The irony is that the majority of people that need this don’t have the cognitive time or skill to process and set it up for themselves. But the agents and bad actors like North Korean hackers would absolutely have the time and ability to implement and use it. Then you have the market for lemons problem - if requests coming from here are malicious most requests coming from here will be seen as malicious. Aka dark alleys earn their reputation over time.
Pathetically, people probably won't even erase cookie, let alone JavaScript. To begin with, any websites are not designed to be viewable without js. There are countless ways to find fingerprints. It is impossible to prevent tracking anyway in current the internet.
Same applies to Apple's Private Cloud Compute. A service provider has to join the program to avoid reading visitor's source IP.
It will handicap service provider's capability if I am not mistaken.
What about browsers making general website requests to services that support it?
- King Lear