> That's a false description. 13 bits of entropy is more than most existing fingerprinting vectors. This header allows clients behind NAT to be identified with significantly greater precision.
That doesn't make the X-Client-Data header identifying. Or, if it does, then your definition of "identifying information" is exactly equivalent to your definition of "information", because it is true that any particular axis or piece of data can be used to identify clients with greater precision. The rest is just how identifying the information is. Country is identifying, as is first digit of IP address, but both are less identifying than MAC address or first name. You're welcome to subscribe to such a definition, but it's not the normal one (which is usually that said piece of data can be tied to a specific individual, although you may not be able to correlate that particular individual with a name or similar).
Under this definition, I'd probably agree that the combination of IP address and X-client-data header is identifying, but that's also not a thing anyone is going to be using, because it's not particularly useful.
> There is. Their business lives and dies on their ability to track web users
Sort of. The value of tracking individual users at the granularity you suggest is, as far as I know, dubiously valuable, and importantly, there's no reason to believe it's done. Like there's no evidence to support this beyond the conjecture.
> This is (obviously) about the hundreds of millions of Chrome users who are not logged in, and as I said above, 13 bits of entropy isn't marginal.
But if you're in this situation, and again, Google is being unethical, there are a host of other tracking tools that provide 13 or more bits of entropy that they can use.
> Nobody "lied" per se, but the end result is the same.
I'd classify that as lying (for actually more than one reason). But I'll just leave you with the same point I made to 0xy the last time this was brought up: this X-client-Data header is nearly 9 years old. When it was introduced it was considered nonidentifying and was used for chrome experiments. It is still considered nonidentifying and used for chrome experiments.
And this is why the whole idea doesn't make sense: if the header was introduced now, I could see this train of thought making sense. But it wasn't recently introduced. They've had more than 8 years to use it while there have been all kinds of other ways to get additional bits.
So now your chain of reasoning is more like
1. Telemetry is introduced and a restrictive policy is established, e.g. "we won't use this to track people.
2. 6-12 years pass, multiple executives pass through the area. The CEO of the company changes twice. The entire org chart shifts and metamorphizes more than once. The policies are maintained.
3 [concurrently with 2]. A number of nations pass new privacy laws. Previously, using this particular set of data to track individuals would have been unethical, but legal. It is now both unethical and illegal in many places.
4. Google invests significantly in a different, somewhat privacy preserving alternative to individually identifying tracking technology which is openly criticized because it is mediocre in terms of privacy preservingness.
5. At some point between 2 and 4, they started actively breaking the law by using this can't-be-used-to-identify telemetry to identify unique users. And instead of completely hiding this fact, using it as a competitive advantage, and openly being a leader in privacy (for example by being an early proponent and supporter of things like 3rd party cookie restrictions), they don't do that, and instead suffer reputational harm due to the existing tracking, the telemetry illegally used for tracking, and the proposed new scheme for privacy preserving tracking that is inferior to the illegal telemetry-based approach.
It's a line of reasoning that requires that Google be simultaneously incredibly unethical and incredibly inept. It doesn't make sense.