Google shares update on next step toward phasing out third-party cookies
blog.google
blog.google
https://www.aclu.org/news/immigrants-rights/the-u-s-governme...
Targetting people to arrest and deport them, to use violence against them. That would be a practical example of government privacy violation.
I work at a telco, and they also do this for debt enforcement, locating not-up-to-date-on-payments cars, tracking down kids who ran to their parents from youth services is also done, ...
THAT is a real problem.
Suggesting it's time to buy a present for your wife because of upcoming wedding anniversary is targeted advertising.
* https://www.justice.gov/d9/2023-11/417581.pdf
I suggest they do so. It gives a good look at the conflict between the different departments in Google re: revenue vs. value. If there are any questions about the motivations behind changes such as these, this may provide a bit of insight.
1: User visits domain A which includes a script from domain T. The script sets a cookie with a unique ID on domain T.
2: User visits domain B which also includes the script from domain T. With the request for the script, the browser also sends the cookie with the unique ID.
3: T now knows "Someone visited domain A and B".
4: If T figures out something private about the user on site A (say their Twitter handle), they now know that Twitter handle X visited domain A and domain B.
Is this a correct summary of what this is about?
I guess this means that Meta knows a lot of domains which handle xyz visits. Because they set the cookie when the owner of handle xyz logs into their account and then sees them on every domain which includes a script from Meta.
So is this an attack on Meta by Google?
Disclaimer, I work at Google on related things on the Android side, but I only have a layman's understanding of the Chrome side.
If the answer is a very low number, then why is Privacy Sandbox on by default?
In Chrome, none of the Privacy Sandbox APIs even respect the browser's built-in Do-Not-Track setting.
Contextual ads are enough. Advertisers don't have an intrinsic right to optimally profit off my device hardware, and they should be thankful for whatever profit they do end up getting.
Google's tech lead on Privacy Sandbox, Michael Kleber, says that "[…] limiting the web to contextual advertising solutions dramatically decreases the ability of web sites to fund themselves — for example, 52% less revenue for sites on average, and 62% less for news sites, according to https://services.google.com/fh/files/misc/disabling_third-pa..., […]"
48% of current revenue is plenty. Privacy Sandbox is adtech greed forced onto users.
So you're sticking to third party tracking cookies? Sadly this is unlikely to be a false dichotomy, as we've already seen paywalls put up around adblockers, I expect to see the same for browsers without third party cookie support – I already have to mess with Safari on a regular basis to get websites to work because it doesn't accept them.
>> Contextual ads are enough.
to
> So you're sticking to third party tracking cookies?
? The correct amount is zero tracking, on the basis that it's enough to know what ad goes to what page, without needing to follow the user around the web and track them individually.
Competition regulators in the UK, US, and EU all made it clear that Chrome could not remove on-by-default third party cookie support without a replacement that worked well enough for other ad networks.
The UK CMA did it with a formal consent decree, EU, the US states, and DOJ each "just" threatened anti-trust action if it happened.
It isn't a false dichotomy; the choice really is between 3p tracking cookies vd. something like the Topics API.
Regardless, "Google is legally obligated to not protect your privacy" is the weirdest pro-Firefox argument I've read lately, but I guess it's an acceptable conclusion.
That is plenty. Users don't need to assist ad networks.
But the fact is that the regulators covering basically all of the West don't share that opinion. In fact, they're not merely neutral on it. They have expressly forbidden Google from doing what you want.
And while your opinion is as valid as anyone else's, as a practical matter what the regulators decide will trump that opinion.
In case you didn't get the drift from "Advertisers don't have an intrinsic right to optimally profit off my device hardware": I block third party cookies in Chrome and use other browsers that have third-party cookies blocked by default.
If you're asking about how I use third party cookies myself in my own software: I maintain a popular consent manager used all across the internet. It doesn't use third-party cookies. We're actually planning to implement Privacy Sandbox regulation capabilities so that our customers can properly gate your APIs based on tracking consent and user privacy rights (since you don't respect your own browser privacy signals).
If you're asking how I will react to a web with more paywalled ad-free content: Emotions ranging from indifferent to pleased, depending on the content source.
Are you aware that your coworkers have frequently claimed that Privacy Sandbox by itself somehow "enhances" ad privacy, conflating the removal of third party cookies with the introduction of Privacy Sandbox? The notice has since been removed, but I'm still waiting (likely forever) for an issue to be addressed about these fraudulent claims[1].
Nobody wants Privacy Sandbox except advertisers.
1. https://bugs.chromium.org/p/chromium/issues/detail?id=143154...
Docs for Protected Audience API: https://developers.google.com/privacy-sandbox/relevance/prot...
It feels like there's a bunch more pieces to the puzzle too. There's Topic API, which by itself only tells a site more about users, but does so in a supposedly privacy preserving way. There's dozens of efforts listed on https://developers.google.com/privacy-sandbox/relevance/prot... , mostly slated for 2023 & seemingly not updated in a while (with abundant broken links too). It's a bit wild that third party cookies are deprecated even though it seems like then promised fair privacy preserving replacement for ads is maybe still being built?
If you work on Android maybe you can do a 20% project where you let users completely opt out of motion-based user fingerprinting even when airplane mode is on https://www.thesun.co.uk/tech/7811918/google-is-tracking-you...
Or even a change to let Android users get a percentage of the profits garnered from Google’s fingerprinting of them.
I don't want to be influenced by ads on every website that are targeted by my socioeconomic status, such as the potential ability to afford a holiday outing or purchase a car inferred through interest in holidays and cars.
Being able to differentiate on interests such as 'holidays' and 'cars' as compared to 'fast food' enables advertisers to sell the same product at different prices to different socioeconomic groups. This is bad for society.
https://webkit.org/blog/11529/introducing-private-click-meas...
More recent discussion over last few days instead of this old post that's been submitted a bunch.
Preparing for the end of third-party cookies
Is it what you want - often "no"
Is it better than what we have - often "I suppose so :("
"chrome://flags/#test-third-party-cookie-phaseout is available from Chrome 118" if you want to test it.
Oh god, we are going to see something more annoying than cookie banners soon. (And this time we are not even sure whether Google is at least trying to do things in users' favor...)
If Google is phasing out 3rd party cookies, they're not doing it for privacy, they're doing it because they've figured out how to track people without them. And they don't want their competitors to do the same.
Thus: Remove 3rd party cookie support from their market-leading browser to hobble competition.
Based on commentary I think google has done a good job of misleading people.
ITP and isolated cookies are a response to companies like Google and Facebook developing mechanisms to defeat/undermine 3rd party cookie blocking.
Google's "tracking protection" is something Safari did from the very first beta two decades ago, Firefox adopted 3rd party cookie blocking more recently, but that's all google is doing right now, and (presumably because) it's a tracking mechanism that they have already defeated.
They're calling it "tracking protection" to try and launder the "tracking protection" terminology of actual privacy mechanisms and terminology of other browsers, rather than actually acknowledging that what they're doing now was insufficient years ago (when safari and firefox had to introduce a bunch of very complex logic to continue to actually protect user privacy).
https://www.theverge.com/2020/3/24/21192830/apple-safari-int...
ITP is not 3rd party cookie blocking.
3rd party cookie blocking has been the default in safari and webkit since literally the first beta.
ITP is a response to companies like google and Facebook developing techniques to circumvent 3rd party cookie blocking as it became more popular (due to Firefox, Safari, and mostly iOS safari). Google is not developing an equivalent to ITP, it's literally flipping a single flag that they decided to turn off when they launched chrome because they're an advertising company that was dependent on them.
You need to understand here: Google is not working on releasing anything equivalent to ITP or whatever Firefox calls their version, they're working on something much more basic, and it's something they have already circumvented (which is why Safari and Firefox have their complex ITP or whatever mechanisms).
ITP is not about 3rd party cookies, ITP is first and second party cookies where people use indirect load mechanisms to circumvent 3rd party cookie blocking. e.g when people load Facebook buttons and such like directly into a page the 3rd party cookie isn't available in JS but the resource load for the Facebook button allows Facebook (or whoever) to return the tracking identifier directly to the host page so that it can update its own tracking information. ITP (and similar in Firefox) prevents that by saying some variation of "if I see requests to domain X from lots of different domains, we should assume that's being used for tracking purposes, and so not every request to domain X from a domain Y should be completely isolated from queries to domain X from any other domain" so now once you decide the domain X is used for tracking purposes you don't have a "cookies for X" database you have "cookies for X when loaded from Y", "cookies for X when loaded from Z", etc.
What google is talking about is not anything approaching ITP, they're literally talking about something even more basic: JS on domain A can't directly interact with cookie information on domain B, which is the 3rd party blocking that is what Safari and WebKit have always done by default.