Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

221–230 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#221
post #159

Earlier quoted context omitted.

If you have figured out a way to eliminate tracking, be my guest. Mozilla would like to know, Apple would like to know. Until then FLoC attracts attention because it's new, yes, this explains our reaction. It's still an irrational reaction. Also what's this "predatory targeting of unsophisticated consumers" about? You don't need targeting for this. Heck you don't need anything for this. The way it's usually carried o…

So you're the one who keeps doing that, or is it a group thing? Just curious. It undoubtedly works, but I've always wondered why it's so pervasive.

Congratulations, you win a free iPhone.

Re: Proposal: Treat FLoC as a security concern

#222
post #141

Earlier quoted context omitted.

> Fundamentally better for whom? In the long run it's better for everybody. But it is true that "the long run" can be pretty long. > Do you think Google has never considered that business model? I think Google probably considered it early on but found it easier to go the way they actually went. But "easier" is not the same as "best in the long run". > their current business model will let them extract the most money…

Can you explain how exactly charging their users money is a better long term business model for Google than selling their data? If you don’t count the threat of regulation (since you say it won’t solve the issue) I can’t think of a single piece of evidence supporting that. It sounds like your reasoning is “users will eventually wake up!” which I would bet a lot of money will never happen.

> Can you explain how exactly charging their users money is a better long term business model for Google than selling their data?

Because long term, users will realize that letting their data be sold is bad for them and will stop considering it acceptable. Indeed, that is already happening. And so, as I said, Google will have to continually become more and more evil to try to prop up their business model by further obfuscating what they are doing, until it becomes unsustainable and they crash.

> It sounds like your reasoning is “users will eventually wake up!”

More like: when enough users have suffered serious harm from having their data sold (which is only a matter of time--plenty of users already have suffered harm due to Google's incessant seeking after data--see for example all the furor over the "real names" policy, which was not just Google but they took plenty of flak for it), it will stop being considered acceptable. (Users who already correctly foresee such harms, like me, are already taking whatever precautions we can to avoid providing the data in the first place. I don't use Facebook, I don't use Twitter, I don't use any other social medial "platforms", the only Google services I use are search and maps, and I never click on ads. And I would be glad to pay Google directly for search and maps, if only they would let me do so in order to avoid having what data I do provide them sold to third parties. In fact, given that "freemium" is now a recognized business model, I don't see why they aren't trying it.)

> which I would bet a lot of money will never happen.

Then I assume you are long Google?

Re: Proposal: Treat FLoC as a security concern

#223
post #133

Earlier quoted context omitted.

> The best outcome is to come up with a fundamentally better business model A fundamentally better business model already exists: make users into customers. Google should charge users directly for the services they use. Then they wouldn't need to resort to all these underhanded tactics to try to monetize their valuable services. They could just monetize them directly. Of course this is highly unlikely to happen now t…

Do you think it woukd be better if we were still billed by the kilobyte used? A pay per use or monthly quota would outright discourage curiosity and add in another mental fatigue of tracking costs. Keeping information access gated behind wealth would not be an improvement. Those very real costs outweigh the vague theoretical and frankly some psychologically self-inflicted ones. Your data being monetized by others is…

> Do you think it woukd be better if we were still billed by the kilobyte used?

What does this have to do with Google? Yes, my ISP charges me a flat monthly fee for Internet access, and I prefer that pricing structure to being billed by the kilobyte (not that any ISP I'm aware of tries that any longer). But I'm still paying directly for the service. My ISP doesn't give me my Internet connection for free and then try to monetize it by showing me ads.

> A pay per use or monthly quota would outright discourage curiosity and add in another mental fatigue of tracking costs

Google could use the same pricing structure my ISP does: a flat monthly fee, with no limit on usage, billed to my credit card. No more mental fatigue than "do I have a working Internet connection?", which is exactly how much mental fatigue it takes for me to use Google now.

Would this be a challenge to achieve at scale? Sure. But a company that really took the motto "don't be evil" seriously would be taking on exactly this kind of challenge, precisely because it's a problem that someone is going to have to solve sooner or later, and is worth a lot to whoever solves it because it makes things better for everybody. Who better to do it than Google? But instead of hiring smart engineers to solve this problem, they're hiring smart engineers to figure out better ways to capture users' eyeballs. It's insane.

> Keeping information access gated behind wealth

In a sane society, resources like Google search would be made more widely available by the standard method taught in economics classes: price discrimination. The price they charge for their services would vary according to what the particular customer can easily afford. People in first world countries, like me, might pay $10 or $20 a month. People in the poorest countries, where Internet access itself is not guaranteed, might pay nothing, as they do now. Google has about four billion users and about $180 billion in annual revenue; that works out to an average of $45 a year per user. That seems feasible, if they are allowed to price discriminate. But of course price discrimination is considered "evil", even though it's not--it delivers more value to more people when it is allowed to happen.

> Your data being monetized by others is not an intrinsic harm.

While there are of course ways in which my data can be monetized that don't harm me, I think the actual evidence clearly shows that the ways in which our data is being monetized do carry a high risk of causing harm. "Traffic surveys" is not a good proxy for what most data harvesters are actually doing.

Re: Proposal: Treat FLoC as a security concern

#224
post #67

Earlier quoted context omitted.

Exactly. A big part of the WordPress community are publishers, bloggers, affiliate marketers, etc who rely on ads to generate revenue. I'm not sure they'd be too thrilled with this proposal.

Sure, but this doesn’t mean no advertising, it means no default supporting FLoC. I know advertisers aren’t going to like it, but I doubt it means they’ll give up advertising altogether. I wonder if AdWords will require use of floc headers

> I wonder if AdWords will require use of floc headers

I don't know, but I guess they won't. Instead, you'll just get worse targeting on your site if your users don't send the headers. Which I think may also not be very popular with WordPress users, but I guess the proof will be in the pudding.

Re: Proposal: Treat FLoC as a security concern

#225
post #213
post #150

> Why is this bad? As the Electronic Frontier Foundation explains in their post “Google’s FLoC is a terrible idea“, placing people in groups based on their browsing habits is likely to facilitate employment, housing and other types of discrimination, as well as predatory targeting of unsophisticated consumers. All of this has been happening with tracking cookies, fingerprint tracking, pixel tracking and so on. And wi…

People don't want more things like 3rd party cookies.

The idea is that this is the bare minimum the industry needs in order to stop needing 3rd party cookies (and other tracking strategies).

It's not pretty but on the other end... ads do serve a function. And not all ads are bad. The focus should be on getting rid of the scammy ones, and not tracking won't help much with that.

Re: Proposal: Treat FLoC as a security concern

#226
post #150

> Why is this bad? As the Electronic Frontier Foundation explains in their post “Google’s FLoC is a terrible idea“, placing people in groups based on their browsing habits is likely to facilitate employment, housing and other types of discrimination, as well as predatory targeting of unsophisticated consumers. All of this has been happening with tracking cookies, fingerprint tracking, pixel tracking and so on. And wi…

Third-party cookies can be blocked by technological means. Heck, cookies can be blocked. There's even a toggle in Chrome to disable them, no extension needed. And yet, here we are, attempting to preserve the bucketing of humanity despite what anybody using the browser actually wants.

Re: Proposal: Treat FLoC as a security concern

#227
post #225
post #213

Earlier quoted context omitted.

People don't want more things like 3rd party cookies.

The idea is that this is the bare minimum the industry needs in order to stop needing 3rd party cookies (and other tracking strategies). It's not pretty but on the other end... ads do serve a function. And not all ads are bad. The focus should be on getting rid of the scammy ones, and not tracking won't help much with that.

Fuck the industry. The entire point is to get you to spend more money on stuff. I will do nothing to assist with the brainwashing of humanity, and will continually fight against it.

Re: Proposal: Treat FLoC as a security concern

#228

Earlier quoted context omitted.

If the ToS are contrary to the law, then they are null and void. Laws tend to trump private agreements. Then, if it goes to trial in Europe, they’d have a hard time proving that the ToS are fair and that the user agrees freely and understanding what is being agreed, which is also another condition for any form of contract to be valid.

You're saying there is some law which prevents me from inputting my own data into a program, and it categorizes me into one of a thousand types of people?

My comment was specifically that ToS are not a licence to behave illegally. There is no law preventing you from doing that in general (though there are specific limitations), but there are laws on how PII needs to be processed and stored.

Re: Proposal: Treat FLoC as a security concern

#229
post #185

Earlier quoted context omitted.

yes, laws can prevent you from doing things that, when explained technically and without context, sound trivial and not important.

Does the gdpr or any other law prevent end users processing their own data in their user agents? Or require that headers sent to respected?

The GDPR requires tracking to be opt in. The fact that you have to use special headers to opt out is already problematic. Ignoring the headers to track anyway is of course worse.
Post reply on HN