I asked for a scheme. How are they differentiating between individual devices without tracking individual users. Again: you seem to be claiming that Google is using some form of linguistic trickery here, but you're unwilling to describe exactly what that trickery is. I content this is because it'll sound ridiculous when you actually say it, so you resort to dancing around it instead.
This isn't good for anyone by the way, it is a disincentive for companies to use clear language to communicate with consumers (which is a pet peeve of mine). Assuming Google isn't actively trying to mislead, which is more useful to the average consumer, the statement they made, or the legalese they'd need to assuage your concerns?
> Even worse. Google had 8 years to adequately disclose to users the DoubleClick tracking or allow them to disable it.
Sort of. No one cared until March of 2020. Not like only the privacy wonks, I mean like literally no one, I can't find reference to the x-client-data string on the internet prior to 2020 except in https://unsearcher.org/more-on-chrome-updates-and-headers, which found it in the Chrome whitepaper. So is your contention that explicitly describing a header and how it is used in the whitepaper on privacy is not adequate disclosure? Or even that including it in the whitepaper is somehow "the deliberate decision to not disclose this tracking"?
That seems pretty far a reach to me.
> Yes, this is why ad networks tend to run fingerprinting scripts.
But does Google? Did Google ever? As far as I know the answer is no, Google doesn't claim to use any advanced fingerprinting techniques, which means your accusation, when fully fleshed out is
"In the case of multiple logged-out but non-incognito chrome users in the same household, x-client-data could be used to better target ads to specific devices in the household, instead of the household as a whole, to better fingerprint devices in a a way that Google has never attempted to do before, and this was intentionally never disclosed."
Because if you're logged in, the x-client data doesn't matter, you have the user id. And if you're one person per household, it doesn't matter. So the only groups this matters for are the people who don't use any Google products but who use chrome but also aren't privacy conscious enough to use an ad-blocker. I can't imagine that group is very big.
And the only way to reach this conclusion is to
1. Assume that this was intentionally not disclosed, as opposed to accidentally not disclosed. There's evidence that it was and is disclosed, just not in ways you personally feel are enough. There's evidence that it was not intentionally hidden.
2. Assume that Google is intentionally misleading you with sneaky wording, in ways that are more reminiscent of freeman-of-the-land style legal tomfoolery than actual things that businesses, even unethical ones, do.
3. Assume that all of this was done to continue to do a thing that there's no evidence that Google has ever done.
The amount of bad faith you have to assume is staggering.
> Additionally, Google could be compelled to use this data to track users and lie about it publicly through the use of National Security Letters or other nation state mechanisms.
Which leaves us with this, which I'd consider perhaps plausible, but unlikely. My understanding is that NSL-style mechanisms can compel companies to provide data, but not to build infrastructure. So if the data isn't joinable, an NSL couldn't compel a company to modify things so that it is joinable.
There are fair concerns about why this isn't opt-out. But your concerns go so far beyond anything reasonable that they deserve pushback.