Home Privacy Google Will Limit Cross-Site Tracking In Chrome By Default Starting In February

Google Will Limit Cross-Site Tracking In Chrome By Default Starting In February

SHARE:

Is Google planning its own version of Safari’s Intelligent Tracking Prevention?

Never say never.

Google is less than two months away from instituting a policy change within the next iteration of Chrome that will severely limit cross-site cookie sharing, and most ad tech companies seem blithely unaware.

Starting Feb. 4, and to coincide with the release of Chrome 80, Google Chrome will stop sending third-party cookies in cross-site requests unless the cookies are secure and flagged using an internet standard called SameSite.

Chrome first announced its plan to develop a secure-by-default model for handling cookies back in May at the Google I/O event.

Cookies that aren’t proactively labeled according to the standard will cease to function in Chrome, and all cookie data that was generated prior to being flagged will no longer be accessible – aka, the sooner you set, the sooner you can get back on track.

“For those that don’t make the deadline, their third-party cookies will break,” said Ratko Vidakovic, founder of ad tech consultancy AdProfs, “which means everything that relies on those cookies will break: audience recognition, analytics, attribution – you name it.”

Not the same-old SameSite

SameSite isn’t new. The concept of a secure cookie flag has existed since the late ’90s, but it’s never been a requirement in Chrome, only a best practice.

The SameSite requirements are part of a larger batch of changes focused on security that Google is making to create what it refers to as “incrementally better cookies.”

Google said it’s getting more aggressive with SameSite to prevent insecure data sharing across domains and cross-site request forgery, which is when hackers manipulate authenticated cookies into taking unwanted actions, like generating fake clicks.

In the short-term, ad tech companies and publishers that haven’t already will be forced to move to HTTPS. If they don’t, their cookies will be discarded by the browser.

But there are potentially wider implications for anyone that does retargeting or relies on third-party iFrames.

“Basically, they’re screwed,” said Zach Edwards, chief data officer at MetaX.

“For the last 22 years, the default has been to allow data, like third-party cookies, to flow across domains – that’s how the whole internet works,” Edwards said. “After February 2020, the default becomes not allowing that transfer to happen in Chrome unless specific cookie flags are set.”

Wave the flag

Developers, or whoever is responsible for maintaining a company’s code base, will now have to set SameSite cookie attributes in Chrome with one of three values: strict, lax or none.

Specifying a cookie as “SameSite=Strict” allows no cross-site sharing. That cookie won’t work anywhere else other than on the domain it was dropped on. “SameSite=lax” is less restrictive, and allows a site to share cookies across domains owned by the same publisher.

“SameSite=none” enables full-on third-party cookie sharing, as long as it’s secure.

Today, SameSite=none is the default in Chrome, and lets the ad tech ecosystem function.

As of February, SameSite=Lax will become the default for developers that don’t proactively enable SameSite=none.

As long as ad tech companies and publishers with proprietary technology label their cookies as SameSite=none, nothing will change – for now.

But once all of the cookies and pixels firing in Chrome have declared their purpose, Google will know exactly which cookies are sharing data across sites. Armed with this knowledge, there’s nothing – other than anticompetitive concerns – stopping Google from creating a privacy tool that would allow users to remove all third-party cookie tracking without deleting functional cookies, like stored passwords.

“I wouldn’t say this puts Chrome into Firefox or Safari territory, so it’s not the cookie Armageddon, but it does lay the groundwork for something that’s on par,” said Dan Larden, managing partner of product and partnerships at Infectious Media. “It’s another nail in the coffin, but not necessarily the burial.”

Hot button

But what would a “no third-party tracking” button actually look like in Chrome?

There’s no need to speculate. Just download Canary, the development version of Chrome where Google tests out beta features before general release; visit “chrome://flags;” and enable the experimental “removing SameSite=none cookies” feature.

Then open an incognito window, and there it is: a toggle called “Block third-party cookies” that, when turned on, will disable browsing activity across different sites from being used to personalize ads.

If Chrome activates this feature for its users, they will have an easy way to opt out of cross-site tracking.

“I wouldn’t be surprised if you could turn tracking on and off in Chrome by, maybe, 2021,” said Mathieu Roche, CEO and co-founder of ID5.

But right now, there’s a countdown to Feb. 4, which is when ad tech companies, publishers and anyone whose business involves the dropping of pixels will have to add SameSite flags to their cookies or risk breaking their corner of the internet.

Ready … or not

So, why isn’t the industry all over this?

Google hasn’t publicized the coming changes enough, Edwards said, because it doesn’t want to be perceived as the second coming of ITP.

“They don’t want articles written about them that they’re gutting the availability of third-party data, so they’re doing things quietly and they’ve only got a few people on their Chrome outreach team talking about this,” he said. “When things break in February, Google’s answer will be, ‘We gave people tons of time, we’ve been talking about this,’ but they’ve only been talking about it very, very softly.”

To be fair, though, the SameSite changes aren’t a secret.

Google told AdExchanger that it started reaching out to its partners directly about SameSite and the incrementally better cookies initiative in May through phone calls, over email and via in-person meetings and group events to explain the announcement and remind them that the Chrome 80 release is around the corner.

Google also posted a series of blogs, dev notes and reminders between May and October.

Some of the larger ad tech players, including Rubicon and The Trade Desk, took notice and set their SameSite cookie flags early. But a lot of folks still aren’t ready.

Female-focused digital media network CafeMedia, for example, ran a test on a few of its sites in mid-November and found that nearly all of the ad tech companies it works with either hadn’t set the SameSite variable correctly or hadn’t set it at all, said Paul Bannister, CafeMedia’s EVP of strategy.

CafeMedia reached out to the laggards and all of them claim that they’re “working on it,” said Bannister, who noted that CafeMedia is handling the SameSite situation for its publisher partners.

Still, publishers shouldn’t expect that SameSite cookie settings are going to magically take care of themselves, Edwards said. Put your head in the sand, and your site isn’t going to work properly after Feb. 4.

“Publishers need to audit all of their core user experiences to find out what cookies are going to break and then proactively determine what they’re responsible for and what their partners are responsible for,” Edwards said. “My biggest piece of advicde would be: Don’t assume that your partners are just going to take care of this for you.”

Must Read

AdExchanger's Big Story podcast with journalistic insights on advertising, marketing and ad tech

Google Had Its Day In Court. Now, It’s Amazon’s Turn

Google won’t have to break up its ads business after being declared an online monopolist. Meanwhile, Amazon faces a lawsuit from the FTC alleging that it charged advertisers more than necessary for ecommerce ads.

The FTC’s Amazon Lawsuit Is Ad Tech’s History Of Opacity Repeating Itself

Buy-side experts said it’s another example of a Big Tech platform taking advantage of the lack of transparency built into programmatic ad auctions. And they’re not optimistic change is coming.

How The Fin Tech Clearco Finances Ecommerce Startups (Without Losing Its Shirt)

This week, the Commerce Media Newsletter catches up with a startup from outside the world of data-driven advertising, but with an interesting position when it comes to ecommerce advertising. That’s Clearco, a Canadian fin tech company founded in 2015.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters
LOS ANGELES, CALIFORNIA - APRIL 26: Halo Collar CMO Seth Solomons attends a Celebration to Shine a Light On Dog Safety With Halo Collar on April 26, 2022 in Los Angeles, California. (Photo by Stefanie Keenan/Getty Images for Halo Collar)

How Halo Collar Uses Data And Incrementality To Raise Both Awareness And Sales

Halo Collar, a dog collar brand with direct-to-consumer origins, is preparing for its retail expansion by honing its first-party data strategy and incrementality measurement.

tech family cartoon technology family

CartographAI Launched To Help Advertisers Pick The Right Tech Vendors. Now, It’s Helping Vendors Market Themselves, Too

The company is launching an accelerator program to help tech vendors pitch their solutions in a way that makes sense to advertisers.

Comic: Weather Bar

Neuroscience And AI Are Transforming The Weather Company’s Measurement Stack

TWC is building a monetization model that treats weather as both a contextual and an emotional signal, and it’s using AI sales agents to bring it to market.