Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

51–60 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#51
post #30

Earlier quoted context omitted.

Then advertisers will fingerprint the browser as well, to see whether the FLoC data can be trusted.

Just have everyone spoof Chrome then

For firefox this is nearly impossible because of the different quirks it has in its javascript/layout engine. It might be easier to do with all the chromium forks, but it's unknown how the proprietary bits in chrome affect browser behavior. At worst they can use something like have obfuscated code (eg. widevine L3) for attestation.

Re: Proposal: Treat FLoC as a security concern

#52

Earlier quoted context omitted.

What do you mean? They are widely used, which seems far from dead. Aren’t you declaring victory too early?

These are strategies that are being aggressively restricted. Chrome has not started preventing third party cookies yet , but they're the last holdout and have already stated they will kill them shortly. If you're using a non-user-hostile browser, these strategies are already heavily limited by default and are already not a concern. Every Firefox release is making significant improvements on reducing the fingerprintin…

> Chrome has not started preventing third party cookies yet, but they're the last holdout and have already stated they will kill them shortly.

Chrome's original announcement about phasing out third-party cookies is explicit about new technologies like Privacy Sandbox (which includes FLoc) being how third-party cookies will no longer be needed:

"After initial dialogue with the web community, we are confident that with continued iteration and feedback, privacy-preserving and open-standard mechanisms like the Privacy Sandbox can sustain a healthy, ad-supported web in a way that will render third-party cookies obsolete. Once these approaches have addressed the needs of users, publishers, and advertisers, and we have developed the tools to mitigate workarounds, we plan to phase out support for third-party cookies in Chrome. Our intention is to do this within two years." -- https://blog.chromium.org/2020/01/building-more-private-web-...

(Disclosure: I work on ads at Google, speaking only for myself)

Re: Proposal: Treat FLoC as a security concern

#53

It would appear that there are already at least two plugins that take care of this for those who'd like to do so before it's rolled into the WordPress core: https://wordpress.org/plugins/search/floc/

You don't need a plugin for this (every plugin is a security risk). You only need to send one single http header.

[deleted]

Re: Proposal: Treat FLoC as a security concern

#54

Earlier quoted context omitted.

What do you mean? They are widely used, which seems far from dead. Aren’t you declaring victory too early?

Safari and Firefox already block them by default, and Chrome is set to block them before 2022: https://www.wired.co.uk/article/google-chrome-cookies-third-... The FLoC proposal (and others) are happening now because of the coming cookiepocalypse.

The causality is more complex: Chrome's approach from the beginning was that they would remove third-party cookies and replace them with more private alternatives like FLoC: https://blog.chromium.org/2020/01/building-more-private-web-...

(Disclosure: I work on ads at Google, speaking only for myself)

Re: Proposal: Treat FLoC as a security concern

#55
post #32

Earlier quoted context omitted.

I don't see why not, but that doesn't help the ~95% of people not using Firefox (let's be real, Microsoft is not going to pass up the chance to violate someone's privacy).

The Verge interpreted MS’s stance on FLoC as a soft no. In any event, it is not an obvious yes. https://www.theverge.com/2021/4/16/22387492/google-floc-ad-t...

This interpretation is missing the important context that the PARAKEET proposal (https://github.com/WICG/privacy-preserving-ads/blob/main/Par...) is another strategy for opt-out personalized ad targeting. So they may have technical quibbles or business concerns, but they're not opposed to the core concept.

Re: Proposal: Treat FLoC as a security concern

#56
post #15

Earlier quoted context omitted.

> "Kill it before it lays eggs." but do we worry about what evolves from this if it dies? Nothing really evolves here - status quo is what stays. You continue to be tracked head to arse on everyones servers, the media keeps adding 150 trackers to every webpage and the internet moves on. Thinking that one of the biggest profit making industries in US will just go away if you scream loud enough on HN is utterly naive a…

Only govt action will work. That too concerted action by several national govts.

Developing a browser (or forking the existing one) with comprehensive anti-tracking features would also work.

There are a half-dozen plugins one can add to Ungoogled Chromium to browse the web in (relative) safety. It's not a nation-state level undertaking: six or seven figures.

The problem really comes from apps, which are loaded to the gills with spyware.

Re: Proposal: Treat FLoC as a security concern

#57
post #26

Earlier quoted context omitted.

Most likely google will just turn off that silly opt out functionality. It's not like anyone's going to stop using their spyware browser.

Chrome is entranched, but not like IE was. You have to install the browser in the first place, which means the moment it starts to be too crappy people move elsewhere. Why do you think Google hasn't prevented adblockers from running on it? If they did so, it would sink the browser so quickly.

One of the ways Chrome got as popular as it did was to bundle installation of it with various other programs, the way spyware and adware did. You install a random program, you don't open "advanced install" and uncheck "Chrome", and you end up with Chrome installed.

Re: Proposal: Treat FLoC as a security concern

#58

Earlier quoted context omitted.

Well, FLoC is implemented on Chrome, you don't disable it, you opt out with a Header. So if Googles find that too many people uses the header, they can just decide to ignore it from now on. Who is going to prevent them to do that ?

Possibly GDPR? As an explicit no-consent to tracking? Not rhethorical questions, I know too little about the details.

When you use Chrome for the first time, it makes you accept its ToS which tells you they are going to track you.

Re: Proposal: Treat FLoC as a security concern

#59
I just love the Google's way of thinking.

Users: We hate cookies, because they are abused to hurt our privacy by allowing advertisers to build a profile about us

Google: We have a great idea! We can get rid of 3rd party cookies and instead make your browser build profile about you and share it with everyone.

Re: Proposal: Treat FLoC as a security concern

#60
post #15

I am hopeful that this will help get rid of FLoC but I worry about two things. One, this will end up being treated like the "no track" headers. That's just totally ignored after IE (was it IE?) enabled it be default. That gave all the trackers a reason to just ignore it and track everyone. I don't know if that exact same thing can happen here, but something similar maybe? The other thing I worry about is that FLoC 2.…

> "Kill it before it lays eggs." but do we worry about what evolves from this if it dies? Nothing really evolves here - status quo is what stays. You continue to be tracked head to arse on everyones servers, the media keeps adding 150 trackers to every webpage and the internet moves on. Thinking that one of the biggest profit making industries in US will just go away if you scream loud enough on HN is utterly naive a…

Also, nearly $125B was spent on internet advertising in the US in 2020, per the first estimate I found on the internet [1]. While Google and Facebook keep huge chunks of that, my guess is at least 40% flows through to publishers. So that's a $50B revenue stream to publishers (all sorts of web sites, including news; apps, musicians (via spotify and so forth)) that we're talking about breaking. I really don't believe people have thought through all the effects of that. Not least of which is seeing almost all (reliable) news behind a paywall.

[1] https://www.statista.com/statistics/183523/online-advertisem...

Post reply on HN