> https://github.com/jkarlin/floc
> Browsers would need a way to form clusters that are both useful and private: Useful by collecting people with similar enough interests and producing labels suitable for machine learning...
This still doesn't address spreading mass propaganda (show feed of immigrant crimes to floc 43A8C before the elections, because well, they happen to be Xenophobic) and user control. They propose browsers send random flocs to avoid clustering flocks of sensitive categories, but pretty sure the default isn't going to be random.
--
> https://github.com/bslassey/privacy-budget
> Fundamentally, we want to limit how much information about individual users is exposed to sites so that in total it is insufficient to identify and track users across the web, except for possibly as part of large, heterogeneous groups.
So, this is a glorified version of Do Not Track but with budgets and involves more telemetry to be shared with browser vendors and/or websites? How is this even in the conversation? How about browsers simply block attempts to fingerprint a user or allow extensions that do? Penalise websites known to fingerprint from search results? Display a big red banner before the user navigates to that website? Proxy such websites, if the user so agrees and send only content that's relevant (like some kind of an advanced read-mode)?
--
> https://github.com/dvorak42/trust-token-api#motivation
> Preventing fraud is a legitimate use case that the web should support, but it shouldn’t require an API as powerful as a stable, global, per-user identifier. In third party contexts, merely segmenting users into trusted and untrusted sets seems like a useful primitive that also preserves privacy. This kind of fraud protection is important both for CDNs, as well as for the ad industry which receives a large amount of invalid, fraudulent traffic.
I like the concept of issuing tokens and then redeeming them later... but it seems like a lot of elaborate crypto to only really prevent ad-fraud (the advanced fingerprinting techniques they talk about elsewhere cannot prevent it?). It opens up another attack surface, whilst also not being truly anonymous to the first-party that issues the tokens.
--
> https://github.com/csharrison/conversion-measurement-api
> Since the ads industry today uses common identifiers across advertiser and publisher sites to track conversions, these common identifiers can be used to enable other forms of cross-site tracking.
> This doesn’t have to be the case, though, especially in cases where identifiers like third party cookies are either unavailable or undesirable. A new API surface can be added to the web platform to satisfy this use-case without them, in a way that provides better privacy to users.
This is all out battle against content-blockers. Block third-party cookies, and still you're in their cross-hairs... but wait... this is more privacy-friendly, so will you, the end-user, please suck it up.
--
I hope Raymond Hill is reading and already thinking of ways to mitigate this. I see this as push by Chrome in response to the ecosystem Brave is building and the direction Apple is going, and simply taking control of the privacy conversation by doing what's best for them, all around, without holding back any punches. That's not to say, Apple isn't doing the exact same thing! BigTech can't be trusted with privacy, and this post kind of proves it?
"It is difficult to get a man to understand something, when his salary depends on his not understanding it." Indeed.