| Both sides previous revisionPrevious revisionNext revision | Previous revision |
| provenance:privacy:privacy_sandbox [2026/09/01 16:42] – Reword an escaped citation marker that the bibtex plugin picked up anyway. Authored by Claude. karel.kubicek.claude | provenance:privacy:privacy_sandbox [2026/09/01 17:36] (current) – Remove a literal citation marker the bibtex plugin picked up through its nowiki escape, and stop asserting self-referential heading and table counts for this page. Authored by Claude. karel.kubicek.claude |
|---|
| | Full text names ''%%/Privacy\s+Sandbox/i%%'' at least once | 5,869 papers with ''paper.cols.txt'' | **43** (0.7%) | yes | | | Full text names ''%%/Privacy\s+Sandbox/i%%'' at least once | 5,869 papers with ''paper.cols.txt'' | **43** (0.7%) | yes | |
| | Same, five or more times | 5,869 | **9** (0.2%) | yes | | | Same, five or more times | 5,869 | **9** (0.2%) | yes | |
| | Names at least one folded API family | 5,869 | **72** (1.2%) | yes | | | Names at least one folded API family | 5,869 | **67** (1.1%) | yes | |
| | Topics family (incl. FLoC) | 5,869 | 22 | yes | | | Topics family (incl. FLoC) | 5,869 | 22 | yes | |
| | Protected Audience family (incl. FLEDGE, TURTLEDOVE) | 5,869 | 11 | yes | | |
| | UA Client Hints / UA reduction | 5,869 | 10 | yes | | | UA Client Hints / UA reduction | 5,869 | 10 | yes | |
| | | Protected Audience family (incl. FLEDGE, TURTLEDOVE) | 5,869 | 8 | yes | |
| | Privacy Sandbox on Android | 5,869 | 7 | yes | | | Privacy Sandbox on Android | 5,869 | 7 | yes | |
| | Related Website Sets (incl. First-Party Sets) | 5,869 | 6 | yes | | |
| | CHIPS | 5,869 | 5 | yes | | | CHIPS | 5,869 | 5 | yes | |
| | Private State Tokens (incl. Trust Tokens) | 5,869 | 5 | yes | | | Private State Tokens (incl. Trust Tokens) | 5,869 | 5 | yes | |
| | Attribution Reporting | 5,869 | 4 | yes | | |
| | Fenced Frames | 5,869 | 4 | yes | | | Fenced Frames | 5,869 | 4 | yes | |
| | | Related Website Sets (incl. First-Party Sets) | 5,869 | 4 | yes | |
| | | Attribution Reporting | 5,869 | 3 | yes | |
| | Shared Storage | 5,869 | 3 | yes | | | Shared Storage | 5,869 | 3 | yes | |
| | Private Aggregation | 5,869 | 2 | yes | | | Private Aggregation | 5,869 | 2 | yes | |
| | IP Protection | 5,869 | **0** | yes | | | IP Protection | 5,869 | **0** | yes | |
| | Bounce Tracking Mitigations, by that name | 5,869 | **0** | yes | | | Bounce Tracking Mitigations, by that name | 5,869 | **0** | yes | |
| | Web crawls 2023–2026 naming an API family | 332 web crawls | 25 (7.5%) | yes | | | Web crawls 2023–2026 naming an API family | 332 web crawls | 24 (7.2%) | yes | |
| | Web crawls 2024–2026 naming an API family | 235 web crawls | **19 (8.1%)** | yes | | | Web crawls 2024–2026 naming an API family | 235 web crawls | **18 (7.7%)** | yes | |
| | Web crawls 2025–2026 naming an API family | 153 web crawls | 12 (7.8%) | yes | | | Web crawls 2025–2026 naming an API family | 153 web crawls | 11 (7.2%) | yes | |
| | Chrome/Chromium-stating web crawls 2023–2026 | 129 | 11 (8.5%) | no | | | Chrome/Chromium-stating web crawls 2023–2026 | 129 | 11 (8.5%) | no | |
| | Chrome/Chromium-stating web crawls 2024–2026 | 86 | **8 (9.3%)** | yes | | | Chrome/Chromium-stating web crawls 2024–2026 | 86 | **8 (9.3%)** | yes | |
| | ''%%/Aggregation Service/%%'' bare | 2 | A 2022 outage paper and a 2012 analytics paper | | | ''%%/Aggregation Service/%%'' bare | 2 | A 2022 outage paper and a 2012 analytics paper | |
| | ''%%/\bFLoC\b/%%'' before a year | 3 | "FLoC 2018" is the **Federated Logic Conference** | | | ''%%/\bFLoC\b/%%'' before a year | 3 | "FLoC 2018" is the **Federated Logic Conference** | |
| | | ''%%/\bFLEDGE\b/i%%'' | 2 | **"full-fledge crawling system"** — the hyphen is a word boundary, so ''%%\b%%'' does not save you | |
| | | ''%%/First[- ]Party Sets/i%%'' | 1 | **"the first party //sets// the cookies"** is a verb phrase | |
| | | ''%%/attribution reporting/i%%'' bare, lower case | 1 | Apple's **SKAdNetwork** "delays and anonymises attribution reporting to advertisers" | |
| |
| Two of these needed a structural fix rather than a narrower alternation: | Two of these needed a structural fix rather than a narrower alternation: |
| |
| * **The CHIPS family is the only case-sensitive family in the folder.** Lowercase ''chips'' is silicon, and a WPA3 paper that says "anti-clogging **cookie**" a few hundred characters from "chips" lands in the family if the acronym is matched case-insensitively — Dragonblood did exactly that. The report script therefore honours each family's own regex flags instead of forcing ''gi''. This removed 1 false positive and the family went 6 → 5. | * **The CHIPS family is the only case-sensitive family in the folder.** Lowercase ''chips'' is silicon, and a WPA3 paper that says "anti-clogging **cookie**" a few hundred characters from "chips" lands in the family if the acronym is matched case-insensitively — Dragonblood did exactly that. The report script therefore honours each family's own regex flags instead of forcing ''gi''. This removed 1 false positive and the family went 6 → 5. |
| * **Protected Audience** had to drop bare ''interest group'' entirely; the ad-tech phrasings (''ad interest group'', ''joinAdInterestGroup'', ''runAdAuction'', ''leaveAdInterestGroup'', ''interest-group bidding/auction'') are the whole family. This took the count from 234 to 11. | * **Protected Audience** had to drop bare ''interest group'' entirely; the ad-tech phrasings (''ad interest group'', ''joinAdInterestGroup'', ''runAdAuction'', ''leaveAdInterestGroup'', ''interest-group bidding/auction'') are the whole family. This took the count from 234 to 11 — and then to **8**, because ''%%\bFLEDGE\b%%'' with an ''i'' flag matches "a full-fledge crawling system" and "a full-fledge experience". The Protected Audience, Related Website Sets and Attribution Reporting families are now **all case-sensitive**, for the same reason CHIPS is. |
| | * **Attribution Reporting** is the subtlest of the three. Lowercase "attribution reporting" is ordinary ad-tech English, and a 2026 PETS paper used it of //Apple's// SKAdNetwork. But papers also write "Attribution reporting API" and "privacy sandbox attribution reporting api", so a purely case-sensitive rule loses two of the three true positives. The accepted rule is: the capitalised proper name in any position, **or** the phrase followed by "API" in any case. Family count 4 → **3**. |
| |
| **Residue that remains, stated rather than hidden:** the folded families still admit passing mentions. Of the 72 papers that name at least one family, **11** were judged to actually measure a Privacy Sandbox mechanism (the [[privacy:privacy_sandbox#What the corpus did measure|page's table]]), plus 3 more that supply CHIPS context without measuring the attribute. That is a precision of roughly **15%** for "names a family" as a proxy for "measures the thing", and it is why the page publishes the family counts as //reach// and the measured results as a hand-audited table, never as a percentage of the family counts. The per-family lists are printed in full in the report output below so that anyone can redo that audit and disagree with it. | **Residue that remains, stated rather than hidden.** Two kinds: |
| | |
| | * **False positives.** The folded families still admit passing mentions. Of the **67** papers that name at least one family, **11** were judged to actually measure a Privacy Sandbox mechanism — the [[privacy:privacy_sandbox#What the corpus did measure|page's table]] — plus one, ''bahrami2025_cookieguard'', that supplies CHIPS context without measuring the attribute. That is a precision of roughly **16%** for "names a family" as a proxy for "measures the thing", and it is why the page publishes the family counts as //reach// and the measured results as a hand-audited table, never as a percentage of the family counts. The per-family lists are printed in full in the report output below so that anyone can redo that audit and disagree with it. |
| | * **A known false negative, accepted deliberately.** Pinning ''FLEDGE'' to upper case also drops ''2024/USENIX/web-platform-threats-automated-detection-of-web-security-issues-with-wpt'', which lists ''fledge'' in lower case as one of the web-platform-tests directories it exercises. That is a genuine reference to the API. It is excluded because the only way to keep it is to re-admit "full-fledge", and one true positive is not worth two false ones. It is recorded here rather than silently lost. |
| |
| ===== Evidence quotes checked ===== | ===== Evidence quotes checked ===== |
| |
| == CDP events received (7) == | == CDP events received (7) == |
| Storage.interestGroupAuctionEventOccurred {"eventTime":1788280668.965319,"type":"started","uniqueAuctionId":"49E0BB9B63C9BD64E47335ECBF4728D0","auctionConfig":{"auctionSignals":{"pending":false,"value":null},"decisionLogicURL":"https://probe.example:8444/decide. | Storage.interestGroupAuctionEventOccurred {"eventTime":1788282880.844885,"type":"started","uniqueAuctionId":"BAA2639A8868AB941264DB3DB6CB5BED","auctionConfig":{"auctionSignals":{"pending":false,"value":null},"decisionLogicURL":"https://probe.example:8444/decide. |
| Storage.interestGroupAuctionNetworkRequestCreated {"type":"bidderJs","requestId":"96FF20B838C9A062BFC9B2D1EB2074F6","auctions":["49E0BB9B63C9BD64E47335ECBF4728D0"]} | Storage.interestGroupAuctionNetworkRequestCreated {"type":"bidderJs","requestId":"06A218F8B3F436C7E8D3F44A2D2806C3","auctions":["BAA2639A8868AB941264DB3DB6CB5BED"]} |
| Storage.interestGroupAuctionNetworkRequestCreated {"type":"sellerJs","requestId":"E700229B68625D5ED4A44112015F90EE","auctions":["49E0BB9B63C9BD64E47335ECBF4728D0"]} | Storage.interestGroupAuctionNetworkRequestCreated {"type":"sellerJs","requestId":"C09A1952CA56CC58940B85D959CCD3A3","auctions":["BAA2639A8868AB941264DB3DB6CB5BED"]} |
| Storage.sharedStorageAccessed {"accessTime":1788280669.021785,"scope":"window","method":"set","mainFrameId":"9EE9B30C8B76A15625E274C35BD01EC1","ownerOrigin":"https://probe.example:8444","ownerSite":"https://probe.example","params":{"key":"k","value": | Storage.sharedStorageAccessed {"accessTime":1788282880.902479,"scope":"window","method":"set","mainFrameId":"B3037C0FA13BA8CE8A07D1020A778F25","ownerOrigin":"https://probe.example:8444","ownerSite":"https://probe.example","params":{"key":"k","value": |
| Storage.sharedStorageAccessed {"accessTime":1788280669.02439,"scope":"window","method":"addModule","mainFrameId":"9EE9B30C8B76A15625E274C35BD01EC1","ownerOrigin":"https://probe.example:8444","ownerSite":"https://probe.example","params":{"scriptSource | Storage.sharedStorageAccessed {"accessTime":1788282880.904117,"scope":"window","method":"addModule","mainFrameId":"B3037C0FA13BA8CE8A07D1020A778F25","ownerOrigin":"https://probe.example:8444","ownerSite":"https://probe.example","params":{"scriptSourc |
| Storage.sharedStorageAccessed {"accessTime":1788280669.033277,"scope":"window","method":"run","mainFrameId":"9EE9B30C8B76A15625E274C35BD01EC1","ownerOrigin":"https://probe.example:8444","ownerSite":"https://probe.example","params":{"operationName":"p | Storage.sharedStorageAccessed {"accessTime":1788282880.912412,"scope":"window","method":"run","mainFrameId":"B3037C0FA13BA8CE8A07D1020A778F25","ownerOrigin":"https://probe.example:8444","ownerSite":"https://probe.example","params":{"operationName":"p |
| Storage.sharedStorageWorkletOperationExecutionFinished {"finishedTime":1788280669.033894,"executionTime":847,"method":"run","operationId":"0","workletTargetId":"383073F2489DBB30E78E8E91A9CF2429","mainFrameId":"9EE9B30C8B76A15625E274C35BD01EC1","ownerOrigin":"https://probe.ex | Storage.sharedStorageWorkletOperationExecutionFinished {"finishedTime":1788282880.913208,"executionTime":1050,"method":"run","operationId":"0","workletTargetId":"EBB22A0151158B1D33AB96EBCA57DF2F","mainFrameId":"B3037C0FA13BA8CE8A07D1020A778F25","ownerOrigin":"https://probe.e |
| </file> | </file> |
| |
| | ''privacysandbox.google.com/blog/update-on-plans-for-privacy-sandbox-technologies'' | The 2025-10-17 retirement of ten technologies | Fetched; the list and the CHIPS/FedCM/PST carve-out quoted **verbatim**; page footer reads "Last updated 2025-10-17 UTC" | **Used**, quoted | | | ''privacysandbox.google.com/blog/update-on-plans-for-privacy-sandbox-technologies'' | The 2025-10-17 retirement of ten technologies | Fetched; the list and the CHIPS/FedCM/PST carve-out quoted **verbatim**; page footer reads "Last updated 2025-10-17 UTC" | **Used**, quoted | |
| | ''privacysandbox.google.com/overview/status'' | Per-feature status: Continue to support / Deprecate and remove / Discontinue / Do not launch; CHIPS default in Chrome 114; Storage Access default in Chrome 119 | Fetched; page states "Last updated: August 14, 2026" | **Used** | | | ''privacysandbox.google.com/overview/status'' | Per-feature status: Continue to support / Deprecate and remove / Discontinue / Do not launch; CHIPS default in Chrome 114; Storage Access default in Chrome 119 | Fetched; page states "Last updated: August 14, 2026" | **Used** | |
| | ''privacysandbox.google.com/private-advertising/enrollment'' | "We will no longer accept new account creation and enrollment" | Fetched, quoted verbatim | Used in provenance; the page states the consequence rather than the quote | | | ''privacysandbox.google.com/private-advertising/enrollment'' | "We will no longer accept new account creation and enrollment" | Fetched, quoted verbatim | **Used, quoted on the content page.** A first draft only implied the consequence; a review pass pointed out the sentence was never actually written, so the quote and the ''%%--privacy-sandbox-enrollment-overrides%%'' workaround are now both on the page | |
| | ''chromestatus.com/api/v0/features/<id>'' × 19 | Ship milestones (M114/M115/M116/M108) and removal milestones (M152/M153/M155), all with status ''Proposed'' | Fetched individually through the JSON API | **Used** | | | ''chromestatus.com/api/v0/features/<id>'' × 19 | Ship milestones (M114/M115/M116/M108) and removal milestones (M152/M153/M155), all with status ''Proposed'' | Fetched individually through the JSON API | **Used** | |
| | ''chromiumdash.appspot.com/fetch_releases'' and ''fetch_milestone_schedule'' | Chrome stable = M152 since 2026-08-25; M153 stable_date 2026-09-08; M114 2023-05-30; M115 2023-07-18; M116 2023-08-15 | Fetched, parsed | **Used** | | | ''chromiumdash.appspot.com/fetch_releases'' and ''fetch_milestone_schedule'' | Chrome stable = M152 since 2026-08-25; M153 stable_date 2026-09-08; M114 2023-05-30; M115 2023-07-18; M116 2023-08-15 | Fetched, parsed | **Used** | |
| | ''gov.uk/cma-cases/investigation-into-googles-privacy-sandbox-browser-changes'' | Case opened 2021-01-07, **closed 2025-10-17** | Fetched; "Case state: Closed" read off the page | **Used** | | | ''gov.uk/cma-cases/investigation-into-googles-privacy-sandbox-browser-changes'' | Case opened 2021-01-07, **closed 2025-10-17** | Fetched; "Case state: Closed" read off the page | **Used** | |
| | ''github.com/GoogleChrome/related-website-sets'' → ''related_website_sets.JSON'' | **70 sets, 320 member domains, 66 (94.3%) with an associated site** | Fetched and counted in this run | **Used** | | | ''github.com/GoogleChrome/related-website-sets'' → ''related_website_sets.JSON'' | **70 sets, 320 member domains, 66 (94.3%) with an associated site** | Fetched and counted in this run | **Used** | |
| | | GitHub API on ''privacysandbox/attestation'' and ''patcg-individual-drafts/topics'' | Both ''archived: true''; last pushes **2026-01-22** and **2025-11-07** | Fetched 2026-09-01 after a review pass flagged that the page treated these as live feeds | **Used.** The archival of the topics repo is also the reason there is no taxonomy v3 | |
| | | ''ChromeDevTools/devtools-protocol'' commit history, bisected | The CDP ''Storage'' domain carried ''setAttributionReportingTracking'', ''setAttributionReportingLocalTestingMode'', ''sendPendingAttributionReports'' and four ''attributionReporting*'' events. Present in the descriptor at **2026-04-01**, absent at **2026-04-08** | Fetched five dated snapshots (2026-01-01, 02-01, 03-01, 03-15, 04-01) and four in April, resolving each date to a commit SHA through the GitHub commits API and pulling ''json/browser_protocol.json'' at that SHA | **Used.** This changed the page's advice: Attribution Reporting is measurable with first-class CDP events on a pre-April-2026 build, which the first draft denied | |
| | | ''chromiumdash.appspot.com/fetch_milestone_schedule'' for M146–M151 | Branch points: M147 2026-03-09, M148 **2026-04-06** | Fetched | **Used as an inference, labelled as one.** M147 should carry the ARA surface; M148 branched inside the removal window and is a coin flip. **Not tested** — this run had only Chromium 151 | |
| | | blink-dev, "Intent to Deprecate and Remove: Topics API" (thread ''_R85yctz4Rs'') | "Deprecate in M144 and then remove in M150"; "The Topics API was deprecated in Chrome-144 with a plan to remove it in Chrome-150. Currently the usage is 4.9% of page loads"; the phased M150 field-trial / M152 stub plan, quoted verbatim on the page | Fetched 2026-09-01. Thread opened 2025-11-07; the phased-plan message is dated 2026-06-12; later messages 2026-06-25 and 2026-07-08 | **Used.** A first draft asserted "the removal dates have already slipped twice" on a sub-agent's word; the primary source shows something more precise — deprecation landed at M144 **on schedule**, and it is the removal that moved M150 → M152 → M153. The page was rewritten to say that. It also turned the speculative field-trial hedge into a sourced fact | |
| | | Chrome Platform Status ''motivation'' fields for Topics, Shared Storage, Protected Audience, RWS, Attribution Reporting | Chrome's own usage telemetry: Topics 13% then 4.9% of page loads; Shared Storage ~11% of page loads; Protected Audience ''joinAdInterestGroup()'' down ~100x and ''runAdAuction()'' down >10x with "virtually none" of auctions having winners; RWS 71 sets and ''requestStorageAccessFor'' ~0.95% of page loads; ARA no figure | Fetched 2026-09-01 through the JSON API | **Used, with the caveat foregrounded.** These are unaudited vendor telemetry with no stated methodology and a //page load// unit. They are on the page because they are the only post-April-2025 adoption numbers in existence, and the page says exactly that. The 71-vs-70 RWS discrepancy is published rather than reconciled | |
| | | MDN header reference pages for ''Attribution-Reporting-Eligible'', ''Attribution-Reporting-Register-Source'', ''Attribution-Reporting-Register-Trigger'', ''Sec-Browsing-Topics'', ''Observe-Browsing-Topics'' | All five exist; ''Sec-Browsing-Topics'' "fails silently" and is deleted for an unenrolled caller | All five fetched, HTTP 200; the silent-failure sentence quoted verbatim from the ''Sec-Browsing-Topics'' page | **Used.** ''Sec-Shared-Storage-Writable'' was checked and returns 404 on MDN, so it is not on the page | |
| | GitHub API on ''GoogleChrome/related-website-sets'' and ''GoogleChrome/ip-protection'' | Both ''archived: true''; last pushes 2025-11-21 and 2025-11-03 | Fetched | **Used** | | | GitHub API on ''GoogleChrome/related-website-sets'' and ''GoogleChrome/ip-protection'' | Both ''archived: true''; last pushes 2025-11-21 and 2025-11-03 | Fetched | **Used** | |
| | ''github.com/privacysandbox/attestation'' → ''enrollment_report.csv'' | **326 rows**; Topics 249, Protected Audience 237, Attribution Reporting 228, Shared Storage 205, Private Aggregation 193; 25 rows with no Chrome API | Fetched and counted in this run | **Used** | | | ''github.com/privacysandbox/attestation'' → ''enrollment_report.csv'' | **326 rows**; Topics 249, Protected Audience 237, Attribution Reporting 228, Shared Storage 205, Private Aggregation 193; 25 rows with no Chrome API | Fetched and counted in this run | **Used** | |
| ===== What the corpus does not establish ===== | ===== What the corpus does not establish ===== |
| |
| * **Nothing about Attribution Reporting in deployment.** 4 of 5,869 papers name it, none instrument it. | * **Nothing about Attribution Reporting in deployment.** 3 of 5,869 papers name it, none instrument it. |
| * **No adoption measurement after February 2025.** The two crawl-based papers are from 2023 and February 2025; the retirement was announced in October 2025. Chrome's own removal notes claim usage collapsed; this corpus cannot confirm or refute that. | * **No //independent// adoption measurement after February 2025.** The two crawl-based papers are from 2023 and February 2025; the retirement was announced in October 2025. Chrome's own removal notes claim usage collapsed and give numbers, now quoted on the page; this corpus cannot confirm or refute them, and the party that produced them is the party being measured. |
| * **No CHIPS adoption study inside the seven venues.** ''rasaii2025_crumbs'' gives a 1.3% figure as a side measurement; the dedicated study is a PAM 2025 paper outside the corpus. | * **No CHIPS adoption study inside the seven venues.** ''rasaii2025_crumbs'' gives a 1.3% figure as a side measurement; the dedicated study is a PAM 2025 paper outside the corpus. |
| * **Regional gating of the ads APIs.** Both Google availability pages 404. FLoC's 2021 trial excluded the EEA, which makes a DMA-driven gate on the successors plausible, but plausible is not measured. Published on the page as an explicit unknown with an instruction to test it rather than assume. | * **Regional gating of the ads APIs.** Both Google availability pages 404. A DMA-driven gate is plausible but plausible is not measured. A first draft asserted that FLoC's 2021 origin trial excluded the EEA; that came from a sub-agent citing Wikipedia, no primary source for it could be found in this run, and it was removed from the page. What ''berke2022_privacy'' does say, and what the page now carries instead: the trial ran Chrome 89 to 91, spring to autumn 2021, for users with at least seven domains in their history, with //k// = 2000 giving 33,872 cohorts of which 2.3% were deemed sensitive. Published on the page as an explicit unknown with an instruction to test it rather than assume. |
| * **Whether ''chrome://*-internals'' pages are still reachable in Chrome 152 stable.** Not tested: this container has no Chrome stable, only Playwright's Chromium 151. | * **Whether ''chrome://*-internals'' pages are still reachable in Chrome 152 stable.** Not tested: this container has no Chrome stable, only Playwright's Chromium 151. |
| * **Whether the CHIPS default-on milestone is M114.** Chrome Platform Status and Google's status page agree on M114 for CHIPS but **disagree** for the Storage Access API (M115 versus "Chrome 119 and higher"). The page carries both and tells the reader to test if it matters. | * **Whether the CHIPS default-on milestone is M114.** Chrome Platform Status and Google's status page agree on M114 for CHIPS but **disagree** for the Storage Access API (M115 versus "Chrome 119 and higher"). The page carries both and tells the reader to test if it matters. |
| * **The retirement is the page's lead, not a footnote.** A reader who takes only one sentence away should take "these are being removed and your browser version is the measurement". The alternative — leading with the API descriptions — would have reproduced the 2022 roadmap, which is the failure mode the task spec warns about. | * **The retirement is the page's lead, not a footnote.** A reader who takes only one sentence away should take "these are being removed and your browser version is the measurement". The alternative — leading with the API descriptions — would have reproduced the 2022 roadmap, which is the failure mode the task spec warns about. |
| * **Removal milestones are reported as //proposed//, not as fact.** They are the ''desktop'' milestone on a Chrome Platform Status entry whose status string is ''Proposed''. Two of them (M144, M150) had already slipped once before landing on M152/M153. The page dates them and does not promise them. | * **Removal milestones are reported as //proposed//, not as fact.** They are the ''desktop'' milestone on a Chrome Platform Status entry whose status string is ''Proposed''. Two of them (M144, M150) had already slipped once before landing on M152/M153. The page dates them and does not promise them. |
| * **Published the "8.1% of recent web crawls" silence figure** even though it is a keyword proxy, because the direction is unambiguous at that magnitude and the confound (a paper can measure the platform without naming an API) can only inflate the //true// figure slightly, not reverse it. The page names the proxy. | * **Published the "7.7% of recent web crawls" silence figure** even though it is a keyword proxy, because the direction is unambiguous at that magnitude and the confound (a paper can measure the platform without naming an API) can only inflate the //true// figure slightly, not reverse it. The page names the proxy, and now also names the opposite confound a review pass raised: the denominator includes crawls with no reason to touch an ads API, so the figure is an upper bound on non-engagement rather than a defect rate. |
| * **Did not publish the "Privacy Budget" or "k-anonymity" counts** at all: both regexes are dominated by generic differential-privacy usage and no qualified version was found that was worth the space. | * **Did not publish the "Privacy Budget" or "k-anonymity" counts** at all: both regexes are dominated by generic differential-privacy usage and no qualified version was found that was worth the space. |
| * **Did not publish a figure from the PAM 2025 CHIPS paper.** It is outside the corpus, Springer would not serve its abstract to this run, and nobody here read it. | * **Did not publish a figure from the PAM 2025 CHIPS paper.** It is outside the corpus, Springer would not serve its abstract to this run, and nobody here read it. |
| Generated with ''scripts/bibgen.mjs''. Two needed hand-completion because PETS and USENIX index records carry no authors: the PoPETs authors came from ''petsymposium.org/popets/2023/popets-2023-0101.php'' and the USENIX authors from the venue landing page, both fetched with a browser User-Agent. Reused without change: ''jha2023_topics'', ''beugin2024_interest'', ''ali2023_navigating'', ''lin2024_browsing'', ''rasaii2025_crumbs'', ''bahrami2025_cookieguard'', ''kancherla2025_least''. | Generated with ''scripts/bibgen.mjs''. Two needed hand-completion because PETS and USENIX index records carry no authors: the PoPETs authors came from ''petsymposium.org/popets/2023/popets-2023-0101.php'' and the USENIX authors from the venue landing page, both fetched with a browser User-Agent. Reused without change: ''jha2023_topics'', ''beugin2024_interest'', ''ali2023_navigating'', ''lin2024_browsing'', ''rasaii2025_crumbs'', ''bahrami2025_cookieguard'', ''kancherla2025_least''. |
| |
| After saving, ''literature:bibliography'' and the page were purged (''?purge=true'') and the rendered DOM checked: **58 ''bibtex_citekey'' markers, 13 rendered references for 13 distinct keys, zero unresolved citation markers, 10 tables, 22 headings, 4 WRAP boxes.** | After each save, ''literature:bibliography'' and the page were purged (''?purge=true'') and the rendered DOM re-checked, counting only inside the ''%%<!-- wikipage start -->%%'' … ''%%<!-- wikipage stop -->%%'' markers so that the theme's own chrome is not counted. |
| | |
| | Counts below are for [[privacy:privacy_sandbox]] only. This page's own heading and table counts are deliberately not asserted, because every edit to this paragraph changes them and a self-referential count can never be right for long; what //is// asserted about this page is that it renders **7** downloadable file blocks and **zero** red links. |
| | |
| | ^ Count ^ [[privacy:privacy_sandbox]] ^ |
| | | citation markers in the wiki source | **33** | |
| | | distinct citekeys among them | **13** | |
| | | ''bibtex_citekey'' spans in the rendered DOM | **66** | |
| | | ''%%<dt>%%'' entries in the rendered ''bibtex_references'' list | **13** | |
| | | ''%%<table>%%'' in the rendered body | **12** | |
| | | ''%%<h1>%%''–''%%<h4>%%'' in the rendered body | **23** | |
| | | ''%%<WRAP>%%'' boxes | **5** | |
| | | ''wikilink2'' (red links) | **0** | |
| | | downloadable ''%%<file>%%'' blocks | **1** | |
| | |
| | **Read the first three rows together, because two reviewers independently got them wrong and then disagreed with each other.** The bibtex plugin emits **two** ''bibtex_citekey'' spans per source marker — an anchor and a link — so 33 markers render as 66 spans, and neither number is the reference count: 33 markers over 13 distinct keys give 13 entries in the reference list. The rendered heading count is one higher than the source heading count because ''%%~~DISCUSSION~~%%'' contributes its own heading. And a source-side count is not a substitute for a rendered one on either page: the embedded script output here contains ''%%==%%''- and ''%%##%%''-prefixed lines that a naive source-side heading regex picks up as headings (44 against a real 22). |
| | |
| | Two earlier versions of this paragraph were wrong — first 58/22, then 60/21/4, both counted with an unscoped grep and both before the last round of edits. A review pass could not reproduce either. It is recorded rather than quietly corrected because a provenance page whose own self-check does not reproduce is worse than one that has none, and because getting a trivial count wrong twice is the honest illustration of why the rest of the page is scripted. |
| |
| ===== Folding script ===== | ===== Folding script ===== |
| label: 'Protected Audience', | label: 'Protected Audience', |
| also: 'FLEDGE, TURTLEDOVE', | also: 'FLEDGE, TURTLEDOVE', |
| // "interest group" bare matched 234 papers (political science, federated | // NOT case-insensitive. `/\bFLEDGE\b/i` matches "full-fledge crawling |
| // learning, recommender systems). Only the ad-tech phrasing counts. | // system" and "a full-fledge experience" — the hyphen is a word boundary, |
| re: /Protected\s+Audience|\bFLEDGE\b|TURTLEDOVE|joinAdInterestGroup|runAdAuction|leaveAdInterestGroup|ad\s+interest\s+group|interest[- ]group\s+(?:bidding|auction)/i, | // so \b does not help. Two papers (de-Kodi WWW 2020, Android SmartTVs |
| | // USENIX 2021) were in this family until the acronyms were pinned to |
| | // upper case. Found by a review pass on 2026-09-01, not by the author. |
| | // "interest group" bare also matched 234 papers (political science, |
| | // federated learning, recommender systems); only ad-tech phrasing counts. |
| | re: /[Pp]rotected [Aa]udience|FLEDGE|TURTLEDOVE|joinAdInterestGroup|runAdAuction|leaveAdInterestGroup|ad interest group|interest[- ]group (?:bidding|auction)/, |
| }, | }, |
| { | { |
| label: 'Attribution Reporting API', | label: 'Attribution Reporting API', |
| also: 'Conversion Measurement API', | also: 'Conversion Measurement API', |
| re: /Attribution\s+Reporting|Conversion\s+Measurement\s+API|attributionsrc|aggregatable\s+attribution/i, | // The bare lowercase noun phrase is generic ad-tech English: a 2026 PETS |
| | // paper used it of *Apple's* SKAdNetwork ("delays and anonymises |
| | // attribution reporting to advertisers"). Two forms are accepted and |
| | // nothing else: the capitalised proper name, in any position, and the |
| | // phrase followed by "API" in any case (papers write "Attribution |
| | // reporting API" and "privacy sandbox attribution reporting api"). |
| | re: /Attribution Reporting|[Aa]ttribution[- ][Rr]eporting [Aa][Pp][Ii]|Conversion Measurement API|attributionsrc|attributionSrc|aggregatable attribution/, |
| }, | }, |
| { | { |
| label: 'Related Website Sets', | label: 'Related Website Sets', |
| also: 'First-Party Sets', | also: 'First-Party Sets', |
| re: /Related\s+Website\s+Sets?|First[- ]Party\s+Sets/i, | // NOT case-insensitive. Lowercase "the first party sets the cookies" is a |
| | // verb phrase, and it put a 2021 WWW cookie-swapping paper in this family. |
| | re: /Related Website Sets?|First[- ]Party Sets/, |
| }, | }, |
| { | { |
| ['/\\bFLoC\\b/ before a year', 3, '"FLoC 2018" is the Federated Logic Conference'], | ['/\\bFLoC\\b/ before a year', 3, '"FLoC 2018" is the Federated Logic Conference'], |
| ['/Aggregation Service/ (bare)', 2, 'a 2022 outage paper and a 2012 analytics paper, neither about the Sandbox'], | ['/Aggregation Service/ (bare)', 2, 'a 2022 outage paper and a 2012 analytics paper, neither about the Sandbox'], |
| | ['/\\bFLEDGE\\b/i', 2, '"full-fledge crawling system" — the hyphen is a word boundary'], |
| | ['/First[- ]Party Sets/i', 1, '"the first party sets the cookies" is a verb phrase'], |
| | ['/attribution reporting/i (bare, lowercase)', 1, "Apple's SKAdNetwork \"anonymises attribution reporting\""], |
| ]; | ]; |
| |
| |
| papers naming "Privacy Sandbox" at all : 43 (0.7% of 5869) | papers naming "Privacy Sandbox" at all : 43 (0.7% of 5869) |
| papers naming >=1 API family (folded) : 72 (1.2%) | papers naming >=1 API family (folded) : 67 (1.1%) |
| papers naming "Privacy Sandbox" >=5 times : 9 (0.2%) | papers naming "Privacy Sandbox" >=5 times : 9 (0.2%) |
| |
| ------------------------------------------------ ---------------------------------- ------ ----- | ------------------------------------------------ ---------------------------------- ------ ----- |
| Topics API FLoC (predecessor, withdrawn 2022) 22 0.4% | Topics API FLoC (predecessor, withdrawn 2022) 22 0.4% |
| Protected Audience FLEDGE, TURTLEDOVE 11 0.2% | |
| User-Agent Client Hints / UA reduction - 10 0.2% | User-Agent Client Hints / UA reduction - 10 0.2% |
| | Protected Audience FLEDGE, TURTLEDOVE 8 0.1% |
| Privacy Sandbox on Android SDK Runtime 7 0.1% | Privacy Sandbox on Android SDK Runtime 7 0.1% |
| Related Website Sets First-Party Sets 6 0.1% | |
| CHIPS (partitioned cookies) the Partitioned cookie attribute 5 0.1% | CHIPS (partitioned cookies) the Partitioned cookie attribute 5 0.1% |
| Private State Tokens Trust Tokens 5 0.1% | Private State Tokens Trust Tokens 5 0.1% |
| Attribution Reporting API Conversion Measurement API 4 0.1% | |
| Fenced Frames - 4 0.1% | Fenced Frames - 4 0.1% |
| | Related Website Sets First-Party Sets 4 0.1% |
| | Attribution Reporting API Conversion Measurement API 3 0.1% |
| Shared Storage API - 3 0.1% | Shared Storage API - 3 0.1% |
| Private Aggregation / Aggregation Service - 2 0.0% | Private Aggregation / Aggregation Service - 2 0.0% |
| 1x 2026 NDSS are-your-sites-truly-isolated-automatically-detecting-logic-bugs-in-site-isolation-implementations | 1x 2026 NDSS are-your-sites-truly-isolated-automatically-detecting-logic-bugs-in-site-isolation-implementations |
| |
| -- Protected Audience (11 papers) -- | -- Protected Audience (8 papers) -- |
| 170x 2024 USENIX fledging-will-continue-until-privacy-improves-empirical-analysis-of-googles-priv | 150x 2024 USENIX fledging-will-continue-until-privacy-improves-empirical-analysis-of-googles-priv |
| 39x 2023 NDSS navigating-murky-waters-automated-browser-feature-testing-for-uncovering-tracking-vectors | 26x 2023 NDSS navigating-murky-waters-automated-browser-feature-testing-for-uncovering-tracking-vectors |
| 11x 2025 CCS exploiting-the-shared-storage-api | 11x 2025 CCS exploiting-the-shared-storage-api |
| 9x 2024 CCS the-privacy-utility-trade-off-in-the-topics-api | 7x 2024 CCS the-privacy-utility-trade-off-in-the-topics-api |
| 8x 2024 PETS interest-disclosing-mechanisms-for-advertising-are-privacy-exposing-not-preservi | 5x 2024 PETS interest-disclosing-mechanisms-for-advertising-are-privacy-exposing-not-preservi |
| 3x 2022 IMC what-factors-affect-targeting-and-bids-in-online-advertising-a-field-measurement | 2x 2022 IMC what-factors-affect-targeting-and-bids-in-online-advertising-a-field-measurement |
| 1x 2020 WWW de-kodi-understanding-the-kodi-ecosystem | |
| 1x 2021 USENIX android-smarttvs-vulnerability-discovery-via-log-guided-fuzzing | |
| 1x 2024 USENIX web-platform-threats-automated-detection-of-web-security-issues-with-wpt | |
| 1x 2025 NDSS you-can-rand-but-you-cant-hide-a-holistic-security-analysis-of-google-fuchsias-and-gvisors-network-stack | 1x 2025 NDSS you-can-rand-but-you-cant-hide-a-holistic-security-analysis-of-google-fuchsias-and-gvisors-network-stack |
| 1x 2026 PETS the-pet-paradox-how-amazon-instrumentalises-pets-in-sidewalk-to-entrench-its-inf | 1x 2026 PETS the-pet-paradox-how-amazon-instrumentalises-pets-in-sidewalk-to-entrench-its-inf |
| |
| -- Attribution Reporting API (4 papers) -- | -- Attribution Reporting API (3 papers) -- |
| 2x 2024 PETS interest-disclosing-mechanisms-for-advertising-are-privacy-exposing-not-preservi | 2x 2024 PETS interest-disclosing-mechanisms-for-advertising-are-privacy-exposing-not-preservi |
| 2x 2025 IMC a-permissions-odyssey-a-systematic-study-of-browser-permissions-on-modern-websit | 2x 2025 IMC a-permissions-odyssey-a-systematic-study-of-browser-permissions-on-modern-websit |
| 1x 2026 NDSS snpeek-side-channel-analysis-for-privacy-applications-on-confidential-vms | 1x 2026 NDSS snpeek-side-channel-analysis-for-privacy-applications-on-confidential-vms |
| 1x 2026 PETS the-pet-paradox-how-amazon-instrumentalises-pets-in-sidewalk-to-entrench-its-inf | |
| |
| -- Private Aggregation / Aggregation Service (2 papers) -- | -- Private Aggregation / Aggregation Service (2 papers) -- |
| 2x 2025 PETS tracking-without-borders-studying-the-role-of-webviews-in-bridging-mobile-and-we | 2x 2025 PETS tracking-without-borders-studying-the-role-of-webviews-in-bridging-mobile-and-we |
| |
| -- Related Website Sets (6 papers) -- | -- Related Website Sets (4 papers) -- |
| 64x 2024 IMC a-first-look-at-related-website-sets | 63x 2024 IMC a-first-look-at-related-website-sets |
| 2x 2021 NDSS whos-hosting-the-block-party-studying-third-party-blockage-of-csp-and-sri | |
| 2x 2022 PETS who-knows-i-like-jelly-beans-an-investigation-into-search-privacy | 2x 2022 PETS who-knows-i-like-jelly-beans-an-investigation-into-search-privacy |
| 2x 2024 PETS interest-disclosing-mechanisms-for-advertising-are-privacy-exposing-not-preservi | 2x 2024 PETS interest-disclosing-mechanisms-for-advertising-are-privacy-exposing-not-preservi |
| 1x 2021 WWW cookie-swap-party-abusing-first-party-cookies-for-web-tracking | 1x 2021 NDSS whos-hosting-the-block-party-studying-third-party-blockage-of-csp-and-sri |
| 1x 2025 PETS measuring-the-accuracy-and-effectiveness-of-pii-removal-services | |
| |
| -- Private State Tokens (5 papers) -- | -- Private State Tokens (5 papers) -- |
| 2018 254 0 0.0% 0 0.0% | 2018 254 0 0.0% 0 0.0% |
| 2019 402 0 0.0% 0 0.0% | 2019 402 0 0.0% 0 0.0% |
| 2020 402 1 0.2% 2 0.5% | 2020 402 1 0.2% 1 0.2% |
| 2021 380 1 0.3% 4 1.1% | 2021 380 1 0.3% 2 0.5% |
| 2022 546 4 0.7% 7 1.3% | 2022 546 4 0.7% 7 1.3% |
| 2023 720 7 1.0% 12 1.7% | 2023 720 7 1.0% 12 1.7% |
| 2024 701 13 1.9% 18 2.6% | 2024 701 13 1.9% 17 2.4% |
| 2025* 770 13 1.7% 22 2.9% | 2025* 770 13 1.7% 21 2.7% |
| 2026* 415 4 1.0% 7 1.7% | 2026* 415 4 1.0% 7 1.7% |
| * 2025-2026 provisional (CCS/IMC 2026 not held; IEEE S&P/WWW 2026 under-selected). | * 2025-2026 provisional (CCS/IMC 2026 not held; IEEE S&P/WWW 2026 under-selected). |
| /\bFLoC\b/ before a year 3 "FLoC 2018" is the Federated Logic Conference | /\bFLoC\b/ before a year 3 "FLoC 2018" is the Federated Logic Conference |
| /Aggregation Service/ (bare) 2 a 2022 outage paper and a 2012 analytics paper, neither about the Sandbox | /Aggregation Service/ (bare) 2 a 2022 outage paper and a 2012 analytics paper, neither about the Sandbox |
| | /\bFLEDGE\b/i 2 "full-fledge crawling system" — the hyphen is a word boundary |
| | /First[- ]Party Sets/i 1 "the first party sets the cookies" is a verb phrase |
| | /attribution reporting/i (bare, lowercase) 1 Apple's SKAdNetwork "anonymises attribution reporting" |
| |
| ## 5. The measuring papers: population, instrument, and measured result | ## 5. The measuring papers: population, instrument, and measured result |
| |
| web crawls published 2023-2026: 332 | web crawls published 2023-2026: 332 |
| of those, naming >=1 Privacy Sandbox API family: 25 (7.5%) | of those, naming >=1 Privacy Sandbox API family: 24 (7.2%) |
| web crawls published 2024-2026: 235 | web crawls published 2024-2026: 235 |
| of those, naming >=1 Privacy Sandbox API family: 19 (8.1%) | of those, naming >=1 Privacy Sandbox API family: 18 (7.7%) |
| web crawls published 2025-2026*: 153 | web crawls published 2025-2026*: 153 |
| of those, naming >=1 Privacy Sandbox API family: 12 (7.8%) | of those, naming >=1 Privacy Sandbox API family: 11 (7.2%) |
| |
| Population "web crawl": crawlConfig != null OR studyTypes contains | Population "web crawl": crawlConfig != null OR studyTypes contains |
| ===== Review log ===== | ===== Review log ===== |
| |
| To be completed after the review passes. | Three focused ''sonnet'' passes on the published first draft, run in parallel, each told explicitly that the author's context may not be exhaustive and each handed the page text, the report script, its output and these notes. Findings applied below; a generic ''fable'' pass follows. |
| | |
| | ==== sonnet — figures versus script ==== |
| | |
| | ^ Finding ^ Disposition ^ |
| | | **By-year table: 2020 says 4 and 2022 says 8 in the "any API family" column; the script says 2 and 7.** | **Accepted, fixed.** Diagnosed: the year table was copied from a run made //before// the folding regexes were narrowed, and never refreshed. This is exactly the carry-over defect the task spec warns about, committed inside a single sitting. The whole table was regenerated from the current output | |
| | | ''%%/\bFLEDGE\b/i%%'' **matches "full-fledge crawling system"** in de-Kodi (WWW 2020) and "a full-fledge experience" in Android SmartTVs (USENIX 2021) | **Accepted, fixed.** Verified both by hand. The Protected Audience family is now case-sensitive; count 11 → 8 | |
| | | ''%%/First[- ]Party Sets/i%%'' **matches "the first party //sets// the cookies"** in Cookie Swap Party (WWW 2021) | **Accepted, fixed.** Verified. RWS family is now case-sensitive; count 6 → 4 (the same fix also dropped a second borderline match) | |
| | | **Bare "attribution reporting" matches Apple's SKAdNetwork** in the 2026 PETS PET-paradox paper, so the page's "four passing mentions" is three | **Accepted, fixed.** Verified. The naive case-sensitive fix over-corrected to **zero** — papers write "Attribution reporting API" and "privacy sandbox attribution reporting api" — so the accepted rule is capitalised-proper-name OR phrase-plus-"API". Count 4 → **3**, and both places on the page that said "four" now say "three" | |
| | | **The published ''ps_cdp_probe.mjs'' snippet produces zero events when run as printed**, contradicting the page's "verified end to end" claim; the real script uses a local mock HTTPS origin the snippet omits | **Accepted, fixed, and the most useful finding of the three passes.** The block now contains ''sandbox/ps_cdp_probe.mjs'' in full — mock server, bidding script, decision script, worklet and all — and the surrounding prose says what its real output was and what happens if you point the listeners at a site you do not control. The reviewer also mutation-tested the real script (removing ''setSharedStorageTracking'' drops the event count from 7 to 3), which is quoted on the page | |
| | | Provenance says "3 more" CHIPS-context papers; the content page names two, and the third has no CHIPS content of its own | **Accepted, fixed.** Now one, and it is named | |
| | | Family table not sorted descending by count | **Accepted, fixed** (had already been caught independently) | |
| | | Rendered heading/citekey counts in this log are close but do not reproduce exactly | **Accepted, fixed.** Recounted from the rendered DOM after the final save; the numbers in [[#Bibliography]] are the recount | |
| | |
| | **Not found by this pass, and worth recording:** it verified the silence table against the pre-fix script and reported it correct, which it was — but the four fold fixes then moved it (25/19/12 → 24/18/11). The page was re-derived from the post-fix run, not patched. |
| | |
| | ==== sonnet — citations and quotes ==== |
| | |
| | ^ Finding ^ Disposition ^ |
| | | ''kancherla2025_least'' **does not support the claim it is cited for.** The page said it and ''bahrami2025_cookieguard'' "both note that Chrome's partitioning is opt-in per cookie while Firefox and Safari partition by default". "Safari" and "opt-in" appear **zero** times in that paper; "CHIPS" appears once, in the reference list | **Accepted, fixed.** Verified. The sentence now attributes the claim to ''bahrami2025_cookieguard'' alone, quotes its actual wording, and says plainly that an earlier draft attached it to the wrong paper | |
| | | Five **pre-existing** same-paper-different-key duplicates elsewhere in ''literature:bibliography'' (''lerner2016internet''/''lerner2016_internet'', ''bouhoula2024automated''/''bouhoula2024_automated'', ''fouad2022my''/''fouad2022_cookie'', ''bottger2025_regional''/''boettger2025_regional'', ''ahmad2026_ipfp''/''ahmad2026_more'') | **Noted, not acted on.** None involves this page's 13 keys and none was introduced by this run. Left for whoever owns the bibliography; recorded here so the next run does not rediscover it as new | |
| | |
| | Everything else passed: 13 keys resolve, 724 keys unique, the six new entries match Crossref on authors, order, title, year, venue and DOI, ~34 quantitative claims traced to the sentence in ''paper.cols.txt'', all 8 footnotes verbatim against live sources, and the claim that ''rasaii2025_crumbs'' cites the PAM CHIPS paper with a broken DOI independently confirmed (''10.1007/978-3-031-55528-2_1'' 404s; the correct one is ''10.1007/978-3-031-85960-1_8''). |
| | |
| | ==== sonnet — external currency ==== |
| | |
| | ^ Finding ^ Disposition ^ |
| | | Nothing wrong. ~65 external claims independently re-fetched; **zero** out of date | **No change.** Confirmed specifically: M153 has **not** shipped (''stable_date'' 2026-09-08, ''stable_cut'' is today), no removal entry has moved off ''Proposed'', and the "there is a window" framing is still correct as written | |
| | | A summarising fetch tool mis-read the status page's Discontinue / Do-not-launch groupings; the raw HTML table matches the page exactly | **Noted.** Recorded as a warning to the next reviewer: on that page, parse the table, do not summarise it | |
| | | ''bugzilla.mozilla.org/show_bug.cgi?id=1979093'' returns HTTP 400 to a bare ''HEAD'' but 200 to a ''GET'' | **Noted.** Not a dead link; recorded so a future link-checker run does not report it as one | |
| | |
| | Also confirmed by this pass and not previously checked here: Playwright 1.62.1 is npm's current ''latest'' (2026-07-30) and bundles exactly Chromium 151.0.7922.34; Playwright's ''chromiumSwitches.ts'' on ''main'' disables ''ThirdPartyStoragePartitioning'' and no ads-API feature; the W3C Attribution Level 1 Working Draft is dated 2026-08-28; ''taxonomy_v3.md'' returns 404. |
| | |
| | ==== fable — generic ==== |
| | |
| | Run after the three focused passes and their fixes, with no checklist. It found more than the other three combined, and two of its findings were substantive enough to change what the page tells a reader to do. |
| | |
| | ^ Finding ^ Disposition ^ |
| | | **"Topics and Attribution Reporting have no CDP surface at all, in any Chromium version checked" is misleading, and it misdirects the page's own headline call to action.** "Any version checked" was two versions. ARA had a full CDP ''Storage'' surface until it was removed from the protocol in April 2026 | **Accepted, fixed, and this was the most valuable finding of the whole review.** Verified independently by bisecting the ''devtools-protocol'' history (present 2026-04-01, absent 2026-04-08). The page now carries a box saying the gap is closable with first-class instrumentation on a pre-April-2026 build, with a one-line check for whether a given binary has it. The CDP table has a new row. The two dead ARA listeners in the published script now carry a comment saying why they are there | |
| | | **HTTP headers are missing entirely as an observation surface**, and they are arguably the //primary// one for Attribution Reporting and Topics | **Accepted, fixed.** New subsection with all five headers, verified against MDN. Added to the "What to Report" list | |
| | | **Wrapping the ''attributionSrc'' IDL setter misses server-rendered ''%%attributionsrc%%'' content attributes**, because the parser does not invoke IDL setters | **Accepted, fixed.** The page now says not to do it and gives three alternatives. This was a genuine instrument bug in advice the page was giving | |
| | | ''privacysandbox/attestation'' **and** ''patcg-individual-drafts/topics'' **are also archived**; the page marked only the RWS repo, and said "two of the three" artefacts are frozen | **Accepted, fixed.** Verified through the GitHub API: archived, last pushes 2026-01-22 and 2025-11-07. All three rows now carry the archive date, and the "two of the three" sentence is rewritten — with the distinction that the ''.dat'' inside a Chromium install still moves with the component updater | |
| | | **The enrollment-closure "consequence" this log claimed the page stated was never actually written on the page** | **Accepted, fixed.** The quote and the ''%%--privacy-sandbox-enrollment-overrides%%'' workaround are now both on the content page. This log's own claim has been corrected | |
| | | Two stale figures in **this log's prose**: "4 of 5,869 papers name Attribution Reporting" and "the 8.1% silence figure", both pre-fold-fix | **Accepted, fixed.** This is the known failure mode where a correction reaches the page but not the log; recording that it happened here too | |
| | | **The removal-date slip history is only in this log, not where the reader decides.** "Measured in days" is stated as if M153 were firm | **Accepted, fixed.** The slip history (M144 → M150 → M152/M153/M155) is now a bullet in the top box, and "days" is hedged | |
| | | **"They have not been removed yet" rests on a Chromium 151 probe while stable is M152** | **Accepted, fixed.** The box now says so in one clause | |
| | | **Missing hedge: field trials.** A code-removal milestone is the //latest// end of the window; Chrome ramps features down server-side first, and an automation Chromium has no variations seed | **Accepted, added**, flagged as not established for these specific features | |
| | | **The measured-results table has no written inclusion rule**, and two of its rows are not Privacy Sandbox measurements | **Accepted, fixed.** The rule is now stated above the table and the two exceptions are named and justified. The precision sentence in [[#Folding and residue]] counts the same 11 | |
| | | **Missing: user-side gating.** Real users hold heterogeneous "Ad privacy" toggle states; a crawler profile is one | **Accepted, added** to the pitfalls list | |
| | | "A dozen papers … over sixteen years", after showing 43/67/9 and an 11-row table; and self-referential prose about its own placement; and "the re-identification numbers everyone cites" in a page that proves almost nobody cites them | **All three accepted, fixed** | |
| | | The silence figure's denominator includes crawls with no reason to touch an ads API | **Accepted.** The defence was in this log only; half a sentence of it is now on the content page, framing the figure as an upper bound on non-engagement | |
| | | Bounce-tracking dating differs in phrasing from [[privacy:browser_storage]] | **Accepted, fixed** by naming both the milestone and the later default-on, and cross-linking | |
| | | The provenance page is honest in tone; its overclaims are the three concrete ones above | **Noted.** All three fixed | |
| | |
| | **Rejected: nothing.** Every finding from this pass was accepted. That is unusual and is recorded as such: it is evidence the generic slot earns its place, and also that the three focused passes, by having checklists, all missed the same class of defect — advice that is well-sourced and wrong. |
| | |
| | ==== Work done after the generic pass, and the second round ==== |
| | |
| | Verifying the generic pass's "removal dates have already slipped twice" finding against the blink-dev thread turned up more than the finding itself, and the content page gained a section that no reviewer had seen: **"The only post-2025 adoption numbers that exist are Chrome's own"**, five rows of Chrome Platform Status ''motivation'' telemetry. It is recorded here rather than folded silently into the page because it postdates every review, and because it is exactly the kind of late addition that escapes an audit trail. Its sources are in [[#External sources, verified and rejected]]; two subsequent re-review passes checked all five quotes verbatim and found no error in them. |
| | |
| | Two ''sonnet'' re-review passes were then run over the edited pages, one on figures and one on currency and citations, both told the earlier fixes might themselves be wrong. |
| | |
| | ^ Finding ^ Disposition ^ |
| | | **The DOM self-check numbers in [[#Bibliography]] are still wrong** — "60 citation markers, 10 tables, 21 headings, 4 WRAP boxes" against actual 33 source markers / 12 tables / 23 headings / 5 boxes. Found independently by both re-reviewers, who then disagreed with each other (33 vs 60 markers, 21 vs 22 headings) | **Accepted, fixed, and the disagreement diagnosed.** The whole paragraph is now a table with the counting method stated, and it explains the trap that caught both of them: the plugin emits two spans per source marker, and ''%%~~DISCUSSION~~%%'' adds a heading. Third time | |
| | | **"Every call returned a benign empty value rather than throwing" is contradicted by the page's own committed probe output** — ''sharedStorage.worklet.addModule()'' throws ''OperationError'' in all four configurations, and the illustrative code box on the page had silently dropped that line | **Accepted, fixed.** The eighth call is back in the box, with the reason (the probe server returns ''text/html'' for every path, so the worklet module fails a MIME check — an artefact of the probe, not of the API) and a note that it was trimmed for one revision | |
| | | **The headers table overclaims**: ''Attribution-Reporting-Register-Source'' names a ''destination'' field; MDN documents no "reporting origin" field, which is implicit in the sending origin | **Accepted, fixed** | |
| | | **The bisect window is wider than necessary.** The removal landed in one commit, ''96e032552f'', 2026-04-02, "Roll protocol to r1608973"; the last commit with the symbols is ''1abe750809'', 2026-03-25 | **Accepted, fixed.** Both re-reviewers found the same commit independently. The page now names it | |
| | | The page's "which partition by default" gloss on Firefox and Safari is not literally in ''bahrami2025_cookieguard'' | **Accepted, fixed.** The gloss is now marked as ours and attributed to [[privacy:browser_storage]] instead | |
| | | The new telemetry section had no provenance trail | **Accepted, fixed** — this subsection | |
| | | ''%%--privacy-sandbox-enrollment-overrides%%'' could not be confirmed against Chromium source (code search needed auth); corroborated only by Google's own docs and by the fact that this run's own probe passes it without error | **Accepted as a limitation, recorded.** The switch is used in ''sandbox/ps_call_probe.mjs'' and Chromium does not reject it, which is weaker than a source citation | |
| | | ''w3.org/TR/attribution/'' returns 403 to ''curl'' but 200 to a browser-grade fetch; Bugzilla rejects bare ''HEAD'' | **Noted.** Neither is a dead link; recorded for future link-checkers | |
| | |
| | Everything else in both re-reviews checked out: the fold fix lost exactly the one true positive already admitted and no more (179 of 180 case-insensitive extras in the Protected Audience family are "full-fledged"), every regenerated table matches a fresh script run byte for byte, the published code block is byte-identical to the committed script and reproduces its seven events, the mutation test still drops it to three, and all 34 external claims re-fetched today were confirmed verbatim. |
| |
| ====== References ====== | ====== References ====== |