Chrome team's idea for a new, but still cookie-based, anti-tracking standard is technically disingenuous and aimed at protecting Google's business interests
Mayer and Narayanan's critique lands months after Google announced anti-fingerprinting technology for Chrome alongside an opt-in requirement for cross-site cookies — the first move in what became a years-long Chrome privacy campaign. Their charge is that the proposed replacement standard keeps tracking cookie-based, which conveniently preserves the asymmetry between Google's first-party data trove and everyone else.
The later coverage validates the skepticism they helped seed: Wired argued Google's plan to remove third-party cookies would leave the underlying dynamics of behavioral advertising intact, Google promised not to build alternate identifiers, and by 2024 it was only restricting third-party cookies for 1% of Chrome users — with marketers and publishers saying the market was unprepared.
First-order effects
Third-party trackers and adtech firms face a Chrome standard written around cookies — the one mechanism where Google, sitting on unmatched first-party data, loses least from tighter controls.
The critique puts immediate pressure on the Chrome team's framing: if the standard is disingenuous, every downstream claim that blocking cookies improves privacy inherits the flaw.
Second-order effects
Rival browsers and privacy advocates gain a concrete technical argument against deferring to Chrome's spec, forcing Google to defend the design on its merits rather than its market position.
Publishers and adtech companies end up dependent on whatever standard Chrome ships, so a self-interested design choice by Google propagates directly into their infrastructure — a dependency the 2024 rollout complaints made explicit.
Third-order effects
If the pattern holds, the company with the largest advertising stake becomes the de facto rule-setter for web privacy — standards shaped so that restrictions bind competitors more than the standard-setter, exactly the dynamic Wired identified when the cookie-removal plan left behavioral advertising's foundations untouched.
The trend: Browser vendors are becoming the arbiters of web tracking standards, and the conflict of interest between writing those rules and running the web's biggest ad business keeps resurfacing at each step from fingerprinting pledges to staged cookie deprecation.
Google just made a long-awaited announcement on Chrome's approach to privacy. Sadly it is full of excuses for *not* doing tracking protection, including the absurd claim that blocking cookies is bad for privacy. @jonathanmayer and I deconstruct the claims: https://freedom-to-tink…
Another example of smart people at big tech companies losing the moral and ethical forest for the trees. It's easy to get so wrapped up in the complexity of the enterprise that a small series of defensible arguments add up to an unjust result that you just can't see. https://twit…
Today's update to your privacy theory vocabulary is brought to you by @jonathanmayer & @random_walker. Privacy Gaslighting https://freedom-to-tinker.com/ ...
“If history is any indication, launching a standards process is an effective way for Google to appear to be doing something on web privacy, but without actually delivering.” A bit more in depth than my initial snark on why this is tone deaf https://twitter.com/...
It would be better for *Google* if people used Safari and Firefox instead. Using other browsers will force Chrome back towards open standards. The ad team will hate it. The engineering team will love it. https://twitter.com/...
Wow. This is an outstanding analysis of Google's misleading announcement by blog post yesterday. I'm going to stop debating press coverage that ran with it (simply because Google said it) and instead recommend they all read Arvind's post ASAP. https://twitter.com/...
While we support the Chrome team's efforts to improve people's privacy, for any of it to be effective, they really have to make privacy protection the default. https://www.cnet.com/...
It's good that Google now wants to standardise techniques for more privacy-preserving ads (even if we and others proposed many of them a decade ago http://www.deutsche-telekom- laboratories.de/... 🙄) 1/2 https://blog.chromium.org/...
ah I see google are up to their same old tricks again ‘oh no but chrome needs this data to serve relevant ads!’ chrome's malware, don't use it https://www.blog.google/...
The @googlechrome proposals include some potentially significant proposals for ways to do ad targeting, attribution, and even fraud/security w/o needing to individually track users across websites. Lets hope the engineers convince the risk-averse lawyers https://blog.chromium.org…
“Traffic for which there was no cookie present yielded an average of 52 percent less revenue for the publisher” Consistent with our analysis more than a year ago: https://rsci.app.link/... @WibsonOrg #OwnYourData https://www.blog.google/...