Live data from Hacker News

Chrome is entrenching third-party cookies that will mislead users

brave.com

281–290 of 329 posts

Re: Chrome is entrenching third-party cookies that will mislead users

#281

Earlier quoted context omitted.

> Regarding analytics, I believe browsers should take user's side and do not cooperate with marketing companies Browsers were supposed to act as agents working for the user. User-agents. These days it's getting harder and harder to find a browser that doesn't work for an ad company at the expense of the user. Chrome's entire reason for existing is data collection. Firefox can, for now at least, be hardened to work fo…

> Mozilla is an ad-tech company too now. I'm sorry, this seems egregious. I agree that it should've been off by default but I challenge anyone to read how the implementation works (not just the blog post and the FUD responses to it) before calling it a giveaway to the ad industry: https://github.com/mozilla/explainers/tree/main/ppa-experime... FF is currently a key tool in the fight to avoid a Google-top-to-bottom fu…

It is ridicoulous. Why do browser developers cooperate with ad companies? They were supposed to protect us from them.

It gives no benefits to end users. Ad companies will not stop using old methods, they will just add one more method.

I hope responsible Linux distributions will patch this out and disable by default.

A fair model would be if this feature was opt-in and if Mozilla paid to the users who enabled it.

> The purpose of this API is to provide a privacy-first design for advertising companies to be able to measure how advertising drives conversions. That is, answering the question of whether advertising effectively achieves its goals, such as increased sales.

Not my problem. I don't earn anything from their sales.

Re: Chrome is entrenching third-party cookies that will mislead users

#282

Earlier quoted context omitted.

> Mozilla is an ad-tech company too now. I'm sorry, this seems egregious. I agree that it should've been off by default but I challenge anyone to read how the implementation works (not just the blog post and the FUD responses to it) before calling it a giveaway to the ad industry: https://github.com/mozilla/explainers/tree/main/ppa-experime... FF is currently a key tool in the fight to avoid a Google-top-to-bottom fu…

It really is disheartening to see so many technically-inclined people berate the one browser that is preventing Apple/Google hegemony. The expectations set upon Mozilla and Firefox are so unrealistic it's laughable. Firefox is rock solid, open-source, backed by a great organization (which has recently reinvested additional resources in it) and a joy to use imo. Also, the levels of vitriol that even the slightest bit…

While Firefox is great, they should not sell their userbase to Facebook with such proposals. If ad companies want to know about ad effectiveness, they must pay the users for collecting the data, not collect it for free without asking the user.

Re: Chrome is entrenching third-party cookies that will mislead users

#283

Have been using Firefox for a long time, no issues, though long ago when I had little memory, Chrome was using less of it. Firefox also has HTTPS-only mode, encrypted DNS without fallbacks, supports SOCKS and Encrypted Client Hello (although almost no website support it). However, it is better to just buy more memory (unless you are lucky to use Apple products). Regarding analytics, I believe browsers should take use…

> Every new web API should guarantee that it doesn't provide more fingerprinting data or hides the data behind a permission. FWIW, it's practically impossible to provide that guarantee because the API necessarily provides at least the data point of, "Did they select an option in the permission notification?" ("If yes, what option was selected?" etc.) It's often said that the only solution to this is regulation and th…

> FWIW, it's practically impossible to provide that guarantee because the API necessarily provides at least the data point of, "Did they select an option in the permission notification?" ("If yes, what option was selected?" etc.)

If 99% of users will have permission disabled then it has little value, and only those who enabled it can be tracked. I don't give permissions to sites so this will not apply to me.

Also, the status of permission (1 bit) provides less information than API it protects (for example, list of installed fonts or GPU name) so it is a win.

Re: Chrome is entrenching third-party cookies that will mislead users

#284
post #251

Earlier quoted context omitted.

> Forcing Pocket into the browser Fun fact: by subscribing to Pocket, you're directly contributing to Firefox's development. Mozilla found itself in a situation of damned if they do, damned if they don't . People scream at them for depending on Google, and then they scream at them for trying to diversify their revenue. Nobody wants to pay for a browser, browsers are essentially incredibly complex nowadays, and I have…

> Mozilla found itself in a situation of damned if they do, damned if they don't. People scream at them for depending on Google, and then they scream at them for trying to diversify their revenue. People didn't like Pocket as a product. It wasn't as if they just didn't like it because Firdfox wanted to make money out of it. Sure they should diversify, but with something that isn't otherwise (so) objectionable. Like t…

What people? Do you have source for that?

Anectodal one: I liked it.

Re: Chrome is entrenching third-party cookies that will mislead users

#285
post #221

Earlier quoted context omitted.

You’re not but that’s the point. Google realise they don’t control the OS (in many cases) and thus struggle to monetise it. I don’t have a problem with doing dns lookups over http, or any other protocol you want to use, if I configure my OS resolver to do that. When people don’t like DoH they tend to mean they have a problem with bypassing the OS. Theres then the concept of DoH, network admins have a harder job block…

What you mean is that network admins have a harder time controlling people's devices. I have a DoH server set in my Chromium browser, installed on my corporate laptop, and I love it, because my DNS queries don't leak to my network admin.

The perspective is significantly different when you're both the user and network admin. From your vantage point, you're picking the lesser of two evils.[1] But there's a third option that keeps you in even greater control, yet it's increasingly becoming more onerous to preserve. It's something like a collective action problem.

[1] Or at least you think you are. If your employer is running provisioning and "security" malware, I wouldn't take any bets on what they're logging or not logging.

Re: Chrome is entrenching third-party cookies that will mislead users

#286

Earlier quoted context omitted.

> Forcing Pocket into the browser Fun fact: by subscribing to Pocket, you're directly contributing to Firefox's development. Mozilla found itself in a situation of damned if they do, damned if they don't . People scream at them for depending on Google, and then they scream at them for trying to diversify their revenue. Nobody wants to pay for a browser, browsers are essentially incredibly complex nowadays, and I have…

> And of course they want to cater to advertisers because it is advertising that maintains the open web As someone who worked both on advertiser and publisher sides (incl. content monetisation): advertisers like to say that they support publishers and the open web, but in fact, they are keeping it hostage. We've had the means/tech to support publishers directly for years (I don't mean crypto). It's in the interest of…

When I was a kid you could buy a browser in an electronics store :)

Re: Chrome is entrenching third-party cookies that will mislead users

#287

Earlier quoted context omitted.

> Mozilla is an ad-tech company too now. I'm sorry, this seems egregious. I agree that it should've been off by default but I challenge anyone to read how the implementation works (not just the blog post and the FUD responses to it) before calling it a giveaway to the ad industry: https://github.com/mozilla/explainers/tree/main/ppa-experime... FF is currently a key tool in the fight to avoid a Google-top-to-bottom fu…

Ultimately, the problem is that entire premise is deeply offensive. I do not want my browsing history being monitored, collected, sent to third parties, and sold to marketers in any form period. I do not want a browser using my data in any way to support surveillance capitalism. The implementation is just FLoC/Topics API all over again and it's still not compelling. The first kick in the teeth comes right at the star…

You're preaching to the choir, but even preaching needs to be truthful and I don't think calling Mozilla ad-tech or suggesting that it's just as bad as Google is remotely true. This is where "the perfect is the enemy of the good" comes from.

I mean, what do we have now? Google and a bunch of middle-man ad techs are hoovering up everything they can get, including a crap-ton of stuff that browsers can't affect at all, and wink-wink-promising that they anonymize some of it in some cases even though no one can verify that. A world in which the subset of that data that passes through a browser has been provably anonymized would seem to be strictly better, even if you still don't like it.

Re: Chrome is entrenching third-party cookies that will mislead users

#288
post #172

Have been using Firefox for a long time, no issues, though long ago when I had little memory, Chrome was using less of it. Firefox also has HTTPS-only mode, encrypted DNS without fallbacks, supports SOCKS and Encrypted Client Hello (although almost no website support it). However, it is better to just buy more memory (unless you are lucky to use Apple products). Regarding analytics, I believe browsers should take use…

Firefox doesn't have ECH support (atleast not turned on by default) https://privacytests.org/ (Scroll down to Misc tests)

I observed Firefox sending ECH extension in ClientHello, maybe I just enabled it in the settings, so Firefox supports ECH (on by default since version 119). However, virtually no servers support ECH now. Not Google, not Hackernews, not Cloudflare etc.

This seems to be a not very good comparison, and it looks like it cherry-picks convenient for a certain browser points and ignores others. Look at "fingerprint protection", for example, and see that it does not include features that provide most fingerprinting data:

- preventing reading GPU name via WebGL debugging extension (does Brave block this?)

- preventing reading back canvas data which is used to fingerprint browser and OS code responsible for rendering graphics and text

- enumerating audio devices

And if you read the issues in Brave github [1], then you'll notice that Brave developers refuse to block features providing important fingerprinting information under compatibility" reasons (including GPU vendor and model), although these features could be made blocked only in high security mode.

So regarding fingerprinting, the comparison you refer to is pretty much worthless: it doesn't mention many important fingerprinting APIs.

[1] https://github.com/brave/brave-browser/issues/35646

Re: Chrome is entrenching third-party cookies that will mislead users

#289
post #272

Earlier quoted context omitted.

Not OP, but Firefox didn't have to lose nearly all its market share to Chrome. Mozilla could have course corrected and righted the ship, but instead they got distracted on dozens of unrelated and often controversial projects and ended up burning most of their credibility. Mozilla is a husk of what it could have been, and that's hurt Firefox.

What, specifically, should they have done differently that would have made Firefox not lose most of its market share to Chrome, and how do you know it would have worked?

Keep Firefox in focus instead of losing sight of the browser and getting distracted on a million side projects, most of which had only a tangential relationship to the internet. Raise money to support the browser rather than to support politically divisive causes of the month.

I can't say for sure it would have worked, but I know that what Mozilla actually did do was actively counterproductive.

Re: Chrome is entrenching third-party cookies that will mislead users

#290

Earlier quoted context omitted.

> And of course they want to cater to advertisers because it is advertising that maintains the open web As someone who worked both on advertiser and publisher sides (incl. content monetisation): advertisers like to say that they support publishers and the open web, but in fact, they are keeping it hostage. We've had the means/tech to support publishers directly for years (I don't mean crypto). It's in the interest of…

> As someone who worked both on advertiser and publisher sides (incl. content monetisation): advertisers like to say that they support publishers and the open web, but in fact, they are keeping it hostage. I know what you're saying, I agree, as I worked (in the past) on advertising platforms as well, but both of those statements can be true at the same time. The open web was built on advertising, but the perverse inc…

> micro-transactions are not possible given the huge banking fees

I actually worked on several projects like this and we found a few ways of making this work. A simple example would be having a wallet you can top up, so you can pay per article. The fee was _roughly_ 2x the CPM for a post, and the cost for an average user ca. $5 per month IIRC. There's a bunch of companies doing this stuff, but their usual issue was scale/publisher relationships. After a few years of trying and 3 companies later I ended up in a situation where this wasn't a problem. Apologies for being vague here.

> I also think that Google isn't the greater evil, because Google has an incentive to keep the web going

True, but the web Google wants to "keep going" is _very_ unlikely the same as the one that's good for users. Chrome or Android serve as storefronts, hence consent assumed by default (think Manifest V3, FLOC, etc...).

Example: think of the deal they signed with Conde Nast (and earlier Reddit). Nowadays, Google has exclusive access to search results from Reddit.

> For instance, what happens with local newspapers, when they die, besides depriving ad networks of revenue, is that the audience of these newspapers moves to walled gardens like Facebook. The failure of advertising on the web right now results in more centralisation.

I witnessed it in 2010s when working with publishers (EU, UK, and some US-based). It wasn't much different than what happened during the "cookiegeddon" around '17 '18 (IIRC): moving to new platforms, pushing towards subscriptions, bundles, or focussing on premium/high quality content.

The publishers I spoke with (again, as a vendor working in publishing and then, later, in adtech) generally would be more than happy to drop the ads if we had any other way to let people pay for stuff without using dark patterns (e.g. subscriptions people tend to forget about).

The only people who created pushback were not even their advertising partners, it was _their own sales people_, responsible for pushing their inventory via direct sales. It makes perfect sense, from a people/internal politics point of view. I'd be happy to elaborate on that, but it's getting a bit late!

People like free stuff, but they're also happy to pay for stuff if they understand its value. Imagine walking into a coffee shop and asking for a free americano promising that you'll stare at their ads on your phone for 5 minutes. (This idea only makes sense if you're running an adtech / marketing startup.)

Then, we have more interesting examples like The Guardian, where many of the people supporting them did so because they wanted _other_ people to have access to it.

So yeah, I agree that people like free stuff, and that the current situation is messy to say the least, but I think we need to take a step back and reconsider the things/ideas we take for granted.

Post reply on HN