Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

141–150 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#141
post #133

Earlier quoted context omitted.

> The best outcome is to come up with a fundamentally better business model A fundamentally better business model already exists: make users into customers. Google should charge users directly for the services they use. Then they wouldn't need to resort to all these underhanded tactics to try to monetize their valuable services. They could just monetize them directly. Of course this is highly unlikely to happen now t…

Fundamentally better for whom? Do you think Google has never considered that business model? I think it’s much more likely that they’ve put a considerable amount of effort and research into it, and concluded that their current business model will let them extract the most money from their products. That’s why we need regulation. Under these market conditions, Google’s business model does appear to be the best for the…

> Fundamentally better for whom?

In the long run it's better for everybody. But it is true that "the long run" can be pretty long.

> Do you think Google has never considered that business model?

I think Google probably considered it early on but found it easier to go the way they actually went. But "easier" is not the same as "best in the long run".

> their current business model will let them extract the most money from their products

Google doesn't have products, they have services. And of course, since their services are free to users and users are now addicted to that, they can obviously extract more money with their current business model since they have made a concerted effort to make the "users as customers" business model impossible.

However, their current business model was being built during the same time period when "Don't be evil" was still the company's motto and still apparently taken seriously by company leaders. Which means those leaders were either very disingenuous or delusional. Because addicting people to a free service and then exploiting them and their personal data in order to make the money they can't make from the users directly, as customers, is evil. And trying to keep their current business model propped up in the face of users becoming increasingly aware of the ways in which they are being exploited, is only going to force Google to be more and more evil. Sooner or later, if it doesn't change, it will kill Google as a company.

> That’s why we need regulation.

Regulation won't fix this problem. Corporations can always either buy their way around regulations (oh, another million dollar fine because we broke regulation XYZ about exploiting user data? just rounding error in our accounting) or buy enough influence to get the regulations written so they don't actually impose a burden on them (but do impose a huge burden on potential competitors, the new startups that would otherwise be finding ways to disrupt Google's current business model, since users are clearly becoming dissatisfied with it).

The only thing that will fix this problem in the long run is for users to realize that there is no such thing as a service that is (a) free and (b) valuable. We are going to pay the costs somehow. The simplest way to pay them--with money--is also, in the long run, the best.

Re: Proposal: Treat FLoC as a security concern

#143

Earlier quoted context omitted.

Possibly GDPR? As an explicit no-consent to tracking? Not rhethorical questions, I know too little about the details.

When you use Chrome for the first time, it makes you accept its ToS which tells you they are going to track you.

[deleted]

Re: Proposal: Treat FLoC as a security concern

#144
post #97

The intro lost me: > WordPress powers approximately 41% of the web – and this community can help combat racism, sexism, anti-LGBTQ+ discrimination and discrimination against those with mental illness with four lines of code:" function disable_floc($headers) { $headers['Permissions-Policy'] = 'interest-cohort=()'; return $headers; } add_filter('wp_headers', 'disable_floc'); If you seriously think this is going to make…

FLoC exists to group users down into behavioral targeting categories, it should be obvious that some of those will end up corresponding to gender or race or other traits that are protected statuses. We've repeatedly had incidents where big companies were caught accidentally letting (for example) landlords filter advertisements by race or recruiters filter listings by age, both of which are illegal.

Does race determine behavior?

Re: Proposal: Treat FLoC as a security concern

#145
post #67

Earlier quoted context omitted.

Between large web publishing platforms and all alternate browsers blocking FLoC, I think we could kill it, yes. WordPress is used by a lot of marketing focused folks though, so we'll see if WP is able to land this.

Exactly. A big part of the WordPress community are publishers, bloggers, affiliate marketers, etc who rely on ads to generate revenue. I'm not sure they'd be too thrilled with this proposal.

Sure, but this doesn’t mean no advertising, it means no default supporting FLoC. I know advertisers aren’t going to like it, but I doubt it means they’ll give up advertising altogether.

I wonder if AdWords will require use of floc headers

Re: Proposal: Treat FLoC as a security concern

#146
With the death of third-party cookies Google is trying to force browsers to add enough bits of entropy so that the same level of user tracking can be achieved through fingerprinting instead. Simple as that. The fact that Google is rolling this out right now but their plans to reduce fingerprinting move much more slowly, if at all, is telling. This absolutely needs to be treated as the massive privacy leak that it is.

Re: Proposal: Treat FLoC as a security concern

#148
post #146

With the death of third-party cookies Google is trying to force browsers to add enough bits of entropy so that the same level of user tracking can be achieved through fingerprinting instead. Simple as that. The fact that Google is rolling this out right now but their plans to reduce fingerprinting move much more slowly, if at all, is telling. This absolutely needs to be treated as the massive privacy leak that it is.

Can’t you just switch to a Chromium fork without the FLoC? If they were closed-source, I think I would agree.

Re: Proposal: Treat FLoC as a security concern

#149
post #146

With the death of third-party cookies Google is trying to force browsers to add enough bits of entropy so that the same level of user tracking can be achieved through fingerprinting instead. Simple as that. The fact that Google is rolling this out right now but their plans to reduce fingerprinting move much more slowly, if at all, is telling. This absolutely needs to be treated as the massive privacy leak that it is.

Can’t you just switch to a Chromium fork without the FLoC? If they were closed-source, I think I would agree.

How many people who use Chrome can or will even know to do so? Tech oriented people already have alternatives.

Re: Proposal: Treat FLoC as a security concern

#150
> Why is this bad? As the Electronic Frontier Foundation explains in their post “Google’s FLoC is a terrible idea“, placing people in groups based on their browsing habits is likely to facilitate employment, housing and other types of discrimination, as well as predatory targeting of unsophisticated consumers.

All of this has been happening with tracking cookies, fingerprint tracking, pixel tracking and so on. And will continue to happen.

I find it so bizarre it took Google to talk about phasing out 3rd party cookies and replacing it with a much lesser technology in the face of FLoC, for people to suddenly be all up in arms about it.

Post reply on HN