New in Chrome 113
developer.chrome.com
developer.chrome.com
It used to be you could just "clear your cookies" and you'd have a virtually clean identity on the internet. Now basically every ad platform, including Google Ads, is heavily encouraging the use of "first party data" - aka name, email addresses, phone numbers, mailing addresses - as a way to target customers. Google Ads help docs specifically cite the phasing out of cookies as the reason advertisers should send Google as much "first party data" as possible.
In effect, that means "clearing your cookies" will do nothing if you're the average Google users who's still logged into chrome/google after clearing your cookies.
And instead of Google + ad networks just having your data in cookies, now they have your name, email, mailing address, zip code, etc provided to them on the backend with no way for the consumer to easily opt out or delete their data.
Edit: adding another supporting example: for advertisers tracking conversions, it’s no longer good enough to just fire a conversion pixel on a checkout page. Now it’s heavily encouraged to send the user’s personal data (email, name, phone, etc) along with the conversion pixel/tag so Google (or whatever ad platform) can match the conversion to clicks without cookies at all. This type of conversion tracking was not pushed or encouraged until browsers started phasing out 3rd party cookies.
Edit 2: Google has even gone as far as adding a setting to their AdWords tracking tag that automatically scrapes the HTML of a page in search of anything that resembles a user’s email address or phone number to make it easier to collect first party data automatically.
> Google has even gone as far as adding a setting to their AdWords tracking tag that automatically scrapes the HTML of a page in search of anything that resembles a user’s email address or phone number to make it easier to collect first party data automatically.
Really? Link?
https://support.google.com/google-ads/answer/10763826?sjid=1...
The help docs are a bit cryptic, but the UI within Google Ads is a lot more straightforward in how it works. It searches the landing page for an email address to automatically pair with a conversion event. All the advertiser needs to do is accept some privacy policies and enable the feature.
I definitely did not consent, in fact I go out of my way to tell companies I give such information to not to share it with anyone.
I'm curious, would you purchase a membership to youtube if it included absolutely no tracking, sharing of first-party data, or advertising at all?
Now without cookies, you typically want to share email, phone, zip code, etc in order to do remarketing without 3rd party cookies.
No ephemeral 3rd party cookies = ad platforms rely on user data that never changes (email addresses, phone numbers, etc)
I agree with your advertisement of your viewpoint.
It seems like they're just trying to remove any distinction between 1st and 3rd party cookies at all.
Non-goals: ... Information exchange between unrelated sites for ad targeting or conversion measurement.
To get something onto the list (https://github.com/GoogleChrome/first-party-sets/blob/main/f..., currently empty) you need to make a public PR with rationale (https://github.com/GoogleChrome/first-party-sets/blob/main/F...). It doesn't look to me like DoubleClick would qualify?
Quite literally the same company is trying to neuter adblocking with Manifest V3 right now and pitched it as "improvements to security."
Google’s changes only affect people who use vanilla Chrome. And the people who use vanilla Chrome without any privacy extensions don’t have much privacy to begin with, so First Party Sets does not make things much worse than they already are.
If all you want to do is blocking cookies, why would you use a browser extension for that? Most browsers ship with a configuration option to disable them.
For Chrome/Chromium it's over at chrome://settings/cookies
To avoid breaking sites that cease to function without cookies. EFF's Privacy Badger is pretty good at this and it allows you to select individual domains in the popup to add or remove the ability to receive cookies.
DoubleClick is hard coded into every Chrome browser :) [1]
[1] https://chromium.googlesource.com/chromium/src/+/e51dcb0c148...
Blocking third party cookies is great, but with these "Third-Party Sets", self-appointed gatekeeper Judge Google (Judge Dread) takes requests from website owners for lists of domains they control to be partially exempted from these third party cookie restrictions.
Instead of making third-party cookies obsolete as is one of the exclaimed goals of the broader initiative, they turned it into an insidious and opaque tool that lets them increase their insight, influence, and control over the web and all its users even further.
This is bad for both advertisers and their prey alike.
Addendum: Getting rid of third-party cookies whilst not breaking Single Sign-On and similar such features could also have been achieved with a user-controlled local browser setting and a new type of permission request popup.
The need for Google to be in control of this is non-existent and the people working there are more than smart enough to understand this. They are playing us all here.
Settings and pop ups mean that users have to understand them - which can be a huge user education challenge. I'm pretty skeptical of the argument that it's simple to add in a new user facing pop up and have the majority of users use it correctly.
Nevertheless: even if a solution turns out to be too difficult for users to understand no matter how you present it (at which point you might want to rethink whether this apparently fundamentally flawed idea should even be implemented at all), violating your users' agency by taking the reigns and obfuscating the whole thing to them is morally wrong and in simple terms: an arsehole move.
I'd see a browser side system that could actually more user friendly and more unified than the current SSO situation.
More specifically, website owners populate /.well-known/first-party-sets.json for their site and Chrome will always allow those cookies.
Because domain owners use /.well-known/first-party-sets.json, others can also scan for that themselves and perhaps build an independent repo from spidering.
Sounds like most of the laws passed in my lifetime
Literally. Lol.
Instead of direct JavaScript includes I now recommend just putting it in an iframe and I share example code on the homepage.
This lets me still update the script while also ensuring it can not access cookies or other things in the main page context.
What do you think?
Wrapping the script tag in a iframe does not accomplish this as far as I can tell.
So the iframe sandbox deals with the security issue is a different fashion.
Also the iframe can not block the main pages so it has even less impact on the main page experience.
This is as secure now as the majority of ads served on the web.
---
EDIT: That might have been too cynical. Let me take another stab:
That opens up some cool new possibilities, but also a seemingly large new attack surface.
Does anyone know what's been done to mitigate it?
The mitigations, however, feel rather light given the exposure.
Would it make sense for GPU access to be a permission that users have to explicitly grant?
They've restarted actively advertising their browser on Youtube, and now random releases are getting to #1 slot on HN.
I'm guessing this is having to do with Edge gaining popularity?
Google can only funnel people to Google Search with Chrome and first party Android. If Chrome falls, they're in a precarious position.
Google is being IBMified right now.
Haven't the responses already been handled? Assuming no time travel, it's not clear what actually happens after you edit a response header.
If they integrate request header modification, we can get rid of cookie tools and plugins such as ModHeaders.
This is a really great dev experience improvement.
https://developer.chrome.com/blog/deps-rems-113/
Does that mean there are no changes here?
Ridiculous.
Am I correct in my understanding that this basically undermines a user's choice to block third party cookies? Because a third party cookie is a third party cookie no matter how much icing you dump on it.
I hope this is an option that can be disabled or is separate from the current blocking of all third party cookies.
This is intended to deal with several technical challenges (https://github.com/WICG/first-party-sets#use-cases), such as the technical challenge that when company A buys company B, the process of fusing the auth rules so that being logged into A implies a login to B is a colossal nightmare project under first-party-only rules. So, for example, this lets Facebook declare that instagram.com is in the same FPS as facebook.com to simplify the auth story. What it should not allow is for joe-random-domain.com to declare that the DoubleClick ad endpoints are first-party to them.
But it lets Google declare that doubleclick is part of them.
Like I don't like tracking either, but this is kind of the point of the first party thing. They're clearly the same party.
From poking at https://github.com/GoogleChrome/first-party-sets/blob/main/F..., it looks like at a minimum, a given domain can only belong to one FPS, and needs to be preregistered publicly.
That makes the opportunities for abuse much more limited. And the "service-domains" (intended for things like auth or CDN that want to be isolated) have some reasonably strict automated checks (github.com/GoogleChrome/first-party-sets/blob/main/FPS-Submission_Guidelines.md#subset-level-technical-validation), while you're limited to 3 "associated" domains.
This just allows you to do that while maintaining security boundaries around things like user generated content (e.g. facebook.com vs. fbcdn.net).
This doesn't allow some random site that uses third party ads to allow doubleclick cookie access, or vice versa.
(New Tab Promos are the stupid one-line blurbs that come up under your website list on the new tab page that "you won't see THIS SPECIFIC message again" when you dismiss. Please respect my decisions, I should be able to say "I don't want to see these at all".)
[1] https://bugs.chromium.org/p/chromium/issues/detail?id=134746...
edit: correct URL
https://bugs.chromium.org/p/chromium/issues/detail?id=134746...
What still galls me is that instead of doing the right and reasonable thing and making a feature flag (and adding some indication that you're over their arbitrary limit) they did the bare minimum possible short of nothing at all, replacing one arbitrary mobile limit with the arbitrary desktop limit. And their communications on this? tumbleweeds pass by...
This still hasn't dropped for Android so there's no way to test it out fully yet, and if you're a user with over 100K bookmarks? Too bad, so sad, apparently.
Once Android chrome is out with the update, I'll start looking at other browsers and bookmark options.
>Can not create WebGPU Device and/or context.
Oh well.