How to fight back against Google FLoC
plausible.io
plausible.io
This may need CVE.
Not saying that filing issues against weservers is a bad idea.
Just that the security angle is wrong.
For one, because Google, or chrome, could just choose to ignore that header if too many servers fly it.
This is the important part regarding "security". Websites choose to not honor "DNT" headers.
Clients can just as easy choose not to honor no-floc headers.
Which is why I'm saying that this is not a security-thing. If people can just choose to ignore your security-headers, they are not a security-feature. At most they are a suggestion that, when followed, make the client honor privacy concerns from servers.
> Removed the Do Not Track flag, which ironically was used as a fingerprinting vector, adding uniqueness to the users who had enabled it.
https://lapcatsoftware.com/articles/catalina-executables.htm...
“Segments We create segments, which are groups of people who share similar characteristics, and use these groups for delivering targeted ads. Information about you may be used to determine which segments you’re assigned to, and thus, which ads you receive. To protect your privacy, targeted ads are delivered only if more than 5,000 people meet the targeting criteria.”
Why is everyone championing Apple while shooting down Google if they are doing the same thing.
Unless I am mistaken, I am reading a lot of double standards from people on the issue.
One more specific argument against FLoC is that it will make help tracking users via fingerprinting. I don't really buy it. First of all, the estimations from [EFF article](https://www.eff.org/deeplinks/2021/03/googles-floc-terrible-...) are just plainly wrong. They are talking about narrowing down to thousands of users, while in fact if Chrome has on the order of a billion users, and if FLoC has only 8 bits of entropy, the actual number of users in a cohort is on the order of millions. Secondly, from my understanding this cohort is based on your recent activity, so it will change over time.
Sure, I can give an example: it goes beyond simple basic fingerprinting, it allows you to be associated with a group of "others" (your cohort) in ways that can be dangerous to you.
Suppose you live in a country where you may not enjoy certain freedoms or some behaviors may be outlawed; end up in the wrong cohort(s) and a state actor will be able to know these things rather easily, this is not to say there aren't already means to do it today, but why make the job even easier for them?
But state actors won't be able identity me individually, so I don't see the harm either. And you can actually reset you FLoC id at any time.
I think advertisers (like Facebook) know that this will damage their revenue and doing mass brain wash to make people think this is harmful for everyone (Cambridge Analytica style).
Replace "hiking boots" with "dissent" in this example.
Why wouldn't they be able to? FLoC tells them you're a dissenter, your IP tells them who you are.
Just because you can reset it doesn't mean that you should have to be constantly afraid of your browser working against you. You're just listing ways in which FLoC is slightly less terrible than some maximally terrible hypothetical version. It doesn't make FLoC proper less bad.
I would argue the very notion that your recent browsing history affects what you see in the present is a wrong and dangerous one.
> I would argue the very notion that your recent browsing history affects what you see in the present is a wrong and dangerous one.
It already does, 3p cookies do exactly that and deleting them is a pain because you would also be getting rid of legitimate cookies, so you have very little or no control. Reseting your FLoC id is as easy as pressing a button and you don't have to worry about having to re-login everywhere.
So the argument for FLoC is moot because this is actually a false dilemma. We shouldn't be acting as if it is a choice between either third-party cookie or FLoC. Rather, we should reject both.
Aside: In some ways, FLoC is worse than third-party cookies since the latter are not under central control and do not provide a way of automatically grouping an entire browser user population into similarity groups based on past browser history.
From the EFF article that you don't like:
> Google’s experiment used 8-bit cohort identifiers, meaning that there were only 256 possible cohorts. In practice that number could be much higher; the documentation suggests a 16-bit cohort ID comprising 4 hexadecimal characters.
Also, its since someone can belong to more than 1 cohort, the 8bits is a bare minimum and not a maximum. For instance, techie who likes hiphop, buys whisky and is looking for a washing machine is 32bits of entropy and covers the billion users with ease.
> someone can belong to more than 1 cohort
I'm pretty sure you will only belong to one cohort at a time. Otherwise it would defeat the purpose of this change. It seems like k-anonymity is an express goal of FLoC.
Yes, but Google already has atleast 32-bits from the ip address already (which I know for a fact that they don't use).
> EFF brings up a second concern which is also novel and scary in terms of privacy. If you sign up to an online service with your email address, they can immediately tie your last week’s browsing data with the email address that you supply them (or physical address, phone nr, etc). It means any service you use now knows what you’ve been up to and not just in an anonymous way
in contrast to that Facebook can identify you as LGBT+ today based off your likes and dislikes and shares.
Just because this is said to be so on paper doesn't mean it would actually be so. How would this work in practice with the LGBT example? Would every LGBT-related website be tagged as a "political" website in Google so that it is not included in the calculation? What about clearly non-problematic a-politicial categories which nevertheless serve as a good proxy for detecting LGBT members because of e.g. their increased interest in the topic?
> in contrast to that Facebook can identify you as LGBT+ today based off your likes and dislikes and shares.
This is irrelevant because we're not choosing. Facebook tracking is also terrible.
(i'm surprised people screaming apocalypse have such poor understanding of the web).
FLoC, AMP, ... With Chrome, Google is hijacking the web in a more cunning way than Microsoft and IE. The revolt against that needs to happen now. When Firefox is dead, it will be too late...
Are you wanting proof for how it is harmful?
One possibility is that with a FLoC and a few other details, you can be fingerprinted as an individual not a cohort. So it's not effective at anonymizing the data advertisers are tracking from you.
It’s time to pick another browser.
`permissions-policy: interest-cohort=()`
See also this post on StackOverflow for information on how it adds a warning message in Chrome DevTools for browsers that aren't part of the current test [1]
[1] https://stackoverflow.com/questions/66997942/error-with-perm...
Edit for typo.
Privacy is really important to me, so I am not affected because I don't use chrome in the first place. All the people who use chrome, especially on this site, know damn well what they agreed to. You all already opted into this and everything google comes up with tomorrow. Why should I put in work to give you the warm fuzzy feeling of having staved of the google spying for another day? If you want protection from this, use another browser.
At this point, blocking this from the website level just seems to support google even more, because it takes the pressure from chrome users to actually start thinking and stop being victims.
When websites block FLoC, the activity of their users on those websites are not available to Google's Cohort Assignment Algorithm.
It's not about your personal privacy as the individual website operator. It's about your customers' privacy as visitors to your website.
Now, you can rightly point out that they don't know, but we are on Hacker News here. I am not talking about someones grandparents, I am talking about users of this site, working in the IT industry. I am talking about my collegues at work. About IT professionals. We all should know, most of us do. Yet, many here always proclaim how they can't use privacy friendly alternatives because "minor reason". The whole industry regularly creates content that only properly works in chrome, reminding one of the old Internet Explorer days.
It's not that "normal" people don't listen to "us" experts and use chrome regardless, it's that many so called professionals seem to care about privacy even less. And I am not getting complicit with this attitude in helping google make everyone feel save using their crap piece of spyware.
Switch your browser now and tell the people who don't know why they should too, or stop complaining about "evil google" while enabling them with building shit that includes their tracking and only works in their browser.
What about this statement is so inherently difficult to understand for SEs at companies like Google?
It's time to stop!
That would be why SEs at Google et. al. seem incapable of understanding. The business model, and thus, their salaries, is dependent upon tracking people, consent or no.
More info: https://volument.com/learn/data-privacy
Note that I work at Volument.
I wrote a bit about this [here](https://github.com/StevenBlack/hosts/issues/1346#issuecommen...), pasted below:
> I feel like a lot of this comes down to what "track" means, and what I as an average user am expecting when I enable "do not track".
> Personally, I feel like "track" means following me across multiple websites, or keeping a detailed record of my individual browsing habits on an individual site.
> If you think about what "tracking" means in real life, it means constantly following someone/something or monitoring it. If someone had one of those little infrared foot traffic counter things at the door to their shop, I wouldn't say they're tracking me as an individual. They're tracking how much foot traffic they get, but they're not tracking me.
> Both Plausible and Fathom are just like this. They don't keep the same user identifiers for more than 24h, they just take an anonymous count when you walk in the door to a site (along with a few other anonymous things like referrer). In short, as a user, I don't feel like my individual activity is being tracked to create a profile of my browsing, I just feel like the website is counting me when I walk in the door. They're tracking their visit stats, but they're not tracking ME.
> As cause enabling DNT, what I'm saying and expecting is "do not track ME". It's fine to track your usage stats, but don't track ME and build a profile of ME. So I would not expect services like Plausible and Fathom to do anything about this header, since they're not tracking me as an individual in the first place.
I wish we all did it. However, I think we're often obsessed with delivering our products to the broadest possible audience.
“You are using Chrome which tracks you without consent. Download a spyware-free browser here.” In red at the top of the page with links to brave and Firefox.
I’m genuinely hoping to do this on some of my web properties - if anyone has a hint on how, please let me know.
I’d like to see more written and more popularly known about effective, targeted but privacy respecting ad models. Then a good argument would be “why FloC when X is possible?”
To me FloC looks like an attempt at a compromise. Whether we like the world we have or not, there is no going back to the “good old days”.
The market is big enough and can survive regulation, and would evolve alternatives, and the associated deadweight loss would be an acceptable compromise.
Not to mention, the targeted advertising is a game of Prisoner's Dilemma, where all parties lose, it's not even 100% sure if the regulation would cause inefficiency at all.
Every http server project should include the header by default to disable this, and even back port it for older versions as a critical security vulnerability update, since old sites with sensitive information will clearly be still serving content, and the DEVs may not even be working on the site anymore, and basically an IT guy is just updating software (hopefully...).
...
> We need to ban targeted advertising to truly have a privacy-first web.
Why ban it when it's a dying business?
FLoC seems like a method of saving my preferences locally, which is fine. I'm not interested. I won't use Google's browsers and I'll continue to filter my traffic.
Internet privacy will always be an uphill battle, there's worse things going on, starting with centralized and monopolized DNS, I feel we should focus on fixing that.
But either way, your initial statement assumes that ads will only be interesting to you if your browsing habits are tracked across the internet. There’s another option: if you visit sites that are focused on GPUs they can advertise GPUs to you. This is the way advertising worked from 1700-2000.
From 2000-2010 you had site/search based adverts
From 2010-2020 you had tracking based adverts
I can't think of even 1 time I've seen a useful advert though
And almost without exception, those were relevant ads, not targeted.
Relevant like getting a coupon code for digital ocean storage credits below an article on how to run your own IPFS host.
Or relevant like getting an offer for pizzafriday on the 'where to eat' information section of a campsite in some unfamiliar city.
Maybe on both sites you get shown ads for coca cola or a car.
None of those require building up a profile that tracks your personal browsing habits across the entire internet and is simply targeting your customers where they are.
Its a fucking horrible thing to do to someone, Even if you try to opt out of family and that type of topic you still get them.
It's all about some random company building a detailed file on your person.
If you have trouble understanding it's an issue, imagine all physical businesses - restaurants, shops, taxis, barber shops, hospitals, postal service - recording all your visits, mugshots and all, and forwarding them to Moms Friendly Robots company, which knows exactly what you eat, shit, like to fuck and generally predisposed to do. They also sell this info to others, but that's really secondary.
What you are missing is that FLoC is basically a different vaseline flavor and you preferring it over the original is the biggest issue of it all - that, shokingly, you are OK with the rape to begin with.
Would you be OK with an opt-in solution? If you want to be tracked and get "good" ads you install a browser extension and now you get your ads and now everyone is happy.
I even found my current broker that I do most trades with via targeted advertising, and I'm super happy with it.
Targeted ads of course don't always show perfect companies and products, but they're often a good starting point if I'm looking for a product and I see an ad about it that looks interesting.
That being said, I do try to avoid ads as much as possible, but if I'm gonna see them, for example there's no way to block them on iOS instagram, I'd rather they be targeted than generic.
What bothers me much more is Google’s et al crushing dominance over the competition, meaning that whatever shenanigans they come up with end up forced on {m,b}illions of users. This, and the sneaky hiding of data grabbing in “consent” boxes or 100 page ToS docs.
DuckDuckGo sucked at searching last time I tried it - and I'd happily pay money for an alternative. Ditto for Google Docs. Google Scholar - another thing I use a lot.
I think the root cause is not really FLoC etc. but Google's total dominance over the Internet, and with it, a lack of real alternative.