Security News > 2021 > April > WordPress core contributor proposes treating Google FLoC as a security vulnerability

WordPress core contributor proposes treating Google FLoC as a security vulnerability
2021-04-19 20:27

A proposal by a WordPress core contributor to treat Google's FLoC ad tech as a security vulnerability, and therefore backport an automatic opt-out to previous WordPress versions, shows the depth of community opposition to the technology.

Now a WordPress Core contributor has proposed treating "FLoC as a security concern."

If WordPress were to treat FLoC as a vulnerability and apply this header to all WordPress sites that automatically apply security patches, a substantial proportion of the web would be opted out.

The author of the proposal, Carike, added that there is also a feature request to make the next version of WordPress, 5.8, opt-out of FLoC by default - but remarked that "5.8 is only scheduled for July 2021. FLoC will likely be rolling out this month."

There are of course also naysayers, such as this one arguing that "Those websites who want to block FLoC are likely to have the technical know-how to add in the header and disable it ... Where do we draw the line at what WordPress should be blocking in core for privacy? ... Calling it a"security concern" is just absolutely false and sets a dangerous precedent for what is security, and what is privacy.

Much of what is called SEO is focused on how to optimise a site for Google and it is likely that supporting FLoC will simply be added to the list of steps web sites should take in order to perform at their best from a commercial perspective.


News URL

https://go.theregister.com/feed/www.theregister.com/2021/04/19/wordpress_core_contributor_proposes_treating/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 102 253 4226 4525 728 9732
Wordpress 7 2 95 44 18 159