Begs the question of long-term support, etc...
218 karma · joined June 22, 2020
Begs the question of long-term support, etc...
Note that such a payload can come from anywhere, like a pdf document the user analyzes, an image, a spreadsheet, etc...
-) Is is possible to re-identify webpages a user visits based on Cohort ID?
-) E.g. can a website be built to show your "profile" and "interests" based on the Cohort, rather than just the FLoC ID? Google and others who (I assume) will share their back-end data will be able to build such a website.
-) Can a "rainbow table of FLoCs" be pre-calcuated? This would allow to re-identify certain browsing habits of users
-) In fact what if someone creates a Chrome extension that publishes visited domain names and their resulting FLoC ID - Imagine many people download and use it for fun! This would sort of decentralize the previous mentioned de-identification attacks and render FLoC useless for all other privacy concerned users.
-) How much easier is it now to track a user with just IP address + FLoC ID now?
BUT, what I'm missing entirely at this point is how will the web server (Google and other ad companies) actually *use/share* the Cohort information? That is not being described at all by Google - and seems rather critical to me.
More details and testing ideas in this article: https://embracethered.com/blog/posts/2021/red-teaming-floc-c...
This threat model of an ML system is quite interesting also, it highlights the various security challenges a typical ML system faces: https://embracethered.com/blog/posts/2020/husky-ai-threat-mo...