Live data from Hacker News

Google’s approach to replacing the cookie is drawing antitrust scrutiny

digiday.com

191–200 of 354 posts

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#191

Earlier quoted context omitted.

Yes it does. Users now have a unique IP address that is now static. Yes you can rotate your exact IP inside your block but you still keep the same subnet.

That is the promise they sold it on. But, point me to a single ISP that gives a cable subscriber more than one IPv6 address. or a /48 as initially everyone was hopping. ISP profit from NAT. They will never get rid of it. Even if you get a /54 /64 the ad networks will just learn to assign /54 as they do today. But, another point, ipv4 today is barred from being used to form your advertising profile under current legis…

Spectrum assigns a /128 to your router via DHCPv6, but you also get a delegated prefix. That prefix seems to be a /64 by default, but you can request and receive a /56.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#192

Earlier quoted context omitted.

How would chrome survive as a business?

As the window 70% of people access the Internet through globally , Chrome has nearly limitless options for monetization. Arguably, being part of Google hurts it, because it has to fit into Google's ideal business strategy.

limitless options? you mean ads. I don't think they can start charging users money. And if Chrome is forced to start directly monetizing, I can't see that ending well for the product. Any way they could possibly extract money from me would require it to do something I don't want, such as interjecting itself between me and an online merchant, or between me and content, or via integrations with partners I don't want (maybe even Google, which would defeat the purpose of the proposed split), or by selling a "premium" feature set. If Chrome had to make money it would suck as a product and everyone would move to safari/edge/etc bc they don't have the same pressure.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#193

Earlier quoted context omitted.

You would see mydomain.com/adnetwork then.

Can browsers look up a different server addresses to send requests to that way? I didn't think that's how DNS worked but I'm no expert. Advertisers can't trust content people to forward requests because it would be too easy to fake them.

No I don’t think so. DNS only works on the domain part of the url.

However a server like nginx can be set up to proxy requests matching a specific url pattern to another server. This would be a bit more work than adding a DNS entry and referencing that though.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#194

It is so annoying to see that HN and general media have collectively decided that Google and everything it does is evil, but honestly you have no idea how good you have it right now. Google is not abusing your user data like you are made to think. If you talk to a Google engineer, you would realise the countlesss number of measures they take to safeguard user's data - human access is next to impossible. Only machines…

I would say that we have different definitions of 'abuse' in the case of Google. Of course, Google doesn't sell your data directly to anyone, allow anyone to get your metadata, or allow anyone to view your data. In that sense, I also completely trust Google to be good stewards of my data. That said, while I agree that Google does not 'abuse' my data by giving it to others in any form, Google absolutely does use my da…

Does Netflix with its recommendation engine also "psychologically manipulate" you into watching movies you like?

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#195
post #80

Earlier quoted context omitted.

Google's response to this allegation: https://9to5google.com/2020/02/06/google-chrome-x-client-dat... TL;DR, they claim that this header is sent to all Google-owned domains, and describes the feature flags that your browser has enabled, and it doesn't contain any PII. Oh wait They backpedalled on this by removing from the whitepaper their claim that the X-Client-Data field doesn't contain PII: https://vpnoverview.com…

[I work at Google, not on chrome] The current text of the whitepaper is "The combined state of these variations is non-identifying, since it is based on a 13-bit low entropy value (see above). These are transmitted using the "X-Client-Data" HTTP header, which contains a list of active variations"[0]. The X-Client-Data header is still described as non-identifying. You're reaching for controversy where there is none. I…

> The X-Client-Data header is still described as non-identifying.

That's a false description. 13 bits of entropy is more than most existing fingerprinting vectors. This header allows clients behind NAT to be identified with significantly greater precision.

> There's no rational basis for Google doing what people suggest it's doing.

There is. Their business lives and dies on their ability to track web users, and tracking methods are gradually being eliminated from web standards, therefore Google has a rational basis for adding new tracking methods that it can leverage - especially ones that only it can leverage.

> If you start from the assumption that Google is acting unethically and is entirely untrustworthy

I think the base assumption is less dramatic: that Google is simply acting in its own best interests by prioritizing growth over user privacy.

> If you're logged in, the entire conversation is moot. If they wanted to track you, they have your google account. So this only matters for logged out users, and even then, the value is marginal even if you assume Google isn't using any other form of nefarious tracking.

This is (obviously) about the hundreds of millions of Chrome users who are not logged in, and as I said above, 13 bits of entropy isn't marginal.

> And again that all assumes Google is openly lying. If you don't include that in your threat model, well, then, Google probably isn't lying.

Not necessarily. All it takes is a policy change. It looks like this:

1. Privacy regression is introduced and a restrictive policy is established, e.g. "we won't use that to track people".

2. 6-12 months go by; maybe a new VP gets hired, or a bizdev team discovers that this data could be leveraged for a significant bump in revenue.

3. The policy is relaxed to allow existing & future data to be used for fingerprinting.

Nobody "lied" per se, but the end result is the same.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#196

Earlier quoted context omitted.

Oh, I didn't realize a subdomain was not considered 3rd party. So soon we'll see adnetwork.mydomain.com and www.mydomain.com. I think we should just make cookies only work when the domain matches exactly.

You would see mydomain.com/adnetwork then.

The reason why subdomains work is that you can make the root domain go to your own site, while the subdomain goes to your ad provider. If you use a CNAME it's literally just a matter of publishing another DNS recod and you're done. Moving to a subdirectory requires setting up a reverse proxy on your existing infrastructure, and keeping it up to date every time your ad network switches domains. Hell, on a lot of platforms you don't even have the ability to reconfigure the server in such a way as to proxy through an entire ad network, so you'll have to use a platform or technology specific plugin if available.

That's why the ad industry used third-party domains in the first place, BTW - it's a zero-setup solution. Subdomains are minimal-setup; subdirectories are a huge hassle.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#197
post #160

Earlier quoted context omitted.

Of course it isn't good. This is HN, and we want the web advertising industry to go away. However, that's not going to be the outcome. Antitrust scrutiny in this case means making it more fair to third party advertisers...the people who will be hit most by third party cookie disabling. As much as we want to hate on Google, articles like this won't make them move toward more privacy.

You present a false dichotomy. "Google's Privacy Sandbox" versus Third Party Cookies, as if those are the only alternatives. Now you are following along with another false dichotomy! > This is HN, and we want the web advertising industry to go away. Here's a crazy idea. We don't need either Google's monopoly preserving Privacy "Sandbox" or third party cookies... and we don't need to do away with web advertising. We'r…

I'll add a third option: neither! Seriously, I've had 3rd party cookies disabled four years and almost nothing breaks. The last time I remember needing to enable them was some online homework system that came with a math textbook.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#198

Earlier quoted context omitted.

I don’t want the web advertising industry to go away. It’s benign. If you don’t want advertisers to track you you have the option to default browse without cookies. Even better, default browse without cookies and JavaScript. Yes, I do this. If you understand how cookies work then this is a perfectly viable option for you. If you don’t, you likely don’t care about advertisers tracking you.

I disagree with your last statement. People may care about being tracked even though they don’t understand the mechanism, or even that it’s happening.

Well I just think that if you aren’t aware you are being tracked, you probably don’t really care too much.

People who care they are being tracked will take the time to learn how stop being tracked. That’s why I learned about cookies etc.

I think this is probably a way for google to assert further control over the advertising industry, using the guise of improving user privacy. Like I said, most users don’t really care because if they did they would just disable cookies, so I think they are solving a problem no one is actually having and that seems suspicious.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#199

Earlier quoted context omitted.

Doesn't that risk massive fines if proven? Like a percentage of all revenue?

I believe they already did lawyerising, as written above. They grabbed onto the wording of PII as " personally identifiable information" that information is identifiable, but not personally identifiable, so it is ok to use for ads.

So we knows it's you, but you are a integer.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#200
post #78

Earlier quoted context omitted.

And Google is probably paying Mozilla so that they block those cookies too... I think that they might have paid them for other things too... like for blocking 99% of extensions on Firefox mobile (those are speculations, that are very probable).

I still use Firefox 68 on Android since that's the last version to support extensions. It works well, for now.

The current stable version of Firefox on Android works just fine with uBlock Origin, Privacy Badger, Ghostery, HTTPS Everywhere, etc.
Post reply on HN