5 ms·
What we need is a way to jam these trackers with generated data to the point that they are useless. Something like https://trackthis.link https://trackthis.link
by gnu8 7y ago
What we need is a way to jam these trackers with generated data to the point that they are useless. Something like https://trackthis.link https://trackthis.link, but running 24x7 on countless computers, phones, raspberry pi, hacked routers, and virtual machines.
- 3pt14159 7y agoThe way CORS and other cross domain tech works this is actually pretty easy to accomplish. Though many sites track IP, because IPv6 is out it's getting pretty tricky to filter without losing some data. Plus an IPv4 address costs less than a penny per hour to rent. But at the end of the day it doesn't really change much. They're going to detect signal somewhere or another. Where they detect it, they keep the data and source locations, where they don't they update their spam ML models. Unless you start going to the illegal side of the spectrum (DDOS, widespread fraudulent ad engagement, etc) you're not even going to piss them off, really. They won't even notice you.
- DennisP 7y agoIs making a bot click on ads illegal, if you're not one of the parties financially benefiting?
- ummonk 7y agoProbably against the terms of service of most websites.
- DennisP 7y agoOk but breaking a website's terms of service is not illegal, according to the Ninth Circuit: https://www.eff.org/deeplinks/2018/01/ninth-circuit-doubles-down-violating-websites-terms-service-not-crime https://www.eff.org/deeplinks/2018/01/ninth-circuit-doubles-...
- archie2 7y agoYou can install the AdNauseam browser extension - it's a fork of uBlock Origin that can automatically click links for you. The idea is that you click on every single ad link while you browse the web, and completely muck up all of the data that trackers have on you. https://adnauseam.io/ https://adnauseam.io/
- metalliqaz 7y agoI really don't understand how that tool is useful. So AdBlock blocks an ad, then this tool sweeps in and undoes any privacy benefit you get from not loading the tracker, AND wastes your bandwidth at the same time. Edit: Yes, I understand that it is annoying for the ad networks to have to register lots of wasted clicks, but that doesn't benefit me at all. It just makes my own browsing slower. I figure at least 20% of the people browsing the web would have to use the extension for it to make any difference to the ad networks, and it's probably higher than 20%. That's never going to happen.
- rdtsc 7y agoYou don't see the ads, so you are blocking them and dilute the value of ads to begin with. Yes, it does waste your bandwidth. > I figure at least 20% of the people browsing the web would have to use the extension for it to make any difference to the ad networks, and it's probably higher than 20%. That's never going to happen. They have tried though: https://adnauseam.io/free-adnauseam.html https://adnauseam.io/free-adnauseam.html So it means, they are worried about at least enough to bother. Now, looking at my stats I just don't see as many clicks as before. So perhaps, Google just fixed their backend code to detect these clicks and moved on without triggering the Streisand Effect by fighting against this project publicly further.
- xgulfie 7y agoAdNauseum is the an act of protest and a tool at once. Yes it compromises on privacy compared to just plain adblock. But if it hides all ads anyway, does it matter if nobody is making money off of you? The noise that the ad-clicking introduces must mess with your ad interest profile at least a little.
- 7y ago
- panpanna 7y agoThis might sound childish but it is EXTREMLY powerful. Uncertainty will make the collected data worth far far less. For years people used custom ROMs to block Android gps data collection and Google didn't care. Then someone added the option to send random data instead and Google filed a C&D within days.
- jammygit 7y agoThis add on does something similar, visiting sites automatically to add noise to your browsing https://trackmenot.io/ https://trackmenot.io/
- codezero 7y agoHeya. I work for an analytics company, and this kind of thing is pretty easy to detect and mitigate. It’d take a pretty huge scale to work at all, which is maybe what you’re suggesting. At scale, I'm pretty sure the companies you most likely associate with unethical tracking would be able to mitigate it, but smaller companies would suffer, only further embedding the established giants.
- rdtsc 7y ago> Heya. I work for an analytics company, and this kind of thing is pretty easy to detect and mitigate. Already happens. I don't see nearly as many clicks accumulated in AdNauseum as I used to a few years ago. Google tried to ban the extension https://adnauseam.io/free-adnauseam.html https://adnauseam.io/free-adnauseam.html, but they've probably been reminded about the Streisand effect and just fixed their code to check for it and ignore it.
- ignoramous 7y agoIf it isn't a trade secret, can you pls outline how it is detected and mitigated? Thanks.
- codezero 7y agoHeap is pretty small compared to Google, so I think that what I’d describe would be too elementary. For us, the client has some state that is hard (not impossible) to imitate, and we have a good sense for what “real” activity looks like. Someone hitting an analytics endpoint blindly will not look natural so is easier to detect. The classic heuristic is to just ignore outdated browser versions since most headless rigs that are naive aren’t on the most up to date user agent or lie about it in a haphazard way. There are a lot more sophisticated techniques that people trying to game ad networks use.
- danShumway 7y agoReally appreciate the info you've given here so far. Followup question off of GP's: if networks know to filter click-fraud out based on metrics as simple as browser version, then aren't those same metrics exploitable to avoid tracking? Firefox's resist fingerprinting setting locks the reported browser version to the latest ERS. If I have that turned on, will every ad click I make be ignored? Keep in mind, the big goal I have with misinformation is to confuse user profiles; not to generate fake clicks or waste money -- it's to make is so that my actual data profile is either unreliable or outright ignored. If this kind of filtering is so ubiquitous, then would it be feasible defense to get user browsers to act like bots instead of getting bots to act like users? How bot-like would I need to be before advertisers started assuming the data they collected from me was untrustworthy?
- ljm 7y agoThis strategy would be great in browsers, to break fingerprinting. Change the permission model such that access is always perceived to be granted, so there is no distinction between providing legit data and random but well-formed fuzz. The tracking will still be there, but the tracker will never know if you granted access or not, it would always look legit. Unfortunately, I imagine that would be tough to pull off in practice because the problem isn't just with web browsers, it's with every piece of software that embeds telemetry SDKs.
- tetraca 7y agoYou need it to be smarter. It needs to look just like someone using a real device - visiting at sensible times with sensible durations - but slowly mixing in to the visitor's actual profile and visiting enough of the "wrong" sites to begin poisoning the data well. And you can't poison everything the same way. You need to make different users have their data poisoned in different ways, so that you can't just filter it into background noise but it becomes impossible to meaningfully filter the data to draw any one conclusion. I would love it, if I could build such a thing.