REVIEW 4 major objections 5 minor 84 references
Technical Report: The Need for a (Research) Sandstorm through the Privacy Sandbox
T0 review · 4 major / 5 minor · reviewed 2026-08-03 · deepseek-v4-flash
Pith's one-line read This report claims that Privacy Sandstorm, a community-maintained research portal, gives broader and more complete visibility into independent Privacy Sandbox research than Google's official channels.
desk verdict A useful portal and a real dataset, but the 'better visibility' claim is a mission statement, not a result. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the Privacy Sandstorm portal, a continuously updated public inventory that maps every Privacy Sandbox proposal to its overview, official explainers, and the set of independent analyses performed on it. The inventory is what the paper's visibility claim rests on; because it is open to contributions and is the source of the automatically generated report, the authors argue it can surface research findings that Google's official channels do not show. Supporting pieces are the curated datasets and software — a reimplementation of the Topics classifier used to classify 147 million hostnames, a crawler for .well-known attestation files, and pointers to measurement toolin
What would settle it
Compile a comprehensive list of all independent analyses of Privacy Sandbox proposals from literature databases, browser-vendor blogs, regulatory filings, and conference proceedings; if that list contains entries absent from Privacy Sandstorm — or if Google's official channels are found to reference independent analyses the portal omits — the claim of broader perspective is undercut. A minimal version for one API: for Topics, enumerate every published analysis (papers, blog posts, standards-position documents) and check what fraction the portal lists.
Extended reading notes
Core claim
On its own terms, the paper's claim is that Privacy Sandstorm — a website built and maintained by the authors — achieves what no official Google channel does: it systematically gathers and makes visible the independent research on every Privacy Sandbox proposal, from FLoC (an early cohort-based targeting proposal) to Topics (its replacement that classifies browsing into interest categories) and Attribution Reporting (the API for measuring ad conversions without third-party cookies). Beyond the catalog itself, the report asserts that such an inventory is necessary because Google has implemented, shipped, and deprecated APIs without consensus from other browsers, and because independent analys
Load-bearing premise
The claim that the portal provides better visibility than Google's official channels rests on the unverified premise that the inventory is representative of all relevant independent research and that simple listing of resources constitutes visibility; the report offers no coverage analysis, user data, or direct comparison against Google's channels to back it.
Editorial extensions
If this is right
- The portal gives any researcher, regulator, or journalist a single entry point to the independent literature on each Privacy Sandbox proposal, making it harder for critical findings to be overlooked.
- The bundled data — 147 million hostnames classified with the Topics classifier, .well-known crawl results, and tracker datasets — supports reproduction and extension of existing measurement studies, such as measuring Topics adoption or attestation compliance.
- The per-proposal analysis lists show a recurring pattern of independent evaluations finding privacy weaknesses in FLoC, Topics, and Protected Audience; if the list is complete, that pattern is a documented record of the gap between Google's privacy claims and external results.
- Because Google deprecated most APIs in October 2025, the inventory preserves the evaluations as a knowledge base for designing future privacy-preserving advertising mechanisms.
- The open, pull-request-based structure turns the portal into shared community infrastructure, so the visibility claim can be maintained and improved by contributors other than the authors.
Reading between the lines
- The report's transparency claim is stronger than its evidence: if the inventory were compared quantitatively against Google's official status pages and documentation, the claimed gap in visibility could be measured — e.g., counting how many independent analyses the portal lists per API versus the number referenced anywhere by Google's channels.
- A natural extension is meta-analysis: annotating each listed analysis with its conclusion (privacy risk found, utility loss, adversarial result) would convert the bibliography into a knowledge base from which research trends per API could be extracted.
- One could test whether the inventory predicts outcomes: proposals with more independent critical analyses in the portal may correlate with later modification or deprecation, suggesting research influence on industry decisions.
- The report does not itself weigh the trustworthiness of the analyses it lists; treating the portal as a comprehensive map is separate from endorsing the findings, a distinction future users of the portal will need to keep in mind.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The report introduces Privacy Sandstorm, a community research portal that curates resources—overviews, analyses, datasets, and software—on Google's Privacy Sandbox and related proposals for online advertising and privacy. It describes the portal's objectives, lists several datasets and software tools (including a Topics classifier and .well-known crawler), and catalogs analyses for each Privacy Sandbox API as well as for other mechanisms such as GPC, Privacy Pass, and TURTLEDOVE variants. The central claim, stated in the abstract and Introduction, is that this inventory 'provides a better visibility and broader perspective' on research findings than Google's official channels. The paper is a technical report whose content is automatically generated from the website.
Significance. If the inventory is comprehensive, maintained, and independently usable, Privacy Sandstorm is a valuable community resource—particularly as the Privacy Sandbox APIs are deprecated but their analyses remain relevant for future proposals. The concrete artifacts (the Topics classification of 147M hostnames, the .well-known crawler, and the Topics API reimplementation) are reproducible and could support future measurement studies. The paper also raises a legitimate call for independent privacy, security, usability, and utility evaluations of such proposals. However, the main 'finding' about visibility is not empirically substantiated: the report does not define visibility, enumerate Google's official channels, measure coverage, or provide user-reach data. The contribution is therefore best seen as a position statement and resource announcement rather than an empirical comparative study, and the central claim needs reframing or evidence before it can support the paper's conclusions.
major comments (4)
- [Abstract and Section 2] The abstract states: 'we find that our inventory provides a better visibility and broader perspective on the research findings in that space than what Google lets show through official channels.' This is the paper's strongest claim, but it is never operationalized. Neither 'visibility' nor 'broader perspective' is defined (e.g., number of resources, unique findings, audience reach, searchability, timeliness), Google's official channels are not enumerated or compared, and no coverage analysis is provided. Without such evidence, the claim is an assertion, not a finding. The authors should either reframe it as a hypothesis/position statement or add a systematic comparison against a defined set of Google channels, including a coverage audit.
- [Section 2 ('Privacy Sandstorm: a Research Portal')] The report says 'we continuously perform an inventory of the relevant analyses' but gives no methodology for how resources are discovered, selected, or validated. There are no inclusion/exclusion criteria, no search protocol, no inter-rater reliability, and no mechanism for detecting omissions. Because the authors are the portal operators, the evaluative claim about 'better visibility' is self-referential unless an independent audit or a clearly defined curation policy is provided. The absence of such methodology makes it impossible to assess whether the inventory is representative of all relevant research or biased toward works critical of Google.
- [Section 3.1 (Datasets)] The Topics Classification dataset is described as covering 'more than 147 million hostnames corresponding to 31 million unique domains,' but no accuracy or validation details are given. There is no comparison against a gold standard, no description of how the classifier was applied or verified, and no discussion of known failure modes. Similarly, the .well-known dataset lacks crawl methodology and validation. Since these datasets are presented as contributions of the portal, the lack of validation undermines their utility for independent researchers and weakens the paper's overall credibility as an empirical resource.
- [Section 4.19.3 (Topics API analyses)] The analysis list for the Topics API includes the authors' own papers ([7], [9]) alongside independent works. This is not inherently problematic, but the report should disclose a self-citation/conflict-of-interest policy and explain how the authors' own analyses were selected relative to other works. Without such disclosure, the claim of a 'broader perspective' could be seen as advancing the authors' own agenda rather than providing a neutral inventory. A brief statement about curation independence and the role of the authors in the portal would address this.
minor comments (5)
- [Abstract / Note] The note about Google's October 2025 deprecation appears immediately after the Keywords, outside the main text. It should be integrated into the Introduction, as it materially affects the report's framing and the relevance of the analyses being catalogued.
- [Section 4.15.2] The sentence 'Check out our .well-known crawler and analysis code, more details also on this post.' contains an unresolved link ('this post') that is meaningless in a printed report. Please replace with a full URL or a reference to the corresponding repository.
- [Section 4.19.2] Under API calls, 'Documentation (Android)' appears twice in succession. One entry is likely redundant or mislabeled; please correct or remove the duplicate.
- [Section 5.5.2] The subsection heading 'Unified 2.0' appears to be a truncation of 'Unified ID 2.0', which is the term used in the body text. Please align the heading.
- [General formatting] Several inline references are vague, such as 'see this status overview' and 'this post', without a URL or identifier. In a technical report meant to be read offline, all such links should be either fully specified or accompanied by a citation.
Circularity Check
No circular derivation: this is a curated inventory, and the 'better visibility' claim is an unsupported self-assessment rather than a circular reduction.
full rationale
This technical report does not present a derivation chain, fitted parameters, or predictions; it is an annotated inventory of Privacy Sandbox research and artifacts. The strongest claim ('we find that our inventory provides a better visibility...') is a self-referential judgment about the authors' own portal, and it is indeed asserted without an operationalized measure of visibility or a comparison against Google's channels — but that is an evidentiary/rigor weakness, not circularity: no quantity is defined in terms of another, no parameter is fit and then renamed as a finding, and no load-bearing argument reduces to a self-citation. The authors do cite their own prior work ([7], [8], [9], [10], [72]), but those citations are supporting bibliography entries for the catalog; none is invoked as a uniqueness theorem or as the sole justification for the portal's conclusions. Section 2's stated goal of 'giving broader visibility' and the later finding of 'better visibility' are conceptually the same, but the report does not derive the latter from the former by construction; it simply asserts an outcome. Per the stated rules, unsupported or self-promotional claims without a specific equation- or definition-level reduction are not circularity. The central catalog content (proposal overviews, datasets, software pointers, and third-party analyses) is externally sourced and independently checkable, so the report is self-contained against external benchmarks and receives score 0.
Assumptions & free parameters
assumptions (2)
- domain assumption A systematically gathered inventory improves research visibility and coordination
- domain assumption The listed analyses and datasets are a representative sample of the research space
Cite this review
Pith. "Pith review of Technical Report: The Need for a (Research) Sandstorm through the Privacy Sandbox." pith.science (2026). https://pith.science/paper/TEJBKFG5
@misc{pith2026251203207,
author = {Pith},
title = {Pith review of: Technical Report: The Need for a (Research) Sandstorm through the Privacy Sandbox},
year = {2026},
howpublished = {\url{https://pith.science/paper/TEJBKFG5}},
note = {Machine review of arXiv:2512.03207}
}
read the original abstract
The Privacy Sandbox, launched in 2019, is a series of proposals from Google to reduce ``cross-site and cross-app tracking while helping to keep online content and services free for all''. Over the years, Google implemented, experimented, and deprecated some of these APIs into their own products (Chrome, Android, etc.) which raised concerns about the potential of these mechanisms to fundamentally disrupt the advertising, mobile, and web ecosystems. As a result, it is paramount for researchers to understand the consequences that these new technologies, and future ones, will have on billions of users if and when deployed. In this report, we outline our call for privacy, security, usability, and utility evaluations of these APIs, our efforts materialized through the creation and operation of Privacy Sandstorm (https://privacysandstorm.github.io); a research portal to systematically gather resources (overview, analyses, artifacts, etc.) about such proposals. We find that our inventory provides a better visibility and broader perspective on the research findings in that space than what Google lets show through official channels.
Reference graph
Works this paper leans on
-
[7]
Yohan Beugin and Patrick McDaniel. 2024. A Public and Reproducible Assessment of the Topics API on Real Data. In IEEE Security and Privacy Workshop on Designing Security for the Web (SecWeb), May 2024. https://doi.org/ 10.48550/arXiv. 2403.19577
-
[9]
Yohan Beugin and Patrick McDaniel. 2024. Interest disclos ing Mechanisms for Advertising are Privacy Exposing (not Preserving). In Proceedings on Privacy Enhancing Technolo - gies Symposium (PETS) , July 2024. https://doi.org/ 10.56553/ popets20240004
2024
-
[1]
Varadara jan
Hidayet Aksu, Badih Ghazi, Pritish Kamath, Ravi Kumar, Pasin Manurangsi, Adam Sealfon, and Avinash V. Varadara jan. 2024. Summary Reports Optimization in the Privacy Sandbox Attribution Reporting API. Proceedings on Pri - vacy Enhancing Technologies (2024). Retrieved from https:// petsymposium.org/popets/2024/popets20240132.php
2024
-
[2]
Mir Masood Ali, Binoy Chitale, Mohammad Ghasemisharif, Chris Kanich, Nick Nikiforakis, and Jason Polakis. 2023. Navigating Murky Waters: Automated Browser Feature Test ing for Uncovering Tracking Vectors. In Proceedings 2023 Network and Distributed System Security Symposium , 2023. Internet Society, San Diego, CA, USA. https://doi.org/ 10. 14722/ndss.2023.24072
arXiv 2023
-
[4]
Alvim, Natasha Fernandes, Annabelle McIver, and Gabriel H
Mário S. Alvim, Natasha Fernandes, Annabelle McIver, and Gabriel H. Nunes. 2024. The PrivacyUtility Tradeoff in the Topics API. In Proceedings of the 2024 on ACM SIGSAC Confer- ence on Computer and Communications Security , December
2024
-
[5]
Enrico Bacis, Igor Bilogrevic, Robert Busa Fekete, Asanka Herath, Antonio Sartori, and Umar Syed. 2024. Assessing Web Fingerprinting Risk. https://doi.org/ 10.48550/arXiv. 2403.15607
work page Pith review arXiv doi:10.48550/arxiv.2403.15607 2024
-
[6]
Alex Berke and Dan Calacci. 2022. Privacy Limitations of InterestBased Advertising on The Web: A PostMortem Em pirical Analysis of Google's FLoC. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security (CCS '22), November 2022. Association for Comput ing Machinery, New York, NY, USA, 337–349. https://doi.org/ 10.1145/3...
arXiv 2022
-
[8]
Yohan Beugin and Patrick McDaniel. 2024. The Need for a (Research) Sandstorm through the Privacy Sandbox. In 17th Workshop on Hot Topics in Privacy Enhancing Technologies (HotPETs), July 2024. Retrieved from https://privacysandstor m.github.io/
2024
Show all 84 references
-
[10]
Yohan Beugin, Sam Dutton, Yana Dimova, Rowan Mere wood, and Barry Pollard. 2024. The 2024 Web Almanac: Cookies. The 2024 Web Almanac . https://doi.org/ 10.5281/ zenodo.14065903
2024
-
[11]
Grinstead Brian. 2023. Request for Mozilla Position on an Emerging Web Specification. Retrieved from https://github. com/mozilla/standardspositions/issues/852
2023
-
[12]
Giuseppe Calderonio, Mir Masood Ali, and Jason Polakis
- [13]
-
[14]
In 33rd USENIX Security Symposium (USENIX Security 24) , 2024
Fledging Will Continue Until Privacy Improves: Em pirical Analysis of Google's Privacy Preserving Targeted Advertising. In 33rd USENIX Security Symposium (USENIX Security 24) , 2024. 4121–4138. Retrieved from https:// www.usenix.org/conference/usenixsecurity24/presentation/...
2024
-
[15]
Bennett Cyphers. 2019. Don't Play in Google's Privacy Sand box. Retrieved from https://www.eff.org/deeplinks/2019/08/ dontplaygooglesprivacysandbox1
2019
-
[16]
Benjamin Case, Richa Jain, Alex Koshelev, Andy Leiserson, Daniel Masny, Thurston Sandberg, Ben Savage, Erik Taube neck, Martin Thomson, and Taiki Yamaguchi. 2023. Interop erable Private Attribution: A Distributed Attribution and Aggregation Protocol. Retrieved from https://...
2023
-
[17]
Alex Davidson, Ian Goldberg, Nick Sullivan, George Tanker sley, and Filippo Valsorda. 2018. Privacy Pass: Bypassing Internet Challenges Anonymously. Proceedings on Privacy Enhancing Technologies (2018). Retrieved from https:// petsymposium.org/popets/2018/popets20180026.php
2018
-
[18]
Bennett Cyphers. 2021. Google's FLoC Is a Terrible Idea. Retrieved from https://www.eff.org/deeplinks/2021/ 03/googlesflocterribleidea
2021
-
[19]
Travis Dick, Alessandro Epasto, Adel Javanmard, Josh Karlin, Andrés Muñoz Medina, Vahab Mirrokni, Sergei Vassilvitskii, and Peilin Zhong. 2025. Differentially Private Synthetic Data Release for Topics API Outputs. In Proceedings of the 31st ACM SIGKDD Conference on Knowledge D...
2025
-
[20]
John Delaney, Badih Ghazi, Charlie Harrison, Christina Ilvento, Ravi Kumar, Pasin Manurangsi, Martin Pál, Karthik Prabhakar, and Mariana Raykova. 2024. Differentially Pri vate Ad Conversion Measurement. Proceedings on Privacy Enhancing Technologies (2024). Retrieved from htt...
2024
-
[21]
Alessandro Epasto, Andres Munoz Medina, Christina Il vento, and Josh Karlin. 2022. Measures of Cross Site ReIdentification Risk: An Analysis of the Topics API Pro posal. (2022), 12. Retrieved from https://github.com/patcg individualdrafts/topics/blob/main/topics_analysis.pdf
2022
-
[22]
French Center of Expertise for Digital Platorm Regulation (PEReN). 2022. Shedding Light On…The Privacy Sandbox: A Collection of Tools for Third Party Cookieless Online Advertising. Retrieved from https://www.peren.gouv.fr/en/ actualites/20220428/_eclairage/_sur/_privacy/_sandbox/
2022
-
[23]
IAB Tech Lab Privacy Sandbox Task Force. 2024. Privacy Sandbox Fit Gap Analysis for Digital Advertising. Retrieved from https://iabtechlab.com/standards/privacysandbox/
2024
-
[24]
Alessandro Epasto, Andrés Muñoz Medina, Steven Avery, Yijian Bai, Robert BusaFekete, \relax CJ Carey, Ya Gao, David Guthrie, Subham Ghosh, James Ioannidis, Junyi Jiao, Jakub Lacki, Jason Lee, Arne Mauser, Brian Milch, Vahab Mirrokni, Deepak Ravichandran, Wei Shi, Max Spero, Y...
2021
-
[25]
Konrad Hanff, Anja Lehmann, and Cavit Özbay. 2025. Secu rity Analysis of Privately Verifiable Privacy Pass. In Proceed- ings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25), November 2025. Associ ation for Computing Machinery, New York, ...
2025
-
[26]
Zhengrong Gu, Garrett Johnson, and Shunto Kobayashi
-
[27]
Philippe Le Hégaret. 2023. Web Environment Integrity Has No Standing at W3C; Understanding New W3C Work. Retrieved from https://www.w3.org/blog/2023/web environmentintegrityhasnostandingatw3c/
2023
-
[28]
Sarp Ilgaz. 2025. Investigating High Entropy Client Hint usage in HTTP/2 and HTTP/3. Bachelor Thesis. Retrieved from https://www.cs.ru.nl/bachelors theses/2025/Sarp_Ilgaz___1093588___Investigating_High_ Entropy_Client_Hint_usage_in_HTTP2_and_HTTP3.pdf
2025
-
[29]
Jean Luc Intumwayase, Imane Fouad, Pierre Laperdrix, and Romain Rouvoy. 2023. UA Radar: Exploring the Impact of User Agents on the Web. In Proceedings of the 22nd Workshop on Privacy in the Electronic Society (WPES '23) , November
2023
-
[30]
Cory Doctorow and Jacob Hoffman Andrews. 2023. Your Computer Should Say What You Tell It To Say. Re trieved from https://www.eff.org/deeplinks/2023/08/your computershouldsaywhatyoutellitsay1
2023
-
[31]
Nikhil Jha, Martino Trevisan, Emilio Leonardi, and Marco Mellia. 2023. On the Robustness of Topics API to a Re Identification Attack. Proceedings on Privacy Enhancing Tech- nologies (2023). Retrieved from https://petsymposium.org/ popets/2023/popets20230098.php
2023
-
[32]
Nikhil Jha, Martino Trevisan, Emilio Leonardi, and Marco Mellia. 2024. Re Identification Attacks against the Topics API. ACM Trans. Web 18, (August 2024), 39:1–39:24. https:// doi.org/10.1145/3675400
2024 doi
-
[33]
Garrett A Johnson and Nico Neumann. 2024. The Advent of Privacy Centric Digital Advertising: Tracing Privacy Enhancing Technology Adoption. (2024). Retrieved from https://pep.gmu.edu/wpcontent/uploads/sites/28/2024/04/ JohnsonNeumann.pdf
2024
-
[34]
Garrett Johnson. 2024. Unearthing Privacy Enhancing Ad Technologies (PEAT): The Adoption of Google's Privacy Sandbox. https://doi.org/10.2139/ssrn.4983927
2024 doi
-
[35]
Przemysław Iwańczak and Mateusz Rumiński. 2022. The Future of Frequency Capping in PrivacyCentric Digital Ad vertising. https://doi.org/10.2139/ssrn.3985974
2022 doi
-
[36]
Anne van Kesteren. 2023. WebKit Standards Positions The Topics API. Retrieved from https://github.com/WebKit/ standardspositions/issues/111
2023
-
[37]
Michael Kleber. 2019. Privacy Model for the Web. Retrieved from https://github.com/michaelkleber/privacymodel
2019
-
[38]
Shunto Kobayashi, Garrett Johnson, and Zhengrong Gu
-
[39]
Elena Bakos Lang, Giacomo Pope, Giovanni De Fer rari, Huy Nguyen, Lydia Yao, Thomas Pornin, Tyler Colgan, and Viktor Gazdag. 2024. Privacy Sandbox Aggre gation Service and Coordinator. (April 2024). Retrieved from https://www.foxit.com/media/m3yogjsq/_ncc_group_ google_pr...
2024
-
[40]
Guillaume Kessibi, Aymen Ould Hamouda, Charly Poirier, and Antoine Boutet. 2022. A Complementary Utility and Privacy Trade off Evaluation of Google's FloC API. (2022). Retrieved from https://inria.hal.science/hal03953308 v1/document
2022
-
[41]
Haoran Lu, Yichen Liu, Xiaojing Liao, and Luyi Xing
-
[42]
Stephen McQuistin, Peter Snyder, Hamed Haddadi, and Gareth Tyson. 2024. A First Look at Related Website Sets. In Proceedings of the 2024 ACM on Internet Measurement Con- ference, November 2024. 107–113. https://doi.org/ 10.1145/ 3646547.3689026
2024
-
[43]
Mozilla. 2019. Mozilla Position on Web Packaging. Retrieved from https://docs.google.com/document/d/1ha00 dSGKmjoEh2mRiG8FIA5sJ1KihTuZeAXX1r8P8/edit?usp= sharing
2019
-
[44]
https:// doi.org/10.2139/ssrn.4972368
PrivacyEnhanced versus Traditional Retargeting: Ad Effectiveness in an IndustryWide Field Experiment. https:// doi.org/10.2139/ssrn.4972368
-
[45]
Alexandra Nisenoff, Deian Stefan, and Nicolas Christin. 2025. Exploiting the Shared Storage API. In Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25), November 2025. Association for Comput ing Machinery, New York, NY, USA, 1260–12...
2025
-
[46]
Minjun Long and David Evans. 2024. Evaluating Google's Protected Audience Protocol. Proceedings on Privacy Enhancing Technologies (2024). Retrieved from https:// petsymposium.org/popets/2024/popets20240147.php
2024
-
[47]
Lukasz Olejnik. 2023. Reconciling Privacy Sand box Initiatives with EU Data Protection Laws. (2023). Retrieved from https://lukaszolejnik.com/stuff/ PrivacySandbox_PAAPI_LLM_LO.pdf
2023
-
[48]
In 33rd USENIX Security Symposium (USENIX Secu- rity 24), 2024
Towards Privacy Preserving Social Media SDKs on Android. In 33rd USENIX Security Symposium (USENIX Secu- rity 24), 2024. 647–664. Retrieved from https://www.usenix. org/conference/usenixsecurity24/presentation/luhaoran
2024
-
[49]
Michiel Philipse. 2024. Post ThirdParty Cookies: Analyz ing Google's Protected Audience API. Master Thesis. Re trieved from https://www.cs.ru.nl/masterstheses/2024/M_ 16 Philipse___PostThirdParty_Cookies_Analyzing_Google's_ Protected_Audience_API..pdf
2024
-
[50]
Julien Picalausa. 2023. Unpacking Google's New ``Danger ous'' Web EnvironmentIntegrity Specification. Retrieved from https://vivaldi.com/blog/googlesnewdangerousweb environmentintegrityspec/
2023
-
[51]
Shaoor Munir, Konrad Kollnig, Anastasia Shuba, and Zubair Shafiq. 2024. Google's Chrome Antitrust Paradox. Retrieved December 2, 2025 from https://papers.ssrn.com/abstract= 4780718
2024
-
[52]
Eric Rescorla and Martin Thomson. 2021. Technical Com ments on FLoC Privacy. (June 2021). Retrieved from https:// mozilla.github.io/ppadocs/floc_report.pdf
2021
-
[53]
Mark Nottingham. 2021. Playing Fair in the Privacy Sand box: Competition, Privacy and Interoperability Standards. https://doi.org/10.2139/ssrn.3891335
2021 doi
-
[54]
Mateusz Rumiński, Przemysław Iwańczak, and Łukasz Wło darczyk. 2022. Findings from the Early Fledge Experiments. https://doi.org/10.2139/ssrn.4219796
2022 doi
-
[55]
Lukasz Olejnik. 2023. On the Governance of Privacy Pre serving Systems for the Web: Should Privacy Sandbox Be Governed?. Handbook on the Politics and Governance of Big Data and Artificial Intelligence , 279–314. https://doi.org/ 10. 4337/9781800887374.00022
2023
-
[56]
Asuman Senol and Gunes Acar. 2023. Unveiling the Impact of UserAgent Reduction and Client Hints: A Measurement Study. In Proceedings of the 22nd Workshop on Privacy in the Electronic Society (WPES '23), November 2023. Association for Computing Machinery, New York, NY, USA, 91...
2023
-
[57]
Peter Snyder and Brendan Eich. 2021. Why Brave Disables FLoC. Retrieved from https://brave.com/blog/whybrave disablesfloc/
2021
-
[58]
Deepak Ravichandran and Sergei Vassilvitskii. 2020. Eval uation of Cohort Algorithms for the FLoC API. (2020). Re trieved from https://raw.githubusercontent.com/google/ads privacy/master/proposals/FLoC/FLOCWhitepaperGoogle. pdf
2020
-
[59]
Peter Snyder and Ben Livshits. 2019. Brave, Fingerprinting, and Privacy Budgets. Retrieved from https://brave.com/web standardsatbrave/2privacybudgets/
2019
-
[60]
Eric Rescorla. 2021. Technical Comments on Privacy Budget. (2021). Retrieved from https://mozilla.github.io/ppadocs/ privacybudget.pdf
2021
-
[61]
Peter Snyder. 2020. WebBundles Harmful to Content Block ing, Security Tools, and the Open Web. Retrieved from https://brave.com/webstandardsatbrave/3webbundles/
2020
-
[62]
Shivan Kaul Sahib and Peter Snyder. 2021. Encrypting DNS Zone Transfers. Retrieved from https://brave.com/web standardsatbrave/5encryptingdnszonetransfers/
2021
-
[63]
Peter Snyder. 2022. Google's Topics API: Rebranding FLoC Without Addressing Key Privacy Issues. Retrieved from https://brave.com/webstandardsatbrave/7googles topicsapi/
2022
-
[64]
Peter Snyder. 2022. First Party Sets: Tearing Down Privacy Defenses Just as They're Being Built. Retrieved from https:// brave.com/webstandardsatbrave/8firstpartysets/
2022
-
[65]
Peter Snyder and Anton Lazarev. 2020. Global Pri vacy Control, a New Privacy Standard Proposal. Re trieved from https://brave.com/webstandardsatbrave/4 globalprivacycontrol/
2020
-
[66]
Martin Thomson and Eric Rescorla. 2021. Comments on SWAN and Unified ID 2.0. (August 2021). Retrieved from https://mozilla.github.io/ppadocs/swan_uid2_report.pdf
2021
-
[67]
Peter Snyder, Pranjal Jumde, Tom Lowenthal, and Brian Clifton. 2019. Brave's Concerns with the Client Hints Pro posal. Retrieved from https://brave.com/webstandardsat brave/1clienthints/
2019
-
[68]
Martin Thomson. 2023. A Privacy Analysis of Google's Top ics Proposal. (January 2023). Retrieved from https://mozilla. github.io/ppadocs/topics.pdf
2023
-
[69]
Peter Snyder. 2022. Privacy And Competition Concerns with Google's Privacy Sandbox. Retrieved from https://brave. com/webstandardsatbrave/6privacysandboxconcerns/
2022
-
[70]
Florian Turati, Karel Kubicek, Carlos Cotrini, and David Basin. 2023. Locality Sensitive Hashing Does Not Guaran tee Privacy! Attacks on Google's FLoC and the MinHash Hierarchy System. Proceedings on Privacy Enhancing Tech - nologies (2023). Retrieved from https://petsympos...
2023
-
[71]
Šimon Vacek. 2024. FedCM API Integration into Keycloak. Bachelor Thesis. Retrieved from https://theses.cz/id/qldogj/
2024
-
[72]
Peter Snyder. 2023. ``Web Environment Integrity'': Locking Down the Web. Retrieved from https://brave.com/web standardsatbrave/9webenvironmentintegrity/
2023
-
[73]
Alberto Verna, Nikhil Jha, Martino Trevisan, and Marco Mellia. 2024. A First View of Topics API Usage in the Wild. In Proceedings of the 20th International Conference on Emerg- ing Networking EXperiments and Technologies (CoNEXT '24), December 2024. Association for Computing M...
2024 doi
-
[74]
Martin Thomson. 2022. An Analysis of Apple's Private Click Measurement. (June 2022). Retrieved from https://mozilla. github.io/ppadocs/pcm.pdf
2022
-
[75]
Maximilian Westers, Andreas Mayer, and Louis Jannett. 2024. Single SignOn Privacy: We Still Know What You Did Last Summer. In 2024 Annual Computer Security Applications Con- ference (ACSAC), December 2024. IEEE, Honolulu, HI, USA, 321–335. https://doi.org/10.1109/ACSAC63791.2...
2024
-
[76]
Martin Thomson. 2024. Protected Audience Privacy Analy sis. (March 2024). Retrieved from https://mozilla.github.io/ ppadocs/protectedaudience.pdf
2024
- [77]
-
[79]
Yash Vekaria, Yohan Beugin, Shaoor Munir, Gunes Acar, Nataliia Bielova, Steven Englehardt, Umar Iqbal, Alexandros Kapravelos, Pierre Laperdrix, Nick Nikiforakis, Jason Polakis, Franziska Roesner, Zubair Shafiq, and Sebastian Zimmeck
-
[80]
https://doi.org/10.48550/arXiv.2506.14057
SoK: Advances and Open Problems in Web Tracking. https://doi.org/10.48550/arXiv.2506.14057
-
[82]
Alberto Verna, Nikhil Jha, Martino Trevisan, and Marco Mellia. 2025. Understanding Topics API in the Wild: Dubious Usage and Stale Adoption. IEEE Transactions on Privacy 2, (2025), 119–130. https://doi.org/10.1109/TP.2025.3615120
2025
-
[84]
Stephan Wiefling, Marian Hönscheid, and Luigi Lo Iacono
-
[85]
In Proceedings of the 19th International Conference on Availability, Reliability and Security (ARES '24), July 2024
A Privacy Measure Turned Upside Down? Investigat ing the Use of HTTP Client Hints on the Web. In Proceedings of the 19th International Conference on Availability, Reliability and Security (ARES '24), July 2024. Association for Comput ing Machinery, New York, NY, USA, 1–12....
2024
-
[2024]
https://doi.org/10.1145/3658644.3670368
1106–1120. https://doi.org/10.1145/3658644.3670368
-
[2025]
https://doi.org/ 10.2139/ssrn
Can Privacy Technologies Replace Cookies? Ad Rev enue in a Field Experiment. https://doi.org/ 10.2139/ssrn. 5284526
-
[2936]
https://doi.org/10.1145/3719027.3765172
Reviewed August 3, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.