News: 1618864032

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

WordPress core contributor proposes treating Google FLoC as a security vulnerability

(2021/04/19)


A proposal by a WordPress core contributor to treat Google's FLoC ad tech as a security vulnerability, and therefore backport an automatic opt-out to previous WordPress versions, shows the depth of community opposition to the technology.

FLoC (Federated Learning of Cohorts) is Google’s scheme to replace third-party cookies with an ad personalisation system based on groups of users. It has run into wide [1]opposition from privacy advocates and browser makers, but Google has nonetheless pressed ahead with trials in the current version of Chrome.

[2]

Now a WordPress Core contributor has [3]proposed treating “FLoC as a security concern.”

The proposal is significant because WordPress is the most popular content management system on the web, with around a 40 per cent market share according to [4]builtwith . It relies on the fact that websites can [5]opt out of FLoC via a new interest-cohort permission policy. This involves sending an HTTP response header:

[6]

Permissions-Policy: interest-cohort=()

If WordPress were to treat FLoC as a vulnerability and apply this header to all WordPress sites that automatically apply security patches, a substantial proportion of the web would be opted out.

Sites that specifically want to use FLoC, most likely because the site owners believe it will improve income from advertising, would be able to enable it. In effect, for WordPress sites the scheme would become opt-in rather than opt-out.

The author of the proposal, Carike, added that there is also a feature request to make the next version of WordPress, 5.8, opt-out of FLoC by default – but remarked that “5.8 is only scheduled for July 2021. FLoC will likely be rolling out this month.”

The WordPress proposal won immediate support and offers for help from other developers. “WordPress should be taking an Apple like stance on privacy with this,” [7]said one .

Security... or privacy?

There are of course also naysayers, such as [8]this one arguing that “those websites who want to block FLoC are likely to have the technical know-how to add in the header and disable it ... Where do we draw the line at what WordPress should be blocking in core for privacy? ... Calling it a “security concern” is just absolutely false and sets a dangerous precedent for what is security, and what is privacy.”

Google's FLoC flies into headwinds as internet ad industry braces for instability [9]READ MORE

This concern was echoed by another who [10]said “while I agree with the overall sentiment here, I think it is a mistake to treat this as a security update and risks abusing user trust in automatic updates.”

Despite opposition from the development community, there are likely to be plenty of site owners who would rather have FLoC enabled than risk reduced advertising revenue. Much of what is called SEO (Search Engine Optimisation) is focused on how to optimise a site for Google and it is likely that supporting FLoC will simply be added to the list of steps web sites should take in order to perform at their best from a commercial perspective.

This unusual proposal does demonstrate the depth of opposition to FLoC. It also suggests that Google needs to secure W3C support in order to win support for the scheme beyond Chrome. That currently looks difficult, with WC3 bodies like the Technical Architecture Group (TAG) [11]calling First Party Sets, another part of Google’s privacy sandbox, “harmful to the web in its current form”. Google has [12]requested a TAG review of FLoC, but given the speed of its rollout, it is not clear how much weight the company attaches to the W3C’s views.

[13]

Last week, [14]Google told us : "The Privacy Sandbox proposals are developed as part of a collaborative, open-source effort and we welcome feedback as we continue working with the W3C and broader web community to find solutions that improve privacy while maintaining a healthy ecosystem." ®

Get our [15]Tech Resources



[1] https://www.theregister.com/2021/04/17/google_floc_adoption/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YH39dqETqlc5GdV6gt4j2gAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://make.wordpress.org/core/2021/04/18/proposal-treat-floc-as-a-security-concern

[4] https://trends.builtwith.com/cms

[5] https://github.com/WICG/floc#opting-out-of-computation

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YH39dqETqlc5GdV6gt4j2gAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://make.wordpress.org/core/2021/04/18/proposal-treat-floc-as-a-security-concern/#comment-41060

[8] https://make.wordpress.org/core/2021/04/18/proposal-treat-floc-as-a-security-concern/#comment-41063

[9] https://www.theregister.com/2021/04/17/google_floc_adoption/

[10] https://make.wordpress.org/core/2021/04/18/proposal-treat-floc-as-a-security-concern/#comment-41071

[11] https://www.theregister.com/2021/04/08/w3c_google_multple_domains/

[12] https://github.com/w3ctag/design-reviews/issues/601

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YH39dqETqlc5GdV6gt4j2gAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://www.theregister.com/2021/04/14/browser_makers_reject_google_floc/

[15] https://whitepapers.theregister.com/

"Permissions-Policy: interest-cohort=()"

LDS

Sites implementing it will be misteriously down-ranked by Google algorithms, until Google is caught and will accuse a "rogue developer"....

Re: "Permissions-Policy: interest-cohort=()"

b0llchit

Only one rogue? The era of do no evil has officially ended a long time ago. The presumption of innocence does no longer apply to google. Google has consistently shown to be guilty of manipulation in google's interest and they are not even hiding that fact. There is only one cohort in the flock. Therefore, the permission header should read:

Permissions-Policy: interest-cohort=(Google)

We are all interested in google and google in the only one of interest. Google is interested in all of us and we reciprocate. We may now identify with and as google. There can be only one. One flock. One cohort. One winner. One money machine. Now, get google some money; they are surely in desperate need to have more of that. And because google is us, we all make lots of money in the process.

/s

grizewald

If many sites enable FLoC because it will hurt their ad revenue if they don't, doesn't that amount to extortion by default?

"Enable this new privacy invading ad tracker or we will cut off your ad revenue."

Whatever way you try to write it, it boils down to "enable this feature or else".

Whatever happened to "Do no evil" Google?

Come on Al, if you have real arguments let hear them, if you want to insult
people you gotta do better than that above. :)

- Jakob stergaard poking Alexander Viro on linux-kernel