Do you think the average user knows that Chrome is sending unique identifiers to DoubleClick? Of course not, it was never disclosed and they were never given the option to disable it.
Do you think the average user knows that Chrome is sending unique identifiers to DoubleClick? Of course not, it was never disclosed and they were never given the option to disable it.
> Do you think the average user knows that Chrome is sending unique identifiers to DoubleClick?
What's your actual concern? What you've described here applies to nefarious data like the IP address.
This can also be considered anti-competitive behavior. DoubleClick has access to orders of magnitude more tracking data than its competitors.
IP Addresses cannot be used to differentiate devices. X-Client-Data can, easily.
My concerns are:
- Their statement is ambiguous, and does not rule out use for tracking or advertising purposes, nor does it rule out future use for individual user tracking.
- This "feature" was added sneakily. No notification, there's no user disclosure. Nothing. That just screams suspicious, given the value of the data being sent.
- It cannot be disabled. This is the key point. Why can't it be disabled?
- DoubleClick is in the whitelist for no reason other than ad tracking purposes. The amount of websites who make calls to DoubleClick and not GTM or GA must be vanishingly small. So the argument that you want to collect the most data is disingenuous. 87%(!!!) of the top 100,000 websites globally make calls to GA.
My concern is Google has sneakily added a feature that can be used for tracking purposes while refusing to disclose it to end users and making it impossible to disable.
Yes and no. I work on tooling very similar to the actual, intended, use of the x-client-data header (aggregate performance analysis).
> because the data being sent to DoubleClick without notification is gold for tracking purposes
What does it provide that other data that is accessible does not?
> IP Addresses cannot be used to differentiate devices.
Ah, I see, so in the case of multiple logged-out but non-incognito chrome users in the same household, x-client-data could be used to better target ads to specific devices in the household, instead of the household as a whole. That's the "gold" here?
> - This "feature" was added sneakily. No notification, there's no user disclosure. Nothing. That just screams suspicious, given the value of the data being sent.
Sure, sort of, in 2012[0]. Doubleclick was added a bit later, in 2014[1]. The reasoning, at the time, is provided in the linked bug[2]. Sure looks nefarious. So was this an 8+ year scheme?
Now, there are (at least) two possible ways to look at this, either it's an almost decade long scheme, or alternatively no one on chrome had any intent of ever tracking individual users, and it wasn't even considered.
The bug also provides some more insight, doubleclick and GA serve different types of data, and that might matter for measuring things about QUIC.
> DoubleClick is in the whitelist for no reason other than ad tracking purposes. The amount of websites who make calls to DoubleClick and not GTM or GA must be vanishingly small.
Literally the first website I picked, CNN.com, has doubleclick sources, but not GTM or GA (at least as far as I can tell).
> and does not rule out use for tracking or advertising purposes
I will once again ask for a scheme by which the header is both useful for tracking or advertising, and isn't used for tracking individual users. It seems like you're claiming that Google is attempting to split hairs and say that tracking individual devices is different from tracking individual users.
I've explained before why something like x-client-data can actually be a useful privacy-preserving tool elsewhere[3] (since it allows you to join across a quasi-identifier instead of a PII-identifier).
[0]: https://chromium.googlesource.com/chromium/src.git/+/f89fdab...
[1]: https://chromium.googlesource.com/chromium/src.git/+/64d617e...
[2]: https://bugs.chromium.org/p/chromium/issues/detail?id=379341
I can see they're preloading GTM scripts, which means those requests are absolutely made. I can't tell if the script is executed, but that doesn't even matter since it's requested.
Just open up your network console and filter by "Google". There are numerous requests to Google services, including Google.com and GoogleTagServices.com.
>I will once again ask for a scheme by which the header is both useful for tracking or advertising, and isn't used for tracking individual users.
Tracking groups of users.
>So was this an 8+ year scheme?
Even worse. Google had 8 years to adequately disclose to users the DoubleClick tracking or allow them to disable it. To this day, disabling is not possible (not even via config).
>Ah, I see, so in the case of multiple logged-out but non-incognito chrome users in the same household, x-client-data could be used to better target ads to specific devices in the household, instead of the household as a whole. That's the "gold" here?
Yes, this is why ad networks tend to run fingerprinting scripts.
Tracking specific devices is huge. That's partially why the ad industry took a huge hit when Safari cracked down on third-party tracking.
I asked for a scheme. How are they differentiating between individual devices without tracking individual users. Again: you seem to be claiming that Google is using some form of linguistic trickery here, but you're unwilling to describe exactly what that trickery is. I content this is because it'll sound ridiculous when you actually say it, so you resort to dancing around it instead.
This isn't good for anyone by the way, it is a disincentive for companies to use clear language to communicate with consumers (which is a pet peeve of mine). Assuming Google isn't actively trying to mislead, which is more useful to the average consumer, the statement they made, or the legalese they'd need to assuage your concerns?
> Even worse. Google had 8 years to adequately disclose to users the DoubleClick tracking or allow them to disable it.
Sort of. No one cared until March of 2020. Not like only the privacy wonks, I mean like literally no one, I can't find reference to the x-client-data string on the internet prior to 2020 except in https://unsearcher.org/more-on-chrome-updates-and-headers, which found it in the Chrome whitepaper. So is your contention that explicitly describing a header and how it is used in the whitepaper on privacy is not adequate disclosure? Or even that including it in the whitepaper is somehow "the deliberate decision to not disclose this tracking"?
That seems pretty far a reach to me.
> Yes, this is why ad networks tend to run fingerprinting scripts.
But does Google? Did Google ever? As far as I know the answer is no, Google doesn't claim to use any advanced fingerprinting techniques, which means your accusation, when fully fleshed out is
"In the case of multiple logged-out but non-incognito chrome users in the same household, x-client-data could be used to better target ads to specific devices in the household, instead of the household as a whole, to better fingerprint devices in a a way that Google has never attempted to do before, and this was intentionally never disclosed."
Because if you're logged in, the x-client data doesn't matter, you have the user id. And if you're one person per household, it doesn't matter. So the only groups this matters for are the people who don't use any Google products but who use chrome but also aren't privacy conscious enough to use an ad-blocker. I can't imagine that group is very big.
And the only way to reach this conclusion is to
1. Assume that this was intentionally not disclosed, as opposed to accidentally not disclosed. There's evidence that it was and is disclosed, just not in ways you personally feel are enough. There's evidence that it was not intentionally hidden.
2. Assume that Google is intentionally misleading you with sneaky wording, in ways that are more reminiscent of freeman-of-the-land style legal tomfoolery than actual things that businesses, even unethical ones, do.
3. Assume that all of this was done to continue to do a thing that there's no evidence that Google has ever done.
The amount of bad faith you have to assume is staggering.
> Additionally, Google could be compelled to use this data to track users and lie about it publicly through the use of National Security Letters or other nation state mechanisms.
Which leaves us with this, which I'd consider perhaps plausible, but unlikely. My understanding is that NSL-style mechanisms can compel companies to provide data, but not to build infrastructure. So if the data isn't joinable, an NSL couldn't compel a company to modify things so that it is joinable.
There are fair concerns about why this isn't opt-out. But your concerns go so far beyond anything reasonable that they deserve pushback.
[0]: https://stackoverflow.com/questions/12183575/what-is-followi...
Google made the deliberate decision to not disclose this tracking, right? That's the definition of secret.
I won't speak to legality since I'm not a lawyer, and I never claimed it was illegal for that reason.
If this feature was disclosed to users with an opt-out, it'd be significantly less suspicious. Instead you've got a secret hard-coded mechanism for tracking users that is impossible to disable. Maybe the reason people are suspicious is because it's a little hard to trust "we don't use this for tracking! trust us!" from a company that makes their money from advertising and tracking (including shadow profiles).
Additionally, Google could be compelled to use this data to track users and lie about it publicly through the use of National Security Letters or other nation state mechanisms.