EFF believes that replacing tracking cookies with FLoC could lead to new problems.

The Electronic Frontier Foundation (EFF) has criticized Google's FLoC API, which is part of the Privacy Sandbox initiative. It should be noted that in Chrome 89, experimental implementation of a series of APIs began that could replace third-party cookies used for tracking movements. In the future, Google plans to completely eliminate the use of cookies for tracking and discontinue support for third-party cookies in Chrome that are set when accessing sites different from the current page's domain.

The FLoC API (Federated Learning of Cohorts) is designed to determine a user's interest category without conducting individual identification and without linking to the history of visiting specific sites. FLoC allows for the identification of groups of users with similar interests without identifying individual users. A user's interests are determined using 'cohorts', short labels that describe different groups of interests. Cohorts are computed on the browser side using machine learning algorithms applied to browsing history and content opened in the browser. Details remain on the user's side, and only overall information about the cohorts reflecting interests is shared externally, allowing for relevant advertisements without tracking specific users.

According to EFF, the proposed API may replace one problem with another. If interest labels can be accessed by any site, conditions are created for user discrimination based on their preferences and views, as well as for the active use of predatory targeting.

Instead of completely abandoning targeting, Google is trying to replace old targeting with a new targeting method that comes with its own problems. EFF believes that users should decide what information to share with each site and not worry that the traces of their past activity may be used to manipulate them when opening sites. The implementation of FLoC could lead to user behavior information following them from site to site like a stigma.

The new risks include:

  • The emergence of an additional factor for the hidden identification of the user's browser ("browser fingerprinting"). Although FLoC cohorts will cover thousands of individuals, they can be used to enhance the accuracy of browser identification when combined with other indirect data, such as screen resolution, the list of supported MIME types, specific parameters in headers (HTTP/2 and HTTPS), installed plugins and fonts, the availability of certain Web APIs, graphics card-specific rendering features via WebGL and Canvas, CSS manipulations, and patterns of mouse and keyboard usage.
  • Providing additional personal data to trackers that already identify users. For example, if a user is identified and logged into their account, the service can explicitly match the preferences data indicated in the cohort with that specific user, allowing for tracking of preference transformations when cohorts change.
  • Reverse engineering of browsing history based on cohort data is also possible, meaning that the cohort assignment algorithm can provide insights into which types of websites the user likely visited. Additionally, cohort data can be used to infer age, social status, gender identity, political preferences, financial difficulties, or past traumas.
  • Discrimination based on user preferences. For instance, job offers and loan approvals may vary depending on ethnicity, religion, gender, and age. Users facing financial issues might be pushed into loans with inflated interest rates, and demographic data and political preferences may be leveraged to enhance the persuasiveness of disinformation.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster