Do. Not. Allow. Anything. LGBTQ+. Related. To. Be. A. Topic. Unless. It's. Opt. In.
People. Live. In. Unpredictably. Unsafe. Places.
People. Will. Die.
Do. Not. Allow. Anything. LGBTQ+. Related. To. Be. A. Topic. Unless. It's. Opt. In.
People. Live. In. Unpredictably. Unsafe. Places.
People. Will. Die.
To me, in the United States, there are two major camps of thought:
* Targeted advertising is useful to me and I don't mind someone knowing everything about me
* Targeted advertising is dangerous to me for x, y, and z reason
A world that allows both is optimal. Allow companies to collect data, but have federal agency oversight and requirements up to and including the right to be forgotten. It should be possible to pull a level and dump most (if not all) collected data associated with you.
I don’t personally think targeting works - does anyone have a good research paper that proves it?
I think the optimal solution would be the old pre-internet advertising.. general ads on billboards, but now on websites. No tracking.
That means if we go back to pre-internet style of ads, then it will be expensive to advertise your business to a niche community therefore only larger companies can advertise.
There is a privacy angle that needs to be figured out, and it is complex. But just going back to the old way just empowers larger businesses to beat out smaller ones. This is the sad reality we live in now.
You can choose where to advertise. Is this website, page, game, product, etc related?
You can do it how DuckDuckGo does it by targeting keywords.
Multiple people can buy space/impressions and you can rotate them. It doesn’t have to go back to old static banners.
I agree with your overall sentiment, but I think the solution you propose is bad. It allows companies to collect data automatically behind users' backs, and then tries to address the extreme power imbalance that creates with regulations and escape hatches that users can take after that data has already been created. But ideally, we want to prevent problems from occurring at all, not just to try and fix them after the fact.
To your point about voluntary tracking, users may want to signal interest in some topics but not others. They may want to signal interest about some topics only in certain situations. They may want to signal interest about a topic to one site, but signal interest about another topic to a different site. They may want to "freeze" the topics that they signal interest about, so that they don't need to worry about accidentally revealing new preferences in the future, or to think about how browsing a set of sites will change the ads that they get. All of these are valid things for a user to want to do.
It is better if users have complete agency over what data is transmitted, and if companies do not fingerprint or correlate users behind their backs at all. Attempting to determine user cohorts clientside is the correct move, arguably the only part of FLoC that Google got right. The problem with FLoC is that even if cohorts are determined completely clientside, the user still does not have agency and transparency about those cohorts.
There is theoretically a version of FLoC that would be really good for privacy, and that would also allow the kind of optional tracking that some users want. Such a system would need to be easy for users to toggle on and off on the fly on a site-by-site basis. It would need to be transparent to users about what categories they're in, it would need to allow users to edit and delete their categories, to add new categories, and to turn off category aggregation. It would need to not send new categories to a website without the user's permission. It would need to block websites from determining whether they're being given an automatically generated category, or a user-defined category. And importantly, it would all need to be opt-in.
Right now, tracking is an invisible system that happens automatically, with (rare) escape hatches that the majority of users are not expected to pursue, and that give little to no granularity about how users can customize how they present to the world. This kind of tracking is inherently invasive. We should pursue a paradigm shift where users proactively volunteer information about how they want to present to the world in any given situation -- in other words, we should give users agency to choose their own identities online.
Most regulatory suggestions that I see online (including the one you give) consciously or unconsciously focus on preserving the invasive nature of tracking while adding safeguards to try and prevent advertisers from abusing the inherent power imbalance. Instead, that power imbalance ought to be totally flipped in favor of the user. We need to reject the underlying idea that preferences should be extracted from users, rather than something that users consciously choose to volunteer.
----
I've commented to the same effect a couple of times in the past:
- https://news.ycombinator.com/item?id=25906791
- https://news.ycombinator.com/item?id=26353494
- https://news.ycombinator.com/item?id=25907079
This isn't only true for advertising. Think about how little control users have over how personalized algorithmic content filtering/ordering works on sites like Youtube, and you'll see similar conceptual problems with how the systems are designed. But it's really apparent in advertising, moreso than in other contexts.
I want to fight back against policy changes that (in my mind) cement and normalize the current philosophical approach to advertising. It's not OK to be tracked without your permission, and regulations or safeguards and escape hatches around tracking aren't enough to make it OK. The system would still be fundamentally broken.
I think it's kind of important when talking about privacy to keep in mind that the goal shouldn't be to force people to never reveal anything about themselves, it's to give them agency over what they reveal. That gets lost sometimes, I'm often guilty of losing sight of it as well. So a privacy world that makes it impossible for people to connect with each other, or that tells them that they're not allowed to present a certain way online is just as much of a problem as a solution that requires them to do so.
To me, the core idea behind privacy in regards to user tracking is that people should have agency over what their identities are, over what identities they're "allowed" to have, and over where they share those identities and whether those identities are associated with each other. It's totally valid for people to want to be able to tell Google that they're interested in seeing certain ads, they should be able to do that.
And when we expand out from privacy and look at algorithms on sites like Youtube/Twitter, that underlying idea of control becomes a bit more obvious -- it's not that content suggestions are bad, it's the inversion of control over how those suggestions are determined, the requirement that suggestions are constantly being computed and updated based on every action the user takes, the requirement that there be one set of suggestions for each user regardless of context, and the refusal from companies to give users the ability to do anything beyond slightly tweak or retrain their suggestions or to treat personally volunteered preferences as valid or trustworthy compared to what the algorithm determines they should like.
But I do want to get Youtube suggestions for related videos, I just want to be in control over how that happens. I want to be the entity with power in that relationship, I want to be the entity holding onto my data, I don't want to have to trust Google not to abuse me or to ask permission for Google to forget things.
This also gets at the potential benefits of a private world where users have real agency. It's very easy (I'm often guilty of this) to phrase the end goal of privacy as a world where tons of things just go away. But the reality is that targeted ads today mostly kind of stink, and there's a lot of potential for filtering, curation, and community aggregation that we can't take advantage of because users are excluded from the process of determining what they see online and how they're perceived by others. I wish there was more effort to try and describe how a private world could be better for things like search suggestions, user-relevant ads, content filtering -- because in a world where users had control over how this stuff worked and could customize their own experiences, it might be possible to try new applications, share more information, or experiment with new identities without risking abuse.
Imagine a world where you're an LGBTQ+ adjacent teen trying to figure out your own identity, and you temporarily turn on a category related to that for a subset of sites. If there's not a huge danger of fingerprinting, you can see how it feels for sites to recognize that -- maybe to tell Youtube that for right now you'd like to see more videos suggested based on that category. But you can safely do that because you know that other sites won't get that information, and that at any point you can switch the category off with zero consequences. You don't have to ask Google/Youtube for permission to edit what they know about you or to forget a category, you can control it locally right from your browser without asking anyone's permission.
That opens the door for really powerful applications or recommendation engines that arguably couldn't be (morally) built today. It's not about trying to create a world where nobody knows anything about anyone, it's about flipping the power imbalance and inverting the current predominant narrative about how information should be collected online.
With FLoC (and with other privacy initiatives from companies like Facebook), the feeling I get is that Google is trying to convince users that it can be a responsible data steward both because of internal policies and regulations. These companies try to create a narrative that the only options are either they track us, or that we never get anything recommended again. But neither of those options are what I want, what I want is to be my own data steward.
When providing information in response to a search by a user of the EAIS, the EAIS must order the information provided so that the flight options that best satisfy the parameters of the user-selected search criteria are displayed conspicuously and no less prominently (e.g., in the same or larger font size and the same or more noticeable font color) than any other flight option displayed.
https://www.law.cornell.edu/cfr/text/14/256.4
...............
The airline industry (once upon a time) got its collective hand slapped because they would only display flights from certain carriers on "page 1" and relegated "other options" to "page 2".
It doesn't seems like we're going to put the genie back in the bottle of push promotion or "algorithmic" ordering, and it's a very difficult battle to fight.
The original genius of reddit/n.y.c display ordering algorithm was that it represented an aggregate priority order that was user-controlled (ie: 100 users give 500 upvotes across 1000 articles, and you get to see them ordered 10 at a time). The site is/was the cohort, and "the algorithm" was shown equally to all comers.
Contrast to twitter (presumably) and facebook (definitely) where content "chum"[0] is intermingled as soon as possible after the original "hook" of original or requested content, and tailored to the individual user. It's a constant stream of distraction and lies, and no wonder that a significant portion of net-users become hooked.
> Do not allow anything LGBTQ+ related to be a topic unless it's opt-in. People live in unpredictably unsafe places. People will die.
I try to write in an accessible way generally, but in this specific case I wanted a message that would stand out visually to sighted people, because they are the most likely (probabilistically) to be both the group leading this project at Google, and also the group who might have not thought about how their technical choices can impact people with diverse backgrounds. I definitely tripped over the trolley problem here, and I sincerely apologize for hurting you.
With FLoC, though, the idea was that the browser would provide document.interestCohort() and the individual site's JS could react accordingly: https://github.com/WICG/floc . This means that any site, regardless of its contracts with ad networks, could immediately identify your cohort and associate it with your activity. Web developers working in good faith would be encouraged to have user.cohort or user.topic fields from day one "just so you have it" - imagine all the ways someone could use this in bad faith. Inevitably this data would leak (or be intentionally leaked) and could trivially become a target list for doxxing closeted people. It's a dangerous, dangerous proposal.
FLoC is one of a collection of proposals, which does include preventing fingerprinting: https://www.chromium.org/Home/chromium-privacy/privacy-sandb...
If you're not going to prevent fingerprinting, why even get rid of third-party cookies? Fingerprinting is a step backwards from cookies, since, for example, closing and reopening a private browsing window gives you a new cookie jar but the same fingerprint.
(Disclosure: I work for Google, speaking only for myself)
I’m skeptical that fingerprinting can be “solved”, but let’s suspended disbelief.
Let's say fingerprinting is completely solved. The browser's still going to be sending your FLoC data to Facebook/Reddit/Twitter/Amazon when you log in -- and it's not clear you'll even be able to tell what information that FLoC payload reveals about you.
Solving fingerprinting is one thing, but there are a ton of situations online where users will be revealing their real identity to service providers, regardless of the fingerprinting protections. What FLoC data will be sent to those providers?
FLoC greatly increases the potential abuses that can come from fingerprinting, particularly from smaller sites.
So is Google committed to completely eliminating fingerprinting from the browser before it launches FLoC? Because it would really stink for everyone if the privacy sandbox doesn't completely block fingerprinting, and then the sites that manage to fingerprint users suddenly have a huge amount of extra data about them.
What will happen if the privacy sandbox comes out and people are still fingerprinting through other invasive means, or if a hard-to-fix exploit is found, or if a research paper demonstrates that the privacy sandbox is insufficient? Will Google commit to disabling FLoC if that happens?
It shows that google no longer things owning data is a competitive advantage.
This seems like it should be bigger news.
FLOC is centralized at the individual. That means YOU are profiled completely and all the profile info is centralized for everyone to grab.
With FLoC, anyone can get that data without entering into an expensive agreement. I can get that data as a single person from a personal blog with no cookies. I can get that data directly, I don't need to sign up with another 3rd-party tracking company that might not tell why they're serving my users a specific ad or what data they have about them. And it's all scaleable with no extra cost to my operations. This opens up additional attack vectors that might not exist otherwise: in a small operation it may be a lot easier for me to fingerprint you using your IP address, login information, or other data I have access to and to correlate that to a real-world identity. When that happens, I also have access to all of the information about you from your FLoC categories, for free.
On some level, Google is taking a gamble that users will be difficult to fingerprint or identify using FLoC so it won't matter that some sensitive information is leaked. But it's just not the case, users can be fingerprinted. And in scenarios where they are fingerprinted/identified, FLoC provides a much more complete picture of that person based on activity from sites that might not have ever sold that information, that might have never intended to leak information about them in the first place.
FB and google used to (idk about now, don't care to check) allow you to upload data you gathered/bought and use it for tracking.
To prove a point, i created a fb ad to target my parents and family (uploaded their email, phone number, identifiers, interests, locations they frequent - only data i knew fb already had) and watched as their ads became "hey vineyardmike's parents. the internet is not private".
FLoC is fundamentally is a proxy for your aggregate browser history which is something that hasn't really be exposed before.