Live data from Hacker News

Google’s approach to replacing the cookie is drawing antitrust scrutiny

digiday.com

131–140 of 354 posts

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#131
post #50

Earlier quoted context omitted.

You mention nearly limitless options but fail to mention one. Can you give some examples?

It's data collection is in Chrome's DNA. They could just continue to collect data on browser usage, and then "sell" that data to Google. No need for sites to install Analytics into their website when they can get 100% of all site analytics viewed from within their browser.

A key difference here is that Chrome could sell aggregated analytics data for performance testing and such, but not allow the ad company to get user-targeting quality data. With them in the same company, this is a nearly impossible barrier to achieve.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#132

Earlier quoted context omitted.

Thanks, removed Chrome ages ago in favor of Microsoft's Edge (the new one). Microsoft is fast becoming the good guys. It sets a default tracking level of Balanced, which blocks trackers from unvisited sites - you may then make it more strict if desired, out of the box with no extra plugins required. https://support.microsoft.com/en-us/microsoft-edge/learn-abo...

> Microsoft is fast becoming the good guys I think it's probably about time we stop pretending any of these major tech corporations are good guys.

Exactly. At the end of the day, it is all about the money. If something isn’t making money, it is bound to be canned/changed sooner than later.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#133

Earlier quoted context omitted.

Yes it does. Users now have a unique IP address that is now static. Yes you can rotate your exact IP inside your block but you still keep the same subnet.

That is the promise they sold it on. But, point me to a single ISP that gives a cable subscriber more than one IPv6 address. or a /48 as initially everyone was hopping. ISP profit from NAT. They will never get rid of it. Even if you get a /54 /64 the ad networks will just learn to assign /54 as they do today. But, another point, ipv4 today is barred from being used to form your advertising profile under current legis…

Comcast gives you a /60 block that you can assign multiple /64's out of.

My computer rotates out IPv6 addresses every 30 minutes using SLAAC with privacy addresses.

While you can identify the /64, there is no guarantee that it is a single user, just like in IPv4 because of NAT there is no guarantee it is a single user. It'll identity a household, but that's it.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#134
post #80
post #67

Earlier quoted context omitted.

This is a good time to remind everyone that Google has planted a hard-coded "X-Client-Data" telemetry backdoor that is sent to DoubleClick domains, is never disclosed to users and is impossible to disable. The header, which is not available to any of their competitors, contains unique information about the install that could allow them to track people better than anyone.

Google's response to this allegation: https://9to5google.com/2020/02/06/google-chrome-x-client-dat... TL;DR, they claim that this header is sent to all Google-owned domains, and describes the feature flags that your browser has enabled, and it doesn't contain any PII. Oh wait They backpedalled on this by removing from the whitepaper their claim that the X-Client-Data field doesn't contain PII: https://vpnoverview.com…

[I work at Google, not on chrome]

The current text of the whitepaper is

"The combined state of these variations is non-identifying, since it is based on a 13-bit low entropy value (see above). These are transmitted using the "X-Client-Data" HTTP header, which contains a list of active variations"[0].

The X-Client-Data header is still described as non-identifying. You're reaching for controversy where there is none. I've had this conversation with GP before[1], and it's always unenjoyable, because it's like talking to a conspiracy theorist. There's no rational basis for Google doing what you and they suggest that Google is doing. And you're willing to take events that aren't actually evidence of any kind of malaction (like rewording a document to mean essentially the same thing) and try and draw nefarious conclusions out of those things. Like, why?

If you start from the assumption that Google is acting unethically and is entirely untrustworthy, there are tons of other approaches they can take to do fingerprinting that wouldn't be detectable at all. If you're logged in, the entire conversation is moot. If they wanted to track you, they have your google account. So this only matters for logged out users, and even then, the value is marginal even if you assume Google isn't using any other form of nefarious tracking.

And again that all assumes Google is openly lying. If you don't include that in your threat model, well, then, Google probably isn't lying.

[0]: https://www.google.com/chrome/privacy/whitepaper.html#mediad...

[1]: https://news.ycombinator.com/item?id=24040675

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#135
post #74

Earlier quoted context omitted.

> increasingly unethical and invasive fingerprinting techniques to remain competitive. ... or serve cookies via first-party subdomain ... Also, hasn't Safari already killed third party cookies?

I haven't had third party cookies enabled in Firefox for a decade. Google is coming late to this.

[deleted]

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#136
post #67

Earlier quoted context omitted.

This is a good time to remind everyone that Google has planted a hard-coded "X-Client-Data" telemetry backdoor that is sent to DoubleClick domains, is never disclosed to users and is impossible to disable. The header, which is not available to any of their competitors, contains unique information about the install that could allow them to track people better than anyone.

Thanks, removed Chrome ages ago in favor of Microsoft's Edge (the new one). Microsoft is fast becoming the good guys. It sets a default tracking level of Balanced, which blocks trackers from unvisited sites - you may then make it more strict if desired, out of the box with no extra plugins required. https://support.microsoft.com/en-us/microsoft-edge/learn-abo...

> Microsoft is fast becoming the good guys.

Are you not familiar with Windows 10's ads and invasive tracking?

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#137

Google's way of leveraging their browser dominance to use 3rd party cookies as a way to gain competitive advantage: Step 1: Implement a whole new browser functionality where Google alone can track people. Step 2: Eliminate 3rd party cookies so Google's competitors have to create increasingly unethical and invasive fingerprinting techniques to remain competitive. Step 3: Increase advertising rates since they are the o…

> increasingly unethical and invasive fingerprinting techniques to remain competitive. ... or serve cookies via first-party subdomain ... Also, hasn't Safari already killed third party cookies?

Google's identity signal that they have given themselves access to works across cross-domain and cross-device. First-party cookies do neither.

I would strongly prefer that everyone restrict themselves to the capabilities of first-party cookies. But it's still true that Google is not holding themselves to the same restrictions that they're trying to enforce on other parties.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#138

Earlier quoted context omitted.

I have extensions on Firefox nightly for android.

You have 20 extensions that were "approved" by mozilla more than a year ago! All the others are banned forever. You can install uBlock, but not uMatrix. Many many extensions are banned just because they reviewed ONE extension that they preferred for a certain usecase. For example, for OLED phone night reading, there's the most installed at the time extension "Dark Background and Light text" that offered many customiz…

> You have 20 extensions that were "approved" by mozilla more than a year ago! All the others are banned forever.

This is a ridiculous lie, Mozilla has said repeatedly that more extensions are being enabled as support for more extension APIs are added, and it has been true. Several of my extensions which were previously disabled have come back online after updates.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#139

Google's way of leveraging their browser dominance to use 3rd party cookies as a way to gain competitive advantage: Step 1: Implement a whole new browser functionality where Google alone can track people. Step 2: Eliminate 3rd party cookies so Google's competitors have to create increasingly unethical and invasive fingerprinting techniques to remain competitive. Step 3: Increase advertising rates since they are the o…

> increasingly unethical and invasive fingerprinting techniques to remain competitive. ... or serve cookies via first-party subdomain ... Also, hasn't Safari already killed third party cookies?

The things people don't know about third-party Javascript and "first-party" cookies...

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#140

Earlier quoted context omitted.

I still use Firefox 68 on Android since that's the last version to support extensions. It works well, for now.

I can't imagine the kind of Stupids that are steering mozilla, but they definitely want people to move to chrome. They disabled many loved extensions by power users for absolutely no reason at all! after those power users spend years bending to all their capricious changes. moving to webextension? done. moving to a new mobile UI? done. But, they still want you to move to chrome no matter what. We should take firefox…

>They disabled many loved extensions by power users for absolutely no reason at all!

The reasons were stated repeatedly. They rewrote the mobile browser engine, which broke extension API support since all of the internal APIs changed, and they didn't have the resources to support both browsers simultaneously for a long period of time, so they prioritized the most-used extensions first and will enable more extensions as the APIs are hooked back up underneath.

This had tangible benefits - the new browser is significantly snappier and uses less power in my experience.

>We should take firefox out of their hands before it is too late.

It's open source, if you aren't satisfied with the speed of their progress, you can always help out. You say you'd like to take this work out of their hands? Well, here it is.

https://mzl.la/3jgCsW3

These are, specifically, unimplemented APIs and known API bugs in the new Firefox Mobile, that are on the Mozilla TODO list, and for which contributions would presumably be welcome. Enjoy.

Unless when you said "we", you actually meant "other people".

Post reply on HN