Full third-party cookie blocking and more
webkit.org
webkit.org
Of course Google could do this too, if they had a reason, even if only downstream from Chromium. It's just a commercial decision. Apple have decided they don't want their users to have usable anonymous web apps. Of course, since they don't support beforeinstallprompt, we already know they don't want their users to have web apps, period. Gotta get that sweet 30% cut!
For applications that have you add it to your home screen using the app icon, it may be more of an issue, but why wouldn't you sync that data back up to the server?
It's fine that Apple don't want to support this valid mode of app distribution and use. It is a valid mode, however.
It's not trivial, though, seeing how notification prompts were abused...
If it's a PWA that's regularly used you should be fine. But if not, yeah, that's going to be very annoying.
Installing a native app is a stronger form of opt-in than simply clicking an URL to a new website.
That's what a PWA is :). Browsers should lift these restrictions for installed PWAs, and probably do.
“ Web applications added to the home screen are not part of Safari and thus have their own counter of days of use. Their days of use will match actual use of the web application which resets the timer. We do not expect the first-party in such a web application to have its website data deleted.
If your web application does experience website data deletion, please let us know since we would consider it a serious bug. It is not the intention of Intelligent Tracking Prevention to delete website data for first parties in web applications.”
This post is about them extending it to all storage set from JS.
I expect companies will start working around this with CNAMEing and proxying, and I'm curious how Apple will handle it.
And since they can easily correlate logs server side, they can track people between sites.
Blocking 3rd party cookies I'm fully on board with, but I don't want first party cookies deleted unless I actually specify it. Fortunately as a user I can keep using Firefox, but since iOS is always going to be a large percentage of our users, there's not much choice on the provider side.
I wouldn't be surprised if this is one of the ways ad tracking tries to rebuild a universal identifier like the old urchin module. Might not be as easy as a cname but those might get blocked. It's always a game of cat and mouse. Could place uuid as 1st party httponly cookie. maybe uuid is domain scoped. then 'echo out' so accessible by 3rd party JS. Like a hash, one would need to know the global pooled uuid already and then combined with knowable domain could tie that uuid into the 2nd party tracking pool.
You need the user to manually provide an identifier (i.e. login) to avoid losing everything.
The user's password safe is now the only non-volatile storage mechanism on Safari.
httponly cookies can't be set from JS, and the seven day erasure only applies to cookies set from JS. That's why they're the recommended method for keeping a user logged in.
The key phrase is “without user interaction”. Only e.g. invisible nested iframes that scammy ad companies love to use will have their localstorage limits affected. Top level frames are unchanged.
“seven days of Safari use without user interaction on the site”
Does not mean that top-level frames are unaffected. Everybody is affected. They specifically call out first party storage as being misused currently. I think the correct interpretation is:
Whenever the user interacts with your page then the clock gets reset to 7 days, also the clock only runs on days the user uses Safari.
Now ITP has aligned the remaining script-writable storage forms with the existing client-side cookie restriction, deleting all of a website’s script-writable storage after seven days of Safari use without user interaction on the site.
...maybe "script-writable" should be "third-party-in-iframe-script-writable"? If so this document should be edited.
> “chrome will never have this”
Indeed :)
Seems like a great way to drive less use of local browser storage options and promote greater use of cloud storage solutions. Cynical me says "YAY iCloud".
"seven days of Safari use without user interaction on the site"
It's not immediately obvious the way it's phrased but they couldn't be calendar days if there are days you don't use Safari; it's only counting a day as one where Safari is used and you don't visit the site.
The problem is that this blocking induces some failures which are hard to diagnose. For instance, on the official site of my city I can't use some pages because they loop on requiring my authentication, since they use iframes with shared cookies. On other sites, submitting a form will fail with no error messages. I also remember a Python MOOC that failed with a blank page because of this blocking. Fortunately, all of these errors are uncommon.
Now some huge double-digit share of traffic is going to encounter these issues, and force sites that depend on 3rd party cookies to re-architect themselves to support "normal" people on their iPhones.
My wife finds that various sites just don't work so I have to disable it whilst she checks out.
If these 3rd party cookies and domains are highlighted and force people's practices to change a bit, I will be happy.
I just don't understand people that run a site that relies on so many third-party sources to actually function. Since the site owner is not in control of the third-party reliability or uptime, it is essentially handing control/resiliance of the original site to the third-party (and putting the fate of their shop in it too). Absolutely baffling.
This is the front loaded approach which can cause breakage. I prefer the back loaded approach of using an extension like Cookie Auto Delete or similar that deletes cookies once you're away from a domain for a set amount of time (I think mine is set to 2 minutes).
I just tried the new Safari Preview and this indeed stopped our framed web app from working. I managed to get it somewhat working again by asking permission via the new Storage Access API. Yet another popup users need to click through, ugh. I also managed to get one Safari Preview in a state where it would consistently deny access, without prompting the user again. This is going to make for painful support tickets.
I guess a more permanent solution would to ask my customers to put a piece of JavaScript on their page so we can set first party cookies but that seems a support nightmare as well. Any other suggestions to work around this would be most welcome.
Too bad Safari isn't my default browser anymore, ever since they essentially killed it when they neutered extensions.
Edit: someone just told me you can do it with osx adguard, in the user rules you can set "||domain.com^$cookie" to block all cookies from domain.com
Although maybe ITP is still involved, as Google implemented workarounds to be able to set third-party cookies regardless of this Safari setting, costing Google $22.5M. https://www.ftc.gov/news-events/press-releases/2012/08/googl...
Blocking third party cookies seems like overall a good thing for security. Security is good right?
Edit: 2 years is a long time to wait for a security improvement that is literally flipping a switch.
If Chrome blocked third party cookies today we'd see something between these two outcomes:
a) Publishers lose about half their revenue because ads aren't personalized anymore: https://services.google.com/fh/files/misc/disabling_third-pa...
b) Advertisers figure out how to keep personalizing ads through fingerprinting (non-cookie tracking)
Since (b) is worse than the status quo (users can't reset their fingerprint) I think "a security improvement that is literally flipping a switch" doesn't fit.
Chrome's approach (as described in https://blog.chromium.org/2020/01/building-more-private-web-...) is:
* Block fingerprinting
* Figure out how to let advertisers personalize in privacy preserving ways (https://www.chromium.org/Home/chromium-privacy/privacy-sandb... primarily FLoC and TURTLE-DOV)
* Then remove cookies
I'm skeptical about the approach, since I think blocking fingerprinting and server-side correlation of requests is very difficult, but I think the people working on this are very good and have thought a lot more about it than I have.
This is a great reason to not use Chrome.
Do you think the browsers should block all ads by default?
Browsers, after all, are user-agents designed to serve the user and not corporate interests. Technology as a whole should be there to make our lives easier, not waste our time.
Publishers will not go out of business don't worry. Clickbait will die off because the cheap nasty ads that currently make it viable will disappear. Tasteful, pleasant ads tailored to the current content, negotiated directly between the publisher and the advertiser will remain, and will be harder to block because they are just content served just like the rest of the content on the page instead from a nasty ad network domain.
Resounding yes. Such a thing would be the single greatest security improvement a browser could implement. It would also completely destroy pretty much the only vector online scammers have to reach you.
Most forms of advertising are totally fine. Hell I’m even favor of targeted advertising so long as it’s targeted to the content demographics instead the literal individual following them around.
> I’m even favor of targeted advertising so long as it’s targeted to the content demographics instead the literal individual following them around
Then you might like FLoC (https://github.com/jkarlin/floc) and TURTLE-DOV (https://github.com/michaelkleber/turtledove). These are both ways of implementing targeted advertising without letting the advertiser or ad network follow you around.
Types of ads that I don't like but I won't be up in arms about from a security perspective.
* Paying for sponsored reviews.
* Affiliate links and partnerships.
* Paying promoters and influences to push your product.
* "One way broadcasts" like billboards, commercials, magazines.
* In house ads like Kroger sending you coupons based on your purchase history at Kroger.
* Corporate press events like E3.
* Paying to post on the community billboard.
* Paying have a booth at professional/enthusiast conferences/trade shows.
* Stuff like E3/NintendoDirect/PAX/BlizzCon.
* Selling air time on radio, podcasts, online videos.
* Sponsored articles/announcements on blogs/news sites.
* Native advertising a la Buzzfeed where they would get paid to write a listical "top 10 things you should order off the secret menu at Taco Bell."
* Generic direct mailings and coupon books.
* Paying employees to suggest and guide customers through the sale provided they're upfront about it. I've seen Lululemon do it somewhat tastefully on Reddit when people post topics looking for recommendations.
But ads that come from ad networks/exchanges are nothing like these while simultaneously being the bulk of what ad blockers actually block.
So I don't see it as a contradiction. The kinds of ads that ad blockers block aren't usually these and are instead are the spyware/malware kind.
(i am a user; i don't presume to know what is best for others; speaking as a user that talks to others like me; i don't need to speak about 'users' as a third party entity; i am a significant sample of the set)
At best the ad revenue is taking money away from other web business models by instituting that kind of mentality that drives people away from donations and paid accounts.
Please, consider a paid account/membership when you read the guardian, the intercept, or look for the donation page of quality content articles in wikipedia or any of the loads of blogs written by authors with patreon accounts.
Estimate how many websites you visit each month; people would need dozens of monthly subscriptions if such a system was set up.
Instead, they will rather go to and pay google news, facebook press or apple information to get all their news content. Where would money be taken away then? Content publishers.
For example, I want to disable WebRTC as it can be used to collect my IP address, or disable WebGPU APIs or anything that can be used to finger print me.
JS has far, far, far too much broad access to information that might seem mundane but can be used to profile a user.
Android is the same - you can get the entire list of installed packages on the system and various other pieces of information to build a unique, persistable tracking ID.
There's also a lack of accountability: What information is being sent to what servers? I want a detailed JSON formatted breakdown of EVERY single piece of data that is being sent from my device.
I should be able to block anything that is outside my own determined comfort zone.
But most OS' just make requests to US IP's without much thought now - just turn on Windows 10 in a VM and watch as it sends so many requests with no insight into the data, which many companies (including Google) don't tell you about.
Ask me about a recent GDPR request to Google which I just got a generic response about (and they didn't action my request to delete information, so now I need to complain to the regulator because it was also late).
So yes, blocking ALL tracking by default is sensible.
I am on the demand side, and the thesis and testing methodology seems extremely flawed.
If you disable third party cookies on a test group of certain publishers our (demand side) bidders will start optimizing towards the control group; this is very obvious.
Also, was this analysis conducted on other ad exchanges? For example, Google ADX makes only ~30% of the global traffic we get, and the traffic has very different characteristics from the traffic we get from APPNEXUS, Rubicon, etc.
I believe this is an analysis for Google's internal conclusions, and not for the industry in general. Has this been made public before?
It says "turned off the availability of personalized data for a small fraction of randomly selected users" and "The experiment was applied to a small fraction of each publisher’s traffic because we did not want to materially affect publisher revenue, though in aggregate the amount of traffic evaluated as part of the experiment was significant". It sounds like you're responding to a version of the experiment that was run on a per-publisher basis?
> was this analysis conducted on other ad exchanges?
It says the experiment was conducted "through the programmatic arm of Google Ad Manager’s serving system". I'm not sure what this means, but I don't think it includes AppNexus or Rubicon.
I believe any publisher could run their own version of this experiment by picking a slice of traffic and telling all their bidders to only show non-personalized ads.
> Has this been made public before?
This document was released in August: https://www.blog.google/products/ads/next-steps-transparency...
This means the cookies for the auctions of a control group of users were not exposed. The experiment is still wrong, the bidders will still react in real time discarding the traffic without identifiers; specially since it comes from ADX where the identifier is the key to evaluating the model.
Not taking any other ad exchange into account is a huge flaw if you want to extrapolate the conclusions into conclusions for the whole industry. Other exchanges provide different identifying properties such as the 4th octet of the ip_address with each auction. Google ADX doesn't send this bit of information, they obfuscate the ip_address always. It's obvious that if you remove cookies from ADX, there is no reason to use ADX since the cookie is the proxy for your model on that exchange, but on the other ad exchanges you could survive just fine.
There is no way I read this experiment in which it makes sense as a conclusion for the whole ad industry.
Granted desktop fingerprinting is more of a challenge due to differing OS's, screens, GPUs for WebGL, etc. But it doesn't seem impossible.
They have also blocked third party cookies for so many years. The world did not catch on fire.
They use an advertising ID the user can reset.
https://weis2019.econinfosec.org/wp-content/uploads/sites/6/...
They find publishers only have a 4% premium on programatic ads that involve behavioral targeting.
It was critical to election tampering in 2016, it's been used for racism, sexism, and every imaginable sort of scam.
The only way personalized advertising would be remotely ethical is if it were explicitly opt-in. I notice that's not a thing on your list of steps Google is planning on doing. No surprise.
Specifically, I referenced two proposals for privacy-preserving ad personalization, FLoC (https://github.com/jkarlin/floc) and TURTLE-DOV (https://github.com/michaelkleber/turtledove), and their response was that privacy wasn't the issue, the effects of personalization are harmful in themselves.
For privacy I do agree that you can't just do it with legislation and you also need technology. But if you think the issue is personalization itself, regardless of how privately it is implemented, then legislation is the critical playing field. Blocking personalization on the open web through technical means while allowing it in walled gardens means you (a) still have most of the claimed harms of personalization but also (b) massively disadvantage the open web.
Reading through those links on FLoC and TURTLE-DOV, those are interesting concepts. My worry is that even though the ad selection is done in the browser, it will still leak significant information. For image/video ads, it would require bloating the amount of bandwidth used to serve the ads, or would leak information about which ad was selected by the client.
The two are more or less intertwined. "Personalization" leaks information about people. It has also allowed advertisers to promote material targeting (or eliminating) otherwise protected groups.
People have been outed for being pregnant and for being gay, by outside observers noticing what promotions they were getting.
Unfortunately back when I thought of this I wasn't aware of browser fingerprinting or all the other nefarious things the advertising industry is doing. Fingerprinting turns both FLoC and my idea into tracking vectors, so that's out of the question. The authors acknowledge this problem in the readme.
Turtledove is a longer spec and I haven't had the time to read it thoroughly, but while the idea is good, I see some potential problems - first off, this still involves executing JS to do the "ad auction" on the browser which could have security implications (they explicitly mention that JS should be prevented from talking to the outside, leaks would be vulnerabilities in this case, and I don't trust the ad industry to be nice and not attempt to exploit them); there's also the issue that I just don't want my device to expend processing power and expose me to potential security vulnerabilities for ads; I want ads to be served as static images from the website without the whole bidding thing. From an advertiser's perspective, I'm not sure how fetching the potential ads in advance and moving the auction on the client device would work - my understanding is that auctions are in real-time. I'm also not sure whether exposing all the ads to the public (even the ones that ultimately don't get chosen at the auction) and the auction details would reveal information that advertisers consider sensitive.
Finally, if you look at my other post here: https://news.ycombinator.com/item?id=22680559 you'll see that I have other problems with online and targeted ads besides the privacy and security aspect.
Unlike print and TV ads, there little-to-none human review, no accountability (Google isn't liable if they serve me a scam ad if I fall for it), and targeting allows to target scams to only the people most likely to fall for them while hiding these ads from the savvy people who would recognise the scam and report it. At the core, this isn't a tech problem but a law problem, but short of a law it can be solved by tech if we heavily block the current model of ads (targeted and served from a central ad network) so it becomes unprofitable and publishers & advertisers have no choice but to host static ads on their own domain, thus becoming liable if they host malware or something illegal (this would hopefully encourage human review).
Does what it says on the tin.
Third party cookies have been blocked in Firefox since September 3rd (2019) [1]. They mention Brave in the article, so surely Firefox being large than Brave should be included in "Major browsers", but not a single mention was made in the article. It really reminds me of the meme "what do you mean you've seen it?".
[1] https://blog.mozilla.org/blog/2019/09/03/todays-firefox-bloc...
i suppose it’s great for the 90% of “default settings” users.
because a solution (many) is already available for tracker blocking , i’d rather see effective html5 video and popup blocking. is that infeasible?
I guess later is better than never, but this seems like something they could have done long ago.
> Safari continues to pave the way for privacy on the web, this time as the first mainstream browser to fully block third-party cookies by default. As far as we know, only the Tor Browser has featured full third-party cookie blocking by default before Safari, but Brave just has a few exceptions left in its blocking so in practice they are in the same good place. We know Chrome wants this behavior too and they announced that they’ll be shipping it by 2022.
I hope that there might be a way to safely auto-sync my Firefox profile, bookmarks and history especially, to Safari iff it's really the more secure of the available browsers for iOS.
I'm looking forward to it. Seriously. I know you're intending to be facetious with this, but everything you listed sounds good to me. Either charge for your service, or include ads that don't follow me around the Internet.
Somehow advertising worked on radio, on TV, and in print without correlating data about each viewer with all their other habits. I see no reason why that can't be the same online.
Did you not notice that print is dead?
Print as a medium may be dead, but journalism is still here. And it’s possible to provide without invasive tracking, just like it has been for centuries. The transition from ink to pixels doesn’t rely on analytics to succeed.
And to circle back to the original comment I replied to: They don't have to. A business can be run providing entertainment without granular user tracking. HBO and Showtime did it back when they were just add-ons to cable packages.
What OG commenter was implying, is that the Internet will be worse without 3rd-party cookies and tracking. I can't disagree strongly enough.
The problem here is when data is collected by third-parties I do not know, do not trust, and do not need. They collect data for their benefit without providing me anything of value, only ads aka spam.
Online ads are also nothing like print or TV ads. The latter has a barrier to entry and some minimum criteria they must meet like the laws on what's allowed to be broadcasted and they are at the discretion of the publisher. This makes it less likely that a scam or malware would be promoted for example. Online? It's the Wild West, anyone can advertise anything (fake tech support numbers for example) for a few hundred bucks and targeting means they can make sure only the people most likely to fall for the scam would see the ad, while flying under the radar of anyone savvy enough to recognise it as a scam and report it.
Or maybe I'm misunderstanding and you are suggesting to replace cookies with browser or DNS fingerprinting?
Show them in random order, or based on timestamp.
>ad discrimination
I don't want to be discriminated. If I have to watch ads, then I want the same ads as everyone else. I don't see how that's a problem, as billboards and TV ads are the same for everyone too.
The webs continued existence is not dependent on surveillance capitalism.
That's like saying that life is equally good and the US and North Korea because "people find a way" to work around problems. There's a real way in which economic inefficiencies reduce our standard of living. Making advertising worse on purpose is just a race to the bottom, all feel-good crusading without any end benefit to humanity.
"But I won't be tracked!", the privacy people say. So what? What harm will you have prevented?