Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

31–40 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#31

I am hopeful that this will help get rid of FLoC but I worry about two things. One, this will end up being treated like the "no track" headers. That's just totally ignored after IE (was it IE?) enabled it be default. That gave all the trackers a reason to just ignore it and track everyone. I don't know if that exact same thing can happen here, but something similar maybe? The other thing I worry about is that FLoC 2.…

We're already successfully killing third party cookies and most browser fingerprinting strategies. This is an attempt by a browser to build an intentionally user hostile mechanic to compensate, but we can kill this too. We just need to continue to make it increasingly impractical and expensive to track users until it stops being considered a viable business strategy.

By "we" here you mean... Google with Chrome (as the most popular browser), Apple with Safari and Mozilla with Firefow. Google being the one against whom the fight against FLoC is being fought?

That sounds... optimistic since you needed Google to form that "we".

Re: Proposal: Treat FLoC as a security concern

#32

From my surface level reading of FLoC - would it be possible for Edge or Mozilla to implement FLoC - but to send noise / random / incorrect data up in a way that essentially wrecks the algorithm?

I don't see why not, but that doesn't help the ~95% of people not using Firefox (let's be real, Microsoft is not going to pass up the chance to violate someone's privacy).

Re: Proposal: Treat FLoC as a security concern

#33

Can't privacy concious browser defeat FLoC simply by sending random cohort IDs on each request?

That would require admitting that moving the tracking process to client-side actually improves on status quo (by not collecting data on the server).

While the whole framing of EFF et. al. is put in a way that does not allow for even a small doubt that the proposal is just the worst thing ever with no redeeming qualities. That framing disallows working within this feature to modify browsers to send the required headers.

Re: Proposal: Treat FLoC as a security concern

#36
post #26

Earlier quoted context omitted.

Most likely google will just turn off that silly opt out functionality. It's not like anyone's going to stop using their spyware browser.

Chrome is entranched, but not like IE was. You have to install the browser in the first place, which means the moment it starts to be too crappy people move elsewhere. Why do you think Google hasn't prevented adblockers from running on it? If they did so, it would sink the browser so quickly.

> the moment it starts to be too crappy people move elsewhere

You seriously underestimate the power of inertia.

Re: Proposal: Treat FLoC as a security concern

#37
post #33

Can't privacy concious browser defeat FLoC simply by sending random cohort IDs on each request?

That would require admitting that moving the tracking process to client-side actually improves on status quo (by not collecting data on the server). While the whole framing of EFF et. al. is put in a way that does not allow for even a small doubt that the proposal is just the worst thing ever with no redeeming qualities. That framing disallows working within this feature to modify browsers to send the required header…

not at all if you're not taking part in the data collection at all and are just sending noise on the channel. I guess chrome could counter DRM-signing the cohort-id or something

Re: Proposal: Treat FLoC as a security concern

#38

It would appear that there are already at least two plugins that take care of this for those who'd like to do so before it's rolled into the WordPress core: https://wordpress.org/plugins/search/floc/

You don't need a plugin for this (every plugin is a security risk). You only need to send one single http header.

Re: Proposal: Treat FLoC as a security concern

#39
post #32

From my surface level reading of FLoC - would it be possible for Edge or Mozilla to implement FLoC - but to send noise / random / incorrect data up in a way that essentially wrecks the algorithm?

I don't see why not, but that doesn't help the ~95% of people not using Firefox (let's be real, Microsoft is not going to pass up the chance to violate someone's privacy).

The Verge interpreted MS’s stance on FLoC as a soft no. In any event, it is not an obvious yes.

https://www.theverge.com/2021/4/16/22387492/google-floc-ad-t...

Re: Proposal: Treat FLoC as a security concern

#40
post #30

From my surface level reading of FLoC - would it be possible for Edge or Mozilla to implement FLoC - but to send noise / random / incorrect data up in a way that essentially wrecks the algorithm?

Then advertisers will fingerprint the browser as well, to see whether the FLoC data can be trusted.

Just have everyone spoof Chrome then
Post reply on HN