anywhere in the documentation indication that sites are only included in the FLoC model if they call the FLoC API.
- mark_and_sweep 5y agoYes. Take a look at this issue: https://github.com/WICG/floc/issues/103 https://github.com/WICG/floc/issues/103 Then again: "final design is still subject to change based on [Origin Trial] feedback".
- 0xy 5y agoFinal design is subject to the numbers in Google's ad department. Chrome is an adware browser, and security takes a backseat to any broken API or security disaster that Google's ad customers decide to mercilessly abuse for fingerprinting (AudioContext, etc).
- deleted 5y ago[deleted]
- hansoolo 5y agoProposal: use Firefox
- Black101 5y agoAlthough Firefox keeps getting worst, it is still a good alternative to Chrome... at least on PC... Firefox mobile stripped too many features from the latest version.
- ajnin 5y agoWith the death of third-party cookies Google is trying to force browsers to add enough bits of entropy so that the same level of user tracking can be achieved through fingerprinting instead. Simple as that. The fact that Google is rolling this out right now but their plans to reduce fingerprinting move much more slowly, if at all, is telling. This absolutely needs to be treated as the massive privacy leak that it is.
- jimbob45 5y agoCan’t you just switch to a Chromium fork without the FLoC? If they were closed-source, I think I would agree.
- thisarticle 5y agoHow many people who use Chrome can or will even know to do so? Tech oriented people already have alternatives.
- JeremyNT 5y agoSure, "you" - as a reader of hacker news - can use Firefox (or a chromium fork). The problem is that most normal users have no idea about any of this stuff, and no understanding of why they might want to switch.
- oh_sigh 5y agoRealistically most people just don't care the same amount that the subset of privacy-obsessed+techies do.
- anchpop 5y ago> Simple as that. Not quite? Maybe this will add more bits that will be useful for fingerprinting, but this seems like an absurd way for google to go about making it easier to fingerprint browsers, considering that most browsing happens over Chrome where Google can see what pages everyone visits anyway. And Google is currently proposing adding anti-fingerprinting measures [0] that observe how many bits of information a website has gathered and block API access after it reaches a certain threshold. A straightforward analysis of Google's motivations makes sense here: they want to keep their ad business profitable while improving their reputation on privacy. FLOC allows targeted ads, keeping their business profitable, and doesn't rely 3rd parties observing your browser history, improving privacy. From https://web.dev/floc/ https://web.dev/floc/ : > With FLoC, the browser does not share its browsing history with the FLoC service or anyone else. The browser, on the user's device, works out which cohort it belongs to. The user's browsing history never leaves the device. > There will be thousands of browsers in each cohort. A further privacy improvement is that they're designing it to avoid leaking whether you're a member of a "sensivitive category": > The clustering algorithm used to construct the FLoC cohort model is designed to evaluate whether a cohort may be correlated with sensitive categories, without learning why a category is sensitive. Cohorts that might reveal sensitive categories such as race, sexuality, or medical history will be blocked. In other words, when working out its cohort, a browser will only be choosing between cohorts that won't reveal sensitive categories. [0]: https://techcrunch.com/2019/08/22/google-proposes-new-privacy-and-anti-fingerprinting-controls-for-the-web/ https://techcrunch.com/2019/08/22/google-proposes-new-privac...
- slver 5y ago> Why is this bad? As the Electronic Frontier Foundation explains in their post “Google’s FLoC is a terrible idea“, placing people in groups based on their browsing habits is likely to facilitate employment, housing and other types of discrimination, as well as predatory targeting of unsophisticated consumers. All of this has been happening with tracking cookies, fingerprint tracking, pixel tracking and so on. And will continue to happen. I find it so bizarre it took Google to talk about phasing out 3rd party cookies and replacing it with a much lesser technology in the face of FLoC, for people to suddenly be all up in arms about it.
- jffry 5y agoThird party cookies, love them or hate them, have been with us for a long time, and simply dropping them would not be viable without the long phase out. And a long phase out is not something around which you can form a singular rallying cry. FLoC is a new thing which is just being rolled out, so it's a lot easier for people to resist adding a new thing that makes the internet more crappy and less private. I think it's unnecessarily fatalist to say that all of this will continue to happen so what's the point of resisting it. Public awareness and negative opinion of the pervasiveness and creepiness of internet tracking continues to grow, and advocacy against tracking mechanisms helps create the type of groundswell which could actually shift public policy to forbid such tracking. Google specifically is catching some heat for potential antitrust problems, so raising a ruckus about Google abusing its dominant browser position to cram FLoC into the internet is more likely to have positive effect than ever before.
- slver 5y agoIf you have figured out a way to eliminate tracking, be my guest. Mozilla would like to know, Apple would like to know. Until then FLoC attracts attention because it's new, yes, this explains our reaction. It's still an irrational reaction. Also what's this "predatory targeting of unsophisticated consumers" about? You don't need targeting for this. Heck you don't need anything for this. The way it's usually carried out is you hack some sites and redirect them to you landing page about "this one magic trick to riches, banks hate her".
- rattray 5y agoAh come on. The FLoC proposal has built in ways to turn it off. If you don't wanna be put in a cohort you can just configure your browser (even chrome) to say you don't have one.
- dannyw 5y agoIf it's not opt in, it's malware and should be treated as such. Don't let Google gaslight you.
- deleted 5y ago[deleted]
- rattray 5y agoI'm not going to let anyone gaslight me. Features of a browser that aren't opt-in aren't definitionally malware. User agents, for example, or even cookies, are not malware by any reasonable definition of the term. They present risks to the user and must be managed, but this is bounded.
- mark_and_sweep 5y agoIt's sort of opt-in. For websites, FLoC cohort computation only triggers if you call the document.interestCohort API or load ads - these actions are considered an opt-in. (https://github.com/WICG/floc/issues/103 https://github.com/WICG/floc/issues/103) For users, it's sort of opt-in, too: You must be logged into a Google account, must have enabled Chrome history data sync, must not block third-party cookies, must have enabled Google web activity tracking and must have enabled ad personalization. (https://github.com/WICG/floc#qualifying-users-for-whom-a-cohort-will-be-logged-with-their-sync-data https://github.com/WICG/floc#qualifying-users-for-whom-a-coh...) Also, you can disable FLoC via chrome://settings/privacy or chrome://flags. (https://github.com/WICG/floc/issues/103#issuecomment-821814605 https://github.com/WICG/floc/issues/103#issuecomment-8218146...) It's not a perfect opt-in, but it's also not malware.
- bagacrap 5y agoI believe what you are reading is ways that sync of floc classifier is disabled. That is, Chrome won't save the floc classifier in the cloud if sync is disabled, but, like history, will save it locally even if sync is disabled. (Assuming the setting isn't turned off.)
- golemiprague 5y agoIf it is a security concern why he mention there racism, sexism and LGBT stuff? Isn't it a concern for any person with no relation to those groups? or is is there some political underlying thing going on which I should be aware of? When I see those terms I get an immediate suspicious feeling that someone is trying to manipulate me.
- Havoc 5y agoHonestly I’m starting to think treating google like a security concern is the answer here. Lately their moves have been actively open web hostile. See AMP etc
- Forge36 5y agoI've not been following this proposal closely I did find https://github.com/WICG/floc https://github.com/WICG/floc >Tracking people via their cohort >A cohort could be used as a user identifier. It may not have enough bits of information to individually identify someone, but in combination with other information (such as an IP address), it might. Whose purpose is: >A FLoC cohort is a short name that is shared by a large number (thousands) of people, derived by the browser from its user’s browsing history. I wonder if it's possible to define a large enough number X that people are OK with the idea. (Cookies are effectively "1" and nothing is "3,010,000,000" ie on the internet) Could the cohort minimum size be configurable? Given the IP address can be known today: what's the existing accidental "FLoC proxy" or "How unique are you online?" Or "online finger print" (something I'd not thought of before: my timezone can significantly narrow down who I am) You can try using yourself on: https://amiunique.org/fp https://amiunique.org/fp
- nightpool 5y ago"Could the cohort minimum size be configurable?" this is a good idea, but unfortunately it would just lead to MORE ways to track users, since "size of cohort" is now a (probably very, very high entropy, given how many users never configure anything) source of information
- oh_sigh 5y agoThe benefit of FLoC is that you will need to go out of your way to track and de-anonymize your users. Yes, it can probably be done with enough data. But it is literally the simplest operation in the world with 3P cookies, so simple that tracking users across the internet may just happen on accident. That is unlikely to happen with FLoC.
- pabs3 5y agoAnyone know if there has been any research into the relative value to people placing advertisements in content-targetted vs person-targeted ways?
- isahabib49 5y agoGood
- loldk 5y agoThis is a tu qoque rationalization, but at this point I could care less. We're already being tracked & targeted by people we should've been able to trust. We've all seen the damage that anonymity can do. I changed my mind. I used to support EFF.org in many of their stances, but at this point it seems inevitable that everyone will be forced out into the open online and forced to use their real identity online to put an end to the endless information warfare. Unless someone can convince me that all this garbage we have going on now is somehow worth hanging onto. I'm open minded, but dudes and dudettes... what in the actual fuck is going on with social media, bot nets, people with dozens or more accounts manipulating online reviews and swaying elections in favor of nazis. It has to end.
- alkonaut 5y agoI wish someone at Google said "We have this idea that would significantly improve user privacy, and that's through means that would fundamentally hurt our possibility to deliver ads". Or facebook saying "we have this idea that would improve the experience on our platforms, and we think it's a great idea despite hurting our ability to grow, show ads and our short term bottom line. It actively discourages 'engagement'". If I had any stock in either company I'd still be delighted about these. I think it's the best long term growth strategy they can have. Focusing not on growth but on users and goodwill.
- pradn 5y agoThe FLoC debate is pretty binary - you're either for it or against it. I think it's better to frame the debate as "how much tracking entropy should browsers provide?" Tracking entropy is log(cohort you're in). So if a service can tell you're in a group of 1024 users, tracking entropy is log2(1024) = 10. The cohort you're in currently determined by 1) third-party cookies 2) fingerprinting techniques. Removing third-party cookies and introducing FLoC will probably reduce the entropy provided by the user. Recall that the FLoC proposal aims to put each user in a group of several thousand other users. That's about 12 bits of entropy. A third-party cookie would probably provide more, though I don't know the number off the top of my head. You only need log2(3 billion internet users) = 32 bits to identify every internet user hyper-precisely. So, moving to FLoC probably reduces the tracking entropy provided by the user. But it still leaves fingerprinting as a viable way to identify users. Even if both third-party cookies and FLoC were eliminated, there would still be fingerprinting. So, I think the Google approach is "provide a minimum tracking entropy via FLoC, and try to bound maximum entropy by limiting fingerprinting." Privacy advocates want a world where browsers try aggressively to limit tracking entropy, perhaps ideally eliminating it altogether. See the "privacy budget" mentioned here for a similar idea: https://blog.chromium.org/2019/08/potential-uses-for-privacy-sandbox.html https://blog.chromium.org/2019/08/potential-uses-for-privacy... Disclaimer: I work at Google.