4 ms·
> Reliably identifying a (unique) visitor is pretty difficult using ip logs, though. > Cookies generally make this much easier, at the very least identifying a
by chimeracoder 4y ago
> Reliably identifying a (unique) visitor is pretty difficult using ip logs, though.
> Cookies generally make this much easier, at the very least identifying a visit.
You don't actually need cookies to reliably identify unique users. Browser fingerprinting is very identifiable and difficult to obscure.
https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/
- minusf 4y agoif it was that effective, why wouldn't just google switch to it and stop wasting money on ideas like FLoC, and ditch 3rd party cookies?
- chimeracoder 4y ago> if it was that effective, why wouldn't just google switch to it and stop wasting money on ideas like FLoC, and ditch 3rd party cookies? First, I would be shocked if Google isn't using fingerprinting data in conjunction with cookies. But also, this comment misunderstands what FLoC was. FLoC was, at least in theory, an attempt to get the benefits of targeted advertising without uniquely identifying users. That's what the "C" in FLoC refers to - users aren't targeted individually, but rather by the cohort they belong to. FLoC unfortunately had many issues, one of which is that there were concerns that the cohorts were too granular and could still effectively denanonymize users. There's some research indicating that this was the case - FLoC cohorts revealed more info than they intended to, but also still less than individualized profiles do. The stated goal of FLoC was actually more privacy-focused than the status quo (individualized profiles). Unfortunately, that's not what ended up happening - or at least, the general public didn't trust that it was.
- minusf 4y agofingerprinting probably brings in more identifyable bits, but without the cookies it would not be commercially reliable data to determine uniqueness. i am aware what FLoC was and tried to be. it was a horrible idea with it's default optin putting onus on website operators to add headers to opt-out from a mass survelience exercise generating money for the surveillance capitalists.
- chimeracoder 4y ago> i am aware what FLoC was and tried to be. Well, you asked (perhaps rhetorically) why Google didn't switch to using fingerprinting instead of FLoC. And the answer is that FLoC and fingerprinting suit different use cases. Fingerprinting doesn't serve the goals of FLoC, and FLoC doesn't provide the same data that fingerprinting would.
- __turbobrew__ 4y agoYea on top of that you can fingerprint the TCP/IP/TLS settings of the user’s connection as an additional point of data: https://nmap.org/book/osdetect-fingerprint-format.html https://nmap.org/book/osdetect-fingerprint-format.html. My gut feel is that browser+tcp+ip+tls fingerprinting can get you pretty damn close to uniquely identifying users without needing cookies.
- nicbou 4y agoThis whole argument is irrelevant since the GDPR is not about cookies