Live data from Hacker News

WebKit Tracking Prevention Policy

webkit.org

41–50 of 254 posts

Re: WebKit Tracking Prevention Policy

#41
post #21

Given the definition of cross-site tracking and the note on single-site analytics in Unintended Impacts, is it safe to say this will impact all site analytics tools served by a 3rd party (eg Google Analytics, but really almost all "drop-in" frontend analytics)?

Google analytics still works since it uses first party cookies but you lose data on repeat vs new visits.

There are ways to make GA work around these limitations, but it requires more work than just dropping it in.

Re: WebKit Tracking Prevention Policy

#42
post #40

So what is going to happen when Apple succeeds in making it impossible to make any money off advertisements shown to iOS users on the web? I'm currently imagining a future where publishers start to just redirect iOS traffic to install their app, where they can actually make money. Good news for the walled garden, I guess?

It is not impossible to advertise without tracking users.

Re: WebKit Tracking Prevention Policy

#43
post #40

So what is going to happen when Apple succeeds in making it impossible to make any money off advertisements shown to iOS users on the web? I'm currently imagining a future where publishers start to just redirect iOS traffic to install their app, where they can actually make money. Good news for the walled garden, I guess?

Yes. The walled garden of AAPL. Spend money in an app, Apple gets a cut. As it is, Google and Facebook get the revenue instead.

Re: WebKit Tracking Prevention Policy

#44
post #40

So what is going to happen when Apple succeeds in making it impossible to make any money off advertisements shown to iOS users on the web? I'm currently imagining a future where publishers start to just redirect iOS traffic to install their app, where they can actually make money. Good news for the walled garden, I guess?

perhaps they can just use advertising that doesn't involve tracking

Re: WebKit Tracking Prevention Policy

#45
post #26
post #12

Earlier quoted context omitted.

Indeed, the Gtk+ and WPE ports, as well as Sony's Windows port, are the most active after the Apple-maintained ones.

the browser in Steam client also uses webkit

No, it does not. Steam has been using Chromium Embedded Framework since 2010, so when Chromium moved to Blink (~2013), so did Steam.

Re: WebKit Tracking Prevention Policy

#46
post #40

So what is going to happen when Apple succeeds in making it impossible to make any money off advertisements shown to iOS users on the web? I'm currently imagining a future where publishers start to just redirect iOS traffic to install their app, where they can actually make money. Good news for the walled garden, I guess?

I’m way past the point of caring. Five years ago maybe I’d have been bothered, but targeted advertisement installs spyware on my computer, destroys its performance, and builds a profile on me that is begging to be exploited by hackers and/or the government. May it rot in pieces and to hell with the consequences, and if advertisers are unhappy that I’ve taken such an extreme position, they should examine how their behavior drove me to this point.

Re: WebKit Tracking Prevention Policy

#47
post #40

So what is going to happen when Apple succeeds in making it impossible to make any money off advertisements shown to iOS users on the web? I'm currently imagining a future where publishers start to just redirect iOS traffic to install their app, where they can actually make money. Good news for the walled garden, I guess?

Didn't people make money off internet advertising before the modern surveillance-marketing complex? What happened to it?

I mean, maybe the answer is that those ads were only profitable because of the novelty factor and now that we have metrics we know they don't work, or at least don't work anywhere close to how much they cost. But I do miss things like the webcomics running their own ad network, Google's textual ads based solely on the search query, even the text ads on Read The Docs from a few years ago, etc.

Also I assume / hope that iOS ads aren't tracking people either; third-party cookies simply have no equivalent in the iOS app sandbox design. (And in-app ads tend to be abysmally targeted in my experience, at best "You're playing a mobile game? Try this other mobile game with even more in-app purchases!") So why wouldn't similarly untargeted web ads work too?

Re: WebKit Tracking Prevention Policy

#48
post #36

Earlier quoted context omitted.

You're manually curating a specifically targeted mitigation list, but it's non-public. Mozilla/Edge's approach seems preferable, not problematic

We are not presently manually curating a specifically targeted mitigations list. Just saying we might in the future. We did do a one shot rollback of HSTS super cookie abuse in the past, but that’s it.

But it needs to be public. “Trust, but verify.”

Re: WebKit Tracking Prevention Policy

#49
post #27

Earlier quoted context omitted.

Well, how does a competitor make money on iOS without giving Apple a 30% cut of app installs and in-app purchases and/or using their ad network?

Simple, the same way that Spotify, Netflix, Amazon (Kindle), DirecTVNow, Sling, and a bunch of other companies do - force people to pay on their own websites to use the app.... Apple doesn’t have an “ad network”.

Only catch here is that Apple also takes a cut of such subscription revenue if it goes through an app [0].

Individually, I support Apple's decisions around enforcing privacy on the web. However, Apple's decisions when taken as a whole is making it incredibly difficult for a company to generate revenue from iOS users without sharing some of that revenue with Apple. Whether this makes Apple a monolopy I do not know, but it's certainly less clear of a good thing than their privacy efforts.

[0] https://www.theguardian.com/technology/2019/mar/13/spotify-c...

Re: WebKit Tracking Prevention Policy

#50
post #24

Would "Sign In With Apple" be considered a "Privileged Third Party" if they make sure it works but break other Single Sign On providers as an "Unintended Impact"?

I'm not sure what you mean by this; WebKit Tracking Prevention doesn't break third-party login. Third-party login works by handing a token back to the first party, who then stores it directly and validates it on the backend. After the initial login with the third party, the third party isn't involved anywhere that the browser can see. And the initial login happens in a browser window that's navigated directly to the…

TBH a browser prevents Medium from showing a Google iframe in the top-right corner with "Hi geofft, I know your name is geofft, please click the login button geofft," that would be delightful....
Post reply on HN