Cohort IDs can be collected over time to create cross-site tracking IDs
github.com
github.com
I did a lot of work on privacy coins, and the power of statistics is staggering. Doesn't matter if you shield yourself by grouping with 100,000 people per transaction, if your anonymity set isn't _everyone_, eventually you can be singly identified.
Same goes for browsers, tracking, and "anonymized data".
What is the point of a transaction you can't eventually confirm whether it happened or not?
Monero may utilize a heaping helping of obfuscatory steps, but those steps need to be consistent, and reversible. Otherwise, you have no guarantee that someone well placed hasn't modified the record in all the right places. Nation state's sole reason for existence is to implement solutions to these kinds of hard-to-reverse problems by sponsoring tooling and regulation to ensure that knowledge graph can be traversed. Either through mandatory reporting of the requisite metadata by exchanges that handle those transactions en-masse and who make money off it as a pre-condition of doing business, or by banning systems and instituting penalties for being discovered to use such an unreversible system.
This is the part that blockchain people don't get. If you have a public ledger, it's a matter of time until LE and regulators figure out how to legally constrain you. You may have a chunk of time when you can get away with untraceable transactions, but measures will eventually be implemented that will practically break anonymity for a lawfully operated business if you keep any sort of bifurcated record.
Then there's the final measure of making it impossible to legally reenter the fiat market from these types of assets as well. Successful money laundering is already fairly difficult. Without a way to feasibly re-enter, it becomes that much harder.
While in theory you could have two monetary instruments that fuel disjoint economic systems, there still has to be a cross-over point, and you can bet that that will be the point of maximum scrutiny.
Not saying it's impossible to make work, but don't expect everyone else to make it easy for you. The glacier may not move quickly, but it does in fact, move.
> The researchers generalized their Netflix work to find isomorphisms between arbitrary graphs (such as social networks stripped of any and all data except for the graph structure), for example Flickr and Twitter , and give many examples of public datasets that could be de-anonymized—such as your Amazon purchases (Calandrino et al 2011 ; blog).
Example:
1. male?
2. East of the Mississippi?
Etc etc.
FWIW, it has only been getting better for me
Both at home and work, Firefox desktop (with uBlock Origin) has been a pretty frictionless tool in terms of my browsing experience these past years, across Linux, Windows, and Mac machines.
Which is not to say it's not useful, and TIL - I didn't know they had released this, so thanks :) But I don't think it particularly applies to this thread.
Anything I need to know?
Then they released a preview of a re-design which also broke all extensions. That's arguably fine for a preview, though a bit concerning. Many were raising alarms at this point.
Then they released the re-design to the stable release, with still-broken extensions. This pretty unambiguously is "a mess", if not earlier.
Then they released built-in support for a couple dozen Mozilla-selected extensions (uBO included, I believe). This is still a mess, and rightfully raises a few eyebrows.
... and we're still there now, after over a year of "this will be fixed soon". I believe you can install nightly + manually tweak config and still install other extensions, but Firefox for Android does not support extensions right now. That's A Problem™, and not a good sign for extension-longevity that it was ever allowed out of preview. It broadly implies extensions are very low on their priority list, which is concerning, as extensions have been the clear leaders on preserving privacy and user control in general. Browsers overwhelmingly follow popular extension behaviors, not the other way around - cripple extensions and you also cripple advancement and experimentation.
No access to extensions and blocking about:config was to me just heretic. Those two are the raison d'être of Firefox.
Nightly build thankfully reverted this babysitting of users but indeed we are still stuck with 'vetted' add-ons downgrade in the official Firefox release for Android.
Also lots of other little papercuts: https://news.ycombinator.com/item?id=26470454
As I don't like getting bug reports that boil down to "doesn't work", I don't create them myself.
You may get a helpful reply from someone on the team with suggestions on how to troubleshoot it, like enabling specific logging flags or pulling some info out of the console.
I've filed lots of bug reports against Firefox in the past and just because you don't have an isolated reproduction case for a devtools issue, that doesn't mean it can't be fixed.
I still do all my development in Firefox regardless, I'm sure if I switched to Chrome I'd quickly discover a set of equally annoying bugs and quirks there too. Better the devil you know.
And yes, I'm aware of the extensions that offer similar functionality, but unfortunately they still have some way to go before they can reach parity with Chrome translator.
Edge has an ok-ish implementation of vertical tabs but it still has a ways to go to match tree-style tabs.
Once Firefox moved to the per-process approach and removed the ability to hack the UI, I saw no more reason to stay on what was a terribly slow browser back then, compared to Chrome. Startup times of 10+ seconds and such shenanigans.
Honestly I don't know and I think I should. I have uBlock Origin, Privacy Badger, ClearURLs installed on Firefox, I'm running pi-hole at home, it's just so much.
Privacy badger is largely useless ever since they got rid of heuristics. ClearURLs is useful, but you'd probably be fine without it. And pi-hole doesn't block anything that uBo doesn't in Firefox (but is still useful for applications outside of the browser).
On the other hand, maybe you're like me and want to squeeze as much privacy out of your browser as you can, even if it means breaking some websites. If that's the case, check this website out. Just remember that the tweaks listed here are nice, but not entirely necessary.
I've switched to Vivaldi and it's just much snappier and doesn't have the papercuts FF mobile is currently struggling through.
Total rewrites are cool, but they're real rough around the edges at first.
I strongly disagree. There are certainly issues, many of which are a result of the recent redesign, but I still find it a much better experience than Chrome on mobile and I think calling it "awful" is hyperbolic. Here are some examples of why I think FF > Chrome on mobile:
Firefox mobile supports extensions which I consider necessary at this point, such as uBlock Origin.
I can put the address bar at the bottom, where my fingers are.
The reader features makes many websites much easier to read - particularly on mobile.
Chrome defaults to opening things in tab groups now, which I find to be much more finicky to use than normal tabs. Bookmarks are for saving pages long-term, not tabs.
- I've noticed it crashes much more.
- It still doesn't support all the extensions I used to have, like uMatrix.
- All my bookmarks disappeared when it updated to the new version. I know syncing bookmarks would've let me recover, but I didn't realize it'd happen on the first place. And it seems like an easy problem to Amos even if a user didn't sync.
I know that Firefox also has a syncing feature ("Sign into Firefox", "Continue to Firefox Sync").
My problem is that I don't trust Mozilla's ability to keep this data secure. I believe that sooner or later they are going to get hacked, and that data will leak. The same might happen to Google, but I also believe that no other company has the degree of expertise of Google to protect that data.
Am I wrong in this assumption? Does Firefox Sync end-to-end encrypt the data, without knowing the key, like Google's Sync Passphrase feature?
What are your experiences with Firefox Sync? Does it work just as good as Chrome's, or even better?
The sync server is open source and free, so you can host an instance yourself if you'd like.
Firefox accounts have 2FA support, and passwords are end to end synced anyway, so even if your Firefox account is compromised, nobody can recover data without the key.
For about a decade in the working, there were zero breaches in mozilla AFAIK.
I use Firefox sync in my Windows laptop, Firefox on Android beta. There is also an app called Lockwise that can work as a standalone app and a password fill feature for other apps as well.
Dunno if it's better than the one in Firefox, but it's the one I know =)
Behavioral tracking needs to die. It was a mistake created from lack of web security in the early days, nothing more. It's a bug, not a feature.
Google is finally showing us what Chrome was meant to be. A browser monopoly to defend Google's user tracking interests.
In other words, the only way they will ever give up privacy invasion is if it is no longer profitable.
That's kinda evil don't you think?
Even if FLOC changes you just link a new floc to old IP, if you never see the old floc and you start seeing new one you have a transition and continue tracking. (not all will change at the same time i assume)
This thing fixes cookies... they would be obsolete... It would allpw an ad network to track you much better.
3rd party cookies are basically already gone.
See also this extensive list of browsers [2].
[0] https://github.com/midori-browser/core [1] https://gitlab.com/midori-web/midori-desktop [2] https://wiki.archlinux.org/index.php/Web_browsers#WebKit-bas...
I guess I'll still be waiting for Safari.
> Segments We create segments, which are groups of people who share similar characteristics, and use these groups for delivering targeted ads.
The key to segments is ensuring that the attributes give you enough entropy.
In Apple's world, Apple owns the supply side ad surfaces, Apple maintains the segmentation and mapping, and Apple mediates the demand side.
What does an advertiser see? Pretty much nothing.
You can learn more about how safari protects you by reading these blog posts.
But how does the website initially join the different floc ids, unless they have already identified the user?
So just track that and you have your user.
If floc changes - just look what floc is dead on that ip and match to that user.
If IP changes in same subnet (ipv6 privacy extension) just match new ip to old floc.
Add in browser fingerprint for overkill.
A sufficiently large network can identify a user if he's logged in anywhere and you have everything you need
The beauty is that Googles business works just fine with FLOC and their competitors don't.
When third party trackers "abuse" the ids one "obvious" solution could be to only allow "trusted" advertisers to receive it.
If, in a great stroke of fortune, the requirements to become trusted are basically "be Google" I wouldn't be surprised.
Google's Widevine (streaming media DRM) is a great correlate to this. If you wanted to try and create a great, novel 4th web engine/browser; good luck. Many of the major streaming sites use Widevine. You can't build a browser to stream that content without asking for access to Widevine encryption. Google will not give it to you; they may, eventually, if you build up enough of a userbase, but what browser would be able to build up that userbase without access to streaming media?
Its less about building a bulwark around Google's technology, a clear monopoly, and moreso a bulwark around the Boys Club of Established Big Tech. Then Google can go to Congress and say "we have competition, look, Facebook serves ads".
Yes, you just don't understand what working is. Everyone realizes you can do screen recording, HDMI recording, or just invite a friend over to watch on your screen. What it does do is make the content owners comfortable enough that there is a reasonable level of protection as to allow their content to be streamed online.
Because these users are still anonymous to companies using Google services. Uniquely identifying users, and the liability for doing so, falls to intermediary services. I expect it will be the domain of data brokers like LiveRamp, Epsilon, and others.
"Use Google and be compliant" is a good sales tool and good value for companies that use Google services. Companies that don't want to sell data to brokers will stick with Google.
https://www.cnbc.com/2019/07/23/anonymous-data-might-not-be-...
Privacy is dead. Once they have ubiquitous cameras everywhere, and connect the databases, the AI can correlate everything you do, and infer who is meeting whom and for what etc.
Similarly online. You are going to get deanonymized unless you go to great lengths to change everything about what you do, including not doing anything in real time.
More info: https://magarshak.com/blog/?p=169?p=169
JK Rowling: https://www.smithsonianmag.com/science-nature/how-did-comput...
And the mac daddy: https://news.bitcoin.com/a-look-at-stylometry-can-we-uncover...
But, if you want to anonymously browse the web and talk to people on HN then that’s still possible.
A state level actor can easily dox u
Sure, not fucking up for years, using the same identity, and communicating with people while being hunted ups the difficulty, but still doesn’t make it impossible.
> In 2006, the internet company AOL released a large amount of user search requests to the public. AOL did not identify users in the report, but personally identifiable information was present in many of the queries. This allowed some users to be identified by their search queries, prominently a woman named Thelma Arnold.
Cohorts are sized at "a few thousands" (what does that even mean?).
There is a lot a heuristic information retrievable using JS. This is separate from the information Cohorts use to group you.
Put both together and you have something quite close to a unique id.
There is absolutely no way to fix this problem while having cohort id's and not having very very large cohorts. Which I can't see google using.
Just as an example, I have a unusual setup so `coveryourtracks.eff.org` reports that my fingerprint is unique in the 292,340 tested in the last 45 days from heuristics alone.
Thinks are not that bad for the average windows or mac user (me: Linux, Firefox, 1440p screen, etc. I'm not surprised tbh.). Still combined that "not so bad" with a FLoC Id and you are back at basically unequally identifiable.
EDIT: Btw. there IS a fix, instead of letting advertisers decide on the ad based on you FLoC Id you let your Browser decide based an "available ad topic channels" (if combined with a fixed set of lables and a few other thinks, it's not trivial).
You could always ask first for a FLoC Id and then ask for the JS things, it's a dynamic language and there are always corss-domain redirects with tracing in url Id's.
Also some of them are very fundamental parts which are not at all thinks "you need to ask for". Like Chromium is a serve offender when it comes to accidentally providing unnecessary identifiable information. E.g. my Chromium user agent string is more identifiable then the Firefox one, the canvas fingerprints are way worse. There are additional attack vectors like list of plugins, some with names containing way to much information.
Also just combining things like Language + TimeZone + User Agent are probably enough to narrow down a FLoC group from multiple thousand to just a view hundred or even less users if you are not in the US/China/India. (Or if you limit yourself to HTTP headers: user agent header + accept lang header + accept header + accept encoding header).
Also don't forget you have a fixed Ip address as long as you don't to VPN perma-bouncing.
IMHO all the "fixes" are trying to fix a massive hole with a few thin sheets of paper, i.e. at best it will look fixed, for a short moment. But it's not fixing anything.
Lastly this doesn't change the point that this basically makes sure Google stays in it's pseudo monopoly position. Tbh. independent of privacy this should be shut down by courts handling problematic monopolies.
I'm also not sure if it cna really work, but if we can't remove all identifiable information from the browsers, it seems like a good idea.
I don't know how well ip tracking works. Can you track most people on ip alone?
Permissions-Policy: interest-cohort=()
Has anyone stopped to consider where laws and regulations should come in to say that tracking like this is far too invasive?
By setting this on the site level, your users won't have to opt-out. You are doing it for them (all of them).
If you don't, then the browser can always ignore it also. But that would only affect that individual user.
[ ] Add `Permissions-Policy: interest-cohort=()` header.
edit: in a previous version of this comment I said that Cloudflare should use this mechanism to "kill FLoC in the crib", which is quoted in southerntofu's reply.
Maybe its finally time we stopped using these corporations and their products once and for all and started empowering our own communities instead?
https://www.remarkbox.com/remarkbox-is-now-pay-what-you-can....
Header set Permissions-Policy: interest-cohort=()
...into my site's .htaccess and that's it, job done?
If your users go to another site, and they don't have client-side FLoC-blocking in Chrome, your settings obviously won't do anything for them.
So it's a nice step for your users, but is limited.
Header always set Permissions_policy "interest-cohort=()"
nginx: add_header Permissions_policy "interest-cohort=()" always;Is FLoC not built on sound principles of differential privacy? That would be a big shame on Google.
EDIT: Huge shame on Google! From their FLoC whitepaper: "We want to emphasize that, even though differential privacy is now the de facto privacy notion in industry and academia, we decided against using it as our privacy measure for building audiences."
What in the world are they thinking?!
In floc's case the model is public but isn't being trained on individual's features in realtime, only used for inference as far as the proposal says, e.g. the proof of concept stage will develop a fixed model that all browser instances (of a given vendor) share. Individuals' features are kept private to the extent that the model output can't be effectively reverse-engineered.
Differential privacy probably also won't be useful in the POC stage because the training will require accurate labels which defeats privacy.
https://www.researchgate.net/publication/265973077_Robust_De...
https://github.com/WICG/floc/commit/d822a35f4bfe7d5003fda4a7...
Although the follow-up comment summarizes why this probably won't work
https://github.com/WICG/floc/commit/d822a35f4bfe7d5003fda4a7...
From what I've seen the most unobtrusive ads are the most expensive methothelioma and personal injury ads since they're generally a short message on a solid color background.
One of the problems I see with is FLoC is that giving the user direct control over their cohort ID.
even if cohort is in the millions a UA+ip or geo should be enough to ID, or even add a couple more bits of window.property entropy enough to stay under the 'budget' limit
The browser can tell any site this data and it’s a small enough number of bits that I’m not uniquely identifiable even when geography is added.
If site B also had an account and both sites would work together, they could simply compare the email address.
This tells you where google's priorities are, not that it was in question before, but it just makes it clearer.
If it's even possible to block...
One of Google's aims has been to make Adblockers useless.
Think Manifest V3, which would originally enforce a static filter list with only a few thousand or so entries allowed.
uBlock Origin and other actually useful adblockers make heavy use of dynamic filtering lists.
Jesus christ what a mess. This web browsing looks like navigating across a minefield.
Do you think they keep going bec they don’t actually care about the privacy implications or do you think they try to “legislate” their way out of it by adding something to the EULA of the FLoC program that you can’t share IDs. So they can say “see we don’t allow it” and can pretend no one is gonna do it behind their back.