Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

161–170 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#161
post #153
post #63

Earlier quoted context omitted.

It's just HN. It's just like the reaction to AMP on this board. Most clients like the feature if it speeds up the site and brings more visitors to the site. Here, you'd think it represents the end of the internet or something.

If we have to be fair, Google didn't build a browser, an email service, a free DNS service, and free hosting/optimization service (AMP) just because, y'know, whatever. I tend to roll my eyes at the blind hatred of corporations, but we also have to have both feet firmly on the ground, that these products and services are strictly tied to long-term plans for ROI. What kind of a ROI would the biggest advertising network…

Look at gmail: I pay $60/year-ish for Fastmail. Gmail is at least that good. So is the purpose of gmail to have a cross device stable identifier? Absolutely. Are people realizing tons of value from it for free? Also yes.

Re: Proposal: Treat FLoC as a security concern

#162
post #146

With the death of third-party cookies Google is trying to force browsers to add enough bits of entropy so that the same level of user tracking can be achieved through fingerprinting instead. Simple as that. The fact that Google is rolling this out right now but their plans to reduce fingerprinting move much more slowly, if at all, is telling. This absolutely needs to be treated as the massive privacy leak that it is.

Can’t you just switch to a Chromium fork without the FLoC? If they were closed-source, I think I would agree.

Sure, "you" - as a reader of hacker news - can use Firefox (or a chromium fork). The problem is that most normal users have no idea about any of this stuff, and no understanding of why they might want to switch.

Re: Proposal: Treat FLoC as a security concern

#163
post #146

With the death of third-party cookies Google is trying to force browsers to add enough bits of entropy so that the same level of user tracking can be achieved through fingerprinting instead. Simple as that. The fact that Google is rolling this out right now but their plans to reduce fingerprinting move much more slowly, if at all, is telling. This absolutely needs to be treated as the massive privacy leak that it is.

> Simple as that.

Not quite? Maybe this will add more bits that will be useful for fingerprinting, but this seems like an absurd way for google to go about making it easier to fingerprint browsers, considering that most browsing happens over Chrome where Google can see what pages everyone visits anyway. And Google is currently proposing adding anti-fingerprinting measures [0] that observe how many bits of information a website has gathered and block API access after it reaches a certain threshold.

A straightforward analysis of Google's motivations makes sense here: they want to keep their ad business profitable while improving their reputation on privacy. FLOC allows targeted ads, keeping their business profitable, and doesn't rely 3rd parties observing your browser history, improving privacy.

From https://web.dev/floc/ :

> With FLoC, the browser does not share its browsing history with the FLoC service or anyone else. The browser, on the user's device, works out which cohort it belongs to. The user's browsing history never leaves the device.

> There will be thousands of browsers in each cohort.

A further privacy improvement is that they're designing it to avoid leaking whether you're a member of a "sensivitive category":

> The clustering algorithm used to construct the FLoC cohort model is designed to evaluate whether a cohort may be correlated with sensitive categories, without learning why a category is sensitive. Cohorts that might reveal sensitive categories such as race, sexuality, or medical history will be blocked. In other words, when working out its cohort, a browser will only be choosing between cohorts that won't reveal sensitive categories.

[0]: https://techcrunch.com/2019/08/22/google-proposes-new-privac...

Re: Proposal: Treat FLoC as a security concern

#164
post #124
post #15

Earlier quoted context omitted.

> "Kill it before it lays eggs." but do we worry about what evolves from this if it dies? Nothing really evolves here - status quo is what stays. You continue to be tracked head to arse on everyones servers, the media keeps adding 150 trackers to every webpage and the internet moves on. Thinking that one of the biggest profit making industries in US will just go away if you scream loud enough on HN is utterly naive a…

We should keep in mind why Google invests in FLoC, though. Either they realize third party cookies are on a (regulated) dead end. Or they realize there is a bigger moat. Or something else that helps them. But in any case, seeing the current Google, this is not something benefitting their users(products?) primarily. Unless some benefits accidentally aligned. So, pushing back towards the broken status quo may be the ri…

Don't users not like being tracked by 3P cookies? Isn't that why 3P cookies are being phased out?

Re: Proposal: Treat FLoC as a security concern

#165

Earlier quoted context omitted.

When you use Chrome for the first time, it makes you accept its ToS which tells you they are going to track you.

If the ToS are contrary to the law, then they are null and void. Laws tend to trump private agreements. Then, if it goes to trial in Europe, they’d have a hard time proving that the ToS are fair and that the user agrees freely and understanding what is being agreed, which is also another condition for any form of contract to be valid.

You're saying there is some law which prevents me from inputting my own data into a program, and it categorizes me into one of a thousand types of people?

Re: Proposal: Treat FLoC as a security concern

#166
post #159
post #155

Earlier quoted context omitted.

Third party cookies, love them or hate them, have been with us for a long time, and simply dropping them would not be viable without the long phase out. And a long phase out is not something around which you can form a singular rallying cry. FLoC is a new thing which is just being rolled out, so it's a lot easier for people to resist adding a new thing that makes the internet more crappy and less private. I think it'…

If you have figured out a way to eliminate tracking, be my guest. Mozilla would like to know, Apple would like to know. Until then FLoC attracts attention because it's new, yes, this explains our reaction. It's still an irrational reaction. Also what's this "predatory targeting of unsophisticated consumers" about? You don't need targeting for this. Heck you don't need anything for this. The way it's usually carried o…

So you're the one who keeps doing that, or is it a group thing?

Just curious. It undoubtedly works, but I've always wondered why it's so pervasive.

Re: Proposal: Treat FLoC as a security concern

#167
post #80
post #2

WordPress is 41% of the web. If this goes through and FLoC is disabled by default by WordPress, will FLoC be dead on arrival?

My fear is that it will end up exactly like the do not track headers and that at some point Google won't listen to the disable Floc header.

Why is that a problem? If I visit ognarb.com, what right do you have to tell me "You aren't allowed to use that fact for developing a profile about yourself"?

You send me a bunch of data, including headers, and I'm more or less free to do with that what I want within the privacy of my own browser. I don't have to listen to any of your headers if I don't want to.

Re: Proposal: Treat FLoC as a security concern

#168

Earlier quoted context omitted.

Can’t you just switch to a Chromium fork without the FLoC? If they were closed-source, I think I would agree.

Sure, "you" - as a reader of hacker news - can use Firefox (or a chromium fork). The problem is that most normal users have no idea about any of this stuff, and no understanding of why they might want to switch.

Realistically most people just don't care the same amount that the subset of privacy-obsessed+techies do.

Re: Proposal: Treat FLoC as a security concern

#169
post #157

Ah come on. The FLoC proposal has built in ways to turn it off. If you don't wanna be put in a cohort you can just configure your browser (even chrome) to say you don't have one.

If it's not opt in, it's malware and should be treated as such. Don't let Google gaslight you.

[deleted]

Re: Proposal: Treat FLoC as a security concern

#170
post #155
post #150

> Why is this bad? As the Electronic Frontier Foundation explains in their post “Google’s FLoC is a terrible idea“, placing people in groups based on their browsing habits is likely to facilitate employment, housing and other types of discrimination, as well as predatory targeting of unsophisticated consumers. All of this has been happening with tracking cookies, fingerprint tracking, pixel tracking and so on. And wi…

Third party cookies, love them or hate them, have been with us for a long time, and simply dropping them would not be viable without the long phase out. And a long phase out is not something around which you can form a singular rallying cry. FLoC is a new thing which is just being rolled out, so it's a lot easier for people to resist adding a new thing that makes the internet more crappy and less private. I think it'…

I have 3rd party cookies off. The only thing I have seen requiring 3rd party cookies in the last year is Microsoft when I had to use teams.
Post reply on HN