惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

SecWiki News
SecWiki News
WordPress大学
WordPress大学
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
Project Zero
Project Zero
博客园 - 聂微东
Recorded Future
Recorded Future
MongoDB | Blog
MongoDB | Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Stack Overflow Blog
Stack Overflow Blog
T
The Exploit Database - CXSecurity.com
博客园 - 三生石上(FineUI控件)
C
CERT Recently Published Vulnerability Notes
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Engineering at Meta
Engineering at Meta
美团技术团队
Microsoft Azure Blog
Microsoft Azure Blog
C
Cisco Blogs
www.infosecurity-magazine.com
www.infosecurity-magazine.com
小众软件
小众软件
N
News and Events Feed by Topic
D
DataBreaches.Net
量子位
B
Blog RSS Feed
Apple Machine Learning Research
Apple Machine Learning Research
F
Fortinet All Blogs
博客园 - 司徒正美
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
T
Tailwind CSS Blog
Spread Privacy
Spread Privacy
Blog — PlanetScale
Blog — PlanetScale
M
MIT News - Artificial intelligence
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
C
Check Point Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
爱范儿
爱范儿
S
SegmentFault 最新的问题
人人都是产品经理
人人都是产品经理
C
CXSECURITY Database RSS Feed - CXSecurity.com
Hugging Face - Blog
Hugging Face - Blog
AI
AI
腾讯CDC
I
InfoQ
P
Palo Alto Networks Blog
G
Google Developers Blog
T
Threat Research - Cisco Blogs
T
Tenable Blog
Vercel News
Vercel News
Google Online Security Blog
Google Online Security Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Blog of Simple Analytics

The EU wants to kill cookie banners Google is tracking you (even when you use DuckDuckGo) German court rules Meta’s tracking tech violates GDPR Closing the data gap - Simple Analytics x Usercentrics The EU-US data deal may be dead in the water You are missing 20% of your website data with GA4 How a reverse trial will push Simple Analytics to the next level Google will start tracking all your devices (WTF?) Big Tech Fails EU’s Digital Services Act: Only Wikipedia Passes the Test Meta fined $102 million by the Irish Data Protection Commission Europeans spend 575 Million hours per year clicking cookie banners The most interesting GDPR fines GDPR and fines: all there is to know Google loses key antitrust case Web Analytics for Crypto Companies Web analytics for publishers Privacy Monthly July 2024 Privacy Perspectives June 2024 Privacy Monthly June APRA fumbles targeted advertising Privacy Monthly May Meta loses key privacy battle Google delays cookie phase-out once again Privacy Monthly April 2024 Web Analytics and Consent Cookies 101 Privacy Monthly March 2024 German authority cracks down on cookie banners Google Tag Manager vs Google Analytics Google search alternative Data retention in Google Analytics Guide to Google Analytics and Cookie consent What are Google Analytics' identifiers? How to export data from Google Analytics Privacy Monthly February 2024 The Criteo case: a big deal for Big Tech Privacy Monthy January 2024 What the Digital Markets Act means for privacy Google Settles in $5B Incognito Mode Lawsuit Legal troubles for Adobe Analytics Web analytics for nonprofits HIPAA and mental health Why Meta subscriptions are under attack, and why it matters for privacy Privacy Monthly: December Simple Analytics AI Host analytics on Cloudflare Zaraz Add Google Analytics to Convertkit Google Analytics Pricing - Paid vs Free Road to 1 Million ARR - October update CCPA and Data Protection: all there is to know Analytics without a cookie banner Enterprise Analytics Privacy Monthly: November 2023 Delete Act: all you need to know Mobile App Tracking Under Fire The road to 1 Million ARR - September Update Privacy Monthly: October 2023 HIPAA violations First challenge to the EU-US data transfer framework Direct Marketing under GDPR Road to 1 million ARR - August Update CCPA vs CPRA: what is new? Privacy Monthly: September 2023 A/B Testing with Simple Analytics Dobbs v. Jackson ruling is a privacy mess Privacy Monthly: August 2023 What are your rights under the CCPA? When does the CCPA apply? How does the HIPAA compare to the CCPA and GDPR? Why Meta is in a world of trouble CJEU: cookie-based analytics collects sensitive data Road to 1 million ARR - July update All about the new Data Transfer Framework Road to 1 Million ARR - June update What is PHI under HIPAA? Sweden declares Google Analytics illegal Searching for GA4 Alternatives? Top 10 Reliable Options for Google Analyticss Ultimate HIPAA Compliance Checklist: Essential Steps for Healthcare Providers Privacy Monthly: June 2023 More troubles for Google Analytics The path to 1M ARR - May Update Data Processing Agreements Minimal Product Analytics Facebook data transfers declared illegal Is Google Analytics CCPA-compliant? Help us with your input Cookie banners: How to stay GDPR compliant? GDPR Compliance Checklist Privacy Monthly: May 2023 Simple Analytics: Privacy-first website analytics Improve your e-commerce performance with analytics European Facebook blackout is closer than we think Know your website’s Carbon Emissions - and how to reduce it The path to 1M ARR - April 2023 How to add video tracking using Google Tag Manager? How to track form submissions using Google Tag Manager? Why is my Simple Analytics data different from Google Analytics? Debug Simple Analytics script How to Import Google Analytics Data to Simple Analytics
Google pulls Uno Reverse card: Rolls back decision to kill third-party cookies
Carlo Cilent · 2024-07-30 · via Blog of Simple Analytics

Google officially announced it will scrap its long-delayed plan to deprecate third-party cookies on Chrome. Third-party cookies are here to stay despite years of promises to the contrary.

This is big news: third-party cookies are a crucial part of the ad tech ecosystem and a pressing privacy issue. Here is all you need to know about the decision and its implications for online privacy.

  1. What are third-party cookies?
  2. What is wrong with third-party cookies?
  3. Why is Google so important for cookies?
  4. Why didn’t Google deprecate cookies?
  5. What will Google do?
  6. What does this mean for privacy?
  7. What is in store for ad tech?
  8. Final Thoughts

What are third-party cookies?

As you probably know, cookies are small files that browsers exchange with servers. They are used for all sorts of purposes: showing targeted advertising, authenticating users, remembering UI preferences or the items in your shopping cart, and so on.

First-party cookies can only be read by the domain that placed them in your browser while third-party cookies can be read by other domains. This makes third-party cookies very useful for targeted advertising because an advertiser can learn about your interests based on your browsing habits and display an ad that you are likely to be interested in.

What is wrong with third-party cookies?

There is a serious and obvious downside to third-party cookies: websites can learn a lot about you from your browsing behavior - including intimate information that could compromise you, expose you to exploitative advertising, and get you in trouble in a number of other ways.

To make things worse, targeted advertising is powered by the exchange of information between many actors. It is not about an individual website learning information about you: your personal information is disclosed to an enormous number of advertisers bidding for each ad placement (including the hundred advertisers that lose each bid!), and passed on to data brokers with questionable data governance.

Long story short, the real time bidding environment behind targeted advertising is nothing short of a dumpster fire, as the ICCL explained in detail.

And yet, third-party cookies have long been a staple for ad tech despite the privacy issues. But the winds are changing: the public is increasingly concerned about data privacy and many legislations around the world passed stringent privacy legislations in the wake of the GDPR. The climate is not as favorable to the widespread use of third-party cookies as it was in the early, wildly unregulated days of Web 2.0 and the industry is reluctantly adapting to these changes by leaning towards first-party data.

Why is Google so important for cookies?

Google Chrome is the only major browser to accept third-party cookies by default and accounts for a whopping 65% of the browser market worldwide. Google is effectively keeping third-party cookies on life support in a browser market that has long moved on.

Google’s motives are obvious: the company is an ad tech monopolist (which is why, incidentally, the US DOJ is attempting to break up its ad tech stack). The company owns many of the key services that power the ad tech environment, including Google 360, AdExchange, DoubleClick, and Google Analytics.

Google cookies That’s not what a healthy market looks like (source: US DOJ).

For a long time Google’s lucrative ad tech environment was largely powered by the invasive user tracking allowed by third-party cookies. But even Google eventually acknowledged that tracking users across websites was not sustainable in the long run. So, the company started experimenting with ways to move past third-party cookies without destroying its own ad tech empire.

Google’s plan for replacing cookies revolved around several key points. The company started working on new standards and ideas for facilitating (supposedly) privacy-friendly targeted advertising. Collectively, these proposals were dubbed the Privacy Sandbox. Google would not only develop these standards, but also nudge stakeholders towards embracing them by deprecating third-party cookies as well as Universal Analytics- the older version of Google Analytics built on third-party cookies.

Things didn’t go as planned. The company first announced the deprecation of cookies in 2020 with 2022 as the deadline and later pushed the deadline to 2023, 2024, 2025, and never. Cookie deprecation basically became something of a joke in the tech community.

Google Cookie U-turn Google will surely deliver.

Why didn’t Google deprecate cookies?

Google never got around to kill third-party cookies because it failed to replace them. A first proposal called FLoC (Federated Learning of Cohorts) was scrapped after facing backlash from privacy advocates, regulators, and some stakeholders. Google tried again with a proposal called Topics and it met the same fate as FLoC.

We have another blog on Topics so we won’t bore you with the details here. Long story short, Topics analyzes the user’s browsing history to figure out their interests and broadcasts them to advertisers. Much like under FLoC, this analysis is carried out by the Chrome browser directly and does not involve Google’s servers.

Not everyone was happy about that. The developers of other browsers (with the notable exception of Microsoft) wouldn’t touch Topics with a ten foot pole. They pointed out that browsers are user agents: they are supposed to work for the benefit of the user, not the developers.

Topics suffered from other problems too. Privacy advocates claim that Google used deceiving language to sugar-coat Topics as a “privacy feature” in order to collect consent from Chrome users. The Mozilla Foundation examined Topics in depth and highlighted its vulnerability to re-identification attacks. Last but not least, the UK privacy watchdog and antitrust authority both took issue with Topics.

What will Google do?

Google hasn’t scrapped the Privacy Sandbox entirely but isn’t looking to get rid of third-party cookies anytime soon. So, replacing them remains a long-term goal at best.

The company has been vague over its next moves. Its blog mentions that they are working on “a new experience in Chrome that lets people make an informed choice that applies across their web browsing”, which sounds like tighter restrictions over third-party cookies will be implemented.

It is hard to see how this “new experience” could represent a meaningful change for privacy. Again, Chrome is the only major browser that accepts cookies by default. Safari, Firefox, and even Microsoft Edge are shipped with privacy-friendly cookie settings. Only Chrome is that invasive by default.

But hey, the user will be "able to adjust that choice at any time”. As if enjoying some degree of control over your personal data was a gracious concession from the company rather than a legal requirement in the EU and many countries around the world.

What does this mean for privacy?

On the one hand, third-party cookies are still around and that sucks. On the other hand, we are happy to see that the proposal to turn a browser into a tracking machine was met with the backlash it deserved. This backlash may actually force Google to come up with a good proposal that strikes a better balance between privacy and advertising necessities.

But is such a balance even possible?

The public has shown time and time again that it doesn’t like tracking. When Apple implemented user controls over third-party tracking in 2020, a whopping 96% of US users opted out of tracking- a number that exceeded advertisers’ worst fears. Would the public respond any better if companies promised to track users a little less, like Google did with Topics?

This is not a theoretical question. Each year privacy laws around the world increasingly reinforce the principle of user control over their personal data and often require consent for tracking users. This is why commercial surveillance is largely built on user blackmail and deception.

We see these two strategies all the time: Google chose deception for Topics while Meta opted for [take-it-or-leave-it extortion] for Facebook and Instagram. It is not just the big fish, either: many online news outlets present readers with cookie walls and countless apps refuse to work unless you give them permission to access data on your device which they don’t really need except for monetization.

But these practices are facing increasing scrutiny from regulators and relentless challenges from privacy advocates. These advocates have some legal ammunition on their side as the GDPR sets a high standard for valid consent- as do legislations inspired by the Regulation. Deceiving or blackmailing users is not only shitty but also increasingly risky in the current regulatory landscape.

This is a time of uncertainty. Regulatory developments will deeply impact the ad tech environment in the next future but it is hard to say how just yet. Regulators may legitimize invasive practices that currently sit in a legal gray area or deliver the final blow to commercial surveillance- at least in the key European market.

Meta’s long-running pay-or-ok saga is commercial surveillance’s last stand in Europe. We already have a blog about pay-or-ok so here is the takeaway: the Court of Justice needs to clarify to what extent and under which conditions companies can ask users to pay with their data. The answer to these questions will have immense implications for ad tech as a whole and may very well end up killing cookie walls and other forced consent practices.

The European will play a key role as well: the long awaited ePrivacy Regulation is in the works and should eventually replace the ePrivacy Directive that currently governs cookies in the EU. The final draft may stick to the strict approach of the Directive and enforce strict consent, or carve some room for (allegedly) privacy-preserving approaches to advertising. The Regulation may also take a page from the CCPA and strictly enforce Global Privacy Controls or other do-not-track signals from browsers.

Last but not least, there is ADPPA- the US’ latest bipartisan attempt at a federal privacy law. ADPPA would have an enormous impact on the ad tech environment as a whole because the Google/Meta duopoly is subject to US legislation. The current draft is unclear when it comes to advertising, to put it mildly. Hopefully, new drafts will be formulated more clearly and give us a glimpse of what lies in store should ADPPA become law.

Final Thoughts

With all these regulatory developments in the work, we may see a privacy-friendly Internet soon enough. But why wait?

We believe in an independent internet that is friendly towards its visitors. That's why we built Simple Analytics to provide you with all the traffic insights while preserving user privacy.

No cookie banner. 100% GDPR-compliant and easy to use. Feel free to give it a spin.