Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

61–70 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#61
A comment in the WP post brings up the malicious nature of FLOC opt-out - it requires base layer changes to your site. Google knows from Samesite that it requires "your app is going to break" levels of urgency to get old sites to update, and can likely follow the dots to how an opt-out is much less likely to be used than an opt in.

This feels like something that should get more attention/discussion. It flew for Samesite because "better security defaults" is a good argument. Not sure it works that way for FLOC.

Despite being involved in the Samesite rollout I hadn't quite made the same connection as that commenter, as I am not as connected to the FLOC work.

Re: Proposal: Treat FLoC as a security concern

#62
It’s a opportunity to put priv engineering techniques to the test in prod, at least. That’s 100% the main thing that stands out here.

In the raw browser history, prior to ~hashing it to a FLoC ID, can Google anon PII while still maintaining good data analytics from the rest* of the dataset’s fields?

Priv engineer, as an engineering discipline, would argue yes.

If this is what Google does and the privacy is put through its paces (can a FLoC ID de-anon into a user?), then yeah this isn’t a bad trade off.

Use case: Google has to make money, I love Chrome’s and GSuite’s UX, priv eng’ing lets them use my data to pay for that UX while moving all the tracking in-house and ending 3rd party cookies.

Re: Proposal: Treat FLoC as a security concern

#63

I think this is starting to get to the level of a moral panic. I respect that these developers think FLoC is bad, but what does it have to do with the WordPress project?

It's just HN. It's just like the reaction to AMP on this board. Most clients like the feature if it speeds up the site and brings more visitors to the site. Here, you'd think it represents the end of the internet or something.

Re: Proposal: Treat FLoC as a security concern

#64
post #60
post #15

Earlier quoted context omitted.

> "Kill it before it lays eggs." but do we worry about what evolves from this if it dies? Nothing really evolves here - status quo is what stays. You continue to be tracked head to arse on everyones servers, the media keeps adding 150 trackers to every webpage and the internet moves on. Thinking that one of the biggest profit making industries in US will just go away if you scream loud enough on HN is utterly naive a…

Also, nearly $125B was spent on internet advertising in the US in 2020, per the first estimate I found on the internet [1]. While Google and Facebook keep huge chunks of that, my guess is at least 40% flows through to publishers. So that's a $50B revenue stream to publishers (all sorts of web sites, including news; apps, musicians (via spotify and so forth)) that we're talking about breaking. I really don't believe p…

So if suddenly all tracking stopped, advertisers would just stop spending money on advertising? That doesn't seem right... advertisers published ads before tracking was a thing, they would still do it if tracking becomes impossible.

Re: Proposal: Treat FLoC as a security concern

#65

Earlier quoted context omitted.

Surely that depends on what their experience using it is, just like every other "winning" browser before that is no longer winning? If FLoC generates so much hostility within the web dev community that a few major sites/platforms start actively blocking it, and if Google responds by ignoring the opt-outs in Chrome, and if the community responds with a SOPA-like "no access using Chrome for the next 48 hours then, here…

>and if the community responds with a SOPA-like "no access using Chrome for the next 48 hours then, here are some other fine browsers you can use instead that don't invade your privacy in this way" that seems unlikely.

Is it, though?

It appears that Google is trying to rewrite the rules of how browsers and the Web work, with the appearance of being on the side of privacy, but actually introducing an alternative method of surveillance that is going to be less favourable to almost everyone except Google. How many of the huge-audience sites are potentially going to lose out from that, not least because they rely on advertising themselves for the lion's share of their revenues?

This whole discussion started with a proposal from a platform that is supporting nearly half of the sites people are visiting. That puts WP in a unique and potentially very powerful position here as well, and evidently they're interested in trying to force the issue.

And finally, the SOPA experience has shown that it is not entirely implausible for large numbers of sites to collaborate in this way if they feel the threat is serious enough. So if FLoC is as bad as the critics are suggesting, it doesn't seem entirely out of the question. There seem to be quite a few powerful organisations that would have a variety of motivations for wanting to give Google a bloody nose over this one.

Re: Proposal: Treat FLoC as a security concern

#66

Earlier quoted context omitted.

Possibly GDPR? As an explicit no-consent to tracking? Not rhethorical questions, I know too little about the details.

When you use Chrome for the first time, it makes you accept its ToS which tells you they are going to track you.

IANAL, but my understanding is that this is not in line with GDPR. You are not allowed to force the customer into tracking, which effectively happens in the scenario you describe since the user can't use the browser without accepting the ToS. Also, you have to be quite explicit: simply burying tracking in 52 pages of unrelated legalese is not compliant with GDPR.

Someone please chime in if I'm wrong here. I'm no lawyer but do take these things seriously (I'm trying my best to provide a tracking-free website.)

Re: Proposal: Treat FLoC as a security concern

#67
post #2

WordPress is 41% of the web. If this goes through and FLoC is disabled by default by WordPress, will FLoC be dead on arrival?

Between large web publishing platforms and all alternate browsers blocking FLoC, I think we could kill it, yes. WordPress is used by a lot of marketing focused folks though, so we'll see if WP is able to land this.

Exactly. A big part of the WordPress community are publishers, bloggers, affiliate marketers, etc who rely on ads to generate revenue. I'm not sure they'd be too thrilled with this proposal.

Re: Proposal: Treat FLoC as a security concern

#69

Earlier quoted context omitted.

Possibly GDPR? As an explicit no-consent to tracking? Not rhethorical questions, I know too little about the details.

When you use Chrome for the first time, it makes you accept its ToS which tells you they are going to track you.

They will lose that case under GDPR, you can't hide the details in ToS and hope the user doesn't see it. You must get informed and freely given consent. Google is violating both, because I can't click "No" and the information is so hidden you can't expect a normal consumer to find it.

It will take a few years but they're going to get hit very very hard by EU privacy regulators.

Re: Proposal: Treat FLoC as a security concern

#70
post #44

The submitted title was "WordPress Proposal to Treat Google's FLoC as a Security Concern". That makes it sound like Wordpress itself is officially making this proposal. Is it? The page doesn't look like that to me. We've reverted the title in keeping with the site rule: " Please use the original title, unless it is misleading or linkbait; don't editorialize. " ( https://news.ycombinator.com/newsguidelines.html ).

The page does seem to be the official wordpress development blog, linked from wordpress.org's "get involved" page.

"The WordPress core development team builds WordPress! Follow this site for general updates, status reports, and the occasional code debate."

Post reply on HN