Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

261–270 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#261

Earlier quoted context omitted.

The issue really is: Google isn't phasing our 3rd party cookies out of charity. They are clearly looking for a way to keep doing all the things third-party cookies enable after they go away. Here we find people saying (through legislative and regulatory action) that they want to end the use of 3rd party cookies because the bad behaviors they enable, and they are rightly outraged at the efforts to comply with the lett…

Why is firefox phasing out 3rd party cookies? Is it out of charity?

Firefox is not a product of the 800lb gorilla of targeted ad revenue. The Mozilla foundation could live without the ad revenue tied 3rd party cookies. They feel pressure from their users (people like us) who want to not be tracked everywhere, and ending the use of 3rd party cookies is one technical step.

At some point in the past year it seems the privacy concerns reached a critical mass. The Mozilla foundation is responding in ways to keep its browser share relevant.

Re: Proposal: Treat FLoC as a security concern

#262
post #173

It’s a opportunity to put priv engineering techniques to the test in prod, at least. That’s 100% the main thing that stands out here. In the raw browser history, prior to ~hashing it to a FLoC ID, can Google anon PII while still maintaining good data analytics from the rest* of the dataset’s fields? Priv engineer, as an engineering discipline, would argue yes. If this is what Google does and the privacy is put throug…

> can a FLoC ID de-anon into a user? Currently yes and seems like a though problem to solve (there are trade offs but it's likely that this will never be fully solved, like encryption, you can only make it so difficult that it isn't worth doing it but not impossible to do): https://github.com/WICG/floc/issues/100

Very cool I’ll check it out.

I’ll push back on it being tough to solve — unless you’ve looked into privacy engineering and have some further data in that direction.

Whole field exists to de-link PII to data that supports business analytics, and the tech is there at a non-tough level for Google to achieve.

Re: Proposal: Treat FLoC as a security concern

#263

Earlier quoted context omitted.

The issue really is: Google isn't phasing our 3rd party cookies out of charity. They are clearly looking for a way to keep doing all the things third-party cookies enable after they go away. Here we find people saying (through legislative and regulatory action) that they want to end the use of 3rd party cookies because the bad behaviors they enable, and they are rightly outraged at the efforts to comply with the lett…

Why is firefox phasing out 3rd party cookies? Is it out of charity?

Yes. Mozilla is a non-profit, pretty much everything they do is out of charity.

Re: Proposal: Treat FLoC as a security concern

#264

Earlier quoted context omitted.

Why is firefox phasing out 3rd party cookies? Is it out of charity?

Yes. Mozilla is a non-profit, pretty much everything they do is out of charity.

Sort of true. To know what a non-profit's motivations are, look at the biggest donors and donations. Some of the Mozilla Foundation's money comes from the Mozilla Corporation, which does get a lot of money from the big tech companies.

Re: Proposal: Treat FLoC as a security concern

#265
post #183
post #155

Earlier quoted context omitted.

Third party cookies, love them or hate them, have been with us for a long time, and simply dropping them would not be viable without the long phase out. And a long phase out is not something around which you can form a singular rallying cry. FLoC is a new thing which is just being rolled out, so it's a lot easier for people to resist adding a new thing that makes the internet more crappy and less private. I think it'…

> Third party cookies, love them or hate them, have been with us for a long time, and simply dropping them would not be viable without the long phase out. Not true, FireFox and Safari have had them off by default for over a year now. Additionally Chrome had planned to turn them off last year but then cried "covid" which for some reason = delay... because... think of the adverts! i mean covid! Anyway, I'm pretty sure…

this is the same execuse facebook's been using, although they're trying to push the narrative that limited tracking in Apple's iOs 14+ "hurts Small Business!"

https://twitter.com/jason_kint/status/1383391849902075911 (video in thread)

Re: Proposal: Treat FLoC as a security concern

#266
post #222

Earlier quoted context omitted.

> Can you explain how exactly charging their users money is a better long term business model for Google than selling their data? Because long term, users will realize that letting their data be sold is bad for them and will stop considering it acceptable. Indeed, that is already happening. And so, as I said, Google will have to continually become more and more evil to try to prop up their business model by further o…

> Because long term, users will realize that letting their data be sold is bad for them and will stop considering it acceptable. Indeed, that is already happening. It's happening at the fringes, in communities that are already more privacy-conscious. I haven't seen any signs of a groundswell of support for this position. > Then I assume you are long Google? No, I was speaking figuratively; I don't have any desire to…

> I simply see regulation as a far more likely solution than users demanding an ethical business model with their wallets.

In the short term, I agree we're far more likely to get regulation than a significant change in user demand. I do not, however, think any regulation we get will be a "solution".

Re: Proposal: Treat FLoC as a security concern

#267
post #161

Earlier quoted context omitted.

Look at gmail: I pay $60/year-ish for Fastmail. Gmail is at least that good. So is the purpose of gmail to have a cross device stable identifier? Absolutely. Are people realizing tons of value from it for free? Also yes.

I expect to get a gmail type service paying only the "price" of having some unobtrusive ads when I'm on the gmail site , nothing else. I absolutely do not agree to google using anything from gmail to generate a stable user id for advertising, or e.g. show me ads in google search results or youtube videos, based on analysis of email content. If Google can't provide what I expect (a free mail service paid only by ads o…

Then don't use gmail. It turns out they have competitors, including one listed in my comment.

Re: Proposal: Treat FLoC as a security concern

#268
post #267

Earlier quoted context omitted.

I expect to get a gmail type service paying only the "price" of having some unobtrusive ads when I'm on the gmail site , nothing else. I absolutely do not agree to google using anything from gmail to generate a stable user id for advertising, or e.g. show me ads in google search results or youtube videos, based on analysis of email content. If Google can't provide what I expect (a free mail service paid only by ads o…

Then don't use gmail. It turns out they have competitors, including one listed in my comment.

Too late, I used the address in hundreds of places. I’d like to pay Google for having them respect my privacy now.

Re: Proposal: Treat FLoC as a security concern

#269

Earlier quoted context omitted.

One difference between third party cookies and FLoC is that with FLoC it is being explained to the public how browsing history is being used. The third parties who send Set-Cookie headers do not write up documentation attempting to explain to the public what they are doing and why it is not a threat to privacy. As other comments point out, it would be more difficult for people to "be all up in arms" about third party…

“attempting to explain to the public what they are doing” The idea that you can explain FLoC, third party cookies or any other digital advertising technology to the public is crazy talk. Ad tech is extremely complex and constantly evolving - “the public” includes children, the intellectually disabled, the mentally ill, the elderly and the illiterate. No amount of documentation is going to help these people reach a po…

Agreed 100%.

Only me, but I actually find the docs insulting for the reasons you stated.

Re: Proposal: Treat FLoC as a security concern

#270
post #259
post #208

Earlier quoted context omitted.

Since you seem to work for Microsoft, the broken use case I know: without 3p cookies Microsoft Teams is broken (it shows a not very useful error page asking to refresh the page, when you do it shows the same error again). Many of us need it for remote work so I guess this one of the things Google had in mind when they delayed disabling 3p cookies by default.

Yes, Teams relies on silent auth from within an iframe (all those chat windows etc). This is impossible without 3p cookies, so we're working with Google to find a solution. Storage access API in Safari works, but sounds like it won't make it to Chrome.

Thanks, nice to know you are working on it.
Post reply on HN