18 ms·
Chrome is entrenching third-party cookies that will mislead users
- namdnay 2y ago> and even after third-party cookies have been deprecated in Chrome apparently this was written a few weeks ago :)
- pimlottc 2y agoCare to explain?
- Etheryte 2y agoChrome backtracked on the decision, they won't be blocking third-party cookies. There were a number of articles and a fair bit of discussion about it at the time, see e.g. [0] and [1]. [0] https://news.ycombinator.com/item?id=41038586 https://news.ycombinator.com/item?id=41038586 [1] https://www.theverge.com/2024/7/22/24203893/google-cookie-tracking-prompt-ad-targeting-privacy-sandbox https://www.theverge.com/2024/7/22/24203893/google-cookie-tr...
- IX-103 2y agoIt's complicated. Chrome won't block 3rd party cookies by default. But it will present the users with a choice of whether to block them (with what exactly that means TBD). If most or all users choose to block them then it would have roughly the same effect as blocking third party cookies by default would. Though regardless of that, Related web sites (or whatever that set is currently called) does present a hole in that logic. It was originally meant to allow sites with different domains to share cookies/storage (like google.com and google.co.uk). From what it sounds like, bad actors are using it in the expected ways. There were supposed to be mechanisms to prevent this, but it seems like they failed in this case. The list is in a public repository however, so Brave could have filled issues and a pull request to address the issue. Instead they decided to stage a meaningless survey and declare Chrome a threat to people everywhere.
- dwighttk 2y ago>If most or all users choose to block them then it would have roughly the same effect as blocking third party cookies by default would. Sure but most won’t unless the “go away now” button is “block” which I’m guessing Google wouldn’t do.
- jeroenhd 2y agoGoogle wanted to (that's why they created stuff like FLoC) but other advertisers didn't like that and went to the market authority. They demanded the ability to track users, arguing that the system would give Google an unfair advantage. After years of back and forth, Google abandoned their efforts. You can still disable third party cookies, in fact I don't think there's been a version of Chrome that doesn't let you block them. Go to your settings and set "third part cookies" to always be blocked. By default, grouped sites may be permitted to read each other's cookies, but you can disable that too. The problem Google faces is changing the default, simply blocking third party cookie has never been an issue.
- riku_iki 2y ago> and went to the market authority its interesting that authority is in UK, but they pushed Google to abandon effort globally.
- jsnell 2y agoAuthorities in the US, EU and (IIRC) Japan had expressed anti-trust concerns (threats?) about the original plan. The UK CMA is the only one of those that had a formal complaint, and thus ended up with a veto right on the new design.
- svieira 2y ago> We conducted a user study with 30 Web users, recruited over social media, and presented them each with 20 pairs of websites. Website pairs were randomly selected from both the Related Website Sets list (i.e., sites Google designates as “related”, and so warranting reduced privacy protections), and the Tranco list of popular websites. Each user was presented with different pairs of websites, asked to view the sites, and then decide if they thought the two sites were operated by the same organization. This resulted in 430 determinations of whether unique pairs of websites were related. > In our study, the large majority of users (~73%) made at least one incorrect determination of whether two sites were related to each other, and almost half (~42%) of the determinations made during the study (i.e., all determinations from all users) were incorrect. Most concerning, of the cases where both sites were related (according to the RWS feature), users guessed that the sites were unrelated ~37% of the time, meaning that users would have thought Chrome was protecting them when it was not. > ... We conclude from this that the premise underlying RWS is fundamentally incorrect; Web users are (understandably, predictably) not able to accurately determine whether two sites are owned by the same organization. And as a result, RWS is reintroducing exactly the kinds of privacy harms that third-party cookies cause. > Lest anyone judge the study participants for being uninformed, or not taking the study seriously, consider for yourself: which of the following pairs of sites are related? 1. hindustantimes.com and healthshots.com 2. vwo.com and wingify.com 3. economictimes.com and cricbuzz.com 4. indiatoday.in and timesofindia.com > (For the above quiz, if you chose “4”, then, unfortunately that is incorrect. That is in fact the only pair of the four that isn’t considered “related” to each other.)
- nsagent 2y agoIf anything it sounds like "related" is not what they are actually doing. Rather they are looking at ways to uniquely fingerprint users through optimizing how they split "related" sites. Reminds me of the research that shows that 87% of people in the US can be uniquely identified with only three pieces of information: date of birth, gender, and zip code [1]. [1]: https://dataprivacylab.org/projects/identifiability/paper1.pdf https://dataprivacylab.org/projects/identifiability/paper1.p...
- 2y ago
- hashtag-til 2y agoDoes this affect non Chrome users?
- judah 2y agoIt's a proposed web standard, so ultimately yes, it could affect other browsers in the long run. And it would almost certainly affect other Chromium-based browsers.
- IX-103 2y agoOnly other chromium web browsers that enable that feature. Safari and Firefox already said they're not implementing the feature, so unless they change their mind it's not going anywhere.
- thayne 2y agoIt's proposed, but it's unlikely to be accepted. Firefox and Safari have both said "no, we're not doing that". And then chrome decided to move forward with it, regardless of whether it gets standardized.
- troupo 2y agoSince Chrome dominates the browser market, they just pay lip service to the web standards process. They will have this as proposal, its status will be "not on any standards track", it will be shipped in Chrome, and enabled by default.
- tomComb 2y agoAs if brave were a good or objective source for this topic.
- neilv 2y agoDo you mean that Brave is a competitor, or something else?
- TylerE 2y agoBoth a competitor AND a history of operating in, to be polite, less than good faith.
- nicce 2y agoAs a competitor, let's add that they are ad company too.
- bad_user 2y agoName one browser that isn't funded by ads. Even the minor browsers, pretending to not be funded by ads at this point (while the VC capital is drying up) depend on one of the 3 browser engines, all of which are funded by ads.
- zimpenfish 2y ago> Name one browser that isn't funded by ads. Safari? Unless you're going to say that Apple gets the money for Safari through ads which, y'know, technically correct but disingenuous in this context, surely.
- bad_user 2y agoGoogle is paying Apple 20 billion per year in their search deal, which is 40 times more than what Mozilla takes. Safari is funded ENTIRELY by Google's ads, also making a profit, and this is a fact. We can entertain a counterfactual, maybe Safari would still be funded without Google funding it with billions, but that's not the world we live in today. And given Apple's reluctance to advance the web, going against their other cash cows, it's disingenuous to suggest otherwise. I recommend reading this opinion: https://infrequently.org/2022/06/apple-is-not-defending-browser-engine-choice/ https://infrequently.org/2022/06/apple-is-not-defending-brow...
- cabbageicefruit 2y agoDamn. If there was ever any doubt about why you should get off chrome, this seems to put an end to that.
- JonChesterfield 2y agoShed a tear for the Firefox that could have been
- rectang 2y agoFirefox is still working great for me, and I intend to keep using it for the foreseeable future. I don't know what it might take for people to migrate away from Chrome en masse, but the alternative is there.
- nicce 2y agoMozilla is slowly turning to ad company too. Let's see what future brings us.
- delfinom 2y agoI mean...they have to fund operations somehow. There's no money in pure open source in today's society.
- yencabulator 2y agoMozilla has a lot of money, almost none of which is spent on Firefox/Servo. https://lunduke.locals.com/post/4387539/firefox-money-investigating-the-bizarre-finances-of-mozilla https://lunduke.locals.com/post/4387539/firefox-money-invest...
- devrand 2y agoAnd the recent antitrust ruling against Google might see Mozilla lose like 80% of their revenue...
- nashashmi 2y agoI always thought that rws was built in with cross site scripting declarations
- acheron 2y agoPadme: So then Brave isn’t going to be based on Chrome anymore, right?
- topspin 2y agoBrave is a Chromium derivative, not Chrome. Can't imagine why any of this would imply they would need to stop deriving Chromium: they can develop and deploy whatever cookie policies and defaults they want.
- fabrice_d 2y agoAt this point they likely have no choice but to keep building on a chromium base. However the cost of maintaining their changes and additions will likely increase.
- topspin 2y agoI suppose. That is a matter of business model, whereas I was addressing purely technical aspects. I've been using Brave as primary for years. At this point I'd pay for a license if it were necessary. Frankly that would be an improvement: if it's free, you're the product. Brave just monetizes you differently. I no longer argue with the legion of Brave haters. I've decided they're a benefit: the more people that don't use Brave the less likely Google et al. will be compelled to destroy it.
- nicce 2y ago> Can't imagine why any of this would imply they would need to stop deriving Chromium: they can develop and deploy whatever cookie policies and defaults they want. Maintaining a very diverged fork can take even more work than building your own browser. I think they don't want to stop receiving upstream updates when the upstream is one of the biggest software projects in the world.
- kevwil 2y agoNot to disagree with you specifically, but this seems a good context to make this point: Maybe I missed the memo that we stopped hating monopolies? Every browser worth considering, except Firefox and Safari, is based on Chromium. Firefox and Safari make up about 20% global market share, meaning Chromium in about 80% [0]. A bug in Chromium is a bug in all of them. A backdoor in Chromium is a backdoor in all of them. A feature of Chromium, good or __bad__, is a feature in all of them. It baffles me that this isn't a bigger concern to more people. [0] https://gs.statcounter.com/browser-market-share https://gs.statcounter.com/browser-market-share
- aftbit 2y agoI know this isn't quite the right place, but can anyone point to some research or writeups on the Chrome ad topics stuff? How does that impact user privacy? What is shared with third parties? I know next to nothing about it at the moment.
- deleted 2y ago[deleted]
- afavour 2y agoThis is a great paper on how it doesn’t make reserve privacy in the way Google claims it will: https://arxiv.org/html/2403.19577v1 https://arxiv.org/html/2403.19577v1
- pennybanks 2y agoso do they mention if the old system would be better in comparison? cause short of just making you pay to use the products i dont know if it can be any worse. at the end of the day it seems like 90% of people using google products dont even care. while some even prefer the convivence of some features that directly save your info. not sure what percentage that is compared to the people that practice a lot privacy. but shown by the chrome market share google really doesnt have to care about this section of users. the fact theyre willing to try things is a good sign imo. either way in 2024 to be complianing about google is funny to me. literally dont have to interact or use a google product, they already have your information and so does the internet better to not let them occupy any of your mind as well
- yohhaan 2y agoHi! I am the main author of 2 papers evaluating the Topics API from Google: [1] and [2] and working on more research in that space. I have also started compiling different papers and analyses on projects like the Privacy Sandbox initiative from Google (https://privacysandstorm.com/proposals/ https://privacysandstorm.com/proposals/) as well as releasing other resources (datasets, tools, etc.), contributions welcome if you are interested! Best, Yohan (https://yohan.beugin.org/ https://yohan.beugin.org/) [1] Interest-disclosing Mechanisms for Advertising are Privacy-Exposing (not Preserving) https://petsymposium.org/popets/2024/popets-2024-0004.php https://petsymposium.org/popets/2024/popets-2024-0004.php [2] A Public and Reproducible Assessment of the Topics API on Real Data - https://arxiv.org/abs/2403.19577 https://arxiv.org/abs/2403.19577
- knallfrosch 2y agoI don't care because I use Firefox.
- immibis 2y agoFirefox will either support this or your favorite websites won't work so you'll switch to Chrome so they do work.
- kstrauser 2y agoUnlikely. Love 'em or hate 'em, Apple nudged most organizations to handle third party cookie blocking unless they wanted to completely lose iPhone users. "If Google limited 3rd party cookies, we'd go out of business!", said the companies who have literally 0 Safari users.
- JohnFen 2y ago> or your favorite websites won't work If my favorite websites stop working with Firefox, they won't be my favorite websites anymore. I'll just stop using them instead.
- reaperducer 2y agoI'll just stop using them instead. Easily said, until it's your bank, or a government entity, or the electric company, or any of the thousands of other entities that have started blocking Firefox. Firefox should really camouflage its user agent, or make it trivial to do so.
- JohnFen 2y ago> Easily said, until it's your bank, or a government entity, or the electric company Still easily said, since I don't use the websites for any of those things anyway. If it's really important, or involves very sensitive personal information, I'm not doing it on the web. > or make it trivial to do so. There are extensions that make this very trivial.
- JohnFen 2y agoThat seems the obvious result of this sort of thing. > Related Website Sets (RWS) is a way for a company to declare relationships among sites, so that browsers allow limited third-party cookie access for specific purposes. So the website itself gets to declare other "blessed" domains that can bypass third party cookie blocks? Big websites are constantly looking for ways to abuse users by bypassing their attempts at protecting themselves. How would anyone think these sites can be trusted not to abuse this?
- jahewson 2y agoNo, the website itself does not get to declare this. There’s a master list that they have to submit their site to and go through an approval process. But as the article details, the contents of that preliminary list is already disconcerting. The whole “Google as the arbiter of all things ads” concept is a bust. But the alternative isn’t great either - today’s system of third party cookies allows for far worse. We need some better ideas.
- deleted 2y ago[deleted]
- klabb3 2y ago> There’s a master list that they have to submit their site to and go through an approval process. Wtf, seriously? I skimmed the post and honestly didn’t think RWS was so bad, assuming that obviously it would be decentralized. A centralized list that Google (or some shell consortium) controls is the biggest no-no. Decades of erosion of web principles have clearly made us complacent.
- JohnFen 2y ago> There’s a master list that they have to submit their site to and go through an approval process. How is that not the website declaring it? Approval processes are meaningless. > today’s system of third party cookies allows for far worse. That's why I want zero third party cookies.
- 2y ago
- callmeal 2y agoI guess it's time to start blocking /.well-known/related-website-set.json
- bradley13 2y agotl;dr: Google is evil. The antitrust measures cannot come soon enough.
- deleted 2y ago[deleted]
- codedokode 2y agoHave been using Firefox for a long time, no issues, though long ago when I had little memory, Chrome was using less of it. Firefox also has HTTPS-only mode, encrypted DNS without fallbacks, supports SOCKS and Encrypted Client Hello (although almost no website support it). However, it is better to just buy more memory (unless you are lucky to use Apple products). Regarding analytics, I believe browsers should take user's side and do not cooperate with marketing companies; even better, they should implement measures to make user tracking and fingerprinting more difficult. There is no need to track user's browsing history; just make a product better than competitors (so that it gets first place in reviews and comparisons) and buy ads from influencers. It would be great if browsers made fingerprinting more difficult, i.e.: not allowed to read canvas data, not allowed to read GPU name, enumerate audio cards, probe for installed extensions etc. Every new web API should guarantee that it doesn't provide more fingerprinting data or hides the data behind a permission. Regarding 3rd party cookies: instead of shady lists like RWS browsers should just add a button that allows 3rd party cookies as an exception on a legacy website relying on them (which is probably not very secure). Although, there is a risk that newspaper websites, blog websites and question-answers websites will force users to press the button to see the content.
- lcnPylGDnU4H9OF 2y ago> Every new web API should guarantee that it doesn't provide more fingerprinting data or hides the data behind a permission. FWIW, it's practically impossible to provide that guarantee because the API necessarily provides at least the data point of, "Did they select an option in the permission notification?" ("If yes, what option was selected?" etc.) It's often said that the only solution to this is regulation and there seems to be a good case for that perspective.
- XlA5vEKsMISoIln 2y ago> API necessarily provides at least the data point of, "Did they select an option in the permission notification?" If a bird app (or, heck, pancake recipe site) asked for WebRTC or GPU access I would be rightfully suspicious. It's a shame these things don't happen.
- doo_daa 2y agoI've tried brave and Firefox on mobile (android) and I've tried Safari on MacOs. I still just prefer Chrome, it's just a bit better. So I use it with third-party cookies turned off, which is easily (and transparently) done using the settings menu. I can also turn off this "related websites" thing. So what exactly is the problem? All major browsers have allowed users to turn off 3P cookies for years.
- b59831 2y ago[dead]
- ssss11 2y agoGoogle doing something not in the interests of their users? Shock
- mrwww 2y agoFirefox for mac and firefox focus for iOS is great.
- thayne 2y agoThis is a tough situation. Yes, this can, and will, be abused for tracking users across domains that they don't expect to be related. But there are also legitimate use cases for this. For example, consider the stackexchange family of sites. They are clearly related, have a unified branding, etc. but are on separate domains. On Firefox, which blocks third party cookies, I have to log in to each of those domains separately. I can't log in to stackoverflow.com, then go to superuser.com and already be logged in. That is a problem that First party sets would solve. You can argue that it would be better for those sites to be subdomains of a single unified domain, but when the sites were created there wasn't any compelling reason to need to do that, because third party cookies were still very much alive and kicking. And I can say from experience that migrating an app to a different domain without breaking things for users is a royal pain, and can be very expensive. I'm not saying that First Party Sets should be accepted as is, but it is attempting to solve real problems. And I think a solution that simultaneously protects users' privacy and maintains a good experience for sites that are legitimately related will be difficult to find, or maybe impossible.
- muratsu 2y agoThis reminds me how google conveniently made the switch to manifest v3 when there were legitimate use cases like adblockers. Sure, technically speaking v3 is more secure and that may be better for users but your comment just made me think the opposite is in motion here.
- renegat0x0 2y agoIn politics there is a Churchill quote "Never let a crisis go to waste". In IT, big tech never wastes opportunity to introduce a dark design behind a useful feature.
- tyingq 2y agoAlso see "Patriot Act".
- matheusmoreira 2y ago
- martinald 2y agoThis seems quite out of date given Google has announced they are not deprecating third party cookies recently? Or am I missing something?
- _933hs_ 2y ago[flagged]
- bugtodiffer 2y agoHey Google, this site is the password change site for Google. Is that enough rationale to add this to the list?
- andresp 2y agoMost people here seem to forget that ads is what pays for the free internet services. The main issue with them is not making the consent more explicit to the user. I think the business model: you either get this for free with ads and targeting, or otherwise you have to pay X, should be more common. I bet most people would pick the free option with ads and targeting.
- troupo 2y agoYou don't need pervasive and invasive targeting to run ads. Google earned billions of dollars with their contextual ads long before pervasive tracking was a thing.
- JohnFen 2y ago> Most people here seem to forget that ads is what pays for the free internet services. Nobody forgets that, and the issue (at least for me) isn't the ads, it's the spying. It's entirely possible to have a financially healthy ad ecosystem without the spying. It used to be the norm, even.
- enhancer 2y agoPeople re leaving chrome more and more. Let's hope the trend continues
- styfle 2y agoDoes Google expect other browsers to just copy their list[0]? Or are developers supposed to submit their related domains to each browser and they all have their own list to maintain? This sounds like HSTS. [0]: https://github.com/GoogleChrome/related-website-sets/blob/main/related_website_sets.JSON https://github.com/GoogleChrome/related-website-sets/blob/ma...