Live data from Hacker News

Proposal: Treat FLoC as a security concern

make.wordpress.org

81–90 of 274 posts

Re: Proposal: Treat FLoC as a security concern

#81
post #70
post #44

The submitted title was "WordPress Proposal to Treat Google's FLoC as a Security Concern". That makes it sound like Wordpress itself is officially making this proposal. Is it? The page doesn't look like that to me. We've reverted the title in keeping with the site rule: " Please use the original title, unless it is misleading or linkbait; don't editorialize. " ( https://news.ycombinator.com/newsguidelines.html ).

The page does seem to be the official wordpress development blog, linked from wordpress.org's "get involved" page. "The WordPress core development team builds WordPress! Follow this site for general updates, status reports, and the occasional code debate."

This is make.wordpress.org kinda like a issue tracker for WordPress core

Re: Proposal: Treat FLoC as a security concern

#82
post #74
post #59

I just love the Google's way of thinking. Users: We hate cookies, because they are abused to hurt our privacy by allowing advertisers to build a profile about us Google: We have a great idea! We can get rid of 3rd party cookies and instead make your browser build profile about you and share it with everyone.

IIUC while floc does indeed build a profile browser side it isn’t something that advertisers can track with the same precision as they can with 3p cookies. So while it’s not the holy grail it does appear to be a small step in the right direction from the status quo. Do I understand the situation correctly? Genuinely curious.

True, but the FLoC implementation comes with its own sack of worms look eff excellent post on it.

Re: Proposal: Treat FLoC as a security concern

#83
Lately the loss of security, increased tracking, etc are very pressing issues, which the "general public" is not aware of. Would it be feasible, or actually doable, to create an wareness month - a la Movember? This would help to shine some light on what is being done by major corporations, and which affects everyone.

Re: Proposal: Treat FLoC as a security concern

#84

Can't privacy concious browser defeat FLoC simply by sending random cohort IDs on each request?

I would believe that random noise is easy to filter when you are Google.

Depends upon the noise, But even if they filter it out it will get the desired result of not having a cohart id. In case of opting out you are in the default don't like privacy invasive cohart

Re: Proposal: Treat FLoC as a security concern

#85
I mean yes, web ads have been used to hack people for decades. Just put your code in the ad and steal his cookies (and the next 10 issues after that gets patched by the ad service). It was a favorite topic in blackhat presentations. At the end of the day there is no way to do ads securely, aside from maybe JPEG ads. People don't seem to understand that adding more bloat to the web (which is already a terribly insecure and inefficient way to implement software) directly reduces the security of online banking and e-commerce.

disclosure: I don't know what FLoC is, and the OP page doesn't load. Seems to be something about web ads security.

Re: Proposal: Treat FLoC as a security concern

#86

Earlier quoted context omitted.

Possibly GDPR? As an explicit no-consent to tracking? Not rhethorical questions, I know too little about the details.

When you use Chrome for the first time, it makes you accept its ToS which tells you they are going to track you.

If the ToS are contrary to the law, then they are null and void. Laws tend to trump private agreements. Then, if it goes to trial in Europe, they’d have a hard time proving that the ToS are fair and that the user agrees freely and understanding what is being agreed, which is also another condition for any form of contract to be valid.

Re: Proposal: Treat FLoC as a security concern

#87
post #44

The submitted title was "WordPress Proposal to Treat Google's FLoC as a Security Concern". That makes it sound like Wordpress itself is officially making this proposal. Is it? The page doesn't look like that to me. We've reverted the title in keeping with the site rule: " Please use the original title, unless it is misleading or linkbait; don't editorialize. " ( https://news.ycombinator.com/newsguidelines.html ).

> That makes it sound like Wordpress itself is officially making this proposal. Is it?

Seems like it is to me.

Re: Proposal: Treat FLoC as a security concern

#88
post #83

Lately the loss of security, increased tracking, etc are very pressing issues, which the "general public" is not aware of. Would it be feasible, or actually doable, to create an wareness month - a la Movember? This would help to shine some light on what is being done by major corporations, and which affects everyone.

Sectember?

Re: Proposal: Treat FLoC as a security concern

#89
post #74
post #59

I just love the Google's way of thinking. Users: We hate cookies, because they are abused to hurt our privacy by allowing advertisers to build a profile about us Google: We have a great idea! We can get rid of 3rd party cookies and instead make your browser build profile about you and share it with everyone.

IIUC while floc does indeed build a profile browser side it isn’t something that advertisers can track with the same precision as they can with 3p cookies. So while it’s not the holy grail it does appear to be a small step in the right direction from the status quo. Do I understand the situation correctly? Genuinely curious.

That's what I've been wondering. If FLoC is better for privacy than current tracking methods and Google intends to switch to using FLoC instead of current tracking methods, wouldn't it be better for FLoC to succeed?

Re: Proposal: Treat FLoC as a security concern

#90
post #69

Earlier quoted context omitted.

When you use Chrome for the first time, it makes you accept its ToS which tells you they are going to track you.

They will lose that case under GDPR, you can't hide the details in ToS and hope the user doesn't see it. You must get informed and freely given consent. Google is violating both, because I can't click "No" and the information is so hidden you can't expect a normal consumer to find it. It will take a few years but they're going to get hit very very hard by EU privacy regulators.

Of course, but the goal is not to win, the goal is to make it so it take years before they get fined. In the meantime, they will have made enough money and it will be factored into the cost of business, then they will come up with a new tracking scheme. Rinse and repeat.
Post reply on HN