April 2021
353 tweets
You assume that they actually want this adjudicated when it might disprove a theory that their constituencies already largely believe. There might not be an upside?
Not to say it can't be done and shouldn't be tried, but I'm not sure that that's the winning argument.
♥ 1
I really hate to be the cynic but I don't think that's stopped anyone before...
I would actually flip it around: policy proposals are all over the place right now and there is significant regulatory risk to these companies that someone will get something stupid to carry the day.
So would it not be perhaps in *their* interest that, if they're going to be regulated, they might as well have it be science-based. It could also use Facebook’s "please regulate us" to good effect.
Sure, I mean, the nutshell version is that it is a core (I believe unspoken, but necessary) assumption of the Sandbox work that obtaining consent for tracking isn't right.
♥ 1
If it were right, then you could just move consent to the browser in a nice little doorhanger prompt, make it a worldwide requirement to get 3P cookies — done! None of that complicated stuff is needed, you can get a junior engineer to solve it inside of a release cycle.
♥ 1
The most worrying thing from the "Justin Thread" that @kyotonio mentions is that it seems like the Chrome people are completely blind to this. It simply doesn't cross their mind that anything they do might not be entirely ethical and above-board.
♥ 2
I think my mistake in that was to try to get to agreement or agree-to-disagree in increments, but that just drove him to more anger and denial, and he felt like it was a "trap" that he somehow dodged.
I mean — the facts are there.
♥ 1
Oh, I'm enthusiastic (from the sidelines) too — I'm only chipping in out of concern this could trip up from the wrong angle.
There are also growing communities around data trusts and the such that might be able to help mediate the conversation, if it's possible.
♥ 1
I'd be happy to link it, but I don't understand how twitter builds threads, I can't get a link that has it all. Here is the starting piece, but you have to jump down branches to get it all.
I'm sorry if it reads that way, it is not an attack and certainly not innuendo. Just intended as a statement of fact. Are you saying Chrome does not collect browsing history in the clear from a majority of its users?♥ 3↺ 1
I think consent is underdiscussed amongst web technologists in general. I think it would help to come to a definitive position. I have some draft ideas, but it'll take time and energy.
♥ 3↺ 1
Re the Sandbox, six months ago I would have said that it would be best to solve without regulatory intervention, but that was under the assumption that Google was going to have to improve its own practices if they wanted any credibility in antitrust and standards.
But instead it looks like they don't even understand just how much they're part of the problem. So yeah, this is going to require intervention. Which is the point at which the MOW folks make things complicated and might actually cause enough distraction for Google to get away.
♥ 1
I agree it's the only way forward worth wanting — unfortunately I don't think it's the only way forward that might happen!
"Three futures: Exploring the future of web monetization", by @stephanierieger — yiibu.github.io/web-monetizati….
If you wonder what places the Web good go that are different from what we have in interesting (though not always necessarily good) ways, read this.
A few notes: 🧵
♥ 10↺ 1
The risks of bundled offers are very real and may happen sooner.
Constant decrease in ad revenue from a dysfunctional market joined with aggregation platforms that force participation through dominance (AMP, Apple News, FB+Free Basics) are turning the Web into cable TV.
There is a growing attitude from publishers that the years of independence on the Web were just a blip and now we have to (as they put it) "know your masters."
In this view, Google is just the latest Comcast and the way out is to license content through eg. Showcase and co.
Congratulations! We were just talking about the work you did here yesterday. I hope you'll come see us and say hi one of these days!
♥ 2
Oh god that's a depressing thought.
♥ 1
Exactly! It looks like "tolmun" isn't used much outside model UN events and Estonian. Not bad!
♥ 1
I recall the same, though I can't seem to track it down. There are also some sites where it's the only option that will work.
♥ 2
Oh this is going to be fun 🍿
♥ 4
The national security angle is interesting, frankly I'm surprised no one has looked more closely at the industrial espionage & security angle. Do you know how much can be inferred from your business activity through programmatic? How much malware your employees are exposed to?
Quoting a tweet by @WolfieChristl ↗
♥ 13↺ 3
Haha, yeah, I'm not even sure it's meant as a threat, but as they prepare privacy leg, a lot of smart staffers are bound to be understanding how this works, and if you're paying attention, the ADINT possibilities are quite... interesting.
♥ 2
Solid research piece on using programmatic to deliver malicious payloads to national security targets.
Homing in on specific targets whose email address you have is also a fun and cheap option in a world of hashed email targeting!
Quoting a tweet by @kfranasz ↗
♥ 11↺ 2
Security decisions like SafeFrame shouldn't be publisher decisions, because publishers can be pressured away from them if they need the money.
We should have an <ad> element with strict security and get rid of iframes and code injection.
♥ 9
OMG, why France???
♥ 3
Exactly, I've been assuming that these exist. I've wanted to study this for a long time but it's intense work for which I don't have the bandwidth (or budget). I'd also love to see work on RTB as delivery mechanism for browser or SDK 0days.
♥ 1
Yes, or when they meet. Or what analysts are reading. Or even just traffic volumes.
The book is great!
"Cybernetic Revolutionaries: Technology and Politics in Allende's Chile", by @edenmedina. There is much to love in this book. A fast-paced rendition of Allende's short time in power centring on Cybersyn, a project that blended cybernetics and socialism.♥ 9↺ 1
♥ 2↺ 1
Yup! If it's the only way it works. For instance, with a PARAKEET-style approach with defined trustworthy server, it could be the only way to access ads.
♥ 2
I don't have a problem with the AMP format, I even have someone on my team working with the AMP AC to try to fix it. The problem is the forced caching. Sunset the cache and we end up with an interesting alternative to React, which we need!
♥ 1
My thinking is to use bundles for this, and start with some strict limitations, stricter than AMP, then build up. I think @alextcone wanted just the pieces, no script, to make it work for native just as easily.
♥ 3
That's exactly the kind of thing I would imagine being offloaded to the trusted server in a trusted server architecture.
♥ 1
It's not naive! We need to revisit pretty much everything...
Some of the scripts actually have legitimate purposes, so those need to be pushed into the browser or declarative options.
Then, what you describe is pretty close to what Alex had in mind I think.
♥ 1
Yes, I think there's a point of sufficient ad safety at which we can start having good conversations about ad blocking.
The distinction feels artificial, what counts as complex varies a lot. I think it would be better to distinguish between "data inferred just from what is known of the subject" vs "data inferred from joint knowledge of the subject and many others".
♥ 7
This captures a strong difference, which is that the privacy of others affects your own.
♥ 5
Sure, I get the background and you make very good points. Where I'm coming from is sort of "implied transparency" (guessability?) by the data subject. If I tell you I was born in 1788 and you infer I'm dead (or undead) that's not surprising.
♥ 1
If I tell you I'm born in 1988 and you infer all sorts of things about my tastes and what I'm susceptible too because you have extensive data on subjects from the same year, that's a wholly different thing.
♥ 1↺ 1
I think that's it yes!
♥ 1
Right, I'm looking at standardising this kind of this. Hoping to be able to share a document soon!
♥ 2
Wouldn't common knowledge roughly map to things you can figure out without having data about others? I understand that philosophically you do, but you didn't collect it.
♥ 2
I think the possibility that the data subject would know (and therefore have been able to switch browsers for the application) is the important bit for autonomy. It's like if I tell you smoking you can infer cancer odds, vs other more obscure predictors.
♥ 3
It turns out that New Jersey is actually cool 😎
♥ 5
You too 🤗 Hopefully, soon...
♥ 1
Cat, book, backyard, mom jeans?
♥ 1
Those logs are from the tree that fell and bumped the house last winter. We turned some of it into seats.
♥ 1
Is it possible that that's a conjunction of Twitter's contenteditable implementation and your browser/os keyboard autocompletion? Like, it's buffered but not committed? Maybe get into the habit of ending with punctuation?
♥ 1
Aren't you in, like... Connecticut?
Meteorologically, I can't dispute that.
If you think scientists don't know what the fuck they're doing, try technologists 😁
♥ 1
That's actually a real theory, the "riding the juggernaut" thing!
♥ 2
Watercoolers?
I spent decades resisting. It's... actually nice here?
Yes! They can never understand doors, for instance.
Frankly, what with all that we've been doing, it's about time the Ents came for us.
♥ 1
And can @DPCIreland sleep through this one?
♥ 3↺ 1
Dans la même veine: un ami a eu Marseille pour première affectation comme prof de philo.
Il fait son tout premier cours sur la différence entre le philosophe et le savant.
Une semaine plus tard il se rend compte que les gamins ont tous compris "le philosophe et le savon". 🧼
Quoting a tweet by @pmgentry ↗
♥ 3
People... do that?
♥ 1
I admire how restrained you are in posting about it.
♥ 1
CITP is amazing — if this is your kind of position, it's a wonderful place so check it out!
Quoting a tweet by @PrincetonCITP ↗
♥ 3↺ 1
Battery draining while charging isn't all that unusual, depending on the device it can happen relatively easily. Some phones have that problem regularly, notably with crap chargers.
The pain of being on a committee designing a battery status API, it teaches you things.
It's heartening to see publishers stepping up on some core issues for the future of advertising, and get into the hard details. github.com/WICG/conversio…
♥ 16↺ 5
I'm at the "so, it looks like the problem with the Web is modernity itself" stage of that specific rabbit cave network.
♥ 3
I may have hit bedrock — but then again maybe not.
♥ 2
Yeah, but that one lacks good solutions.
♥ 2
Also, why are they called "duplicate"? The buy and the sell side get reports, that seems like a primary thing?
♥ 2
A Google proposal in which only Google gets data? How is that possible?
♥ 1
First shot! 💉
♥ 12
Moderna here at the Trenton megasite. Congrats!
♥ 1
Considering how anything remotely tied to healthcare in the US is a flaming train wreck of red tape and maddening nonsense, I feared the worst for the vaccine rollout.
I have to say that, at least in NJ, the experience was straightforward and very well organised. Thanks @NJGov!
♥ 3↺ 1
I can feel the antibodies partying already.
♥ 1
Merci 😁!
Hahaha 😂 Non, j'avoue qu'un des avantages de ne pas habiter en France est que je ne me sens pas obligé de regarder Castex en replay!
I absolutely think that's a factor. Also, while the federal government and many states have been systematically stripped of institutional capacity for ideological reasons, a number of them have kept it up (at least to some degree) and so can still come through.
♥ 1
With this picture, I'm sort of disappointed that you can't embed sound in twitter cards. Like, say, distant maniacal evil laughter.
Quoting a tweet by @nytimes ↗
♥ 5↺ 2
Indeed, especially in a state with massive pharmaceutical industry presence
It loses its edge without autoplay, though.
Fingers crossed you'll get it soon!
♥ 1
"We weren't hacked, we just negligently put the data on public pages" is a whole new level of Facebook apology that, I feel, borders on the art form.
Quoting a tweet by @AuraSalla ↗
♥ 52↺ 11
It's a continuous stream of gifts.
♥ 1
There's an interesting dynamic in Core Web Vitals that I haven't seen anyone comment on yet: if I understand it right, it incentivises having your content distributed through Google's properties instead of through direct relationship with your readers. 🧵
♥ 20↺ 4
A page's performance is measured by looking at its CWV scoring across all its alternate representations (Web and AMP). A site's perf (which is used for pages that don't have enough data) in turn depends on page perf.
So you get a boost the more of your pages load fast.
♥ 1
Important detail: (cached) AMP always wins because it gets its own cheat-boost in that its performance is measured preloaded/prerendered. Unless you can magically teleport your pages into the browser, they'll always be slower than cached AMP.
♥ 7
So the more you find ways to get your content read on Google's various properties that use AMP instead of on your own, the higher it'll rank. Or did I miss something?
Funny how that works out.
♥ 5
Thank you!
♥ 1
Yes — the way they approach Chrome is much more as the in-app browser of the Google universe than as a browser. It's a data capture race to the bottom against Android.
♥ 1
Things that cross-leverage Chrome with other parts of that world are always worrying (SXG, CWV, SSO, Sync). They're slowly eroding the notion of user agent and no one is pushing back because policymakers don't understand how infrastructural that is.
♥ 1
Maybe a little bit longer indeed!
♥ 2
It was a huge red flag for a lot of people; I'm not sure what competition authorities were doing at the time to be honest...
♥ 1
Facebook: Hold my 🍺.
I warmly recommend paying some attention to @LMSacasas's "Your Attention Is Not a Resource": theconvivialsociety.substack.com/p/your-attenti…
I *think* (but need mulling over) that I disagree: attention is a resource, the error in framing is to think it's an individualistic resource.
♥ 8↺ 2
AMP rendered elsewhere won't get you the caching cheat-boost for CWV. I see no problem with people using AMP as a JS lib, that's how it should be.
AMP lib is fine, AMP caching means Google owns the media. That's a very shitty outcome if you want a democracy.
♥ 1
In fairness, I think it is most destructive to news and it's one of the primary reasons that in news we all have Google listed as a direct existential threat in the 5-10yr time frame.
But yes indeed, they're doing the same to others, for instance e-commerce!
♥ 1
You mean turn your pages into bitmaps and blit them over?
It's not about that rendering (otherwise it would be easy to match) but actually loading the content and rendering it so it has zero latency when you click the link.
I'm glad you find the destruction of independent media amusing, at the current pace you're going to have a lot to laugh about over the coming years.
It's one of the things I like about your writing: even if I disagree with something I still feel it was good to read.
Towards the end of your piece, I thought you were heading to the collective aspects of attention. Between Cayley and Illich, "it's there."
♥ 1
There is something about how we pay attention that I feel is always directed at others. We have conversations with books. We engage with ideas. When we are alone and just receiving a stream or feed, it feels more like nihilism than attention.
♥ 1
Maybe attention isn't so much scarce as it is attenuable and damageable, like togetherness. It's not that we deplete it, but we can organise in such a way that we have less of it, and its "supply" is threatened. We could have more than enough, unless we break the source.
♥ 1
In that sense, it would still be a form of commons.
♥ 1
Yes, and I was in a research group yesterday where people reached the same conclusion: Chrome sees itself as a first party, not a browser. See also this note:
Quoting a tweet by @justinschuh ↗
♥ 2
Indeed!
Some might even say: there's a nap for that.
♥ 2
Sorry, I didn't mean to drag you into anything, I do read that as stating there's such a thing as browser as 1P.
Then again, last we spoke you expressed pride at putting an adtech dialog in a browser which still baffles me so clearly I don't get you well.
Sure, I mean, the nutshell version is that it is a core (I believe unspoken, but necessary) assumption of the Sandbox work that obtaining consent for tracking isn't right.♥ 1
Happy to, as always, but... that wasn't an ad hominem! I'll laugh at many things, but this I feel is too serious in its consequences. Sorry if we don't see eye to eye on this. I just think that we're together against problems too big to have society undermined at the same time.
You seem to like AMP and that's cool. As I've said plenty of times, I do too (I even contributed a small bit). I think it bento has properties that are much better than many JS frameworks. But the dynamics of power around caching are a serious threat.
OK, hey, I'm not rabidly anti-Google, I've worked on Google's dime and still have friends there. I just have problems to solve that happen to be Google-caused.
I discuss them with people here who share that interest. I was citing your tweet, not intending to involve you.
♥ 1
So please ignore this, I'm just giving context in a chat with others. If you ever get a sense that I'm earnestly trying to solve a real set of problems & that criticism isn't hating, I'm here. If not, let's just ignore each other cordially? Either way, I wish you a good night.
♥ 1
You're right Justin. Every time I disagree with you it's either bias, a trap, or gaslighting. The whole "caring about the web and news" thing is a front.
Since we finally agree on something, I reckon I'll just stop here.
But that's precisely the problem I see: there's a whole class of things that I think a browser, as an app, shouldn't do. That's why I'm actually angry (instead of just unhappy) with the Chrome folks. I thought that as browser people, they wouldn't cross this line 😕
♥ 1
The whole point of issuing requirements (nytimes.github.io/std-cat/) was to open a channel and try to make it clear that we see a path forward.
Previous proposals like SXG weren't great, but the hope remains that with the right discussions it can be figured out.
♥ 1
I don't have the resources to evaluate (or even notice) everything that Google sends to the W3C. But if you think there's something promising, I'm more than happy to loop in the right people on our end and see if it's workable!
♥ 1
I think that can be mitigated, but it requires (re)building trust. I'll be the first to admit: when I hear "new thing from Google" my mind jumps straight to "oh no what is it this time." That's not a great starting place. (I'm not saying that reflex is necessarily all G's fault.)
♥ 1
I've been toying with some ideas to fix that. They're not ready for prime time yet and they're not entirely conventional — but I think there are unexplored options that it's worth thinking about instead of returning to the same issues over and over again.
♥ 2
I really like how you tied attention and tools in there. That's something I've been looking for. More mulling! Thanks :)
♥ 1
"🌟 🌟 🌟 🌟 🌟 I liked it very mulch"?
♥ 3
Do you know if that's a specific race? I want one!
Thank you! Not at all, one should always have a besserwisser around, I would say doubly so around cats.
♥ 1
I can't seem to track it down now, but I remember reading about the cases curve by age in Israel. They vaccinated more or less from oldest down, and you could see the age of new cases dropping as soon as the first shot, which is super encouraging.
HOWEVER, having an effect...
...and being "safe" are two different things. I think that so long as there isn't significant immunity in others, we can't claim "normal" levels of safe. But it seems it's definitely safer from the first shot!
So... "This would only be possible if the people converting are signed into their browser across their devices." They're basically using the Sandbox to be the only cross-device graph in town. I keep being surprised at how shameless this is.
♥ 1
I just... don't understand the strategy. It only makes sense if they are reasonably sure that antitrust authorities are entirety asleep. It just seems needlessly high risk and brazen?
♥ 1
It's a rational hazard.
I was thinking "wow, this woman has the coolest hobby."
♥ 10
Exciting! It's great to see this moving.
♥ 1
It's not clear to me that the other browsers keep enough information about their users' behaviour to make this work, but I hope you're right. I guess it can work E2E?
Right, I wasn't initially thinking in that frame, that's promising!
♥ 1
I mean, there's a reason this is a classic. xkcd.com/2347/
♥ 2
I mean, it's a nice word 😁 I have to say that I would have liked to spend more time on performative ontologies and a little less on the characters k even though they're cool). But I may have weird interests.
♥ 1
That really riled me no end. Who does that?
♥ 1
Or that!
Right, there's a difference between Apple News where it's clear that you're reading from Apple and AMP where you're being tracked by Google but it's trying to fake you being on the content site, even including a fake URL bar. I agree that AMP is disingenuous for sure 😁
♥ 1
Yeah, it's one of the problems with disappearance of 3P cookies that no one has noticed yet. Publishers can't use their shiny new 1P capabilities there unless they plug into AMP's ID thing to map to their own users, and that's very hit and miss.
♥ 1
Thanks for writing it :)
♥ 1
I do 😁 I often wish for nerdier fiction (that doesn't have to be sci-fi), though, so this was right up my alley.
♥ 2
Don't miss this event in which two amazing colleagues explain how they built the system that NYT uses across products to support privacy business rules!
Quoting a tweet by @transcend_io ↗
♥ 13↺ 1
I wonder if what happened to time is related to what's happening to data. At the very least, the notes at the end should serve as a warning against propertarian approaches to privacy.
Quoting a tweet by @SenorTren ↗
♥ 7
Thanks Amy! Checking it out.
"@kathyvsinternet, a senior analytics manager and a member of the organizing committee, said in an interview that The Times felt like “an emerging company” in some ways, although it is a 170-year-old institution."
nytimes.com/2021/04/13/bus…
♥ 6↺ 2
It wasn't a full Jedi mind trick for me, but it definitely helped. The ideas in there stuck, and eventually worked.
Hang in there Brian, it can be done!
♥ 2
I know someone who did and it worked for him.
♥ 2
That's not the goal 😁
♥ 1
No dataification without representation.
Data is collected - and meaningful - because it is about a population as much as about a person. Why would users only have individual rights and not have collective representation through a form of union, for each collector large enough?
♥ 24↺ 4
Just stumbled upon this (not read yet): foundation.mozilla.org/en/blog/when-o…
♥ 5↺ 1
I don't know yet, but the first step is to think it's an option. There's some very good background thinking in papers.ssrn.com/sol3/papers.cf…. And there are good parts in foundation.mozilla.org/en/data-future… (I haven't read all of it yet).
♥ 1
I also have a separate project in which I'm thinking about a subset of those problems, where governance is intermediated through private actors. Not wonderful, but it might be a start. It's not ready for prime time but happy to chat offline if you want!
♥ 1
You know, I'm glad those people don't work here.
♥ 2
I usually manage a couple of hours a day (in the evenings) but that's nowhere near enough and the pile just keeps on growing...
♥ 1
Man — I'm not sure even Brexiteers deserve this.
♥ 2
Aram is just jealous because his bounded rationality keeps him from understanding the disciplines of engineering, lawyering, and economicsing. 😂
♥ 5
Is this the network interaction diagram for the Sequence of WTFs Advertising Nonsense?
♥ 4
It's edgier, Mar. Your phone sees an edgier bunny.
♥ 3↺ 1
There is a broader aspect to the excellent point that @johnwilander makes about FLoC: the broad diffusion & collection of personal data is more valuable the bigger you are and encourages concentration. It should be banned on competition grounds alone.
Quoting a tweet by @kyotonio ↗
♥ 10↺ 4
There's a lot less risk in having my data split between dozens of small companies with only partial views than the totality of it with a single entity. It's not even about malicious actors, it's how good you need to be at governance for it not to have nasty side effects.
Right, I'm curious about what kind of scale you need to break cohort privacy, especially if you have content that overindexes strongly on some demographics.
♥ 1
I know, but it's still small compared to the big ones
Well, that's a user agent right there! So convenient.
♥ 2
I've been wondering about those same lines. If you're legible, you're controllable. Presumably, whatever was too legible either died, lost its individuality and was subsumed, or is being farmed.
There are papers on how organisms need to process their environment’s information efficiently in order to predict it and survive, but is there anything good on how they must also be illegible/unpredictable (protect information about themselves) to predators too?♥ 5
♥ 10
The current Internet economy provides a great real time example of how that works. I'm curious to hear if you dig up anything beyond Krakauer's paper (that seems quite interesting, I hadn't found it).
♥ 2
That's my concern as well. Are we illegible enough for an adversary that has millions of data points about billions of us? What happens to societal complexity when the editorial infrastructure that shapes our access to information comes from 2-3 relatively simple algorithms?
♥ 2↺ 1
I wish I could work on this full time. I know there's some literature on this (I have the cognitive democracy stuff from @henryfarrell with Cosma Shalizi or Bruce Schneier lined up) but there's a lot we need to know, ideally rather quickly.
♥ 2
I wish Google stopped talking about the "Privacy Sandbox". It's not a coherent idea, just stuff thrown together. It sits weirdly with the standards process (are proposals from others in it?). People think it's a product or an architecture, confuse parts for the whole, etc.
Quoting a tweet by @garjoh_canuck ↗
♥ 15↺ 4
There's good and bad in that grab-bag, and same outside of it (though I'm not sure what the boundary is intended to be). But naming it that way makes it look like there's an overall plan. That's turning out to be misleading more than anything else.
This is probably futile, but I'd like to ask: Can we stop talking about the "Privacy Sandbox"? I know Google used (uses?) the term but… I'm a Web & Privacy guy through & through and I have no clue what that name is supposed to mean. "Vague grab bag of specs that may help"? 🧵♥ 28↺ 2
♥ 2↺ 2
Franchement, il n'y a pas grand chose à faire autre que de faire bouger la loi. Ne pas utiliser Chrome ni généralement aucun produit Google ou Facebook, pas d'assistant vocal. Au-delà de ça c'est un peu écoper le Titanic. Tu as un contexte spécifique?
♥ 1
"If the Times workers are successful in their union bid, it will become the largest of any contemporary white collar tech worker organizing effort to be recognized by the National Labor Relations Board." — @SamWHarnett
kqed.org/news/11869185/…
♥ 14↺ 5
I thought that article also offered an interesting insight into the work culture at The Times (at least on the tech & data side) and what motivates people to work here.
♥ 2
What is a good dataset to look at to get which third-party scripts are loaded most? Browsers are still being very timid on privacy, a plan to eliminate third-party script loading would take us further.
It's ridiculously ambitious — but not more so than what we've done before.
♥ 15↺ 1
Well, I'm trying to think about how to slice this into stages that could be shared and agreed-upon as standard. Remove cookies, proxy requests, fence all the 3P frames, then start blocking but with an allowlist. Then chip away from the allowlist (eg. SSO), etc.
♥ 1
I'm interested in answering questions like "what would break that we actually need to fix" and which of these are above the threshold at which we care about breakage (eg. present on 0.5% of loads).
♥ 1
Tag managers are an interesting issue. They can be used for good or for bad!
♥ 1
Thanks — I'm mostly noodling this over in terms of how we could approach it so I reckon I have enough to chew on with what people have shared already!
Good questions, and I don't have a good answer! I would be tempted to keep it simple from the browser's PoV at least at first, so it's either same origin or it's not.
♥ 1
Loading code shares data.
Right — but they can be shaven away with browser improvements. SSO should really be a browser concern (which should allow you to pick identity providers not listed by the site, and the spec could require a choice screen + no email sharing). Bot detection: 1P?
♥ 1
I've been waiting to see this happen. Are the same discussions happening with respect to the nginx and Apache default configurations? make.wordpress.org/core/2021/04/1…
♥ 12↺ 3
There's some kind of trends there, can't quite put my finger on it...
♥ 1
I don't know about backfiring, but failing: yes. It's at the same time a privacy problem and an infringement of publisher sovereignty, so there's a lot of discontent. And server-side system have a say in this default.
♥ 1
I think erroring is probably too hardcore to be palatable to anyone maintaining a server, but I sure love @RichFelker's vibe there :-D
♥ 1
Well, FLoC isn't the only proposal they have. But yeah, if that's gone there's nothing in that niche. I think we *could* build alternatives that did some useful work, but we'd have to exit the "tech titans know better and build for everyone" approach.
♥ 1
That's totally why I RTed it :-D
♥ 1
My preference is actually for avoiding consent as much as possible (in matters of data), I want it rare, slow, difficult, fricative, and temporary. I think there are better ways of governing personal data but of course always happy to discuss!
♥ 6
and @coolharsh55 might have what you're looking for!
♥ 2
"Don't exaggerate what your algorithm can do" pretty much wipes out most of the industry 😂
♥ 18
I've seen the two together a lot, but I'm unclear on how they articulate conceptually. Curious to hear more!
♥ 2
Right, in cases in which consent is needed then making sure people really are informed is key. I love the concept of proof of understanding, thanks! Imagine doing that on every GDPR consent banner... 🎉
♥ 5
The broader context is that I'm trying to picture what a principled project to make privacy work on the web would look like.
One aspect is that you might need controls over what leaves the origin (maybe like CORS for data), to gain commitment to some rules.
But that will lead to resources being blocked, which leads to "OK, so what most breaks?"
If people are encouraged to move scripts to 1P that's already a win just for the injection improvement. But are there things that such an approach wouldn't fix? Totally.
But listing them once the parts that can be handled are done makes for a great bridge to policy.
♥ 1
Do you want to help build a future for the Web? This is a great place to start.
Quoting a tweet by @cyberdees ↗
♥ 5↺ 3
I know, but conversely 3P loading means the 1P, where the trust sits, can't audit anything. It breaks both ways.
♥ 1
That's not a decision that has been made yet, but the principle of FLoC is hostile to publishers since it cuts them out of the loop entirely, so it's certainly a possibility.
One of the painful things if you stay in standards long enough is that history does in fact repeat itself — but just because you saw it unfold before doesn't mean you can prevent people from reinventing the same mistakes.
If you miss MPEG LASeR vs SVG, come to WebAdv for SWAN.
♥ 8↺ 1
"Yes, we built this to be inspired by GPC, we just made a few small changes: it's not Global, works against Privacy, & affords no meaningful Control at all. But it's totally inspired by it!"
If you do standards, remember to also talk to good faith folks, for your mental health.
♥ 10↺ 2
How did you guess?
No, it's not.
Judging by the mess we're in, it's about time us sexy murder bureaucrats stepped up.
Quoting a tweet by @lastpositivist ↗
♥ 6↺ 2
That's already the case! It looks uniform because it's never going to tell you that it's not, but most digital actors will target calls to action based on personalised predictions about how they'll perform.
♥ 1
Sometimes it's even done badly — that's when you notice most. For instance, I'm in a Twitter test in which the follow/following button looks alternatively hollow or blue but they've made it different on different devices and it's breaking my brain.
♥ 1
I meant *actually* sexy murder :)
♥ 1
I think "sexy murder bureaucrat" captures the whole W3C vibe pretty well :-D
♥ 1
Maybe a 🍾🥂 kind of hearing!
I hope there are some for alumns!
♥ 1
Are you ready for some internet governance? "Of course we're ready," I hear you say. "We thought you'd never get to it!"
This thread includes: a W3C group you didn't know exists, the future of the Web, the business model of news, and a bit about the platforms. All at once!🧵
♥ 26↺ 11
The @w3c is reinventing itself:
• changing its underlying legal entity,
• preparing for existence after inventor-founder-director @timberners_lee steps down, and
• figuring out what it means to shepherd the Web when technology isn't neutral and things aren't going so great.
♥ 4↺ 1
The group driving this work is a great bunch of folks known as the "W3C Advisory Board" (@W3CAB), many of whom have been trying to make things less bad for years.
They've started putting together some "vision" ideas over at github.com/WebStandardsFu…. They want help and input!
♥ 5↺ 1
Yes — that's why I frame it as knowledge of audience rather than data. There are ways you can know your audience without or with minimum personal data, and there are ways to learn more about people in a relationship (same as would happen eg. in a bookshop).
♥ 1
I would say: start by looking at what the AB have in their repo (it's relatively short) and about what issues you think the Web has that could be helped if we had a principled stance about them. Then file issues, proposals, etc.
♥ 2
If you're not very familiar with W3C, the best is often to start by outlining case studies, requirements, issues, rather than offering solutions as it's hard to know what's a good fit without experience (it's a different workd).
It actually is, at least in some demographics: "We examine the proposal that children interpret the birthday party as playing a causal role in the aging process." journals.sagepub.com/doi/abs/10.117…
♥ 1
So, trying to parse that: a page with ad-like things will cause the domain to contribute to a cohort definition, but not every page of that domain to contribute. Correct?
♥ 2
OK, now I'm confused because what I understand you to be saying is what I understand Zach to be saying!
♥ 2
I get that, but I read Zach's point as stating that it was easy to get a domain into FLoC (based on those rules) for a given browser.
Making a thread of @transcend_io's live notes on this talk about how the NYT built a privacy rules engine to have consistent implementation across products.
(Yeah, they still let me pick acronyms at The Times, I don't know why.)
Quoting a tweet by @transcend_io ↗
♥ 5↺ 2
You can't prevent anyone from matching cohorts to whatever they want to. Art 15 shouldn't be hard, Art 9 (and a few others) strike me as more difficult - but that's for the lawyers.
No, the fact that it maps to a group doesn't change its personal data nature. To say that I have property "sexy" or that I'm a member in the set of sexy people says the same thing (in this ontology).
But there are fun GDPR questions in there, and I guess it's Friday so... 😀
One is that it doesn't say "sexy" but rather 17. Is that meaningful? Well, you can act on it, so yes: it passes the performative test. Is it anonymised? Well, can someone reasonably break the indirection? Someone can, so it isn't.
You say it's not consented, but in Google's current implementation it relies on consented processing to protect special categories from being identified. Is that consent reasonably informed commensurate with the extent of the processing, its risk, and Art 9 aspects?
I would say that's at least a risk position, especially since Google has indicated that they don't believe similar consent to be sufficient for milder processing. The expectation might be that the DPC won't do anything, which is probably a smart bet.
One extra fun difficulty: with the special categories part of FLoC, Google have more or less made a public DPIA. This means other implementers can't ignore those risks, but they don't have the data to implement similar protections... This severely reduces the odds of a standard.
Anyway, interesting times and all that 😂
♥ 2
I think we should be careful not to describe this as "hyper-hygiene". Hygiene is the set of practices that lead to good health. Applying antibacterials everywhere is definitely unhygienic.
nytimes.com/2021/04/23/opi…
♥ 3↺ 3
I'm quite enjoying the triggering :)
♥ 1
It's a trend, too :-D
The Times is really pushing the envelope on graphics. nytimes.com/2021/01/29/tec…♥ 45↺ 4
♥ 1
You do make a good point, I guess it is a campaign theme then!
♥ 1
With the cookiepocalypse coming, I wonder how much of this kind of last minute pump-and-dump we're going to see.
♥ 5
That matches what I've heard (which may also be outdated). I would be surprised if they were completely contextual and didn't take at least something of a hit.
♥ 3
OB UUID!!! Is about the sound I make when I wake up from a nap I hadn't intended.
♥ 3
You don't think there'll be UID2 IVT? 😉
♥ 3
Are there good resources about what goes into writing a constitution?
♥ 8↺ 2
Classic :)
♥ 1
Thank you! The historical angle is of particular interest to me, so this is great.
Thanks — this looks like a treasure trove, I'll definitely dig into it.
♥ 1
Thanks — I think I get the overall idea, and it's interesting, but it's likely that the translation is losing some subtleties :)
An intellectual toolbox!
♥ 3
Not so much planning as thinking. I've been thinking about how to make good principles for the Web Vision thing, and it's hard. I want to look at how others have established legitimacy not necessarily to copy the approach but at least to understand the mechanisms.
♥ 3
We need something that is legitimate both externally and for those of us who've been around forever. I've met with issues on both of these for things that seemed to me to be "self-evident", and so the question is "how do we make this work?"
♥ 4
Externally, the idea that browsers are the user's agent surprises people (good faith people; not just MOW). RFC 8890 helps, and the need to balance automation asymmetry could be a principle — but is that enough?
♥ 4
I'm noticing the same: an increase in interest, but mostly from people who confuse privacy with either security or compliance. I guess this part of a field's maturing?
I wonder how long it'll be before data governance reaches that stage, too!
Quoting a tweet by @johnwilander ↗
♥ 11↺ 3
That I read when it came out! It's great, I recommend pretty much anything that @ma_franks writes. But it doesn't help with my current issue.
I'm looking at this: bookshop.org/books/the-gun-…
♥ 3
Thanks, this one might be the right idea indeed!
It's okay Chris, we're amongst old farts here ;-) (Well, not Tzviya of course.)
♥ 1
I didn't mean to imply you had said it shouldn't be taken, but indeed you did see it as more aspirational than established. On my end, I thought I was starting with an easy one 😂 I think it's that kind of distance I want to make sure we are equipped to handle.
♥ 1
Oh, now I see what you mean. I don't actually see it as related to those legal concerns. Or, rather, those legal concerns probably played a part in creating the current situation but solving them might not solve this. There's a difference.
♥ 1
Here's the background I'm working from: it was a "self-evident" expectations when people started relying on 3P infrastructure that they would retain exclusive control over audience data. Otherwise, they never would've used it — it's just a net loss. But that expectation broke.
♥ 2↺ 1
The reason I don't see it as distinctively a problem of monopoly power is because it's also what TDD et al are working towards with UID2 — which is just as problematic.
♥ 2
Put differently, it would be just as objectionable if the DDG browser took our audience info the way Chrome does. The impact is different because of scale, but it's inherently the same problem in that it makes investing in the Web a lot less valuable.
♥ 2
And it has a direct impact on how we should be designing standards. Forget all the other issues, it's an architectural expectation of FLoC that the effort one site puts into developing its own cohort should be used by others to monetise independently. That's a huge assumption!
♥ 2↺ 1
Thank you! I'll add that to the other piece of prior art I have from 2007, back when that was just considered self-evident by all parties.
♥ 1
Whoa, thanks. Do you just happen to have stuff I'm about to think about handy?
♥ 2
Network effects do not require the current rules, though. You can have network effects without transferring ownership. Also, when it's the browser taking your audience data, there's no way to opt out at any level of cost. It's like a spy sat.
♥ 1
I need to get me one of those.
That may have been a mistake :-D
I mostly keep you around for the searing zingers and the fuzzy hope that we'll meet again and hug soon — but the tips on constitutional process or notes on Robert Nozick are a plus!
Thanks — I'll look over there too.
♥ 3
Sure, that's a point I've made a few times: we'll need more in-depth discussions.
♥ 1
Oh that [eye roll].
♥ 2
I mean, the idea that you can even write "ad privacy" without it being funny is already a recent innovation :)
♥ 1
This is amazing work from @Aaron_Krolik and @kashhill: nytimes.com/interactive/20…. Talk about being the guinea pig you want to see in the world.
♥ 7↺ 1
I've been trying for a while now to come with a good privacy paradox paradox paradox, but so far nothing great.
♥ 3
"Elder" is just Middle Low Germanic for "old fart", so...
♥ 2
I didn't say the opposite?
If you believe that tech is apolitical, I can only recommend you read this evergreen thread about René Carmille, hacker in the Résistance.
Quoting a tweet by @WebDevLaw ↗
♥ 23↺ 18
There are very good reasons to use "selling" in many cases, but probably not in Facebook's — they're actually buying data. Part of the problem in the data economy is that we have a monopsony (or a duopsony).
♥ 3↺ 1
Just about to go on a Zeal call with @ashk4n to talk about @globalprivctrl. Watch it here! youtube.com/watch?v=wHhfhE…
♥ 2
I think they record them, I can check later — or maybe @ElectricCoinCo knows?
I'm not sure what you're getting at? I haven't seen Apple buying data all over the place the way that Facebook and Google do.
Sorry but I don't see it. That's extremely limited compared to what Google and Facebook do. Which part strikes you as similar?
♥ 2
I'm on a panel in which people who make standards at the @w3c were referred to as "Lords of the Internet".
So, you know what to call me now.
♥ 39↺ 2
In official function, I expect people to use both.
♥ 2
We're talking about buying data not being "bad". A sale takes place when you give something to someone else in exchange for something, and they can then use that as they wish. I don't see that in what you link, so I don't understand what you're getting at?
♥ 1
We prefer "Order of the Old Farts".
♥ 4
You're switching the topic from sale to 1P. Google is (rightly) getting slammed for violating contextual integrity in how they use first-party data. But it's a totally different issue.
♥ 3
Lack of choice in doing what? Google and Facebook will take data directly from publishers and there is essentially nothing we can do about it. At best it's a sale, in many cases it's plain theft. Apple, as far as I can tell, does none of that or at worst very little.
♥ 2
This isn't to say that there are no problems with Apple. I have any number of notes about how they operate their platform. But on this topic they really aren't a good whataboutism option.
♥ 2
I'm pretty sure that Apple doesn't monetise anything on my phone, but I guess that's orthogonal :)
Sure — the payment issues are real, as is the overreach in treating 1P data like tracking. But they're a different issue!
♥ 1
Wait — are you implying we're not?
I had to correct a deck where they'd used @Chronotope's face instead of mine — I guess we all look the same :)
♥ 1
This isn't consent, this is an assertion of rights. Rights that people have vary across jurisdictions. Under the CCPA to opt out of sale, under the GDPR to withdraw consent, etc.
Every intersection of protocol and law is somewhat novel, but there are others.
♥ 1
That would depend on jurisdictions. If it is clear (to users) that they are indeed expressing that intent, then you probably have a case (though get advice on this from an actual lawyer and not some dude on the Internet).
If it's implicit, it's more complicated but possible.
♥ 1
I find your lack of faith in URNs… disappointing.
♥ 2
I think that's the best allegory for CR, ever.
Make it so.
Me too :( I've been wondering if there's something we could organise, say in September, to get some of us together.
♥ 3
Ouch!
♥ 1
Always.
Maybe, but still: this is a teeny tiny fraction of what others do, it takes an awful lot of squinting to put it even in the same neighbourhood. If all our problems were on that level, we'd be in a much, much better place.
♥ 2
This piece is entirely accurate — and it doesn't even get into the monstrous river of red tape that the American healthcare system produces.
Quoting a tweet by @nytopinion ↗
♥ 13↺ 6
I'm not surprised. It also has a cost in that it allows fake costs to be drowned in the flood and keeps everyone scared because it's incomprehensible.
♥ 1
I wonder which part(s) she sees as opportunities. FLoC comes to mind, but is it just that?
Or maybe she is simply countering the narrative that they're losing tracking and that'll harm them.
♥ 5
Great. If that's the emphasis I've got the follow up for it 😁
♥ 2
One thing that's problematic with unwritten norms is also that they're subject to slipping over time. You move into some wiggle room to fix a real problem and... ten years later you're doing something you would never have condoned initially.
♥ 3
"If you have to resort to design tricks to obtain consumers consent you ought to think twice about your business model and how your design principles coordinate with honesty and fairness." — @RKSlaughterFTC, #DarkPatternsFTC
♥ 53↺ 23
I qualify this as outrageous, and yet it is *still* a tiny fraction. Google does the same through AMP with almost all news content, and far more forcefully. To give you a sense, we're not in Apple News because it's ignorable; for AMP we have a gun to our head.
♥ 2
That is the issue discussed in Origin Sovereignty: github.com/darobin/Vision….
Is this a violation of sovereignty from Apple? Yes. It's a different issue from the one at top of the thread. (And it's still a much, much smaller such violation than AMP+GAM+Chrome tracking.)
♥ 1
If your argument is that 1P/3P isn't the best implementation of privacy, then that's IMHO pretty clear. The problem is: what can be automated by the browser?
We can make a typology:
• 1P being one context, doing context inappropriate things. Bad, but browser can't tell.
♥ 1
• 1P being several contexts and sharing data across those (eg. G). Almost always bad, browser can't tell.
• 1P/1 ctx, using 3P that can reuse data independently. Bad, the browser can tell.
• 1P/1ctx using 3P only for 1P. Likely OK, but browser can't tell apart from previous.
♥ 2
• User agent collecting data as if it were 1P. Always bad, but the entity supposed to protect you isn't.
The question is: can we fix that at the tech level? Some of it but not without policy support. Distinguishing the 3P cases could be done with a header (and the 1st blocked).
♥ 1
But it's easier to fix with policy: just outlaw transferring data unless there is a consent *for that specific transmission* (and not permanently, as with the GDPR nonsense). The UA is also a relatively easy policy fix.
The 1P multicontext one is harder, I'm looking for ideas.
♥ 1
Yes, would love to chat about it! I used "bad" for contextual integrity norm violations, but that's indeed sweeping a lot under the rug… I have a draft with all the definitions we need for this (running at 16pp and growing), hopefully it gets approved and we can use that!
♥ 2
Where is the hoodie I can buy?
7yo: So, Daddy, I wanted to ask: bread is basically a giant crumb?
Mereologists, help! This is the time you have been training for!
♥ 8↺ 2
So, in your worldview, a loaf made of nothing but crust is a loaf of bread?
♥ 1
I think we're gearing up for the first debates to rival the patent policy — I'm sure there'll be some skunks!
♥ 1
My friend — that's not bread, it's biscotte!
♥ 1
We're hiring (a whole bunch): nytimes.wd5.myworkdayjobs.com/NYT
♥ 13↺ 1
Amazing cover design!
♥ 1
If you work in technology you work in politics — it's as simple as that.
If what you actually wanted was to solve harmless little made-up problems, there's plenty of options like crosswords or sudoku.
Quoting a tweet by @CaseyNewton ↗
♥ 106↺ 25
Recommended classic: Do Artifacts Have Politics? cc.gatech.edu/~beki/cs4001/W…
♥ 9
It scares me to imagine where you stood on The Sandwich Debate 🥪
♥ 1
Hahaha well played 😁
I'd love to try rusk, whether it's bread or not! (Biscotte isn't, it's biscotte!)
♥ 1
Yes, having fun with imagined problems is perfectly legitimate, and relaxing!
♥ 3








