Google delays third-party cookie demise yet again
digiday.com
digiday.com
https://privacysandbox.com talks about advertising, but not "logged in elsewhere" functionality. Does Youtube or Google have something ready, or will all Youtube Premium subscribers see ads on embedded videos?
Put another way, an ad iframe loading a tracking (identity) cookie is indistinguishable from a YouTube iframe loading a login (identity) cookie.
If/when third party cookie blocking is fully deployed, this won't be true. Your browser won't send YouTube's session cookie to YouTube when it's loaded in an iframe on an unrelated site, so YouTube won't know you're a premium user.
The third party cookies don't control ads in embedded videos, there are currently no ads in embedded videos whether you have paid for premium or not.
I have a bookmarklet that converts a youtube page to an embed for this reason, for when I get sick of seeing the same couple of adverts on a loop.
I certainly don't when using the inline-from-youtube-itself-via-bookmarklet trick.
https://support.google.com/youtube/answer/132596
>Ads appear on brand safe sites: YouTube works diligently so that our advertisers' brands appear on sites that reflect our respective core values. Our systems closely evaluate websites and their content against various factors when finding out whether to turn on In-stream ads on YouTube embeds. These factors include a strict set of guidelines on content like adult imagery, violence, inappropriate and hateful language, and sites that promote infringement.
https://developer.mozilla.org/en-US/docs/Web/API/Storage_Acc...
https://developers.google.com/privacy-sandbox/3pcd/storage-a...
From Google's own page: "Work is continuing to resolve all remaining blocking issues, before standardizing the API."
Any specific problems you ran into that you could share?
Google needs to be forced to spin out Chrome to someone else, it is a clear conflict of interest when nearly every (or every? are there any that haven't?) other browser has already taken steps for actual privacy instead of dressing up a new tracking system.
While we wait for this to never happen, we should be encouraging everyone to use any other browser so google doesn't have the marketshare to strong-arm the web anymore.
If Chrome was made by an independent company regulators couldn't care less if they disabled third party cookies.
But that counterfactual seems totally irrelevant to the claims the GP was making?
Regarding this, it's been 4 years. I am not letting google off the hook with this, especially when many other browsers already block third party cookies.
I stand by my opinion that an ad company operating a browser is a clear conflict of interest. If they didn't, this "privacy" feature would never have been a thing and this would have been done years ago.
Yes but the question is why is anyone using those things when they are only supported in a single browser? If its not fully supported by the major 4 browsers then its not getting put in my code, simple.
But regulators from both the US and the EU have made similar statements.
The answert is that the solution they are proposing hinders other ad compnies and give google unfair advantage in the ad space. Hence the they are not allowed to do for competition reasons.
Without this interference, third-party party cookies would have been dead years ago.
Ultimately the Privacy Sandbox has dozens of different proposals, and each is on a separate standards track. It's not a singular technology.
I will say that many of the proposals do directly improve user privacy, or offer more-private alternatives to existing APIs. But I'd also be surprised if there weren't objections as well. It's the web, and scrutiny is important.
Some of the required technologies (private model training, debuggable trusted execution environments) are still research topics, so some sacrifices have to be made until it can be deployed.
Google actually has interest for new solution having weak performance, since it will shift Ads funds from 3p sites to their own properties(search, youtube, maps) where 3p are not as critical.
The opener specifically whitelists the embeder's domain in a response header.
https://developer.mozilla.org/en-US/docs/Web/Privacy/Privacy...
edit: to my surprise apparently web teams (both "old" and "new") no longer needs 3rd party cookies enabled. Last I checked was a few months ago.
It had one @&_+ing job...
And they managed to instead product design something with 2 (3?) different chat models, limitations around every corner, an incomplete API for basic use cases (e.g. getting notified of @'s), and an embedded ability to build entire apps inside Teams.
I think the answer is more banal in that some of their oauth flow runs in a different domain from the main application. I think this is tied to wanting to reuse part of oauth flow in the desktop application.
Remember "DOS Isn’t Done Until Lotus Won’t Run"?
That large companies do self-serving underhanded tricks is not a conspiracy, just yet another Monday in the office.
Example of how it looks:
https://hacks.mozilla.org/files/2021/02/Screenshot-2021-02-0...
So for example:
a.foo.com sets cookie X (Set-Cookie: X=value;)
a.foo.com sets a cookie Y on foo.com (Set-Cookie: Y=value; domain=foo.com)
b.foo.com can read Y, but can not read X
What a joke!
I have 3rd party cookies as well as all ads and trackers blocked and have no major issues. On the odd occasion a site doesn't work, it doesn't get my business/attention. Non-technical people should be afforded the same protections.
That said, this has been on the table now for years so it's time for the operators of these old apps to feel the heat. The Times They Are A-Changin'
Secure sessions (ie first party cookies) are unaffected. Your bank is likely entirely unaffected beyond whatever tracking cookies they’ve been installing.
These cookies have nothing to do with the people you call into. If the bank’s help desk can access your first party cookies, may God have mercy on them because hackers and the government won’t.
These changes almost entirely affect third party tracking, and the occasional niche, legitimate use case. Those are fairly rare, in my experience. The vast majority of core functionality in applications are fine with only first party cookies.
Interestingly, Firefox does have these bugs, but these apps will not work on Firefox due to other issues.
Actually, it’s not clear whether these are bugs or just different interpretations of the specifications
[1] https://chromeenterprise.google/policies/#BlockThirdPartyCoo...
[1] https://chromeenterprise.google/products/chrome-enterprise-p...
If they had just not added this tracking vector in the first place this would not be something to debate.
Did Safari also originally enable third party cookies by default for the purpose of enabling spying on its users?
3rd party cookies are the original way advertising companies spied on users, and the only way the vast majority of companies can spy on you. What they do is make is so that when you request a resource you can attach cookies to the request that are not from the domain making the request, so that if you have multiple unrelated sites requesting https://advertiser.com/resource they will share the same cookies and allow the operator of advertiser.com to uniquely identify the same user regardless of the site actually being visited. Wikipedia has a big page on this specific technical concept: https://en.wikipedia.org/wiki/Third-party_cookies
This is what a "3rd party cookie" is in the context of blocking "3rd party cookies", and this is what more or less every browser other than chrome now does (except maybe edge?). Safari has had blocking 3rd party cookies be the default behavior since the very first betas. It was the first browser to do this by years, to this day I'm not sure why Firefox didn't immediately follow suit, but that's something best answered by someone from Mozilla of the era.
The article you're pointing to is discussing a further hardening of the restrictions, ITP, and origin based cookie segregation. These are all increases in the degree to which cookies are blocked, and these are necessary specifically to deal with privacy invasive tracking that companies like google and Facebook are able to do.
For the overwhelming majority of tracking networks simply blocking 3rd party cookies is sufficient. But over the last decade or so companies like Google have aggressively introduced new mechanisms to promote their 3rd party cookies into the sets that can be shared. Google has been very aggressive in this by working extremely hard to get as many webdevs as possible to add spyware to their pages to get "metrics".
There are numerous steps they take - redirect loops were in vogue for a while, i'm not sure what they're doing now - basically trying to either link a cookie from the domain embedding the tracking code to a cookie on the advertisers domain, or promote the "3rd party" domain into being part of the primary site. Defeating that requires cookie segregation (so that every site you visit has a different cookie vault for every different origin it contacts), and things like "tracking protection" which tries to detect sites that are being pinged from many different origins (implying they're for tracking rather than site content) and severely curtailing any cookies for those origins.
The post you linked to is talking about that, and it sounds like an end game step which is that loads to any resource from a different origin gets no cookie state at all, which historically didn't seem possible due to many weird ways sites managed account login and the like but maybe things have changed since then.
This world of cookie segregation and tracking prevention is _significantly_ stricter and more powerful protection, and is far beyond the "3rd party cookie blocking" that google is still delaying to this day, and has been something safari and Firefox have been doing for years, but it came after, and in response to, companies like google trying to circumvent the privacy provided by 3rd party cookie blocking.
This is also why google is now talking about blocking 3rd party cookies - they've spent more than a decade come up with ways to track people in spite of 3rd party cookie blocking, and they have no implemented any of the privacy protections Firefox and safari have been shipping for years (nor is chrome likely to implement anything of the kind). Google (and FB, etc) are in a position where they can do this, but smaller advertising networks can't (google has tracking code on almost every page as part of their "we'll provide you with analytics/metrics" scam).
In Safari, if you loaded a pixel from https://advertiser.com/resource that was referenced on different sites, advertiser.com would get the same cookie. This is still true. What blocking third party cookies means is that advertiser.com can't set a cookie when its pixel is loaded from another website. Safari didn't even think to implement it until Chrome announced that they would do it and worked with web publishers to migrate away. As far as sending cookies to a different origin, Safari didn't even support the SameSite attribute until 2019, three years after Chrome and one year after Firefox. It's not for nothing that Safari gained its reputation for being slow at adopting web standards.
I guess that's why the Competition and Markets Authority is involved.
It's easily broken if multiple such datasets are combined. And that's probably exactly what the commercial surveillance industry does.
This magazine had their OWN branded browser, based on Chromium and many used that.
Now that I think about, what a gigachad magazine.
Ah, right, the makers of the world's most popular web browser are also the world's most profitable online advertising company, that's why.
It's explained in the article, and below in this thread. They legally cannot due to intervention from the CMA.
A great pro-tip I try to follow (but sometimes fail since this is human nature): don't make assumptions, and don't be over-confident if you don't know. It can be especially embarrassing if TFA is quite short and well covered
But I hadn't even considered that this might benefit Google, but that certainly makes sense! I'm grateful for good old British skepticism :-) Looking forward to their findings.
That's debatable, but I doubt that's the case. The CMA isn't a privacy organization; they deal with monopolies. They're intervening at the behest of other advertisers who are concerned that they'll lose the ability to adequately track users under the Privacy Sandbox proposal. The CMA's chief concern is that everybody is on equal footing.
The alternatives proposed for more private ad targeting have gone through multiple evolutions, including FLoC and Topics, but these were created largely in response to the CMA's objections.
The CMA has specifically mentioned that just blocking 3rd party cookies would provide Google an unfair competitive advantage because their large web presence allows them to develop better user advertising profiles based on just first party information. Advertisers without a large first party user base (because they only do advertising) would not be able to develop user profiles.
The whole privacy sandbox effort it's supposed to level the playing field between large content providers that are also advertisers (Google, Facebook, etc) and providers that only do advertising (Criteo, RTBHouse, etc). Google couldn't drop 3rd party cookies support without Privacy Sandbox.
[0] https://www.adexchanger.com/marketers/the-uks-cma-wants-ad-t...
Sounds like a very flimsy excuse, Safari has blocked 3PC by default for years, so the restriction would apply to iOS Chrome as well. Didn't need the UK to sign off on it.
https://webkit.org/tracking-prevention/#intelligent-tracking...
https://developer.chrome.com/blog/resuming-the-transition-to...
At least, to Google's credit, they're starting to listen to users who give them solid reasons why a surprise migration isn't feasible... tomorrow.
> To maintain your extension's Featured status, you will need to migrate it to Manifest V3 by June 3rd. [...] Extensions that do not complete this transition will see their Featured badge removed
> Manifest Version 3 extensions will be prioritized in the Chrome Web Store, including in search results and recommendations
> Beginning June of this year, we will begin to gradually disable extensions running Manifest V2 for Chrome users
> Thank you for your cooperation and participation in the Chrome extension ecosystem.
I am really dismayed that an advertising company has such a stranglehold on the web. They are not good custodians.
Nevertheless, if I wish to keep my extension in the Chrome Web Store, and keep it working in Chrome browsers, I am required to bend to Google's demands and spend a considerable chunk of my time to perform this unnecessary update. And it must be done NOW!, with an artificial sense of urgency. Time is precious, and I'd really rather not donate mine to a multibillion dollar advertising corporation. Google is the primary beneficiary of Manifest V3. They are demonstrating why they abandoned their "Don't be evil" mantra[2].
My browser extension doesn't make money. I made it purely to improve my own browsing experience, and shared it for free with others. It's working fine on Manifest V2, and has done so for years. I have no desire to learn Google's crappy new implementation.
[1] https://www.androidauthority.com/google-chrome-manifest-v3-c...
[2] https://gizmodo.com/google-removes-nearly-all-mentions-of-do...