29 ms·
Why is Stack Overflow trying to start audio?
- synthmeat 7y agoIt's most likely for web scraper detection. State of the art was using video codec availability as fairly reliable data point, and I haven't seen audio being used for this. Quite interesting.
- jupp0r 7y agoWhat makes you think it would be for web scraper detection vs user fingerprinting?
- synthmeat 7y agoBecause they had a lot of trouble with sham sites generated by their content.
- icebraining 7y agoThey literally provide full website dumps of all the content: https://stackoverflow.blog/2014/01/23/stack-exchange-cc-data-now-hosted-by-the-internet-archive/ https://stackoverflow.blog/2014/01/23/stack-exchange-cc-data... (yes, the post is old, but they still update the archive).
- yjftsjthsd-h 7y agoIs there a difference? I mean, slightly different ends, but both very much benefit from fingerprinting.
- jackdh 7y agoHas there been any serious thought / discussion about how the cat and mouse chase of the ads vs ad blockers is going to end? It would be interesting to see where we are in ten years.
- eof 7y agoSeems obvious without thought to me that it’s mostly moot. Very few people will be running machines like we have for the last 30-40 years, most will be on Android/iOS where ad blocking will be minimal. Savvy users will continue to block on machines that aren’t walled gardens and through pi-hole style blocking. I think the cat and mouse aspect will be completely overshadowed by tech giants continually neutering their users ability to block ads.
- saagarjha 7y ago> most will be on Android/iOS where ad blocking will be minimal Safari on iOS allows for content blocking, and Firefox for Android allows users to install extensions.
- danielg6 7y agoI guess your parent post should have given it some more thought lol
- mattigames 7y agoOn android many links are open in a Webview (e.g. opening links on Gmail app) and many ads come through webviews inside apps themselves (e.g. some ads inside the youtube app itself)
- jimktrains2 7y agoYou can install hostfile blocking on rooted android devices.
- mattigames 7y agoWe need a solution that works for the average Joe, rooting devices don't fall in that category.
- eof 7y agoSafari on iOS allows limited content blocking. It doesn’t allow ad blocking anywhere else, which is most of the platform. And, I was referring to the future and trends rather than the current situation. System wide ad blocking used to be possible on iOS without jailbreaking, now it’s not. I expect in time google will go similar and change android APIs, or play store rules, to do similar.
- ReedJessen 7y agoIs this a scandal?
- dymk 7y agoIt's 2019, everything is a scandal
- dRaBoQ 7y agoAnd everyone is outraged.
- ProAm 7y agoNo but SO has always prided themselves on reasonable, pro-consumer, safe advertisements. So the fact that SO is allowing this speaks to them a little, its unlikely they know whats happening but it's still a little gross.
- kapep 7y agoI don't think it's a scandal. It's not new or surprising that ads use tracking techniques like this. Stack Exchange recently announced [1] that they will use ad networks as an experiment. That announcement was quite unpopular and met with resistance and pleas to allow only static images to avoid annoying ads as well as sophisticated tracking. So this is no scandal since they were open about it and knew the risks. It seems they ignored the community though so they probably lost some trust by the community. I wonder if they will take action and stop the experiment. [1]: https://meta.stackexchange.com/questions/329763/were-testing-advertisements-across-the-network https://meta.stackexchange.com/questions/329763/were-testing...
- superasn 7y agoMaybe it's to identify users behind a VPN as this is fingerprinting the device, not the connection. That's why I think the idea of running each site in a container is so effective. And while we're at it the container should just spit out random shit like different resolution, audio api, user agent, once in a while (unless the user turns it off) to thwart such attempts. Unfortunately when the creator and maintener of 67% of all browsers is an ad company who is exploiting this in the firsr place, then there is no chance that this could happen
- apetresc 7y ago> And while we're at it the container should just spit out random shit like different resolution, audio api, user agent, once in a while (unless the user turns it off) to thwart such attempts. Wouldn't that break the legitimate feature-detection uses for these APIs? Asking the user to identify and whitelist each call is impractical, especially since the fail-case in this scenario would be subtle (you'd still see the page but it might randomly be in the wrong mode, or images might be scaled incorrectly, etc). At that point you might as well just turn Javascript off.
- superasn 7y agoYes I thought about it that's why "unless the user turns it off" comment in parens. I think out of 100 sites I visit everyday no website needs to access the audio api without my consent maybe except one or two which i can whitelist. Same for user agent, I don't think it should break if the container says I'm running firefox v65 or v67, etc.
- amadeusw 7y agoDoes Microsoft (ad owner) or Google (ad provider) perform the fingerprinting in this case?
- dymk 7y agoGoogle
- dudus 7y agoIt seems that the specific script comes from https://integralads.com/ https://integralads.com/ as stated by another commentator. I think the blame is to be shared here. integralads is guilty of developing and selling this technology. Microsoft is guilty of buying it and using it Google is guilty of serving it. And why not also StackOverflow is guilty of offering that space to advertisers without enough vetoing of their ads. After reading about integralads I'm not even sure if the purpose is to fingerprint, it seems to be more targeted towards detecting fraud, which does not require fingerprinting necessarily. My point is that it's not as easy as pointing to one company and blaming them. This is a problem that concerns anyone on the Ad space.
- inglor 7y agoWhy is this surprising to anyone? It is clear that ads use tracking mechanisms and cookies and this is no different. Audio feature detection isn't even a novel techique. I've seen trackers look at download stream patterns to detect whether or not BBR congestion control is used, I have seen mouse latency based on the difference between mouse ups and downs in double clocks and I have seen speed-of-interaction checks in mouse movements. Just checking for the constructor of something an ad might legitimately use (like audio) is relatively benign to be honest and it is naive to expect ads to not do this and it is why I use an ad blocker even on sites without annoying ads
- inglor 7y agoAnd as a fun fact networking timing fingerprinting attacks and work even if you don't have JavaScript enabled and I have been able to make a PoC that was very accurate (I did not release it but I did disclose some bits to relevant parties)
- saagarjha 7y agoI hope "relevant parties" includes "browser vendors" and not "adtech companies" :)
- inglor 7y agoYes of course, browser and OS vendors.
- function_seven 7y agoWhich one is Google?
- ehsankia 7y agoBut for code that's supposed to be so smart in trying to fingerprint people without them knowing, calling an API that throws a warning in the browser seems like a really stupid move. Especially since that can be checked through feature detection, which is literally what this code is doing...
- JimBrimble35 7y agoAside from the obvious usability benefits, this kind of thing makes it abundantly clear why much of the web has gone to javascript dependent SPAs. If you need JS to run the site, then you also have to leave it on to be tracked/fingerprinted. Kind of makes sense why companies like Google and Facebook have invested so much in creating open-source front-end frameworks. The ROI is probably phenomenal. I get that stackoverflow isn't an SPA, it just made me think of this point. Side-note: you can block JS on stackoverflow and still view answers. That works for 98% of my usecase for the site.
- __jal 7y ago> If you need JS to run the site ... Then I move on. Those dorky little crapware widgets are basically never worth looking at in any case, and I do take that sort of strategic tooling decision as a signal that I probably don't want to accept the 'bargain' being offered.
- JimBrimble35 7y agoThat's fair, my point is that in many cases (a rapidly growing number of cases), the entire site is JS. If you need to service, then you have to accept the tracking.
- captn3m0 7y agoA little bit of corporate newspeak (and digging): Ad URL: https://static.adsafeprotected.com/sca.17.4.95.js https://static.adsafeprotected.com/sca.17.4.95.js JS Domain: adsafeprotected.com Domain Owner: Integral Ad Science, Inc[0] Google's recent stance on the matter of fingerprinting[2]: >Chrome also announced that it will more aggressively restrict fingerprinting across the web. When a user opts out of third-party tracking, that choice is not an invitation for companies to work around this preference using methods like fingerprinting, which is an opaque tracking technique. Google doesn’t use fingerprinting for ads personalization because it doesn't allow reasonable user control and transparency. Nor do we let others bring fingerprinting data into our advertising products. The important part being: _Nor do we let others bring fingerprinting data into our advertising products._ The same company advertises their fingerprinting capabilities: >Browser and Device Analysis: We analyze the technological fingerprints of browsers and devices in order to uncover bots fraudulently posing as human users. We can validate what type of mobile or desktop device a browser is running on, providing additional context with which to identify fraud. And it is this fingerprinting that gets them selected as a Google Brand Safety and Viewability Preferred Measurement Partner[1] >New York, NY – Integral Ad Science (IAS) has been selected as a preferred partner in Google’s Measurement Program for both brand safety and viewability. Partners were selected after meeting rigorous standards for accuracy and using reliable methodologies to measure KPIs that matter for marketers. The program is designed to make it easier for advertisers to source trusted, third-party measurement providers. The gist of it being that Google has heavy cognitive dissonance, with their advertising wing rewarding partners that fingerprint users (against their own policies), and the Chrome team barely managing to introduce some anti-fingerprint measures, which are clearly not enough. [0]: https://integralads.com/capabilities/ad-fraud/ https://integralads.com/capabilities/ad-fraud/ [1]: https://integralads.com/news/google-selects-ias-brand-safety-viewability-preferred-measurement-partner/ https://integralads.com/news/google-selects-ias-brand-safety... [2]: https://blog.google/products/ads/transparency-choice-and-control-digital-advertising/ https://blog.google/products/ads/transparency-choice-and-con...
- pdkl95 7y ago> Google has heavy cognitive dissonance Perhaps, but I think some of that behavior only appears dissonant. Like the NSA, Google often uses carefully constructed language that is designed to sound like a statement about a topic of concern without saying anything actually useful. For example: > Google doesn’t use fingerprinting for ads personalization The only reason to add "...for ads personalization" is if they are using fingerprinting for for other purposes. This could include other ad-related purposes like attribution. Google claims about not using specific data for a specific purpose are probsabl7 true. They simply fingerprint (and probably correlate) everything else.
- rkagerer 7y agoTLDR: A case of invasive fingerprinting triggered by a Microsoft ad delivered by Google.
- rkagerer 7y agoAre all fingerprinting techniques used in the wild pretty generally well-known? Do any browsers have an option to blindly return a standard set of values regardless of actual client capabilities/metrics? (i.e. make it difficult to achieve more granular results than browser agent). I know Mozilla made an anti-fingerprinting announcement recently but IIRC all it does is check scripts against a blacklist: https://blog.mozilla.org/futurereleases/2019/04/09/protections-against-fingerprinting-and-cryptocurrency-mining-available-in-firefox-nightly-and-beta/ https://blog.mozilla.org/futurereleases/2019/04/09/protectio...
- sfink 7y agoThere's an option in Firefox, yes. privacy.resistFingerprinting or something, you can search for it. It tends to break a number of sites, iiuc.
- kabwj 7y agoIf you don’t use an ad blocker you should expect your browser to behave in strange ways. If you don’t use an ad blocker you should consider your computer compromised.
- penagwin 7y agoIt's been known that ads are commonly used to spread viruses / invasive tracking for years. And I've used adblock for almost 10 years! Honestly, how are still allowed to execute javascript at all?! I get it if the ad-manager still executed javascript, but how is it okay to let random 3rd parties run js on your website?
- johnwheeler 7y agoI wonder if the top brass at alphabet ever worry that their trillion dollar empire is based on fragile foundations like web audio fingerprinting, etc. that sure would keep me up at night. obviously, i know google does more, but it seems like a large chunk of their revenue must be dependent on shady technical tricks like these working.
- colinbartlett 7y agoThey realized it was a risk so they built their own browser to have more control. And it worked. Only now, users are wising up and moving to Firefox.
- gdw2 7y agoIs firefox less fingerprintable?
- jes 7y agoI'm not an expert, but I'm running Firefox Nightly for exactly that reason. https://blog.mozilla.org/futurereleases/2019/04/09/protections-against-fingerprinting-and-cryptocurrency-mining-available-in-firefox-nightly-and-beta/ https://blog.mozilla.org/futurereleases/2019/04/09/protectio...
- lloydde 7y agoIt looks like the related feature is now in the regular release.
- butteroverflow 7y agoWhat's your user agent like? I would imagine there are not many Nightly users out there.
- a012 7y agoStill there are a lot of information in your user-agent and metadata (OS version, platform, screen size, timezone, and more).
- miohtama 7y agoI like the comment on SO: "Deanonymizing via fingerprinting - illegal in EU"
- 6gvONxR4sf7o 7y agoI would love for this to be illegal.
- dymk 7y agoThank God we live don't live in a direct democracy
- nvr219 7y agoAlways use ublock (origin)
- mappu 7y agoThere's something up with my PulseAudio (maybe changing audio output formats?) that means i hear a very loud "pop" when pages try to do this. e.g. Browsing to an arstechnica.com article, with speakers on but nothing else playing.
- draw_down 7y agoThat sounds annoying. I don't think I would want my desktop environment to do that.
- meerita 7y agoDid anyone checked how much data from our data plan cede to advertising? I bet it's 30%-40%.
- chance_state 7y agoI have been using uBlock Origin for about three years and I browse the web heavily (4-6 hours/day). In that time it has blocked 13% of requests (10% on mobile). I don't have enough info to quantify the amount of data blocked though.
- gorhill 7y agoIt's often the case that what is blocked prevented more scripts to be pulled, which scripts could pull even more scripts and so on. Those subsequent waves of scripts are not counted as blocked because they never had a chance to be pulled by the first wave of blocked scripts. I have a tweet in my timeline which illustrate this: https://twitter.com/gorhill/status/934474012377444352 https://twitter.com/gorhill/status/934474012377444352
- chance_state 7y agoMakes sense, thanks. How does uBlock calculate the "blocked since install" percentage?
- meerita 7y ago10% on mobile isn't that bad. It's quite a lot!
- meerita 7y agoI tried to check my uBlock stats, but it didn't worked well. It seems on Firefox doesn't fully works.
- EGreg 7y agoI don’t get how it can get the fingerprint to be so unique as to attribute ads. Most mobile browsers are exactly the same, you have the same screen resolution and so on. And most desktop browsers when maximized are the same resolution. I mean there must be groups of thousands of users for each combination of fingerprinted features. So it’s not all the way down to the person, right? It’s just correlations?
- appleiigs 7y agoNo, it's not all the way down to the person. Yes, it's just correlations. Even if the fingerprint was so unique and it went down to 1 user, it wouldn't be able to actually identify that person's name etc. The most likely use-case here is ad fraud detection anyway.
- Cpoll 7y ago> The most likely use-case here I'm not so sure. There's a lot of market value in knowing that User 2341423 went to Site A, then Site B, then bought this item, etc.
- jupp0r 7y agoYou can try out https://panopticlick.eff.org/ https://panopticlick.eff.org/, which estimates the entropy of information they can extract from your browser. For me it's ~18 bits, which isn't great but probably enough to infer who I am if tracked across multiple sites. They don't even use the more exotic things like audio devices/codecs mentioned in the stack overflow question.
- hyperpape 7y agohttps://amiunique.org/fp https://amiunique.org/fp gives a unique fingerprint for both my Mac and my iPhone. To be honest, I don't know how they manage to fingerprint the iPhone, but they claim it's a unique fingerprint.
- helloworm 7y agoHas anyone made a plugin that does a DOS on each ad server(s) detected? Then, we have built-in DDOS on the ad servers, if enough users install it.
- anfilt 7y agoWhile the idea is cute you do realize that would have criminal repercussions for people who install said plugin in certain countries.
- progval 7y agoNot exactly a DoS, but there's a browser extension designed to click on all ads and blur the signal: Ad Nauseam
- icebraining 7y agoGood luck getting that past the Chrome Web Store censors. I doubt even Mozilla would accept it.
- iamnotacrook 7y agoIt's ok. SO's policy on abusive ads is to mention it on mets and hope a moderator notices and then acts upon it.
- TheOtherHobbes 7y agoIronic that content moderation is annoyingly aggressive, but ad moderation is annoyingly permissive.
- fredsanford 7y ago>> Ironic that content moderation is annoyingly aggressive, but ad moderation is annoyingly permissive. It's not ironic at all if you think about it a bit. >>annoyingly aggressive, Volunteer labor from nerds who expect you to match their idea of perfection >> ad moderation is annoyingly permissive Done by employees so it costs SO money.
- gortok 7y agoAs a community elected moderator (https://stackoverflow.com/users/16587 https://stackoverflow.com/users/16587 ) I can tell you with certainty that moderators have no control over ads; only the development (and maybe the community team). In this case we would do the same thing the OP did, in addition we would reach out in Stack Overflow chat to the community team do inform them of the situation.
- iamnotacrook 7y agoWell perhaps you should get your story straight because on this page: https://meta.stackexchange.com/questions/329763/were-testing-advertisements-across-the-network https://meta.stackexchange.com/questions/329763/were-testing... which is being prominently announced in a yellow "featured on Meta" box you can read: "If you see any ads that are inappropriate or have any questions about this experiment, please let me know by starting a new question and tagging it with advertising" and "If you wish to report an advertisement, please take a screenshot of the ad and paste the URL (if possible) along with the site where you saw it to a comment or answer. I'll report it to the ads team and we can track it down to investigate." Screenshots? Start a new question with a tag? Track it down? Shouldn't you cut to the chase and have a "report this ad" button built-in so you can immediately be alerted to malware/abusive/inappropriate ads? Perhaps it's not moderators who have the power here. As a non-moderator/employee I couldn't care less what you call the people who do it; it seems entirely inadequate. Run the ads now and if enough people complain or it gets embarrassing - like google and/or microsoft spying on users - then publish a theatrical apology. No, that doesn't work for me. No, my ad-blocker is never coming off.
- Nick-Craver 7y agoI just wanted to chime in from Stack Overflow here and let people know: we are aware of the issue. And we're NOT okay with it. We're trying to sort out how to kill the audio behavior now. It's not very straightforward to find where it's coming from, but we are working on it. We've also reached out to Google for their assistance in tracking it down. If anyone can offer advice, we'll more than happily take it. - Nick Craver, Architecture Lead at Stack Overflow
- detaro 7y agoNot sure how that plays with rules about how you can place ads etc, but <iframe> with a feature policy can stop access to audio I think.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- coldpie 7y agoWhy are you allowing arbitrary javascript to be served to your users?
- wlesieutre 7y agoNot just arbitrary JavaScript, arbitrary JavaScript where they can’t easily even see where it came from! Sheesh. Could we require advertisers to sign their ad code to have a trail of where it came from, prevent tampering, and make it easier to pull the plug on bad actors? The people bearing the costs of the internet ad economy aren’t the people in any position to do anything about it. So there’s very little pressure to fix anything. Maybe if the US government started threatening to enact something like GDPR unless the a democratic industry gets its shit together.
- manigandham 7y ago
- dabeeeenster 7y ago"It's not very straightforward to find where it's coming from, but we are working on it." This encapsulates the entire problem with the current state of digital advertising in 1 simple sentence.
- keyle 7y agoBut you know, we wouldn't stop serving ads until we work it out... no no imagine the loss in revenues.
- craftinator 7y agoLet's be adults here. This is SO, and I imagine you've used and enjoyed the use of their services just like the rest of us. Support them by letting passive ads sit on the edges of the page, and appreciate that they are actually trying to solve this issue.
- keyle 7y agoI want to agree with you, but "passive ads sit on the edges of the page" is a false argument.
- muckrakerz 7y agoNo. We got content without this in the past, and we can do this in the future. And I will note THEY admit this is bad. Stop trying to defend the indefensible.
- manigandham 7y agoYou didn't get Stackoverflow, and barely any of the content today. You may be fine with the internet of the early 90s but most people are not.
- zrobotics 7y agoWho paid for the content I actually visit StackOverflow for? It surely wasn't SO; they provide a nice platform but they also get that content for free. This isn't a journalism site, the value in SO comes from freely provided user answers. Yes, SO provides some value vs. forums via their q/a platform, but it is a marginal amount of value. Sure, SO is easier than parsing a forum thread, but the actual value that I care about is the answers provided for free by their users. I could easily return to 90's era usenet, it wasn't as convenient but it worked. What I couldn't deal with is a lack of a platform where people ask technical questions & get answers, I remember being on dial-up and reading paper manuals that were out-of-date/incomplete. But SO isn't irreplaceable, and I am oftentimes frustrated with finding questions closed for incorrect reasons, normally my answer is buried 2 links deep in SO because my DDG search (and Google too) takes me to an improperly closed question where the 'previously addressed' question is adjacent to my query. StackOverflow does not provide an irreplaceable service; like github they do some nice things but there isn't any reason they must be the dominant platform. And the real value is in the answers, which SO gets for free.
- sergiotapia 7y agoIs there something I can use to randomly fuzz every tab individually as I browse the web? They can track me through websites and I don't want that. Already using ublock origin.
- kevin_thibedeau 7y agoNoScript + Decentraleyes + Random user agent + Self-destructing cookies.
- fimdomeio 7y agoNot exactly what you asked for but got this from mozilla today: https://blog.mozilla.org/firefox/hey-advertisers-track-this/ https://blog.mozilla.org/firefox/hey-advertisers-track-this/
- kylegordon 7y agoAnd this is why, even with the best intentions of site operators, my browser will continue to use the best ad-block tools I can get, and my networks will be protected by tools like PiHole.
- MRD85 7y agoIn the 2005 era when I was a young video gamer I used to play World of Warcraft. There was a site, Thottbot, that players would use to find out information about things in game. I picked up a keylogger malware from their adservers. One of the advertisers had been hacked and was serving Malware every few thousand ads. Since that day I've used an adblocker and I'll always continue to do so.
- mrosett 7y agoI wonder if that’s how I got hacked....
- jimmaswell 7y agoThis seems melodramatic for something as trivial as an audio request.
- yifanl 7y agoArbitrary code execution isnt really that trivial.
- jimmaswell 7y agoArbitrary javascript execution is generally meaningless. Very rarely you'll get a zero-day or something, or maybe a site will use too much battery when focused.
- JetSpiegel 7y agoBut if that page is Stack Overflow, with millions of views, you are collectively wasting tons of power. Granted, you don't pay those bills.
- ndiscussion 7y agoHow We Make Money at Stack Overflow: 2016 Edition: Quality ads. "...we don’t want to use an automated system that selects some ads for us. We looked at this. It didn’t allow us the control we required to maintain the level of quality we want to maintain." How We Make Money at Stack Overflow: 2019 Edition: Taking money from Microsoft and Google fingerprinting our users 100+ ways source: https://stackoverflow.blog/2016/11/15/how-we-make-money-at-stack-overflow-2016-edition/ https://stackoverflow.blog/2016/11/15/how-we-make-money-at-s...
- rsj_hn 7y agoYour options, as I see them. 1. Text based ads only (no third party js) 2. HTML based ads but no js (run it through DOMPurify https://github.com/cure53/DOMPurify https://github.com/cure53/DOMPurify) 3. Look for a js sandbox -- this _will_ break arbitrary js, will not be supported in all browsers, and will require dev work on your side: * Google Caja https://github.com/google/caja * MentalJS https://github.com/hackvertor/MentalJS other options are available as well, in varying levels of maturity and support. I think using a sandbox iframe is not going to be able to defeat browser fingerprinting, because the sandbox control options are not rich enough. You would need to block all JS.
- lostmsu 7y ago> HTML based ads but no js (run it through DOMPurify https://github.com/cure53/DOMPurify https://github.com/cure53/DOMPurify) Or use iframe.sandbox, which was designed for it. https://www.w3schools.com/tags/att_iframe_sandbox.asp https://www.w3schools.com/tags/att_iframe_sandbox.asp
- rsj_hn 7y agoUsing an iframe sandbox has some issues: 1. scrollbars and positioning can cause problems with iframes that an inline div doesn't have, especially if there are multiple small iframes on the page. 2. As soon as you allow script in the sandbox iframe, then you are susceptible to these types of fingerprinting attacks. The fact that you have origin isolation doesn't really block what the ad was doing. This is because iframe sandbox was never designed to block fingerprinting attacks, it was design to create a separate origin that gave the dev broad control over features like 'allow js' 'allow access to origin', etc.
- miguelmota 7y agoSeems like classic fingerprinting behavior from Google Ads. It's unfortunate and hope they fix it quick but most importantly figure out a way to prevent it in the future
- ploxiln 7y agoIt's pretty obvious that the only real fix is to accept money in exchange for putting an image with a hyperlink on your website. Anything involving javascript will do shenanigans for various reasons. Fingerprinting via any means possible is industry standard ad-network behavior at this point. No one in the industry could imagine doing any less - it's impractical, it's absurd. But targeting! But fraud! But the only fix is to just give it all up, go back to how it was done in the 90s.
- jasonjayr 7y agoWhy can't Google come up with an AMP for ads? That will transpile a restricted javascript (or whatever) into a runtime that just doesn't do these things? This would get rid of the greasy ads, and Google could focus on making tools that allow site owners to filter by "features used in ad", and ad developers could actually return to delivering ads, rather than collecting fingerprints?
- progval 7y ago> That will transpile a restricted javascript (or whatever) into a runtime that just doesn't do these things? They already invented that: https://github.com/google/caja https://github.com/google/caja "Caja uses an object-capability security model to allow for a wide range of flexible security policies, so that your website can effectively control what embedded third party code can do with user data."
- skoocda 7y agoHere you go: https://amp.dev/documentation/guides-and-tutorials/learn/intro-to-amphtml-ads https://amp.dev/documentation/guides-and-tutorials/learn/int...
- patriciaosvaldo 7y ago"Thank you very much! HACKNET CREDIT SPECIALIST to date, I have been quite pleased with his service and happy to report that my credit is very good and up to standard now. I have not been able to get a normal credit score for the past 5years, however, after contacting HACKNET CREDIT SPECIALIST just 3weeks ago and explain my credit situation to him and how I was turned down by Lexington Law several times trying to get my credit fixed. He boost my score to 800 excellent credit score and got rid of all negative items, student loans, collections and hard inquires on my report. I’m now enjoying a good rating of credit score. I am approved for most credit lines that I apply for — at good rates. I will continue to endorse his service. Contact him today and get all your credit issues fixed (HACKNET567@GMAIL.COM / +1 949 397 8437)
- zaphirplane 7y agoIf this is caused by accepting JS enabled ads. What’s to stop the ad from changing the dom or redirecting the browser to a SO fishing site
- z3t4 7y agoI guess it's part of Googles Ads's endless battle against "robot" clicks. A site as big as SO should not use Google ads, but instead use their own ad service. Just make an automated system where people can signup and show an ad. Make it cost 1$ per 100 page views. That would probably earn SO two orders of magnitude more then they get from Google Ads.
- cameronbrown 7y ago> $1 per 100 page views Eh, that's like 10x average CPM nowadays. And advertisers usually are paying per click, not impression.
- z3t4 7y agoAs an advertiser, yes, but on Google Ads you know that 90% of those will be fake ¹. And as a publisher on Google Ads you only get something like 1$ per 10000 impression ². Advertising directly on SO you know all views are not only legit, but also target at developers, so I think advertisers are willing to pay more. While most advertisers are paying per click, the whales only care about impressions, not clicks (TV commercials). 1) Measured by analyzing the traffic I got from Google Ads 2) That's what I get from Google ads as a publisher, but you used to get a lot more in the epoch, like $5-10 CPM
- cameronbrown 7y agoIs such a high fake impression rate common on the display network?
- ddtaylor 7y agoHow about stop letting remote sites execute arbitrary Javascript on your pages?
- crispyporkbites 7y agoAs a website publisher, is there an ad network available for me to use that doesn’t allow advertisers to run JavaScript? If so, what kind of rates can I get?
- thelazydogsback 7y agoThis issue (along with many others) is due to one simple fact -- the internet is still primarily about presentation and rendering not information. We had both client-side template-based rendering and Semantic Web initiatives -- these failed for various technical and non-technical reasons at the time, but I'm hoping we go in that general direction again at some point. Nobody else should be able to (definitively) decide what information I want and how it should be presented to me. We only get the Internet that the majority are willing to put up with.
- emmelaich 7y agoIt now makes sense that you’re rewarded for staying logged in.
- unixhero 7y agoPost closed due to wrong category.
- unixhero 7y ago"Probably it tries to use the AudioContext for browser fingerprinting. – Bergi 11 hours ago"
- pnw_hazor 7y agoProgrammers make these tools. When challenging said programmers who work for companies that promote this kind of behavior (G) they suggest that they work for these evil companies because their job is interesting and it pays well. This practice could stop tomorrow if the best and brightest of us decided so.
- luckylion 7y agoI doubt that. If "the best and the brightest" wouldn't do it, the second best and second brightest would be asked. At some point, somebody will do it. Also, isn't Google already selecting for moral flexibility? I find it hard to believe that a principled developer would start at Google, much like a pacifist engineer wouldn't work at a Pentagon contractor. So they are getting the best and the brightest whose limits of what they won't do because of personal ethics don't include ad tech, surveillance etc. I'm not so sure that education would help either, it's my impression that ethics is just individually set. Of the people that understand Kant's categorical imperative, some will act accordingly and others will ignore their knowledge because doing so gets them more money.
- avip 7y agoIf you're a newcomer to this long thread, pls CTRL+F manigandham and read all his comments as a primer. Lots of misinformed couch-comments here. If you'd like to reasonably rant about ad-tech (and that's welcome), understand the value it provides first.
- louhike 7y agoGosh, it's incredible the length they will go to de-anomize user data. I guess I will think better next time a website I like ask me to add them to my ad blocker whitelist.
- lol768 7y agoIt's insane to me the extent to which companies will go in order to prevent cross-site scripting attacks.. and yet they're perfectly happy to include unvetted, potentially malicious JavaScript on the same origin in the form of ads. There is no reason these ads should be anything other than a linked image.
- atoav 7y agoI don’t get the modern ad stuff, any reasonable person uses an adblocker anyway, because ads are often slow, problematic in terms of privacy and security. The fact that even people of a big site like stack overflow don’t know where it comes from instantly, is only further proof that using an adblocker is a resonable decision. Maybe it is naive, but all ads should be in my eyes is a picture and something that counts the page views. And when you are a site that has ads as it’s main income you should have at minimum one employee who knows and tests each ad before it gets accepted and put onto your server. Only then your customers will trust the ads you use and only then any reasonable person can even consider deactivating the adblocker for your site. I am pretty sure somebody explored this idea before me, why doesn’t it work?
- bongobongo 7y agoIt works, it just won’t happen because all the structural incentives point to the status quo. Another reason to love our current crop of monopolists...
- paulcarroty 7y agoUltradisgusting case on StackOverflow: 99.999% top answers are edited by moderators - they just promote yourself with free content. We need a real alternative - without stupid ads and master-slave karma-based community relations.
- boomlinde 7y agoTangentially related anecdote: I came across a site the other day that requested access to the MIDI API for no apparent reason. Is this a common tracking vector? The available MIDI interfaces can say something about the system but in 99% of cases (the 99% that don't have any physical MIDI interfaces) I don't imagine that you'll discover anything other than operating system family.
- eyeball 7y agoI’ve been noticing horrible battery drain on my iOS devices lately. The battery monitor in settings says the worst offender is “safari audio”. I wonder if it’s something similar.
- alinspired 7y agothis is the time to appreciate uBlock Origin's advanced mode, since 3rd party JS is blacklisted by default https://github.com/gorhill/uBlock/wiki/Advanced-user-features https://github.com/gorhill/uBlock/wiki/Advanced-user-feature...