Live data from Hacker News

Google’s approach to replacing the cookie is drawing antitrust scrutiny

digiday.com

211–220 of 354 posts

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#211

Earlier quoted context omitted.

As the window 70% of people access the Internet through globally , Chrome has nearly limitless options for monetization. Arguably, being part of Google hurts it, because it has to fit into Google's ideal business strategy.

So they’d be Firefox & wholly dependent on Google for search revenue money (I.e. ad money) anyway? Firefox already gets a lot of flack with their 3.65% & I don’t think that complaints about Chrome will stop if they’re still owning ~70% of browser market share with Google paying their bills. The only solution that would actually work is better regulation of the advertising space, but all advertisers (Google included)…

> So they’d be Firefox & wholly dependent on Google for search revenue money (I.e. ad money) anyway?

Not necessarily, its engine is now what powers Edge. Microsoft might support it.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#212
post #160

Earlier quoted context omitted.

Of course it isn't good. This is HN, and we want the web advertising industry to go away. However, that's not going to be the outcome. Antitrust scrutiny in this case means making it more fair to third party advertisers...the people who will be hit most by third party cookie disabling. As much as we want to hate on Google, articles like this won't make them move toward more privacy.

Nothing is free however. If advertisers can't violate one's privacy, that simply means they will pay less to the websites one uses, and that will lead to its quality deteriorating, or even more extreme content filters to appease advertisers and remain afloat.

You're assuming people won't create great things without ad profit. I submit Open Source and Wikipedia as evidence to the contrary. Not making a profit on the original creative act might lead to larger profits for society overall and indirect advantages to the original creators.

And usually content created for profit is quite untrustworthy, I prefer content created out of passion. It's the ad based content creators who are lacking in diversity, not the passionate creators who go in deep the rabbit hole.

Also, there's nothing wrong with ads, but they need to be topical to the content at hand, not targeted to users.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#213
post #142

I hope no one is saying Privacy Sandbox is worse than third party cookies, or is trusting this article to form an opinion about it. Web advertising was a $319 billion dollar industry in 2019. Does anyone wonder who may be lobbying their government to scrutinize Google and offer themselves for interviews for articles like this? Does anyone think the result of beating up Project Sandbox will be more radical privacy pro…

> I hope no one is saying Privacy Sandbox is worse than third party cookies Sort of like saying: "I hope no one is saying having a tracker in your car is worse than having a guy following you around." Sure, it's better. But it's not good either.

[deleted]

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#214
post #80

Earlier quoted context omitted.

Google's response to this allegation: https://9to5google.com/2020/02/06/google-chrome-x-client-dat... TL;DR, they claim that this header is sent to all Google-owned domains, and describes the feature flags that your browser has enabled, and it doesn't contain any PII. Oh wait They backpedalled on this by removing from the whitepaper their claim that the X-Client-Data field doesn't contain PII: https://vpnoverview.com…

[I work at Google, not on chrome] The current text of the whitepaper is "The combined state of these variations is non-identifying, since it is based on a 13-bit low entropy value (see above). These are transmitted using the "X-Client-Data" HTTP header, which contains a list of active variations"[0]. The X-Client-Data header is still described as non-identifying. You're reaching for controversy where there is none. I…

The fact it is undisclosed to users, unjustified (they could get the same result by sending the header to GTM) and impossible to disable make it nefarious.

Google have a header being sent to advertising domains that can be used for tracking purposes, Google didn't ever disclose this fact, and Google made it impossible to disable.

Already that's nefarious.

"Just trust us, we won't abuse this!" is not good enough, considering the way it was implemented is already cloak-and-dagger suspicious.

If this were innocent, it'd be disclosed and you could opt-out. Google made a deliberate choice to not disclose this tracking to users, and made another deliberate choice to have it to be impossible to disable.

Coupled with the other highly questionable choices Google has made with Chrome, such as the giant amount of telemetry available through JavaScript that ad networks are actively abusing and it's hard not to think of Google as nefarious.

For ad networks, including Google's own ad department, Chrome is like a candy store. Firefox and Safari have tracking prevention and cookie mitigations. Chrome on the other hand has undisclosed, impossible to disable ad network tracking headers being sent to DoubleClick explicitly. Chrome's cookie security is similarly a joke, designed for the benefit of ad networks.

Chrome puts ease of tracking above security, time and time again. Not only is this choice made repeatedly, but billions of dollars are made in the process.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#215
post #88

Earlier quoted context omitted.

> it doesn't contain any PII. Even if that was the case, this is a bullshit argument. They don't need any PII, it's just more fingerprinting. They already have all the personal information they'll ever need by using all the other means.

Yep, they have GREASE TLS bytes, TLS resume ticket, RLZ value, X-Geo header, UA header, JS APIs with persistent random values (which they do indeed use on adsense! This is why you get surprise WebGL code seemingly doing nonsense once a while in adsense ads) This cannot be a coincidence. They packed Chrome with fingerprints to work around GDPR by combining fingerprints on their side.

Thank you for the list, it could be useful.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#216

Earlier quoted context omitted.

> And then, who gets to run those servers? Even if it’s not Google, it’s probably not just anyone, right? Does that lead to a situation where there’s some authority or group of authorities that decides whether you or your startup gets to track users? And would you suppose it would be free for anyone to join this list of approved advertisers? Or might there be a fee, or some conditions to apply? This is how DNS, the I…

Maybe this is just my cynicism shining through, but I'm not sure I trust Google, or really most modern companies, to create something that wouldn't mainly be for their own benefit.

You don't really need to couch your statement with "Maybe this is just my cynicism" considering the daily news stories for years about the sociopathic behavior of many companies including google. It's absurd that anyone even defends these monstrosities let alone attacks anyone that suggests they are not trustworthy.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#217

Earlier quoted context omitted.

[I work at Google, not on chrome] The current text of the whitepaper is "The combined state of these variations is non-identifying, since it is based on a 13-bit low entropy value (see above). These are transmitted using the "X-Client-Data" HTTP header, which contains a list of active variations"[0]. The X-Client-Data header is still described as non-identifying. You're reaching for controversy where there is none. I…

It's about consistency and intent -- these observations do not extend to conspiracy tier thinking. What is the primary purpose of the X-Client-Data header if not for some unplanned future-proofing? Masquerading about it does not add to credibility

It's for tracking which chrome experiments are enabled, allowing chrome to check the impact of new chrome features by enabling them for only some populations and comparing the results. As it says in the white paper: "This header is used to evaluate the effect on Google servers - for example, a networking change may affect YouTube video load speed or an Omnibox ranking update may result in more helpful Google Search results."

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#218
Once they remove cookies, Google will still be able to track you... they'll just restrict the ability of others.

Personally, I think anonymizing the web and de-incentivizing companies from collection data is a good thing, but privacy sandbox itself is just a ploy to kill competition.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#219

Earlier quoted context omitted.

>They disabled many loved extensions by power users for absolutely no reason at all! The reasons were stated repeatedly. They rewrote the mobile browser engine, which broke extension API support since all of the internal APIs changed, and they didn't have the resources to support both browsers simultaneously for a long period of time, so they prioritized the most-used extensions first and will enable more extensions…

> so they prioritized the most-used extensions first and will enable more extensions as the APIs are hooked back up underneath. We've been waiting nearly a year and a half so far for them to enable extensions on the new engine.

And progress is being made. Like I said, I've personally seen most of my extensions that were initially disabled due to incompatibility, reenable themselves after update.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#220

It is so annoying to see that HN and general media have collectively decided that Google and everything it does is evil, but honestly you have no idea how good you have it right now. Google is not abusing your user data like you are made to think. If you talk to a Google engineer, you would realise the countlesss number of measures they take to safeguard user's data - human access is next to impossible. Only machines…

I would say that we have different definitions of 'abuse' in the case of Google. Of course, Google doesn't sell your data directly to anyone, allow anyone to get your metadata, or allow anyone to view your data. In that sense, I also completely trust Google to be good stewards of my data. That said, while I agree that Google does not 'abuse' my data by giving it to others in any form, Google absolutely does use my da…

My problem is different, I was all in with google, and with all my data of 20 years, they couldn’t recommend me a good next video on YouTube or better search for long tail keywords for which I did found site on their very own search engine.
Post reply on HN