Per the linked article, the browser is filling in the blanks "___N_" as you visit each website, but it's telling each website not _what_ site you visited, but that you are in the groups of "FAA_G" vs. "FAANG".
The browser manufacturer is effectively seeing every user for what they are (all the letters of the alphabet, as it were), and each site is only seeing a hash/digest/cohort/group, but those group segregations are not coming from particular "networks of websites", but instead from the browser itself.
The end result is that you can't trust the browser b/c it might be (ed: it is!) spying on you.
Google started removing the URL bar and replacing it with the omni-box. Instead of https://google.com/ => ?q=guitar, you would simply type "guitar" into the URL bar.
The lesson here is to reduce the number of intermediaries between you and your customer. Own the hardware, the screen, the operating system, the network, _everything_ between your CPU's and the user's eyeballs. (or in amazon's case, the manufacturer, the boxes, the website, the shipper, the TV, etc.). (or in netflix's case, the content, the edge-cache storage tank, the TV, the remote control, the pixels, etc.)
You only ever belong to a single FloC. So let's for a second assume the non-adversarial use case. The advertiser isn't using any additional tools to track you. Then the only thing the advertiser has is your FloC. This doesn't identify you individually, but it might correlate with various interests.
If your FloC changes, which it will periodically, the advertiser doesn't have any history, so the correlation changes and you're given different ads.
Now let's assume that they have some additional information, like an IP address. Then they can say ah you had this FloC on this date, and this different FloC later. Its not more identifying (they already have your IP, which we assume is identifying enough). The FloC might let them infer things about your interests on other sites, so they have precise information on your browsing interests on this site, but only partial information on other sites.
As opposed to today, where 3rd party trackers mean they have full information on the other sites too.
a) every site you visit loads some Google/Facebook/whatever JavaScript to track you. That are not all sites.
b) you didn't disable these scripts with extensions like UBlock (that to me is essentials these days) or use a browser that value your privacy (like Firefox) that blocks them by default.
This system not only is deeply integrated in the browser and thus impossible to block with extensions (without modifying the source code of the browser, that in case of a proprietary browser like Google Chrome you can't), but also track all your browsing history, meaning that they catch even sites that doesn't include Google trackers inside.
Another bad thing about this system is that is integrated inside the browser, meaning that for a closed source browser like Chrome only Google knows how it works and what exactly it does. While classical tracker scripts that uses third party cookies are implemented in JavaScript, minified and obfuscated, but still you can in theory read the source code and understand what they do.
This is far worse for privacy than how things are now!
Right, but it is, to a first approximation, all of the sites that are going to be showing you personalized ads.
> Another bad thing about this system is that is integrated inside the browser, meaning that for a closed source browser like Chrome only Google knows how it works and what exactly it does. While classical tracker scripts that uses third party cookies are implemented in JavaScript, minified and obfuscated, but still you can in theory read the source code and understand what they do.
I'm not quite sure what you're getting at here. The setting and reading of a cookie by a client, yes, will be written in JS. That doesn't mean that you can know what its doing (there are likely cookies on your system that contain encrypted payloads that you can't read). The system that "actually" reads those cookies is hidden behind an API, so you don't have access to even the binary code.
From that perspective, FloC is no worse, and is usually better, as the payload itself is generated and managed on your machine.
Tangentially, FloC is similar to but probably more privacy preserving than the way Brave Browser does advertising today, and that was heralded by many on HN as a huge privacy improvement.
afaik you cannot disable floc with an addon and you do not have any control over the floc id is assigned to you.. the floc id is calculated once a week based on the sites you visit on the previous 1 week.. so it leak information of what sites you have being visiting if anyone is able to reverse the sites that generated that floc id even if the site does not have adds or social media button on then or you use add blockers..
and i bet all the major tracking players will have farms calculating all possible floc ids from all the popular sites..
maybe do an addon that load randon stuff from randon domains in the background to taint the floc id so it makes harder to reverse the actual sites you are visiting.. or just use an browser that does not have it..
but beside floc, browser fingerprinting already allow tracker to identify people almost uniquely even without using cookies, there is already work on how to fingerprint someone without using either cookies or client side scripts, just by analyzing the timing when accessing several random subdomains using hundreds of redirects..
floc is just one more info they will have on you with no added benefit..
I wonder how this feature even passed an internal Google privacy sniff test...
A company can already fingerprint you with 100% certainty with a third party cookie. The idea is to replace those with FLoC. It's at worst a lateral move, and usually an improvement.
Wait, I thought the whole point was that third parties could define what a "cohort" is, and the browser would handle determining whether or not you belong in them?
and it will include all sites from the last week, whatever you used adblocker to prevent tracking or if the site did not had any social media buttons that would allow then to track you there in the first place..
Better to avoid that fire and just let the reader infer FLoC is bad, whatever it is.
That wasn't hard.
If it was complemented with a Privacy Budget API– each privacy-losing API call costs budget and there is a limit– to eliminate other factors for fingerprinting and IDing that you can combine with FLoC to unique track people– thus giving advertisers complete browsing history– then I'd reconsider.
Another thing is webmasters can opt-out of FLoC through a header. But many webmasters don't control headers...
And on top of the practical consequences of its implementation.... not good.
There doesn't seem to be space for dialog or a common standard here, either Google does it or they fail and Firefox and privacy wins the world!
If I browse stackoverflow I'm probably looking for some saas, or tech related, or a react training course on a react question. If I browse game sites maybe I want a MMORPG promo or time card sale.
I don't want to see an ad to buy more toilets after having purchased a toilet once a month ago that is supposed to last decades. On every single site. For the next year.
> That wasn't hard.
It also doesn't explain why that's worse than the current practice of directly identifying individuals. Which is the hard bit.
they will still be able to identify you individually.. floc actually might make it easier by first assigning you to group of just a few thousands other people.. that mean they just need a few extra bits of fingerprinting to identify you uniquely from there..
also previously they could only track were you had being if there was an ad in that page or if it had a social media button basically they could store a cookie or run a script in a specific context of a specific site and now they knew you visited that site..
now with floc they can track you everywhere, even sites that do not have ads or buttons will be included when calculating your floc..