Yes and no. I work on tooling very similar to the actual, intended, use of the x-client-data header (aggregate performance analysis).
> because the data being sent to DoubleClick without notification is gold for tracking purposes
What does it provide that other data that is accessible does not?
> IP Addresses cannot be used to differentiate devices.
Ah, I see, so in the case of multiple logged-out but non-incognito chrome users in the same household, x-client-data could be used to better target ads to specific devices in the household, instead of the household as a whole. That's the "gold" here?
> - This "feature" was added sneakily. No notification, there's no user disclosure. Nothing. That just screams suspicious, given the value of the data being sent.
Sure, sort of, in 2012[0]. Doubleclick was added a bit later, in 2014[1]. The reasoning, at the time, is provided in the linked bug[2]. Sure looks nefarious. So was this an 8+ year scheme?
Now, there are (at least) two possible ways to look at this, either it's an almost decade long scheme, or alternatively no one on chrome had any intent of ever tracking individual users, and it wasn't even considered.
The bug also provides some more insight, doubleclick and GA serve different types of data, and that might matter for measuring things about QUIC.
> DoubleClick is in the whitelist for no reason other than ad tracking purposes. The amount of websites who make calls to DoubleClick and not GTM or GA must be vanishingly small.
Literally the first website I picked, CNN.com, has doubleclick sources, but not GTM or GA (at least as far as I can tell).
> and does not rule out use for tracking or advertising purposes
I will once again ask for a scheme by which the header is both useful for tracking or advertising, and isn't used for tracking individual users. It seems like you're claiming that Google is attempting to split hairs and say that tracking individual devices is different from tracking individual users.
I've explained before why something like x-client-data can actually be a useful privacy-preserving tool elsewhere[3] (since it allows you to join across a quasi-identifier instead of a PII-identifier).
[0]: https://chromium.googlesource.com/chromium/src.git/+/f89fdab...
[1]: https://chromium.googlesource.com/chromium/src.git/+/64d617e...
[2]: https://bugs.chromium.org/p/chromium/issues/detail?id=379341