21 ms·
Browsing your website does not mean I want your spam
- r721 10y agoThis is the reason I keep "Block third-party cookies and site data" option checked in Chrome.
- Sir_Substance 10y agoI'm a big fan of "self-destructing cookies" for firefox. It automatically clears your cookie cache when you leave websites, unless you add exceptions.
- bitchypat 10y agoGreat extension. The only annoyance is that when I run ccleaner it wipes the list of sites I want to keep cookies for, so I have to re-add them. But those extra clicks are definitely worth it.
- themoonbus 10y agoI used to do that, but it would sometimes break functionality on certain sites, and the whitelist is a bit of a pain to manage. I've had good success with http://disconnect.me http://disconnect.me
- r721 10y agoYeah, there are some problems, but nothing too critical for me. Examples: 1) Disqus-like commenting systems (I don't use them) 2) Diigo bookmarklet (whitelisted) 3) Youtube liking/favoriting at the time when they tried to marry it with Google+ (fixed now) And I think that's it, can't recall anything else.
- themoonbus 10y agoYeah, Disqus and Facebook comments were the issue for me, although I don't know if I'm better off being able to see them or not :)
- joesmo 10y agoI'm not going to wait for legislation to fix problems I can fix myself. You don't want this to happen? Make sure you have ad-blocking and third party tracker blocking on. I go a step further and use 'Quick JS Switcher' for chrome. By default JS is off and I only turn it on for sites I want. The percentage of sites that I turn it on for is minuscule. I'm seriously starting to question why this isn't the default setup for any freshly downloaded browser.
- danjc 10y agoSurely you must use some SaaS?
- jamiesonbecker 10y agoI'm just checking out that plugin now (awesome plugin btw) and turning on JS remembers that hostname for the future. I haven't dug into the code yet though so can't vouch for its safety..
- joesmo 10y agoYeah, I whitelist things like github, gmail, etc. But it's a very short list. Everything else loads without JS by default. I can turn it on with a click if I want to so it's a minor inconvenience when I reach a site and I need it. Also, the extension will remember which sites I have turned it on for. I have < 100 sites whitelisted. YMMV.
- danjc 10y agoI haven't really considered how short that whitelist might be but you make a good point and I'll likely adopt your approach!
- cocotino 10y agoSo use an ad blocker. Your profile says you are a "former VP of data @ Kickstarter", I'm sure you know what an ad blocker is, what's your excuse?
- Normal_gaussian 10y ago> [...] there may not be much you can do about this besides blocking cookies, ads, and opting out of Criteo’s entire system [...] He knows, and nobody needs an excuse.
- cocktailpeanuts 10y agoJust because he knows doesn't mean he should ignore what's rotten and let it pass. Also your comment probably qualifies for flagging since you use personal details to attack someone.
- dang 10y agoWe've banned this account for repeatedly posting uncivil and/or unsubstantive comments and ignoring our requests to stop. If you don't want to be banned, you're welcome to email hn@ycombinator.com. We're happy to unban accounts when people give us reason to believe that they'll abide by the site guidelines in the future.
- r1ch 10y agoI've had several companies ("data partners" they call themselves) approach us to add these scripts to our websites. All of the ones I've seen use MD5(email) for the "anonymous hashing". I mentioned our privacy policy doesn't allow us to give out user emails, and their marketing guys never seem to understand that MD5(email) is basically the same thing. I even made a video example https://www.youtube.com/watch?v=ViCjzJpEaJw https://www.youtube.com/watch?v=ViCjzJpEaJw that failed to convince them.
- criddell 10y agoUpton Sinclair once said “It is difficult to get a man to understand something, when his salary depends on his not understanding it.”
- nathancahill 10y agoGold.
- pdkl95 10y ago> video example Computerphile recently did a similar example of cudahashcat using a variety of strategies to break passwords. Their goal is to scare people into using better passwords, but the principle is identical to de-anonymising emails. Maybe it can help convince stubborn people? https://www.youtube.com/watch?v=7U-RbOKanYs https://www.youtube.com/watch?v=7U-RbOKanYs If nothing convinces the marketing guys, maybe it's time to pull rank and ask to see the CS degree they are basing their opinion on?
- throwanem 10y agoI would be surprised to learn that a CS degree outranks a marketing role in a lot of organizations responsible for this kind of nonsense.
- mootothemax 10y agoI'd like to know what happens if next time you end by asking for them to send you "a password you don't consider important." If they're interested in the truth, that'll be a pretty convincing illustration. (For any avoidance of doubt - this comes say after explaining what the score is)
- gwbas1c 10y agoThis is why I own my own domain and have a catch-all email address. When I give a company my email address, I use (companyname)@domain.com. They all forward to gmail; where it is very easy to filter out (companyname)@domain.com once shenanigans like this happen. It's also easy to track down and shame companies for doing this, too.
- Bartweiss 10y agoEven for Gmail users, the + notation will handle this well. foobar@gmail.com and foobar+SearsSoldMyEmail@gmail.com will both direct to the same location, and relatively few resellers have the sense to strip the extra data.
- Nadya 10y agoI do this but note that '+' will invalidate your email on some sites and can't be used to begin with. Yay for poor email validation! Gmail ignores `.` in email addresses so you could also try `y.o.u.r.e.m.a.i.l@gmail.com` which will validate in more places - but then you can't pinpoint where exactly unless you start keeping track in a complex spreadsheet. But you will know that somewhere you signed up for sold your email address. [0] https://gmail.googleblog.com/2008/03/2-hidden-ways-to-get-more-from-your.html https://gmail.googleblog.com/2008/03/2-hidden-ways-to-get-mo...
- TeMPOraL 10y ago> unless you start keeping track in a complex spreadsheet The spreadsheet doesn't have to be that complex. Just treat the spaces between letters as bits. Dot is 1, no dot is 0. Suddenly, an e-mail temporal@example.com has 128 different variants, and your spreadsheet may just be a numbered list of companies :).
- techsupporter 10y agoThe problem with the + notation is twofold: First, not all places accept the + character; second, you've now revealed your actual e-mail address (since foobar@gmail.com is just as valid as foobar+dontspamme@gmail.com). I use a subdomain with catch-all, like me.example.com. Everybody is fine with subdomains and then I can use companyname@me.example.com. Using that format doesn't expose my actual e-mail address and makes it easy to filter (if match companyname, immediately bin and never tell me).
- gwbas1c 10y agoThis is why gmail has a big fat "REPORT SPAM" button. Shenanigans like this are SPAM, and should be reported accordingly.
- criddell 10y agoThe email is just a symptom of the actual problem - tracking. Rather than hit the report spam button, I'd recommend installing a browser add-on that limits tracking.
- hueving 10y agoReporting it as spam impacts their entire operation. Disabling tracking only helps yourself.
- criddell 10y agoYou're right. People should do both.
- ryandrake 10y agoBut does it? No matter how many times I click "Report Spam" Google is not going to wholesale block LinkedIn's E-mail operation. At least those E-mails will start showing up in my own spam folder, but that's hardly affecting "their entire operation".
- sejordan 10y agoThis is like refraining from voting in an election because "my vote won't matter." If enough people "Report Spam" then even LinkedIn's email operation will start to be impacted.
- TeMPOraL 10y agoLinkedIn may be a special case, and then Google may be a special case too. But it will definitely help for all the other countless sites that are not LinkedIn.
- trjordan 10y ago> This transaction breaks a core promise using the internet: just because I visit a website doesn’t mean I consent to getting spam from it. No it doesn't. There is no core privacy premise of the internet, and certainly not one that everybody used it signed up for. I'm not condoning this behavior, but we're in territory that we don't have prior art for. It used to be totally fine for one shopkeeper to mention to another that he saw a customer looking for a particular item. When you do it at scale, the old rules don't apply. If you think it's spam, hit the spam button in gmail and get rid of it. Use an adblocker. Talk to your congressman about data privacy and sharing laws, because we don't have anything that's effective. Frankly, continue to write Medium posts, because it raises awareness :) But, I disagree with the notion that this is a solved problem with bad actors, because we're in unknown waters.
- sp332 10y agoThis is really pushing the boundaries of the CAN-SPAM act. You're not allowed to send unsolicited emails. You shouldn't be allowed to pretend that visiting a site is a solicitation. Edit: I misunderstood the mechanism of collecting the addresses. This isn't skirting "unsolicited mail", but it is circumventing the ban on harvested email addresses.
- jamiesonbecker 10y ago> You're not allowed to send unsolicited emails. Actually, you ARE allowed to send unsolicited email, even commercial (UCE). It has to be clearly labeled, contain the postal address of the sender, and contain unsubscribe links. Also, CAN-SPAM only applies to senders in the U.S. (unfortunately). https://en.wikipedia.org/wiki/CAN-SPAM_Act_of_2003#Applicability https://en.wikipedia.org/wiki/CAN-SPAM_Act_of_2003#Applicabi...
- sp332 10y agoI don't know if I would call it a "relationship" message, but maybe it's a "transactional" message, where serving the webpage counts as the transaction?
- kazinator 10y agoI wrote myself a web application called Tamarind that runs on my web server for managing throwaway mail aliases. "Tamarind" == "Throw-Away Mail Alias Randomization Is Not Defeatable" :) http://www.kylheku.com/cgit/tamarind/tree/README http://www.kylheku.com/cgit/tamarind/tree/README I log in with my IMAP4 user name and password, and then get a simple UI with a table of my aliases, and attached memo strings (which can contain URL's that get converted to links). I can edit these, change their order (select multiple, move to top or bottom, etc) create new ones and delete. When I create an alias, it goes "live" instantly, and when I delete one, it goes dead. Dead means that the address is "unroutable" at the SMTP level; it bounces. I keep a few aliases from Tamarind in my wallet, in case I have to hand out an e-mail address in "3D life" to some untrustworthy outfit to be eligible for some promo or whatever.
- simcop2387 10y agoI do a similar thing with google apps and aliases for my main address. that looks like it's nicer to manage.
- icebraining 10y agoI made my own system: it's just a text file with a list of aliases, kept in a git repo. When I push it to my mail server, a git hook runs a very simple script that formats that list into a valid sieve[1] rule. [1] https://en.wikipedia.org/wiki/Sieve_(mail_filtering_language) https://en.wikipedia.org/wiki/Sieve_(mail_filtering_language...
- perlgeek 10y agoA public (which also means: no logins) service that offers similar one-time email addresses is http://wasteland.rfc822.org/ http://wasteland.rfc822.org/ You can use any word @wasteland.rfc822.org as a an email address, and then look into the inbox of the same name, without any password. I tend to use it for services that want my email address, but from which I don't want any emails, and don't want to maintain permanent accounts with. Looking at a mostly random example, http://wasteland.rfc822.org/cgi-bin/inbox?inbox=foo http://wasteland.rfc822.org/cgi-bin/inbox?inbox=foo it seems to have received about 20 spam mails and one or at most two legitimate signup mails.
- jamiesonbecker 10y agotl;dr: related: Amazon sold (or gave) my secret Amazon email address to third parties without my express consent rather than using their remailers. I have exactly one email address that I use for Amazon, and I've never used it elsewhere for anything else. I occasionally receive emails from vendors (through the vendors' mail servers themselves, not remailed through Amazon per mail headers) at Amazon that I have bought things from (via one-click) as gifts and I am 100% sure I never gave them my email address or replied to any email from them. An example vendor is a large outdoor clothing store that I bought a North Face jacket for a relative from. I'm now on their mailing list. In the ultimate irony, I could just click unsubscribe but it's actually good stuff ;) Thanks, Amazon.
- pdkl95 10y ago> exactly one email address that I use for Amazon This is why I use my entire domain as my email address (i.e. *@example.com is routed to my inbox). This makes it trivial to hand out a unique address every time I fill out a form. If any spam arrives that is addressed to "vendor.com@example.com", it's obvious who sold their email db. Bonus: it's easy to filter out spam when the spammer is sending to a unique address.
- Animats 10y agoYou still have third-party cookies enabled? Go to Options in Firefox under Privacy, and set "Accept Third Party Cookies" to "Never".
- desdiv 10y agoI couldn't find that options under the Privacy menu. Turns out they made it slightly more complicated now: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences https://support.mozilla.org/en-US/kb/enable-and-disable-cook...
- anilgulecha 10y agoMore directly - if you want your precious content/resources to make you money, make sure you send the bits over an authenticated & paid account. Not behind an overlay, or with a adblock redirector or when the user-agent has 'googlebot' in it. If you send the bits over, then I may consume them with no additional payment, whether via ads or mailing-list or account signups.
- FussyZeus 10y agoI just love the amazing "Terms of Service" that all of these ad companies have, letting you know that by virtue of loading an HTML page you've consented to have your personal information of ANY caliber spread all over their ad network, their "partners" networks, and to anyone else with a buck and a server, and immediately absolve themselves of any responsibility for what that might mean in terms of information falling into the wrong hands. I can't think of another business that has this kind of insane amount of easy-to-start interaction that results in so much activity and yet can claim zero culpability for any consequences. It's as if you purchased an airline ticket and the ticket came with a 17 page document attached where they spell out that by flying on this aircraft you agree to have tickets pre-planned in your name for 24 other flights, the plane may or may not make a stop off in 6 airports en route to your destination, the pilot occasionally likes to do barrel rolls and loops but he's real good at it so don't worry, and by the way occasionally the engines fall off but you don't get to sue us if anything goes wrong. ENJOY YOUR FLIGHT
- jimsug 10y agoThe legal enforceability of browsewrap is questionable. Certainly if it's not prominent enough, it would be a weak argument.
- FussyZeus 10y agoThe problem is while our metaphorical airline is still able to get away with this, luggage is getting lost and people are getting killed. I legitimately would love to see how much identity theft can be traced back to these fly-by-night companies and their shady ass practices.
- DavideNL 10y agowhat i usually do is reply to their spam e-mail on a support mail address and ask them to stop sending me spam: waste their time the same way they waste my time... if everyone would do that the problem would be solved.
- chime 10y agoI feel less paranoid now for my browsing process. Almost everything I search is in an incognito window, from shopping and research to programming and how-tos. And when I'm done with looking for a new dog leash or Python module, I close that window. Only things in my main browser are the regular sites I visit and am logged into (email, HN, reddit etc.) I started this after learning about the filter bubble but I've noticed how helpful it is when searching on Amazon, Wayfair, or Sears. I get non-machine-learned results every time while my wife using her primary browser with cookies often cannot see the same results I do. If I find something on Amazon, I copy-paste the URL without the ?query-string and replace 'www' with 'smile'. It seems like a hassle but it's no different from cleaning your feet before stepping inside the house after playing in the park. This post just highlights that my practice to avoid unpermitted-profile-building-and-linking is for a good reason. I also have my own @example.com domain that I use and have certainly caught companies selling my info. However, even without being emailed, I don't want algorithms the determine what is best for me based on criteria I choose not to share.
- softawre 10y ago> It seems like a hassle but it's no different from cleaning your feet before stepping inside the house after playing in the park. I mean, you can make that exact argument about every annoying thing you have to do that wastes 1-5 minutes of your time. But over time, especially as a software programmer, if you don't automate those away, it really hurts your productivity.
- chime 10y agoThe more annoying buying on Amazon is, the more I reduce spending. Win-win in this specific case.
- franciscop 10y agoThere are Firefox/Chrome plugins to auto redirect to 'smile.' seamlessly
- roywiggins 10y agoI use Self Destructing Cookies on Firefox. It burns cookies when you close tabs which seems a workable compromise.
- jdavis703 10y agoThis is why I have the username part of my email address tailored to each site/service I register with. So I have a hackernews@example.org, amazon@example.org, etc. Human beings get my real email though (because it would be weird if I told John Smith to email me at johnsmith@example.org). If people start abusing this (politicians do this a lot), I can just block say timkaine@example.org, and never hear from them or people they've sold and traded my email to.
- sneak 10y agoThis breaks "i forgot my password" links years later when you forget what tag you used to sign up at some rarely-used service. I stopped doing it.
- Nadya 10y agoOnly if the site is renamed or asks for your username instead of your email to reset a password. `their.domain.com@example.org` means as long as they use `their.domain.com` you'll know which email to check: `their.domain.com@example.org`
- robin_reala 10y agoLuckily your password manager has remembered which email address you used with which domain.
- __david__ 10y agoFWIW, I've been doing this for about 15 years and I've never had that trouble. I tend to keep the same system for customizing emails so I can guess my username in one or two tries. But using a password manager has completely eliminated even that.
- delecti 10y ago> If people start abusing this (politicians do this a lot) I wish I had set something like this up before falling in for the Ron Paul hype in 2008 (sue me, I was 19). Got untold heaps of junk from those jerks for years before I got it under control.
- 10y ago
- sneak 10y agouBlock origin plugin. Globally disable 3p resources for all pages. Manually greylist CDNs only for sites. Browsing the web any other way is for schnooks.
- davb 10y agoI once had something similar, if not worse, happen. I was researching some network equipment, looking at lots of websites and comparing products. Then my desk phone rings. A call being passed from the switchboard - someone asking for the person responsible for IT purchasing. It was a sales rep from a network equipment distributor, saying they noticed I was browsing their website and wanted to help me through the purchasing process. I had never used their website in the past. No-one from my company had. I never signed up. I didn't login. I was bewildered. I asked how they got my details. The rep said they pay a third party remarketing agency for contact details of people who visit their website. We were a really small company, with no DNS PTR on our main (NAT'd) public IP. We did have an A-record for our mail domain pointing to this IP. As the sales rep didn't know my name, all I can assume is that their remarketing agency was looking up our public IP addresses in some IP-to-business database, populated by email headers or sign ups at other user sites. In any case, I wasn't pleased and was pretty surprised at the rather aggressive sales technique.
- meowface 10y agoExact same thing happened to me, though with a different IT-related vendor.
- akg_67 10y agoIn early 2000's, as B2B Product Manager, I implemented a similar customer outreach program. We will reverse lookup the name associated with visitor IP address and then look into our own sales contact database for contacts in that company. Depending on contact quality, we will reach out to them using phone, email or personal visit from a sales rep in the area. A few times, we decided to hold 'lunch-and-learn' type in-person events in a region based on the regional concentration of IP addresses from prospect companies and search queries from those regions to tailor our presentations.
- wpietri 10y agoWow. Any vendor doing this to me goes on a perma-ban list. If they don't respect me before the sale, I'd have no reason to think they'd respect me after.
- upofadown 10y ago>The CAN SPAM act actually allows direct marketing email messages to be sent to anyone, without permission, until the recipient explicitly requests that they cease (opt-out). Isn't this the root problem here? It is hard to see how you could even start to fix this sort of thing without fixing the spam law first.
- dnh44 10y agoEveryone should use this: http://someonewhocares.org/hosts/hosts http://someonewhocares.org/hosts/hosts
- LoSboccacc 10y agonah it slows windows brutally
- dredmorbius 10y agoPark it on your router. DD-WRT: https://www.dd-wrt.com/wiki/index.php/Ad_blocking https://www.dd-wrt.com/wiki/index.php/Ad_blocking https://ello.co/dredmorbius/post/v9l7zvlyynvl1pskbwssmq https://ello.co/dredmorbius/post/v9l7zvlyynvl1pskbwssmq Uses dnsmasq for instant query caching.
- walrus01 10y ago... and I just created a new spamassassin rule for criteo. Done and done.
- rootlocus 10y agoI was thinking whether or not sending these emails actually helps companies like Sears by bringing in customers, and whether or not (to an extreme) they might depend on them to survive as a profitable enterprise. What came to me as a revelation is that it's irrelevant. If their income relies on bothering everyone who comes across their website, tricking them into clickbaits or spamming them with (possibly malicious) ads, it might mean their services are not enough to justify their existence. As such, I decide not to pity them, and happily continue loving my adblocker.
- deleted 10y ago[deleted]
- robryan 10y agoThere would definitely be some level of revenue being driven off these. It is an interesting case where apart from the software it didn't cost them anything to get the email address, so getting a higher unsubscribe rate doesn't seem so bad. (As opposed to discounts/ deals/ competitions) you might normally run to get someone onto a mailing list.
- __jal 10y agoI think it is about time to build a one-click opt-out to preemptively opt-out of all of these scumbags' systems.
- rocqua 10y agoOpt outs require giving out emails though. If you think they are scummy enough, that might be a bad proposition. That said, someone in the comments stated how these companies actively avoid those who might click 'report spam', so this might work.
- JohnTHaller 10y agoI've been getting more spam lately from "legitimate" companies. One of my email addresses leaked from a major open source project I corresponded with. Harvesters found it and now sell it to every small business and entrepreneur marketer you can think of. I get spam from CDNs, off-shoring companies, SEO/SEM, marketing, you name it. Lots of them use sketchy services like reply.io to make it seem like a real person sent the email. And then another that looks like a reply to the first when you don't respond. And then another and another. Like Katie Malone at HawkSEM.com who 'personally' spammed me another 'reply' today. Essentially, folks like reply.io and similar automate the process of repeat spamming. Even their tag line is "Send Cold Emails That Feel Warm". Here's a reality check for you: sending "cold emails" to a list of email addresses you bought makes you a spammer. Even if you try to make them appear personal. The giveaway is the tracking image (usually hidden or 1px by 1px white of course) and tracking links in every email so they can track whether you opened it and whether you clicked anything along with the unsubscribe link at the bottom. Except they don't label it as unsubscribe. It says "If you don't want to get any more emails from me, just let me know." with 'just let me know' as a link. Be sure to mark every email like this you receive as spam so you don't get any more and so their reputation decreases enough to route all of this spam to everyone's spam folders.
- Nagyman 10y agoThis has absolutely picked up recently! It doesn't help their brand in my case, as I put them into the "Overly Aggressive Vendor" folder for future reference when I'm actually looking at purchasing services. Those reply.io emails that look like they're from a real person are a grey area of marketing. I think it's deceptive and places undue social pressure to reply. Sometimes I do reply, but only when I get annoyed. In such cases, I turn the tables and start trying to sell them adventure travel (G Adventures). Sadly, we also use Criteo; thankfully adblockers block Tealium tag manager by default anyway. When I saw OPs article screenshots, I actually suspected that Criteo had harvested the email address from the Forgot Your Password screen. This isn't uncommon – VE Interactive (I've mentioned them before), reads forms for email address fields and onBlur, they capture it and send marketing emails later. I _think_ this type of behaviour is supposed to be limited to cart abandonment situations, but I'll bet an incorrectly configured tag would target all forms.
- arnaudlaudwein 10y agoThis is legal[1] in Europe if you consented to receive marketing emails from "partners" of a website you subscribed to (through an opt-in, not an opt-out checkbox). You subscribe to website X, you opt-in to offers from third-parties, and this allows X to share your e-mail address with Criteo. Then Criteo sends you marketing e-mails for the account of Sears (but they surely don't share any PII with Sears - the e-mail is sent by Criteo). The logic isn't that "browsing Sears is considered as having a preexisting business relationship with them". It's because users opted-in to third-party communications from a website they may have signed up with, back in 2008. Other similar use cases include sending you an e-mail for website X when you browse website Y because they know you are in front of a computer/phone and this increases chances of opening e-mails. Doesn't make it more or less "right" though and it's surely very surprising for users, myself included. (On a tangent, what still looks like a legal gray area to me are the Data Management Platforms (DMP) - everyone shares user data in a big bucket/database provided by a common partner, all users are identified with IDs but not directly with PII, how much data can companies push/pull legally?) [1] Not a lawyer but worked with legal teams on these topics. Laws still differ slightly depending on the European country you're talking about, but the GDPR will soon be unifying data privacy regulations. Right now the French and German Data Privacy regulations are some of the most restrictive ones.
- mSparks 10y agoQuick vent. I'd much rather lawyers just kept of the internet entirely.
- mSparks 10y agoAnd for the avoidance of doubt. That is nothing so much against lawyers, the are essential in the real world where land is a finite resource. But the better solution to problems in an environment when CPU ticks are not a finite resource, and bandwidth is nowhere near capacity are technical and educational problems, not legal ones.
- deleted 10y ago[deleted]
- idlewords 10y agoIt's a little rich to write this complaint on Medium, a site that has been uniquely aggressive about tracking its readers' behavior (it has a script that phones home with your position on the page, and its URLs abuse the fragment identifier to track who you got the link from). If you dislike surveillance capitalism enough to write an essay about it, think about where you're publishing it.
- shostack 10y agoThe page position thing I totally get. They don't care about individual data there but they want to identify if content is being fully read. It is a big challenge for any publisher and very important in getting the most engaging content front and center.
- shostack 10y agoThe page position thing I totally get. They don't care about individual data there but they want to identify if content is being fully read. It is a big challenge for any publisher and very important in getting the most engaging content front and center.
- ChuckMcM 10y agoSet privacy badger to block all Criteo cookies.
- TeMPOraL 10y agoYesterday, after many years, my curiosity finally got better of me - I started playing World of Warcraft. Since my head is now full of thoughts about MMO, excuse me for saying this: There should be a new class - or race - added to fantasy worlds. The Marketers. More evil than demons, undeader than the Lich King. Their gameplay mechanics would be based around earning gold by draining their own souls, as well as the souls of characters around them. Their primary combat role would be casting annoying debuff spells at everyone around, friend and foe alike. Seriously though, this article basically says that someone out there has reached another level in insidiousness. If it was an MMO, we could at least form a raiding party and get rid of the problem once and for all.
- saltyhiker 10y agoThe real problem here is not the chain of marketing tech that allowed this, the issue is that the marketing message itself sucked. If the message was valuable, many people wouldn't have been bothered by receiving it. As for the message itself, if their intent is to sell you that specific item you searched for, they should say so. Of course, they need to avoid the creepy-factor, which, along with laziness are the two reasons they may have ended up with the junky message you received.
- TeMPOraL 10y ago> The real problem here is not the chain of marketing tech that allowed this, the issue is that the marketing message itself sucked. If the message was valuable, many people wouldn't have been bothered by receiving it. I disagree. This sounds like the rationalization marketing folks put forward, namely that they're actually helping people. No, they are not. At best, they're shoving messages into peoples' faces. At worst, they're shoving poisonous radioactive garbage messages full of lies into peoples's faces. The range of behaviour here is from mildly annoying to outright malicious. Very rare is the case when unsolicited marketing messages are something people are actually happy about.
- saltyhiker 10y agoI agree with you that the lazy/poisonous methods are far too common, and was exaggerating to some extent. In this case the chain of tech may be too sullied for a good message to be well-received. I'd also like to add that as punishment for insulting the Sears marketing team, I got a piece of spam from them 20 minutes after my comment.
- not_a_codfish 10y agoJust because you write a blog post doesn't mean I have to do it. Spam is acceptable content, you've no right to tell anybody what they can or cannot create. If you don't like it, then don't look at it. If they shove it in your face, it's YOUR job to ignore it, not their job to somehow pre-determine who wants to see it and who doesn't. As a content creator, I'm not obligated to do a background check on each user and try and see if my content is going to offend them, or bother them, or be considered irritating by them, it's just to C R E A T E.
- TeMPOraL 10y agoYou're joking, right? > If they shove it in your face, it's YOUR job to ignore it, not their job to somehow pre-determine who wants to see it and who doesn't. No, it's exactly their job. It's the difference between pushing and pulling. If you want to show your content to people, start a webpage and put it there. No one gets the right to be offended by the content of a website they're browsing voluntarily. But conversely, no one gives you the right to shove the content in my face.
- not_a_codfish 10y agoYou visited the website and you're mad that they choose to show you content?
- lolc 10y ago> Spam is acceptable content You have no right to be heard. If you try and force it, be prepared to get shunned by society. Just because it's legal to violate social norms does not mean that people will hate you any less for doing it. See when I get mail from inconsiderate assholes, and it didn't get filtered, I look up the abuse contact of their provider. Then I forward the mail to them with a note that it was unsolicited. (In most cases I will CC their upstream abuse contact too because I'm nice like that.) With responsible senders, this works wonders. The irresponsible senders end up on blacklists and their asshole customers get terrible reach.
- not_a_codfish 10y ago
- cptskippy 10y agoI've been using a catch-all email domain for years where anytime I give out an email address, the local part is a description of the party receiving the address (e.g. bestbuy.com@mydomain.com). If I receive spam at a particular address, it's easily blocked and I know who leaked it. An interesting side effect of receiving email from so many different addresses to the same inbox is that I often receive the same spam to multiple addresses simultaneously. This is easily caught by spam filters and so I never have Spam in my inbox. It also makes identifying false positives in my Spam box easy because they usually stand out against the repeated subject lines so it's a simple game of which one of these is not like the others.
- loup-vaillant 10y agoHow fitting. I have just received a mail from Medium with no "unsubscribe" button because I commented on it.
- LoSboccacc 10y agohere's another special snowflake that does the internet equivalent of 'I want to talk to the manager' it is their website, so if you don't like their terms, leave. I do run adblocks etc to avoid drive bys, but if a website relies on delivering me spam&malware I just avoid it Also why is this guy so upset about retargeting now? it has been a thing for more than a decade, and without it one would just see some generic spam instead of these sorta ineffective reminders. creepy? sure! then again there's one simple trick to make them disappear: don't go on shady websites where you're the product and bring your money elsewhere.
- hudell 10y ago1) There's no way to know the site's terms when you're coming to it for the first time from google. 2) He isn't complaining about retargeting, he's complaining that his email address was shared through it.
- sklivvz1971 10y agoI just mark all this stuff as spam, including stuff from legit companies that might have tricked me into subscribing to some list. The thing is, I am never, ever interested in receiving marketing emails. Every single time, without doubt, I opt out of marketing emails. So if I receive one it means that one of these things holds true: 1. It's just spam 2. The website used some dark pattern to trick me into subscribing to something I did not want to 3. The website assumed consent and didn't bother asking Guess what -- I'm perfectly fine burning all of this crap with a spam filter. It's a waste of time, and time is my most precious asset.
- mirimir 10y agoResources like https://sneakemail.com/ https://sneakemail.com/ are useful :)
- nashashmi 10y agoI don't understand why everybody does not block third-party cookies by default. I took a stab at my cookie list and found 300 cookies from advertisers and intel gatherers. I deleted them selectively, but I did not want go through that again, so I blocked the third-party ones. Some have been explicitly aloud because I trust them, like google analytics. But other google cookies are prohibited, like plus.google.com. Facebook is explicitly blocked. Doubleclick is blocked. some websites will not work if certain third parties are blocked, so i have to explicitly allow them once i realize the problem.
- cyberferret 10y agoI am really beginning to hate browsing the web these days... Especially poop up dialogs asking for my email as soon as the mouse cursor leaves the active browser screen. With an average of 20 browser tabs open, while one is loading I often go to click on another to check on something, and this instantly triggers a flurry of popups begging me to stay/subscribe. Also the retargeted ads that follow me everywhere now. MOST of them are for companies where I have ALREADY bought something, so they are wasting their ad spend on chasing an existing customer, not a likely prospect. This has made me resolve to try and make the web a less shitty place, one web site at a time - and I have ensured that my web projects absolutely DO NOT have any popups or cross site tracking in there (aside from normal analytics that is only used in house). [I accidentally mis-typed 'pop up' above but LOVE the Freudian slip so will leave it as-is].
- kaila 10y agoI assumed poop up was intentional and thought it was pretty clever. Glad you left it as-is!
- Jaruzel 10y agoDitto!
- majewsky 10y agoAnd you don't use an adblocker yet?
- laurent123456 10y agoIt feels like ad-blockers are less and less effective at blocking ads these days, in particular I don't think any of them block these annoying JS popups.
- executesorder66 10y agouBlock Origin has never failed me. Even for annoying "non-ad" crap like that.
- chadgeidel 10y agoAm I paranoid in assuming their "opt out" system is basically probably an "opt in"? Related: I know that it's possible to "opt out" via the Direct Marketing Association communications (https://dmachoice.thedma.org/ https://dmachoice.thedma.org/), but have thus far not done this as I assume I'll just get more junk mail.
- mungoid 10y agoI think it depends on what companies agree to not send you emails if you opt out. I'm betting if a company agrees to the dma opt out then they will stop and you will get a little less. But I think most advertisers don't care if you opt out or not. It's in their best interest to not care
- singold 10y agoHe talks about tge legality of sending the spam, but what about the legality of the partner he is really subscribed to that shared his information with a 3rd party? IANAL but AFAIK that wouldn't be legal in most countries
- tempestn 10y ago> Only when we craft the email on behalf of our advertisers, we receive your name, surname and email address from our partners, should you have consented to receive their emails marketing. > Let’s ignore the fact that they assume Sears had my consent (they didn’t). Just a note: I think what Criteo is saying here is that you gave permission to some third party to use your email for marketing purposes and to share it with their "partners", not that you gave Sears permission to use it. But they shared it with Criteo and Criteo shared it with Sears (or sent the email on their behalf) so technically there is "consent". (Of course in practice it's often possible to supposedly give such consent without ever realizing what you're opting into.)
- davidgerard 10y ago"Dear Criteo: You opted in to this box of dead rats we just sent you because you once visited a site that partners with our dead rat promotion service."
- imron 10y agoAnd people wonder why adblockers are so popular...
- astdb 10y agoWould disabling third party cookies have prevented this?
- zymhan 10y agoYes, it should have. Unless the ad tracker placed some other cookie-like file that would evade your browser's cookie settings.
- sandworm101 10y ago>>> But until legislation catches up to regulating the negative consequences of retargeting, there may not be much you can do about this besides blocking cookies, ads, and opting out of Criteo’s entire system by submitting your email address here. No no no. Handing over your email address to an online advertiser is a horrible idea. Do not engage them. Blacklist their content, their cookies, via whatever means you want (I use adblock) and be done with them. An article that discusses tracking via online advertising but doesn’t discuss blocking is very suspicious. The most powerful tool against the problem isn't worth even a mention?
- ahm750 10y agoFaced a similar situation recently. It was both surprising and frustrating.
- justrossthings 10y agoI talk a lot about this stuff with a friend doing sales operations at a hyper-growth startup in SF. With Criteo, tools like Reply.io and others he thinks we're going to see an event horizon where recipients of spam say enough is enough and online privacy finally becomes 'cool'.
- dredmorbius 10y agoI've mentioned putting the Winhelp2002 hosts file on my dd-wrt router a few times. I just checked to see if I need to add any specific entries. root@router:/tmp# grep criteo hosts0 0.0.0.0 cas.criteo.com 0.0.0.0 dis.criteo.com 0.0.0.0 dis.eu.criteo.com 0.0.0.0 dis.ny.us.criteo.com 0.0.0.0 dis.sv.us.criteo.com 0.0.0.0 dis.us.criteo.com 0.0.0.0 ld2.criteo.com 0.0.0.0 rta.criteo.com 0.0.0.0 rtax.criteo.com 0.0.0.0 sapatoru.widget.criteo.com 0.0.0.0 sslwidget.criteo.com 0.0.0.0 static.criteo.net 0.0.0.0 static.eu.criteo.net 0.0.0.0 widget.criteo.com 0.0.0.0 www.criteo.com Apparently not. Deets: https://ello.co/dredmorbius/post/v9l7zvlyynvl1pskbwssmq https://ello.co/dredmorbius/post/v9l7zvlyynvl1pskbwssmq https://www.dd-wrt.com/wiki/index.php/Ad_blocking https://www.dd-wrt.com/wiki/index.php/Ad_blocking
- malchow 10y agoPlease. There is no core privacy premise of the internet. The core premise of the internet is one protocol to deliver meshed knowledge to any computer. And the commercial possibilities of the internet are what have underwritten the growth of the network. Reaction like this one make me think: entitled. But they also make me think: unrealistic. How much should hypertargeted ads really bother us? Call me when they are using my bank account and medical records to show me ads. Not my browsing history, over whose exposure I have complete control, and which doesn't really expose very much about me or my family.
- benjamincburns 10y agoThere is no core privacy promise _built in_ to the core of the internet in the same way that there is nothing in the laws of physics which prevent murder. We have laws and cultural norms for this sort of thing, and it's not at all entitled or unrealistic to suggest that those tools be used to curtail a rather parasitic situation such as this.
- Jaruzel 10y agoFrom the Article: I am signed up to some platform which is a Criteo partner. It’s entirely unclear who this partner is. While Criteo boasts a “close partnership” with Facebook, Facebook claims that they do not share personally identifying information such as your email address with ad partners. Regardless, a platform with my email address gave it to Criteo. This issue is exactly why I use specific email addresses for each website. I tend to follow the pattern <websitename>@mydomain.com. That way if a site leaks my email address to spammers (either intentionally or accidently) I know which site it was, and immediately boycott them in future and move that email address into a blacklist. For big sites I cannot boycott, I simply register a new email address with them (i.e. <website><number>@mydomain.com), and move the original into the blacklist. As I run my own on-premises email system, I can't benefit from crowd-managed spam systems, so keeping a lid on the incoming spam is very much a pro-active action for me.
- jimsug 10y agoAnd this is why I use uMatrix, despite the little bits of extra hassle I go through when visiting sites for the first time.
- a_imho 10y agoI know there are a couple of solutions out there, but what exactly stopping the main email providers to offer on demand proxy addresses for one's main account? I think there is a legitimate demand for it, but not enough to actually sign up for yet another service.
- andrewaylett 10y agoPrivacy Badger is pretty good at blocking things like this -- it watches out for domains that are third-party for more than one site, and blocks requests to them. Does require some tweaking for genuine CDNs (and indeed comes with a yellow-list of common domains that will receive requests but not cookies) but generally very useful. https://www.eff.org/privacybadger https://www.eff.org/privacybadger
- rapht 10y agoI personally switched to the following policy a year or two ago to avoid all this crap: 1) NoScript extension filtering everything except the base domain => no third party scripts are allowed except when I explicitly allow them 2) Cookie Whitelist extension to allow cookies only from domains I choose, only when I need => no third party cookies allowed, ever 3) µBlock incase the webpage tries to load iframe ads 4) a unique email address per service (like amazon.[5 random chars]@mydomain.com) so if all else fail and your address gets in the hands of somebody who should not have it, you know where it came from and can expose them
- DoubleGlazing 10y agoMy wife's cousin had something like this happen to her two years ago when she was planning her wedding. She browsed a few specialist wedding sites for inspiration and when she went to to some well known retail sites to start pricing things they seemed to know she was getting married and promoted wedding goods and services on their front page to her. It freaked her out no end. I suggested a few plugins that seemed to put a stop to it. But a few weeks later she did start getting wedding related snail mail spam. Its very creepy, especially after the whole Target teenage pregnancy thing.
- kjs3 10y agoYup...with my ex-wife is was first time we got pregnant. Browse a couple of specialty sites and suddenly everyone and their mother is spamming us with new-parent ads. Let me tell you how much fun it was to still be getting "free Enfamil baby formula" spam for a year after she had a miscarriage.
- bogomipz 10y agoOn a somewhat related note and what I thought the article was going to be about, what is going on with the phenomenon of a HTML 5 light boxes loading when you are barely a few seconds into reading a page asking you to "sign up for the newsletter." This trend is out of control. If you were browsing shelves in a grocery and someone came and stood between you and the book you would want to punch them. Does annoying people into something actually work? I feel like it must since its so prolific. I wish there was a way to block these.