Live data from Hacker News

Google’s approach to replacing the cookie is drawing antitrust scrutiny

digiday.com

221–230 of 354 posts

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#221
post #160

Earlier quoted context omitted.

> I hope no one is saying Privacy Sandbox is worse than third party cookies Sort of like saying: "I hope no one is saying having a tracker in your car is worse than having a guy following you around." Sure, it's better. But it's not good either.

Of course it isn't good. This is HN, and we want the web advertising industry to go away. However, that's not going to be the outcome. Antitrust scrutiny in this case means making it more fair to third party advertisers...the people who will be hit most by third party cookie disabling. As much as we want to hate on Google, articles like this won't make them move toward more privacy.

>This is HN, and we want the web advertising industry to go away

I had a chuckle from this, but many here seem to be taking the statement at face value.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#222
post #73

This post got me into looking up what Google's privacy sandbox actually is. One proposal I found quite interesting was TURTLEDOVE, which proposes to move ad bidding onto the user device [1]. The current proposal of course uses bidding logic delivered by the ad seller. However, if this were to gain wide adoption, the step to imposing user control over bidding gets a bit smaller. Imagine being able to tell advertisers…

> "ok I'll look at any ad that pays me at least 50 cents"

Personalised advertisement industry is inherently harmful. Remember, the end goal is to charge the user as much as they are willing to pay.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#223

Earlier quoted context omitted.

Nothing is free however. If advertisers can't violate one's privacy, that simply means they will pay less to the websites one uses, and that will lead to its quality deteriorating, or even more extreme content filters to appease advertisers and remain afloat.

You're assuming people won't create great things without ad profit. I submit Open Source and Wikipedia as evidence to the contrary. Not making a profit on the original creative act might lead to larger profits for society overall and indirect advantages to the original creators. And usually content created for profit is quite untrustworthy, I prefer content created out of passion. It's the ad based content creators w…

> You're assuming people won't create great things without ad profit. I submit Open Source and Wikipedia as evidence to the contrary. Not making a profit on the original creative act might lead to larger profits for society overall and indirect advantages to the original creators.

Both examples you listed are products that are feasibly created by the many small contributors. Many products cannot feasibly be created in such a manner and rely on some manner of income to remain feasible.

There are quite a few content creators that are capable of producing content because their efforts are supported by advertisement. It would be hard for them to operate on the many small contributions-model.

> And usually content created for profit is quite untrustworthy, I prefer content created out of passion.

Few men enjoy the luxury to devote so much time to their passions when other parts of their time are allocated to securing the income they need to feed themselves.

> Also, there's nothing wrong with ads, but they need to be topical to the content at hand, not targeted to users.

This situation would indeed benefit the visitor more; it would not benefit the advertiser, nor the middleman, nor the space where the advertisement stands.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#224

Earlier quoted context omitted.

You present a false dichotomy. "Google's Privacy Sandbox" versus Third Party Cookies, as if those are the only alternatives. Now you are following along with another false dichotomy! > This is HN, and we want the web advertising industry to go away. Here's a crazy idea. We don't need either Google's monopoly preserving Privacy "Sandbox" or third party cookies... and we don't need to do away with web advertising. We'r…

I'll add a third option: neither! Seriously, I've had 3rd party cookies disabled four years and almost nothing breaks. The last time I remember needing to enable them was some online homework system that came with a math textbook.

I feel like there are some misunderstandings in this thread. Let me summarize my understanding:

Safari has effectively disabled third party cookies. Nothing broke. Chrome has announced that they will do the same in 2022. However, unlike Apple, Google doesn't want to cannibalize the ad industry so they decided to introduce this Privacy Sandbox which allows targeted advertising without sending a personal identifier to the server.

The article that we are discussing is saying that this Privacy Sandbox will favor Google Ads. The top comment said that this article is likely astroturfing. It written by people affiliated with other ad networks, whose goal is to water down the Privacy Sandbox proposal so that it enables more tracking.

Some people have said that they don't trust Google to implement Privacy Sandbox in a privacy friendly way, so it shouldn't exist at all. But that was never really on the table.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#226
post #73

This post got me into looking up what Google's privacy sandbox actually is. One proposal I found quite interesting was TURTLEDOVE, which proposes to move ad bidding onto the user device [1]. The current proposal of course uses bidding logic delivered by the ad seller. However, if this were to gain wide adoption, the step to imposing user control over bidding gets a bit smaller. Imagine being able to tell advertisers…

> "ok I'll look at any ad that pays me at least 50 cents" Personalised advertisement industry is inherently harmful. Remember, the end goal is to charge the user as much as they are willing to pay.

How is that inherently harmful? Doesn't charging a large sum for something offered by an ad mean, that the ad provided something of value to the user? My issue with personalized ads isn't that users end up spending money on what they offer; it's the potential for the collection of that pervasive data to negatively impact the user and broader society.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#227

It is so annoying to see that HN and general media have collectively decided that Google and everything it does is evil, but honestly you have no idea how good you have it right now. Google is not abusing your user data like you are made to think. If you talk to a Google engineer, you would realise the countlesss number of measures they take to safeguard user's data - human access is next to impossible. Only machines…

I never understood why an individual would go out of their way to defend a corporation. Otherwise, found a "google engineer".

The issue most people have with it is the amount of data collected unnecessarily, rather than the practices around safeguarding it. Many "small startups" wouldn't collect it in the first place and it would be a non-issue. Even when "small startups" are collecting more information as they should, it's not in one basket and has less value without context.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#228
post #190
post #160

Earlier quoted context omitted.

Of course it isn't good. This is HN, and we want the web advertising industry to go away. However, that's not going to be the outcome. Antitrust scrutiny in this case means making it more fair to third party advertisers...the people who will be hit most by third party cookie disabling. As much as we want to hate on Google, articles like this won't make them move toward more privacy.

I don't want web advertising to go away. The issue here is excessively intrusive tracking, not the ads themselves. Otherwise how are Youtube creators, newspapers, Firefox, etc going to operate with out it? Companies adding multiple megabytes of JS tools is probably another issue entirely as they often involve a variety of crap like 2-3 ad publishers, content recommendation services (chum), 5 different analytics and a…

« The issue here is excessively intrusive tracking, not the ads themselves.»

I use privacy badger as an ad blocker, even though it does not target ads. It somehow block privacy intrusive domains, which happen to be related to ads.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#229

Earlier quoted context omitted.

[I work at Google, not on chrome] The current text of the whitepaper is "The combined state of these variations is non-identifying, since it is based on a 13-bit low entropy value (see above). These are transmitted using the "X-Client-Data" HTTP header, which contains a list of active variations"[0]. The X-Client-Data header is still described as non-identifying. You're reaching for controversy where there is none. I…

> The X-Client-Data header is still described as non-identifying. That's a false description. 13 bits of entropy is more than most existing fingerprinting vectors. This header allows clients behind NAT to be identified with significantly greater precision. > There's no rational basis for Google doing what people suggest it's doing. There is. Their business lives and dies on their ability to track web users, and track…

> That's a false description. 13 bits of entropy is more than most existing fingerprinting vectors. This header allows clients behind NAT to be identified with significantly greater precision.

That doesn't make the X-Client-Data header identifying. Or, if it does, then your definition of "identifying information" is exactly equivalent to your definition of "information", because it is true that any particular axis or piece of data can be used to identify clients with greater precision. The rest is just how identifying the information is. Country is identifying, as is first digit of IP address, but both are less identifying than MAC address or first name. You're welcome to subscribe to such a definition, but it's not the normal one (which is usually that said piece of data can be tied to a specific individual, although you may not be able to correlate that particular individual with a name or similar).

Under this definition, I'd probably agree that the combination of IP address and X-client-data header is identifying, but that's also not a thing anyone is going to be using, because it's not particularly useful.

> There is. Their business lives and dies on their ability to track web users

Sort of. The value of tracking individual users at the granularity you suggest is, as far as I know, dubiously valuable, and importantly, there's no reason to believe it's done. Like there's no evidence to support this beyond the conjecture.

> This is (obviously) about the hundreds of millions of Chrome users who are not logged in, and as I said above, 13 bits of entropy isn't marginal.

But if you're in this situation, and again, Google is being unethical, there are a host of other tracking tools that provide 13 or more bits of entropy that they can use.

> Nobody "lied" per se, but the end result is the same.

I'd classify that as lying (for actually more than one reason). But I'll just leave you with the same point I made to 0xy the last time this was brought up: this X-client-Data header is nearly 9 years old. When it was introduced it was considered nonidentifying and was used for chrome experiments. It is still considered nonidentifying and used for chrome experiments.

And this is why the whole idea doesn't make sense: if the header was introduced now, I could see this train of thought making sense. But it wasn't recently introduced. They've had more than 8 years to use it while there have been all kinds of other ways to get additional bits.

So now your chain of reasoning is more like

1. Telemetry is introduced and a restrictive policy is established, e.g. "we won't use this to track people.

2. 6-12 years pass, multiple executives pass through the area. The CEO of the company changes twice. The entire org chart shifts and metamorphizes more than once. The policies are maintained.

3 [concurrently with 2]. A number of nations pass new privacy laws. Previously, using this particular set of data to track individuals would have been unethical, but legal. It is now both unethical and illegal in many places.

4. Google invests significantly in a different, somewhat privacy preserving alternative to individually identifying tracking technology which is openly criticized because it is mediocre in terms of privacy preservingness.

5. At some point between 2 and 4, they started actively breaking the law by using this can't-be-used-to-identify telemetry to identify unique users. And instead of completely hiding this fact, using it as a competitive advantage, and openly being a leader in privacy (for example by being an early proponent and supporter of things like 3rd party cookie restrictions), they don't do that, and instead suffer reputational harm due to the existing tracking, the telemetry illegally used for tracking, and the proposed new scheme for privacy preserving tracking that is inferior to the illegal telemetry-based approach.

It's a line of reasoning that requires that Google be simultaneously incredibly unethical and incredibly inept. It doesn't make sense.

Re: Google’s approach to replacing the cookie is drawing antitrust scrutiny

#230
post #214

Earlier quoted context omitted.

[I work at Google, not on chrome] The current text of the whitepaper is "The combined state of these variations is non-identifying, since it is based on a 13-bit low entropy value (see above). These are transmitted using the "X-Client-Data" HTTP header, which contains a list of active variations"[0]. The X-Client-Data header is still described as non-identifying. You're reaching for controversy where there is none. I…

The fact it is undisclosed to users, unjustified (they could get the same result by sending the header to GTM) and impossible to disable make it nefarious. Google have a header being sent to advertising domains that can be used for tracking purposes , Google didn't ever disclose this fact, and Google made it impossible to disable. Already that's nefarious. "Just trust us, we won't abuse this!" is not good enough, con…

> they could get the same result by sending the header to GTM

Do you mean Tag manager, or some other GTM?

I also, and this'll be seriously counterintuitive, doubt that they could be quite as conscientious of user data if they were handled via GTM. To sketch out the concern here: Chrome telemetry that is not used to identify people and personal ad preferences/data tied to an individual user probably shouldn't be sent via the same channel or logged in the same place. They're used for different purposes, by different people, and likely have different infrastructural concerns related to storage and querying. In fact, it would be rather suspicious if chrome telemetry data was sent via Google's ads logging infrastructure. That would imply an odd level of co-design and coupling.

> sent to DoubleClick explicitly

And everything else owned by Google. It's not sent to Doubleclick specifically, which you never seem to acknowledge. It's sent to stuff that Google owns (and presumably, really just a large selection of things sitting behind the GFE[0]).

> For ad networks, including Google's own ad department, Chrome is like a candy store. Firefox and Safari have tracking prevention and cookie mitigations. Chrome on the other hand has undisclosed, impossible to disable ad network tracking headers being sent to DoubleClick explicitly. Chrome's cookie security is similarly a joke, designed for the benefit of ad networks.

Firefox does the same thing as chrome (via Firefox Telemetry). There's privacy tradeoffs between the two approaches, Firefox's allows the telemetry holder to reconstruct browsing data for a particular user (assuming the browser sends the data out of band to some central server). Google's approach doesn't allow that. There's also some technical advantages to Google's approach in terms of telemetry (both for Chrome and for Google sites), but those don't affect the privacy tradeoffs of how the telemetry is ultimately reported.

> Google didn't ever disclose this fact

You mean except in the Chrome whitepaper.

> "Just trust us, we won't abuse this!" is not good enough, considering the way it was implemented is already cloak-and-dagger suspicious.

But, like, it's not. The lengths you have to go to to make it appear suspicious (including lying repeatedly about how Google didn't disclose the feature) demonstrate how it's not in fact that suspicious. Yes, when you misrepresent the facts, it begins to sound suspicious. But that's because you're misrepresenting what was actually done.

[0]: https://sre.google/sre-book/production-environment/

Post reply on HN