Google to stop selling ads based on your specific web browsing
wsj.com
wsj.com
There's a lot of confusion over what this story is actually saying, and, given the obscurity with which Google deals with it's tech, I don't think this is going to get cleared up, leaving room for a lot of speculation. But one thing is absolutely certain: There's no possible way that Google is going to make a change to their biggest money maker that would make them LESS money. Maybe that just means that they consider their duopoly enough of a barrier that advertisers will be forced to accept less-targeted marketing, but I doubt it...
Radar Cross Section
RCS: Radar Cross Section - how big of a reflection an object makes at radar wavelengths.
RCS -> Radar cross section
RCS = Radar Cross-section (a bit more field-specific, more or less how "big" the thing looks on radar, but it is a bit jargony -- it depends on things like the material and radar wavelength).
Keep in mind that advertisers really don't care what your name is or where you live. They care that you are into action movies and buy fancy shampoos. The other stuff just creates trouble.
Google cares on their own.
And current advertisers may not care but who knows what kind of technology they may come up with in the future where that data might be valuable, having extra data has never been a problem for google.
https://blog.google/products/ads-commerce/a-more-privacy-fir...
Make no mistake - as far as I can tell, this preserves Google's ability to track that you are, say, a new parent because you've searched for baby clothes. What it won't know is which new parent you are. The system is designed to give probabilistic assurances of k-anonymity. But Google will no doubt tune those "cohort" memberships, and the value of "k," to capture the vast majority of current advertiser needs, while still being able to communicate to antitrust inquiries and the public that they are not giving people unique identifiers. If anything, it hurts their competition more than it would hurt them, because it allows them to thread the needle in a privacy-conscious world.
Still probably a step in the right direction.
How far can this data be reversed? If I have a group of ten people can google tell with high reliability that probably three of them are homosexual, two have Alzheimer's and none are pregnant?
If you've searched for baby clothes in Google there's absolutely nothing in the FLoC proposal that stops Google from inferring that you're a parent from that search and, idk, storing a bit in your profile or something.
This proposal is about allowing ad targeting to interests or whatever without tracking your visits across the web - your browser generates the cohorts clientside (idk how the cohort assignment algorithms get standardised on, I guess that's where the 'tuning' would go). And yes, you could just tell your browser not to do that, or have it only use the most recent n days' data, or randomize your cohort, or freeze your cohort in time, or blocklist certain sites from ever entering your cohort, and so on.
Where this ties into tracking if you're a parent is that while it doesn't prevent tracking that, it does lessen the incentive - if you're a parent, you're likely going to wind up in a parent-y cohort. Is the signal from the original search still going to be useful enough to warrant keeping around?
(obligatory: googler, but nothing to do with ads)
Either way I reckon it's the same thing stopping people from just sending random data over google-analytics. So, not a whole lot, other than whatever anti-spam mechanisms google bothered to put in place.
Back when I was in the security field, I heard discussions about this sort of thing as a form of attack. The question was whether a computer that sent false or incorrect information was either engaging in a DOS attack or was violating the CFAA in that it was using false information to access a service. The DOS attack would be on the tracking system rather than a website resource, false information to degrade the effectiveness of the tracking system overall. The CFAA angle would be that participation in ads/tacking was part of the contract for accessing the 'free' service, that by blocking ads or sending false info the user is using a false credential to access the service. At the time, many thought that by using an ad-blocker that users were failing to pay, passively stealing website content. Those who sent false information were engaged in active theft.
I don't think I'll ever quite understand the idea that the user is under any obligation to do whatever. Just because their user-agent might have some default behaviour doesn't mean that the user-agent should be expected to act in the interest of the server.
Though there's an argument to be made that sending lots of false data in response to a request to post personal information to google-analytics is a bit like manipulating a public survey by sending in silly answers. I'm not sure to what extent that is illegal but I'll grant that it's not exactly ethically correct.
Because, at this time, ad blocking tools are relatively benign. But what if we think of them more as content-blocking or content-management tools? What if I have a tool that blocks only right-wing advertisements or content? What if I have a tool that blocks all images of women showing too much skin? Block images of black people? Such not-neutral tools would radically change public perceptions. Legislation might follow.
There was a comical toll out there that would replace the text "Trump" with "The idiot" on viewed websites. That's the thin edge of this wedge.
There does seem to be momentum towards a narrow reading of the CFAA when it comes to providing false information against terms of service, though, as per these 2013 analyses... though they fall short of actually giving any guarantees.
https://www.whiteandwilliams.com/media/alert/247_Coverage%20...
http://tsi.brooklaw.edu/cases/matot-v-ch
On the other hand, a denial of a motion to dismiss in Ticketmaster v. Prestige from 2018 seems to have drawn a distinction between breaching terms of service alone, and being told in a cease-and-desist not to breach those terms; the latter more clearly outlines what would be considered exceeding authorized levels of access.
https://casetext.com/case/ticketmaster-llc-v-prestige-entmt-...
Where does false information end and privilege escalation begin? Can that question depend on whether your privilege escalation is something as simple as "I'm now able to avoid the fine-print contract that I need to watch certain types and customizations of ads in order to access the service?" What constitutes sufficient notice to a user that certain actions are explicitly forbidden, if a C&D does but terms of service do not? All questions that, as far as I can tell, haven't been fully answered.
(Obligatory: Not a lawyer, the above is not legal advice.)
I'm horrified whenever I see people having this perception of the issue, and worried that it'll get accepted by the legal system as the correct view.
From my POV, the only contract that exists between me and a random ad-loaded website is the one negotiated between my computer and their server - that is, the HTTP protocol, which clearly stipulates that I can render any reply you send me in whatever way I like. This contract provides many tools for expressing the intent of gating content behind some requirements (like payment, or receiving different content first), but the common rule is: you don't send the content you're gating before the client proves they've met the requirements.
And honestly, I'd consider mixing ads into content to be borderline CFAA (the ads themselves being abusive and often fraudlent, and sometimes malware) - and sending software intending to compromise my user agent (like trackers, or ad-blocking busters) to be crossing the CFAA line. Unfortunately, I don't think the lawyers would agree with me :(.
Much like cinemas. If I try to bring in food I didn't bought at the cinema store, I will be stopped at ticket check and refused entry. Also, the cinema doesn't require me to buy food as a condition for watching the movie. If they did, I'd consider it the price of entry.
What current ad-loaded websites are doing is the equivalent of letting you in to watch a movie, and then having someone come to you as you're watching, and poke you and yell at you because you didn't buy anything at the store.
> They can call the cops and have you arrested for accessing the theatre in contravention of the rule.
I've never heard of a cinema calling cops on people who snuck in food into the theatre. Is that US-specific?
If you are asked to leave and do not leave I can see you possibly being arrested for trespassing, but I fail to see what you would be arrested for by bringing in food from outside the theatre. Sure, they could ban you from coming back to property (and this could lead to trespassing arrests, if you did return) but thats about it.
As I noted in my original message - yes, its client side, you can do whatever. (‘Whether the browser sends a real FLoC or a random one is user controllable’ https://github.com/WICG/floc)
This prompt will never happen. The last thing Google wants is any additional association between their brand and advertising.
Google's mode of operation has always been to sneak in the back door and count how many boxes of cereal you have while you are looking at underwear. Knocking on the front door and to ask if they can come in would likely never occur to them.
There is no mention of Chrome being an ad supported product anywhere when you install it. They want that association completely out of people's heads.
1. Advertisers - who would add you to a cohort they own, so say "Nike - womens-running-shoes"
2. Publishers - who'd want these cohorts to better allow for advertisers to advertiser on their site, so "NYTimes - business-section-reader"
3. Third party ad-tech companies looking to create audiences for advertisers who work with them, so "Example Agency - mens-formal-wear". They'd partner with publishers so that when you go to somewhere like GQ or Man of Many and read an article on tuxedos then you'd get added to the cohort.
So you are right, you'd never see a prompt to add in your interests, but this isn't because Google doesn't want to associate with specific brands, it's that Google isn't necessarily an owner of a cohort (though they totally could create their own under any 3 of those categories).
I don't think we'll get away from the cookie popups, ever. It's just like the "I agree to the TOS / EULA" checkboxes. Legally toothless, but you'd better have one, just in case.
Of course you need to store the user's preference. So now the site needed to have a cookie. One cookie which just stores the fact that the user has or hasn't consented to cookies.
Even cookie pop ups are not respected. If you visit Facebook sites by accident they’ll leave their tracking cookies before you’ve had a chance to read the terms and leave the site.
What would stop them from implementing FLoC in the cloud for non-Chrome users? Fundamentally, where the data is stored is meaningless. So long as they are pushing everything through this same "FLoC" model, they are claiming they won't be tracking individuals.
So on Chrome, FLoC is local—your own browser working against you—for Safari and FireFox, FLoC is cloud based.
So long as the web sites in question are running Google Analytics, they still have the software on your system on a huge number of sites.
This would require being to identify a user when they are on many different sites (cross-site tracking), which all the major browsers intend to prevent.
(Disclosure: I work at Google, speaking only for myself)
https://www.independent.co.uk/life-style/gadgets-and-tech/ne...
There was also the Do not Track setting, which Google ignored. So in my book (and I’m not alone here), anything coming from Google is taken with a huge grain of salt.
For some time, there has been a sort of cat and mouse game between advertisers and browser makers. Do you know Google isn’t using fingerprinting to identify us? Or just IP or some other means?
What I'm saying is Safari [1], Firefox [2], and Chrome [3] are planning technical mitigations that would prevent anyone from implementing a cloud-based FLoC. Even if you don't believe Chrome, it wouldn't be possible in Safari or Firefox.
> Do you know Google isn’t using fingerprinting to identify us? Or just IP or some other means?
https://blog.google/products/ads-commerce/a-more-privacy-fir... has "once third-party cookies are phased out, we will not build alternate identifiers to track individuals as they browse across the web, nor will we use them in our products" and "our web products will be powered by privacy-preserving APIs which prevent individual tracking while still delivering results for advertisers and publishers" which seem pretty clear to me? Additionally, I work in client-side ads infra, and I'm pretty sure I would know if Google were fingerprinting users to target ads.
[1] https://webkit.org/tracking-prevention-policy/
[2] https://wiki.mozilla.org/Security/Anti_tracking_policy#1._Cr...
[3] https://www.chromium.org/Home/chromium-privacy/privacy-sandb...
Google doesn’t really need much more that what it has. It has third-party big data, Gmail, Google Search and a very recent optimized cache of everything important that it’s crawlers can get and more. People get so caught up in the minutia; Google is big, like category 100 Hurricane big, where people laugh and say there is no category 100; but that’s what it is- classification system aside.
Anti-trust and pro-privacy are distractions that Alphabet, Google, etc. can put their left-fielder on while they run the bases, because they play both teams.
curl -s https://www.wsj.com/amp/articles/google-to-stop-selling-ads-based-on-your-specific-web-browsing-11614780021 \
|sed -n '/<meta property=.og:title. content=./{s//<title>/;s/\" ./<\/title/;p;}' \
|egrep -o "(<p>.*</p>)|(<title>.*</title>)" > 1.htm
firefox ./1.htm
Solution #2: Use browser that does not process it. links https://www.wsj.com/amp/articles/google-to-stop-selling-ads-based-on-your-specific-web-browsing-11614780021
Unfortunately some countries block archive.is websites (e.g., at DNS-level), so archive links will not work for everybody.Free extension that can remove paywalls from many of the big news sites. Works on Chrome, Edge and Mozilla.
Much like a tech company that wants www readers to believe it is working to solve a problem www users are having that the tech company itself created (which, it just so happens, is not a problem at all for advertisers).
Just knowing how things worked resulted in a number of people assuming I could hack banks, and either asking me too, or shunning me. Or flat out accusing me of it.
Umm you could go around mugging people much easier then I could hack stuff. That explanation never went over well.
Had to ask one boss to stop threatening employees to have me hack them. It was in jest, but I was terrified at how people would react if they thought I bypass security. Didn’t help that I knew how, as security was crap back then.
I leaned to keep my mouth shut, and refused to keep up with security stuff. Can’t hack if I don’t know how.
So, you have millions of users, and you make it "k-anonymous", or "anonymous if you squint real good". Is it really possible to find k such that privacy is meaningfully preserved, given the heaps of other information you have?
Say I belong to some cohort, and you know my IP address. I think this would be enough to fingerprint me reliably, never mind OS version, browser, plugins, etc.
https://www.chromium.org/Home/chromium-privacy/privacy-sandb... links to https://github.com/bslassey/ip-blindness for how they intend to handle this.
(Disclosure: I work on ads at Google, speaking only for myself)
New parent. Lives in Springfield. Works at a power plant. Drives a car. Owns house. Horrible credit rating. Married with 2+ kids. Voted in last election. Ex military. Ex astronaut. Once purchased an effective baldness cure. How many seemingly large cohorts does it take before you are really talking about one clearly identifiable person?
It takes 33 “perfect” yes/no questions to identify uniquely anyone on earth. It is seemingly large since each question splits the world in two.
Of course this is in a perfect world, but I remember seeing quizzes which would guess any object given a few yes/no question. Or perhaps it was people.
"Each player starts the game with a board that includes cartoon image of 24 people [...] Players alternate asking various yes or no questions to eliminate candidates."
Not many probably know the person in question with her real name - but almost everyone who's ever watched Charlie Brooker's productions should recognise her as Philomena Cunk.
At that point the kids usually go for broke and ask me if my player is Susan.
Advertising rarely is about targeting “John doe” but usually about targeting “[men] && [in Springfield] && [searching for a baldness cures]”.
(I still will do everything in my technical power to disable floc, and still will never trust google). But I do think the implementation removes most of the advertising incentive to track on an individual person level.
Thats what makes FLOC tolerable. The legit stuff is enabled, and it makes it harder to get the other stuff (not impossible of course).
> What about nefarious people who want to put a malware link in front of a specific person.
It'll at least be harder than pre-floc (ideally).
The point is to remove the incentives to collect as much data about an individual (you don't need full profiles of someone) by creating even easier ways to get useful targeting without the direct individual identification.
---
(also, i'm broadly against tracking in general, just to be clear. The point you raised is very valid - esp with existing methods).
No, users are only in a single cohort: "cohort = await document.interestCohort()" -- https://github.com/WICG/floc
(Disclosure: I work on ads at Google, speaking only for myself)
Do cohorts allow advertisers to say, "Show this ad to anyone in a cohort with an affinity for 'new-parent' over threshold X?" is that so?
Do they let advertisers say, "here are the cohorts of our best 1000 customers, please show ads to anyone else in those cohorts?"
Would people in "my cohort" be the 1000-10000 people most like me in browsing habits in the world?
(Disclaimer, have tried to buy limited quantities of ads in the past, interested in some part as an advertiser)
Yes: "a browser can group together people with similar browsing habits, so that ad tech companies can observe the habits of large groups instead of the activity of individuals. Ad targeting could then be partly based on what group the person falls into."
> there would be one cohort of "new-parent-lives-in-springfield-works-in-power-plant-etc-etc" (combining multiple unrelated interests), it just has to have thousands of people in it?
I mean, there aren't thousands of new parents who live in Springfield and work in a power plant? You would be in a cohort like "43A7".
> Do cohorts allow advertisers to say, "Show this ad to anyone in a cohort with an affinity for 'new-parent' over threshold X?" is that so?
Not really? An advertiser or (ad tech company) might learn, over time, that people in cohort "43A7" are very likely to be interested in baby clothes while people in cohort "5B7E" are more likely than average but not by that much. So they might be willing to bid more to show baby clothes to someone in 43A7 than in 5B7E, and not bid at all for most other cohorts. But the browser API just gives you an opaque cohort identifier.
> Do they let advertisers say, "here are the cohorts of our best 1000 customers, please show ads to anyone else in those cohorts?"
From my reading of the spec, that seems like it would work well.
Could a browser vendor send down a mapping of cohort hashes to interest vectors? I don't see anything in https://github.com/WICG/floc that suggests that couldn't happen, and it seems like it could greatly enhance utility without too much sacrifice to privacy. For example, it'd allow an advertiser to target all cohorts who like american football, I'd think.
The current landscape, however, does not prioritize user-privacy and serves ads to unsuspecting users who do not always know the terms they agreed to.
Moving away from the present opt-out to an opt-in model would give the user a say in how they would like to be tracked across the web. This is also what Apple is trying to do with its "nutritional-info" (not fanboying Apple here) labels. A user is free to consume the content they would like, but they have a right to know how their data is being used.
I know this sounds laughable given how toothless regulators have been thus far, but let's not forget that a) fines under GDPR have been growing and are likely to continue to do so, with ad tech in a particularly awkward spot, and b) both the EU and US governments and regulators have started nosing around big tech on a variety of fronts, including privacy and antitrust concerns.
Given that, the cost-benefit analysis becomes pretty complicated. They may feel a shift to a scheme which lowers revenues while avoiding regulatory scrutiny now makes sense.
I'd love to see my scenario be true, but I'm afraid that it's much less likely than yours.
My guess is that they smell a change in the regulatory wind (EU and possibly US as well) and anticipate that if they get out ahead of it, those regulations will serve as a competitive moat against other advertisers.
That, or their A/B testing has confirmed ad quality isn't remarkably improved over the combination of search-tuned ads, adsense topic ads tuned to the site the user is browsing, and display ads tuned by data the site owner vends to Google about the user to fine-tune ad selection for them. They have enough data to know one way or another, and if it turns out there's not enough value-add to justify retaining all that user browsing state, dropping collation and storage of it can free up room for dozens of new projects.
It's easy to forget that one of the major constraints on what Google can do, at their scale, is storage and processing; they're so big that from most people's vantage points, those resources seem limitless, but inside Google, they know exactly how much they aren't doing because the machines and networking they already own are already pushing petabytes of data around and are already near max peak capacity for their mission-critical applications. Sometimes, the cheapest way to get more space for a new bet or an existing mission-critical task is to just stop doing something else.
In the future, you don't have to rely on serendipity to find money on the street. You just use a satellite to find it for you.
the US hegemony relies on a perception of omnipotence, so there will always be a lot of boisterous claims
Even the NSA presentations and code leaks this century didnt really have surprises more just angst about their lack of accountability
To be fair, Google's biggest money maker is their SEA, which doesn't rely on your behavioral data, since user intent is given through a search query.
I think this is your answer right there.
tracking, including the costs of collecting and storing all that data as well as the PR cost of people being creeped out by all that data you store, is expensive. Given how accurately i'm targeted by most advertising (not very) it seems perfectly reasonable to assume that ads will be just as effective and just as revenue-generating if their tracking becomes a bit less granular.
I think the problem is not ad targeting, but ad inventory. They want to sell things we don't need, that's the real cause of the low efficiency.
They should better focus on things people actually need at the time of search.
Bigger telescope systems can resolve smaller objects, but even if you were to yeet an enormous, optically perfect, 10m telescope into the very lowest earth orbit possible (not maintainable due to atmospheric drag) you would still be a couple orders of magnitude away from being able to read the date on a dime.
https://en.wikipedia.org/wiki/Diffraction-limited_system#/me...
I would guess that you'd need 0.25mm resolution, which at 200km would require 250microarcseconds angular res, which doesn't even register on that graph at any wavelength or size of telescope lol
edit: this is a very 'spherical cow' analysis. i'm pretty sure that atmospheric effects will kill your ability to image stuff like this well before angular resolution will.
Also, perhaps there's a need for a better naming system than one that produces ‘Extremely Large Telescope’.
https://en.m.wikipedia.org/wiki/Overwhelmingly_Large_Telesco...
a degree of arc is divided into minutes of arc (MoA)(1/60 degree each), and there are 60 arcseconds in a minute of arc.
Two points that are 1 milliarcsecond apart, projected on a flat surface 200km away, are about 1mm apart on that surface.
edit: (can plug "tan(0.001 arcseconds) * 200km in mm" into google to check this out for yourself)
10m is a tiny aperture: https://en.m.wikipedia.org/wiki/Synthetic-aperture_radar
Correction: if you go by the profit reports from Alphabet, Google Display Ads is not their biggest money maker by a long shot. That's still Search Ads
Of course they move away from this, the must have brainstormed and tested new ways for years. OTOH, it is stunning that we’ve invented tech that is stable even when an ad-blocker interferes with the webpage, cookies, js, requests, etc. Try that with binaries! (which is probably where they plan to move the code)
Advertising is just applied sociology, and sociology is just applied statistics. So statistically significant and unbiased sampling is what makes advertising work.
Highly-targeted and personalized ads are a crutch due to the fact that unbiased sampling is pretty much impossible on the internet. (There's a joke about this: "an online poll has shown that internet penetration has now reached 100 percent".)
Neither advertisers nor publishers actually want to collect high-resolution data, it's a huge cost with very little benefit.
* Google sees the writing on the wall: people are becoming more privacy conscious, but more importantly governments in many countries are making motions to suggest this sort of tracking could be regulated in the future. They need to stay ahead of the curve.
* The value of tracking people in this way may be less than everybody seems to think - not all data about a person's activities is equally monetizable. Just because you read an article about Julius Caesar and then looked at some clickbait article about Britney Spears doesn't mean an advertiser can sell you a chariot.
* Google in making the first move can create an advantage for itself in the market
* Much of Google's revenue comes from their own properties -- in the case of search, they are already well positioned to show you relevant ads because you have shown intent. No need for cookies there.
* Google has a dominant position with Chrome and the article suggests they want to do fingerprinting of a person's browsing behavior and put people into different cohorts without sending the raw data to Google. This is similar to how Apple does machine learning on device. If Google has exclusive access to these cohorts, they have a strong incentive to move to a cookie-less model because it puts other ad networks at a disadvantage.
It also completely eliminates the creep factor and conspiracies around adverts. "How did they know I was interested in this, are they listening to my phone?" goes away when its the same as the content you are looking at currently.
A constant bombarding reminder that I need a new backpack. 90 percent of websites I visit are not about backpacks. I'm getting 90% more ads about backpacks.
Also there are a plethora of contexts where this wouldn't work well. For example, Instagram has the best targeted ads I've ever seen – basically every ad I get is for something I would consider buying.
I don't think their ads would work nearly so well if I got an add for a guitar just because my friend tagged her post with #guitar.
Full disclosure: I'm reading The Age of Surveillance Capitalism and I get more skeptical (and fearful) with each page turn.
https://www.wnycstudios.org/podcasts/otm/segments/living-und...
Oh stop it with these conspiracies.
Google (like Facebook) has been pushed in this direction for ~2-3 years by changes in Safari to the point that Google has started preparing for this pro-actively
Why do you think Google hasn't complained like FB about the upcoming changes in ios ?
Facebook seems to know what Kickstarter products I’ve backed, what specific miniature paints I like and seemingly which I’ve already bought. Possibly because a lot of my miniature hobby socialising takes place in messenger and on Instagram.
Google by contrast is so bad at advertising, that I often have to re-search on duck duck go to find a webshop that I can actually use post-brexit. Maybe because google knows I don’t speak Spanish, Italian and suck at German? But I mean, I still buy stuff from Spanish websites using the translate function in chrome, so, shouldn’t they know better?
Anyway, for me personal and anecdotal, it seems google is really bad at predicting what I want. I mean, even for content. The front page of YouTube is full of videos I’ve already seen...
With the announcement of federated learning of cohorts [0], it allows Google to use their massive amount of information they have on you already, as well as their dominance in AI to cut out the easy way of tracking people, and make it harder for anyone else to personalize ads.
Don’t get me wrong it’s a good thing that we are removing third-party cookies, but the idea that Google is confident they can track you without them makes me worried for the future of advertising. This move is undoubtedly going to cement google as the best ad tracking company for some time into the future.
[0]: https://www.cnbc.com/2021/01/24/google-extremely-confident-a...
It's also worth noting that other groups have proposed systems that would not result in Google creating another monopolistic product line. Google did not seem very interested in such alternatives.
yes, yes yes yes. This proposal is that:
* the web have no individual tracking
* the browser, instead uploads our every activity across all sites into the cloud
* the cloud/browser-operators (google, firefox, microsoft, opera, brave) take these troves of big data & apply machine learning to generate cohorts
* the browser then places us into these cohorts
this would, as parent post suggested, absolutely "cement google as the best ad tracking company". it also makes it radically harder to create a new browser. Brave would have to become not just browsing software you run on your computer, but a cloud-service, gathering reams of data like Google, generating cohorts out new big data systems. how is Lynx/elinks supposed to become compliant with this new proposal? how is anyone other than the already existing giants of the world supposed to do this?
bold bold bold plan organize & own all the worlds data here. privacy on the web, but none in the web browser: brave new world Google. you madmen.
Personal information will attempted to be scrubbed, but it very much is an upload of one's detailed web history to the cloud. Google alleges they wont know it's my tracks, but these federated learning systems are all powered by endless reams of data gathered from us.
That the decision of which cohort we are in can be done locally does not change the fact that that data has to come from somewhere, is gathered, en-mass, via huge bulk collections, of very specific, detailed data. It is only weasel words that it is called "not personal data"; our individuality is being harvested, tracked, modelled via these systems. That the information is free of personal identifiers does not make me feel much better about this all.
And it is something few other enterprises will ever have the capability to repeat or compete with. It mandates the web browser be powered by clouds & big data.
"The browser ensures that cohorts are well distributed, so that each represents thousands of people."
> how many cohorts can a person be part of?
It's just:
cohort = await document.interestCohort();
See https://github.com/WICG/floc(Disclosure: I work on ads at Google, speaking only for myself.)
"Additionally, a subset of low entropy variations are included in network requests sent to Google. The combined state of these variations is non-identifying, since it is based on a 13-bit low entropy value (see above). These are transmitted using the "X-Client-Data" HTTP header, which contains a list of active variations. On Android, this header may include a limited set of external server-side experiments, which may affect the Chrome installation. This header is used to evaluate the effect on Google servers - for example, a networking change may affect YouTube video load speed or an Omnibox ranking update may result in more helpful Google Search results." -- https://www.google.com/chrome/privacy/whitepaper.html
And my personal browsing habits are for me, that doesn't seem to stop Google from inventing new and imaginative ways to use them for ad targeting. The id is also long enough to be unique in a group of thousands, which is a size range in which the groups created by this new way of targeting ads apparently are.
Of course, there are reasons why they aren't such a good thing as I make them sound to be. And the fact that you don't feel in charge of them should rather emphasize, than negate my point: if such a simple thing turns out to be something you learn to hate, don't you ever dream of something more complicated and less transparent to be your salvation.
And ever since federated learning became "the next big thing" I was arguing here on HN (rather unsuccessfully, I feel) that this doesn't mean that there's suddenly "no tracking", buying into that is just naïve. I'm not directly commenting on FLoC API, both because I don't know it well and because it's usually about making a stronger point anyway: that performing learning client-side and then submitting some sort of "depersonalized data" means better privacy and essentially is having your cake and eating it too. But I think it's just misleading to describe things this way. The idea that "sensitive data" is your document id, your name/surname and such is hopelessly outdated. In fact, it's funny that anyone even believes that, because if you are not a complete bureaucrat, it should be clear that you are not your name or some other sort of ID number, you are your behaviour. It's just that people are used to the idea, that Big Brother needs that simple ID number to keep you in line. But perhaps he doesn't anymore.
What I'm saying is essentially that sending "depersonalized data" is just obfuscating which personal & sensitive data is actually exchanged. And (again, not in the context of FLoC API, but more generally) it can be any data: I think we all remember funny stories how completely impartial GPT-3 learns someone's phone number and such.
So, this, and all of what you already said about the monopolization of people-tracking market.
What’s difficult to conceive is how the currently bloated and monetization heavy internet could survive without advertising. An internet composed of relevant and useful information stored as light weight documents could easily (and used to) exist without advertising. Without ads we probably wouldn’t have millions of identical recipe sites with infuriating backstories, pop ups, share buttons, in-line promotions, etc. but we would still have people sharing their grandmother’s apple pie recipe on personal sites along with a few paid services that add real value instead of SEO garbage and social fluff.
The no-monetization web ship sailed circa 1995. The internet is about a lot of money and it will be about even more money. If it's not monetized through ads, it will be monetized in other ways (probably regular sales but most likely subscriptions).
It is difficult to conceive Google without advertising as its economic foudnation.
Google revenue cut is around 30%, not the other way around.
Any concrete traffic measurements between those sites then and now? I'd be extremely surprised if traffic didn't shoot up by orders of magnitude.
That's also assuming that no ads means we'd go back to the mid-90s internet. Pretty sure there are still companies that would like to do business online, even without targeted ads. The tactics would change, that's it.
> Without ads we probably wouldn’t have millions of identical recipe sites with infuriating backstories, pop ups, share buttons, in-line promotions, etc.
True for pop-ups, in-line promotions or ads. But SEO will be a thing as long as we have search engines. Hell, earlier search engines were getting gamed with keyword stacking all the damn time. Bringing you on the page and showing you ads wouldn't be enough to make money, but I don't see how you'd even get rid of sites wanting traffic. Unless you're really advocating for getting rid of commercially motivated sites - which I'll assume you're not, as it is kind of delusional, IMHO.
> we would still have people sharing their grandmother’s apple pie recipe on personal sites along with a few paid services that add real value instead of SEO garbage and social fluff
That's a whole lot of extrapolation, and a rather subjective judgement call. Hell, one could definitely call this very site "social fluff".
Key words:
Individual: They might still track persons by group, by placing people into pools of like-minded internet users and track the browsing trends of this group.
Browsing: Geographic location, sleep cycles, or media streaming/viewing preferences are still on the table.
Multiple: Tracking within one website is still a thing. YouTube habits are still a go.
Websites: Apps, and everything we do with them, are not "websites".
While I think this is a step in the right direction, I don't see this statement as very limiting. It only addresses a very narrow type of tracking.
I'm having a hard time parsing this out, and seeing what's actually changed. How do they determine an individual's "cohort(s)", without collecting information about that individual across multiple websites?
Is it simply that the data is collected and processed client-side, rather than server-side? Would using a non-Chrome browser effectively opt-out altogether, then? I find this difficult to believe.
Some sort of principal component analysis to determine your "cohort".
An advertiser isn't that interested that you are you. They care that you are, for example, 55 with an interest in gardening and have been looking at lawnmower review sites.
Edit: Actually, come to think about it, I wonder how people would have felt in the 80's if they got one of several editions of a newspaper based on magazines that they also subscribed to. Households that subscribed to fitness magazines would get a newspaper with more gym membership and weightlifting gear ads, and households that received woodworking magazines would have more Craftsman ads in their newspaper. Would people appreciate the customization of the paper, or would they see it as an invasion of privacy?
The WSJ seems to be describing https://github.com/WICG/floc, but the kind of remarketing you're describing is what https://github.com/WICG/turtledove is intended to support. Advertisers would still be able to run that kind of personalized ad, but the browser API would not allow them to learn your browsing history in the process.
(Disclosure: I work on ads and Google, speaking only for myself)
[1] https://www.cookiebot.com/en/google-third-party-cookies/
Edit: I did not have time to read it, but here is the paper and probably something like the algorithm they want to use: https://github.com/google/ads-privacy/blob/master/proposals/...
The bit you're quoting sounds like the WSJ trying to describe https://github.com/WICG/floc. That depends on the browser choosing to support the API, yes.
(Disclosure: I work on ads at Google, speaking only for myself)
For example, if they aren't collecting information on you than how do they have enough information to create cohorts? Is it that they are deeming information processed on your local computer running their software something that isn't them collecting? This seems like a form of misdirection.
Without knowing the technical details (which one never knows with Google), it leave me the impression that they have moved some of their categorization software client side (Chrome, web workers, etc) and are saying that they aren't collecting the data in that case.
Is it Google using remote devices as edge devices to do a bunch of work they'd been doing server side?
1) we can sell all our ads for just as much money anyway, even without targeting based on web browsing, because the advertisers will take what we let them get
2) targeting based on browsing history is more complicated, requiring more developers and server capacity, which Google could certainly afford but it has plenty of other things to do that pay off better
3) it turns out that advertising based on what website you are currently on, works just as well anyway; to put it another way, all that "show a person who just bought a car an ad for another car" targeting was not really working.
"We respect privacy" sounds better than "our targeting accomplished almost nothing and you'll buy the ads anyway."
Boy that sure is true for me and has been for a long time. I'm often bewildered not by how accurate my ads are, but rather by how braindead they seem to be. I'm not convinced algorithm-based ads work at all.
In fact I would hypothesize that ads are often more effective when they are unexpected, for something the viewer has never considered buying before. A targeted system would hide such ads.
You are underestimating the big picture, which is - google is really left between apple and regulations (gdpr, ccpa etc) pushing privacy front and google have no choice but to go in this area.
Yes, but it may be that they've decided there's no dollar here. Or, to put it another way, they get that dollar whether they track your browser history or not, so why bother? It's more like cutting corners, which corporations are most certainly willing to do, but in this case we like it (but that is probably only incidentally of interest to top executives).
So I'm super disappointed that I will not be getting such ads from Google. In fact, it annoys the hell out of me that people who are concerned about privacy created such a strong anti-ad-personalization movement. This harms people like me who prioritize getting valuable information over privacy. I think people should be allowed to enable their own privacy settings, but activists and politicians should not force their ideology on the society to such an extent as to scare corporations away from personalization.
Though to be fair, I don't recall a single useful ad from Google in my life. So maybe I overestimate the damage the privacy advocates are causing.
If you believe this, maybe you would like to buy a bridge?
- It also doesn't seem too unlikely, given more and more talk of the possibility that "targeted" ads don't actually work that much better than non-targeted ones, and Google are in the best position to verify that. Switching to ad models that are not based on exact user tracking, as long as they have the monopoly position might be the best way to ensure future profitability before they lose their users due to privacy concerns. All the AI and other technical and other monoplistic (AMP, Maps, etc.) advantages might be good enough to beat any tracking-based competitiors.
They don't and here is why --- if you search but don't purchase through a Google ad, you're likely to still see ads for the item following you all across the internet for months after you made a purchase elsewhere.
This does nothing but annoy the user.
[1] https://www.statista.com/statistics/266471/distribution-of-g...
-site:highrankingspamsite1.com -site:highrankingspamsite2.com etc
And then I would paste that in at the end of each query.
Today they've removed that kind of spam so I don't need that.
Today my problem is that they fuzz my queries to include useless results. Not a spam problem rather than a problem of Google not realizing that I only want relevant results.
But of course, removing results that doesn't contain what I search for is easy and not an interesting machine learning problem so why should anyone care to fix that?
(That said: lately things have improved, so maybe I should just shut up and hope nobody at Google notices and puts back the insane fuzzing.)
As for including "useless" results - that's never a goal, the goal is always to rank the results in the best possible way. What's the best possible way varies depending on the user, and relatively large term expansion is useful for certain users in certain cases.
Lucky you if that consequently works for you. It is getting better lately, but from 2009 to 2019 they've more or less consequently ignored both dpuble quotes and their own verbatim option.
BTW: the way you write make it sound like you work in search. Is that correct?
Try looking for images and see how many results in the first "pages" are not from Pinterest.
Free search incentivizes the cheapest (in CPU and other resource terms) search possible and monetizing in ways that add the least actual value.
Settings > Search Engines > Manage Search Engines > Add
Then input:
- Search Engine: Google Images
- Keyword: i
- URL: https://www.google.com/search?tbm=isch&q=%s%20-site:pinteres...
Then typing i<space> in the url bar will use that search engine. I've got about 30 of these for various sites and they're a great time saver! (Chicago Craigslist, Google Maps Directions to <place>, DuckDuckGo I'm Feeling Lucky, Wikipedia search, etc.)
It seems to me that this is actually giving them more reach, as now it wont just be websites using google analytics, etc - but EVERY website you visit, unless the site owner specifically opts out - a google-made blackbox that sees EVERY site you visit and labels you accordingly
Few questions for the knowledgeable:
- Is it be possible to disable?
- Will they be releasing the datasets for how these ML models are constructed?
- Do sites in "incogito mode" contribute to analysis?> Is it be possible to disable?
"A site should be able to declare that it does not want to be included in the user's list of sites for cohort calculation. This can be accomplished via a new interest-cohort permissions policy." For a per-user opt out, a browser extension could easily block it.
> Will they be releasing the datasets for how these ML models are constructed?
"The browser uses machine learning algorithms to develop a cohort based on the sites that an individual visits. The algorithms might be based on the URLs of the visited sites, on the content of those pages, or other factors. The central idea is that these input features to the algorithm, including the web history, are kept local on the browser and are not uploaded elsewhere — the browser only exposes the generated cohort."
This code will be in the browser, which is open source.
> Do sites in "incogito mode" contribute to analysis?
"All sites with publicly routable IP addresses that the user visits when not in incognito mode will be included in the POC cohort calculation."
(Disclosure: I work on ads at Google, speaking only for myself)
> Is it be possible to disable?
No. You suggest this is possible with an extension, but it clearly wouldn't be permitted in chrome store (as per well known ad-blockers). Why wouldn't it be a setting in the browser? Clearly anti-user practices.
> Will they be releasing the datasets for how these ML models are constructed?
No. You suggest that the code is in the browser (which i doubt - its certainly not at the moment!). Even if it were it is effectively useless without the training datasets. i.e. its a blackbox.
> Do sites in "incogito mode" contribute to analysis?
No (at least this one is a positive "No") :)
Why wouldn't it be permitted? Many ad blockers [1][2][3] are in the Chrome store. Disabling a browser feature is a very standard usage of extensions.
> Why wouldn't it be a setting in the browser?
It might be! I don't know what Chrome (or other browsers that choose to implement the API) will decide. The proposal is not that far along yet. You could consider filing an issue at https://github.com/WICG/floc/issues
> You suggest that the code is in the browser (which i doubt - its certainly not at the moment!)
https://github.com/chromium/chromium/tree/master/chrome/brow...
[1] https://chrome.google.com/webstore/detail/ublock-origin/cjpa... [2] https://chrome.google.com/webstore/detail/adblock-plus-free-... [3] https://chrome.google.com/webstore/detail/ghostery-%E2%80%93...
That code you linked to collects hashes and sends them to google via chrome sync... There is nothing there that labels cohorts
Otherwise like many others this makes me think that Google is still doing something fishy here and I don't trust it.
Edit: For anyone curious what I am talking about https://webkit.org/blog/8943/privacy-preserving-ad-click-att...
It is in Google's best interest that whatever system they use works regardless of browser.
Largely I agree but Google's relationship with Mozilla and Apple is a little more complicated than "arch-rivals".
They'll categorize websites (as they already do) and put you into that category, but forego tracking exactly which website/page put you there. The specific page is probably more granularity and privacy invading than they need to continue printing money. Think Netflix movie categorization; who cares which movie I watched put me into the Norwegian-Horror-Romance-Action category, as long as my preferences are known, targeting will continue working.
While it's great for debugging how someone got into a bucket, all that's really needed is the bucket, not the raindrop. I'm certain they'd like to continue knowing those buckets though, so getting ahead of that is critical to their business.
What works for me is, I buy "Mopar Action" magazine for the ads. Back in the day I bought computer mags for the ads. And so on. Those ads were targeted at what I was actually interested in at the moment.
For another example, recently I've become interested in Film Noir movies. I go looking for them, and I get ads based on my interests last month. No sale. I look at Film Noir websites, and I want to see Film Noir movie ads, not movies I was interested in months ago. If I look at a woodworking web page, I want to see ads for woodworking tools.
On my own web pages on programming, I wish Google and Amazon would run ads based on the page content. Amazon has a way to suggest that, and I tried it out. All it would serve for weeks was Batman movie ads. Why would anyone looking at a programming page want to see Batman movie ads? I finally just disabled the Amazon ads. It's similar with Google ads.
Note that serving relevant ads in this manner has absolutely no requirement to know my browsing history.
P.S. I actually still run Amazon ads on my programming pages. However, I don't let Amazon pick the product anymore. I pick it myself, and my page generation program picks one of those products for each page. The products I pick are from a self-curated list of the best programming books available.
The EFF calls FLoC "bad for privacy". More information here:
https://www.eff.org/deeplinks/2019/08/dont-play-googles-priv...
It seems the right time for Google to pivot, if not a little too late.
I have no objection to targeted ads.
I have a multitude of objections to systematic privacy invasion for profit.
If they can somehow target ads while preserving my privacy, I'm all for it.
How is that not a big improvement in privacy for ad targeting vs the current system?
Also, this solution does nothing to prevent the abuses of the resulting user clustering that we’ve already seen (such as targeting addictive pharmaceuticals to addicts, or youtube promoting conspiracy theories).
The article says they plan to embed the data collection into the operating system as well as web browser, so people on Android will have even more of their privacy stripped away for ad targeting.
Yup, deanonymization is a problem.
That's better than no anonymization now.
But I agree, it's not perfect, and frankly, I don't think there is a perfect solution that prevents bad actors from deanonymizing users.
The real solution to this issue is regulation and transparency.
> Also, this solution does nothing to prevent the abuses of the resulting user clustering that we’ve already seen (such as targeting addictive pharmaceuticals to addicts, or youtube promoting conspiracy theories).
This has nothing to do with the privacy implications of this technology.
Personally, I think you (and the entire advertising industry) are massively overestimating the effectiveness of targeted advertising, but... shrug
> The article says they plan to embed the data collection into the operating system as well as web browser, so people on Android will have even more of their privacy stripped away for ad targeting.
They already do this!
Again, this is still objectively an improvement.
Does it fall short of eliminating targeted advertising entirely?
Yes.
Personally, I'm a realist and recognize that ain't happening, so we should welcome any movements that make the industry a little less invasive and destructive.
As for PG's tweet, I think it's a bit much to call that single sentence an "analysis". At best it's an opinion, and not a very nuanced one at that.
Please explain how this isn't potentially an objective improvement of end user privacy over things like third party cookies, browser fingerprinting, or other mechanisms of identity tracking.
I answered your other questions in a sibling comment.
Either it's a more privacy-preserving method than current techniques and technologies or it's not, irrespective of the competitive landscape of the ad tech industry.
I think it's objectively the case that this is certainly better than assigning unique identifiers to every user and tracking those IDs + associated segmentation in third party databases that are ripe for abuse.
Is it perfect? No. But I didn't realize we were just gonna go full nirvana fallacy, here. If that's your bar, nothing short of eliminating targeted advertising entirely will satisfy you, in which case, frankly, you're being unrealistic.
Or web browsing patterns turned out to be low-signal for ad delivery.
The very first sentence:
It’s difficult to conceive of the internet we know today
—with information on every topic, in every language, at
the fingertips of billions of people — without advertising
as its economic foundation.
He literally describes Wikipedia, which is not based on advertising as its economic foundation.Immediately after that, he says:
72% of people feel that almost all of what they do online is being
tracked by advertisers, technology firms or other companies, and 81%
say that the potential risks they face because of data collection
outweigh the benefits
If that's true, then we are already far past the point where everyone just expects intrusive spying to be a normal part of web use. If that feeling were going to disrupt the advertising business, then it would already have done so. Therefore, his next comment is categorically false (though I wish it were true): If digital advertising doesn't evolve to address the growing
concerns people have about their privacy and how their
personal identity is being used, we risk the future of
the free and open web.
I think another comment here by user samschooler nails it - Google wants to block intrusions by its competitors under the guise of protecting privacy, while opening up new doors to tracking that only it can take advantage of.The right way to respect user privacy in advertising is much simpler: just use what they voluntarily gave you (i.e., the words in their search terms) to present relevant advertisements. That may not provide as great of a "benefit of relevant advertising", as he puts it, but that's fine with me.
> investing in tracking technologies that uniquely identify web users as they move from site to site across the internet.
Fundamentally they are still tracking people and still using your information to sell you advertising. They are just relying on hardware you buy and your own software to do it.
One thing I've been curious about this whole time as they've been talking up "FLOC" is what they are doing with regards to other browsers. Are they simply giving up on the ability to track non Chrome users and rely on market share?
The other piece this doesn't mention is it very specifically says "Web Browsing", not tracking in general, for example across applications on mobile devices or via integration into Android.
You can target ads based on the content of the webpage they are displayed on instead of constantly spying on everyone.
How about we go back to that?
The first principles are exceedingly simple:
What I want: for small, insurgent, creative businesses who want to specifically get my attention to be able to do that through inexpensive, surgical messaging rather than mass advertising.
What I don't want: for middlemen (or anyone) to facilitate this using information I didn't intend to make public and can't verifiably stop my browser (and other tech) from shedding.
However, my reading of this is that they’ve given up on embedding trackers in websites, and instead will embed trackers at the operating system level, where they can gather even more information.
The stuff about cohorts describes standard clustering algorithms that have been used for ad targeting for decades.
This doesn’t sound like a win for privacy. It sounds like greenwashing of a massively expanded surveillance infrastructure.
> Google’s heft means that its move is also likely to stoke a backlash from some competitors in the digital ad business, where many companies rely on tracking individuals to target their ads, measure their effectiveness and stop fraud.
Isn't this just an opportunity for these guys to differentiate themselves from the 900 lb gorilla? And if that tracking really leads to ads with higher conversion rates then those competitors will do better than Google (until, if those ads really are better, the latter reverses its decision).
BTW this is not in any way a defense of intrusive tracking, which I consider both a tragedy and a significant waste of money. My intuition is that this tracking adds little to no benefit. I suspect we're still in the at least "50% of advertising spend is wasted"* world; more like 70%-80%. This is another nut to be cracked, and one unlikely to be addressed by any incumbent.
* Attributed to John Wanamaker (among others, though I feel he is the most likely source)
Disclaimer: I work at Neeva[1], and these opinions are my own.
"That’s why last year Chrome announced its intent to remove support for third-party cookies," aka only Google's cookies are "safe". Sounds like Google is going to try and block it's competitors from being able to gain the information Google uses to make money (tracking information for ad revenue.)
Also this was written like someone needed to fill in the article for a C-Level headline after the headline was already chosen. Disappointing that a company like this maintains it's stranglehold on a market and tool (now commodity) that regular people have no understanding of.
If you are on a site, first-party cookies are cookies for that site and third-party cookies are cookies for any other site. It is "third-party" from the perspective of the site, not the perspective of the browser.
(Disclosure: I work for Google, speaking only for myself)
Looks like Google can still target users who are signed in. From this article: https://www.businessinsider.com/google-to-stop-tracking-indi...
2) Google already has plenty of 1st-party data from search, gmail, maps, news, etc which is more than enough to sustain the same targeting abilities.
Meanwhile if I search for a coffin even once Amazon keeps recommending more to me. Way to go ya boffins.
@People working in the ad/tracking racket: Please, instead of trying to guess who I am or what I like, why not just let me TELL you?
Let me provide some criteria (“pixel art”, “chiptune music”) and feed you some examples (Fez, MegaMan) and try to show me similar games. Then I might actually spend some money because of an ad for once.
Or they've but up such a massive database of individual behavior that they can now generalize that to targeted groups instead of individuals.
The article also just says they won't sell ads or invest in that technology, not that they won't still track and use the data in some other ways. They've probably invested plenty already to not need to push it further.
No, personalized advertising is the key to Google's ad success.
The main reason Google is doing this is to cement their ad monopoly. They have all the data now, when they turn off 3rd party cookies, no one will be able to compete with them.
Is this really the main culprit? I get the impression that a lot of the tracking work has to do with server side data gathering based on ip addresses, matching web sites, shared login data, embedded pixels and probably all sorts of other clues. I would love to be wrong about this.
If I am correct then "blocking third-party cookies" is mainly a feel-good marketing ploy.
https://en.wikipedia.org/wiki/Regulatory_capture
While Google can now expect inevitable regulation, shaping that regulation in their interest will still benefit them by excluding new competitors (for example, by forming it so that execution depends heavily on trade secret and/or patented algorithms).
Everything you type into your Android search bar is part of your Google profile of you.
Technically more challenging of course.
Not looking forward to those discussions in the future.
Yeah, well. Not holding my breath on this one :)
I agree with others, they've found another way to track us
Similarly, for Web Bluetooth: "This API provides access to the Generic Attribute Profile (GATT) of Bluetooth, which is not the lowest level of access that the specifications allow, but its generic nature makes it impossible to clearly evaluate. Like WebUSB there is significant uncertainty regarding how well prepared devices are to receive requests from arbitrary sites. The generic nature of the API means that this risk is difficult to manage. The Web Bluetooth CG has opted to only rely on user consent, which we believe is not sufficient protection. This proposal also uses a blocklist, which will require constant and active maintenance so that vulnerable devices aren't exploited. This model is unsustainable and presents a significant risk to users and their devices."
My read of the disagreement is it it's about a core design trade-off: how important is it that a browser can do anything that an app can do? I think it's very important (https://www.jefftk.com/p/we-need-browsers-as-platforms) and I'm frustrated that Mozilla no longer does.
(Disclosure: I work at Google, speaking only for myself)
The better statement would be "security and privacy".
> I think it's very important (https://www.jefftk.com/p/we-need-browsers-as-platforms) and I'm frustrated that Mozilla no longer does.
I'm frustrated Google brushes aside any security and privacy concerns and just charges ahead and unleashes them onto the world. Mozilla may still think that browser-as-a-platform is important. However, they are clearly not willing to sacrifice security and privacy of users to achieve that goal.
The only reason is that Google wants to own the web stack (see Ars Technica article I'm alluding to: [1]), and no objections to what they propose, and do, will stop them. Honestly, I'm surprised they still ask other browser vendors for their positions (see, e.g. [2]), as they clearly couldn't care less.
[1] https://arstechnica.com/tech-policy/2011/09/owning-the-stack...
[2] https://github.com/mozilla/standards-positions/issues/336
- Apple has been removing many PWA apps from their App Store.
- For Google login and Play Store, Google often has new requirements, like adding more info about privacy to PWA website without replying to questions about more details with robot like answers.
Because of those increasingly more strict requirements and always changing APIs, it seems that in future web is the platform, and not mobile apps.
If google analytics, recaptcha, tag manager,... are going to the graveyard or they becomes payable, there is something to it. If it stays, the google statement is a blatant lie.
https://www.axios.com/google-goodbye-individual-user-trackin...
Google plans to stop selling ads based on individuals’ browsing across multiple websites, a change that could hasten upheaval in the digital advertising industry.
The Alphabet Inc. company said Wednesday that it plans next year to stop using or investing in tracking technologies that uniquely identify web users as they move from site to site across the internet.
The decision, coming from the world’s biggest digital-advertising company, could help push the industry away from the use of such individualized tracking, which has come under increasing criticism from privacy advocates and faces scrutiny from regulators. Google’s heft means that its move is also likely to stoke a backlash from some competitors in the digital ad business, where many companies rely on tracking individuals to target their ads, measure their effectiveness and stop fraud. Google accounted for 52% of last year’s global digital ad spending of $292 billion, according to Jounce Media, a digital-ad consultancy. “If digital advertising doesn’t evolve to address the growing concerns people have about their privacy and how their personal identity is being used, we risk the future of the free and open web,” David Temkin, the Google product manager leading the change, said in a blog post Wednesday. Google had already announced last year that it would remove the most widely used such tracking technology, called third-party cookies, in 2022. But now the company is saying it won’t build alternative tracking technologies, or use those being developed by other entities, to replace third-party cookies for its own ad-buying tools. Instead, Google says its ad-buying tools will use new technologies it has been developing with others in what it calls a “privacy sandbox” to target ads without collecting information about individuals from multiple websites. One such technology analyzes users’ browsing habits on their own devices, and allows advertisers to target aggregated groups of users with similar interests, or “cohorts,” rather than individual users. Google said in January that it plans to begin open testing of buying using that technology in the second quarter. Google’s abandonment of individualized tracking across multiple sites has the potential to reshape the industry, given the market power of its ad-buying tools. About 40% of the money that flows from advertisers to publishers on the open internet—meaning the part of digital advertising outside of closed systems such as Google Search, YouTube or Facebook —goes through Google’s ad-buying tools, according to Jounce. Google says its announcement on Wednesday doesn’t cover its ad tools and unique identifiers for mobile apps, just for websites. But its plan is the latest sign that the tide might be turning on user tracking more broadly. Related Video How Apple and Google Formed One of Tech’s Most Powerful Partnerships Skip Ad in 15 You may also like Created with sketchtool. Up NextCreated with sketchtool. Your browser does not support HTML5 video. Created with sketchtool. Created with sketchtool. 0:00 / 8:03Created with sketchtool.Created with sketchtool. 0:00 How Apple and Google Formed One of Tech’s Most Powerful Partnerships Apple and Google have one of Silicon Valley’s most famous rivalries, but behind the scenes they maintain a deal worth $8 billion to $12 billion a year according to a U.S. Department of Justice lawsuit. Here’s how they came to depend on each other. Photo illustration: Jaden Urbi Apple Inc. is pursuing its own plans to limit tracking of app usage by requiring developers to get opt-in permission from users before collecting an advertising identifier for iPhones. At the same time, European Union privacy regulators have fielded multiple complaints about the information that websites share with third parties about what content users are viewing as part of such tracking. One set of complaints comes from Brave Software Inc., maker of a privacy-focused web browser, where Google’s Mr. Temkin was chief product officer until last summer. Google says Mr. Temkin’s involvement in its plan demonstrates its commitment to user privacy. Brave didn’t immediately respond to a request for comment. Google’s changes come as big tech companies face multiple antitrust investigations. Smaller digital-ad companies that use cross-site tracking have accused Apple and Google of using privacy as a pretext for changes that hurt competitors. And Facebook Inc. Chief Executive Mark Zuckerberg in January said in an earnings call that “Apple has every incentive to use their dominant platform position to interfere with how our apps and other apps work.” In the U.K., the Competition and Markets Authority, the country’s top antitrust regulator, last month opened a formal probe into Google’s phasing out of third-party cookies from its Chrome browser. The probe stemmed from a complaint from a group of marketers that argued Google’s plan would cement the company’s heft in the online advertising space. A Google spokesman said the company has been briefing the U.K.’s CMA on its plan to end its own use of unique tracking across multiple websites. Google’s announcement complicates advertising-industry efforts to come up with an alternative, more privacy-friendly technology for targeting individual consumers, such as the one being led by the Partnership for Responsible Addressable Media, a group of advertisers and advertising technology companies, that would rely on new identifiers, like strings of numbers and letters derived from users’ email addresses. Without mentioning the partnership’s effort directly, Mr. Temkin referred to identifiers “based on people’s email addresses” as examples of tools Google won’t use. Google acknowledged that other companies may push ahead with other ways to track users. Companies that use parts of Google’s advertising infrastructure, such as its ad exchange, could potentially still sell ads that use their own unique identifiers, Google said. But the company said it won’t use or invest in such tools for ads it sells. “We realize this means other providers may offer a level of user identity for ad tracking across the web that we will not,” Mr. Temkin wrote in the blog post. “We don’t believe these solutions will meet rising consumer expectations for privacy, nor will they stand up to rapidly evolving regulatory restrictions.” There are exceptions to Google’s plan. The company’s limit on unique tracking identifiers doesn’t extend to so-called first-party data—information a company gets directly from a customer. For instance, websites will be able to sell ads based on users’ activity only on that specific site. It also means Google will continue to allow advertisers to aim ads on Google services like YouTube at specific clients for whom they already have contact information. But when the changes go into effect, Google will stop targeting such ads at those people when they are browsing other websites. Nestlé SA, a large advertiser that Google had briefed on the changes, said it welcomed the initiative on privacy grounds. “We have long since recognized and advocated for the importance of first-party data, and it’ll become even more vital in a privacy-first world,” said Aude Gandon, Nestle’s global chief marketing officer. Write to Sam Schechner at sam.schechner@wsj.com and Keach Hagey at keach.hagey@wsj.com
Google is scrapping information from you from your phone, your browser, your emails, your searches. They track you at scale. They track millions of people at scale! Using all that data + data mining + their AI capabilities + psychologists, they are able to generate incredibly detailed models of each individual. Their models will have predictive power. And that is what their whole business is about - how to best monetise you for their customers and shareholders. (Of course Apple, Facebook, Amazon etc are trying to do the same.)
So, think about it, they have all this information, and will continue to collect it, but won't give you an indication on what they are collecting - why would they do that? Its because we are reaching a data equivalent of the uncanny valley - where google (et al) know you better than you know yourself, but don't want you to know that!
Its a fight for attention! I often do long comments, but sometimes I'm try to get things down to a concise yet witty nugget ;)
So, of course it makes sense that they would like the people whose privacy they are eroding to be in the dark about how much they know about them! Cos then they won't even know to protest! People are already forgetful, if the information is hidden too, in the dark Google et al will have free reign to do what they like.
> David Temkin, the Google product manager leading the change, said in a blog post Wednesday.
Hey David, if you're on here, how many millions did Google give you to switch?
Oh, turns out you're in a cohort of 1. Privacy sandboxed.
Would Google do something that causes them to make a lot less money? Likely not.
I wonder if Google is treating our computers as edge nodes running their software (i.e. chrome, js workers, etc). Because it's tracking us on our computers they don't consider it Google tracking us. Then they phone home with calculated cohorts and cohorts are always changing. It's still tracking us but in a different way.
I’ll take context/search relevant ads on google and Adsense every day.
From 2006 until about last summer Google only served me useless ads.
Facebook on the other hand managed to pick a number of ads that were in fact interesting. I have bought through them a couple of times which is quite amazing given that I think I easily spend 100 times more on Google properties or web properties with Google ads.
Open source audits of manipulative algorithms. It's really that simple.
That's quite the oxymoron of a title.
Regarding the article, it seems like Google is just doing the bare minimum to keep up with the rest of the industry when it comes to privacy. Every step they make comes shortly after others in the market have already taken a similar step[0]. Google is on top and they want to keep it that way. And they know they can so long as they keep pace just enough so as not to anger their users enough for them to switch away from the Google platforms they're comfortable with.
[0] https://blog.mozilla.org/blog/2021/02/23/latest-firefox-rele...
> Today, we’re making explicit that once third-party cookies are phased out, we will not build alternate identifiers to track individuals as they browse across the web, nor will we use them in our products.
Google is in a position where they don't need to track individuals across the web. Most people have become dependent on Google's products and services. Even third-party websites are often dependent on Google services which feed them data in one form or another (Google Analytics, Google Sign-In, ReCaptcha, Google Cloud, etc). If anything, this move is beneficial to Google because they only have to make a small sacrifice to handicap their competition.
Not necessarily true if you've seen how much Google bends over backwards to protect privacy inside the company. Data is a liability, after all.