Google proposes a new tracking superpower in Chrome
Google might not be completely ready to give up website cookies just yet, but the company is certainly investigating alternatives like a user-tracking ad platform built into one of the most popular web browsers available.
Google logo
For the most part, Google has at least put up a little bit of an effort to reduce the amount of tracking it does, like the Privacy Sandbox for Chrome. Technically, Google is still working towards phasing out third-party cookies. Until then, though, the company is also working on alternatives -- for more tracking.
Apple has its suite of features built into its software platforms to limit device and user tracking. That includes the likes of Privacy Report in Safari, which automatically limits web tracking.
Google is currently proposing what it calls the "Web Environment Integrity API," which is a new web standard that's pretty similar to something like Digital Rights Management, or DRM. It's meant to identify the user at the computer, all to reduce the usage of bots accessing sites like social media or to stop people from cheating in online games.
The new API proposal is published on GitHub, by one of the four Google employees who authored it, but it is already prototyped within Chrome. No wide launch has been announced or even hinted at yet.
First picked up by HackerNews over the weekend, Ars Technica notes that Google's proposal is one that's entirely encompassed by Google services, like Chrome and Google search. And, unsurprisingly, it's a similar standard that's already present in not just Android, but also iOS.
Android has something it calls "Play Integrity API," and it's designed to identify Android devices that have been rooted. A lot of web developers are not a fan of having their apps accessed on rooted devices, no matter the reason why that device was rooted.
As a result of the API, many apps won't function if they are downloaded on a rooted device, including Netflix, and even Google's own Wallet app. And this new web standard for Chrome would work similarly.
Apple's equivalent to the Play Integrity API is called App Attest, which checks for valid app clients.
Chrome could get more privacy intrusive in the future
Google's Web Environment Integrity API would require that the user pass an "environment attestation" test before that user could access any data on a website. Accessing an attestation server, the user would get the question, prove they aren't a robot, and then be given a token to access the site they are trying to reach.
This is where Google's umbrella comes in, with Chrome serving as the gateway to this particular API, one of the world's most popular web browsers. Then it's a safe bet that Google is in some way related to the website getting delivered to the user, and Google may even be associated with the attestation server.
In an available explainer, Google does say it's not trying to single out individual Chrome users, or digitally fingerprint them. However, it adds that there should be "some indicator enabling rate limiting against a physical device."
Commenters have been leaving issue reports on the proposal since its discovery. "Issue #134" calls out the idea as being "absolutely unethical and against the open web," for instance. There are even a few comments posted purely in hexadecimal, which get colorful.
For now, Chrome remains a viable option as an alternative to Apple's Safari. However, if privacy from ad tracking is a priority, Chrome may be a less useful tool in the future if its foundation is built on fingerprinting users.
Read on AppleInsider
Comments
India has jumped ahead of Germany and France, in terms of iPhone sales, Apple won’t be the dominant smartphone (they don’t need to be) in India but they will be the most profitable by far they only need 10% to 15% of the market.
https://www.fool.com/investing/2023/07/20/better-buy-apple-stock-vs-microsoft-stock/
https://www.cnbc.com/2023/07/18/india-is-now-one-of-apples-top-5-iphone-markets-for-the-first-time.html
Thank you so much for supercharging your mining of my data to provide me with more targeted advertising to improve my online experience.
Insincerely,
Sayid No'one Evar
“It Is Difficult to Get a Man to Understand Something When His Salary Depends Upon His Not Understanding It”
Personally, I'm not sure if I care. No intelligent person would use Chrome on any Apple device. Give the Darwin award to people who do.
If they don't believe there is such a company, (there was when I googled it exactly 5 years ago) you can then offer your friend $1/day to attach a similar "bug" to their body so that you can hear what they are doing in the privacy of their own home all day long. Maybe there's an existing app for Apple Watch that sends an audio recording of everything it hears to your computer. Loan them an Apple Watch with that software installed and pay them $1/day to have this audio bug attached to them all day (and night) long. Then after a month tell them what you learned about them.
https://httptoolkit.com/blog/apple-private-access-tokens-attestation/
I don't think the proposal of attestation is a good idea but it's dishonest to say Safari is going to be the solution when it already has this feature. Using something like Firefox might be a better idea.
Also, I'm not sure how the WEI API would permit additional cross site tracking either.