11 ms·
Show HN: Bypassing ad blockers for Google Analytics
- kevingadd 8y agoIf you're hosting the analytics on your own domain, is it really even something an ad blocker should be blocking? It's not coming from a known third-party service domain (for ads or tracking or otherwise) so there's no real reason a blocker should be blocking it. It's first-party analytics on your own website. The fact that you're implementing it via reverse proxying is kind of an implementation detail, because at any point it could stop being Google Analytics, or an existing first-party analytics solution on a website could become GA. It is kind of unfortunate that third-party tracking can 'hide' this way but in this case there's not really much you can do if the content author is going out of their way to pull a fast one...
- Doctor_Fegg 8y agoIt isn't something they should be blocking, but they try to. uBlock, for example, blocks self-hosted Piwik/Matomo. But the entitlement of ad-blockers is astounding sometimes: https://github.com/easylist/easylist/pull/900 https://github.com/easylist/easylist/pull/900, in which the easylist maintainer defended blocking OpenStreetMap advertising OpenStreetMap events on openstreetmap.org, still makes my jaw drop.
- Nextgrid 8y agoI don't see how it's "entitlement" to control what your computer is doing with data it's receiving from the internet. If anything, I'd say it's the opposite site who is coming across entitled when they think not only they can expect to run any crap on user's machines, but also have the right to bitch about it when it doesn't run. In that case, would you also say it's entitlement to be installing antimalware or security updates so malware authors are no longer able to run malware on your computer?
- reitanqild 8y ago> The fact that you're implementing it via reverse proxying is kind of an implementation detail, because at any point it could stop being Google Analytics, or an existing first-party analytics solution on a website could become GA. I think you (probably unintentionally if I understand you correctly) actually just pointed out a good reason why those who really really care should block analytics even from the same domain as the site they are visiting : ) Not that it will help against a determined web site owner trying to track though: Very much of the tracking can be done one the server side (and even proxied from the server side to another third party).
- kevingadd 8y agoRight, my point is essentially that I don't think it's realistic to try and block first-party trackers. They're indistinguishable from page content. The closest you could get would be the 'disable javascript' hammer but there are non-script-based ways to do first party tracking pretty well, I'm sure. I get why people would want or expect tracking blockers to work on reverse proxying but it seems silly to try. On the bright side, if the tracking is being done first-party it makes it much clearer who's taking your data and who's responsible for where it goes - it's going through them even if they're just bouncing it to another server.
- Nextgrid 8y agoThis is akin to bypassing antimalware protection by hosting the malware on your own reputable site. What are you trying to achieve here? Your entire domain will just end up blocked if you do this at scale, not to mention Google themselves would ban your reverse proxy’s IP because of too many queries (since you’ll be proxying all your visitors’ requests from a single IP).
- chrischen 8y agoIf you're doing this "at scale" then people would notice if your domain got blocked.
- Nextgrid 8y agoAssuming your domain is anything of value of course. There are plenty of domains that are technically at scale and yet when my ad blocker blocks a link to it I just go back to the previous page and don’t bother clicking through.
- StefanoC 8y agoIf you were to reverse proxy from the same domain then yes, you'd get blocked eventually. The problem is that creating reverse proxies on random domains is too easy, by distributing this to different domains it wouldn't be possible to block this effectively!
- Nextgrid 8y agoIt would turn into a standard game of cat & mouse just like with signature-based anti malware software. Eventually the world will move on to heuristics and domain-based workarounds will no longer be effective.
- taneq 8y agoTo be fair, self-hosted ads are a thing on some sites and often don't get blocked by adblockers. I know I don't specifically go out of my way to block such ads because they're generally on sites that I'd like to support.
- theironboy 8y agoTechnically, it might be even possible to do reverse-proxy for Google Ads (or any other advertisement)
- deleted 8y ago[deleted]
- rvnx 8y agoNice try but doesn't work on Kiwi Browser ;) Shows "This content should be overriden by GTM". This is because an heuristic is used instead of a blacklist. So to answer, yes this can be blocked easily.
- StefanoC 8y agoThat's interesting, and good to know! I wonder if the heuristic can be bypassed by changing the code (e.g. adding a semicolon) or changing the URL further.
- rvnx 8y agoOf course it can be bypassed and it's not very difficult. It's just that the way of filtering is different (many browsers / extensions are just Easylist/Disconnect clones) To go further on the proxy idea, I think that the best strategy could be to actually do server-side calls to GA: https://ga-dev-tools.appspot.com/hit-builder/ https://ga-dev-tools.appspot.com/hit-builder/ (yes there is an API for server-side hits). The minus of the proxy idea, is that since you don't have access to *.doubleclick.net (which should be blacklisted by any decent track/adblocker) you don't get demographics info back into GA. But after all, like other comments said, aren't you simply a first party tracker ? GA is just a more evolved storage point than, let's say using goaccess on raw logs.
- StefanoC 8y ago> To go further on the proxy idea, I think that the best strategy could be to actually do server-side calls to GA: https://ga-dev-tools.appspot.com/hit-builder/ https://ga-dev-tools.appspot.com/hit-builder/ (yes there is an API for server-side hits). Yes, probably big players would like to use server side analytics! But that's a bit too involved for small websites. > The minus of the proxy idea, is that since you don't have access to *.doubleclick.net (which should be blacklisted by any decent track/adblocker) you don't get demographics info back into GA. When I pull down Google Analytics I also change its content to make it point to the reverse proxy itself. I didn't find any call to that domain being blocked, so I didn't do it for that particular case. I think that the data collections is done via https://www.google-analytics.com/r/collect https://www.google-analytics.com/r/collect, which I do proxy. Notice however that sometimes an easy list filter kicks in and blocks that just because it happens to match "r/collect". I think there is a race condition somewhere that makes it not work sometimes, because I couldn't replicate it consistently. Anyways, it would be as simple as changing that domain specifically to something else. I tried doing so, but Netlify's redirects where playing up (possibly because I'm on the free tier) so I gave up. The concept of masking the domain/url still applies.
- tex5 8y agohttps://rrregain.com https://rrregain.com does this as a service. There are others as well but most do not use your own domain.
- StefanoC 8y agoInteresting, do you know if they rely on the same principle of using several domains, making it harder to block?
- tex5 8y agoI'm not sure, it uses your own domain, thus www.google-analytics.com becomes yourdomain.com/analytics.js. Not all requests are proxied, only the ones blocked by adblockers. Taking this further, you could have your server send an event to GA when /index.html is requested, this can even be from tail -f access_log. No one will know GA was requested.
- rbinv 8y agoIn general, you wouldn't be able to access third-party cookies this way, though.
- pdkl95 8y ago> [ This content should be overridden by GTM. ] lol... pages look better if you send the actual document instead of assuming you have permission to run software in my browser.
- StefanoC 8y agoIt's a proof of concept. If it doesn't work for you then you are meant to know that :) It's not a bug, it's a feature!
- tjpnz 8y agoThose who would consider doing this deserve a special place in hell right next to devs who don't respect user privacy and the crooks in the advertising industry who turn a blind eye to the fact they're distributing malware. By installing an adblocker I've made a conscious decision to not have your BS running inside my browser. Forcing it on me will at the very least result in me disabling JavaScript on all your pages.
- StefanoC 8y agoAs described, rather than disabling js you may want to look into something more complicated, because if you do then the <noscript> side is going to kick in. I think the noscript solution offers less data collection but can still be reverse proxied (try for yourself on the page).
- heliodor 8y agoIf we're going to use ad blockers, at least let's admit to what we're doing and not claim a moral high ground. You're implying the creator of the website is okay letting you receive the service or content on your terms. They are not. Ads and tracking are there because they earn the creators some amount of money. One day when our tech will limit you to a binary choice of ads+tracking versus paying money, which way are you going to swing once your hand is forced?
- mj_olnir 8y agoPaying money. That's an easy choice.
- deleted 8y ago[deleted]
- FridgeSeal 8y agoWe do people who advocate for advertising insist so hard that pervasive tracking needs to be a part of it. If pages were serving up plain, static images, probably free of pervasive tracking, I wouldn’t feel the need to take the nuclear approach to ad tracking. Advertisers have really wrought this upon themselves. I’m actually happy to pay for the media I consume, I actually do pay for some things, but nobody gets their advertising/trackers let through because the whole industry is patently untrustworthy. If publishers want ad revenue from me, they can remove pervasive tracking, it until then, they get nothing.
- beagle3 8y agoMeh. If you're using GA to prove your site's worth, e.g. in some M&A deal, this is useless - your proxying means that you can fudge numbers and thus is no better than anything else you say. (This is a significant use case among looking-for-exit startups). If you're using GA to get insight about your website, it would be somewhat useful, but not really - because GA would not be able to correlate the cookies to figure out the demographics, etc (and I don't know how much it would trust Via / Proxy-for headers, so other statistics it gives you are also limited). Also, if you have non trivial traction, you're going to get flagged by their fraud filters. You're probably better off running a local Piwik or whatever it's called these days.
- StefanoC 8y agoCould you please expand on fudging numbers and fraud filters? The original question that I was trying to answer was if the numbers that I was seeing for mobile users were skewed by how much more difficult it is to get an ad blocker for mobile.
- Nextgrid 8y agoFraud filters is about GA not expecting such a large number of events from a single IP. You’d be sending all your visitors’ events from that single IP - at some point GA will ignore your traffic or give you a captcha (effectively blocking the analytics because it’s not designed to handle the captcha response).
- beagle3 8y agoThen just run an old school analysis on your server logs. Some 20 years ago, I was using webalyzer, it probably still exists and I am sure that are alternatives. Putting google into the mix, through a proxy or not, will definitely skew your results.
- lingz 8y agoIf you are proving your site's worth, you could just use do analytics on anonymized server logs rather than relying on this technique to get GA to work.
- 8y ago
- deca6cda37d0 8y agoI blocked GTM and GA with Little Snitch... your bypass doesn't work
- StefanoC 8y agoPlease explain, I use Little Snitch too!
- Cynddl 8y ago> Hello from Google Tag Manager. This text is being added by a tag running from GTM. One should note that this inclusion, without an opt-in consent banner for instance, is not GDPR compliant. The URL https://analytics-bypassing-adblockers.netlify.com/proxy/https://www.google-analytics.com/r/collect?.. https://analytics-bypassing-adblockers.netlify.com/proxy/htt.... sends personal data to a third party (Google) without my explicit consent. See Article 7 and Recital 32 of the GDPR: > Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject’s agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement.
- ddebernardy 8y ago> One should note that this inclusion, without an opt-in consent banner for instance, is not GDPR compliant. IANAL but as I understand GDPR, this is incorrect. The paragraph you cite discusses personal data. Google's FAQ on GA is instructive (emphasis mine) [0]: > When using Google Analytics Advertising Features, you must also comply with the European Union User Consent Policy. They admittedly keep things as vague as they can, but to me it kind of reads like: using GA to collect site usage analytics is actually fine and requires no explicit consent as long as you've configured it to anonymize the IP addresses (toggle this in GA) and you're not tracking e.g. user IDs and such. Similarly, using GTM to deliver a paragraph like OP did is also fine. In both cases the spirit and the letter of the law would seem to be respected if you add some notice about tracking going on in your footer. No explicit consent is needed here, because no personal data is getting tracked. Edit: clarity. [0]: https://support.google.com/analytics/answer/2700409 https://support.google.com/analytics/answer/2700409
- Cynddl 8y agoThis website does collect personal data. Google's FAQ on GA simply states that the first party should obtain consent before transferring data to a third party (and transfer of consent might not be GDPR compliant, but that's another issue). Here, the first party (analytics-bypassing-adblockers.netlify.com) has to obtain consent before collecting personal data. And IP addresses are not the only personal data that GA can collect.
- userbinator 8y agoIt's an ongoing cat-and-mouse game. This is like the inverse of people using VPNs and proxies to get around filtered Internet, except it's now the server that does the tunneling instead of the client. Personally, I've found that JS off and all the GA/GTM domains (along with many others) blacklisted is sufficient in daily use; no JS gets rid of most of the crap, and the blocked domains clean up the rest. My goal is not to become completely untrackable (I believe that's next to impossible), but just to stop slow-loading pages full of junk I don't care about (which is what I suspect most people using ad-blockers are aiming for.)
- maaaats 8y agoSince it goes through a reverse proxy, wouldn't it not leak personal data the way using it directly would? If using GA directly, the browser uses my google-session data which GA can track between sites/domains. But here the proxy only gets the unique session for this proxy, so it doesn't know who I am. Or?
- StefanoC 8y agoI would be interested in knowing myself. From my analytics dashboard I can tell you that I get some browser data, like language. But I'm not sure if it's safer for the users, or the data is any worse for the tracker! The cookies will be different because the host is different, but I think that Netlify does a good job at keeping the connection like for like.
- StefanoC 8y agoI checked the analytics dashboard yesterday and updated the website: the only data that I'm not getting though is the users country/city and their provider. So in a sense it's better for your privacy: the IP is not your own! I'm not an expert of Analytics but I'm also assuming that since the cookies are different (because the HTTP call to analytics happens on a different domain than usual) it shouldn't be able to track you just as well: G Analytics don't know your IP and have no trace of your previous anonymous IDs set in your cookies!
- Xelbair 8y agoI remember when modern telemetry gathering practices were labeled a malware/adware..
- distances 8y agoEspecially the phone home of ZoneAlarm, that blew up quite big. And to think that's what basically every application does nowadays.
- highace 8y agoI implemented something like this on a site visited almost exclusively by developers, assuming that developers must have amongst the highest adblock usage, and that my real visitor numbers according to GA would be much higher. I saw a boost of about 7-8%. Remember, most adblockers (like Adblock Plus) don't block Google Analytics. uBlock and Ghostery are probably the 2 main GA adblockers, but as a % of adblockers as a whole they're not that large. It's probably not worth it.
- judge2020 8y agoWould like to know, does Google Analytics actually use data for tracking/ad targeting? I thought it would only track users if they embedded the AdWords script. If so, why is it blocked by UBO and Ghostery?
- mcintyre1994 8y agoI've always just assumed it does, in the same way I assume Facebook's like etc. buttons do plenty of tracking even if you don't interact with them.
- rbinv 8y agoIf enabled, it does provide targeting capabilities (by tracking across multiple key domains).
- steve76 8y agoWhat if your DNS resolver on your server gets exploited? All your users are now running someone else's scripts. This happens on client machines. They install something which resolves GA's domains to their server, and leaks all the user's passwords or runs junk that serves their ads. The problem with your solution is if someone did everything right, and goes to your URL, they are exploited, as oppose to one user on one hacked client. It puts you at great risk and more responsibility on you to secure your server which is resolving the GA script. And doesn't GA have protections to prevent someone copying the include tag on their site? Wouldn't you have to turn that off to pull down that tag server side? If it gets widely adopted, anyone can copy anyone and analytics are worthless.
- deleted 8y ago[deleted]
- stunt 8y ago:popcorn:
- everdrive 8y agoThis is unfortunate, but it simply means that we have three options: - Block entire domains - Prevent javascript from running - Use the internet less, read books, use your local library. Happily, I was able to get my browser from the default message: Hello from Google Tag Manager. This text is being added by a tag running from GTM. To the blocked message: This content should be overridden by GTM. But, how far will this game of cat and mouse go?
- ionised 8y agoNo personal offence intended, but I hope this project dies on its arse. It's malicious software, circumventing the protections afforded to me by my ad/tracker blocking software. I'll contribute in any way I can to adblocking tech, and to any impotency of this kind of technology.
- StefanoC 8y agoNone taken. Believe it or not I'm mostly on your side. I published this because I've managed to do this in 4 hours, for fun. It exploits the url based blocking which is so prominent but so easily subverted, and If I've done it anybody can, so I wanted people to know. Having said that, I must add, I don't think this is malicious software. Beside the legalities and the GDPRities which I may have overlooked, when you ask a website for its content that comes with analytics, but you want to block analytics. I don't think you can complain about the content provider bypassing your attempt at blocking it. Don't get me wrong, when I come across websites that stop me from browsing them because I use uBlock I usually bypass their block, or close the tab, but I can hardly complain at their attempt, or deem it as malicious, IMHO.