Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

41–50 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#41
post #2

WordPress is 41% of the web. If this goes through and FLoC is disabled by default by WordPress, will FLoC be dead on arrival?

Well, FLoC is implemented on Chrome, you don't disable it, you opt out with a Header.

So if Googles find that too many people uses the header, they can just decide to ignore it from now on. Who is going to prevent them to do that ?

Re: Proposal: Treat FLoC as a security concern

#42
post #27

Earlier quoted context omitted.

I don’t know it. Where did you learn it?

https://w3techs.com/technologies/overview/content_management 41.1% of websites

Okay, thanks!

It looks like it’s based on the top ten million websites by traffic, but weighted equally. Maybe there are lots of low-traffic WordPress sites?

Re: Proposal: Treat FLoC as a security concern

#43
post #32

From my surface level reading of FLoC - would it be possible for Edge or Mozilla to implement FLoC - but to send noise / random / incorrect data up in a way that essentially wrecks the algorithm?

I don't see why not, but that doesn't help the ~95% of people not using Firefox (let's be real, Microsoft is not going to pass up the chance to violate someone's privacy).

Well, if those 95% of the people (who exactly is counting, and how?) want Mozilla to help them, they should consider switching from Chrome (and stop enabling Google on the meantime).

Re: Proposal: Treat FLoC as a security concern

#44
The submitted title was "WordPress Proposal to Treat Google's FLoC as a Security Concern". That makes it sound like Wordpress itself is officially making this proposal. Is it? The page doesn't look like that to me.

We've reverted the title in keeping with the site rule: "Please use the original title, unless it is misleading or linkbait; don't editorialize." (https://news.ycombinator.com/newsguidelines.html).

Re: Proposal: Treat FLoC as a security concern

#45

It would appear that there are already at least two plugins that take care of this for those who'd like to do so before it's rolled into the WordPress core: https://wordpress.org/plugins/search/floc/

You don't need a plugin for this (every plugin is a security risk). You only need to send one single http header.

True, but modifying core files to send the header isn't good either because you'll have to redo the change at every update. Also, most security plugins such as Wordfence will choke on a modified core file, and rightly so.

Re: Proposal: Treat FLoC as a security concern

#46

Earlier quoted context omitted.

What do you mean? They are widely used, which seems far from dead. Aren’t you declaring victory too early?

These are strategies that are being aggressively restricted. Chrome has not started preventing third party cookies yet , but they're the last holdout and have already stated they will kill them shortly. If you're using a non-user-hostile browser, these strategies are already heavily limited by default and are already not a concern. Every Firefox release is making significant improvements on reducing the fingerprintin…

Okay, I still think it’s too soon to declare victory until Chrome actually does it. It could be delayed.

Re: Proposal: Treat FLoC as a security concern

#47
post #2

WordPress is 41% of the web. If this goes through and FLoC is disabled by default by WordPress, will FLoC be dead on arrival?

Well, FLoC is implemented on Chrome, you don't disable it, you opt out with a Header. So if Googles find that too many people uses the header, they can just decide to ignore it from now on. Who is going to prevent them to do that ?

Possibly GDPR? As an explicit no-consent to tracking? Not rhethorical questions, I know too little about the details.

Re: Proposal: Treat FLoC as a security concern

#48
post #30

Earlier quoted context omitted.

Then advertisers will fingerprint the browser as well, to see whether the FLoC data can be trusted.

Just have everyone spoof Chrome then

A substantial amount of modern Internet infrastructure relies on the fact that major actors are behaving in good faith. This isn't a chain of escalation anyone would benefit from going down.

Re: Proposal: Treat FLoC as a security concern

#49
post #15

I am hopeful that this will help get rid of FLoC but I worry about two things. One, this will end up being treated like the "no track" headers. That's just totally ignored after IE (was it IE?) enabled it be default. That gave all the trackers a reason to just ignore it and track everyone. I don't know if that exact same thing can happen here, but something similar maybe? The other thing I worry about is that FLoC 2.…

> "Kill it before it lays eggs." but do we worry about what evolves from this if it dies? Nothing really evolves here - status quo is what stays. You continue to be tracked head to arse on everyones servers, the media keeps adding 150 trackers to every webpage and the internet moves on. Thinking that one of the biggest profit making industries in US will just go away if you scream loud enough on HN is utterly naive a…

Only govt action will work. That too concerted action by several national govts.

Re: Proposal: Treat FLoC as a security concern

#50
post #32

From my surface level reading of FLoC - would it be possible for Edge or Mozilla to implement FLoC - but to send noise / random / incorrect data up in a way that essentially wrecks the algorithm?

I don't see why not, but that doesn't help the ~95% of people not using Firefox (let's be real, Microsoft is not going to pass up the chance to violate someone's privacy).

> Microsoft is not going to pass up the chance to violate someone's privacy

If they are not benefiting and Google is benefiting they may pass on that.

Post reply on HN