Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

211–220 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#211
post #2

WordPress is 41% of the web. If this goes through and FLoC is disabled by default by WordPress, will FLoC be dead on arrival?

FLoC is designed to be opt-in, so uh...... no?

Currently, for A/B testing, FLoC is automatically opting-in 0.5% of sites that serve ads, but that's only for a small testing population, the idea is that FLoC history contribution will be opt-in exclusively. (There's a proposal that you have to contribute to FLoC history calculations to get access to a user's FLoC identifier)

Re: Proposal: Treat FLoC as a security concern

#212
post #61

A comment in the WP post brings up the malicious nature of FLOC opt-out - it requires base layer changes to your site. Google knows from Samesite that it requires "your app is going to break" levels of urgency to get old sites to update, and can likely follow the dots to how an opt-out is much less likely to be used than an opt in. This feels like something that should get more attention/discussion. It flew for Sames…

FLoC cohort computation only triggers on websites which call the document.interestCohort API or load ads. So your average website does not have to opt-out. It's not opted-in in the first place.

Re: Proposal: Treat FLoC as a security concern

#213
post #150

> Why is this bad? As the Electronic Frontier Foundation explains in their post “Google’s FLoC is a terrible idea“, placing people in groups based on their browsing habits is likely to facilitate employment, housing and other types of discrimination, as well as predatory targeting of unsophisticated consumers. All of this has been happening with tracking cookies, fingerprint tracking, pixel tracking and so on. And wi…

People don't want more things like 3rd party cookies.

Re: Proposal: Treat FLoC as a security concern

#214
post #150

> Why is this bad? As the Electronic Frontier Foundation explains in their post “Google’s FLoC is a terrible idea“, placing people in groups based on their browsing habits is likely to facilitate employment, housing and other types of discrimination, as well as predatory targeting of unsophisticated consumers. All of this has been happening with tracking cookies, fingerprint tracking, pixel tracking and so on. And wi…

I think many people would disagree with the conclusion to your second paragraph. If you don’t take it as given that something must come and replace cookies then FLoC appears to be an attempt to rebuild that which was just cast into the bin of history.

Re: Proposal: Treat FLoC as a security concern

#215
post #204
post #200

Earlier quoted context omitted.

Care to reach out? This username at Microsoft. We're working to understand what legitimate use cases are broken without 3p cookies so we can work with Google to backfill them. FLOC helps ad trackers track but doesn't help with any of the legitimate uses of 3p cookies like auth.

Auth should be doable with just redirects though right? Isn't that how OAuth and OpenID connect work?

Same thought. I’m curious to know what other kinds of authentication protocols require third-party cookies to operate. Within OIDC, even more obscure/advanced features such as session management and global logout require only 1st party (the IdPs) cookies in order to function.

I guess the tradeoff being made here is just leaning into our reliance on the certificate authority system. Whereas before, with third party cookies, you might have had more flexibility with how you structure your domains.

Re: Proposal: Treat FLoC as a security concern

#216
post #194

Earlier quoted context omitted.

So probably the phasing out third-party cookies will be postponed due to these reaction?

It is not clear to me at all what the overall view is on FLoC. Brave and Vivaldi don't like it, sure, but they already ship with built-in ad blockers so of course they don't. People here who don't like it also seem to be against advertising in any form beyond direct deals between publishers and advertisers for https://advertiser.example/ad ">. If there are people who are (a) ok with personalized ads, providing they c…

People here who don't like it also seem to be against advertising in any form beyond direct deals between publishers and advertisers

I doubt many people object to ad networks and real time bidding; it's just that the user's personal information shouldn't be exposed in the process. Yes, that means the only signals you'd get are the current page, and maybe high-level OS/browser/device info.

(a) ok with personalized ads, providing they can be done sufficiently privately

My opinion, which I think is fairly common around here, is that what you're describing is fundamentally impossible. Much like the incessant government demands for encryption backdoors that don't compromise security.

Re: Proposal: Treat FLoC as a security concern

#217
post #150

> Why is this bad? As the Electronic Frontier Foundation explains in their post “Google’s FLoC is a terrible idea“, placing people in groups based on their browsing habits is likely to facilitate employment, housing and other types of discrimination, as well as predatory targeting of unsophisticated consumers. All of this has been happening with tracking cookies, fingerprint tracking, pixel tracking and so on. And wi…

The issue really is: Google isn't phasing our 3rd party cookies out of charity. They are clearly looking for a way to keep doing all the things third-party cookies enable after they go away. Here we find people saying (through legislative and regulatory action) that they want to end the use of 3rd party cookies because the bad behaviors they enable, and they are rightly outraged at the efforts to comply with the lett…

Why is firefox phasing out 3rd party cookies? Is it out of charity?

Re: Proposal: Treat FLoC as a security concern

#218

I've not been following this proposal closely I did find https://github.com/WICG/floc >Tracking people via their cohort >A cohort could be used as a user identifier. It may not have enough bits of information to individually identify someone, but in combination with other information (such as an IP address), it might. Whose purpose is: >A FLoC cohort is a short name that is shared by a large number (thousands) of peo…

"Could the cohort minimum size be configurable?" this is a good idea, but unfortunately it would just lead to MORE ways to track users, since "size of cohort" is now a (probably very, very high entropy, given how many users never configure anything) source of information

The benefit of FLoC is that you will need to go out of your way to track and de-anonymize your users. Yes, it can probably be done with enough data. But it is literally the simplest operation in the world with 3P cookies, so simple that tracking users across the internet may just happen on accident. That is unlikely to happen with FLoC.

Re: Proposal: Treat FLoC as a security concern

#219
post #194

Earlier quoted context omitted.

So probably the phasing out third-party cookies will be postponed due to these reaction?

It is not clear to me at all what the overall view is on FLoC. Brave and Vivaldi don't like it, sure, but they already ship with built-in ad blockers so of course they don't. People here who don't like it also seem to be against advertising in any form beyond direct deals between publishers and advertisers for https://advertiser.example/ad ">. If there are people who are (a) ok with personalized ads, providing they c…

I mean, the issue is personalized ads. It shouldn't exist, and advertisers would make just as much money without it if it were illegal. Content-based targeting has worked for decades and does work today. Sites have target markets, ads have target markete, connect these and you are serving ads to the right people, without compromising their privacy.

Re: Proposal: Treat FLoC as a security concern

#220
post #183
post #155

Earlier quoted context omitted.

Third party cookies, love them or hate them, have been with us for a long time, and simply dropping them would not be viable without the long phase out. And a long phase out is not something around which you can form a singular rallying cry. FLoC is a new thing which is just being rolled out, so it's a lot easier for people to resist adding a new thing that makes the internet more crappy and less private. I think it'…

> Third party cookies, love them or hate them, have been with us for a long time, and simply dropping them would not be viable without the long phase out. Not true, FireFox and Safari have had them off by default for over a year now. Additionally Chrome had planned to turn them off last year but then cried "covid" which for some reason = delay... because... think of the adverts! i mean covid! Anyway, I'm pretty sure…

> Not true, FireFox and Safari have had them off by default for over a year now.

Not quite. They will block some 3rd party tracking cookies that fall on their tracking blacklist. If you want to block all 3rd party cookies you have to explicitly disable them.

Post reply on HN