Resistance to the implementation of the FLoC API promoted by Google instead of tracking cookies.

Launched in Chrome 89, Google's experimental deployment of the FLoC technology, aimed at replacing tracking cookies, has faced resistance from the community. After implementing FLoC, Google plans to completely end support for third-party cookies when accessing sites other than the current page's domain in Chrome/Chromium. Currently, selective testing of FLoC is being conducted on a small percentage of Chrome 90 users, and FLoC support is also included in the Chromium codebase.

Opponents of FLoC argue that this technology does not completely eliminate user tracking, but instead replaces one form of targeting with another, potentially creating new issues while attempting to solve existing ones. For instance, FLoC creates conditions for user discrimination based on their preferences and viewpoints.

Reactions from some projects regarding the integration of FLoC into the Chromium codebase:

  • One of the key developers of the WordPress content management system, which holds about 40% of the CMS market, suggested viewing FLoC as a security threat and utilizing the provision in the specification to prohibit its application and disable interest information tracking for specific sites. The refusal of FLoC can be activated on the site side by setting the HTTP header 'Permissions-Policy: interest-cohort=()'. This FLoC prohibition is suggested to be enabled by default in all WordPress instances and included in one of the updates addressing security issues.

    If the proposal is approved, FLoC will be disabled by default on all sites that automatically apply WordPress updates. For those wishing to use FLoC, there will be an option to disable the transmission of the header 'Permissions-Policy: interest-cohort=()'. A similar FLoC prohibition is also proposed to be added by default in the significant WordPress 5.8 release planned for July, which may miss the mass implementation of FLoC, hence the possibility of disabling FLoC through an intermediate update is being considered.

    In the comments, not everyone agreed on the advisability of releasing such an update, arguing that issues of security should not be mixed with concerns about privacy. Abuses of the changes proposed in automatically installed updates could lead to a loss of trust in such updates.

  • Developers of the Vivaldi and Brave Browser have refused to implement FLoC support in their products, stating that their users have the right to privacy. Representatives from Vivaldi also emphasized that things should be called by their names, and FLoC is not a privacy-enhancing technology as Google tries to promote, but a tracking technology that violates privacy.
  • The nonprofit organization EFF (Electronic Frontier Foundation) launched the website amifloced.org, which allows users to determine whether FLoC is enabled in their browser, giving them the ability to understand if they are participating in Google's experiment.
  • The search engine DuckDuckGo criticized FLoC and added blocking of FLoC in the Chrome extension DuckDuckGo Privacy Essentials, as well as banned the use of FLoC on their site duckduckgo.com (DuckDuckGo Search) by issuing the HTTP header 'Permissions-Policy: interest-cohort=()'.
  • Microsoft has not yet included FLoC in its Edge browser, taking a wait-and-see approach and trying to develop its own tracking technology called PARAKEET (Private and Anonymized Requests for Ads that Keep Efficacy and Enhance Transparency). The essence of PARAKEET is using a proxy,server, which sits between the user and the ad network. The user is assigned a unique identifier, but only the proxy receives information about it, which then transmits only a limited set of anonymized information to the ad network.
  • Mozilla and Opera do not plan to implement FLoC in their products. Apple has not yet made a final decision regarding the implementation of FLoC in Safari.
  • The ad blocker uBlock has implemented FLoC request blocking by default. A similar FLoC blocking has been added to Adguard and Adblock Plus extensions.

It is worth remembering that the FLoC API (Federated Learning of Cohorts) is designed to identify user interest categories without conducting individual identification or linking to specific browsing history. FLoC allows for the identification of groups of users with similar interests, without identifying individual users. User interests are defined using 'cohorts', short labels that describe different interest groups. Cohorts are calculated on the browser side through the application of machine learning algorithms to browsing history and the content viewed in the browser. Details remain on the user's side, while only general information about the cohorts reflecting interests, which allows for relevant advertising without tracking a specific user, is transmitted externally.

The main risks associated with the implementation of FLoC:

  • Discrimination based on user preferences. For instance, job offers and credit approvals may vary depending on ethnicity, religion, gender, and age. Users experiencing financial difficulties may be pushed into loans with high interest rates, and demographic data and political preferences could be used to enhance the persuasiveness of misinformation. When using FLoC, behavior information will follow the user from site to site, and data on past activity can be used to manipulate the user when browsing websites.
  • It is possible to reverse-engineer browsing history based on cohort data. Analyzing the cohort assignment algorithm will allow for conclusions about which sites the user likely visited. Additionally, cohorts can provide insights into age, social status, gender orientation, political preferences, financial difficulties, or past traumas.
  • The emergence of an additional factor for the hidden identification of the user's browser ("browser fingerprinting"). Although FLoC cohorts will cover thousands of individuals, they can be used to enhance the accuracy of browser identification when combined with other indirect data, such as screen resolution, the list of supported MIME types, specific parameters in headers (HTTP/2 and HTTPS), installed plugins and fonts, the availability of certain Web APIs, graphics card-specific rendering features via WebGL and Canvas, CSS manipulations, and patterns of mouse and keyboard usage.
  • Providing additional personal data to trackers that already identify users. For example, if a user is identified and logged into their account, the service can explicitly match the preferences indicated in the cohort with a specific user, and when cohorts change, track the transformation of those preferences.

Additionally, it is worth noting that representatives from the advertising industry are developing other alternative identification methods that could be used to track users in the event third-party cookies are blocked in Chrome. For instance, The Trade Desk has proposed the UID2 (Unified Identifier) technology, implementing a user identification mechanism that operates in cooperation with website owners. The UID2 identifier is generated based on information provided by the user upon registration on the site, such as email, phone number, or social media account details. Based on the encryption of UID2’s content, a token is created by the infrastructure coordinator, which the site owner can pass to advertising networks. Authorized advertising networks can obtain keys to decrypt the token and retrieve the original UID2, which can be used to build a comprehensive user profile aggregating information from various sources.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster