Privacy proves elusive in Google's Privacy Sandbox
- Reference: 1627588506
- News link: https://www.theregister.co.uk/2021/07/29/google_privacy_sandbox_fledge/
- Source link:
The [1]Privacy Sandbox consists of a set of web technology proposals with bird-themed names intended to aim interest-based ads at groups rather than individuals.
Much of this ad-related data processing is intended to occur within the browsers of internet users, to keep personal information from being spirited away to remote servers where it might be misused.
[2]
So, simply put, the aim is to ensure decisions made on which ads you'll see, based on your interests, take place in your browser rather than in some backend systems processing your data.
[3]
[4]
Google launched the initiative in 2019 after competing browser makers began blocking third-party cookies – the traditional way to deliver targeted ads and track internet users – and government regulators around the globe began tightening privacy rules.
The ad biz initially hoped that it would be able to develop a replacement for cookie-based ad targeting by the end of 2021.
[5]
But after last month concluding the trial of its [6]flawed FLoC – Federated Learning of Cohorts – to [7]send the spec back for further refinement and [8]pushing back its [9]timeline for replacing third-party cookies with Privacy Sandbox specs, Google now acknowledges that its purportedly privacy-protective [10]remarketing proposal [11]FLEDGE – First Locally-Executed Decision over Groups Experiment – also needs a tweak to prevent the technology from being used to track people online.
On Wednesday, John Mooring, senior software engineer at Microsoft, opened [12]an issue in the GitHub repository for Turtledove (now known as FLEDGE) to describe a conceptual attack that would allow someone to craft code on webpages to use FLEDGE to track people across different websites.
That runs contrary to its very purpose. FLEDGE is supposed to enable remarketing – for example, a web store using a visitor's interest in a book to present an ad for that book on a third-party website – without tracking the visitor through a personal identifier.
[13]Google updates timeline for unpopular Privacy Sandbox, which will kill third-party cookies in Chrome by 2023
[14]Google herds FLoC back to the lab for undisclosed post-third-party-cookie ad tech modifications
[15]Google: About that whole getting rid of third-party cookies thing – we're gonna need another year or so
[16]UK competition bods to keep tabs on Google, ensure 'Privacy Sandbox' doesn't distort competition
Michael Kleber, the Google mathematician overseeing the construction of Privacy Sandbox specs, acknowledged that the sample code could be abused to create an identifier in situations where there's no ad competition.
"This is indeed the natural fingerprinting concern associated with the one-bit leak, which FLEDGE will need to protect against in some way," he [17]said , suggesting technical interventions and abuse detection as possible paths to resolve the privacy leak. "We certainly need some approach to this problem before the removal of third-party cookies in Chrome."
[18]
In an email to The Register , Dr Lukasz Olejnik, independent privacy researcher and consultant, emphasized the need to ensure that the Privacy Sandbox does not leak from the outset.
It will all be futile if the candidates for replacements are not having an adequate privacy level on their own
"Among the goals of Privacy Sandbox is to make advertising more civilized, specifically privacy-proofed," said Olejnik. "To achieve this overarching goal, plenty of changes must be introduced. But it will all be futile if the candidates for replacements are not having an adequate privacy level on their own. This is why the APIs would need to be really well designed, and specifications crystal-clear, considering broad privacy threat models."
The problem as Olejnik sees it is that the privacy characteristics of the technology being proposed are not yet well understood. And given the timeline for this technology and revenue that depends on it – the global digital ad spend this year is expected to reach [19]$455bn – he argues data privacy leaks need to be identified in advance so they can be adequately dealt with.
"This particular risk – the so-called one-bit leak issue – has been known since 2020," Olejnik said. "I expect that a solution to this problem will be found in the fusion of API design (i.e. Turtledove and Fenced Frames), implementation level, and the auditing manner – active search for potential misuses.
"But this particular issue indeed looks serious – a new and claimed privacy-friendly solution should not be introduced while being aware of such a design issue. In this sense, it's a show-stopper, but one that is hopefully possible to duly address in time." ®
Get our [20]Tech Resources
[1] https://developer.chrome.com/docs/privacy-sandbox/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQMlFDiGhmPLFCf@37TC@wAAAI4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQMlFDiGhmPLFCf@37TC@wAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQMlFDiGhmPLFCf@37TC@wAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQMlFDiGhmPLFCf@37TC@wAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://blog.mozilla.org/en/privacy-security/privacy-analysis-of-floc/
[7] https://www.theregister.com/2021/07/08/google_floc_changes/
[8] https://www.theregister.com/2021/06/25/google_thirdparty_cookies/
[9] https://privacysandbox.com/timeline
[10] https://developer.chrome.com/docs/privacy-sandbox/glossary/#remarketing
[11] https://developer.chrome.com/docs/privacy-sandbox/fledge/
[12] https://github.com/WICG/turtledove/issues/211
[13] https://www.theregister.com/2021/07/26/google_privacy_sandbox_roadmap/
[14] https://www.theregister.com/2021/07/08/google_floc_changes/
[15] https://www.theregister.com/2021/06/25/google_thirdparty_cookies/
[16] https://www.theregister.com/2021/06/11/uk_cma_privacy_sandbox/
[17] https://github.com/WICG/turtledove/issues/211#issuecomment-889269834
[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQMlFDiGhmPLFCf@37TC@wAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[19] https://www.emarketer.com/content/worldwide-digital-ad-spending-2021
[20] https://whitepapers.theregister.com/
Re: On the internet "privacy" is always in quotes
Not so, it is a lot easier for Google to track you even if all the traditional tracking like cookies are blocked since they own the biggest clients (Android and Chrome) and some of the biggest destinations (Google Search, Gmail, Play Store, anything hosted on Google Cloud)
That's why Google needs to be broken up, and at minimum be forced to divest Android and Chrome. Owning both the client and server ends of so much traffic is a privacy disaster.
Re: On the internet "privacy" is always in quotes
The search engine should also be split from AdSense. It creates a conflict of interest.
The same goes for Google Cloud. Basically the whole "Alphabet" should be split into independent companies.
Google search business model should change to selling access to the search database (which funnily enough they built largely without asking the website owners they crawled for consent - contrary to the popular opinion, not every website wants to be in Google search).
AdSense then could use that access bought on the open market to build a search engine with their ads, but so anyone else could do it. That creates competition and removes perverse incentives Google currently has.
Plus Google, Amazon and other companies tax affairs should be thoroughly scrutinised. They say they are compliant, but so said people caught in things like Loan Charge scandal. I hope that HMRC will start looking into classic tax avoidance schemes like fake IP costs and look 20 years back for any tax that should be paid.
Cheeky Jokers
a set of technologies for delivering personalized ads online without the tracking problems presented by cookie-based advertising – continues to struggle with its promise of privacy.
They want to sidestep the regulation and use Orwellian language to justify it.
War is peace
Personalised ads don't violate your privacy
and so on...
Can we ban any sort of advertising that is based on targeting at point of delivery?
If you have a business selling car parts, you should advertise it on a car forum, not use Facebook or other platform to stalk people and manipulate them into buying your services.
Oh right, Facebook and Google pretty much killed independent web.
"First Locally-Executed Decision over Groups Experiment"
Is this an attempt to "baffle 'em with bullshit" from Google??
(Being serious, actually... not joking)
On the internet "privacy" is always in quotes
In fairness, it's not easy to design a system that will block tracking by Google's competitors without impeding Google's own ability to track you.