You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[...] the idea is to consider a bounce/redirect that isn't between two domains in the same first party set as a candidate for being flagged as bounce tracking. From there, the browser can take various protective measures. One way is to count the "fan out" of redirects from that candidate and at some threshold stop the redirects and start asking the user what their preference is.
It seems like this is just one potential use, but it seems to be the main or only use case that he is considering for FPS.
Maybe I'm just not keeping with the navigational/bounce tracking work well enough to understand the pressure to use FPS. FPS is an awfully large lift, but this is a pretty marginal advantage. I'm not even sure that it provides any advantage at all.
On the surface, this seems reasonable. When you have a redirect chain, all of the sites involved can potentially pass arbitrary information to each other. Redirects allow the sites to bind that information to any browser-provided information, like cookies. Limiting the scope of that information sharing seems like a good goal.
This is all built on an assumption, however. That is, an assumption that reducing the number of intermediate redirects - or the total number of "parties" involved - contributes to limiting the spread of tracking information. It would be good to see some analysis that described how this sort of limit could be helpful, along with carefully stated preconditions.
(I've some ideas regarding how to approach the problem; I'm going to chase those, but I don't want to replicate work that has already been done or has already been planned. )
(Separately, if this issue might be filed on the navigational tracking work, I'm happy to take the discussion there.)
The text was updated successfully, but these errors were encountered:
I think the title of this issue is asking a different question from the description. The description appears to be asking the questions "Why is bounce/redirect tracking a problem we need to solve?" and "Should FPS be used to solve aforementioned problem?"
My short answer to "Can FPS help with bounce tracking?" is "yes", because using FPS to solve that tracking prevention problem would be consistent with the use of FPS as a "privacy boundary" for websites.
On #53, @johnwilander identifies one potential use for FPS:
It seems like this is just one potential use, but it seems to be the main or only use case that he is considering for FPS.
Maybe I'm just not keeping with the navigational/bounce tracking work well enough to understand the pressure to use FPS. FPS is an awfully large lift, but this is a pretty marginal advantage. I'm not even sure that it provides any advantage at all.
On the surface, this seems reasonable. When you have a redirect chain, all of the sites involved can potentially pass arbitrary information to each other. Redirects allow the sites to bind that information to any browser-provided information, like cookies. Limiting the scope of that information sharing seems like a good goal.
This is all built on an assumption, however. That is, an assumption that reducing the number of intermediate redirects - or the total number of "parties" involved - contributes to limiting the spread of tracking information. It would be good to see some analysis that described how this sort of limit could be helpful, along with carefully stated preconditions.
(I've some ideas regarding how to approach the problem; I'm going to chase those, but I don't want to replicate work that has already been done or has already been planned. )
(Separately, if this issue might be filed on the navigational tracking work, I'm happy to take the discussion there.)
The text was updated successfully, but these errors were encountered: