August 2019
258 tweets
I was trying to do the normal snap-edit-tweet and it was entirely incomprehensible. Forced consent on permissions that made no sense, no edit, some shit background colour, and tweeted it trying to exit.
It's like an implementation of Instagram by someone who's never seen it, targeted at people who are here precisely because it's not Instagram.
Sometimes I really wonder how come Twitter stays in business.
♥ 2
It's been fifty years since the first arpanet connection, they might need a second example?
♥ 1
One of the primary reasons we need the #GDPR and #CCPA (and more) today is because the @iab, under @r2rothenberg's leadership, has been given 20 years to self-regulate and has used the time to do [checks notes] nothing whatsoever.
Quoting a tweet by @r2rothenberg ↗
♥ 50↺ 16
I have spent much of my adult life working in self-regulatory environments. They are never perfect, but when they work they really deliver.
#Adtech had a chance to self-reg when the FTC asked them to — from which we got the joke known as AdChoices.
♥ 9
They got a second major chance with DNT. But the notion of a level playing field between #adtech and consumers didn't work for them so they did everything to prevent it from existing.
♥ 8
And to make things funnier the article that @r2rothenberg was citing as supporting his view is… calling for stronger enforcement of the #GDPR.
If that's not a metaphor for where the @iab's at, I don't know what is.
Quoting a tweet by @Bershidsky ↗
♥ 7↺ 3
There are quite a few industries that build their own standards overall successfully, yes. They tend to be more consumer facing though.
Hahaha, thanks Johnny — now I have to become a Brave Creator!
♥ 1
Cool job alert! Plus you'd be on the same floor as my team and it's a damn cool area to work in.
Quoting a tweet by @cwarzel ↗
♥ 2
CHALLENGE ACCEPTED.
Quoting a tweet by @RayBoomhower ↗
Whoa. Not speaking for my employer but that is remarkably cheap clickbait from @techreview. All that project is exploring is photojournalistic provenance. No one is talking about stamping out fake news, that's just made up bullshit.
♥ 3
Philosophy friends: are there good texts about events at the epistemological/physics level that you would recommend? The SEP entry is fine (plato.stanford.edu/entries/events/) but it's a lot about semantics and that's not quite so much fun.
What the actual fuck, @dominos? With this kind of ethics now we know why the pizzas are shit.
Quoting a tweet by @jmspool ↗
♥ 8
This is the Times Open blog from the folks on the inside, it's all open access! Yes they worry about fake news and they use blockchain (and make light of it), but they're only exploring the pic provenance issue. Please be the judge: open.nytimes.com/introducing-th….
♥ 3
Trademark IIRC you *have* to defend it or you risk losing it, even over stupid stuff.
Here, it's a values call from @dominos: they actually believe that blind people shouldn't get their pizza.
♥ 1
It's great to hear that you're now supporting strong GDPR enforcement. It's indeed what most helps the smaller players. A good next step to this conversation would be an @iab statement asking to transpose the GDPR to US federal law. Want to start drafting something?
♥ 4↺ 1
Maybe (if you have time) post the advice online for people to find it themselves?
♥ 4
🍿
♥ 1
That, but metric.
Include advice about how the most important factor was to have an ethical project?
♥ 3
They're all about helping.
♥ 1
Yes, or MPAA ratings (whether you like them or not). Much of the Web and Internet run that way, including on topics on which stakeholders voluntarily place constraints on themselves for common good, eg. accessibility or support for languages that wouldn’t be commercially viable.
♥ 1
This seems like the kind of thing that a browser extension (or browser!) should do. Cc @JoeBeOne.
Thanks! I searched for it and came up empty, was even looking at starting to code 😅
Wow, that's a lot of icons! The number is bigger in uppercase, too. I'm sincerely curious: is that an actual KPI?
What was your governance model when you decided to flag people visiting incest/abuse sites as part of your profiling taxonomy and how did you remediate?
Quoting a tweet by @dfgrimaldi ↗
♥ 3
Help me check my data:
* What is your enforcement mechanism for TCF fraud?
* Are you using cookie syncing to propagate AdChoices, if not why?
* What is your roadmap on DNT support?
♥ 5
I would say centralisation is also a factor. I don't think you can flip France if you don't flip Paris. Give me a tenth of the numbers of gilets jaunes but all of them Paris residents and the country is mine next week.
♥ 2
And that still sounds like a low estimate.
Srsly WTF even is French Dip?
I like the sentiment, but the way we've handled nuclear waste has been to dig a big hole in a mountain, deal with lots of angry people, and then give up and hope our kids work it out.
I'd like to do a little better with data.
♥ 4
Unless you are a data behemoth the only way you can run a business is by keeping exclusive access to your audience. Everything about adtech is built to enable others to steal that.
But it needs strong enforcement or you don't get a level playing field.
♥ 4↺ 1
💯 agreed.
There is no reason we can't have programmatic, it just needs to operate on signals other than Web-wide BT. SPO will beat a path to small players who know their audience well and can consistently deliver.
♥ 1↺ 1
This would have the added benefit of incentivising audience building over traffic driving. You get better players even at the publisher level.
♥ 2
In the current system there is little value in building an audience unless you're a big brand with a subscription business. You don't control targeting it if the audience is valuable and you often do better driving clickbait from social media anyway.
♥ 2↺ 1
I wanted all the haters out there to know that, tonight, my pizza has kimchi-marinated-pineapple on it.
There, I said it.
Don't @. Don't think about @-ing.
♥ 19
The platforms are eating all the growth in BT. Trying to fight on their forte is a losing battle. Once no competition is left, how much revenue share will they give? Being a small pub will be like being a small vendor on Amazon.
And who said context only? If you know your audience you can do much better. Small book review site that figures which users have disposable income could sell more bookcases than Wayfair retargeting people ordering pizza.
You seem to be thinking a lot more about retargeting than BT?
Yes! I'm not a big fan of fishy things on pizzas myself but more fucking power to you for eating it, may your future be paved with fish kulambu!
♥ 2
The problem is that the current model is destroying itself, so we have no choice but to build its replacement. We certainly can't count on the @iab to do anything but keep shooting us all in the feet. Nothing mystical, but it may be proprietary.
♥ 1
I said don't @ me, Dan. Come to Brooklyn fight it out!
♥ 1
Always 🤗
♥ 1
The nice people can always @ 😘
Natto is hardcore, you are brave (but I knew that). I'm not sure why you're putting camembert and Vegemite in the same category here? 😇
Yeah, we need to fix that across browsers and mobile apps. I think there's a legal argument to be made.
♥ 3
This @SMBCComics is relevant to your interests.
smbc-comics.com/comic/preferen…
♥ 1
Not yet, I'm just working from market dynamics and my experience advising or being small. What is clear is that the existing system was destroying small players, so it won't be missed.
WRT the *current* compliance struggles, I think they depend a lot on type of company, amount of legacy, and how much stupid advice they followed from some incompetent lawyer.
Hahaha haha hahahahahahahaha aaaaaaaaaaaaaaaaaaaaaaaah.
♥ 1
Privacy changes that but few have figured out how. People need to think about the why rather than about pure compliance.
Antitrust action is vital too, but if the same market rules subsist we'll just get other monopolies five years after a breakup.
Cost is relative. It's like switching energy sources. It's not cheap, but if you don't it will eventually be far more expensive.
Consumers care a *lot* in every study I've seen. They have very high expectations. That's why a consumer-hostile model is unsustainable. You can fool the people some time...
What kind of company? That seems absurdly high compared to anything I've seen.
I'll hold you to that. Let's go to Tokyo!
♥ 1
The overwhelming majority of data collected in violation of privacy isn't done first-party. Users legitimately expect the first party to have the data they give it. Plus monopoly. I wouldn't expect caring about privacy to correlate much with social media use.
♥ 1
Also, there is very strong historical evidence here:
papers.ssrn.com/sol3/papers.cf…
♥ 1
I wish!
Will it involve some entanglement?
♥ 2
Ooh, and lots of superpositions.
♥ 1
"At one point Sunday morning, so many people used the phrase “another shooting” it became one of the nation’s top 10 topics." nyti.ms/2ODW4aZ
↺ 1
Putain...
This could be a competition, but he'd need a whole commemorative monument to write up all the good ideas.
♥ 1
What's the business model of shady apps if not BT? How do device fingerprints used for identity theft end up for sale? And location data stashes get really fun, too.
Also, since when is BT good for publishers? Nothing destroys audiences better.
♥ 1
It's anecdotal of course but my ad experience has substantially improved since I moved to tracking protection.
♥ 2
It's not as if profile resurrection were hypothetical, that's exactly what cookie syncing, cross-device re-id, and identity graphs are *for*. That's how vendors pitch them.
♥ 2
Ouais quand même. Passe-lui le merci, ça va me faire la journée 😁
There is no incentive for clickbait if your business is audience driven rather than traffic driven. You can't separate advertising models from incentives of the media.
And there is no evidence that lack of BT leads to more intrusive.
There is no value in investing in audience development if someone else will monetise your work more than you. BT switches media from audiences to traffic. That's pretty basic dynamics.
♥ 2
They try more extreme things: they are driven to share more data about their users, which in turn continues to devalue their own work. We can see that downward spiral at work across news deserts.
♥ 1
That is a completely wrong methodology. You're comparing crack and flour, noting that crack sells for more, and concluding that it's good for the neighbourhood. You can't establish value to pubs from comparing populations in a market structure that harms them either way.
Where is that counterfactual though? And would you mind sticking to the facts rather than making strawmen up? I didn't say "prefer", I said "better experience", and I called it anecdotal.
It eliminates the scarcity of the primary resource of publishers. If you think that that having a detrimental impact on publishers is illogical I'm not sure where to go. This is Econ 101
But... your conclusions don't in the least follow from your data. Pubs get 2x for BT when BT & non-BT compete does not at all entail that pubs fare better in a world with BT than in a world without. That's not contentious, it's just bad logic.
♥ 1
If that's what you use to infer substantial benefits to pubs then you've effectively proven nothing, I'm afraid.
Has anyone looked seriously into the reproducibility of marketing research? Cc @ChristosEllina1
♥ 1
Well, you know...
♥ 1
It would be a pretty cool extension to automatically visualise canvases being built as you browse.
♥ 1
The causality is backwards: only by ignoring my kids do I occasionally find time to shave.
♥ 1
That's a rather cynical take.
Isn't it men's short hair that's weird and needing explanation?
♥ 10↺ 1
Thanks! I'm thinking (surprisingly) of studies of the effectiveness of various ad-targeting methods. (I know it's not your world but I thought there might be a chance!)
I've noted that people who are awesome in one trait are often totally awesome! I call this the "a" factor.
♥ 4
Many thanks, I’ll check!
♥ 1
Thanks a *lot* :)
♥ 1
If you’re looking for a great work of fiction to read on the beach this summer, this @ITIFdc report on the cost of privacy regulation is a great choice.
Quoting a tweet by @WolfieChristl ↗
♥ 9↺ 6
They massively overestimate the number of DPOs needed, estimating indirectly somehow through the number of accountants. Most business make money (that stick around, at least), far fewer carry out "regular and systematic monitoring of data subjects on a large scale." Cost: $6.3bn!
They then double-count the cost of data rights implementation and support, ignoring the fact that they would normally function from the same infrastructure. This adds up to $7bn.
A small business that considered itself to fall under Article 37.1b conditions would pretty much have to be running a personal data business. Assuming that 10% does not seem very conservative at all, neither does 25% of medium ones.
And I appreciate you reaching out — but it’s not about “sides.” I, and many others in industry, look to scholarship and think tanks to do our jobs.
I’m sorry to be candid but “Here is a collection of all the data we could think of that point in just one direction” does not help.
♥ 1
If you apply enough liquor it can work with IYIs too.
♥ 1
HIPPA is also about medical data, the sensitivity of which is not exactly a contentious topic.
Sure enough if you take the union of all privacy law ever and then assume the worst of that set you’re going to get big numbers.
But how does that help?
I have been following, and I haven’t seen anyone suggest that medial data isn’t sensitive — would appreciate a link if you have it.
Yes, some companies want to dodge HIPPA but I haven’t seen them use that argument at all.
It’s “one-sided” in the sense that “we looked at every data point above 10 and concluded the average was above 10” is one-sided. In the sense that it’s hard to have a sound decision process using a non-random sample of half the facts.
I could *almost* buy that if it didn’t end with an alternative proposal. How is that supposed to even work on a pure-cost basis? “We figure out how to make cars consume less fuel: all it took was removing the wheels!”
Does that not sound like a very biased opinion to ground supposedly quantitative research on?
I don’t understand how that script could even make it to production.
This is not a privacy seminar per se, but there are many good things and you might find stuff to borrow? data-ppf.github.io
♥ 2
It's time to bring DNT back!
♥ 1
The missing bit in the Fashion ID decision is the browser. It's the only party to know all the interactions and it jointly determines the means and purposes of the processing when cookies are shared.
♥ 1
Well, with the CCPA and all I think a growing number of people even in adtech are feeling like DNT would have been a lot simpler… there might be a window.
I saw Alessandro present it, good stuff!
Closed timelike loops. It's how time works in committee.
♥ 1
Working with the badass rest of the Data Governance team at @nytimes to share knowledge and the love of governancing.
♥ 20↺ 1
Have you written this up somewhere? I searched but that only turned up similar coverage.
Does APP switch ITP-like protection on or is tracking not part of the threat model?
I know what it is, I meant of the tech trade-offs you were describing to justify the login requirement.
Ok, can you detail which use cases?
And you seem to be saying something very different now. It could be turned on *conditionally* without being logged in — right?
♥ 2
Sorry if I'm being thick but I still don't understand why this cannot be implemented as:
☑️ Scan malware more actively (risks increased false positives)
♥ 6
Yes, Binary Transparency is definitely cool — I assume that won’t require logging in?
I see @laparisa, @sleevi_, and @tabatkins jumped in to like/RT your response maybe they can help clarify why it would necessitate authentication?
The reason words fail me is because I know a large number of really great people on the Chrome team but this really does not register as the kind of trustworthy behaviour I know they stand for.
So, yes — please help me see how this is required!
♥ 1
Anyone want to nominate me for the “IAB Data Rockstar” award 😄 iab.com/2019-iab-data-…
♥ 7
I'll start harsh because Chrome's track record on privacy is terrible and the history of trying to corral people into logging into it is well established as user hostile.
I'll be chill if you engage, on the assumption I'll get an honest answer.
Sadly, I'm not seeing one.
♥ 2
What's not chill is using important security features to drive authenticated KPIs no matter how marginal. I put that in the same box as using 2FA phone numbers to target ads.
I'm sincere when I say I'd like that to be the wrong impression. But no one seems to be making that case?
♥ 3
No, it doesn't. You could have it on by default for authed APP users without requiring to be authed to activate. The idea that one should reveal their identity to a network agent, what's more one that bleeds data all over, to benefit from a security feature seems pretty bad.
♥ 1
Hahaha, oh dear! I was thinking of this as the best recommendation for the position 😁 techcrunch.com/2019/08/02/don…
Fair, but *data* rock star, man! OK I guess that's @ndw.
Are you trying to imply maybe I don't belong? 😏
♥ 1
It's a cool feature, my understanding from what Chris said was that he was researching it, hey, I think that's cool.
That's what I would think, but so why? Not only as @jyasskin says, is Google part of the threat model but Chrome knowing your identity opens the door to bugs that could leak it - not ideal for some of the target population.
Add to this a background of Chrome being by far the most pro-surveillance browser and this being yet another feature in a long list of Chrome favouring Google and I would say it's a pretty bad look.
Right now you have to be logged in to get APP. It could instead be a default for logged in APP users and an option for those not logged in. No?
But that's the point: the feature is useful to people at (possibly serious) risk, it's simply safer not to require them to provide an identity.
Lots of internal material that we couldn't share in there, but at some point we should do an external version, in fact @k_johnsn has presented some of this at Women in Analytics.
Also, you're in the deck 😉
♥ 3
That's what data rockstars do!
Well it's a serious topic, really.
Fair. I am mindful of the fact that we have different sensitivities when it comes to yet another papercut in a long list of Chrome favouring Google integration and vice versa.
Thank you for your patience and good intentions, have a good day all!
♥ 1
That's the spirit :)
♥ 1
I see a bunch of lecture notes by searching, but your screenshots look better - care to share where you are getting them from? Thanks!
Brilliant, thanks a lot!
TFW when you've run out of bad takes but you need to write something anyway.
Quoting a tweet by @nytopinion ↗
♥ 6
I am so ready for a "but... but think of the innovation!" meme.
♥ 1
Well, the one page of intro you posted seemed like a pretty cool way to get started. And video+notes works better for me than just video, so I'm very tempted.
But I need to do some peeking ahead before committing to see if I'm going to be somewhat comfortably out of my depth or just drowning.
I don't mind not getting all the way through so long as I can make some degree of progress. Years of slowly accrued wisdom have taught me that, surprisingly enough, running out of breath is less painful than splattering up my face against a cliff. YMMV.
None whatsoever, and if I did I wouldn't use it. We're better off with some bad takes than with a world in which Opinion isn't protected from intervention from the business side! I guess you could say that ethics leads to bad takes 😉
I understand that this isn't SafeBrowsing and that's fine, if it were I assume that it would be on for everyone. I essentially have one issue and one open question.
The issue is what @Sally_Hubbard calls far more aptly than I "platform privilege".
♥ 1
Several other interactions tell me that even 100% well-meaning and smart googlers don't notice it. I think it is worth calling out.
My question is whether having to use your identity to turn on such a feature isn't a problem precisely because of the type of threat it deals with.
↺ 1
Lol, not quite, I would say. That is a pure Search decision in the same way that putting this irresponsible idea next to very good stuff is a pure Opinion decision.
What the wall prevents is that I can't go to Opinion and say "don't criticise Google, they're a big advertising client" or "don't run inane pro-nuke positions, it drives subscribers away". Basically we don't cross the streams.
Pocket is decent? I mean not very organised but it does some video (mostly YT?) and you can tag.
I think it may come across as inconsistent because there are really two levels of engagement here. As I said upthread, this is a papercut. There's a wealth of nuanced discussions that we can have around the specifics and I'm thankful for the engagement.
♥ 2
But there is also the problem that this is the thousandth papercut. It's OK to fuck up. But how many times is it OK to fuck up, with the same beneficiary, before it calls for more than a cough-ahem over a cup of tea?
♥ 1
We've talked about this before, in milder tones, but where's the change?
♥ 2
Sure enough, I'm cranky. That's hardly new! But given the option I'd rather be cranky about of bunch of other stuff tbh.
If you want to also fix that incensing level too, we can talk about that too. I can be optimistic yet one more time.
♥ 1
What is your ethical process when you evaluate new features? Does it account for platform privilege? If not, might that be added?
Note that sometimes that'll still mean doing it, but at least on purpose and ideally publicly acknowledged. Just one thought!
♥ 2
What would be a better word for "smart people who continue careless, harmful behaviour despite many previous discussions"?
And I'm not skipping around your point, I'm pointing at exactly where I see the problem. My questions weren't rhetorical.
And if you're getting a sense that I'm feeling some frustration and, yes, hostility then I'm really sorry man, but it's starting to be the case.
I know that every single instance is well-meaning, but it adds up. Each decision may be fine, but governance is ethics at scale and it's different from a collection of small decisions.
Again, I'm happy to change the OP given a better description, I really am.
This was a subsidiary question and I believe it settled (also in DM): it can, and it might, and yet another feature that favours Google even if slightly was not the intention.
It's the bigger question of why we need to keep having these chats that is still open.
As a *collective* entity: yes. There appears to be a distinct lack of reform towards better governance, despite previously noted issues.
On this we disagree. Collective entities do exist and their behaviour can be readily described. I don't think everyone is fine. I think that as time passes everyone is on the hook.
If your question is whether I have room to be more disappointed, the answer is yes! There is a gradient here. I still think you care and would try to fix the issues (if you agree to them). That is one distinction between the parts and the whole.
But yes, there is a point at which I will stop seeing shamelessness as emergent and start seeing it as deliberate. I'm yelling because I would very much like that not to happen.
♥ 1
I'm about to board. If I go silent for a long while it won't be because I'm ignoring you!
I had read the climactic black dogs scene 25 years ago for a creative writing class and have often thought of those dogs. Finally getting around to the full book, it has been an interesting experience doing so with decades of foreboding reading over my shoulder.
♥ 1
Do you happen to know why searching for "news" pretty much only returns broadcasters (or maybe it's video)?
Yeah, no worries, I was just curious if you had any explanation handy. It's still quite video-heavy, the first time I noticed I thought it was pivot-to-video gone bad 😂
It's all digital hoarding! I'm not sure a tool can fix that on its own 😁
There are plenty of ways in which good people can behave poorly as a group without even involving manipulation from the top. Incidentally, this has quite a few details about that: meaningness.com/metablog/upgra….
♥ 1
The whole thread is great but this tweet... We should "comprehensively defenestrate" our theories more often. (via @temptoetiam)
Quoting a tweet by @DrSueOosthuizen ↗
♥ 6↺ 2
OH: "Antipasti, tu perds ton sang froid!"
I don't think it was ever about doing good, but (from the outside at least) there was a time when it felt that building better products for users mattered. I certainly miss the Google that built novel, user-first products.
Are there accounts of actual causation that don't end up lost in considerations of what judgements people might make for some given edge case?
Is there a paper for this?
♥ 1
Coming from another democratic tradition, it often feels like Americans can have an unhealthy fetish for a rather old and dated Constitution.
In "The Cult of the Constitution" @ma_franks makes the burning case that it's much more than just an impression.
♥ 7↺ 1
There is a dearth of research, and little conclusive. It is hard even to establish ROI at normal scales. It also hasn't been compared with serious contextual. There is much innovation to come!
♥ 4
It's good to see the Chrome team finally start down the path to catching up on privacy, but this announcement would be a lot more credible if it contained fewer dishonest statements. Is there a chance we could get a more truthful update?
blog.google/products/chrom…
♥ 17↺ 4
Specifically:
* Admitting that other browsers were onto this much sooner (not "recently"), had to face substantial hostility from the Chrome team (as well as behind-the-scenes intimidation from Google), and have produced solutions worth more than "unintended consequences".
♥ 8
* Being open about the fact that the Chrome Team actively blocked the path to standardisation for ITP, so that talking about relying on standards today is an about-face.
Browser vendors have a tradition of being open about their mistakes, let's not lose it.
♥ 2
* It has been the documented Chrome policy for years to not try to attack fingerprinting. It would feel a lot more honest to note that rather than claim Chrome is swooping in to fix someone else's unintended consequences.
♥ 4
* The paragraph about "funding for publishers falls by 52% on average" from lack of targeting is a direct lie and simply bad science. It looks at the wrong counterfactual to make a self-serving statement. Please just remove it.
♥ 9↺ 2
Don't get me wrong I am very happy that Chrome is finally coming to the table and will be looking closely at their contributions.
But a bit of humility when you change your mind and come last to the game would be welcome -- and more promising.
♥ 11↺ 1
Absolutely, as I've said many times before Chrome's track record on security is outstanding. That makes it all the more obvious that the lack of privacy is a deliberate choice.
♥ 1
It doesn't hurt to ask!
♥ 1
I've made a first pass through Chrome's "Privacy Sandbox" proposals. Unless I missed a thing it does not address the actual threat model from cookie tracking.
Alternative proposal:
1) Implement ITP/ETP like everyone else.
2) We all work together on other privacy features.
Game?
♥ 31↺ 10
Again, don't get me wrong: I'm all for exploring novel privacy solutions. But overwhelmingly the threat model is cross-site cookie tracking and we have excellent solutions deployed in the wild for that.
We need more from the Chrome team than some delaying tactics.
♥ 8↺ 3
The browser's responsibility is to be a user agent, not to run the Web as a planned economy. Privacy is a clear user concern and there are clear solutions.
If that causes monopolistic issues elsewhere that's an argument for a break-up, not for not doing it!
♥ 1
If you mean the "Privacy Model", I've already made a PR. I just removed the statement that was uncontroversially nonfactual. As for the rest of the document, it's very unclear (to me) what it's trying to achieve?
But if you're serious about writing up the threat model and will commit to a timetable for public discussion over it, then I'd be happy to help write it.
♥ 1
Put differently, that's not data. We're talking about global warming and this is an anecdote about how your uncle's cabin went through a rough winter. No offence but if we could skip wasting everyone's time on this it would be a win.
♥ 5
I have, except that's a completely random number with no relationship to the problem.
Where is cookie tracking addressed?
You mention standards, which would be great, but do you have details on the venue?
♥ 2
I have read it, there is no announcement for anything of substance related to cookies in there. What am I missing?
♥ 1
You are running an A/B test of tracking vs no tracking in a world in which 1) buyers can choose what to bid on and 2) the bidding architecture is centered on tracking. You're using that to draw inferences about a world in which tracking does not exist at all or barely.
♥ 8↺ 1
I *really* would like to have a solid conversation on this, but if you don't see the problem with this approach you're missing the basic economics of the situation which we have to deal with.
♥ 3
You can make that finding as statistically meaningful as you want it will still be completely unrelated to the statement it is brought in to support. You're measuring unemployment in Lichtenstein with the LHC.
♥ 2
That's cool! I can't make it but I could try to provide a crisper threat model. Is the intent of the "Privacy Model" doc to do that? It seems to go in several directions.
♥ 1
Would you consider WebAdv to be the expected group for much of this?
This is a longer explanation about why Chrome's "study" about the cost of supporting privacy is misleading. @justinschuh: it would be great if you would consider retracting it.
github.com/michaelkleber/…
♥ 9↺ 1
The problem with this idea is that it ignores market realities in which the publisher is effectively forced to share identities with a market-dominating 3P. That's core to the threat model.
♥ 1↺ 1
Given that it is pitched as a standards-driven approach I was hoping that this would be a fair bit more fleshed out. Usually when Chrome says this there's already an implementation and @wicg_ support. Maybe update the post to be clear you're just thinking about it?
Funny, I really don't recall that tl;dr nor do I see it in the thread. You are making assumptions that you can jump from one to the other with nothing to found the transition.
Class act calling it a rabbit hole though.
I think I've figured out why I'm having trouble parsing that document. It sort of is a threat model but it takes the attacker's viewpoint as equally valid!
♥ 2
Gotcha, thanks. I was thinking that a privacy model would be a good @w3ctag doc, is that an option?
Not to be flippant but the first tip in that doc: "Be clear about the *end-user* need, first and foremost." 😁
♥ 2
The field is in dire need of reproducibility testing. There's a lot that doesn't pass a cursory smell test.
♥ 2
And perhaps more to the point, surveillance is only one way to personalise ads.
Isn't Chrome adware?
I'm trying not to be cynical and am engaging with this on the assumption that it is provided in good faith and not just yet another way to pretend to care about users more than about Google. Granted, there is enough that's misleading in this announcement to harbour doubts...
It's easier not to assume dishonesty when people make at least a token attempt at providing reasonable arguments rather than self-serving ones.
Which is exactly why I would like to see Chrome commit to ITP/ETP (on a progressive timeline) *and* work towards alternatives. Pretending nothing else has happened and they know better for all the things is a tiresome caricature of themselves.
The problem here is that the statement of revenue loss does not apply to the counterfactual in which ITP is the dominant regime. It's hard to "yes, and" from there.
For a second there I thought Carrie was joking, but no. The IA really is lobbying in support of CDA230 with puppies.
The good news is that they must be desperate 😁
Quoting a tweet by @cagoldberglaw ↗
♥ 1
"And yet, even expecting this, I was bowled over by the scale and detail of the tracking" --@fmanjoo and friends nytimes.com/interactive/20…
♥ 8↺ 2
Yet that's what they're claiming to predict! All I'm asking is that they remove such fantasy from the threat model, it makes no sense.
I will explain this better in the GitHub PR, but right now it's beer over sunset in Brittany and browsers don't matter 😏.
♥ 3
Have you considered offering easy opt-ins instead? If not why not?
♥ 2
Publishers aren't first-tier attackers, they are forced into supporting attackers by parties that don't even feature in the Constituencies! I will make a proposal to reorganise @Log3overLog2's to align it with this, with luck it will clarify!
♥ 4
I think most of them only work in Chrome because they assume tracking.
Of course, but that's not at all what I mean. It feels like the document is taking benefits to attackers into account, as benefits. It's a bit like working on ad fraud and including the fact that there are families in Macedonia who live from this.
♥ 2
Which isn't necessarily unreasonable (even for ad fraud, it overtook journalism in industry size a few years ago and that makes it big money) but it's a different exercise from threat modelling.
In fact, it looks like you're closer to following a DPIA methodology than pure threat modelling? Is that the intent?
Agreed, it's huge technical debt. I wonder how successful we could be tying some advanced functionality to not having external scripts, as with https.
I would *very* sincerely like to figure out collaboration here but - and I mean this as a friendly opening and not a jab - you have to understand that your opening position starts from pretty far inside tracking KoolAid land.
It also brushes aside excellent work done by others in a manner that I find quite insulting to them, particularly after the Chrome team has been so hostile to their work, and in a context in which Google has aggressively prevented some from participating.
I absolutely assume neither of you were directly involved in these previous happenings, but it's easier to establish a climate conducive to collaboration by taking one's own shortcomings into account first, before dismissing others.
I agree that there very much is value in taking the use cases into account, but you are starting from assumptions that this is overall good for publishers and advertisers. The situation is a *lot* more complex and nuanced than that.
Assuming that the status quo minus privacy concerns would be good is not actually a clearly defensible position, other than for platforms.
That is what I mean by "forced". Markets have structure and they make some choices impossible or overly costly. This can force entities into short term choices that they know are long-term harmful. But you gotta live to fight another day.
♥ 3↺ 1
It's also important to keep in mind that we run businesses and the ability to keep audiences 1P rather than give them to platforms and 3P is a competitive advantage so it might not get discussed in the open. But if you ask people privately, the answer will be "yes".
♥ 3
I think this right here is core to the difference in approach. There is no point at which anyone gets to pick which businesses win or lose. We stick to the Priority of Constituencies and that's it.
The instant you move away from the Priority, you switch to a situation in which a private corporation is trying to run a public good as a planned economy. No matter where you sit on political spectra that's a pretty bad idea!
WebKit doesn't pick winners and losers, it picks users over authors/publishers over implementers. It's just doing what we've all agreed a user agent is supposed to do.
♥ 1
Your position is probably more nuanced but this sounds like Google is running 3P ads as a Good Samaritan. That's evidently not true.
If you are really willing to forgo revenue in 3P there's a lot that you could do to help publishers without even touching Chrome 😁
Agreed, but then it would be helpful if you also did not make statements about publishers' financials that lack a sound grounding in fact. Is that not equally fair?
The biggest are the ones looking at this because they're the ones that have the financial ability to experiment. That the outcome would only benefit "a few big players" is an assertion that strikes me as quite speculative.
♥ 3
Except that it's a very particular way of looking at publisher revenue. Honestly, it's not much more relevant than a guess.
♥ 1
I suggest we stop this branch of the conversation, you are describing things too far out of line with my direct experience for us to reach consensus.
This might be a more productive discussion without whataboutisms?
Unless you're telling us Google is committed to privacy on Android as well as part of your project, it does feel a bit like whataboutism.
♥ 2
I honestly don't think it is that hard, and it certainly does not involve deceiving them in any situation.
Absolutely.
♥ 1
What's more horrifying still is that they are only reporting on @fmanjoo's Web browsing, only on one device. Throwing in mobile, etc. would reveal so much more.
♥ 2↺ 1
Very familiar to me, recounted in full cringeworthy detail here: berjon.com/the-confusion/
was being precise, the bugs haven't reached up to Opinion's floor (yet) 😬
♥ 1
The same lines persist today between people who think the browser should work for the user and those who think it should maintain some view of the whole Web as a business arrangement.
♥ 1
I would definitely love to take a look; or failing that if you have a rough preorder ETA!
Bon. Maintenant que Jean-Jacques Goldman est enfin sur Spotify, quel est le prochain fol espoir qui vous anime?
♥ 4
People know, but it has remained well below critical mass. It wouldn't take long to push it into the mainstream, though.
Everything Ben said.
♥ 1
This is what happens when you run Facebook software on Google software.
Quoting a tweet by @wongmjane ↗
♥ 13↺ 11
The browser is a key part of the ad business model, it's what enables tracking. That's less obvious for iOS, hence the note.
It felt relevant with respect to your point about the browser? I'd love to hear the flaws, too.
Oh, you meant the flaws in the OP's line of reasoning, not that Chrome is meant for tracking?



