4 ms·
I have yet to see a real whistleblower report by someone deep into the ad industry revealing whats really going on there. There are almost no details about what
by user17843 7y ago
I have yet to see a real whistleblower report by someone deep into the ad industry revealing whats really going on there. There are almost no details about what's really happening on a technical level (beyond the little things we already know), and whether large data sets are abused in the sense that they get routinely de-anonymised.
- otabdeveloper3 7y agoThere's nothing to whistleblow. Advertising is applied sociology. As such, advertisers want to aggregate large data sets into large segments that are easy to manipulate statistically. (Where the central limit theorem starts working.) There is no demand for personal data or de-anonymization because that stuff doesn't sell. The personal data collection is done by Google, Facebook at al not for advertising purposes. They're collecting it because they view it as a resource and a currency in the future de-anonymized world. (Think China's "social capital" except on a larger scale.) Source: I've worked in the ad industry for over 15 years.
- everdrive 7y agoI think in some circles the meaning of the term "whistle-blowing" has drifted enough that people use it interchangeably with "reveal." Given your 15 years of experience, what resources do you recommend to HN so that we can learn more? Can you give us a "life of an advertising bit," eg: A person visits a website on their phone, that information is accompanied by x data on their phone, goes to the initial ad server, this information is compiled against data from sources a,b,c, etc ...
- user17843 7y agoMy question to someone from the ad-industry would be if there are known "intersections" between these anonymised data sets ad-tech is using to sell as much as possible, and companies who buy these data-sets to connect them to real identities. Especially because the web is full of Privacy notices people agree to, and I guess in some of those people actually agree to have their anonymous browsing data connected to their real identities.
- otabdeveloper3 7y ago"Known"? Probably not. Like I said, knowing real identities is the last thing on the list of ad tech priorities. If shadowy entities are collecting "real identities" then it's not for ad purposes.
- cik2e 7y ago> There is no demand for personal data or de-anonymization because that stuff doesn't sell. Say what?? I’ve also worked in the ad industry and deanonymized personal data is shared and sold routinely. You speak of statistics and large segments but every advertiser I’ve interacted with is either doing individual-level targeting or striving towards it.
- nerdponx 7y agoTo wit, A few weeks ago there was a discussion here about a method by which you could figure out how fast a browser/machine could compute an SHA 512 hash, and that this was being used to fingerprint users even who had cookies, images, JavaScript disabled.
- SquareWheel 7y agoWas it just a proof of concept demonstration, or was there evidence that this method is being used in the wild by advertisers?
- nerdponx 7y agoThey stated that they were using it in production for that purpose.
- SquareWheel 7y agoGotchya, thanks. That seems... kinda wild to me. That method has to be super imprecise, and wastes the resources of everybody involved.
- bo1024 7y agoI would like to see more. How can you get their computer to compute the hash? Is it somewhere in the https interaction?
- nerdponx 7y ago
- ramraj07 7y agoThis comes from discussions and lectures from people working on engineering in some ad aggregstors - at least one said that in the end, they have a table with 300 million IDs for each person in the country and they key all the data they can link to that person with this id. In principle this data is annonymized. But does that make a difference? At least in health care people worry about hipaa and do audits to minimize reidentification risk but I'm not sure if adtech companies do anything like that. So yes, a good data scientist can find any person they want from the data but even otherwise I think these companies can work on a fairly meaningless definition of annonymization to get away with all this crap.
- adrianN 7y agoIt's basically impossible to anonymize data. There a numerous papers about how little data is enough to uniquely identify people. Things like the zipcode where you start your commute and the zipcode where your commute ends are enough to identify the vast majority of people.
- telchar 7y agoIt's impossible to anonymize some data. If you're including demographics and locations then yeah, it's going to be hard or impossible to anonymize. If you're using surveys on emotional state or perhaps newsgroup comments? That's not so hard.
- tonyarkles 7y agoIn our case, the postal code (Canadian) and almost any other piece of data is uniquely identifiable. Through a quirk in the layout of our street, my wife and I have the only house in our postal code. Add age, gender, birth month, hair colour, t-shirt size... pretty much anything, and you’ve reduced from 2 possibilities to 1. I still want to try dropping a letter in a mailbox from a different city with just our postal code written on it and see if it arrives.
- geocar 7y agoWhat the author is referring to is usually branded, so it's difficult for people on the sales side to give details without revealing who it is unless you're in the weeds (technically), and I'm sure you can appreciate why they might not want to, so here's the gist: - Companies collect a number of "records" keyed to an email address. How they do this varies from running microsites/forms that collect data directly from people, to scraping linkedIn and resumes. - Data vendors will share this data with each other by hashing the email address. Almost always with md5, and rarely salted. This means you can enrich data both anonymously (by relying on the fact the email address is unsalted) or in an identifying way (because one of the parties has the real email address). In both cases, it's just a LEFT JOIN.
- username444 7y agoIt's much worse than that. I've been approached by a company that trades e-commerce transaction data, for personal data tied to IPs. As in, you give me your customer data, and I'll tell you who visited your site based solely on the IP address. We declined, but it's tempting.
- geocar 7y agoNo, that's exactly what I'm talking about: They'll buy the md5-email-to-cookies from one provider (e.g. Lotame, Liveramp, etc) then use that to onboard email+contact data they've purchased from companies that have email address-to-personal data (e.g. MVF, ZoomInfo, etc). IF that was done as purely a lead qualification step, it's a good way to take legitimate content syndication done by a third party into direct marketing, but there's no technical reason they need to be leads or have any level of qualification -- and only a weak market force (poor conversion rate) that prevents it from being more widespread.
- tomrod 7y agoI worked some in marketing and targeting modeling within retail finance. From what I saw, the data privacy rules and client contracts are followed scrupulously, and infractions are noted and remediated. Encryption slowed us down at least 10X,and bureaucracy another 10X. While frustrating at times, I appreciated that most if not all actually wanted to stay well within the legal guardrails. Of course, this is one person's experience, and obviously can't apply to every company. Genie and cork, toothpaste, and all that.
- titzer 7y ago> legal guardrails What many companies do is they sprinkle some magic "anonymous" pixie dust on their data and then tons of laws no longer apply, even if the data is trivially identifiable stuff. And location data is often of that nature.
- tomrod 7y agoThe will is there sometimes to attempt this, which is why following risk procedures is tied to performance ratings at better companies. Companies also delete data after specified time, as required by numerous legal entities. And engage with third party matching services so that personally identifying information is salted and hashed until the print shop Etc.
- luckylion 7y agoDo you know whether there are actual audits happening by third parties? I've never had anything to do with ad tech, but the (few) certification processes I've been involved with were largely documentation and "yes, we do have backups. no, unauthorized persons cannot access our servers" promises without anybody actually auditing/testing. Do they have independent auditors regularly look at the tech and operation to verify that they actually do conform with the laws and don't just claim to?
- tomrod 7y agoMany. It represents a massive cost. Hence the emphasis on employee incentive to do the right thing in the first place. Further, any time there is a broad news story (e.g. Wells Fargo's bogus accounts) or legal item in pipeline with broad impact, you can be assured every company looks to make sure they aren't in bad shape.
- rolltiide 7y ago> I have yet to see a real whistleblower report by someone deep into the ad industry revealing whats really going on there. Its because nobody cares until Congress starts hauling in software developers and "data scientists" from tech startups, everyone is content watching Zuckerberg be the face of society's discontent. As long as they keep asking the wrong people the wrong questions there is no need for everyone else to acknowledge their role in the problem.