4 ms·
Just a thought - if the ad network uses js code (hosted on abc.com and xyz.com servers), which loads images from the same domain (but it loaded in on a server-t
by tehmaco 11y ago
Just a thought - if the ad network uses js code (hosted on abc.com and xyz.com servers), which loads images from the same domain (but it loaded in on a server-to-server link, and cached and served from the the domain you're visiting). Can they not just set a tracking cookie for that domain that they control with a unique ID, tied to browser fingerprinting, which is transmitted to the ad network?
So you visit abc.com for the first time, get an ad image served from the same domain (but was provided from the ad network), have the cookie set, the ID is noted by the ad network.
You then visit xyz.com, a new cookie is generated, which can be tracked by the ad network as the ID is the same.
So you now get tailored/tracking adverts without any third party domains being accessed by your browser...
- cm2187 11y agoDo you mean: I visit abc.com, abc.com serves me an abc cookie, then I visit xyz.com, and xyz.com makes a call to abc from my browser, so that they can use the abc cookie to track me? Well, that is effectively using abc as a tracking server, and abc.com would quickly be added to the adblockers lists. Effectively this is the current model. The other thing is that I may visit abc.com and xyz.com but this particular combination may be unique to me, i.e. I may visit nytime.com and ford.com which may use the same ad network, but you may not visit nytime.com at all and instead wsj.com. Browser fingerprinting is a different problem. It does defeat the same origin policy. But I suggest you look at the sources of entropy: https://panopticlick.eff.org/ https://panopticlick.eff.org/ With javascript off, there is virtually no entropy, just your user agent and HTTP_ACCEPT header. You can't fingerprint a browser at all. If you enable javascript but not plugins, then the Browser Pluggin details give you some entropy, although looking at the list those a relatively generic and would likely be the same on many machines. If you enable plugins (flash, silverlight, java) then you have a massive amount of entropy but realistically all of these plugins are almost gone from major browsers.
- tehmaco 11y agoThat's not quite what I meant - the ad network provides abc.com with a js file, hosted on the abc.com servers. That js file creates an ID from browser fingerprinting, which is saved in a separate cookie, or an additional data point within whatever abc.com sets. The ad cookie/ID is then sent from the abc.com server to the ad network (along with whatever data they need to determine what ads were seen/clicked), who collate all the data from wherever their js file is running, thusly allowing them to track you, without any requests from your browser being sent to any other domains other than the ones you directly visit.