This is going away: all the major browsers have said they are going to block cross-site tracking.
(Disclosure: I work on ads at Google, speaking only for myself)
This is going away: all the major browsers have said they are going to block cross-site tracking.
(Disclosure: I work on ads at Google, speaking only for myself)
I'm not sure what you mean by this?
Google Ads has committed "once third-party cookies are phased out, we will not build alternate identifiers to track individuals as they browse across the web, nor will we use them in our products." -- https://blog.google/products/ads-commerce/a-more-privacy-fir...
> even if wrapped in something like FLOC
FLoC doesn't allow "a few actors [to] obtain competitive advantages by collecting data from across websites" since everyone sees the same number of identifying cohort bits.
> other parties like KISSmetrics will continue the fingerprinting cat and mouse game
Historically, the TOR browser was pretty much the only one that took fingerprinting prevention seriously, but it's now a substantial focus for Safari/Firefox/Chrome. I do think fingerprinting groups will continue to have things that work when third-party cookies go away, but I don't expect it to persist that long after? I also would not be surprised to see a regulation here, since I (not a lawyer) don't think fingerprinting is compatible with the GDPR or the other regulations it's inspiring around the world.
(Still speaking only for myself)
https://vivaldi.com/blog/no-google-vivaldi-users-will-not-ge...
What in the post gives you that impression?
(I'm not)
I also have a feeling you are trying to explain to yourself why the things Google is doing is not bad. So you twist things a bit here and there to make your point.
In any case, you are not in a position, I assume, to influence what Google does. Google is on a path that a lot of us do not like. We do not like being tracked and we do not like profiles being built on us. We want that to stop. You try to convince us it is not so bad, but the feeling I get is that you are just as much trying to convince yourself, but obviously I am not you, so this is just based on a feeling.
FLoC significantly increases the entropy in a user's fingerprint (typically by 15 bits iirc). This improves existing individual tracking mechanisms that use a fingerprinting-based approach. FLoC therefore enables further individual tracking, and browsers that take privacy seriously should disable it.
https://vivaldi.com/blog/no-google-vivaldi-users-will-not-ge...
"Will you use information about users from third-party sites when making decisions about how to interact with them?"
"Will you use data about offline purchases made by users when deciding how to interact with those users?"
Etc.
Once banned, Google and Facebook will submit. They will attempt to lobby against the reforms, eventually saying "it will prevent legitimate business: it represents a small fraction of our revenue, but we are selflessly lobbying on their behalf to ask you to implement this technically specific law to reign us in". Ignore them. You don't listen to the hitman when they comment on homicide laws.
And ensure that the penalties amount to a ban. The US congress and courts can and do terminate human lives. Whatever penalty they propose on abstract legal entities is not too harsh; even if they completely dismantled Google and destroyed all of their economic value, it is nothing compared to the things we do to natural living breathing humans in response to criminal behavior.
Profitable companies will submit to a law that aims to control their behavior.
This is a terrible philosophy for legislating. It undermines the rule of law, i.e. that you should ex ante be able to determine if what you're doing is legal or not.
What you're describing is rule making. Congress regularly does this, in passing a law that requires such and such agency propose (or even implement) rules that achieve this or that within so many days.
We don't say murder laws are bad because there's no way to know in advance if "bashing someone's head in with a pipe who dies a month later" counts as murder.
Yes, but intent alone isn't sufficient. We need a precise, side-effect light definition of the kinds of activities we want to ban and by whom. To date, I haven't seen that.
Passing a law which bans "surveillance-based advertising" with little more specificity is a recipe for disaster.
That being said, there are great alternatives to GMail that you can use, both free and paid. FastMail, Proton Mail, Tutanote and Vivaldi.net mail are just a few options you might want to try out.
Gradually Google became more and more an ad company. In 2007 they bought DoubleClick that was one of the leading ad companies on the Internet. This was part of them moving towards providing ads not only on search results, but on sites as well. At the time most ads were site or context sensitive.
So Google has been making money off ads for a long time. More or less from the beginning. The big change, however, was the move to surveillance-based ads, where the ads depends not on the site or page you are viewing, but on the person viewing the ad. That is where it went all wrong.
Imagine how quickly companies would only save minimal personalized data.
But anyway, Google Analytics won't be able to do it because nobody will be able to do it. For example, here is Chrome's project to remove cross-site tracking: https://www.chromium.org/Home/chromium-privacy/privacy-sandb...
(Still speaking only for myself)
(GA sends a message to Google, but I had thought that it was not linked to your behavior on other sites via GA?)
1. Google Analytics' primary identity signal is a first-party cookie. this is not shared between domains. There is no technical way to link identity between domains with different cookie values.
1a. Google Analytics has built-in library functions to allow site owners to share first-party cookie values between a whitelisted set of domains. This effectively lets one company with multiple sites share a first-party identifier, but still not let anyone (Google or otherwise) link that identity to identities set on other sites.
1b. BUT. But. BUT. Google is rolling out "Google Signals" for Google Analytics, which will use your Google Account as the identity signal instead for users who are logged in to Chrome. This, obviously, lets your identity be correlated across sites.
(Personally, I suspect that the availability of this feature played a part in Google's decision to let Chrome follow the industry towards blocking third-party cookies. But this is a baseless opinion, one step removed from a conspiracy theory.)
2. Google Analytics can link their identifier (the first-party cookie or Google Signals) to your DoubleClick profile via DoubleClick's third-party cookie. The checkbox that does this is unchecked by default. There are many other features of GA that encourage or require you to check this checkbox.
2a. Google's documentation (including legal contracts!) places limits in the data exchanged between the two profiles. Data exchanged does include demographic and interest information from DoubleClick's profile into GA. This is one of the big reasons why people click the checkbox.
To my knowledge, GA data is not used to inform the DoubleClick profile. GA data can be used to build an "audience" in various Google ad platforms, and direct ads to those people specifically, or to use as the basis for a "look-alike audience."
3. Google is a Processor under GDPR for Google Analytics, and a Controller under GDPR for Google Ads. To a first approximation, this means they make the specific legal claim that they do not use GA data for their own purposes. Linking Analytics and Ads data is... complicated and frankly I still haven't gotten an explanation of its legal status that I fully understand.
In my personal opinion, I don't think Google actually uses Google Analytics data. Most Analytics implementations are tire fires, and they can get all the data from other more reliable sources, like Publisher data or Chrome. Given that they have based on their entire GDPR compliance strategy for Analytics on being a Processor, I don't think the risk/reward is there.
(apologies for lack of copy-editing, the thunder's about to take my internet away)
"When you’re not signed in to a Google Account, we store the information we collect with unique identifiers tied to the browser, application, or device you’re using."
What is stopping, legally, them from taking e.g. HTTP Headers from independent connections and linking them together through fingerprinting? Maybe this is not implemented in Google Analytics, but that is certainly not the only connection made to Google on most websites (see e.g. gstatic and Firebase). Since there is practically no technical barrier, it seems that the vague privacy policy leads to the only question being what the 'unique identifiers' are exactly.
Setting aside legality, the attack you're describing will be thwarted by network state partitioning: https://www.chromestatus.com/feature/6713488334389248
If you're talking about fingerprinting in general, that is also something that all the browsers are working on. I'm most familiar with Chrome's strategy, which is to first switch APIs that provide a lot of entropy from something you get by default to something you have to actively request, figure out how to provide similar functionality more privately, and then enforce a privacy budget that does not allow collecting enough information to identify users: https://www.chromium.org/Home/chromium-privacy/privacy-sandb...
Note this site guideline, including the last bit: "Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith."
Is Google going to consider YouTube, Gmail, Maps, and Android Location history different sites, or is "having an effective monopoly an exemption to crosss-site tracking prohibition?
Does anything in the proposal prevent server-side cross-site tracking? (No.)
Is Google going to stop buying third party tracking data like credit card transactions?
That's mighty pleasing news to hear. A step in the right direction for sure. Here's hoping it's the beginning of a trend.
Really, FLOC is for me the ultimate betrayal. The browser is not supposed to make an ad profile based on the browsing history. It is just wrong.
"Websites can exclude a page from the FLoC calculation by setting a Permissions-Policy header interest-cohort=() for that page. For pages that haven't been excluded, a page visit will be included in the browser's FLoC calculation if document.interestCohort() is used on the page. During the current FLoC origin trial, a page will also be included in the calculation if Chrome detects that the page loads ads or ads-related resources." -- https://web.dev/floc/#do-websites-have-to-participate-and-sh...
The tracking just has to stop. Google can generate plenty of revenue without tracking us. They were in fact making plenty before they moved from context sensitive ads to surveillance-based ads.
But it doesn't! They are proposing, in the stable version, to include only pages that opt in by calling the FLoC API.
For the origin trial in particular, to avoid a chicken-and-egg issue, they are also including pages that have ads. Since ads today make extensive use of third-party cookies for cross-site tracking, This is still not anything like "all sites and pages".
(Still speaking only for myself)
So you start with all pages that have ads, meaning most all pages that are tracked today. Then you add to that by "opt-in". Now, most sites are not built by hand. The tools they use may thus "opt-in" for them. Also, this method may make it harder to block the tracking, so you end up tracking more in practice, which is obviously why this is being introduced, as so many have chosen to use tracker blocking of some kind.
Your statement on "opt-in" really needs be reiterated. In many cases you are left with options like: do you want to use this product? Then you have to "opt-in". Great examples are Windows 10, that insists on you logging in with Microsoft. Similarly many products require you to "opt-in" to use them.
We need this to stop. Ban surveillance-based ads now!