Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

21–30 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#22

Earlier quoted context omitted.

Most likely google will just turn off that silly opt out functionality. It's not like anyone's going to stop using their spyware browser.

Surely that depends on what their experience using it is, just like every other "winning" browser before that is no longer winning? If FLoC generates so much hostility within the web dev community that a few major sites/platforms start actively blocking it, and if Google responds by ignoring the opt-outs in Chrome, and if the community responds with a SOPA-like "no access using Chrome for the next 48 hours then, here…

>and if the community responds with a SOPA-like "no access using Chrome for the next 48 hours then, here are some other fine browsers you can use instead that don't invade your privacy in this way"

that seems unlikely.

Re: Proposal: Treat FLoC as a security concern

#25

Earlier quoted context omitted.

We're already successfully killing third party cookies and most browser fingerprinting strategies. This is an attempt by a browser to build an intentionally user hostile mechanic to compensate, but we can kill this too. We just need to continue to make it increasingly impractical and expensive to track users until it stops being considered a viable business strategy.

What do you mean? They are widely used, which seems far from dead. Aren’t you declaring victory too early?

These are strategies that are being aggressively restricted. Chrome has not started preventing third party cookies yet, but they're the last holdout and have already stated they will kill them shortly.

If you're using a non-user-hostile browser, these strategies are already heavily limited by default and are already not a concern. Every Firefox release is making significant improvements on reducing the fingerprinting footprint of the browser, and several user-hostile API features proposed by Google have been rejected by them and Safari to prevent expanded fingerprinting.

Re: Proposal: Treat FLoC as a security concern

#26
post #2

WordPress is 41% of the web. If this goes through and FLoC is disabled by default by WordPress, will FLoC be dead on arrival?

Most likely google will just turn off that silly opt out functionality. It's not like anyone's going to stop using their spyware browser.

Chrome is entranched, but not like IE was. You have to install the browser in the first place, which means the moment it starts to be too crappy people move elsewhere.

Why do you think Google hasn't prevented adblockers from running on it? If they did so, it would sink the browser so quickly.

Re: Proposal: Treat FLoC as a security concern

#27

Earlier quoted context omitted.

"WordPress is 41% of the web" This blows my mind every time. Even though I know it.

I don’t know it. Where did you learn it?

https://w3techs.com/technologies/overview/content_management

41.1% of websites

Re: Proposal: Treat FLoC as a security concern

#28

Earlier quoted context omitted.

We're already successfully killing third party cookies and most browser fingerprinting strategies. This is an attempt by a browser to build an intentionally user hostile mechanic to compensate, but we can kill this too. We just need to continue to make it increasingly impractical and expensive to track users until it stops being considered a viable business strategy.

What do you mean? They are widely used, which seems far from dead. Aren’t you declaring victory too early?

Safari and Firefox already block them by default, and Chrome is set to block them before 2022: https://www.wired.co.uk/article/google-chrome-cookies-third-...

The FLoC proposal (and others) are happening now because of the coming cookiepocalypse.

Re: Proposal: Treat FLoC as a security concern

#30

From my surface level reading of FLoC - would it be possible for Edge or Mozilla to implement FLoC - but to send noise / random / incorrect data up in a way that essentially wrecks the algorithm?

Then advertisers will fingerprint the browser as well, to see whether the FLoC data can be trusted.
Post reply on HN