Corporate Website Marketing logo — B2B website marketing referenceCorporate Website MarketingB2B website marketing since 2003
From the archive

When Google Shipped a Browser

An archive note on the Google browser, and the twenty years of consequences for measurement, performance and cookies.

The browser was never the point

Google shipping a web browser mattered because of what a browser vendor controls, not because of the browser. This page has been on this site since the mid-2000s, when a Google browser was a rumour that resurfaced every few months and was treated, when treated seriously at all, as another front in a competition with Microsoft. Chrome itself arrived in 2008. The original note was short and of its moment; it is not reproduced or quoted here.

What is worth writing about is how badly that framing missed. A browser vendor decides what counts as a fast page and publishes the measurements. It decides which standards a marketer's developers build against, and when a missing certificate becomes a warning that stops a visitor. It decides whether a cookie set by one site can be read on another — the foundation of retargeting and of most cross-site attribution. Owning the browser meant owning the environment in which marketing work is finally rendered, measured, and permitted or refused.

Distribution first, then everything else

A browser is a distribution asset before it is a technical one. It carries a default search engine, a default set of privacy behaviours, and an update channel reaching most of a company's audience without asking permission. Once it has meaningful share, its defaults are the web's defaults and its developer tools are the ones every team learns first.

That last point is underrated. Chrome DevTools and Lighthouse shaped how a generation of developers reasons about page speed — which numbers they look at, which they ignore, what they call good. When a vendor supplies both the measurement tool and the metric definition, its opinions become the industry's vocabulary without ever being argued. Marketing directors experience this as technical requirements arriving with a deadline attached, from a source they cannot negotiate with.

This is not a complaint about Chrome specifically; Apple exercises the same control in Safari and has used it more aggressively on tracking. The observation is about the position, not the occupant. The browser layer is where a corporate website's fate is decided, and no company selling anything online has a vote there.

Defining what a fast page is, then measuring it in the field

The clearest demonstration is Core Web Vitals. Google defined a set of user-experience metrics, published thresholds, built them into its own tooling, collected them from real Chrome users, and connected them to search. A marketing team that had never held an opinion about layout stability suddenly had a target for it.

The current set is three: Largest Contentful Paint, good within 2.5 seconds; Interaction to Next Paint, at 200 milliseconds or less; and Cumulative Layout Shift, at 0.1 or less. They are assessed at the 75th percentile of page loads, segmented separately for mobile and desktop, so a site can pass on desktop and fail on mobile. First Input Delay, which older articles still list, is retired: INP became stable on 12 March 2024 and FID support ended in Chrome tools on 9 September 2024.

Two consequences matter more than the numbers. These are field data from real sessions, which makes the vendor's measurement of your site more authoritative than yours. And INP cannot be measured in a lab, because a simulated load contains no interactions — so a Lighthouse score of 100 does not mean a site passes Core Web Vitals.

How browser warnings moved the web to HTTPS

Google announced HTTPS as a lightweight ranking signal in August 2014, and indexing HTTPS pages by default in December 2015. Those posts are usually credited with the encryption of the web, and they deserve far less credit than the browser does.

A small ranking signal is an argument a marketing director has to win against a development backlog. A browser interstitial telling a prospect the connection is not private is not an argument; it is a lost form submission. Over the second half of the 2010s Chrome escalated its treatment of plain HTTP from neutral, to a subdued indicator, to an explicit not-secure label, and browsers began blocking mixed content — insecure assets in a secure page — outright. Certificate expiries that once produced a click-through warning came to produce something most visitors read as a malfunction.

HTTPS stopped being an SEO project and became an availability requirement. When a platform vendor wants a change to the web, the ranking signal is the announcement and the browser is the enforcement.

Cookies: the control that reached the media plan

The browser decision with the most direct effect on a B2B media plan is whether a cookie set by one site can be read on another. Cross-site cookies let a retargeting platform recognise a visitor on a publisher's site, and let multi-touch attribution stitch a journey together. Browser vendors decide whether that works.

BrowserDefault treatment of cross-site cookiesConsequence
ChromeRetained, with user choice controls; not being deprecatedCookie-based retargeting still functions on this traffic
SafariFully blocked by default since Safari 13.1 and iOS 13.4, announced 24 March 2020Unaddressable by third-party cookies for years
FirefoxPartitioned per top-level site by Total Cookie Protection, on by defaultSimilar practical effect, different mechanism

The Safari and Firefox positions have been stable for years. State the Firefox one accurately: Total Cookie Protection partitions cookies to the site you are on rather than blocking them, which is not the same thing, though cross-site tracking is defeated either way. The volatile one has always been Chrome, whose share determines whether cookie-based targeting is a working channel or a rounding error.

The reversal, stated exactly

Google spent several years announcing that Chrome would remove third-party cookies, and then did not. This has to be stated precisely, because a large volume of published marketing advice is wrong about it.

On 22 April 2025 Google said it would not roll out a new standalone prompt for third-party cookies and would maintain its current approach to offering users third-party cookie choice in Chrome. On 17 October 2025 it reaffirmed that and went further: it is the replacement advertising interfaces, not the cookies, that are being retired. Its list of technologies to be deprecated and removed includes Topics, Protected Audience, Attribution Reporting, Private Aggregation, Shared Storage and Related Website Sets, with IP Protection discontinued. What continues is the privacy and security plumbing: CHIPS for partitioned first-party cookies, FedCM, Storage Access, Fenced Frames and Private State Tokens.

So: third-party cookies work in Chrome, and there is no deprecation date because there is no deprecation. The Privacy Sandbox advertising interfaces pitched as the successor to cookie-based targeting are not a planning target — most are scheduled for removal, with no end dates published.

What this site, and the industry, spent years getting wrong

The industry prepared, at considerable expense, for something that did not happen, and this site was part of that. Pages were written about the cookieless future, about interest-based interfaces, about audits to run before a deadline, about identity vendors positioning themselves as the answer. Conference agendas were built on it.

  • Wasted: time spent learning interfaces now withdrawn, vendor selection driven by a deadline that evaporated, and reporting that told executives cookie-based retargeting was about to stop working on Chrome.
  • Not wasted: the first-party data work — server-side measurement, hashed identifiers, consent management, CRM as the source of truth for pipeline.
  • The actual error: the reason given. First-party measurement was justified to boards on an announced Chrome deadline. The honest justification was always Safari and Firefox defaults, privacy law, and the principle that a programme should not depend on a mechanism a vendor can switch off. The deadline was the weakest argument available, and the industry led with it.

The lesson is not that vendors lie — Google published its reasoning at each stage. It is that an announced intention and a shipped behaviour are different kinds of fact, and a programme should be planned on the second.

Planning around a platform vendor's roadmap

Some announced deadlines land and some evaporate, and there is no reliable way to tell in advance. Universal Analytics really did stop processing data on 1 July 2023, and organisations that treated the notice as theatre lost their history. Cookie deprecation was announced with equal confidence and abandoned. A workable posture:

  • Separate shipped from announced. Shipped behaviour goes in the plan; announced intent goes on a watch list with an owner and a review date.
  • Ask what breaks if the announcement is withdrawn. Work only worth doing because of a deadline is what to defer.
  • Measure your own browser mix rather than quoting share figures. Your analytics knows what proportion of buyers arrive in a browser that blocks or partitions cross-site cookies. That is the number worth planning against.
  • Prefer mechanisms you control. First-party data, server-side tagging, hashed identifiers passed to ad platforms, CRM-side attribution, self-reported source questions on forms.
  • Read the source, not the summary. Secondary coverage of this topic is years out of date and confidently wrong.

The archived note treated a browser launch as a competitive skirmish. It was a transfer of control over the conditions in which marketing is measured. Watch that layer directly.

Frequently Asked Questions

Are third-party cookies going away in Chrome?

No. Google said on 22 April 2025 that it would not roll out a new standalone prompt for third-party cookies and would maintain its current approach to third-party cookie choice in Chrome, and reaffirmed that on 17 October 2025. There is no deprecation date because there is no deprecation.

Cookie-based retargeting therefore still functions on Chrome traffic. What has been retired is most of the replacement advertising interfaces. Any article offering a countdown to a cookieless Chrome is out of date.

What happened to the Privacy Sandbox?

The advertising parts were withdrawn. Google's status list marks Topics, Protected Audience, Attribution Reporting, Private Aggregation, Shared Storage and Related Website Sets for deprecation and removal, along with several Android equivalents, and IP Protection as discontinued.

What continues is infrastructure: CHIPS, FedCM, Storage Access, Fenced Frames and Private State Tokens. Google has published no removal dates for the retired interfaces. Practically, there is no Google-provided successor to cookie-based audience targeting on the open web.

Should we still move to first-party data if cookies are staying?

Yes, for the correct reasons. Safari has blocked cross-site cookies by default since 2020 and Firefox partitions them, so part of your audience has been unaddressable regardless of Chrome. Consent requirements in Europe and a growing number of US states apply independently.

What changed with the reversal is the urgency argument, not the direction. Fund first-party measurement as infrastructure with a business case, not as deadline compliance.

Does a Lighthouse score of 100 mean we pass Core Web Vitals?

No. Lighthouse is a lab tool: it loads a page in a simulated environment with no real user in it, and Interaction to Next Paint cannot be measured that way. Core Web Vitals are assessed on field data from real sessions, at the 75th percentile, with mobile and desktop segmented separately.

A perfect lab score with failing field data is common, usually caused by conditions the simulation does not reproduce: slower devices, third-party scripts, consent banners, real interactions. Report field data; use lab tools for diagnosis.