7 ms·
Everyone is watching what you do online. How user tracking with cookies works
- mkirklions 8y agoSo a cookie only knows the website that referred me? So if I copy paste the website in the address bar, they dont learn anything about my last browsing habit?
- wierd0 8y ago> So a cookie only knows the website that referred me? Not really. Instead, each time you return to a site that has set a cookie on your computer, that cookie is included in the request header. That same site will also know about your last visited page, even if it's outside of their domain, because of the "referer" frpm the request header. > So if I copy paste the website in the address bar, they dont learn anything about my last browsing habit? If you do that, then the referer will be empty and whatever site you visit will not know what you did last. Cookies are just one thing. Web beacons i.e. tracking pixels, and the fact that companies utilizing those to suck up data about web users sell it feely to others for the sake of targeted marketing, is the reason you see peronalized ads all over the internet whenever you've finalized an online purchase.
- deleted 8y ago[deleted]
- kop316 8y agoAt work I am forced to use Internet Explorer, and by using it I found a surprisingly useful feature: I can not only clock all third party cookies, but it prompts me as to whether I want a first party to store any cookies. The prompt allow allows me to automatically blacklist a site from providing me any cookies. I really enjoy this, as if I know there is a site I will never log into, I can permanently blacklist it with one click. I tried to see if I can do the same but I did not find this feature on Firefox. I have also noted that certain sites will be very user hostile if you do this. Reddit will load the site and actually overlay a white screen to make it appear like it never loads if you block its cookies.
- swebs 8y agoIn Firefox you can just install the uMatrix extension. It not only allows you to block cookies, but also javascript, frames, and images. You can choose to block only third party elements, third party elements from known tracking/ad agencies, or even first party elements.
- daphneokeefe 8y agoIn Chrome, you can also use uBlock Origin, which is potentially a little easier to use if you're not an advanced user. https://chrome.google.com/webstore/detail/ublock-origin/cjpalhdlnbpafiamejdnhcphjbkeiagm?hl=en https://chrome.google.com/webstore/detail/ublock-origin/cjpa...
- JackCh 8y agoFor what it's worth I found uMatrix easier to use than uBlock Origin's "Advanced user" mode. Both took a few minutes to get a hang of since neither have particularly discoverable interfaces, but I find the uMatrix interface just a lot faster to use once I knew both.
- rch 8y agoI should have to install a plugin if I want to see targeted ads, not the other way around.
- m52go 8y ago> Reddit will load the site and actually overlay a white screen to make it appear like it never loads if you block its cookies. That's CRAZY. Couldn't reproduce in Edge though.
- kop316 8y agoDid you already have cookies installed? I found that if I let it load a cookie then block it, it would load (but it already had a cookie on there, defeating the point). Try clearing out everything (or try on IE)
- die_fault_user 8y agoWhere is this information stored on my computer? Is there a central location for the information that I can look at or software to read the cookies?
- zeta0134 8y agoThe information is stored within your web browser, so the instructions to view it will depend on what OS and browser combination you use. In Google Chrome for example, you can view cookies in the Developer Tools (F12, or Menu -> More Tools -> Developer Tools), under the Applications tab. This will show you the cookies visible to the website in your current browser tab. Firefox's developer tools have similar capabilities; I don't know the instructions for other browsers offhand though. Cookies are sent to the website by your browser automatically when you visit pages. This is usually limited to the cookies belonging to the domain that set them, but the rules allow some flexibility for cross origin sharing. When you hear about tracking cookies, these are most commonly set by an embedded iframe; these can use a different domain from the page that embeds them, and in the case of ad networks this domain is often shared among many sites. These cookies present the largest potential danger to privacy, as they allow a third-party domain to track some browsing behaviors on the host sites in a way that isn't obvious to the user, and this can be used to build up a profile about the sites that user visits most frequently. If you clear your history in your browser, the website will see no cookies from your browser on the next request. Most sites will simply set a new set of cookies immediately, treating you as a new visitor. You can instruct most browsers to automatically clear your cookies when you exit. Browsers which use a "private browsing" mode also typically use a separate cookie store, so they won't send any cookies from your regular session. From a tracker's point of view, this creates sort of a second user, and in theory should separate that activity from your main accounts. (In practice this can be easily circumvented with browser fingerprinting if a tracker is particularly determined.) Not all cookies are bad, mind. They're one of the earliest widely adopted implementations of "local storage" for websites, and for a time they were the only reliable way a site could remember a visitor between requests. The most visible effect of clearing your cookies is usually logging you out of everything, since most sites still store your session this way.
- 8y ago
- dstjean 8y agoThank you! Great vulgarization... I'll share that with my non-IT colleagues!
- aerotwelve 8y agoWhat's the best way to circumvent this? Is it even possible? I'm no expert (which is why I ask), but I assume that blocking third-party cookies in your browser won't prevent situations like the tracker example the author provides. That is, since you visited tracker at least once, their cookie would have been set during that visit as a first-party cookie, and therefore the http requests to retrieve the 1x1 transparent image from their server will contain the data they're after, right?
- koolba 8y ago> What's the best way to circumvent this? Is it even possible? Set you browser to clear all cookies on close, use a separate browser for anything that requires authentication (ex: gmail), and never mix the two types of browsing. If they create a profile on you the cookies it's tied to disappear when you close your browser. It's feels like a minor pain when you first start out but you used to it quick. Plus since you're not logged into anything by default there's a slightly higher barrier to ordering needless crap online. It's not foolproof as you can be tracked by a combination of other factors (see: https://panopticlick.eff.org/ https://panopticlick.eff.org/) but it's much better than the alternatives.
- jedimastert 8y agoThere's also Facebook Multi-account Containers (https://addons.mozilla.org/en-US/firefox/addon/multi-account-containers/ https://addons.mozilla.org/en-US/firefox/addon/multi-account...), which might do what you're looking for
- gaius 8y agoIf they create a profile on you the cookies it's tied to disappear when you close your browser. If they see you with an IP address and a cookie and a moment later see that same IP with the same browser etc does something else they will correlate them. There is a whole industry around tracking people who explicitly do not consent or have withdrawn their consent to be tracked. That’s why we need GDPR.
- taurine 8y ago
- sandworm101 8y agoThis revelation should be front page on every newspaper. That IT companies have been hiding these things inside our computers is a violation of our privacy, even our property rights. How muck electricity has been used by these things, electricity I pay for. Either Google needs to reimburse me for hosting their "cookies" or we need to ban cookies altogether. https://torproject.org/ https://torproject.org/
- giggles_giggles 8y agoSince you're proposing banning cookies altogether and I've written a few authentication pages in my time and cookies seem to me to be rather important for managing sessions for users so that they can log in successfully to a web page, can you propose what we should use instead of cookies for boring old session handling?
- bcoates 8y agoHow do you think HN logins work? Cookies are the basis of session management. If you don't want to store cookies for Google, don't. It's a feature right there in your browser. There are lots of shady tracking systems in the world and cookies aren't one of them: they are clear, user-visible, and in the user's direct control both in theory and in practice. Tor isn't relevant to this. If you're using Tor to block cookies you're Doing It Wrong.
- sandworm101 8y agoWow.
- bcoates 8y agoSo are you always simulating someone who knows nothing about anything but still thinks something should be done about it, or just in this post?
- gaius 8y agoCookies are the basis of session management. They are one technique. In, oh, 1996, we did this by simply generating a unique URL for each user. If you wanted to stay logged in you bookmarked it, and if you didn’t you... didn’t. It was right there to see in the address bar as well, no sly hiding it in HTTP headers.
- airstrike 8y agoI vaguely remember using a Firefox extension a long time ago that allowed one to whitelist / sticky a handful of domains that would be spared from the usual "delete every cookie", giving the user a renewed sense of control over what the web knows about them. Nowadays with online fingerprinting¹ this may amount to nothing more than placebo, but I do miss it. __________ 1. https://arstechnica.com/information-technology/2017/02/now-sites-can-fingerprint-you-online-even-when-you-use-multiple-browsers/ https://arstechnica.com/information-technology/2017/02/now-s...
- lucb1e 8y agoCalled self-destructing cookies. It broke with web extensions and cannot be replaced (like many other add-ons I use) because the web extension APIs to provide the functionality do not exist. I'm still on Firefox 55 though, so I can still use it (like firegestures, quickjava, no close buttons, vertical tabs, and others that are labeled as legacy). I always find it very creepy when I looked something up on someone else's laptop and use it again half a year later, only to find that it remembers my last visit and (for example) centers the map where I last left it. I'm so used to having things be cleaned up against tracking, I don't even really experience what the web is like these days.
- ealhad 8y ago> cannot be replaced Or can it? https://github.com/Cookie-AutoDelete/Cookie-AutoDelete https://github.com/Cookie-AutoDelete/Cookie-AutoDelete https://addons.mozilla.org/en-US/firefox/addon/cookie-autodelete/ https://addons.mozilla.org/en-US/firefox/addon/cookie-autode...
- severine 8y agoHappy user of Cookie Autodelete here, I agree it is a good replacement.
- lucb1e 8y agoAh, they did finally implement an API for localStorage then. Good to see! That just leaves hiding the tab bar, gestures that work in all windows (e.g. also in the view-source URL windows) and that work before the target page has loaded, etc.
- gerbilly 8y agoFirefox has firstparty isolation, can anyone comment on how much protection this offers against being tracked liked this?
- a_imho 8y agoBrowser vendors are very much complicit in this abuse, imo cleaning up cookies should be opt-out if they were serious about privacy.
- limonkufu 8y agoI really don't understand why this is a bad practice. I know it is horrifying to give your web history to total stranger for god knows what purposes they will use. But going extra mile to implement privacy so that no site/some sites could talk behind your back (looking at you firefox multi account containers) seems like an equally horrific act that cripples websites not ad providers. When I used these kind of precautions I saw that analytics got no access and I believe most of the site-owners need these information to operate/develop their sites and it seems like a lot of work to implement those in-site tracking features yourself. Or I started to see random ads all over the place like early 2000s, I do enjoy targeted ads because when I am looking for something those ads could help a lot, only if there is a way to stop them after I made a purchase though. So, if anyone could simply explain why this is SO bad or send me to correct discussion (I do believe these matters discussed previously a lot).
- throwawayjava 8y ago> it seems like a lot of work to implement those in-site tracking features yourself Aren't there libraries/frameworks/products for exactly this? E.g., when I google "website tracking framework" amplitude.com is top ad result, and it seems to cover the business uses. And http://google.github.io/tracing-framework/ http://google.github.io/tracing-framework/ is the first non-ad result, which seems to cover the legitimate technical uses. > I believe most of the site-owners need these information to operate/develop their sites Can you give an example of a piece of user-relevant functionality that cannot be implemented without Google Analytics? IME especially Google Analytics is mostly useful for business reasons, not technical reasons. It's certainly fair to say that it's difficult to operate a profitable web business without Google Analytics. But that's a very different claim. And the difference is important because... > So, if anyone could simply explain why this is SO bad or send me to correct discussion Legitimate customer-business relationships should always involve informed consent. Cookie blockers and Firefox containers provide the technical tools that enable me to make an informed decision about whether to use your site. Without those technical mechanisms, it's very difficult for me to constantly monitor whether you are tracking me. You/Google are free to deny me access to your products/content if I choose not to be tracked. But I should be allowed to make an informed decision about whether to use your site. The tools you're complaining about enable that informed decision.