← Latest papers
💻 computer science

Technical Report: The Need for a (Research) Sandstorm through the Privacy Sandbox

This technical report introduces "Privacy Sandstorm," a research portal designed to systematically aggregate and evaluate privacy, security, usability, and utility findings regarding Google's Privacy Sandbox APIs, offering a more comprehensive and independent perspective than official channels.

Original authors: Yohan Beugin, Patrick McDaniel

Published 2026-07-15
📖 6 min read🧠 Deep dive

Original authors: Yohan Beugin, Patrick McDaniel

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the internet as a massive, bustling city where everyone is trying to sell things, but the city council (Google) decided that the old way of tracking people—using "third-party cookies" like tiny, invisible stickers on everyone's backpack—was too creepy. So, in 2019, they launched the Privacy Sandbox. The idea was to build a new, high-tech neighborhood where ads could still work, but without those creepy stickers.

But here's the twist: Google built this new neighborhood mostly by themselves, without asking the other city planners (like Safari, Firefox, or Brave) if the blueprints were safe. They started putting these new rules into Chrome and Android, and suddenly, the whole city was changing.

Enter Yohan Beugin and Patrick McDaniel, two researchers from the University of Wisconsin–Madison. They looked at this new neighborhood and said, "Whoa, hold on. We need to check if these new walls are actually keeping people safe, or if they're just hiding new traps."

The "Sandstorm" of Research

To make sense of this chaos, the researchers created something called Privacy Sandstorm. Think of this as a giant, digital storm cloud that sweeps through the internet, gathering every piece of paper, map, and blueprint related to these new privacy rules.

Usually, if you want to know how Google's new toys work, you have to ask Google. But Google only shows you the shiny, happy parts. The Privacy Sandstorm is different. It's a research portal that gathers everything—the good, the bad, the confusing, and the scary. It's like a detective's board covered in red string, connecting every study, every dataset, and every warning sign from independent scientists.

The researchers found that when they looked at the whole picture through their "Sandstorm," they saw a much bigger, more complex story than what Google was letting the public see through their official channels.

The New Rules of the Game (and the Old Ones That Failed)

The paper lists over 20 different proposals, which are like different tools the city council tried to use to fix the tracking problem. Let's look at a few of the big ones:

  • The "FLoC" Experiment (The Failed Group Hug):
    Google first tried a system called FLoC. Imagine instead of tracking your specific backpack, the city puts you in a giant group hug with thousands of other people who like the same things (like "people who like hiking"). The idea was that if you are in a group of 10,000 hikers, no one can tell which hiker you are.

    • What the paper says: Researchers found this was a bad idea. It was like trying to hide a needle in a haystack, but the needle was still glowing. Studies showed that even in these huge groups, you could still be identified, or the groups themselves could be used to fingerprint you. Google eventually dropped FLoC and replaced it with the Topics API.
  • The "Topics" API (The Interest Card):
    After FLoC failed, Google tried Topics. Instead of a group hug, the browser now gives you a weekly card with 5 "interests" (like "Sports" or "Cooking"). Advertisers can see your card, but they can't see your name.

    • What the paper says: This is still being tested, but researchers are worried. They ran simulations and found that even with just a few cards, it might be possible to figure out who you are, especially if you visit a lot of specific websites. It's like having a card that says "Loves Pizza," but if you only visit one specific pizza shop in the whole city, everyone knows it's you. The paper notes that while Google claims this is safe, independent measurements on real data suggest the privacy risks are still there.
  • The "Fenced Frames" (The Glass Booth):
    This is a new way to show ads. Imagine an ad is inside a glass booth. You can see the ad, and the ad can see you, but the ad cannot peek into your house (your browser) or talk to your neighbors (other websites).

    • What the paper says: This is still being maintained by Google. It's a "maybe" for now, but researchers are watching closely to see if the glass is truly unbreakable.
  • The "Related Website Sets" (The Family Pass):
    This lets a company say, "Hey, these 5 websites are all part of my family, so let them share cookies."

    • What the paper says: Researchers found that this might be a loophole. It's like saying, "I can't track you across the whole city, but I can track you through my entire family's house." The paper suggests this could tear down privacy defenses just as they are being built.

The "Deprecation" Twist

Here is the most important part of the story: In October 2025, Google officially announced they are stopping (deprecating) most of these Privacy Sandbox APIs.

Wait, what? They built all these tools, and now they are throwing them in the trash?
The paper explains that Google is pulling the plug on things like FLoC, Topics, Attribution Reporting, and Fenced Frames. However, they are keeping a few tools like CHIPS (a way to keep cookies separate) and User-Agent Client Hints (a way to tell websites what kind of phone you have without giving away your identity).

The researchers argue that even though Google is stopping these specific tools, the work isn't done. We still need to study them! Why? Because if we don't understand why they failed or what went wrong, we might build the same mistakes into the next generation of tools.

The Takeaway

The main finding of this paper is simple: We need more eyes on the ball.

Google is the only one holding the map of the Privacy Sandbox, and they are only showing us the parts they want us to see. The Privacy Sandstorm portal is the researchers' way of saying, "Let's look at the whole map together." They have gathered datasets, software, and hundreds of studies to show that the reality of these privacy tools is much more complicated than the official press releases suggest.

They aren't saying the internet is doomed, but they are saying that we can't just trust the person who built the wall to tell us if it's safe. We need to bring our own flashlights, our own maps, and maybe even a little bit of a "sandstorm" to make sure the billions of people using the internet are actually protected.

So, the next time you hear about a new "Privacy" update, remember the Sandstorm. It's the reminder that in the world of internet privacy, the truth is often buried under layers of code, and it takes a whole team of curious researchers to dig it up.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →