Apple ad targeting:
- collected from device info, purchases made from Apple (apps, shows, movies, books, etc.), and app store searches
- used to serve ads in Apple apps (App Store, Stocks, News), so while Apple knows what segment you're in, it's hard to see how that's any worse than what they already know about you (assuming you trust Apple with your info, which I assume you mostly do if you use Apple devices)
Google Floc:
- collected from all of your browsing history in Chrome, not just on Google properties
- your Floc ID is available not just to Google, but to every site you visit because Chrome serves it up. This means any site would have immediate access to your interests and demographics. Say you sign up for a site with your name or other identifying information, now they can link your personal information with your interests and browsing habits. So now you don't only have to trust Google, but you have to trust every entity you interact with on Chrome.
Frankly the same problem exists in PCM’s, Apple’s proposed solution to allow private tracking from ad clicks: https://github.com/privacycg/private-click-measurement/issue...
However, both of these are solutions to help web developers of third-party sites and ad networks track end users anonymously. All would argue that they’re better than third-party cookies, though in reality, users might want to turn off or opt out of both of these anonymize tracking devices.
Another way of putting it: I don’t mind sharing my data with Apple when Apple says to trust them. I also don’t mind sharing data with Google when Google says to trust them. I do both on a regular basis with iCloud and Google Drive for example.
What I have a problem with is when people try to “solve” third-party cookies in a way that doesn’t increase privacy but simply pretends to.
I’m not against first party telemetry data, I love it as an engineer and I know that bugs found and reported with it can be fixed, thus improving my experience with products.
What I dislike is when advertising companies can sign deals with Google or Facebook and gain access to lots of info about how well their campaigns are working, or when I don’t know when my data is being used, or when companies start messing with DNS so third-parties look like first-party just to increase revenue.
To me it says it all that Google apparently turns off FLoC when inside GDPR zones. Only stronger laws will actually prevent bad behaviour on legitimate rule-abiding services. Only providing less and less means of tracking can we truly start to prevent it technically. Looking for replacements to tracking to support existing business models is doomed to failure as long as people can keep voting, literally and figuratively, for privacy-preserving alternatives and policies.