32 ms·
Privacy Analysis of FLoC
- ______- 5y ago> FLoC is premised on a compelling idea: enable ad targeting without exposing users to risk The second you open your browser you are exposed to risk. Many times I have had to tweak the default settings of my browser to comply with my (non paranoid) requirements. Basic things like putting DuckDuckGo as the default search engine, turning off various JS APIs like HTML5 Canvas, WebGL, using AD-blockers and other addons, tweaking about:config and hardening it, etc Call me a power user if you want, but all this hardening stuff should ship out-of-the-box.
- SimeVidas 5y ago> all this hardening stuff should ship out-of-the-box. I mean, Brave kinda does that. It’s much more “hardened” by default.
- LeoPanthera 5y ago"No, you shouldn't use Brave": https://web.archive.org/web/20210531085250/https://aspenuwu.me/blog/dont-use-brave/ https://web.archive.org/web/20210531085250/https://aspenuwu....
- slver 5y agoDisabling canvas...
- vlovich123 5y agoThe funny thing is that customizing your browser in this way can be its own kind of fingerprint.
- tylersmith 5y agoThat's the number 1 reason it should be the default.
- freebuju 5y agoNot happening. All those anti-tracking measures break websites more often than not.
- kevin_thibedeau 5y agoThey break sites that are broken by design. If a site isn't usable with html and css it's the devs fault. They don't get to dictate my browser's capability or assume I don't have special accessibility needs.
- throwaway2048 5y ago"more often than not" is a vast overstatement, it breaks a tiny handful of sites at best.
- wearywanderer 5y agoThat is flat wrong in my experience. I browse with javascript and CSS both disabled by default, using uMatrix. Only a minority of sites I browse require me to whitelist JS or CSS; maybe 1-in-10. Most newspapers and blogs do not require JS or CSS.
- pabs3 5y agoI note that uMatrix is archived, do you have a plan for when it stops working? (I'm also a user)
- wearywanderer 5y agoI fear I don't. Probably I'll end up using the web in general a lot less.
- ______- 5y agoYes but disabling JS as a default wipes out whole classes of attacks against your browser. On top of disabling JS, just a simple AD blocker like uBlock Origin greatly diminishes the amount of profiling. There is no silver bullet however. It depends on your threat model. If you really don't want to be tracked and profiled, using the Tor Browser Bundle is worthwhile, but even that is problematic since it's heavily surveilled (both at the entry node and exit nodes).
- passivate 5y agoRealistically, can you ship a website where everything happens client side? - reflow, adjusting layout, computing locations/sizes and whatnot. I am not a web person so my thinking may be outdated on this. I'm imagining something like a stand-alone self-contained "docker" type thing.
- freeone3000 5y agoThat's how most websites work. The JavaScript code that runs on the browser then reports back to a server, because it makes money for the people who wrote the app.
- passivate 5y agoYeah, I meant without the 'reporting back to a server'. Like for e.g., the website sends a 'package' to the browser - The package is built on the fly and contains all the dependencies. The package is then unarchived and files are opened in the browser w/o the server being involved.
- yoz-y 5y agoThat is the standard static html + css + JavaScript without further requests. Aka Web 1.0. (Should you make all in one page with inline images that is)
- freeone3000 5y agoThen how are the people who wrote the app supposed to make money by selling your personal information to advertisers?
- thanhhaimai 5y agoOpinions are my own. I'm not sure if we're being led to focus on a wrong problem. I hate intrusive Ads as much as everyone else. However, it's not only that "when you open your browser, you are exposed to risk". It's also: - Every time you use Windows (without turning off all the bad settings) - Every time you connect to a Cell tower (telcos openly sell your location data) - Every time you use your credit cards Now, I'm not saying those are OK, or to justify intrusive Ads. However, I see a magnitude difference in the "violation of my privacy" for the above cases. The media and certain communities keep focusing on Ads tech because it drives clicks. But then we let the Telcos, Insurance, and Credit Card companies establish a creeping normality on our privacy violation. We don't spend as much effort to stop Telco from directly selling our location data [1], but we have daily threads about companies indirectly use our location data for targeting Ads. Are we having our priority wrong? I couldn't shake the feeling that we're being led by a different narrative. The best situation of course is when we have good privacy laws and practices. However, focusing on the wrong priority like this is how we let other (much more severe) violators (Insurance, Telcos) get away with their creeping normality. [1] https://www.marketplace.org/2020/02/28/fcc-set-to-fine-big-telecom-companies-for-selling-location-data-is-200-million-enough/ https://www.marketplace.org/2020/02/28/fcc-set-to-fine-big-t...
- aboringusername 5y agoIt doesn't matter anymore. The world is literally covered in tracking technologies from satellites orbiting the earth to radiowaves that are invisible to us but are monitoring our interactions within the world. By existing in 2021 (whether you use computers/tech or not) you need to accept your data will be collected, analyzed and sold. It will be leaked, combined/processed and abused in many different ways. I would be surprised if there was a single human on earth Facebook did not have a profile on at this point. I'd suspect the NSA can bring up the profiles of all 7 billion humans and recollect their entire lives from the digital/physical breadcrumbs they leave every day. Now that we can collect so much data, so rapidly (at the speed of light) and can analyze it in real time and store it forever it seems every digital application is focused on obtaining that valuable information and storing it to use in some way (usually, for profit). Even electric cars require apps and digital connectivity before they can be used/charged. Data is the new gold.
- dang 5y agoOngoing related thread: Ad tech firms test ways to connect Google’s FLoC to other data - https://news.ycombinator.com/item?id=27459247 https://news.ycombinator.com/item?id=27459247 - June 2021 (183 comments)
- jonchang 5y agoThis is a summary of the more detailed findings in their paper, which I found easy to read and has some intriguing suggestions for fixing privacy issues with the original proposal: https://mozilla.github.io/ppa-docs/floc_report.pdf https://mozilla.github.io/ppa-docs/floc_report.pdf
- justinplouffe 5y agoWhat bothers me the most about FLOC is that there is no reason or advantage for me as a user to run it unless I'm forced to. Cookies, even if they get hijacked for tracking, are genuinely useful to persist state and having them on results in a better experience. Even in the case of something more invasive like DRM/EME, I might want to turn it on in exchange to be able to watch some new show on a streaming service. Turning on FLOC brings nothing to the user in return and feels like charity towards advertisers.
- md_ 5y agoIsn’t the DRM comparison exactly right, though? Improving ad targeting enables an ad-supported online ecosystem. Admittedly, there’s a tragedy of the commons issue: I have no individual incentive to enable FLOC. But, similarly to your DRM example, at some point publishers could require it, no?
- no_time 5y ago> at some point publishers could require it, no? They could. However they wouldn't have a way of enforcing you play along and don't have a separate floc ID for every site you visit
- jedberg 5y agoI like personalized ads. If I have to suffer with ads to support the websites I like, I'd rather have them personalized. Instagram is really good at this -- I probably click on at least 1/4 of the ads I get, and have definitely made purchases based on Instagram ads. So as a user, the benefit would be better ads. Honestly I'll probably leave FLOC on if given the option (although I use Firefox and Safari, and as far as I know neither will really support it).
- throwaway2048 5y agoHN is the only place on the internet I've seen people expound their love for personalized advertising.
- aboringusername 5y agoIt's really a genius level move by Google here. Get rid of the cookie, implement your own solution, make it seem somewhat unique and rely on other data to identify users and claim impunity since it's nothing to do with them. So how about this, Google must not, and cannot implement FLOC without it being a cross-browser standard; that is to say if anyone of Microsoft, Apple or Mozilla veto FLOC, it's dead. This is how standards are supposed to work. Google should not be given the power to make a thing (like AMP) and just force it upon everyone. We MUST start regulating Google's every product development, I'd rather it get held up for a year in court before it sees the light of day.
- dmitriid 5y ago> So how about this, Google must not, and cannot implement FLOC without it being a cross-browser standard; that is to say if anyone of Microsoft, Apple or Mozilla veto FLOC, it's dead. Google couldn't care less about "cross-browser standards". They've been ramming Google-designed and Google-authored "standards" through standards bodies for years now, and increasingly disregard any objections from other browser implementors. And, sadly, there are only two browser implementors left that have any relevance: Safari and Firefox.
- bingidingi 5y agoGoogle has zero incentive to adhere to any standards because they already own the majority of the browser market. The fact that Google is an ad provider and a browser vendor and trying to implement a browser-level tracking API is very alarming. As mentioned in the Mozilla analysis, Google is also saying that they're who determines which sites are considered "protected" categories... which is the cherry on top of all of this nonsense. I'd really like to understand how someone working on this thinks that it improves the web for everyone... not just Google.
- jefftk 5y ago> Google must not, and cannot implement FLOC without it being a cross-browser standard; that is to say if anyone of Microsoft, Apple or Mozilla veto FLOC, it's dead. This is how standards are supposed to work. This isn't how internet standards work, or the how they have ever worked. Take the development of HTTP/2: [2009] Google researches how HTTP could be improved and develops SPDY: https://blog.chromium.org/2009/11/2x-faster-web.html https://blog.chromium.org/2009/11/2x-faster-web.html https://dev.chromium.org/spdy/spdy-whitepaper https://dev.chromium.org/spdy/spdy-whitepaper [2010] Chrome implements SPDY, and they start gathering real world performance data. [2011] Several rounds of iteration to make it faster, more reliable, and fix bugs. [2012] Major websites built out support, Firefox adds support, the process of standardizing it with the IETF begins: https://datatracker.ietf.org/doc/html/draft-mbelshe-httpbis-spdy-00 https://datatracker.ietf.org/doc/html/draft-mbelshe-httpbis-... [2013] More and more sites build support, CDNs enable it by default [2014] Safari adds support. [2015] Standardized as HTTP/2: https://datatracker.ietf.org/doc/html/rfc7540 https://datatracker.ietf.org/doc/html/rfc7540 Standardization follows cross browser support, and cross browser support follows single browser support. This is the path FLoC is following: it's currently incubated under the WICG (https://github.com/WICG/floc https://github.com/WICG/floc) and Chrome is developing it. Other browsers are paying attention and evaluating: that's what this Mozilla article is about. If at some point we get to a version that other browsers are happy with and choose to implement, then it could potentially be standardized. (Disclosure: I work on ads at Google, speaking only for myself)
- tomrod 5y agoFLoC: micro market segmentation. Profiles versus data. It requires on 33 bits to uniquely identify an individual. [0]. I would be interested to learn whether FLoC employed k-anonymity measures, and their report on it. If I am retired, female, live in the 830* zip3, and own a sedan, it is probably hard to identify me. Add that I am Korean and am searching for thyroid cancer treatments on Tuesday at 8:43AM local, then I am way more identifiable. I don't understand how FLoC works, and how it gets around this type of intrusion. The only solution I am aware of is to dramatically limit the category depth. But that sort of defeats the purpose of micro market segmentation. And that's a good thing, IMO. [0] https://www.eff.org/deeplinks/2010/01/primer-information-theory-and-privacy https://www.eff.org/deeplinks/2010/01/primer-information-the...
- smoldesu 5y agoThe article you linked relies on low-precision guessing that only reduces the entropy in the system, but doesn't eliminate it. No reasonable jury would consider their 33 bits to be "uniquely identifiable".
- olliej 5y agoplenty of places don't have that requirement, and bias goes a long way beyond that. But more to the point, why should google, etc, get to know that about you?
- visarga 5y agoI'm worried the Floc fingerprint will be used to censure content from certain parts of the public. Will sites define lists of undesirables? Floc discrimination made easy? It can be used like the yellow badges.
- tomrod 5y agoRemember that's 33 bits right now. You can be represented, uniquely, by 33 chained 0s and 1s as a GUID with no loss of fidelity. Add to that ongoing observation over time compared to a FLoC profile and the FLoC profile is a huge boon to the bit increase. Think OutBrain a few years ago, who were egregiously intent on serving certain clickbait to certain consumer sets. With FLoC, your winnowing and funnel becomes much easier (rather than serving rotten banana ads with just one trick, you KNOW your consumer has a propensity for Dunkin Donuts and you can increase your ad coverage). Everyone wins but the product -- your eyeballs.
- djhworld 5y agoWill there be a way to turn this off as a user so I'm never included in any cohort calculations?
- eingaeKaiy8ujie 5y agoUse Firefox.
- villasv 5y agoYes, at least for now. Websites can also opt out entirely using HTTP headers.
- tyingq 5y ago"because FLoC IDs are the same across all sites, they become a shared key to which trackers can associate data from external sources" "FLoC leaks more information than you want" "The end result here is that any site will be able to learn a lot about you with far less effort than they would need to expend today." Hmm. From someone (Firefox Team CTO) that probably knows this space well.
- o8r3oFTZPE 5y agoIs there anyone on HN who believes Mozilla will not implement FLoC in Firefox. Mozilla has stated over and over that it is a firm believer in advertising as "essential" for the internet to survive. In practice, they never phrase it as an opinion or even an underlying assumption (that can be questioned), they try to state this as a "fact".[1] This is called advocacy. Mozilla is an advocate for online advertising. They derive their salaries from payments from a deal with an online advertising company and in return they send search queries on Firefox to that company. (This argument that ads are critical is total BS, IMO. The internet worked great without ads. It would work even better now. Anyone who tests these things can see the web without ads works much better than it does with ads.) What Mozilla really needs to state is that Mozilla believes online ads are critical to Mozilla's survival as an employer. If web browser authors and their bosses want to be paid, then they assume they must to sell out to advertisers. Why is there no privacy by default when using web browsers. This is why. 1. Note first sentence, underlying assumption, of Mozilla communications. This company is blinded by advertising payola and cannot see non-commercial use of the web as worth protecting. https://blog.mozilla.org/en/mozilla/the-future-of-ads-and-privacy/ https://blog.mozilla.org/en/mozilla/the-future-of-ads-and-pr... https://blog.mozilla.org/en/mozilla/building-a-more-privacy-preserving-ads-based-ecosystem/ https://blog.mozilla.org/en/mozilla/building-a-more-privacy-...
- GekkePrutser 5y agoYes I believe Mozilla will not implement FLoC or at least offer a way to turn it off.
- o8r3oFTZPE 5y agoIf Mozilla enables it by default but "offers a way to turn it off", this would still count as enabling FLoC. Google could enable FLoC in Chromium by default and then, correct me if I am wrong, the browsers based on Chromium would have to disable it. Mozilla of course is not based on Chromium. However, Mozilla does try to match Chrome feature for feature and Google also is the hand that feeds Mozilla.
- ruuda 5y agoGiven that the cohort id is computed client-side, FLoC also sounds like a nice opportunity to fool trackers. Why not send a random cohort id with every request? In the worst case they’ll fall back to conventional tracking techniques, in the best case it will add some noise to their data.
- rubyist5eva 5y agoI'll continue to just block everything, thanks but no thanks. I don't need or want any of this tracking garbage. I definitely don't want whatever Google is pushing.
- olliej 5y agoFLoC is inherently anti-user, it serves literally no purpose other than to support tracking, while breaking all current anti-tracking tech by mandating its user across domains (a nice solid break of Same Origin policy). That it came from google is hardly surprising, as they are hell bent on stealing every bit of information they can from everyone, whether or not that person has a relationship with them, let alone consented to the abuse. I would be stunned if FLoC lasted more than a few months in the real world before google just started using it as an additional source of entropy to spy on people across domains.
- google234123 5y agoRemoving effective ads from the internet would be even more anti user. I dont think most people will be happy when everything is paywalled effectively.
- olliej 5y agoThe abusive tracking hasn't made ads more effective. I mean it means advertisers spend more paying for bigger and noisier ads sure, but that's also anti-user. There's also nothing stopping ads from being relevant, when google started AdWords (when "don't be evil" was still a thing) you got useful ads based on what you were actually looking at. Now you getting nothing but repeat ads for something you searched for last week. that relevant ads requires spying and abuse is nonsense, and google's original destruction of the ad tech industry demonstrated that non-spying ads that were based on page content were more than effective enough. Of course your uid implies that at best you're a pro-google fan, if not an actual employee, so I don't see me convincing you of anything.
- imiric 5y agoThat's a false dichotomy. Paywalls aren't the only alternative to ads. If companies can come up with user-respecting business models, I'd be happy to support them. If their business is worth supporting.
- gerash 5y ago
- SquareWheel 5y agoThe article itself mostly just retreads existing thoughts, but the linked PDF is actually quite good. That might be the better submission URL.
- ridaj 5y agoWell that's a great argument that it isn't perfect, but the real question is whether it's an improvement. Is it better than the state of the art, which is everyone dropping a shit ton of completely untraceable cookies? For example the browser fingerprinting piece that they highlight is already a problem with or without FLoC. I don't have an opinion about FLoC per se but this piece feels like it's focused on finding flaws with it in the absolute, as if we didn't have pretty awful tracking now. I don't believe we can get to perfect, what with shadow browser fingerprinting techniques and all, I just want to know if it's an improvement.
- ByteWelder 5y agoIf all other fingerprinting techniques would magically disappear, then FLoC is an improvement. If other fingerprinting techniques stay, then it's actually worse, since there is now an extra data point to better identify users.
- doomslice 5y agoThis is the reason they're introducing FLoC in the first place: https://www.chromium.org/Home/chromium-privacy/privacy-sandbox https://www.chromium.org/Home/chromium-privacy/privacy-sandb...
- hda2 5y agoI doubt everyone behind a single household IP address is a homogeneous blob of interests. Their interests + the IP address will be enough to uniquely identify them if trackers are able to accurately identify a single home resident. Did google ever seek proper peer review for FLoC before they started testing it on people?
- lgats 5y agoHow does the browser determine the category of a website?
- yarcob 5y agoIf you peel away the buzzwords, FLOC is basically just your browser tracking you, and telling advertisers which ads you are most likely to click on. Google claims to do this in a way that preserves your privacy, but ultimately these are empty promises. There is no way to spy on people without being creepy. Many (most?) people don't want to be tracked at all, "privately" or not. It's such a pity that online advertising has turned in this direction. It started out so well intentioned! Search ads showed ads related to your search, Google adwords showed ads related to the content of the page you viewed. No invasive tracking necessary! And now we have come to this. Tracking everyone everywhere has become so pervasive that an operating system vendor has just announced this week that they are building a first party VPN into the OS in a desparate attempt to reduce this ubiquitous tracking...
- hyperhopper 5y ago> There is no way to spy on people without being creepy. What "creepy" is, is an entirely subjective opinion that changes from person to person. I'd say there are totally ways. When I go to a grocery store and swipe that card for a discount, I know it's just being used to correlate purchases and track me, but I don't view it as creepy at all. All they got from me was my payment information, but they literally already have that, they get that every time I swipe my credit card anyway. So what is creepy about me explicitly awknowleding I'm being tracked in a reasonable way when I'm in their store?
- yarcob 5y ago> I know it's just being used to correlate purchases and track me, but I don't view it as creepy at all. The creepy part is when people do things without telling you. That stores keep a record of your purchases when you swipe the card is probably not creepy. I'd assume most people assume that's what happens. But if they then share the information they collected on you with others, without asking for your explicit permission, that's where it's starting to get creepy. I'm not sure Chrome users are aware that their browser tracks every website they visit, create a profile on you, and then share that profile (in a supposedly privacy preserving way) with others.
- deleted 5y ago
- MikeGale 5y agoThis needs to be opt in. Both from a web site and from a user.
- loosetypes 5y agoI’ve read here that in prison, if inmates are learning to code without internet access that they’re given offline dumps of stack overflow. Or maybe offline Wikipedia in the library is a better example. I’d really like to be able to buy preloaded offline versions of certain websites to be able to use indiscriminately. For things like embarrassing questions which I might want to search for within a given subreddit without broadcasting it to who knows what systems. I don’t even necessarily care if there’s a result, or even if the information/responses/comments are a decade stale - i can live without current events. I just want the peace of mind that I’m not being observed. That’s something that I’d pay for.
- addingnumbers 5y agoFor wikipedia it's pretty easy if you've got even the most basic systems administration experience... https://en.wikipedia.org/wiki/Wikipedia:Database_download#Offline_Wikipedia_readers https://en.wikipedia.org/wiki/Wikipedia:Database_download#Of...
- visarga 5y agoNo matter how they dress it, the FLoC id gives away personal information. That's unacceptable.