Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

171–180 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#171
post #89
post #74

Earlier quoted context omitted.

IIUC while floc does indeed build a profile browser side it isn’t something that advertisers can track with the same precision as they can with 3p cookies. So while it’s not the holy grail it does appear to be a small step in the right direction from the status quo. Do I understand the situation correctly? Genuinely curious.

That's what I've been wondering. If FLoC is better for privacy than current tracking methods and Google intends to switch to using FLoC instead of current tracking methods, wouldn't it be better for FLoC to succeed?

The problem is that it isn't much better (if at all) in its current implementation. The current implementation allows tracking and identifying individual users (this may be or may not be fixed by Google, it has already been reported to their Github issue tracker). Since it is entirely based on your browsing patterns you can also be tracked cross device (people's browsing patterns rarely change).

For the moment 3p cookies are better, they can easily be erased, blocked or even isolated, and are restricted to a single browser.

Re: Proposal: Treat FLoC as a security concern

#172
post #56

Earlier quoted context omitted.

Only govt action will work. That too concerted action by several national govts.

Developing a browser (or forking the existing one) with comprehensive anti-tracking features would also work. There are a half-dozen plugins one can add to Ungoogled Chromium to browse the web in (relative) safety. It's not a nation-state level undertaking: six or seven figures. The problem really comes from apps, which are loaded to the gills with spyware.

How can it do that when the server needs an IP address to send traffic to? Cookies just make it more convenient but there is fundamentally that "analog hole". You can Tor things up and obfuscate but if you can interact with them they can track you.

Re: Proposal: Treat FLoC as a security concern

#173

It’s a opportunity to put priv engineering techniques to the test in prod, at least. That’s 100% the main thing that stands out here. In the raw browser history, prior to ~hashing it to a FLoC ID, can Google anon PII while still maintaining good data analytics from the rest* of the dataset’s fields? Priv engineer, as an engineering discipline, would argue yes. If this is what Google does and the privacy is put throug…

> can a FLoC ID de-anon into a user?

Currently yes and seems like a though problem to solve (there are trade offs but it's likely that this will never be fully solved, like encryption, you can only make it so difficult that it isn't worth doing it but not impossible to do): https://github.com/WICG/floc/issues/100

Re: Proposal: Treat FLoC as a security concern

#174
If it is a security concern why he mention there racism, sexism and LGBT stuff? Isn't it a concern for any person with no relation to those groups? or is is there some political underlying thing going on which I should be aware of? When I see those terms I get an immediate suspicious feeling that someone is trying to manipulate me.

Re: Proposal: Treat FLoC as a security concern

#175
post #150

> Why is this bad? As the Electronic Frontier Foundation explains in their post “Google’s FLoC is a terrible idea“, placing people in groups based on their browsing habits is likely to facilitate employment, housing and other types of discrimination, as well as predatory targeting of unsophisticated consumers. All of this has been happening with tracking cookies, fingerprint tracking, pixel tracking and so on. And wi…

The issue really is: Google isn't phasing our 3rd party cookies out of charity. They are clearly looking for a way to keep doing all the things third-party cookies enable after they go away.

Here we find people saying (through legislative and regulatory action) that they want to end the use of 3rd party cookies because the bad behaviors they enable, and they are rightly outraged at the efforts to comply with the letter of the law while running roughshod over the intent of the laws.

Re: Proposal: Treat FLoC as a security concern

#176
post #133

Earlier quoted context omitted.

The govt action is the shitty way out. This all is a classic there is not enough to go around situation. Govt regulation will make it more entrenched and "manageable". The best outcome is to come up with a fundamentally better business model. Something that satisfies seller's desire to promote their products and customers desire to feel respected and important. Preferably cutting out a middleman and reducing costs of…

> The best outcome is to come up with a fundamentally better business model A fundamentally better business model already exists: make users into customers. Google should charge users directly for the services they use. Then they wouldn't need to resort to all these underhanded tactics to try to monetize their valuable services. They could just monetize them directly. Of course this is highly unlikely to happen now t…

Do you think it woukd be better if we were still billed by the kilobyte used? A pay per use or monthly quota would outright discourage curiosity and add in another mental fatigue of tracking costs. Keeping information access gated behind wealth would not be an improvement. Those very real costs outweigh the vague theoretical and frankly some psychologically self-inflicted ones. Your data being monetized by others is not an intrinsic harm. Be wary of abuses but use isn't always a harm. Somebody doing a traffic survey may make money from your data but that does not make you poorer.

Re: Proposal: Treat FLoC as a security concern

#177
post #150

> Why is this bad? As the Electronic Frontier Foundation explains in their post “Google’s FLoC is a terrible idea“, placing people in groups based on their browsing habits is likely to facilitate employment, housing and other types of discrimination, as well as predatory targeting of unsophisticated consumers. All of this has been happening with tracking cookies, fingerprint tracking, pixel tracking and so on. And wi…

One difference between third party cookies and FLoC is that with FLoC it is being explained to the public how browsing history is being used. The third parties who send Set-Cookie headers do not write up documentation attempting to explain to the public what they are doing and why it is not a threat to privacy.

As other comments point out, it would be more difficult for people to "be all up in arms" about third party cookies because third party cookies is not an issue that is easily attributable to one entity nor one set of documentation.

Re: Proposal: Treat FLoC as a security concern

#178
post #56

Earlier quoted context omitted.

Developing a browser (or forking the existing one) with comprehensive anti-tracking features would also work. There are a half-dozen plugins one can add to Ungoogled Chromium to browse the web in (relative) safety. It's not a nation-state level undertaking: six or seven figures. The problem really comes from apps, which are loaded to the gills with spyware.

How can it do that when the server needs an IP address to send traffic to? Cookies just make it more convenient but there is fundamentally that "analog hole". You can Tor things up and obfuscate but if you can interact with them they can track you.

> How can it do that when the server needs an IP address to send traffic to?

https://github.com/bslassey/ip-blindness

Re: Proposal: Treat FLoC as a security concern

#179

Earlier quoted context omitted.

The Verge interpreted MS’s stance on FLoC as a soft no. In any event, it is not an obvious yes. https://www.theverge.com/2021/4/16/22387492/google-floc-ad-t...

This interpretation is missing the important context that the PARAKEET proposal ( https://github.com/WICG/privacy-preserving-ads/blob/main/Par... ) is another strategy for opt-out personalized ad targeting. So they may have technical quibbles or business concerns, but they're not opposed to the core concept.

"At Microsoft, we are committed to fostering a healthy web ecosystem where everyone can thrive – consumers, publishers, advertisers, and platforms alike. Protecting user privacy is foundational to that commitment and is built into Microsoft Edge with features like Tracking Prevention, Microsoft Defender SmartScreen, and InPrivate browsing. We also support an ad-funded web because we don't want to see a day where all quality content has moved behind paywalls, accessible to only those with the financial means.

Through this proposal, we believe we can substantially improve end-user privacy while retaining the ability for sites to sustain their businesses through ad funding. We propose a new set of APIs that leverage a browser-trusted service to develop a sufficient understanding of user interests and therefore enable effective ad targeting without allowing ad networks to passively track users across the web. This approach removes the need for cross-site identity tracking, enables new privacy enabling methods to support monetization, and maintains ad auction functionality within existing ad tech ecosystems."

Re: Proposal: Treat FLoC as a security concern

#180
post #60

Earlier quoted context omitted.

Also, nearly $125B was spent on internet advertising in the US in 2020, per the first estimate I found on the internet [1]. While Google and Facebook keep huge chunks of that, my guess is at least 40% flows through to publishers. So that's a $50B revenue stream to publishers (all sorts of web sites, including news; apps, musicians (via spotify and so forth)) that we're talking about breaking. I really don't believe p…

I feel news was of better quality 15 years ago than today so I wouldn't mind going back to that state of the world. And 15 years ago pervasive tracking wasn't a thing. So yes, please, let's kill it with fire.

> I feel news was of better quality 15 years ago than today

Having been around for the last 30 years (yes, even before the 90s!) I can say that the quality of news and the NUMBER of news sources is far greater. The amount of data online has only increased and has increasingly been sourced. Imagine the world before, when the only source of news was to interview someone in person or read the copy that particular source was using in the narrative.

Post reply on HN