Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

121–130 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#121
post #97

The intro lost me: > WordPress powers approximately 41% of the web – and this community can help combat racism, sexism, anti-LGBTQ+ discrimination and discrimination against those with mental illness with four lines of code:" function disable_floc($headers) { $headers['Permissions-Policy'] = 'interest-cohort=()'; return $headers; } add_filter('wp_headers', 'disable_floc'); If you seriously think this is going to make…

FLoC exists to group users down into behavioral targeting categories, it should be obvious that some of those will end up corresponding to gender or race or other traits that are protected statuses. We've repeatedly had incidents where big companies were caught accidentally letting (for example) landlords filter advertisements by race or recruiters filter listings by age, both of which are illegal.

FLoC is replacing cookies, that were already used in pretty much the exact same manner. I can't say I think FLoC is a win for consumers, but how it will promote racism any more than cookies is beyond me.

I could be wrong of course, if so, please explain how.

Re: Proposal: Treat FLoC as a security concern

#122
post #115
post #44

The submitted title was "WordPress Proposal to Treat Google's FLoC as a Security Concern". That makes it sound like Wordpress itself is officially making this proposal. Is it? The page doesn't look like that to me. We've reverted the title in keeping with the site rule: " Please use the original title, unless it is misleading or linkbait; don't editorialize. " ( https://news.ycombinator.com/newsguidelines.html ).

I’m a WordPress committer and (somewhat former) owner of some large parts of WordPress. This is correct; the Make blogs can be posted to by many members of the project, and this does not indicate a decision or “official” word by any means. (I could create a Make post right now with a counter-proposal if I wanted.) It’s not a proposal by the WordPress Foundation, nor by any of the project’s leads. However, this does h…

Thanks! In that case, the article's original title, appearing next to the domain make.wordpress.com, seems right.

Re: Proposal: Treat FLoC as a security concern

#123
post #97

The intro lost me: > WordPress powers approximately 41% of the web – and this community can help combat racism, sexism, anti-LGBTQ+ discrimination and discrimination against those with mental illness with four lines of code:" function disable_floc($headers) { $headers['Permissions-Policy'] = 'interest-cohort=()'; return $headers; } add_filter('wp_headers', 'disable_floc'); If you seriously think this is going to make…

Please don't take HN threads into extraneous flamewar. This is in the site guidelines: "Eschew flamebait. Avoid unrelated controversies and generic tangents."

https://news.ycombinator.com/newsguidelines.html

Cherry-picking a detail you find most provocative in an article and importing it here to express how provoked you feel is a way of setting the thread on fire—no doubt unintentionally [1], besides which the greater part of the problem is caused by the upvotes such things attract—but still, we don't want threads-on-fire. We're trying for something different than that.

Readers should leave tangential provocations where they find them, and commenters should comment on what gratifies their intellectual curiosity, as the guidelines ask.

Edit: also, please don't use HN primarily for political or ideological battle. It's not what this site is for, and it destroys what it is for, so we ban accounts that cross that line [2], and your account's recent history seems to have crossed it. Fortunately that seems to be a recent development so it should be easy to fix.

[1] https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...

[2] https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme...

Re: Proposal: Treat FLoC as a security concern

#124
post #15

I am hopeful that this will help get rid of FLoC but I worry about two things. One, this will end up being treated like the "no track" headers. That's just totally ignored after IE (was it IE?) enabled it be default. That gave all the trackers a reason to just ignore it and track everyone. I don't know if that exact same thing can happen here, but something similar maybe? The other thing I worry about is that FLoC 2.…

> "Kill it before it lays eggs." but do we worry about what evolves from this if it dies? Nothing really evolves here - status quo is what stays. You continue to be tracked head to arse on everyones servers, the media keeps adding 150 trackers to every webpage and the internet moves on. Thinking that one of the biggest profit making industries in US will just go away if you scream loud enough on HN is utterly naive a…

We should keep in mind why Google invests in FLoC, though.

Either they realize third party cookies are on a (regulated) dead end. Or they realize there is a bigger moat. Or something else that helps them.

But in any case, seeing the current Google, this is not something benefitting their users(products?) primarily. Unless some benefits accidentally aligned.

So, pushing back towards the broken status quo may be the right thing, if you know, or believe, how Google is going to benefit from the new FLoC.

I cannot evaluate that. But Googles track record does not offer me confidence their new tech is going to help me overcome the issues I have with the status quo.

Re: Proposal: Treat FLoC as a security concern

#125
post #97

The intro lost me: > WordPress powers approximately 41% of the web – and this community can help combat racism, sexism, anti-LGBTQ+ discrimination and discrimination against those with mental illness with four lines of code:" function disable_floc($headers) { $headers['Permissions-Policy'] = 'interest-cohort=()'; return $headers; } add_filter('wp_headers', 'disable_floc'); If you seriously think this is going to make…

I think you’re the one that’s operating on a purely old-school definition of systematic discrimination. You’re giving people a signal that by it’s very nature groups people like them together and naturally will have a correlation to their age, gender, race, wealth, ability, blah blah. And then you’re told that you’re supposed to use this information to make decisions about them as an individual. How does this not lead to racism?

This is the digital equivalent of trying to be “race blind.” You can’t just remove the race column in your db and assume that’s it fine to torture your data for patterns secure that your results won’t correlate to race.

Re: Proposal: Treat FLoC as a security concern

#126

Earlier quoted context omitted.

FLoC exists to group users down into behavioral targeting categories, it should be obvious that some of those will end up corresponding to gender or race or other traits that are protected statuses. We've repeatedly had incidents where big companies were caught accidentally letting (for example) landlords filter advertisements by race or recruiters filter listings by age, both of which are illegal.

FLoC is replacing cookies, that were already used in pretty much the exact same manner. I can't say I think FLoC is a win for consumers, but how it will promote racism any more than cookies is beyond me. I could be wrong of course, if so, please explain how.

Because cohorts are stronger than cookies for sites that aren’t tracking you across the web and correlating that data.

Re: Proposal: Treat FLoC as a security concern

#127

Earlier quoted context omitted.

Only govt action will work. That too concerted action by several national govts.

The govt action is the shitty way out. This all is a classic there is not enough to go around situation. Govt regulation will make it more entrenched and "manageable". The best outcome is to come up with a fundamentally better business model. Something that satisfies seller's desire to promote their products and customers desire to feel respected and important. Preferably cutting out a middleman and reducing costs of…

As soon as you invent that you will be bought out or strong armed out, it is very rare for a new niche to be established wholesale.

Re: Proposal: Treat FLoC as a security concern

#129

The real solution is to make everyone stop using Chrome.

I am a bit uneducated at this but does Brave browser which is based on chromium also have the same problem?

No, Brave removes everything that has to do with Google from the browser.

Re: Proposal: Treat FLoC as a security concern

#130
post #2

WordPress is 41% of the web. If this goes through and FLoC is disabled by default by WordPress, will FLoC be dead on arrival?

Between large web publishing platforms and all alternate browsers blocking FLoC, I think we could kill it, yes. WordPress is used by a lot of marketing focused folks though, so we'll see if WP is able to land this.

It's staggering how much leverage WordPress has. They were going to stop using React because of the patents clause, and only a week later Facebook caved and relicensed it as MIT.
Post reply on HN