8 ms·
Rebranding FLoC Without Addressing Key Privacy Issues
- fartcannon 5y agoI would use Brave if they didn't use chrome as a backend. We need more diversity in rendering engines otherwise things like FLoC happen.
- sneak 5y agoFLoC has nothing to do with rendering and can easily be removed from the codebase. People make this argument a lot but I don't think it makes logical sense. We all use libicu too, what does that ultimately matter?
- fartcannon 5y agoWell that is great news. It ultimately matters because if we didn't all use Chrome, Google would have to compete more on good things, instead of building bad things that we have to remove. Basically, it's the position of the privacy whack-a-mole oveton window.
- akvadrako 5y agoDiversity of code bases limits the impact of bugs and implementation quirks. For example I used to be part of a team that ran an important DNS service. We purpously used several different server softwares on different nodes to increase resiliency.
- kmeisthax 5y agoRendering engine diversity is a different problem. In order to actually have a web standard, then we need at least two frequently-used implementations. If there is only one implementation, or one dominant implementation, then people stop coding to the spec and start coding to whatever works in browser.[0] Right now, if Mozilla goes bust, then the last hope for web standards is the fact that Apple's mobile OS rules preclude shipping Blink on iOS. If everything is Chrome, then we're right back to the days of Adobe Flash Player, where bugs in one implementation effectively become part of the spec. If we didn't have or didn't care about this problem, then yes - we could just clip FLoC out of the browser and run that. However, that also assumes Google won't mandate FLoC or ban alternative browsers. Their recent attempts to cut down on credential stuffing through headless CEF browsers[1] have already made it harder to actually ship an alternative browser that can log into Google. So hypothetical future Evil Google could totally say "no FLoC, no service" and we would be screwed. [0] This is the same reason why WebSQL died on the vine. SQL is a standard with a lot of wiggle room, enough that most applications either only work on one particular flavor of DB, or ship separate drivers for each DB they need to work with. In practice everyone shipped SQLite, so WebSQL was just "here's a sandboxed SQLite instance". [1] Which, BTW, is not a bad thing in and of itself.
- novok 5y agoWhats wrong with websql being sqlite?
- badsectoracula 5y ago> where bugs in one implementation effectively become part of the spec. Isn't this basically how HTML5's parsing rules came out, except instead of bugs in one implementation it is based on bugs on all implementations? :-P
- tadfisher 5y agoIf you want to ship a browser without writing a browser engine, there are three realistic options. Chromium is the best of these options.
- eitland 5y ago> [...]there are three realistic options. Is the Librewolf option included in those three? Because that (a patch on top of newest Firefox) is something I have been wanting for a long time and I just recently realized someone had done it. > Chromium is the best of these options. Easiest is maybe the word you are looking for here? Because best depends on your goals. If your goal is to reduce dependency on Google (as it is for many here) it could be close to directly counterproductive.
- WithinReason 5y agoI believe Brave was initially (supposed to be?) based on Firefox but needed support for a feature that only Chromium supported and had go with that.
- donkarma 5y agofeature was DRM
- stingraycharles 5y agoIMHO it was a big mistake of Firefox fighting the DRM for so long. It pushed many users and projects towards Chromium.
- autoexec 5y agoI wish they'd kept it up myself. It's not as if folks can't have more than one browser for different things. Now that even the W3C has sold us all out we're pretty much doomed to get screwed over by DRM at some point in our lives online.
- lovefeature 5y ago
- jqpabc123 5y ago"Don't be Evil" wasn't a motto --- it was a warning. A peak into their mindset that foretold what they were thinking and where they were headed. They sell you and your privacy to their "associates" --- aka, anyone willing to pay in some way. Their concern for your interests only extends to the level required to invade your privacy. The thing I find most disappointing is the fact that it took so many so long to realize this.
- dylan604 5y ago>The thing I find most disappointing is the fact that it took so many so long to realize this. The lure of "free" useful things is greater than most's concern/understanding of the capabilities of tech. Gmail is useful. GDocs is useful. Search is useful. Googs has been very smart on exactly the tools they've brought to market so that the lure is maximized.
- fartcannon 5y agoTotally, or maybe a canary clause.
- 1vuio0pswjnm7 5y agoAs I recall the phrase was originally a comment from a new employee who had previously worked in the hardware industry. Still baffled by the ambiguous name given to this secretive, exploitive set of companies, "tech". What the heck is it. Its everything and nothing, IMO. A cover. The company is an intermediary, what many in other industries refer to as a "middleman". HN commenters have tried to attack this term in the past, but I just saw it a few months ago being used in a marketing slogan on the side of a company van. People outside of HN know what it means. Perhaps those who argue it is ambiguous on HN are "tech" workers who are aware of its accepted connotation in the real world. Otherwise why be concerned with the term.
- nl 5y agoPaul B worked at Intel before Google. He never worked in telecoms. Incidentally he was moderately active here in the FriendFeed days. Tech means technology. Nothing ambiguous about it.
- david-cako 5y agoi hope we find each other in our versions of the internet
- smoldesu 5y agoThis comes from the people distributing an ad-fuelled cryptocurrency called "Basic Attention Token". I'll take their word with two grains of salt and a tall glass of water, please.
- fellellor 5y agoAt least you get paid for having your privacy treated as a commodity. If these people are selling indentured labor, then google is straight up promoting slavery. Brave is obviously the lesser evil.
- cmeacham98 5y ago"Lesser evil" implies Chrome and Brave are the only 2 reasonable options. You could install Firefox or ungoogled-chromium and an ad/tracker blocker.
- brnt 5y agoOr, you know, do not go out of your way to enable BAT after you install Brave.
- colordrops 5y agoHow is it evil at all if it's opt-in?
- smoldesu 5y agoIt represents a clear conflict of interest with the way I intend to use the internet. There are no half-measures with advertising, there will be no crypto in or around my browser. If they wanted to make a case for using their browser over Ungoogled Chromium, they shouldn't have started by shilling their own shitcoin. Also, their creator compensation program is quite terrible, which Tom Scott has documented quite thoroughly. It's all designed to feed back into Brave's cut, slowly siphoning your ad money to line their own pockets.
- bfung 5y agoUse a different browser that’s not chrome. Problem solved. Disclaimer: I don’t use Brave because I don’t want to see more ads. In the 90s, there were little banner ads that ran on your pc in the same app that helped you connect to the internet. That’s essentially what Brave is, except I don’t NEED to see more ads, as I needed to pay for internet in the early days. Just us a browser that blocks cookies.
- thinkmassive 5y ago> In the 90s, there were little banner ads that ran on your pc in the same app that helped you connect to the internet. NetZero & Juno, the good ol’ days of free dialup!
- mike_d 5y agoNetZero was the best. When you created an account with their custom dialer it generated a username and password pair (that the user didn't know) for the local dial-up POP in your town. The credentials were stored in a text file using a substiution cipher, so you could extract them and create your own Windows Dialer profile to get free internet without having to use their dialer that showed ads on your screen.
- ocdtrekkie 5y agoBrave is far from being my primary browser, but this is far from an accurate take. I wanted to play with Brave Rewards, and it's actually surprisingly involved to enable it and get it to start showing ads... By default, Brave is pretty much "just another Chrome clone", albeit with default privacy settings that everyone but Chrome has accepted should be standard. FWIW, NetZero was pretty cool if you couldn't afford the phone bill for using AOL. :P
- colordrops 5y agoHow are you seeing ads in Brave? I don't see anything. I believe you have to turn them on, no?
- 5y ago
- deleted 5y ago[deleted]
- newscracker 5y agoThis is Google extending an invite to the EU and other regulators to bring their war hammers and forever ban browser makers from pushing targeted ads and enabling profiling of people. Maybe break Google up and make the Google Chrome team a separate company with restrictions on how much it can work hand-in-hand with Google? Anyone in the EU who can file complaints about these abuses of market power? Tell the people you know to switch from Google Chrome to another browser as their primary one. Google will still pester them on Google’s online properties to install Chrome, and may resort to other tricks on Android. But we are at a time when this can gather momentum and result in some good for all in the future (not mainly for Google, as it seems to be now).
- hackerfromthefu 5y agoThis is the answer - forever ban targeted ads. Ads should be a display only HTML tag that just allows limited read only display WITH NO JAVASCRIPT. This would remove tracking and malware and force ads to be targeted on the content page not on the user.
- petre 5y agoHow can the EU break up a US company?
- kittywav 5y agohttps://about.google/intl/ALL_us/locations/?region=europe https://about.google/intl/ALL_us/locations/?region=europe If you don't want to follow the rules (against anti-competitive practices) of a certain set of countries, perhaps you shouldn't have offices in that set of countries? Just an idea...
- petre 5y agoOkay, so they spin off a bunch of shell companies holding all these offices and stop displaying them on the Google website in order to address the EU requests. But the mothership still gets to remain a single company.
- 1vuio0pswjnm7 5y agoHere is one way to disable "FLoC" chrome://settings/privacySandbox Evolution from FLoC FLoC ended its experiment in July of 2021. We've received valuable feedback from the community^1 and integrated it into the Topics API design. A highlight of the changes, and why they were made, are listed below: FLoC didn't actually use Federated learning, so why was it named Federated Learning of Cohorts? This is true. The intent had been to integrate federated learning into FLOC but we found that on-device computation offered enough utility and better privacy. FLoC added too much fingerprinting data to the ecosystem The Topics API significantly reduces the amount of cross-site identifiable information. The coarseness of the topics makes each topic a very weak signal; different sites receiving different topics further dilutes its utility for fingerprinting. Stakeholders wanted the API to provide more user transparency The Topics API uses a human-readable taxonomy which allows users to recognize which topics are being sent (e.g., in UX). Stakeholders wanted the API to provide more user controls With a topic taxonomy, browsers can offer a way (though browser UX may vary) for users to control which topics they want to include The Topics API will have a user opt-out mechanism FLoC cohorts might be sensitive FLoC cohorts had unknown meaning. The Topics API, unlike FLoC, exposes a curated list of topics that are chosen to avoid sensitive topics. It may be possible that topics, or groups of topics, are statistically correlatable with sensitive categories. This is not ideal, but it's a statistical inference and considerably less than what can be learned from cookies (e.g., cross-site user identifier and full-context of the visited sites which includes the full url and the contents of the pages). FLoC shouldn't automatically include browsing activity from sites with ads on them (as FLoC did in its initial experiment) To be eligible for generating users' topics, sites wil have to use the API. https://github.com/jkarlin/topics https://github.com/jkarlin/topics It is remarkable to me that Google can freely experiment on whomever they wish. If the experiments demonstrate negative effects, e.g., generation of execssive amounts of fingerprinting, it's unfortunate for those who were swept up in these "experiments". Why not ask users if they want to volunteer to particpate in a trial/experiment. Imagine if drug companies did not obtain permission to test their compounds on new patients. Instead they just substituted the new drug into what they sold on the market. Same label. Chrome is Chrome, right. Nevermind all the undisclosed variations and experiments. For example, "field trials" identified by only a number. This is hardly informed disclosure and consent. 1. This is amusing. What users were solicited for feedback. Perhaps they are referring to some surveillance they conducted, looking for mentions of FLoC.
- Kenneth21 5y ago[dead]
- adamsvystun 5y agoI hate tracking as much as the next guy, but this article is so disingenuous that it's painful to read. If you literally look up the most upvoted HN article about FLoC [1], it specifies two main issues with FLoC in BOLD: Fingerprinting and Cross-context exposure. Which if I understand correctly the Topics API fixes. But the article implies that these are minor problems that we never really cared that much about. Whether it is this or constant aggressive writing, it seems that the goal of this blog post is to simply inspire anger and hate, while not furthering the discussion on the topic. Which makes this article unhelpful (if not damaging) to the goal of personal data privacy. [1] https://news.ycombinator.com/item?id=26344013 https://news.ycombinator.com/item?id=26344013 [2] https://www.eff.org/deeplinks/2021/03/googles-floc-terrible-idea https://www.eff.org/deeplinks/2021/03/googles-floc-terrible-...
- hackerfromthefu 5y agoNonsense, as an individual that values my privacy I don't want to be distracted by Googles PR - Google is clearly a stalker, and users want it to stop! The blog post makes sensible points identifying Google's PR based response. Thus your ad hominem attack on the blog instead of the content makes me wonder if you have conflicts of interest regarding this topic?
- xg15 5y agoIn some sense you are right - the article hasn't much useful criticism of Topics in comparison to FLoC (and the Brave plug at the end makes it read like an advertisement). However I think the article is right in the sense that we shouldn't miss the forest for the trees. Image you were robbed and the robber suddenly asked if your issue with him could be solved if he only took half of what's in your wallet. Surely that would be an improvement but it doesn't solve the root issue of him robbing you in the first place. In the same sense, I think pulling attention back to the fact that Google is building third-party tracking right into the browser - and also aggressively protecting the whole concept of tracking as some sort of fundamental necessity of the web - is justified.
- throwawaythekey 5y ago
- Rygu 5y agoFLOC stands for Federated Learning of Cohort.
- cma 5y agoIf Google succeeds in making the whole web Amp, they won't need FLoC anyway.