Chrome now tracks users and shares a “topic” list with advertisers
arstechnica.com
arstechnica.com
chrome://settings/adPrivacy
and turn off the toggles on each of the three subpages.Alternatively, go to this URL https://www.mozilla.org/firefox/ to fix this permanently.
Does this make any difference at all to the tracking?
But hypothetically if Google stopped contributing to Chromium the project would be forked and it would live on. Frankly, Google removing themselves from Chromium would fix the one major complaint a lot of people have with it.
Everybody just gives up at the slightest inconvenience and uses Chrome.
It's not even that much work to just use Firefox.
Keep up the good fight.
Completely immune from this and you don't need to worry that toggle will get mysteriously turn back on.
This isn't iPhone vs Android. This isn't vim vs emacs. You can switch browsers in 5 minutes and never notice any meaningful difference.
Degoogle today.
switching to brave is no better
But, otoh, maybe perfect is the enemy of good here.
I will be caustious with such statement.
https://github.com/patcg-individual-drafts/ipa/
IPA now allows these companies to track users across multiple IP addresses, and regardless of the user's cookie settings, via a unique tracking identifier. It is also proposed that the operating system provides the unique tracking identifier which can then be used by all applications or browsers on a device, allowing different devices behind a single IP address to be distinguished.
Mozilla is one of the authors.
Any more info on IPA? That link doesn't even say what the acronym stands for. I couldn't figure out how it's supposed to work, too complicated. Wikipedia doesn't seem to have heard of it, and a cursory websearch didn't offer an explanation.
> Mozilla is one of the authors.
Mozilla as a company, or is it that there are Mozilla developers contributing? If Mozilla are planning to introduce a built-in tracking system to Firefox, doesn't that imply shooting off your one remaining foot?
So it looks like Interoperable Private Attribution is mostly Meta people; there's one guy from Mozilla, Eric Rescorla. Eric is not notable for adtech achievements; he's notable for his contributions to internet privacy, and security and cryptography.
[Edit] More detail: https://docs.google.com/document/d/1KpdSKD8-Rn0bWPTu4UtK54ks...
Apparently the proposal is to store the match key in browser local storage; which means that you can block it by setting local storage to zero, or by regularly cleaning-out local storage.
That article doesn't mention once the privileges that should be granted to the user. It does mention the powers of the user agent, but that really means the browser manufacturer.
I think Firefox is the least shitty option here.
Using Firefox Developer edition and toggle(s) will get mysteriously turned back on all the time. And Mozilla is not immune to this practice at all for standard Firefox.
Use chromium-ungoogled [1] if you want chrome(ium) without Google-specific stuff.
[1] https://github.com/ungoogled-software/ungoogled-chromium
https://github.com/ungoogled-software/ungoogled-chromium/rel...
https://metadata.ftp-master.debian.org/changelogs//main/c/ch...
There's often days you're going without security patches. If you want a browser without Google tracking, Firefox is a much better choice.
It's difficult to deal with because as the code evolves, so do the configuration settings. The rate of change is high, and it's not always obvious what is relevant to users (and whether a new feature increases or decreases privacy!), so it's hard to communicate this in release notes.
Show someone how to do it, and they can be asked to show someone else
In descending order of significance (i.e. most important objective first):
1. ungoogled-chromium is Google Chromium, sans dependency on Google web services.
2. ungoogled-chromium retains the default Chromium experience as closely as possible.
Unlike other Chromium forks that have their own visions of a web browser, ungoogled-chromium is essentially a drop-in replacement for Chromium.
3. ungoogled-chromium features tweaks to enhance privacy, control, and transparency.
However, almost all of these features must be manually activated or enabled. For more details, see Feature Overview.Harder to distribute than unzip-and-run binaries.
You can't eliminate that anywhere.
brave://settings/system/shortcutsFor me it is better UX.
Mozilla did worse things than brave, at least brave actually does privacy by default rather than just talk about it!
What worse things did Mozilla do?
Embrace: Embrace the open web, create an excellent product and aggressively promote it until you take over the market
Extend: Chrome experiments and advanced features that improve the user experience and developer experience through Chrome only API and Google services. Even provide these services to everyone who wants to use them free or charge so that the user expectations are elevated to that point and web businesses depend on these by building their products around them. Maybe make developers depend on this "topics" feature even.
Exterminate: Cut off or degrade the free services to 3rd party browsers, remove or tame extensions that harm your business and recoup the costs of the free services. Since you no longer have viable competition, reduce the development of Chrome any further, optimize only for profit. Developers who depend on you ad tech can choose to refuse serving users using another browser or opt out of Google verification or account services? The users will stay like they sat with IE.
IE of the 2020s.
Try Chromium?
Decide the site is too much hassle and back away?
Not always practical options, but they are options.
My personal answer to the goalposts in this new position: If a site refuses to work without a Google account, or if Google Ads are blocked, or without some other Google service, they are simply making it clear that I am not the target audience for their broken creation and I should mosey on elsewhere. Much like sites that refuse to work because my stalker blocking measures at home block their adverts (accidentally or, more likely, because those ads are from source that is trying to stalk me across the Internet).
As I said above: this attitude might not be practical for all, or for some all of the time. But it hasn't done me any harm thus far.
--
[1] I switched to Chrome a few years ago when FF went through a period of being unstable²
[2] and because certain extensions didn't have good FF alternatives, because they never were or because some were crippled by the changes in ~2017³, but that latter point is fairly moot as Google is now taking their turn to work towards crippling useful extensions
[3] at least FF's change here were mostly due to massively misreading the room while trying to streamline their platform, where Google's seem to be more malicious when you consider most of the affected extensions are ones that go against their primary business of tracking people & selling adverts.
[4] things breaking after updates, periods of general instability, not keeping up in the performance race for a while, etc.
The deception is to make people believe that studying them as ad targets through their internet use can be "private". Many will believe this nonsense. Including regulators. "It's OK, folks. Privacy is preserved." Green light to keep on tracking, collecting data and serving ads.
But the study of people's internet use to enable programmtic advertising _is_ the problem. There will be more ads. They will be more personal. The www will become even more annoying. Perhaps moreso than any other medium that has come before it.
To Mozilla, there can be no www without advertising. The truth is that there can be no so-called "tech" companies, monopolisng intermediaries, without programmatic internet advertising. The www does not need it and the original www did not have it.
First Mozilla partners with Yahoo. Then Google. Perhaps Meta will be next. Mozilla is no different than so-called "tech" companies in at least one regard: it cannot find a "business model" besides internet advertising.
https://analyticsindiamag.com/despite-clashes-in-the-past-mo...
https://www.adweek.com/programmatic/ipa-the-meta-and-mozilla...
https://www.admonsters.com/eletters/mozilla-and-metas-ipa-fr...
This article has multiple problems:
1. Privacy Sandbox is a project, consisting of many proposals. To pitch it as some cohesive product is misleading.
2. Related: FLoC and Topics are completely separate things, aside from existing under the same project.
3. Topics is reducible to (implementable using) third-party cookies. While the proposal has issues and doesn’t resist tracking as well as Google claims (see below article), Ars’ implication that this is somehow making Chrome less privacy-preserving is patently false.
That's not an option now thanks to multiple antitrust regulatories. Google actually tried to get rid of 3p cookies to use it as an advantage against competitors as well as privacy friendly PR but this has been blocked. One example from CMA (but not limited to): https://assets.publishing.service.gov.uk/media/62052c52e90e0...
It's certainly interesting. The CMA seems to be attempting to balance interests of multiple parties, including both user privacy, healthy competition in the ads space, and the ability for digital publishers to generate revenue from displaying ads.
However, most of it appears to focus on the way Google's superior access to information could distort competition. It's not just about cookies. For example. Google could mine synced history data from Chrome.
Now, I'm not so naive as to think this would actually happen, but again, the Ars author's solution here could solve that particular problem: If Google ceased all behavior-based advertising in favor of, for example, subject-based advertising, there would be no distortions to competition. Google can't track you, and neither can other advertisers. Everyone has a level playing field.
Of course, that would drop revenues for digital publishers and advertising networks, including Google, but it would solve the problems of user privacy and distorted competition.
The one thing this ruling makes very clear though, is that it's very difficult to balance these concerns while Google makes a browser. There's a conflict between Google running a behavior-based advertising network and shipping a browser, and these regulatory bodies seem to be bending over backwards to try to find a solution where both of these things can exist. They could most certainly have taken the much easier road of forcing Google to discontinue Chrome.
Regarding the "easier road" of having Google discontinue Chrome: WTF That would not be easier and would affect so much more.
But I was a bit imprecise with my language there. There are other regulatory remedies to a ruling like that besides discontinuing Chrome. For example, it could be spun off into a separate company, one which does not share any data with Google.
As for the fantasy scenario where Google stops behavior-based tracking, reading that ruling, I think they could get away with it, but there would be some grumbling. Let's say Google stopped tracking on its end, and then six months later, decided to block third-party cookies by default. Regulators could insist that Google keep third-party cookies on, but what leg would they have to stand on? Yes, it would affect their competitors in a big way, but it wouldn't give Google a distorting advantage over them.
And with every other browser blocking third-party cookies, if regulators tried to force Google to keep them, Google could just stop developing Chrome. Without behavior-based tracking, they have no business reason to develop it anymore, and how could regulators possibly say, "You have to keep making a browser, even though your competitors don't"?
That still doesn't work. Google already has built dominant ad network/serving infrastructure as well as exclusive access to billions of its first party user data which gives asymmetric power to Google against any other competitors. Probably the only advantage that those competitors have is their own "secret sauce" on user data and removing 3p cookie effectively eliminates this edge and gives Google unilateral power.
The core problem is that privacy and antitrust regulations usually don't work very well together unless it's carefully designed. EU tried it for GDPR (which took 4 years to design) and it only has strengthened big-tech's position.
> They could most certainly have taken the much easier road of forcing Google to discontinue Chrome.
It's much easier said than done. What's the legal basis of doing this? The only applicable law is too general and requires intervention from the Judiciary. And this level of landmark antitrust cases usually takes several years with extremely high level of uncertainties. And it's worth noting that the US congress has failed to introduce a basic level of digital antitrust laws such as AICOA or OAMA, so good luck with any new direct regulations.
And even if assuming that everything works in your favor, the result is almost guaranteed to be other big guys (likely MS) taking the share and doing something worse since the market is already strongly incentivizing this behavior. To apply the same "correction", it will take another multiple years of trial against more well prepared defendant. Regulators and legislators are not that dumb and they actually care about all those unintended consequences.
I mentioned this in another reply, but I was imprecise with my language here. I meant that regulators could decide it's not OK for Google to have both a dominant ad network and a dominant browser. Discontinuing Chrome would be one remedy here, but there are also other remedies, such as spinning off Chrome development to a separate company.
As for the legal basis for doing that, I'm not as familiar with UK or EU law as I am with US law, but this was in response to the linked UK ruling by the CMA, where I was expressing my awe at how much effort they were going to in order to try to balance competing interests. I don't think regulators are dumb or lazy, but the report very clearly identifies that the core of the problem is that Google has both a dominant ad network and a dominant browser, but they still went through a lot of trouble to try to find a workable solution.
As for US law, Judge Jackson did rule that Microsoft should be split into two separate companies, one for the OS, and the other for apps, but was overruled on appeal. However, that appeal was muddied by other issues as well, and the case never came before the Supreme Court.
You're right about the US congress, but Europe does seem more eager to go after big tech companies.
Google is a corporation that does terrible things. That's not bias, it's observation.
Having said all that, what were his half truths and incorrect claims on passkey? genuinely interested to educate myself.
is the article. The title is already misleading - Google doesn't support passwordless account, and there is no way to get a passkey only account. So factually incorrect title. Anyway, read that and contrast that with:
https://arstechnica.com/information-technology/2023/05/passw...
As an aside, I think this is the source of his confusion about password-less accounts. From Google's help page:
> When you create a passkey, you opt in to a passkey-first, password-less sign-in experience
That comma right there reads; "you opt in to a passkey-first _and_ password-less sign-in experience". I understand what they mean, but that kind of marketing speak is often misunderstood by more technically focussed people.
> 1. Privacy Sandbox is a project, consisting of many proposals. To pitch it as some cohesive product is misleading.
Look, that’s how Google are branding it. It’s an initiative which has turned into a cohesive brand. Just look at how https://privacysandbox.com/news/privacy-sandbox-for-the-web-... speaks of it all. That’s pretty much how it’s being presented in the browser, too.
> 2. Related: FLoC and Topics are completely separate things, aside from existing under the same project.
They’re about as completely separate as Chrome 17 and Chrome 117, or StarOffice and OpenOffice.org. OK, these are both very imperfect comparisons, but although FLoC and Topics work in somewhat different ways, Topics is for all practical purposes just a fork that continues FLoC. They even treated it that way in the browser (at the time at least, no idea if it’s still so). https://en.wikipedia.org/wiki/Federated_Learning_of_Cohorts#... seems overall a fair enough portrayal. They simply rebranded the basic concept.
> 3. Topics is reducible to (implementable using) third-party cookies. While the proposal has issues and doesn’t resist tracking as well as Google claims (see below article), Ars’ implication that this is somehow making Chrome less privacy-preserving is patently false.
The first and last claims here are obvious nonsense. Third-party cookies only let you track stuff where your code runs, whereas the Topics API uses the entire browser history, so it’s not reducible to third-party cookies unless you mean something very different from me by that word. Ars’ implication is by no means patently false; as far as the current status is concerned, where they’ve added this and not removed third-party cookies, it’s patently true. In the longer term, it’s less clear, better in some ways and worse in others, but “patently false” is still an unreasonable characterisation.
It doesn't use the full history. If a site is using the Topics API it will only get back topics that it has observed from sites in the last 3 epochs. For site X to observe a topic from site Y. Site Y must either:
* Be site X
* Embed site X in an iframe on the page with a special attribute on the iframe element
* Send a fetch request to site X with a special header and site X must respond with a special header
Which makes this useless from advertising point of view. Which also means that Google is using the whole history to come up with "rough tooics".
Let's see:
--- start quote ---
With Topics, your browser determines a handful of topics, like “Fitness” or “Travel & Transportation,” that represent your top interests for that week based on your browsing history.
https://blog.google/products/chrome/get-know-new-topics-api-...
The browser observes and records topics that appear to be of interest to the user, based on their browsing activity.
https://developer.chrome.com/blog/new-in-chrome-115/
With the Topics API, the browser observes and records topics that appear to be of interest to the user, based on their browsing activity. This information is recorded on the user's device.
https://developer.chrome.com/docs/privacy-sandbox/topics/ove...
--- end quote ---
> API callers only receive topics they've observed
> A design goal of the Topics API is to enable interest-based advertising without sharing information with more entities than is currently possible with third-party cookies. The Topics API is designed so topics can only be returned for API callers that have already observed them, within a limited timeframe. An API caller is said to have observed a topic for a user if it has called the document.browsingTopics() method in code included on a site that the Topics API has mapped to that topic.
Edit. Literally last link:
> Map browser activity to topics of interest. With the current design of the Topics API, topics are inferred from the hostnames of pages the user visits.
Whereas the description clearly states that topics are derived from the entire browsing history, and they will get topics derived from the test of the history because while coarse, there are still a bunch of them.
A site with a narrow site like a site on fresh-water aquatic plants will probably only get a handful of topics. What will Amazon get? Or Google for that matter? Or a news site? Given that they are likely to "observe" every single topic?
The way that the Topics API works is that a website that could have set a third party cookie will instead be able to observe a topic, and will then be able to get that topic in the future.
That's true, or rather no site gets access to the full history, or to topics that are derrived from the full history, but only to that part of the history that it "observed".
> a site X won't get topics derived for site Y
Unless site Y allowed them to, which of course site Y can also do by allowing them to set a third party cookie.
A site observing a topic in the last 3 epochs unlocks the ability for document.browsingTopics() to return that topic from your top 5.
Every epoch each site has a 95% chance to be assigned 1 topic out of your top 5 topics and a 5% chance that it is assigned a random topic. When browsingTopics is called it gets the topics it was assigned for the last 3 epochs. Real topics are not returned if the site did not observe that topic in the last 3 epochs as mentioned in the previous paragraph.
This is false. Topics only allows ad trackers to see topics associated with sites they were embedded in. In this way, topics is reducible to TPC.
But it seems this comparison to third party cookies ignores the fact that now one company, Google, gets a maximum amount of tracking data without having to cooperate with any other entity. That potentially could be a loss for privacy because the concentration of personal data at one entity, i.e., Google, requires less cooperation, e.g., data sharing. It's easier.
Yes, but aren't 3rd party cookies going to get banned? That seems to be the common assumption in the adtech space. If that's true isn't topics just google's mechanism to continue the kind of tracking that lawmakers are trying to ban by banning 3rd party cookies?
Moving that tracking directly into the browser seems like a cheap attempt at trying to bypass the GDPR.
[1] https://www.mckinsey.com/capabilities/growth-marketing-and-s...
[2] https://www.forbes.com/sites/theyec/2022/09/12/the-slow-deat...
[3] https://blog.hubspot.com/marketing/third-party-cookie-phase-...
[4] https://www.marketingweek.com/death-third-party-cookies-goog...
[5] https://www.techtarget.com/whatis/feature/The-death-of-third...
Since none of your links provided any evidence for this, I'm going to guess that the waste swathe of material doesn't actually exist.
"If that's true isn't topics just google's mechanism to continue the kind of tracking that *lawmakers* are trying to ban by banning 3rd party cookies?"
If you really didn't think you were talking about lawmakers but about big tech (seems like an odd mistake), you could at least have replied right away that you had no idea of why I was bringing laws up. Would have saved us both some time.
Disclaimer: I work for Google but my opinions and web crawling abilities are mine and mine alone.
Even with 1st-party cookie jar isolation?
But the alternative that the people who are against it are proposing is either to keep the status quo or kindly ask Google (and other ad companies) to stop existing, which is not gonna happen. They seem to ignore the fact that ad-tech is a huge industry and a large part of the internet relies on it. Basically the only way to make it go away would be to outlaw it.
(Also so nobody accuses me as being pro-ads: I hate ads and tracking, but sort of in a way like I hate being sick. I can reduce my exposure to ads and tracking (adblock, not using certain apps, etc.), but I know that complaining about it won't make it go away)
I hope it gets implemented because it will give significant ammunition to us in Europe to make server-side behaviour tracking marked as unreasonable under GDPR provisions.
This will make it much easier for is to argue that server side behaviour data collection is outright unnecessary and thus illegal for many ad services.
What if the illness you hoped to avoid were leaking all your private behaviours to the world as though the sickness were the proper state of existence?
> ad-tech is a huge industry and a large part of the internet relies on it.
The Internet is not going away and advertising is not the Internet that we want.
Not necessarily. It will also go away - or more usefully, change its behaviour - if its current model becomes less cost effective. Apple restricted what apps could spy on and Facebook complained like a spoiled child but the sky did not fall. The evidence of effectiveness for all these tracking-based "personalised" ads is limited at best anyway. If you're running a search engine where users have literally just told you what kind of thing they're interested in right now or you're hosting videos where you know which video a user is about to watch or you're serving ads to be included within someone else's web page and you can tell what the content of that page is then you already have very useful information to help you choose which ads might be relevant without needing any additional user tracking at all.
Context-based advertising, AKA “advertising”, has been around forever, and respected privacy to the extent that Gatorade only needed to know that people at gyms might be thirsty. Still sold a ton of slightly salty sugar water, and didn’t even suggest that they should be allowed to rummage through every customer’s gym bag, follow them home, take notes on their dinner choices and television habits, watch them sleep while taking their pulse, and then slip random notes to them throughout the day reminding them that their electrolytes were dangerously slightly on the lower side of average (code RED).
I got the actual update today on my work laptop and… just wow. How did the folks at Google ship this with a straight face? The changeboarding modal basically lies to your face.
I’ve always felt a little weird about Google’s tracking, but this takes it to another level. Creepy as heck.
(Related, comments by both of us within https://news.ycombinator.com/item?id=36713737 two months ago.)
Whether you're convinced or not, this is the reality. Antitrust regulatories have done their homeworks and made it clear that Google alone cannot deprecate 3p cookie.
The linked document is about _replacing_ 3pc,not simply eliminating them, which seems a crucial distinction.
3.34 The Privacy Sandbox Proposals aim to replace TPCs with alternative solutions, while leaving first-party cookies unaffected. TPCs are currently the principal means of achieving common identification of web users on web pages and are therefore a fundamental building block of the open display advertising used by publishers and ad tech providers. While publishers and ad tech providers depend on TPCs to collect information about web users and provide it to advertisers to target advertising and carry out related functionalities such as measuring conversions, the CMA is concerned that Google could use first-party cookies to perform these functionalities in competition with publishers and ad tech providers.
3.35 Although rivals can also use first-party data to provide digital advertising services (as the CMA found in the Market Study), their reach and the quality of their data is in many cases much more limited compared to that of Google. The extensive reach of Google’s user-facing services and its ability to connect data with greater precision (because of its large base of users logged into their Google account) provides Google with a significant data advantage over others.
Because Apple is not running competing ad network. Their only ad network is running on their own app store. Apple does not get any competitive benefits from 3p cookie deprecation for its ad networks.
> The linked document is about _replacing_ 3pc,not simply eliminating them, which seems a crucial distinction.
I don't know why you're getting the impression that the doc is only about replacing 3pc, but Google which tried to remove 3p cookies drew significant attentions from competing ad network and eventually antitrust regulatories. I know this since some of my work closely depends on this timeline.
When all other browsers disable third party cookies, everything is fine. Apple for example has disabled it for years. When Google does it, antitrust regulators fear that this could benefit Google ads more than non-Google ads. Hence this bullshit to "restore competitiveness" between Google and non-Google ad networks.
My recommendation is to both disable third party cookies and this new thing. You don't need either of them.
This is definitely what Google would like you to believe. Considering indeed all other browsers have killed third party cookies, Google legally very well could as well. But they'd love you to believe they must provide a way to invade your privacy.
The issue regulators had was Google retaining special access to user tracking, they have no problem with Google removing their own ability to track as well. Of course, that doesn't buy Larry and Sergey's next yacht or private island remodel.
I don't think you understand the issue. Without third party cookies Google still has search ads while adtech competitors without a search engine are decimated. That's the antitrust concern.
then you will see random low quality ads instead of something you may be interested in
There were news already that they block people from playing youtube videos if they blocked ads.
I'm certain a company could convince me to buy a new mechanical keyboard or nice mouse or some app I don't need but that looks pretty cool. That kind of targeting might just separate me from my money. On the other hand, no one's ever going to convince me to buy any brand of tampons.
Oh wait, I use uBlock Origin, so this doesn't affect me at all! I'm stealing all that data from servers that give it to me when doing an unathenticated GET.
I'm sure they track me nonetheless, but it's a bit less.
Who says that, google?
To make an analogy, don't believe any EU country government when they blame some EU directive for a new law.
Then neo-liberalism took over and they took a page out of the US’ playbook, and started prioritizing businesses.
But unlike in the US they aren’t comfortable outright stating that they’re prioritizing business interests over consumer interests, so instead they do this weird thing in their communications where they act like they’re standing up for small businesses. Problem however is that their definition of “small” business is everything below a trillion euro market cap.
It’s kind of jarring really, to hear them talk about having to protect those poor advertisers, like it’s some UNICEF donation ad.
You have been doing 60-70 hours a week for a few years at startups that never took off. You tried to go into some big companies but got rejected several times. You managed to pass the first screening to the process at being hired at Google. You go through all the process. It’s long and tiring. Somehow you went through it after several weeks and so many steps. After several years in your career of not so successful job/startups this is like a huge thing. You can say to all your family and friends and girlfriend that you work at Google. The pay is great but the work is bad. They ask you to code more stuff to track people into Chrome. You evaluate what quitting would be like and what other opportunities like this you could have. And then I guess they are like hmm no. Let’s code this things from now on.
In just about any other context this is called a bribe. But you're right. If that person doesn't do it, someone else will.
It’s impossible to say for sure, but there’s a certain pervasive collective worship of these employers that will just not quit.
Four years is probably optimistic, unless you got lucky with stock growth.
I searched for "average cost of living map" and found a site[1] that says cost of living at Santa Clara County is $138K. I then did a search for "average salary at Google" and one website[2] says it's $124K, which suggests saving enough money in 4 years on salary alone would be difficult.
You might think that working for Google while living somewhere outside of Bay Area would be a good way to save, but because compensation is dependent on where you live, this doesn't always work out.
[1] https://www.epi.org/resources/budget/budget-map/
[2] https://www.payscale.com/research/US/Employer=Google%2C_Inc....
> The cost of living for a two-parent, two-child family
The typical case is more likely single or DINK.
Manage the money well, throw in a couple of bonuses and a favorable liquidity event around y4 and it's plausible enough to become a motivator or rationalization, I assume.
The average salary for a mid-career engineer at google is north of $300k if you assume no stock movement.
That's my observation as well. And I think this applies especially to Google: for some reason it still has the reputation of this cool tech company here on HN, even though it's an advertising and user tracking/profiling company at this point, and there is really nothing "cool" about it anymore. But criticize Google on HN and you'll get downvoted really quickly.
It’s a pretty large absolute number of people, although thanks to section 1 clause b, it’s growing smaller.
YMMV, but “people who worship recent FAANG employment” can be a filter that’s positive to apply when seeking employment.
Now you have it both ways. You have the resume prestige of working at Google and the faux prestige of being a "virtuous person" who is willing to forgo the comfy Google life to "do what is right."
Switch to a better browser.
In the end, I reverted to clicking the non-primary button (which you are not supposed to click) and checked in the settings everything was in order.
Modern adtech can track users regardless if cookies are enabled or not, and whether they enable this new Chrome feature or not, via browser fingerprinting. They've been doing this for years.
So this new "privacy sandbox" is a diversion to the public, and particularly to law makers, that signals "see, we care about user privacy". When in fact it ultimately makes no impact on their revenue.
The public and law makers are barely starting to get an understanding about cookies, and there's a growing concern about them, so this is Google being proactive towards the blowback. Fingerprinting is much more complex to understand, and concern about it is so under the radar, that it will take many more years for the focus to catch up to these nefarious practices.
The frog is being boiled[1], make no mistake about that.
Not sure what the point you're trying to make is.
Also, Google under Privacy Sandbox has been exploring ways to introduce a fingerprinting limitations and a budget. Which may as well be smoke and mirrors, but if you watch their marketing materials, they talk of fingerprinting in general.
(a) Consent
(b) Contract
(c) Legal obligation
(d) Vital interests
(e) Public task
(f) Legitimate interests
What a lot of companies are trying to do right now is weasel through under "legitimate interests" (eg a lot of scumbag seo-monkey websites have cookie consent dialogs stuffed with "legitimate interest" switches even though that doesn't work the way they think), but it's not clear that "improving my services at the expense of people's privacy" would pass the "legitimate interest" test if that ever goes to court. Legitimate interest requires them to pass "purpose", "necessity" and "balancing" tests. The "balancing" test in particular balances the companies interests against the interest of the user in maintaining privacy. Here's more about "legitimate interest" under GDPR.[2] it's not the get-out clause that people seem to think.
[1] https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-re...
[2] https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-re...
My hope is that with recent rulings against Google, Meta etc. we might see an improvement across the board. Like there's some improvement with reject buttons: https://noyb.eu/en/where-did-all-reject-buttons-come
We can't assume good will and behavior from an industry that is built on deceiving and manipulating the user. The GDPR is a good first step at regulating these practices, but it's too vague, and it's applied far too leniently. It also obviously only applies to EU citizens, and not to the global industry.
I wasn't familiar with the privacy "budget", but it sounds like Google is trying to define privacy as a scale, where some amount of fingerprinting is OK. Users can be identified with just a few data points, and some are more valuable, depending on the context. Some might even be required for the site to function, so will there be "legitimate" exceptions to the budget in those cases? It sounds like a backwards approach that will be difficult to manage, so I'm not sure it will be a win for protecting privacy.
More importantly, I don't trust that an adtech company will go out of its way to implement solutions that go against its bottom line. These companies have a track record of abusing user data, and the only reason they take these initiatives is for good PR, which is again protecting their bottom line. The entire industry needs much broader and stronger regulation for any of this to actually improve.
You're moving the discussion towards law enforcement.
Well, DPAs in EU are overwhelmed, but lawsuits and rulings are progressing. For instance, Facebook found out that they can't force behavioral advertising via their ToS or via legitimate interests:
https://thisisunpacked.substack.com/p/the-eu-war-on-behavior...
I'd also add that small companies may fly under the radar, but big companies like Google and Meta are big targets.
One of the explicit goal of "privacy sandbox" is preventing browser fingerprinting by limiting informational entropy from user environment. https://github.com/mikewest/privacy-budget
For anything “privacy tech” you must divorce the adversarial case (an actor maximizing an attack vector) with the average case (a monopolistic company using the tech to control overall opportunity costs). The latter has under-funded public study because Google et al will both throw gobs of money against it and throw shiny privacy tech problems out there to distract researchers.
Additionally fingerprinting is not a tactic that advertisers want to use - anyone spending real money bets their vendors and wants to stay away from sketchy bs vendors who do that. Google doesn’t want it, TTD doesn’t want it, xandr doesn’t, cococola doesn’t, Nike doesn’t, etc. We all want a technology that is truly privacy focused for users, but still enables functionality that is critical to advertising like brand safety, frequency caps, and some semblance of targeting (even via context). That doesn’t even get into retargeting/dynamic retargeting.
> there is nothing to match a fingerprint to, so fingerprinting is useless
Huh? A fingerprint doesn't need to match _to_ anything. It just needs to be consistent across browsing sessions for a profile of visited sites and interests to be built.
> Additionally fingerprinting is not a tactic that advertisers want to use
Really? Citation needed. All advertisers want their ads to be highly targeted to a consumer who is most likely to make a purchase. The reason web advertising is much more appealing than advertising in traditional media is precisely because it allows microtargetting on a level not possible via traditional means. Advertisers are always chasing a higher conversion rate, and microtargetting is proven to yield better results than showing ads to a large and generic cohort of consumers. Advertisers aren't happy about the Topics API, and many will choose the technology that allows them to continue to target ads more accurately. Fingerprinting is so far the most foolproof method of doing this, since it avoids pesky cookie blockers, and is difficult to detect.
> We all want a technology that is truly privacy focused for users, but still enables functionality that is critical to advertising like brand safety, frequency caps, and some semblance of targeting
I call BS on the first part. Ad targetting goes directly against user privacy. There's no reconciliation of the two. Advertisers can go back to buying ad space in context-relevant places (e.g. show fishing ads on fishing-related sites), but none of them want to lose a _substantial_ part of their revenue by not taking advantage of user tracking.
How you can be so defensive about this is beyond me, and leads me to believe you work in the ad industry.
Their is a world that is privacy focused and gives advertisers what they need - that’s what the privacy sandbox is trying to achieve. My employer works with Google directly on topics and other solutions to achieve what we want and create privacy.
And you're saying that all of those big brands refuse to use profile data acquired by fingerprinting, even if it would allow them to microtarget their campaigns? So they're essentially valuing people's privacy over their own profits? Somehow I highly doubt that.
I'm not saying that what you're saying is false. I just think that in an industry with highly shady and consumer hostile practices, built on the core ideas of psychological manipulation, that needs to be regulated to stop violating people's right to privacy, and even then finds ways to tip toe around regulations, it's quite unbelievable that all of a sudden they have a change of heart and actually claim to care about consumers. I mean, you're a part of it, so forgive me if I instinctively distrust your claims, and the claims of your clients.
> Literally all of them want privacy focused advertising
So they're running ad campaigns without targeting user profiles at all, in the same way advertising is done on traditional media? Because that's the only "privacy focused advertising". I highly doubt this as well.
Again, privacy and advertising are part of a zero-sum game. Advertising profits increase at the expense of user privacy, and the more targeted campaigns are, the more profitable they are. It would be foolish to think advertisers and adtech companies would be willing to sacrifice their profits out of the goodness of their hearts. This is why we need regulation in the first place, because they're not capable of self-regulation, and will pursue profits at all costs. But this is nothing new, and big business has been exploiting people since the dawn of industry. So please don't try to frame advertisers and adtech as some kind of benevolent actor.
Google's justification for this was after all that it's a nerved alternative to persistent user identifiers (like 3rd party cookies), because you have to give the poor, starving advertisers something in exchange if you take away their ability to identify users.
So far, so bad, but if advertisers can in fact still identify users, then FLoC will just be another, relatively high-quality signal that they can add to the profile. (In fact, fingerprinting isn't even needed yet as Google apparently feels it's fine to activate FLoC long before they disable 3rd party cookies. How that squares with the presentation as a privacy feature is a lection in corpospeak I guess)
So especially in that situation, you should turn off FLoC.
They also need to not make sweeping changes to the ad industry that could be described as anti-competitive or monopolistic. I doubt they'd get away with just turning off third-party cookies in their browser.
Ars seems to be confusing the topics API with the privacy sandbox as a whole. Most features are early, like client hints, while others like privacy budget haven't even been released yet.
And if Steve Gibson is to be believed Topics is not only an improvement, it's an unqualified good. (I'm not yet convinced though if Google didn't have so many other harvesting avenues I'd see it as better for privacy too.)
It's still sending interest information to advertisers, so it's an unqualified negative. Stop sending information to advertisers. Kill third-party cookies, and anything purporting to replace them.
Here you go:
* Arts & Entertainment
* Computers & Electronics
* Internet & telecom
* News
* Online communities
Seems reasonably accurate, but so what? What am I missing?These proposals were made directly because of legislation like GDPR. It's not as if Google got up one day and said "Let's make our job harder."
I don't think I'm in the "privacy community". It's my opinion that advertising will always exist, but tracking is complete horseshit and should be abolished ASAP. I don't think this is a very unpopular opinion either. There seems to be an attempt to Stockholm us all into thinking tracking is a necessary evil we must accept.
For the ads, a large portion of the internet that people want (maybe not you in particular but lots of people in general), run on ads. Arstechnica runs on ads, theverge runs on ads, slashdot runs on ads, the register runs on ads, kotaku runs on ads, tech crunch run on ads. To name a few sites that might be popular here
If those sites can't support themselves they'll more than likely disappear. If all those sites disappeared I feel like plenty of people (maybe not you but more people than not) would realize that they thought they wanted (zero disclose) lead to outcomes they didn't want
I feel like Google is genuinely trying to do something positive here. Provide a way of those sites to still target ads, still check if an ad was effective, still try to check for bad actors making fake clicks, but also be practically un-attributable to a single user.
Going through the actual specs, they really are trying to make it so you can't track and individual but sites can still function based on ads.
Is it in Google own interest? Yes. But it's also in the interest of sites people want which means it's also in the interest of the people who want those sites.
Apple on the other hand, would prefer you be tracked directly by having you download an app for each site where that app can track you way more than a browser with these features can track you.
Newspapers and television (pre-digital) managed to survive just fine on advertising before tracking was feasible. There are also subscription services. Content is not going to simply disappear if tracking goes away. Sites that depend on tracking for their survival will adapt or die, but that's fine, businesses fail every day, and I'm certainly not sympathetic to businesses who depend on what I would call unethical practices.
The problem is when regulators ignore an industry for years upon years (capture). Entire industries can grow out of practices that would otherwise have been restricted. The longer it takes, the harder it becomes to implement sane regulation. Instead we just get used to what's most likely a shittier society (the political impact of tracking and nudging).
The internet I want is one with sites run by individuals doing it because they are passionate about certain topics, NOT because it can be profitable when you slap ads on it. Today, the former has a hard time gaining visibility because the latter has much more incentive to make sure you land on their content farm before other sites. Many people don't even know that the former exist. But that doesn't mean that we need the latter. The internet does NOT depend on ads.
> Arstechnica runs on ads, theverge runs on ads, slashdot runs on ads, the register runs on ads, kotaku runs on ads, tech crunch run on ads. To name a few sites that might be popular here
And Somalia runs on piracy so we need to make sure piracy remains possible? Fuck no. Those sites run on ads because that's currently the path of least resistance. They have alternatives.
> If those sites can't support themselves they'll more than likely disappear.
And for a lot of sites, that's OK. There will be replacements.
> If all those sites disappeared
They won't (at least not without replacement) as long as people have a use for the content they provide.
> I feel like Google is genuinely trying to do something positive here.
Are you perhaps interested in buying a bridge?
> Going through the actual specs, they really are trying to make it so you can't track and individual but sites can still function based on ads.
Anything that supports ads is decidedly bad. Slightly less bad is still bad.
> means it's also in the interest of the people who want those sites.
Nope.
> Apple on the other hand
is irrelevant. I can avoid apple devices but there is only one Internet.
https://github.com/patcg-individual-drafts/topics/blob/main/... https://github.com/patcg-individual-drafts/topics/blob/main/...
https://developer.chrome.com/en/docs/privacy-sandbox/topics/...
- When this was introduced, Google asked my if I permit using those topics. I declined and now in the settings the toggle is switched off, just as it should be.
- Your topics will be listed when you open the ad settings.
- Instead of disallowing topics, you can also block individual topics.
Second, if you have a bunch of parameters attached to you, then you can be tracked. What exactly those parameters are doesn't matter, as long as the set is more or less stable and unique.
Third, do you really want to disclose your interest to every website? Without a way to opt out.
It does matter what is tracked, because advertisers need to be able to match on-site behavior to what they can identify and target in a bid.
You’re not disclosing your interest to every website. Your allowing your browser to store a list of your interests and then advertisers can target users who have those interests. This is miles more privacy focused than the current solution where any vendor can place pixels all over the web to build any audience they want, small or big. They can track really any data they want, combine it with any offline data see they want, and sell it to anyone they want.
When a large, publicly traded ad-company (that relies on collecting data and tracking users for most of it's income), creates a product that costs them quite a lot of money to make, and then gives that product to you for free...
Do you expect them:
A.) to be taking a loss on that product because they really just want to gift it to you from the goodness of their heart with no ulterior motives?
B.) to actually have another way to make money from that product, which makes the whole endeavor financially worthwhile to them?
Has Google benefitted more from other people's open source contributions, or have we benefitted more from Google's open source contributions? The answer is not obvious to me.
If (as was stated) Google's Chrome is based on KDE, than any user of Google Chrome is necessarily impacted by KDE. Meanwhile there could in theory be some user of KDE who has never used Chrome.
So the set of lives affected by KDE is the same or larger than the set affected by Chrome.
KDE never ran any PII data collection programs targeting 70% of browser users, for the sake of selling ads.
Oh you meant impacts positively? No. Chrome is a blight on humanity.
Safari started as Webkit which forked from KHTML which was part of KDE.
The various forks of webkit incl Chrome came later. If Chrome was ever based on webkit, iForget.
Your theory doesn't make any sense since every OS/device comes with a free web browser since I can think.
I also think this recent change sucks so it’s not all roses.
Usability is a very subjective topic, but for me there are things in firefox or it's addons that I cannot have in chrome.
And in the end I need to trust my browser for daily (non-developer) use. Trusting google is naive. I don't say Mozilla is deserving of unquestioned trust either, but out of the two it is the better choice.
In the end my (very subjuctive) judgement is that the performance difference in daily use doesn't outweigh the benefits of not using the browser of the monopolist that makes their money with data collection.
That doesn't mean I don't use the browser or it's engine in other ways tho.
Windows now comes with three built in browsers: IE, Edge(Blink), Edge(Webkit) - none of which can be uninstalled.
Every other update users will bugged about switching to Edge again (exact amount varies by version and locale).
System apps will ignore default browser settings and use Edge to open all links (except in the EU they very recently went back to using the default browser again).
Browser-choice dialogue is gone, instead Edge will pester you if try to use it to download another browser.
Point being, all those punishments did absolutely nothing to stop or curb the anti-competitive behavior.
I'd say that makes it an excellent example because it clearly shows that government enforcement of those rules used to have teeth. But since lost them.
And being a publicly traded company - they would have to shut down Chrome as well, if it actually were unprofitable/not worthwhile.
And they do have the data needed to actually get a relatively accurate picture of how Chrome affects their bottom lines overall. They know what they are doing, giving it away for free.
Without Chrome, Google has no control over its product (your eyeballs as you browse) at all.
I don't mean to trivialize it but it seriously reads like an abusive relationship. Or an addiction or something. Just leave, man.
> Chrome user opinion to them is important to their business in about the same way meatpackers care about what cattle think of the design of the feeding stations. As long as they keep coming to eat, it's just mooing.
If you have to chose one devil over another anyway it becomes easier to put your convenience first and ignore the rest.
Even if you somehow think that Mozilla is as bad as Google, which, to me, is a ridiculous notion, you can still choose the lesser of two evils. At the end of the day Mozilla is a foundation, a legal entity which is driven by its mission[0], and Google is a corporation, a legal entity which is driven by profit and data collection. And there are also tons of other browsers that are less bad than the worst one.
To choose Chrome is, again, to bend over backwards to justify continual use of an abusive tool, in the name of convenience.
How then duckduck go managing to compete with them wituhout collecting data and tracking user to the same extend? https://fourweekmba.com/duckduckgo-business-model/
For example: if you search for "standing desk", it will include one or more paid ads that are keyed for some combination that matches with the search query. Those ads aren't targeted at you based on your gender, or your home address or where you eat lunch on Tuesdays or how many devices you regularly use or any number of other creepy shit Google tracks about it's flock of willing cattle.
Yeah. Things are going great in Chrome world. Totally should give them dominance over the one sliver they don’t control.
(I have no problem with letting people have FF/etc. but let’s face it, it will be 90%+ Chrome within days)
Maybe I'm just an open source purist. However, I will say that in almost all tests with websites I am actually using Firefox is faster.
(Maybe not that much of a purist: I do use Chrome at work as we're using various Google products... docs, meet, etc, and those work better on Chrome. Go figure.)
Firefox has since largely caught-up from a performance perspective, although there is still some functionality inconvenience.
Of course the stated attitude toward the user is night and day - I switched back to Firefox about the same time they started integrating Gmail / Google accounts into Chrome.
When it first came out, it was almost literally Safari (well, WebKit).
I'll admit this traditional installer dark pattern seems quaint compared to what OSes regularly attack users with these days but this was the behavior of most pay-to-pack-in crapware at the time.
Chrome users looked at worse versions of images on the web for years. It is a completely bonkers performance optimization.
Chrome did kick Firefox off in web development tools though, so I can understand some people. But today I don't think there is much difference anymore. I am not web dev though. On the other hand webdevs should know about image quality on websites.
I dare say it's actually a nicer experience overall than Chrome, with the caveat that I haven't looked into battery life impact yet.
In the intervening years I bounced between the two depending on which made the most asinine UI decisions but settled on Firefox when my FOSS sensibilities and distaste for Google hardened.
1. Upgraded manually from 116.0.5845.179 to 116.0.5845.180 through About dialog.
2. Restart. No notification that anything has changed.
3. Go to settings, privacy and security, privacy guide, and on the 4th page (only 3 pips!)
Or go to settings, privacy and security, Ad privacy (the new element)
4. The privacy guide blurb: Privacy Sandbox trial
Chrome is exploring new features that allow sites
to deliver the same browsing experience using less of your data
Under Ad privacy:
5. Ad topics: Site-suggested ads.
Based on your activity on a site. This setting is on.
6. Site-suggested ads.
Based on your activity on a site. This setting is on.
7. Ad measurement.
Sites and advertisers can understand how ads perform.
This setting is on.
This roll out is filled with dark patterns. At (2) there is no notification that anything has changed. If not for this article, I would not have known about this at all. At (3) the feature seems intentionally hidden. At (4) the description of these features misleads the user that the purpose is to "use less of their data". This is false, or at least badly misleading. At (5,6,7) they've defaulted all new "features" to "on".This is all so shady, and very un-Google like. I have such high regard for the Chrome team: was there push back on this? Do they realize what a bad look this is?
Let's say that they do realize it. The 0.x% of users that are aware of, understand, and will do anything other than just blindly continuing to use the software is an acceptable number of lost users. In other words, everyone reading HN could stop using Chrome right now, and Googs would not notice the blip
Where have you been the last several years?
It's not about acceptance. It's about trust. Trust has two key components:
1) It's earned. Full stop.
2) Regardless of how much trust equity you've built, it can be lost instantly.
Like it or not, this is how trust works. Accepting what Google does is one thing, but at this point there's no reasonable reason to trust it.
This doesn't seem fair to wholly categorize skepticism of Google's motives as an "ideological stance" if Google hasn't demonstrated any willingness to change.
> Enhanced ad privacy in Chrome [this is bold, centered, and larger font]
> We’re launching new privacy features that give you more choice over the ads you see.
> Chrome notes topics of interest based on your recent browsing history. Also, sites you visit can determine what you like. Later, sites can ask for this information to show you personalized ads. You can choose which topics and sites are used to show you ads.
> [a graphic]
> To measure the performance of an ad, limited types of data are shared between sites, such as the time of day an ad was shown to you.
> More about ads in Chrome [V]
> You can make changes in Chrome settings
> ["Settings" and "Got it" buttons]
Clicking the V-looking thingy next to "More about ads in Chrome" expands that to add this:
> More useful ads [that is in bold]
> Sites can ask Chrome for information to help personalize the ads you see.
> • Chrome notes topics of interest based on your recent browsing history.
> • Sites you visit can also determine what you like based on your activity on the site. For example, if you visit a site that sells long-distance running shoes, the site might decide that you’re interested in running marathons.
> Later, a site you visit can ask for this information — either your ad topics or ads suggested by sites you’ve visited.
> Chrome auto-deletes topics and sites that suggest ads within 30 days. Or you can block specific topics and sites you don’t like.
> Measuring how well an ad performs [that is in bold]
> Sites you visit can ask Chrome for information to help them measure the performance of their ads. Chrome lets sites collect limited types of data, such as the time of day an ad was shown to you.
> Learn more about how Google protects your data in our Privacy Policy.
Since when has shady been un-google like? they ditched "Don't do evil" decades ago.
When they reorganized to have Alphabet as a new parent company, Alphabet’s code of conduct said “do the right thing”, but the subsidiary Google that still makes everything we usually discuss as Google kept “don’t be evil” in its code of conduct. At a later point Google did move that sentence out of of the most prominent position in the preamble, but it’s now in the second-most prominent place, right at the end.
But, yes, as I said at the start of this comment, they do a lot more awful or potentially evil things than they used to.
Disclosure: I worked for Google years ago, but I left before all the changes I discuss in this comment and had nothing to do with any of them. I am sad to see Google decline to roughly the level of being at least as ethically good as most of their major competitors, instead of far better as they used to be.
Thinking about it in a very abstract way I find the whole thing fascinating. Google is clearly terrified that the tracking protection offered by other browsers is going to become the norm and they’re trying to head that off at the pass by implementing this compromise. But I’m not sure why they’re all that worried about it, they still have the lions share or the browser market. Maybe they’re worried about incoming legislation?
Of course they can. They just don’t want to.
Google isn't allowed to stop others tracking you without also removing their own ability to track you because that's anti-competitive.
So, what did the regulators actually say, and does it in fact allow Google to turn off third-party cookies without any replacement? If it does, then this is Google's fault for adding this feature in Chrome. If it doesn't, then this is the fault of bad regulation.
So if they are rolling out a UK mandated feature globally there is no question that Google is all for it.
This is a good example of anticompetitive/anti-monopoly regulation not only not protecting consumers, but in fact making things actively worse.
A better regulatory response would have been "having an advertising/analytics product and a browser product in one company is anticompetitive, split one of them into a separate business from the other, and then the browser product must not privilege the advertising/analytics product". Then the browser could, in fact, just disable third-party cookies without giving advertisers and analytics companies another alternative.
In any case, this is still strictly a privacy downgrade to turn on. It's still deceptive to imply turning it on improves privacy.
That’s not true, this new system is a tracker, not tracking protection. Simply turning it off improves privacy.
> this feature increases your privacy when in reality it does the opposite
My clarification is that their new tracking system does increase your privacy compared to the old. It just doesn’t increase it as much as other browsers. We’re not in disagreement about what is better for users.
“If you let me punch your teeth out, the stabbings will stop (sometime in the future, terms and conditions may apply)”
All while refusing to acknowledge that there is an option that requires neither punching nor stabbing.
To an uninformed user that takes Google’s words at face value it sounds like an upgrade.
Third party cookies can do everything the topics API can do and more. Third party cookies lets sites collect granular data about what exact site you on and any data they want from it. This API just gives them some topics which may even be a random chosen one and not a real one.
I never claimed that. The current estimated timeline for phasing out 3rd party cookies as of last month is:
23Q4 Opt in testing for sites
24Q1 1% disabled
24Q2 fully disabled
https://privacysandbox.com/open-web/
> And once Chrome has phased out third-party cookies the topics API will strictly decrease my privacy, not increase it.
You are free to disable topics, sites, or even the entire system altogether. While it does decrease your privacy in return you can get more relevant ads. With 3rd party cookies if you disable them all you will break things even if those things are unrelated to ads.
This is unambiguously a privacy downgrade, regardless of what third party cookies may also be able to do.
If you are blocking 3rd party cookies by DNS you will also block topics too.
Topics is a mess (see a great analysis from a colleague of mine[1]), but it’s a hard sell to call this current step nefarious.
He's faced enormous challenges due to Google's "privacy" policies... Google is removing nearly all access to user data, they don't even like you looking at the user agent string (which issues a warning)... not to mention its impossible to know about search traffic and even referring urls.
Meanwhile Google has access to all this data, so he tells me all this is just gaslighting so they can illicitly protect their monopoly on web data.
I’m loathe the defend Google but I don’t think this is the case. The replacement for user agent sniffing (client hints? I forget) is a universal thing and I don’t think Google has a secret back door tracking mechanism their ad network is able to use. It would certainly be a big story if they did.
Because there are many ways Google can leverage this data without giving their ad network access.
Privacy isn’t just about privacy from ads. There are all sorts of non ad related privacy abuses that can exist.
Like Chrome??
they have 80% population using search, youtube, storing browsing history etc while logged into google account, so they have lots of data about most of the people.
My point is that even this blatant logged in user tracking won’t be able to use user agent strings to track either.
There is no publicly known method by which Google’s ad network is able to siphon extra data from Chrome users for targeting etc. If there is one, as OP’s friend suggested, definitionally it must be secret.
google "has access to all this data" in exactly the same way any other website does. you request the information you need from the client, and the client can choose to provide it or not. clients provide it by default.
hate on google all you want, but UA reduction is objectively a good thing. "my friend jacob wants to slurp up everything from the user-agent string on the first request" is not a good argument.
Or do you mean your friend's product is a browser plugin? In which case, um, yes, I don't want it having access to any more information than it it needs to do it's job (and honestly, probably not even that.)
They (Chrome) are taking it away [0].
[0]: https://developer.chrome.com/en/docs/privacy-sandbox/user-ag...
A lot of sites will break for people as a result, though. Maybe that's what The Google wants, though.
Yeah, it's even spelled wrong!
I would appreciate it if someone explain what other things people do to tackle this, or if I'm completely wrong?
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Re...
"Origin" means no path, so the referer might tell me which search engine the user used, but not what search query was done. It's much better than in the old days, where I might even see someone's session ID in the referer.
I have no doubt Google has self-serving motivations here but the result is still a win for us. I wish Firefox had enough leverage to force decisions like this down people's throats whether they like it or not but it just ain't so. Reality is imperfect so I'll take what I can get.
The best user agent is the one that offers them the fewest identifying bits. In other words, the user agent of the most popular version of Chrome. The ability to set it to "anything we want" is actually a trap. What we really want is for everyone to use the exact same user agent so they can't tell us apart.
If everyone has the same user agent, it's nothing but a waste of bandwidth and it should be removed. Google is actually achieving our objective here.
So sorry, until you pay with a unique individual bank account to prove identity, you can't post on future social media sites. You are a bot after all.
If it's costing you money, have your HTTP server return 402 Payment Required instead of the free page. That's how it should be.
I do not agree that every piece of the internet "should be" behind a paywall because bad actors exist. That world is the literal death of the "open" internet, putting everything behind a paywall.
Not something that should be prevented.
> false information, information manipulation
Not something any one person should be the arbiter of.
> and any other number of malicious inputs that otherwise in a forum for people require trust to maintain community quality
Trust is how you solve this. Forums shouldn't be letting randoms sign up and post. Just like we developers don't let randoms commit to our git repositories.
But they want that mass market appeal, don't they? They want everyone to have input access, to be able to comment and participate. Usually because they're pushing ads and the more eyeballs the better. They're hopelessly dependent on "engagement".
> That world is the literal death of the "open" internet.
Not really. It might mean the death of the "free" internet but not the "open" one. The open internet is the one where we get to use whatever software we want to interoperate without restriction. It's the one where we get to use a Python script to scrape your site if we wish to do so. It's the one where we get to download videos with yt-dlp.
But I do intend to arbitrate if the election information being input from multiple geographical locations is valid data or not. Otherwise I'm not doing the project and the existing system of it only being owned by the largest political parties who have their own organization doing the tabulation. Others who have attempted this work have seen active manipulation campaigns over the course of their validation and speak to the only way to counteract the manipulation was bot control.
I do not want mass market appeal. I want the thing to get adoption for a day by people that would otherwise be casual at best internet users.
> The open internet is the one where we get to use whatever software we want to interoperate without restriction. It's the one where we get to use a Python script to scrape your site if we wish to do so
Sorry, Error 402, please provide payment. You're a bot until proven otherwise.
How are you going to do that?
I live in a country whose supreme court routinely orders censorship of "fake news" and other kinds of "harmful" information, something not seen since the days of our military dictatorship. This year our government essentially created a ministry of truth. They censored "fake news" which literally turned out to be true after our current president was elected, it's comical.
How do you plan on being any different?
> Sorry, Error 402, please provide payment. You're a bot until proven otherwise.
OK. Do you accept credit cards?
The same way it's organized among the political parties. Word of mouth, social media and good will among interested parties who trust each other for a common goal of maintaining democratic principles. I don't come from a country that censors such work. Their main problem is it's all pen and paper by people that are usually schoolteachers and farmers on a normal day and they need the tech help.
> OK. Do you accept credit cards?
No I do not accept credit cards. I'm neither a business nor a payment processor. Please contact the administrator. Don't expect a reply. If you have to cold call, you're not in the existing trusted network where others vouch for additions to the network and will be two-factor geo-IP verified. Good luck with your python scraping in your world.
A good democracy will have access for whoever requests it to validate and learn about their peers more, not forced behind a paywall. Hopefully by enabling my ethos, it marginally feeds towards culturally maintaining that my country doesn't have a Ministry of Truth and other forms of democratic deficits.
A core of Democracy is indeed preventing ballot stuffing when people go to upload the vote results they see. We're just not talking about electronic means than paper ones. You say "me", why is your script different from a Russian-style nation state trying to put weight on the scales? Or trying to DDOS the site? And if you are indeed different, to make the distinction in any way, some form of meta information must be monitored and acted upon. You may be innocent, I can not know that in the technological future you propose. Without information, as per security best practices, the wire defaults to closed, not open. The cost is the loss of ease of use and access, but the data integrity is more important than your scripting convenience. The data can at least represent the historical record. Without that historical record, scripting of false data is worse than useless and actively dangerous and not worth putting into the world.
> You say "me", why is your script different from a Russian-style nation state trying to put weight on the scales?
Don't accept votes from unknown, untrusted randoms. Even in my country where the election is fully digital, they check my ID before letting me vote. There are ways it could go wrong but that isn't one of them.
> Or trying to DDOS the site?
They can't DDoS you if you have them pay for the resources required to serve them.
> The cost is the loss of ease of use and access
That's fine.
Trust can be built from metadata. You stop it from being unknown, by shock, building up knowledge through recording it.
> They can't DDoS you if you have them pay for the resources required to serve them.
Not a payment processor. Not a business. Nobody is going to pay for membership. This is not on the table.
> That's fine.
I deeply disagree and you're not changing my position on that nor am I likely to change yours. But I'm the implementer, so guess which way it's going. See: Not accepting your money.
What I have though gotten out of this conversation is that I'm now aware of how much more complex feature set I need to put into the first party tracking to get it right in a shifting tech environment. So food for thought.
You're an implementer operating in a deeply adversarial environment where everyone is your enemy. Everything you do can and will be circumvented, especially by the Russia-style attackers you mentioned. See the copyright industry's fruitless attempts to curb copyright infringement. If it actually looks like you succeeded, it's only because people didn't care enough.
Unless the free computing we enjoy today is completely destroyed to the point we can only run government signed software, there's little you can do to defend against these things. To stop this, you will need tyranny the likes of which will destroy everything the word "hacker" stands for. I presumed you cared at least a little about that since you're posting on Hacker News.
Yeah, I grew up and realized that there's more to the world than mere developer convenience above all else. If Hacking means siding with the developer over everyone else in humanity and societal benefit, let it burn. Luckily, that's not my definition.
I'm fine with what my side project is and it's scope. It's secondarily a tech demonstration for the bigger thing that comes later. If that means the early stage is only viewed by 2000 people and improved the lives of some election nerds for no monetary gain plus a news article after submissions close, good, the plan is on track. I'm not trying to be big in this project.
This sort of thing always feels like it's going against the grain, with someone always asking "why wouldn't you do this properly. You know, build an allow list of user agents and match against them". I fully support people being forced into detecting the features they want and doing away with this nonsense,
The web platform gave web developers way too much freedom and they're abusing it. God giveth and god taketh away.
Or for more useful stuff, "X gets you data from URL Y". Either you get that data or you don't. Voila, data about the browser.
The only alternative is that you never ever release any new features or fix any bugs.
If I remember correctly, Firefox's fingerprinting resistance will actually slow down functionality to achieve that. Reduces the precision of performance timers or something. Makes CAPTCHAs exponentially more obnoxious.
So... yes, you could build a "browser" like that. It would effectively have no scripting at all though, nor could it ever introduce new semantics that send data to another site, directly or transitively. You can do some stuff with that kind of system, but it's limited enough that most people don't choose it.
Gopher exists I guess? Lynx too, though lynx supports css, and that largely can't be allowed either.
The web should be fully declarative and permissions/capabilities based. If they can't do something that way, they shouldn't get to do it at all.
I'm not deeply familiar with it, but it's a similar "extremely minimal is best" approach, also in part for privacy reasons.
- People on HN.
Do you think otherwise?
B. Check if a link is visited.
Whether these two even remotely fall into the same category is left as an exercise for readers.
B. Provides bits of identifying information.
To me it seems they're in the exact same category.
Knowing the user's mouse position? Provides bits of identifying information.
Knowing which subdomain the user is visiting? Provides bits of identifying information.
Reading URL query string? Provides bits of identifying information.
If this is a category, it's a quite big one!
Maybe the ultimate conclusion is Javascript should not actually exist at all. The web should be declarative, not executable. Developers tell the browser what they want and the browser does it. If it can't be done that way, it isn't done.
Just like Chrome's Manifest V3 making extensions more declarative and limited. My only problem with it is the fact it cripples uBlock Origin. I actually do want those restrictions applied to 100% of all the other extensions, it's just that uBlock Origin is too important and trusted and should be an exception. Honestly, uBlock Origin should be literally built into the browsers at this point. The only reason we can't have that is the massive conflicts of interest involved: can't trust an advertising company to maintain an adblocker.
Road to hell is paved with good intentions. When you propose a law, you must also think about the numberless ways it could be abused and misused to cause harm. Same principle applies here. The code shouldn't just fail, it should fail in ways that prevent the developer from even knowing it failed much less why. Simply because that would leak information.
More of a "be upset with Google" than a "feel bad for my friend" kind of thing
Also the adtech industry in it's current form is harmful to users. First of it exploits tracking vectors. Secondly it's a malware distribution technique second to none.
If Google wipes out all of the other analytics companies, I can just not use Chrome.
If you do have browser ballots , you’re going to be able to “choose” which Chromium skin you want to use.
Most people know about Firefox and they still choose Chrome.
And if they choose Firefox - they are still downloading a browser where most of its revenue comes from…Google.
No one is going to pay for a browser. Any browser you choose is going to end up supporting itself via ads
ChromeOS isn't a thing?
ChromeOS is only slightly above Linux in marketshare.
https://gs.statcounter.com/os-market-share/desktop/worldwide...
You’re going to have a hard time convincing regulators that Google is acting monopolistic because it’s forcing less than 4% of the population to use Chrome
It's becoming about control of eyeballs and defaults in several dimensions. Lazy and captured regulators are easily convinced to scope the definition of any given 'market' in whatever way their former or soon-to-be employers demand.
These days sites often instruct users to install Chrome, especially Google properties that billions are already accustomed to.
Have we learned nothing from the IE era and the Microsoft anti-trust case?
That is about the entire desktop user base btw.
1. Roll out stuff they brand as “privacy respecting” that actually collects data for their own use.
2. Brand anything that would give competitors access to that data (third party cookies, user agent strings, etc) as a threat to user privacy.
3. Lock all of that stuff down so that nobody can access it (“we’re protecting you!”)
4. I don’t think we need the ???, it’s just straight to profit, via monopoly over the data.
The brilliant/terrible thing about this is that third party cookie tracking is not great so it’s hard to set up a defensible argument where leaving things as they are is the better alternative. Apple and others have been waging a war on third party tracking for years now, and pushing public opinion in that direction, and it seems to me that Google is playing 4D chess here and using it against them (and frankly, the entire internet).
Use a browser that is not made by an advertising company.
In other words, just drop chrome. It has never been easier to do, with Edge and Safari readily available on all major platforms and Firefox for those who prefer it, and of course the many other chromium forks that are around.
There is no reason to be dependent on chrome today. There was a few years where it was overly dominant and very hard to avoid for compatibility and performance reasons, but that is just not true today.
Personally I use Firefox on android and desktop and I don't miss chrome at all. I uninstalled (technically, disabled) it on mobile as Google widgets like to open links in it otherwise.
I have chrome on the desktop as I work in software so I need to test compatibility with it, but that's it.
My personal picks are Firefox on Windows and Linux, and Firefox or Safari on macOS.
I just go with Firefox on any actual computer since I can lock it down with whatever extension/config I want.
Personal opinion we need to tweak business incorporation rules to firewall ad business from all other types of businesses. Meaning General Motors can't sell ads. And ad companies can't sell cars.
And as someone on this site suggested extend antitrust dumping laws to services.
Going back to the alternatives from Arc for browsing and Hey for email management is always jarring. They aren't massive UX changes, but they sure are well thought out and impactful.
Firefox, god love it, is a rough and clunky browser by comparison. Sure you can make it what you want, but it’s an investment. As the only viable noncommercial cross-platform option though, what else are we gonna do
Genuinely curious!
I have absolutely no issues with it. Websites all show perfectly, if I ever have an issue it's down to my many adblocking plugins blocking a little too much.
There’s zero point in switching from Chrome to Edge.
Firefox to my knowledge has no ads revenue, apples limited ads revenue doesn’t come from the web.
Brave I think is a low-key crypto grift run by a homophobe, but still better than Chrome.
> In other words, just drop chrome. It has never been easier to do, with Edge and Safari readily available
Considering Windows 11 has ads in the operating system, how is Edge not made by an advertising company these days?
Isn’t that pretty much the issue here?
Anyway, what’s really locked? Text messages?
Because I can export pretty much everything else. Images, videos, documents, passwords, bookmarks.
Maybe Apple Music’s playlists?
The kool-aid is in their definition of the word "privacy." You and I might think "privacy" means "other entities aren't observing you" but Google in their benevolence knows that it really means "Google will keep your data safe from third parties." Their newspeak doesn't even allow the concept of "data that Google does not collect."
(A friend of mine was involved in the launch of Google Allo. I asked them if it would be possible to use the virtual assistant features offline without sending everything to Google. They never spoke to me again.)
Or check this video if you can't make it in person:
Google's philosophy on this sort of thing has been pretty consistent for over a decade: they trust themselves with user data. It goes in a vault, it's very hard to access inappropriately, and they have some of the best security possible on the modern web. Practically speaking, yes, it's still a risk; if the data collections get breached, that's all the data. But they don't see themselves as more of a risk than anything else out there, so for them it's not philosophically inconsistent to claim other companies doing what they are doing should be considered a privacy threat.
... And honestly, I think there's a good case to be made that if you don't trust Google to respect your privacy and secure your data, You shouldn't be using Chrome period, because the organization you don't trust controls the source code of that browser.
To throw them in the same pit, they're taking a page from Apple's playbook: the privacy benefits for the user will justify any market effect from closing the platform and keeping all user data internals. Platform owner gets to protect the user from some of the abuse, while gaining a critical edge on the competition.
In the current climate, I'm not sure there is any good angle to solve this, short of strong regulation limiting the advantage they get from doing these "privacy first" moves (basically find a way to forbid the platform owners from using their own users' data...I'm not holding my breath)
Well, you could also look into removing some rules, in addition or instead of piling on new ones. Eg you could weaken intellectual property rights, to make it easier for upstart competitors to take on the established giants.
Or you could make it easier for foreign competitors to enter local markets. (As an example, the US has become more protectionist of their tech markets. And the EU has a lot of red tape that's even harder to follow, if you are from outside the area.)
No specific regulation is stopping this. If anything, all the regulation that are getting added have as a goal to reduce the red tape around smaller players and limit the extent of the giant players' monopoly.
If you were thinking about the rules forbidding dark patterns to suck client infos and accelerate growth, it would be a tough sell to be honest.
No?
Lots of regulation just adds red tape in general, and there are clear economics of scale in compliance: larger companies have proportionally an easier time affording the legal experts they need to make sure they are compliant.
I think it was the migration to https everywhere that killed that. Not sure why it went down that way, or if Google was responsible.
But yeah, when I ran a blog, I would look through the referrer URLs to see what people were actually searching for and write articles about that because it was obviously an untapped void in the market.
I have very little trust for Google and other megacorps like it, but I have even less trust for parasitic entities like Jake that just piggyback on top of Google's already horrid practices to extract wealth from, so you'll find no sympathy for Jake from me.
This is factually incorrect. It works like third party cookies, but with privacy. A web page can only retrieve a topic if that site has already observe you visit pages of that topic. In order for you to observe a site that site must send a fetch request to you or embed you in an iframe.
If a random site calls document.browsingTopics() they get no topics as not enough data has been observed by them.
https://source.chromium.org/chromium/chromium/src/+/main:com...
It doesn't matter if edge does not have this "feature".
Microsoft can simply scan documents on your PC.
He's committed to deGoogling his life now and is even migrating off Gmail this weekend - I think I'll be joining him.
Nextcloud
Syncthing
Firefox
Bitwarden
Aegis
GrapheneOS
F-Droid
ntfy
NewPipe
Signal
Matrix
Stop using email or do custom domain + some service. Sync locally with Thunderbird or whatever you like.
Would be great to see more attention being brought to the independent browsers: Firefox, Opera, Brave, Vivaldi etc
Not sure if we are there yet, but seems we are heading that direction.
It was lightweight and fast, but still managed to have a built-in mail client, RSS reader, and IRC client.
All with a consistent and clean UI that treated the user like an adult. Maybe I'm just old, but I hate the flat "everything looks like a webpage" UIs in today's browsers.
I was there for nearly all of it.
I first played with the original Opera when it came out of beta in '96, as an attempt at an alternative to my regulars of Netscape and Thomas Bruce's Cello. It had none of that email or RSS or IRC, just a clean and simple MDI browsing experience.
It was great. By '97 and '98, their capabilities (they added JS, cookies, and image blocking) and performance were solid enough that Opera became my primary browser.
Opera, during '98 and '99, was absolutely the best browser UX around, for me anyway. MDI made up for Windows 95's and later 98's windowing UI which never anticipated that users might have dozens of web pages open at once completely destroying the utility of the Taskbar.
Opera's MDI, like Excel's MDI had done for accountants a decade earlier, was great for "power users" like me, while everyone else making browsers (mostly Netscape and Microsoft but there were a few others) seemed to be targeting newbies or "the enterprise". (The Web was early then, and bringing in new people faster than just about any tech had ever done before, but it didn't have much of the value it does today, so I guess it was reasonable to target new and casual users on the road to critical mass, but after MDI there was almost no going back for me.)
Opera 4, in mid 2000, soon after I joined staff@mozilla.org to help lead the Mozilla project, was the last version I used with any regularity, mostly because I really disliked the redesign and they began cluttering things with each new release while I was trying to convince Mozilla to do the opposite and simplify.
Opera did introduce an MDI switching toolbar then, which is sort of like tabs but really isn't, and that was a good step. But I'd used an actual tabbed browser in the late 90s on occasion, Adam Stiles' Netcaptor, and Opera's MDI toolbar wasn't that. It helped the MDI experience some, but it didn't transform it into tabbed browsing in any meaningful way.
Then Opera 5 introduced the banner ad later that year, just as Mozilla's browser component from the larger internet suite was starting to get decent, good enough that I stopped calling myself an Opera user/fan/booster and started identifying as a Mozilla user.
(The integrated search box on the Opera 5 toolbar did inspire us though, so about a year later we put one in the young Firefox toolbar.)
I checked in with most new Opera releases for many years, but by 2002 Blake and I were deep into working on Firefox and so I was able to help design in some of Opera's earlier simplicity, but with tabs rather than MDI. Rather than wait for Opera to get things back on track, I simply started building the browser I wanted with Firefox.
By the time Opera added email in 2003 and RSS and IRC in 2004, Opera was 8 and 9 years old. Jón S. von Tetzchner's original Opera browser was EOL in 2012 when Presto got cancelled, and was probably dead a year earlier when Jón was forced out (and perhaps even a year before that, when he stepped down as CEO) so yeah, email and RSS and IRC are almost exactly mid-life features in my book. Considering that Opera never recovered after those features were added suggests it was probably over the hill already. Today, and for the last 7 years or so, Opera is little more than a Chinese equity firm's mostly meaningless plaything.
If anything, it wouldn't surprise me if Mozilla announces that they're discontinuing Firefox. Those alternative browsers you mention don't even register on the usage radar to be relevant in a browser "war".
Everything seems to indicate that we're heading towards an even worse single-browser dominance than IE had in the 90s.
There are only 3 real browsers today that meaningfully compete and control their own destiny: Chrome, Safari, and Firefox. Everything else is mostly just a fresh coat of paint on one of those browsers.
Apple, which owns Safari, is the largest company in the world. Alphabet, which owns Chrome, is the 4th or 5th largest company in the world.
Mozilla is a small non-profit that exists to provide meaningful choice. Those others are small businesses trying to make a buck riding Google's treadmill or surfing their wake.
(a) Ignored them, or
(b) Used an incognito window.
But now, when I'm forced to use Chrome, I'm seriously looking at disguising my IP address, etc. But this is not my field.
Would a VPN do what I need? Where are instructions that a n00b can follow?
Every site I've found so far has either been:
(i) Advertising;
(ii) Assuming too much competence;
(iii) Out of date, or
(iv) Wrong.
Clear, robust, and up-to-date advice welcome, as I'm sure it would be for many.
> Would a VPN do what I need? Where are instructions that a n00b can follow?
Never used them myself but lots of HN commenters think highly of the VPN services offered by Mullvad [0]. In fact, right now, Mullvad is currently on the HN frontpage [1], from a blog post by Tailscale.
(for now)
I also use Kagi instead of Google search.
https://vivaldi.com/blog/news/alert-no-google-topics-in-viva...
Shortly: they disable the tracking forcibly, even if "someone" tries to enable it remotely or via flags.
Google was playing 3D chess when they started developing Chrome, and when they started making moves to strip away things like user agent strings, they were really just making the final moves of a campaign set years before to create a walled garden of ads data.
Edit: I had initially said “dominant” in the enterprise, but I imagine that title still goes to Edge?
It would be impressive if it wasn’t so depressing and gross.
If Google and Chrome are mandatory for work, well, tough luck. But I do have the feeling that the enterprise versions are much less intrusive. And even if, I never do private stuff at my work machines and devices anyway.
Firefox has had its ups and downs, but it and its progenitors have been great daily drivers for me over 20 years now. It's not too late. The best time to switch was, well, forever ago -- but today is also a great time to switch. Get on the fucking bus.
Like most companies, Google has a mission statement or "philosophy." Google's philosophy is divided into 10 points; each point is one sentence long. The first and most interesting is quoted in the title of this part of the book. Unlike most corporate mission statements, this phrase did not come about through long committee discussions: This statement is Larry Page's mantra. Early on, when people asked him about financing his projects, he always replied with something like, "Don't worry about it. If our users are satisfied, if we give them all they want and more, we'll be able to find some money.""
https://www.oreilly.com/library/view/the-google-way/97815932...
The conceit is the ability to view responses as nodes in a graph, and laying filters on top. The tradeoff for performance being introspection and control.
Didn't the very initial release of Chrome, many years ago, already create a unique, identifiable ID per user, and open a connection to phone home to Google servers (using that unique ID) on every single key-press and mouse click done anywhere in the browser?
Should I just restrict myself to Safari now? I don't really like Firefox for some reason.
It’s not the new IE. In my mind it’s worse than the new IE because it achieves similar goals as the IE abuse but without necessarily doing anything illegal.
Thars very different from the situation we have now where Firefox is well known and open source, and even Chromium’s open source so it can be leveraged by better stewards of the internet.
Don’t get me wrong. My argument is not that Google is better than Microsoft. My argument is simply that the situation we’re facing right now is very different from the IE era. If anything, I’m arguing that the Chrome era is worse because of how much more insidious Google’s actions are.
It was easy for the EU to essentially eliminate the IE threat by forcing MS to unbundle IE and for Firefox (and later chrome) to replace IE purely on the basis of providing a better software. Replacing Chrome on the other hand is a very different kind of problem that is possibly much harder.
I agree with you that Chrome is even worse than IE ever was. Mostly because Google is much smarter than MS was when it comes to ensuring market dominance. It will be much harder to dethrone Google, simply because Chrome is a much better product.
I'm not a fan of Chrome though. But the problems with Chrome are not identical to the problems of IE.
Stop.
Stop excusing it. “It’s work. It’s my hobby. I like it. But I can make it work.”
Just stop. It’s only hard because you think you’re in this world technology that’s more important than you as a human.
Uninstall chrome. Tell others to do it. Tell others why. Tell others the lies, deceit, marginalization, and corruption. And then don’t participate.
It is hard to beat free.
My own 74 year old dad says.. be practical, I don’t care if Google wants to profile me as a 74 year old man interested in watching my regional language news and religious videos. Nor do I care if Google knows that I spend the little retirement money of mine buying these medicines or paying for the taxis. They can try targeting ads to me all they want, but good luck to them, I’m not going to book an expensive holiday in the Himalayas, nor am I going to buy something I don’t want to buy. I just want something that works in a way I have gotten used to. I don’t want change at my age.
I can sympathize with his argument. I just wish young people don’t find an argument like his..
We have regulations preventing some rich dude flooding the market with free product to gain a monopoly and then charge exorbitant prices. Why not the same for digital services in this internet age? I wish we regulated internet services the same way. No “free” email, chat, social services paid for by creepy ad companies. The real cost of these services at the scale of the number of users is minuscule anyway. The field Google, Amazon, Meta and Apple plays at should be leveled for new competition - that is a Government’s duty to enable.
> They can try targeting ads to me all they want, but good luck to them, I’m not going to book an expensive holiday in the Himalayas
I don't know if this argument is deliberately understating the issue. I'm going to assume it's not. The real cost of pervasive tracking and ad isn't forcing you to buy something. It's much deeper - like increased insurance premiums, denied insurance (based on data that insurance companies buy from data brokers), locked down and unrepairable devices (to force you to consume ads), massive scale political manipulation (like in case of FB and CA), suppression of labor rights and free-market employment (based on racial profiling, search trend analysis etc) and similar. It's going to cost you more than a ticket to the Himalayas - it's just not very obvious.
> Why not the same for digital services in this internet age?
It isn't hard for large companies to capture regulatory bodies. It isn't even effective in open market or even in cases where lives are at stake (recent cases of air crashes is an example). No regulatory body or the government is going to protect your rights unless you demand it. It's their duty, but it isn't going to happen without your insistence.
I can understand how such fights can be very tiring. However, dissuading others is irresponsible. Everyone has the right to ask for a non-dystopian future.