AI

WebKit’s new anti-tracking policy puts privacy on a par with security

Comment

Private sign affixed to gate
Image Credits: Stewart Bremner/Moment / Getty Images

WebKit, the open source engine that underpins Internet browsers including Apple’s Safari browser, has announced a new tracking prevention policy that takes the strictest line yet on the background and cross-site tracking practices and technologies which are used to creep on Internet users as they go about their business online.

Trackers are technologies that are invisible to the average web user, yet which are designed to keep tabs on where they go and what they look at online — typically for ad targeting but web user profiling can have much broader implications than just creepy ads, potentially impacting the services people can access or the prices they see, and so on. Trackers can also be a conduit for hackers to inject actual malware, not just adtech.

This translates to stuff like tracking pixels; browser and device fingerprinting; and navigational tracking to name just a few of the myriad methods that have sprouted like weeds from an unregulated digital adtech industry that’s poured vast resource into ‘innovations’ intended to strip web users of their privacy.

WebKit’s new policy is essentially saying enough: Stop the creeping.

But — and here’s the shift — it’s also saying it’s going to treat attempts to circumvent its policy as akin to malicious hack attacks to be responded to in kind; i.e. with privacy patches and fresh technical measures to prevent tracking.

“WebKit will do its best to prevent all covert tracking, and all cross-site tracking (even when it’s not covert),” the organization writes (emphasis its), adding that these goals will apply to all types of tracking listed in the policy — as well as “tracking techniques currently unknown to us”.

“If we discover additional tracking techniques, we may expand this policy to include the new techniques and we may implement technical measures to prevent those techniques,” it adds.

“We will review WebKit patches in accordance with this policy. We will review new and existing web standards in light of this policy. And we will create new web technologies to re-enable specific non-harmful practices without reintroducing tracking capabilities.”

Spelling out its approach to circumvention, it states in no uncertain terms: “We treat circumvention of shipping anti-tracking measures with the same seriousness as exploitation of security vulnerabilities,” adding: “If a party attempts to circumvent our tracking prevention methods, we may add additional restrictions without prior notice. These restrictions may apply universally; to algorithmically classified targets; or to specific parties engaging in circumvention.”

It also says that if a certain tracking technique cannot be completely prevented without causing knock-on effects with webpage functions the user does intend to interact with, it will “limit the capability” of using the technique” — giving examples such as “limiting the time window for tracking” and “reducing the available bits of entropy” (i.e. limiting how many unique data points are available to be used to identify a user or their behavior).

If even that’s not possible “without undue user harm” it says it will “ask for the user’s informed consent to potential tracking”.

“We consider certain user actions, such as logging in to multiple first party websites or apps using the same account, to be implied consent to identifying the user as having the same identity in these multiple places. However, such logins should require a user action and be noticeable by the user, not be invisible or hidden,” it further warns.

WebKit credits Mozilla’s anti-tracking policy as inspiring and underpinning its new approach.

Commenting on the new policy, Dr Lukasz Olejnik, an independent cybersecurity advisor and research associate at the Center for Technology and Global Affairs Oxford University, says it marks a milestone in the evolution of how user privacy is treated in the browser — setting it on the same footing as security.

“Treating privacy protection circumventions on par with security exploitation is a first of its kind and unprecedented move,” he tells TechCrunch. “This sends a clear warning to the potential abusers but also to the users… This is much more valuable than the still typical approach of ‘we treat the privacy of our users very seriously’ that some still think is enough when it comes to user expectation.”

Asked how he sees the policy impacting pervasive tracking, Olejnik does not predict an instant, overnight purge of unethical tracking of users of WebKit-based browsers but argues there will be less room for consent-less data-grabbers to manoeuvre.

“Some level of tracking, including with unethical technologies, will probably remain in use for the time being. But covert tracking is less and less tolerated,” he says. “It’s also interesting if any decisions will follow, such as for example the expansion of bug bounties to reported privacy vulnerabilities.”

“How this policy will be enforced in practice will be carefully observed,” he adds.

As you’d expect, he credits not just regulation but the role played by active privacy researchers in helping to draw attention and change attitudes towards privacy protection — and thus to drive change in the industry.

There’s certainly no doubt that privacy research is a vital ingredient for regulation to function in such a complex area — feeding complaints that trigger scrutiny that can in turn unlock enforcement and force a change of practice.

Although that’s also a process that takes time.

“The quality of cybersecurity and privacy technology policy, including its communication still leave much to desire, at least at most organisations. This will not change fast,” says says Olejnik. “Even if privacy is treated at the ‘C-level’, this then still tends to be about the purely risk of compliance. Fortunately, some important industry players with good understanding of both technology policy and the actual technology, even the emerging ones still under active research, treat it increasingly seriously.

“We owe it to the natural flow of the privacy research output, the talent inflows, and the slowly moving strategic shifts as well to a minor degree to the regulatory pressure and public heat. This process is naturally slow and we are far from the end.”

For its part, WebKit has been taking aim at trackers for several years now, adding features intended to reduce pervasive tracking — such as, back in 2017, Intelligent Tracking Prevention (ITP), which uses machine learning to squeeze cross-site tracking by putting more limits on cookies and other website data.

Apple immediately applied ITP to its desktop Safari browser — drawing predictable fast-fire from the Internet Advertising Bureau whose membership is comprised of every type of tracker deploying entity on the Internet.

But it’s the creepy trackers that are looking increasingly out of step with public opinion. And, indeed, with the direction of travel of the industry.

In Europe, regulation can be credited with actively steering developments too — following last year’s application of a major update to the region’s comprehensive privacy framework (which finally brought the threat of enforcement that actually bites). The General Data Protection Regulation (GDPR) has also increased transparency around security breaches and data practices. And, as always, sunlight disinfects.

Although there remains the issue of abuse of consent for EU regulators to tackle — with research suggesting many regional cookie consent pop-ups currently offer users no meaningful privacy choices despite GDPR requiring consent to be specific, informed and freely given.

It also remains to be seen how the adtech industry will respond to background tracking being squeezed at the browser level. Continued aggressive lobbying to try to water down privacy protections seems inevitable — if ultimately futile. And perhaps, in Europe in the short term, there will be attempts by the adtech industry to funnel more tracking via cookie ‘consent’ notices that nudge or force users to accept.

As the security space underlines, humans are always the weakest link. So privacy-hostile social engineering might be the easiest way for adtech interests to keep overriding user agency and grabbing their data anyway. Stopping that will likely need regulators to step in and intervene.

Another question thrown up by WebKit’s new policy is which way Chromium will jump, aka the browser engine that underpins Google’s hugely popular Chrome browser.

Of course Google is an ad giant, and parent company Alphabet still makes the vast majority of its revenue from digital advertising — so it maintains a massive interest in tracking Internet users to serve targeted ads.

Yet Chromium developers did pay early attention to the problem of unethical tracking. Here, for example, are two discussing potential future work to combat tracking techniques designed to override privacy settings in a blog post from nearly five years ago.

There have also been much more recent signs Google paying attention to Chrome users’ privacy, such as changes to how it handles cookies which it announced earlier this year.

What Chrome’s browser changes mean for your privacy and security

But with WebKit now raising the stakes — by treating privacy as seriously as security — that puts pressure on Google to respond in kind. Or risk being seen as using its grip on browser marketshare to foot-drag on baked in privacy standards, rather than proactively working to prevent Internet users from being creeped on.

More TechCrunch

ClickHouse has made a name for itself as a real-time data warehouse for large enterprises. Its customer list includes Deutsche Bank, eBay, Fastly, GitLab, HubSpot, Microsoft, ServiceNow and Spotify.

Real-time database startup ClickHouse acquires PeerDB to expand its Postgres support

The EU has kicked off a consultation on rules that will apply to providers of general purpose AI models under the bloc’s AI Act.

EU calls for help with shaping rules for general purpose AIs

Siddhi Capital’s second fund of $135 million is double the size of the venture capital firm’s first fund and will go into CPG and food tech startups.

Siddhi Capital grabs $135M for Fund II to invest in consumer packaged goods startups

Perplexity AI will soon start sharing advertising revenue with news publishers when its chatbot surfaces their content in response to a user query, a move that appears designed to assuage…

Perplexity details plan to share ad revenue with outlets cited by its AI chatbot

Femtech, or tech that leverages innovations in AI, smartphones and connected wearables to give women more insights into reproductive and menstrual health, continues to gain momentum with users, and investors…

Fertility tracking app Flo Health raises $200M at a $1B+ valuation

Meta said Monday that it is rolling out its AI studio to all creators in the U.S. to let them create personalized AI-powered chatbots. The company first announced the AI…

Meta is rolling out its AI Studio in the U.S. for creators to build AI chatbots

The startup is betting it can bring its fusion technology to market at a breakneck pace by leaning heavily on partners.

Bill Gates-backed Type One Energy lands massive seed extension to commercialize fusion power

The U.K.’s antitrust regulator has revealed an early-stage probe into Google’s ties with Anthropic, after the Alphabet subsidiary invested in its U.S. AI rival over several rounds. While it’s not…

UK antitrust body probes Google’s ties with AI rival Anthropic

We’ve been covering US-based Insurtech startup FAYE way back since 2022 with its Seed round, and the Series A round in 2023, and it seems they continue to be on…

Packing travel insurance products into an app helped FAYE to a $31M Series B

Sennder is acquiring the European ground transportation assets of logistics giant C.H. Robinson.

Sennder buys CH Robinson’s European business

When Egyptian B2B e-commerce platform Cartona last raised money in 2022, global and local investors were eager to invest in African startups solving the supply chain and operational challenges for…

Egypt’s Cartona raises $8.1M even as investors pull back from B2B e-commerce in Africa

During an emergency hearing held by the South Korean government, Young-bae Ku, Qoo10’s founder said he would secure the amount over the next 30 days.

Qoo10’s CEO pledges personal assets worth $58M to compensate Korean merchants affected by its liquidity crisis

Zoe sends customers at-home testing materials to collect blood or feces to test blood fat, blood sugar, and gut microbiome health. Following those results, the company scores every food (on…

Zoe, a microbiome-focused nutrition company, raises $15 million to expand in the U.S.

Qualcomm has launched the Snapdragon 4s Gen 2 chip to 5G smartphones in the sub-$100 price segment in India and other emerging markets.

Qualcomm’s new Snapdragon chip aims to bring 5G to sub-$100 devices

Users who have signed up for iOS 18’s developer beta can now get the first taste of Apple Intelligence as the company has released some features of its AI suite…

Apple brings Apple Intelligence with iOS 18.1 dev beta, but there are a lot of limitations

Canva has acquired Leonardo.ai, a generative AI content and research startup, as the company looks to broaden the scope of its AI tech stack. The financial terms of the deal…

Canva acquires Leonardo.ai to boost its generative AI efforts

The U.S. Commerce Department has issued a new report endorsing open models like Meta’s Llama 3.1, which it says promote competition.

New U.S. Commerce Department report endorses ‘open’ AI models

Shared micromobility giant Lime is piloting two new vehicles designed to appeal to women and older folks who might appreciate a lower step-through frame, smaller wheels and an upgrade from…

Lime is piloting two new e-bikes to attract more women and older riders 

Apple has published a technical paper detailing the models that it developed to power Apple Intelligence, the range of generative AI features headed to iOS, macOS and iPadOS over the…

Apple says it took a ‘responsible’ approach to training its Apple Intelligence models

A fireside chat on Monday between Nvidia CEO Jensen Huang and Meta CEO Mark Zuckerberg at the SIGGRAPH 2024 conference in Colorado took a few unexpected turns. It started innocently…

Huang and Zuckerberg swapped jackets at SIGGRAPH 2024 and things got weird

Meta’s machine learning model, Segment Anything, has a sequel: It now takes the model to the video domain, showing how fast the field is moving.

Zuckerberg touts Meta’s latest video vision AI with Nvidia CEO Jensen Huang

Featured Article

The fall of EV startup Fisker: A comprehensive timeline

Here is a timeline of the events that led fledgling automaker Fisker to file for bankruptcy.

The fall of EV startup Fisker: A comprehensive timeline

Hello, and welcome back to TechCrunch Space. In case you missed it, Boeing and NASA decided to keep Starliner docked to the International Space Station for the rest of the…

TechCrunch Space: Catching stars

As failed EV startup Fisker winds its way through bankruptcy, a persistent and tricky question has become a flashpoint of the proceedings: does its only secured lender, Heights Capital Management,…

The question haunting Fisker’s bankruptcy

So-called “unlearning” techniques are used to make a generative AI model forget specific and undesirable info it picked up from training data, like sensitive private data or copyrighted material. But…

Making AI models ‘forget’ undesirable data hurts their performance

Uber is now letting riders in India book up to three rides simultaneously.

Uber now lets users in India book three trips at once

U.S. airports are rolling out facial recognition to scan travelers’ faces before boarding their flights. Americans, at least, can opt out. 

How to opt out of facial recognition at airports (if you’re American)

The promise of AI and large language models (LLMs) is the ability to understand increasingly wider amounts of context and make sense of that information easily, so it makes sense…

Bee AI raises $7M for its wearable AI assistant that learns from your conversations

Featured Article

DEI backlash: Stay up-to-date on the latest legal and corporate challenges

It’s clear that this year will be a turning point for DEI.

DEI backlash: Stay up-to-date on the latest legal and corporate challenges

Bike-taxi startup Rapido, which counts Swiggy among its investors, is the latest Indian firm to become a unicorn.

India’s Rapido becomes a unicorn with fresh $120M funding