Earlier quoted context omitted.
True, but modifying core files to send the header isn't good either because you'll have to redo the change at every update. Also, most security plugins such as Wordfence will choke on a modified core file, and rightly so.
You can chuck the same hook (as seen in the original link) into your theme's functions.php file. Or make your own plugin to hold miscellany.
Proposal: Treat FLoC as a security concern
231–240 of 274 posts
Re: Proposal: Treat FLoC as a security concern
#232Earlier quoted context omitted.
> Third party cookies, love them or hate them, have been with us for a long time, and simply dropping them would not be viable without the long phase out. Not true, FireFox and Safari have had them off by default for over a year now. Additionally Chrome had planned to turn them off last year but then cried "covid" which for some reason = delay... because... think of the adverts! i mean covid! Anyway, I'm pretty sure…
> Not true, FireFox and Safari have had them off by default for over a year now. Not quite. They will block some 3rd party tracking cookies that fall on their tracking blacklist. If you want to block all 3rd party cookies you have to explicitly disable them.
Re: Proposal: Treat FLoC as a security concern
#233Earlier quoted context omitted.
Care to reach out? This username at Microsoft. We're working to understand what legitimate use cases are broken without 3p cookies so we can work with Google to backfill them. FLOC helps ad trackers track but doesn't help with any of the legitimate uses of 3p cookies like auth.
Auth should be doable with just redirects though right? Isn't that how OAuth and OpenID connect work?
Re: Proposal: Treat FLoC as a security concern
#234Earlier quoted context omitted.
Third party cookies, love them or hate them, have been with us for a long time, and simply dropping them would not be viable without the long phase out. And a long phase out is not something around which you can form a singular rallying cry. FLoC is a new thing which is just being rolled out, so it's a lot easier for people to resist adding a new thing that makes the internet more crappy and less private. I think it'…
If you have figured out a way to eliminate tracking, be my guest. Mozilla would like to know, Apple would like to know. Until then FLoC attracts attention because it's new, yes, this explains our reaction. It's still an irrational reaction. Also what's this "predatory targeting of unsophisticated consumers" about? You don't need targeting for this. Heck you don't need anything for this. The way it's usually carried o…
Re: Proposal: Treat FLoC as a security concern
#235Earlier quoted context omitted.
People don't want more things like 3rd party cookies.
The idea is that this is the bare minimum the industry needs in order to stop needing 3rd party cookies (and other tracking strategies). It's not pretty but on the other end... ads do serve a function. And not all ads are bad. The focus should be on getting rid of the scammy ones, and not tracking won't help much with that.
Re: Proposal: Treat FLoC as a security concern
#236We're already being tracked & targeted by people we should've been able to trust.
We've all seen the damage that anonymity can do. I changed my mind. I used to support EFF.org in many of their stances, but at this point it seems inevitable that everyone will be forced out into the open online and forced to use their real identity online to put an end to the endless information warfare.
Unless someone can convince me that all this garbage we have going on now is somehow worth hanging onto. I'm open minded, but dudes and dudettes... what in the actual fuck is going on with social media, bot nets, people with dozens or more accounts manipulating online reviews and swaying elections in favor of nazis.
It has to end.
Re: Proposal: Treat FLoC as a security concern
#237> Why is this bad? As the Electronic Frontier Foundation explains in their post “Google’s FLoC is a terrible idea“, placing people in groups based on their browsing habits is likely to facilitate employment, housing and other types of discrimination, as well as predatory targeting of unsophisticated consumers. All of this has been happening with tracking cookies, fingerprint tracking, pixel tracking and so on. And wi…
Third party cookies, love them or hate them, have been with us for a long time, and simply dropping them would not be viable without the long phase out. And a long phase out is not something around which you can form a singular rallying cry. FLoC is a new thing which is just being rolled out, so it's a lot easier for people to resist adding a new thing that makes the internet more crappy and less private. I think it'…
What exactly about FLoC is making the internet less private though? Every time I see the technology it seems that it's deliberately built to keep private data in your Chrome browser and leak significantly less than anything else Ad related right now.
Also, why is WordPress allowing so many ad and anlytics tracking plugins and not considering those as security issues?
Re: Proposal: Treat FLoC as a security concern
#238Earlier quoted context omitted.
> "Kill it before it lays eggs." but do we worry about what evolves from this if it dies? Nothing really evolves here - status quo is what stays. You continue to be tracked head to arse on everyones servers, the media keeps adding 150 trackers to every webpage and the internet moves on. Thinking that one of the biggest profit making industries in US will just go away if you scream loud enough on HN is utterly naive a…
We should keep in mind why Google invests in FLoC, though. Either they realize third party cookies are on a (regulated) dead end. Or they realize there is a bigger moat. Or something else that helps them. But in any case, seeing the current Google, this is not something benefitting their users(products?) primarily. Unless some benefits accidentally aligned. So, pushing back towards the broken status quo may be the ri…
Is that really so hard to figure out? Google wants to continue running their Ad network and they've been under attack for collecting data.
FLoC seems to significantly reduce the need to data collection while still enabling their core business to continue.
I might be wierd, but this still seems like a major win to me - since I care about my data not being stored somewhere off my devices and FLoC keeps it on my terminal equipment. And it allows my Firefox to send customized or faked data.
Re: Proposal: Treat FLoC as a security concern
#239Earlier quoted context omitted.
> "Kill it before it lays eggs." but do we worry about what evolves from this if it dies? Nothing really evolves here - status quo is what stays. You continue to be tracked head to arse on everyones servers, the media keeps adding 150 trackers to every webpage and the internet moves on. Thinking that one of the biggest profit making industries in US will just go away if you scream loud enough on HN is utterly naive a…
Only govt action will work. That too concerted action by several national govts.
Any government action will be a compromise by necessity. Which is why I think EFF doesn't really push for it - even GDPR doesn't ban targeted advertising in full.
Re: Proposal: Treat FLoC as a security concern
#240Earlier quoted context omitted.
I am a bit uneducated at this but does Brave browser which is based on chromium also have the same problem?
No, Brave removes everything that has to do with Google from the browser.