Home Privacy Google Will Limit Cross-Site Tracking In Chrome By Default Starting In February

Google Will Limit Cross-Site Tracking In Chrome By Default Starting In February

SHARE:

Is Google planning its own version of Safari’s Intelligent Tracking Prevention?

Never say never.

Google is less than two months away from instituting a policy change within the next iteration of Chrome that will severely limit cross-site cookie sharing, and most ad tech companies seem blithely unaware.

Starting Feb. 4, and to coincide with the release of Chrome 80, Google Chrome will stop sending third-party cookies in cross-site requests unless the cookies are secure and flagged using an internet standard called SameSite.

Chrome first announced its plan to develop a secure-by-default model for handling cookies back in May at the Google I/O event.

Cookies that aren’t proactively labeled according to the standard will cease to function in Chrome, and all cookie data that was generated prior to being flagged will no longer be accessible – aka, the sooner you set, the sooner you can get back on track.

“For those that don’t make the deadline, their third-party cookies will break,” said Ratko Vidakovic, founder of ad tech consultancy AdProfs, “which means everything that relies on those cookies will break: audience recognition, analytics, attribution – you name it.”

Not the same-old SameSite

SameSite isn’t new. The concept of a secure cookie flag has existed since the late ’90s, but it’s never been a requirement in Chrome, only a best practice.

The SameSite requirements are part of a larger batch of changes focused on security that Google is making to create what it refers to as “incrementally better cookies.”

Google said it’s getting more aggressive with SameSite to prevent insecure data sharing across domains and cross-site request forgery, which is when hackers manipulate authenticated cookies into taking unwanted actions, like generating fake clicks.

In the short-term, ad tech companies and publishers that haven’t already will be forced to move to HTTPS. If they don’t, their cookies will be discarded by the browser.

But there are potentially wider implications for anyone that does retargeting or relies on third-party iFrames.

“Basically, they’re screwed,” said Zach Edwards, chief data officer at MetaX.

“For the last 22 years, the default has been to allow data, like third-party cookies, to flow across domains – that’s how the whole internet works,” Edwards said. “After February 2020, the default becomes not allowing that transfer to happen in Chrome unless specific cookie flags are set.”

Wave the flag

Developers, or whoever is responsible for maintaining a company’s code base, will now have to set SameSite cookie attributes in Chrome with one of three values: strict, lax or none.

Specifying a cookie as “SameSite=Strict” allows no cross-site sharing. That cookie won’t work anywhere else other than on the domain it was dropped on. “SameSite=lax” is less restrictive, and allows a site to share cookies across domains owned by the same publisher.

“SameSite=none” enables full-on third-party cookie sharing, as long as it’s secure.

Today, SameSite=none is the default in Chrome, and lets the ad tech ecosystem function.

As of February, SameSite=Lax will become the default for developers that don’t proactively enable SameSite=none.

As long as ad tech companies and publishers with proprietary technology label their cookies as SameSite=none, nothing will change – for now.

But once all of the cookies and pixels firing in Chrome have declared their purpose, Google will know exactly which cookies are sharing data across sites. Armed with this knowledge, there’s nothing – other than anticompetitive concerns – stopping Google from creating a privacy tool that would allow users to remove all third-party cookie tracking without deleting functional cookies, like stored passwords.

“I wouldn’t say this puts Chrome into Firefox or Safari territory, so it’s not the cookie Armageddon, but it does lay the groundwork for something that’s on par,” said Dan Larden, managing partner of product and partnerships at Infectious Media. “It’s another nail in the coffin, but not necessarily the burial.”

Hot button

But what would a “no third-party tracking” button actually look like in Chrome?

There’s no need to speculate. Just download Canary, the development version of Chrome where Google tests out beta features before general release; visit “chrome://flags;” and enable the experimental “removing SameSite=none cookies” feature.

Then open an incognito window, and there it is: a toggle called “Block third-party cookies” that, when turned on, will disable browsing activity across different sites from being used to personalize ads.

If Chrome activates this feature for its users, they will have an easy way to opt out of cross-site tracking.

“I wouldn’t be surprised if you could turn tracking on and off in Chrome by, maybe, 2021,” said Mathieu Roche, CEO and co-founder of ID5.

But right now, there’s a countdown to Feb. 4, which is when ad tech companies, publishers and anyone whose business involves the dropping of pixels will have to add SameSite flags to their cookies or risk breaking their corner of the internet.

Ready … or not

So, why isn’t the industry all over this?

Google hasn’t publicized the coming changes enough, Edwards said, because it doesn’t want to be perceived as the second coming of ITP.

“They don’t want articles written about them that they’re gutting the availability of third-party data, so they’re doing things quietly and they’ve only got a few people on their Chrome outreach team talking about this,” he said. “When things break in February, Google’s answer will be, ‘We gave people tons of time, we’ve been talking about this,’ but they’ve only been talking about it very, very softly.”

To be fair, though, the SameSite changes aren’t a secret.

Google told AdExchanger that it started reaching out to its partners directly about SameSite and the incrementally better cookies initiative in May through phone calls, over email and via in-person meetings and group events to explain the announcement and remind them that the Chrome 80 release is around the corner.

Google also posted a series of blogs, dev notes and reminders between May and October.

Some of the larger ad tech players, including Rubicon and The Trade Desk, took notice and set their SameSite cookie flags early. But a lot of folks still aren’t ready.

Female-focused digital media network CafeMedia, for example, ran a test on a few of its sites in mid-November and found that nearly all of the ad tech companies it works with either hadn’t set the SameSite variable correctly or hadn’t set it at all, said Paul Bannister, CafeMedia’s EVP of strategy.

CafeMedia reached out to the laggards and all of them claim that they’re “working on it,” said Bannister, who noted that CafeMedia is handling the SameSite situation for its publisher partners.

Still, publishers shouldn’t expect that SameSite cookie settings are going to magically take care of themselves, Edwards said. Put your head in the sand, and your site isn’t going to work properly after Feb. 4.

“Publishers need to audit all of their core user experiences to find out what cookies are going to break and then proactively determine what they’re responsible for and what their partners are responsible for,” Edwards said. “My biggest piece of advicde would be: Don’t assume that your partners are just going to take care of this for you.”

Must Read

square Headshot of Mohammad (Moe) Chughtai, global VP of strategy & partnerships at MiQ, against an orange and yellow gradient background

Better Attribution Makes Live Sports A Performance Play

To squeeze the most juice out of their live sports campaigns, many marketers are adopting programmatic buying and marketing mix modeling, both of which are also drawing more advertisers to the digital live sports cornucopia.

Roblox Opens Up Advertising To Kids Under 13

Roblox is making its under-13 audience available to advertisers for the first time. And it named youth-focused ad marketplace SuperAwesome as its exclusive advertising partner for under-13 users.

Comic: Header Bidding Rapper (Wrapper!)

Outgoing Prebid President Mike Racic On His Departure And The Org’s Next Act

Prebid is turning the page on what might be called its second chapter as the organization navigates some major changes in the digital advertising landscape and within its own ranks.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters
Meta is giving advertisers the ability to connect their third-party analytics tools directly to its ad platform via API.

How Apparel Brand Tuckernuck Devised The 'Why' Behind Its CTV Ad Performance

Performance CTV tech company Keynes launched an AI-powered platform. Tuckernuck says it can finally “pop open the hood” and see what’s working.

Salt Lake City, Utah, U.S.A. - February 24th 2021: Martinelli Gold Medal Sparkling Blush for festive occasions and gatherings. Fermented Apple Cider from the state of California.

How Juice Brand Martinelli’s Gets To The Core Of Retail Media Incrementality

ROAS who? Martinelli’s is testing how crisp its retail media spend really is by using a new metric called incremental ROAS.

A scale with the letters AI on one side and a pencil and ruler on the other. The pencil and ruler represent the concept of measurement and precision

Measured Has A New Tool That Lets Marketers Chat With Their Incrementality Data

Media measurement provider Measured launched an MCP integration that allows brands to ask ChatGPT, Claude, Gemini and other AI platforms how their media is performing.