Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

241–250 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#241
post #15

I am hopeful that this will help get rid of FLoC but I worry about two things. One, this will end up being treated like the "no track" headers. That's just totally ignored after IE (was it IE?) enabled it be default. That gave all the trackers a reason to just ignore it and track everyone. I don't know if that exact same thing can happen here, but something similar maybe? The other thing I worry about is that FLoC 2.…

> "Kill it before it lays eggs." but do we worry about what evolves from this if it dies? Nothing really evolves here - status quo is what stays. You continue to be tracked head to arse on everyones servers, the media keeps adding 150 trackers to every webpage and the internet moves on. Thinking that one of the biggest profit making industries in US will just go away if you scream loud enough on HN is utterly naive a…

> "this gigantic multibillon industry must be banned and completely destroyed"

Which industry? Online advertising? Or the whole sector with Google at the front? I think it's a mistake to assume that tracking and the massive trading in personal information that takes place now is somehow foundational to either industry. Advertising worked before that was a thing and it will continue to work after. The amount of money flowing into advertising won't be dramatically changed because advertising is necessary.

It might be that if online advertising was significantly dumber, money would be shifted from online to print/tv/whatever, but that doesn't mean it's somehow "gone".

Also, if dumber ads are the only ads you can buy, then dumber ads will cost more. Now clever ads cost money (ads with fraud prevention mechanism, conversion tracking, fantastic targeting) costs a lot money. A dumb ad shown to every visitor to a website without any targeting or followup wouldn't bring much money per visitor. But if that dumb ad was what you could do and your other option is a bus stop ad - then you might have to pay a premium for that too. The loss of the ability to track people wouldn't change the laws of supply and demand for advertising space.

Re: Proposal: Treat FLoC as a security concern

#242
post #61

A comment in the WP post brings up the malicious nature of FLOC opt-out - it requires base layer changes to your site. Google knows from Samesite that it requires "your app is going to break" levels of urgency to get old sites to update, and can likely follow the dots to how an opt-out is much less likely to be used than an opt in. This feels like something that should get more attention/discussion. It flew for Sames…

FLoC cohort computation only triggers on websites which call the document.interestCohort API or load ads. So your average website does not have to opt-out. It's not opted-in in the first place.

How likely is it that any third party script would call the API? Most sites I know try to pull in at least one Google hosted script.

Re: Proposal: Treat FLoC as a security concern

#243
I wish someone at Google said "We have this idea that would significantly improve user privacy, and that's through means that would fundamentally hurt our possibility to deliver ads".

Or facebook saying "we have this idea that would improve the experience on our platforms, and we think it's a great idea despite hurting our ability to grow, show ads and our short term bottom line. It actively discourages 'engagement'".

If I had any stock in either company I'd still be delighted about these. I think it's the best long term growth strategy they can have. Focusing not on growth but on users and goodwill.

Re: Proposal: Treat FLoC as a security concern

#244
post #161
post #153

Earlier quoted context omitted.

If we have to be fair, Google didn't build a browser, an email service, a free DNS service, and free hosting/optimization service (AMP) just because, y'know, whatever. I tend to roll my eyes at the blind hatred of corporations, but we also have to have both feet firmly on the ground, that these products and services are strictly tied to long-term plans for ROI. What kind of a ROI would the biggest advertising network…

Look at gmail: I pay $60/year-ish for Fastmail. Gmail is at least that good. So is the purpose of gmail to have a cross device stable identifier? Absolutely. Are people realizing tons of value from it for free? Also yes.

I expect to get a gmail type service paying only the "price" of having some unobtrusive ads when I'm on the gmail site, nothing else.

I absolutely do not agree to google using anything from gmail to generate a stable user id for advertising, or e.g. show me ads in google search results or youtube videos, based on analysis of email content.

If Google can't provide what I expect (a free mail service paid only by ads on gmail dot com) they should tell me that they want $X per year and I'd happily pay it. It's not that I don't want to fund the operations of services, it's that I'm always assumed to rather pay with my information than with dollars.

Re: Proposal: Treat FLoC as a security concern

#245

From my surface level reading of FLoC - would it be possible for Edge or Mozilla to implement FLoC - but to send noise / random / incorrect data up in a way that essentially wrecks the algorithm?

This should be done at extension level not browser level.

Re: Proposal: Treat FLoC as a security concern

#246
post #194

Earlier quoted context omitted.

It is not clear to me at all what the overall view is on FLoC. Brave and Vivaldi don't like it, sure, but they already ship with built-in ad blockers so of course they don't. People here who don't like it also seem to be against advertising in any form beyond direct deals between publishers and advertisers for https://advertiser.example/ad ">. If there are people who are (a) ok with personalized ads, providing they c…

People here who don't like it also seem to be against advertising in any form beyond direct deals between publishers and advertisers I doubt many people object to ad networks and real time bidding; it's just that the user's personal information shouldn't be exposed in the process. Yes, that means the only signals you'd get are the current page, and maybe high-level OS/browser/device info. (a) ok with personalized ads…

>> providing they can be done sufficiently privately

> what you're describing is fundamentally impossible

I guess the question is what you would consider to be sufficiently private? For example, would it be sufficient for the advertiser to be completely unable to distinguish you from a sufficiently large group of people with similar behavior?

Re: Proposal: Treat FLoC as a security concern

#247
post #194

Earlier quoted context omitted.

It is not clear to me at all what the overall view is on FLoC. Brave and Vivaldi don't like it, sure, but they already ship with built-in ad blockers so of course they don't. People here who don't like it also seem to be against advertising in any form beyond direct deals between publishers and advertisers for https://advertiser.example/ad ">. If there are people who are (a) ok with personalized ads, providing they c…

I mean, the issue is personalized ads. It shouldn't exist, and advertisers would make just as much money without it if it were illegal. Content-based targeting has worked for decades and does work today. Sites have target markets, ads have target markete, connect these and you are serving ads to the right people, without compromising their privacy.

> the issue is personalized ads. It shouldn't exist

Why shouldn't personalized ads exist?

> advertisers would make just as much money without it if it were illegal

It depends very much on the advertiser. Advertisers with broad interest or close matches to specific publication types, sure, but that's not everyone. One way to think of this would be to imagine a world in which advertisers couldn't even choose where their ad appeared -- they would make less money then, without the ability to target contextually, right? There are many valuable transactions that only happen because the right information is given to the right person, and the less well-targeted ads are the more of those you lose.

The story is even worse for publishers. There are major kinds of publishing with negligible commercial tie-in. Historically, the expense of producing a newspaper or magazine meant that you were never holding a single article, and it could be treated essentially as one unit for advertising purposes. But now it is very common for articles to be shared in isolation, which means this cross-subsidy disappears.

Re: Proposal: Treat FLoC as a security concern

#248
post #242

Earlier quoted context omitted.

FLoC cohort computation only triggers on websites which call the document.interestCohort API or load ads. So your average website does not have to opt-out. It's not opted-in in the first place.

How likely is it that any third party script would call the API? Most sites I know try to pull in at least one Google hosted script.

You may have to audit third-party scripts before using them (which is not a bad idea regardless of FLoC).

If you load Google Analytics on your site, I feel like you have no right to complain that it may track users...

Re: Proposal: Treat FLoC as a security concern

#249
post #232

Earlier quoted context omitted.

> Not true, FireFox and Safari have had them off by default for over a year now. Not quite. They will block some 3rd party tracking cookies that fall on their tracking blacklist. If you want to block all 3rd party cookies you have to explicitly disable them.

Safari does actually block all third party cookies by default, not just a subset. And has been doing so for about a year now.

If I understand correctly, they allow 3rd-party cookies but delete them at the end of the browsing session rather than respecting the expiry.

Re: Proposal: Treat FLoC as a security concern

#250
post #157

Ah come on. The FLoC proposal has built in ways to turn it off. If you don't wanna be put in a cohort you can just configure your browser (even chrome) to say you don't have one.

If it's not opt in, it's malware and should be treated as such. Don't let Google gaslight you.

It's sort of opt-in.

For websites, FLoC cohort computation only triggers if you call the document.interestCohort API or load ads - these actions are considered an opt-in. (https://github.com/WICG/floc/issues/103)

For users, it's sort of opt-in, too: You must be logged into a Google account, must have enabled Chrome history data sync, must not block third-party cookies, must have enabled Google web activity tracking and must have enabled ad personalization. (https://github.com/WICG/floc#qualifying-users-for-whom-a-coh...)

Also, you can disable FLoC via chrome://settings/privacy or chrome://flags. (https://github.com/WICG/floc/issues/103#issuecomment-8218146...)

It's not a perfect opt-in, but it's also not malware.

Post reply on HN