35 ms·
Blocking FLoC is as easy as adding this header to the HTTP response: Permissions-Policy: interest-cohort=() Source: https://www.drupal.org/project/drupal/issu
by c0nfused 5y ago
Blocking FLoC is as easy as adding this header to the HTTP response:
Permissions-Policy: interest-cohort=()
Source: https://www.drupal.org/project/drupal/issues/3209628 https://www.drupal.org/project/drupal/issues/3209628
- TheRealDunkirk 5y agoSo, wait. We add this into the headers, and just expect Chrome to respect it?
- sodality2 5y agoIt's that or stop using Chrome
- gpm 5y agoThe website is really a third party here, the browser is choosing to track users browser history and report a summary statistic on it to anyone who asks, there's nothing the website can do about that. Chrome has promised to listen if websites say they don't want to be included in the browser history they calculate that statistic on, but it's all client side, there is nothing the website can actually do but request that they aren't included.
- SquareWheel 5y ago> the browser is choosing to track users browser history and report a summary statistic on it to anyone who asks It doesn't work that way at all.
- gpm 5y agoReally? Because that is how googles documentation says it works: https://web.dev/floc/#how-does-floc-work https://web.dev/floc/#how-does-floc-work
- SquareWheel 5y agoNowhere in this document does it claim that a summary of your browser history is being sent to websites. It explains the actual process of how cohort IDs are generated and used.
- gpm 5y agoA cohort id is literally a summary statistic... I think the problem here is just one of language, a summary statistic is a number calculated from a set of data that gives you some idea of the contents of the data, but condenses it in a way that you can't reproduce the original data. Common examples for numeric data sets are things like mean, mode, median, standard deviation. Common examples for data sets consisting of a finite list of strings (such as browser history) would be things like average length, character frequency, count, etc. The cohort id generated is unambiguously such a summary statistic.
- SquareWheel 5y agoI think language could be an issue here, but the problem as I see it is that cohort ID doesn't contain even a summary of the data. It's really just a number. The website or ad network is able to read those numbers and build profiles on them, but it's still divorced from the user and their specific data. I think a better comparison is that of a hash. It sums up the data, but is just a unique identifier for it. Of course with a cohort ID it's non-unique (by design). Because the browser is only sending a number, it retains the ability to change, randomize, or obscure that number. That's an important privacy consideration of the system. For what it's worth, I do think more work is needed. One of Mozilla's suggestions which I liked was to automatically send a missing ID on occasion, just to keep things a little hazy and reduce fingerprinting viability. Fingerprinting is inherently less-necessary as a result of FloC, and you need to balance it to not become necessary again, but it's a way to protect users that fully opt-out without themselves become fingerprintable.
- 8note 5y agoBased on https://web.dev/floc/#floc-server https://web.dev/floc/#floc-server it looks exactly like an ml class, rather than a hash. Almost certainly your browser history is summarized into a vector, and then the closest class number is chosen and sent. You might not know which vector the number represents, but it does represent a vector for the centroid, and has relationships with other cohorts. I'd say it's guaranteed that that interface is leaky
- anchpop 5y agothat’s my understanding of how it works too. could you explain?
- SquareWheel 5y agoRather than the browser sending a summary of your history, it calculates a cohort ID. That ID is sent to websites, and the website then has the job of associating IDs with interests. So instead of building a profile on specific users, the website (or ad network) builds profiles on cohort IDs. Users can change IDs, or mask theirs altogether if they wish.
- warkdarrior 5y agoSo we'll have to trust Google's browser will respect all website's headers that request not to be included in the cohort tracking. Just like Google respected Safari privacy settings. https://www.eff.org/deeplinks/2012/02/time-make-amends-google-circumvents-privacy-settings-safari-users https://www.eff.org/deeplinks/2012/02/time-make-amends-googl...
- SquareWheel 5y agoChromium is open-source. It's trivial to see if it's respecting the header or not. DNT was DOA. You can blame Microsoft for that one.
- bserge 5y agoHey, it worked with robots.txt all this time :D
- MiddleEndian 5y agoReminds me of when people naively expected "Do Not Track" to be respected lol
- iaml 5y agoI've seen people say dnt could be ignored because it's off by default in some configurations(safari), and user did not make a choice. Would be interesting to see what kind of mental gymnastics these people would apply here to ignore user's opinion.
- ratww 5y agoYep. Microsoft enabling it by default in IE10 was the default excuse for most of the advertisement industry to never start respecting it.
- renewiltord 5y agoWe actually respected DNT at an ad tech company I worked at and people still gave us grief for "tracking" them. We literally just 200'd the request immediately for all DNT requests. No processing, no tracking, nothing. Hilariously, I even opposed removing the code later because I wanted us to be a good citizen but it was practically dead code because people were still calling us evil. They could literally set their UA to play along (or use one that set it by default). I think we always kept the code in but it only incurred cost and we got blamed anyway. I think, looking back, I should have just removed that piece of middleware since no user ever really cared. It wasn't worth it for the org to pay for code so I could have a clean conscience.
- 8note 5y agoIsn't there a response code for no change? Saying you did something doesn't help the user know that DNT was followed
- renewiltord 5y agoWe tried 202 and 204 and both led some UAs to show broken image placeholders. But during the time we did that people assumed that we were tracking them just incompetently ("Look! They've revealed themselves!" style). Maybe we tried some other codes but anything but 200 was unsafe to many UAs (you could 3xx but UAs would break on 304 too because the tracking pixel wasn't actually cached). Anything that led to UA breakage was verboten anyway on our side since we didn't want anyone to have a broken experience because they set DNT. That would have been bullshit. We were dumb-enough to handle P3P headers too (which AFAIK no one really used in the end). Lots of dead code. Ugh.
- Mizza 5y agoWhat else goes in this field? Can we all collude to flood Google's spybox with garbage data?
- gentleman11 5y agoYou might enjoy this project. Its a browser plug-in that submits random search queries over time to ruin the accuracy of companies tracking https://trackmenot.io/ https://trackmenot.io/
- yesbabyyes 5y agoIt's specified here: https://www.w3.org/TR/permissions-policy-1/#policy-controlled-feature https://www.w3.org/TR/permissions-policy-1/#policy-controlle... There is a non-exhaustive list of features/APIs here: https://github.com/w3c/webappsec-feature-policy/blob/master/features.md https://github.com/w3c/webappsec-feature-policy/blob/master/... Each feature takes an allowlist, specifying which, if any, origins can use the feature.
- stock_toaster 5y agothere is apparently no way to define a default disable either, so to turn off all the random features, the header becomes huge. https://github.com/w3c/webappsec-permissions-policy/issues/189 https://github.com/w3c/webappsec-permissions-policy/issues/1... What is happening in w3c?!
- robin_reala 5y agoA cynical view would be that Google paid large sums to advertise Chrome on prime time TV while sideloading it with Flash and Java installs, which lead to an outsize user base, which lead to outsize influence at W3C on specifications.
- deleted 5y ago[deleted]
- 1over137 5y ago>Blocking FLoC is as easy as adding this header to the HTTP response: That's "easy"?! How does my mom do that for her WordPress site?
- paxys 5y agoWordPress should do it directly.
- soperj 5y agoWordpress is doing it as a minor release, and backporting it. So it'll be opt-in to floc for all wordpress sites.
- lioeters 5y agoI hope they do decide to add the HTTP header to disable FLoC by default, unless site admins specifically opt in. From the discussion I've seen, it hasn't been decided for sure yet. Proposal: Treat FLoC like a security concern - https://make.wordpress.org/core/2021/04/18/proposal-treat-floc-as-a-security-concern/ https://make.wordpress.org/core/2021/04/18/proposal-treat-fl... Consider implications of FLoC and any actions to be taken on the provider (WordPress) front - https://core.trac.wordpress.org/ticket/53069 https://core.trac.wordpress.org/ticket/53069
- soperj 5y agoI don't see any of the sites mentioned actually doing that in their head. Can someone point me to how they're actually blocked? edit: ahhh i see it's in the http headers, not the head of the html. nvm.
- alphabet9000 5y agoI'm just curious -- are there any other commonly used HTTP headers that include the characters "()" at the end?