22 ms·
Deconstructing Google’s excuses on tracking protection
- 1024core 7y agoIronically, this site wants to use my browser's canvas to fingerprint me. Umm.. no thanks!
- Crosseye_Jack 7y agoI'm not 100% its being done for tracking, the canvas usage is being used to insert emoji into the page from WordPress Servers. It being a WordPress based blog kinda explains that. Now are WordPress using that ability to track users which the owner of this site isn't aware of? That's another question. Edit: This page doesn't contain any emoji, But it prob just a WP Plugin that replaces any into broswer/os emoji.
- gregdoesit 7y ago>This isn’t the first time that Google has used disingenuous arguments to suggest that a privacy protection will backfire. We’re calling this move privacy gaslighting, because it’s an attempt to persuade users and policymakers that an obvious privacy protection—already adopted by Google’s competitors—isn’t actually a privacy protection. Exactly. Firefox and Safari have both implemented and keep improving the type of fingerprint protection that Google is throwing their hands in the air about. This summary is a thorough response, pointing out just how ridiculous and meritless the original post[1] from Google was. [1] https://www.blog.google/products/chrome/building-a-more-private-web/ https://www.blog.google/products/chrome/building-a-more-priv...
- xvector 7y agoI am honestly surprised at how ridiculous Google’s original blog post was. Zero nuance.
- dialtone 7y agoYou are aware that Google has vowed to actively fight any sort of fingerprinting right? https://techcrunch.com/2019/05/07/googles-chrome-will-soon-get-new-privacy-features-with-better-cookie-controls-and-anti-fingerprinting-tech/ https://techcrunch.com/2019/05/07/googles-chrome-will-soon-g...
- magashna 7y ago"Don't be evil" they said, until it became inconvenient. You can't take Google at their word because their word doesn't mean much. Especially when those vows directly contradict their main source of revenue, targeted ads.
- adam12 7y agoI loved Google back in 2005. It's sad to see what it has become.
- airstrike 7y agoI still loved it as late as 2008... remember this? http://blogoscoped.com/google-chrome/1 http://blogoscoped.com/google-chrome/1
- vezycash 7y ago“It is difficult to get a man to understand something, when his salary depends on his not understanding it.” ― Upton Sinclair
- taurath 7y agoThey’re adding an option, knowing full well that 95% of users will never even think to look in the menu.
- Nicksil 7y agoThe article you linked has Google stating they're planning, over the next few years, to add restrictions to the way fingerprinting is executed. Nothing mentions Google vowing to fight any sort of fingerprinting.
- lowdose 7y agoIt is double speak.
- tareqak 7y agoIsn't that Google blog article completely ignoring the fact that Google implementing tracking protection would hurt their ability to maintain marketplace dominance in one domain (66%+ of web browsers) in order to further maintain and entrench Google's dominance and profitability in yet another (web advertising), and therefore anti-competitive [0][1]? I can completely understand that the software engineers working on Chrome are separate from the ones working on Ads, but ignoring that conflict interest that is extremely obvious to some outsiders reduces how seriously these arguments can be taken by this group of people. I think Google needs to do more to highlight that their technical choices in Chrome and other Google products and services does not advantage their Ad business if that is truly the case. [0] https://www.netmarketshare.com/browser-market-share.aspx https://www.netmarketshare.com/browser-market-share.aspx [1] https://www.statista.com/statistics/193530/market-share-of-net-us-online-ad-revenues-of-google-since-2009/ https://www.statista.com/statistics/193530/market-share-of-n... Update: reworded and added a bit more.
- shawnz 7y agoThat original post was written by the same Justin Schuh who went on this ridiculous tirade on twitter claiming he headed the manifest v3 adblocker neutering changes for privacy reasons: https://twitter.com/justinschuh/status/1134092257190064128 https://twitter.com/justinschuh/status/1134092257190064128 Of course it's not possible that this is true since the observational capabilities of the API are explicitly not being deprecated, only the content blocking capabilities. In other official posts they have claimed that the real "justification" is for performance reasons, which I think is equally nonsense.
- staticassertion 7y agoJustin is a trustworthy guy and, while unfortunate, I believe the Chrome security team was acting in good faith with the manifest v3 changes.
- ocdtrekkie 7y agoWe probably shouldn't refer to someone as "trustworthy" who is repeatedly demonstrated to be blatantly lying and spreading clear falsehoods. As the parent stated, manifest v3 changes didn't hide any information from extensions (hence, by definition, not improving privacy), and independent studies completely discredit Justin's claims about the effectiveness of ad targeting.
- schlipity 7y agoHas anyone ever considered just giving 3rd party javascript less access to things? That may fix the fingerprinting problem too. I do have some appreciation for how badly it would break a lot of the web applications though, but it seems like it might work.
- the8472 7y agoIframes already provide that capability for web authors. Their sandbox and csp attributes allow you to enforce quite a lot of things. Users or extension authors can't do much other than blocking those scripts or restricting what the whole page can do because it's difficult to attribute actions to a specific script.
- deburo 7y agoJavascript coming from a different origin? What about CDNs in that case?
- Crosseye_Jack 7y agoIf you have something like CloudFront in front of your site you can actually make a subdirectory be served from a different origin. To the browser they actually come from the same "place", its just AWS is sitting in the middle. I'm sure its the same with Fastly (Don't use that feature as their shared ssl offering is like and extra $100 p/m) and with cloudflare. EDIT: What I mean is example.com/api/hello could hit your back end, but example.com/js/script.js hits S3 (or another static hosting service) instead of hitting your real origin. So even though to the browser it would appear that /js/script.js is coming from example.com it could actually be coming from anywhere else. BUT the cookie origin would take over. So if script.js was a tracker. the cookie it set on the browser would be example.com and not "AnotherSite.com" which had the same tracking script. But if the script can make the same fingerprint from both domains then that's not so much of and issue. But thats going back to other methods of fingerprinting.
- necovek 7y agoDon't get me wrong, but this way of serving content has been common since, well, apache 1.2 days and mod_proxy ReverseProxy: CDNs did not bring anything new in that respect. Basically, you are confusing some terminology and not really making any point: in your example, there is only one origin, that of example.com. Yes, servers can forward any data they wish to other web sites (like AnotherSite.com). What is the point?
- oconnor663 7y ago> To appreciate the absurdity of this argument [about encouraging fingerprinting], imagine the local police saying, “We see that our town has a pickpocketing problem. But if we crack down on pickpocketing, the pickpocketers will just switch to muggings. That would be even worse. Surely you don’t want that, do you?” Calling arguments "absurd" or "disingenuous" is itself arguing in bad faith, and respectable publications can do better. This sort of thing happens in real life all the time. In the debate over drug policy, one of the major arguments for legalization is that drug prohibition leads to different types of crime. On the one hand, this is a "defeatist" attitude to have about drug policy. On the other hand, the world is complicated, and sometimes we have to make compromises. The author continues: > Based on peer-reviewed research, including our own, we’re confident that fingerprinting continues to represent a small proportion of overall web tracking. And there’s no evidence of an increase in the use of fingerprinting in response to other browsers deploying cookie blocking. That's an excellent, concrete point to make about the question. But it's not "absurd" for others to have less confidence in that conclusion. It sounds like a tricky open question.
- zzzcpan 7y ago> Calling arguments "absurd" or "disingenuous" is itself arguing in bad faith, and respectable publications can do better. If they are not real arguments, but false dilemma kind of arguments presented specifically to push an agenda, how do you call them? You definitely can't take them at face value and provide counter arguments, you can only call them out.
- ska 7y ago> Calling arguments "absurd" or "disingenuous" is itself arguing in bad faith, and respectable publications can do better. I take your point, but calling people out for being disingenuous when they are, in fact, being disingenuous is not bad faith at all.
- Nicksil 7y agoIt's absurd because Google knew it was absurd before including it in their article anyway.
- naringas 7y ago
- devoply 7y agoGet rid of cookies, get rid of fingerprints by sharing them between all browsers using a p2p network so everyone has the same fingerprints. Now get rid of Google. Thanks for all the fish, Google.
- jakeogh 7y agoAnd disable JS. The idea that clients need to execute arb code to see a page broke the information / presentation separation, on purpose. I leave it off (surf lets you easily toggle it per process), and it's pretty rare that I actually want to use it, and in those cases, the page could easily have been designed to work fine without it. It's a deliberate problem.
- la_barba 7y agoNot to mention all the CPU time that JS scripts eat up. The eco-impact of disabling JS world-wide will be significant...
- joes223 7y agoAfaik, TeX is a Turing-complete language that can even read files from disk. Yet, it's only purpose is to render static text documents and nobody blames Knuth for inability to separate the presentation layer. The web is no longer a bunch of text documents. It's the first and only successful cross-platform solution. Moreover, it's still in the very infancy and in 10-20 years it will be the full-blown operation system layer on top of every platform. The problem of the web is that its sandbox has become leaky.
- jakeogh 7y agoMe: executing arb code to view a doc is a bad idea You: TeX is turing complete too! Great. Thanks.
- privateSFacct 7y ago> To appreciate the absurdity of this argument [about encouraging fingerprinting], imagine the local police saying, “We see that our town has a pickpocketing problem. But if we crack down on pickpocketing, the pickpocketers will just switch to muggings. That would be even worse. Surely you don’t want that, do you?” Actually, fingerprinting is not JUST used to track users for ads. Describing the characteristics of a device is used for lots of other purposes as well. For example canvas size etc etc useful for other reasons. Many / most web dev folks rely on fingerprints (user agent / screen size) when targeting layouts, adding / removing features etc. The whole analogy where police are cracking down on criminals is the same as cracking down on fingerprinting is what is "absurd" and "disingenuous". A better analogy is wanting to have a 10mph speed limit to reduce pedestrian deaths. It would (and I like car free planning so would support it). But it would ALSO make commutes etc slower.
- kube-system 7y agoSemantically speaking, the elements that could be used to compose a fingerprint is not the same as fingerprinting. If I write a page that uses user agent / resolution to serve up a layout -- that's not fingerprinting. Fingerprinting would be if I tried to identify a particular user with those elements. I think the problem you're trying to illustrate is that it is difficult for a browser to determine what the requesting site intends to do with those parameters. The browser doesn't know if you want canvas access to draw a pretty picture, or if you want canvas access to perform identification of the user.
- cameronbrown 7y agoMaybe a compromise would be to just build metrics reporting directly into browsers? I'm sure Apple/Mozilla/Google collect this data already, what's stopping them from just forwarding anonymised usage statistics to an HTTP endpoint for each website?
- rwmurrayVT 7y agoIt's also heavily used in fraud prevention, blocking malicious actors, and on gambling websites.
- hartator 7y agoTo be fair, most of the reasons for trackers is to fight ad fraud. Most of traffic on ads are just bots.
- zacksinclair 7y agoThe vast majority of tracking is about behavioral ad targeting.
- jakeogh 7y agoAnd behavioral modification by selectively lying to the user.
- TeMPOraL 7y agoSo liars are in a constant fight with fraudsters. It doesn't justify having regular people's privacy be collateral damage.
- JohnFen 7y agoThat isn't a good justification for trackers. I should not have to be subjected to spying in order to help an industry deal with their own problem.
- jsgo 7y agoSomewhere along the way, ad networks got incredibly greedy (I know, gasp). I remember when I was much younger, there were banner ads on a bunch of pages (and pop-ups/pop-unders of varying levels of frustration). The banner ads were fine even when we were rocking 56k internet: not beloved by any stretch, but typically reasonably okay. I have previously toyed with ad blockers, but at a certain point stopped, figured I'd play nice or whatever. Then there were sites that over time legitimately ate into computer resources to the point they were eating way more energy than reasonable (I can't remember which one, but there was one that if I left the site open long enough, it'd crash all open tabs). At that stage, I went back to ad blockers. I really wish it didn't come to it, but man, that whole "give somebody an inch and they'll take a mile" is in full display online now.
- reaperducer 7y agoI think "Punch the monkey" was the tipping point.
- dredmorbius 7y agoFor the curious: "punch the monkey" online scam explanation: http://www.mikeonads.com/2007/03/01/punch-the-monkey/ http://www.mikeonads.com/2007/03/01/punch-the-monkey/
- abdullahkhalids 7y agoThe energy usage and slow down of your computer are relatively minor concerns when it comes to ads. The real problem is that ads use every dark pattern in the book to influence your beliefs and decisions, effectively taking over your very valuable brain cycles. I think as this conversation evolves, we will find that there is an additional human right, the right for others to not use undue force to influence your mind. This whole battle is ultimately one to secure this right.
- deleted 7y ago[deleted]
- 7y ago
- Schnitz 7y agoSwitched back to firefox on Mac, Windows and Android a few weeks ago and never looked back. Only using chrome for work.
- jedberg 7y agoHow do we reconcile wanting to block fingerprinting so we can't be tracked, with the fact that almost every modern front end uses fingerprinting for things like figuring out the canvas size for responsive designs? I definitely don't want to be tracked, but I'd like responsive designs to keep working.
- doctorpangloss 7y agoReader mode.
- jedberg 7y agoThat's great for the 1% of people who know how to use that, but what about for the general public. When I make a website I'd like the responsive parts to keep working.
- jakeogh 7y agoYou really only need some small JS fragments. Whitelist the hashes (heck bundle them with the browser), run nothing else. The JS does not need to know the canvis size, the browser (the user) can decide. Executing arb programs is poor design.
- dredmorbius 7y agoReader mode by default.
- ninkendo 7y agoI really hope this never happens. Why? Because I have reader mode turned on by default and haven’t looked back since over a year ago, and I can’t imagine the web without it any more. It’s the only thing that makes the web tolerable, no matter how many ad blockers I install. If everyone else used it too, websites would become wise and start blocking it somehow. Oh, wait, I mean, reader mode is terrible and nobody should use it!
- TACIXAT 7y agoGoogle's original post is super gross. It dismisses the idea that there could be alternate ways to fund content (i.e. micropayments). I get why they promote "free content" but it is not free at all when you are trading your attention and privacy. Further, their privacy sandbox sounds like it would just monopolize the advertising space to them. If they don't allow advertisers to collect data, that takes control away from advertisers and centralizes it to their ad market platform. The post also creates some weird false dichotomy between cookies and fingerprinting. Let's just block both, yea? That's what is best for the user, and probably best for the web in the long term. We absolutely need a new funding model for the web (to kill ads). The biggest barrier I see are the high transaction fees of digital transactions (30 cents + 2.9%). I don't know if the solution will be Brave, Libra, or something else entirely. Whatever it is, it can't come soon enough.
- lancesells 7y agoI don't see ads being replaced or killed anytime soon. I think regulation and laws are needed where if I'm not using a Google or Facebook product they aren't building and tracking my profile everywhere I go both online and offline. I mean these are massive spyware businesses and they should be called out as such.
- INTPenis 7y agoYou mentioning micropayments made me think, I would probably pay more than 100 EUR/year for using a Google without ads and tracking (except what I opt-in to). I mean seriously I would probably pay more. I hope regulations from governments help bring google down in size instead of breaking it up for a monopoly. IT has been extremely lucrative.
- TACIXAT 7y agoYea, I would probably pay on that order of magnitude (hundreds) to get all my internet content per year from trustworthy sources. News articles, videos, community sites (HN, reddit), email (with strong blocking to not waste money), chat apps. I wish I could pay them all some fraction of a cent per page load. I'm sure it would add up to be viable.
- gnode 7y ago> the pickpocketers will just switch to muggings. That would be even worse. Surely you don’t want that, do you? A contrast with law enforcement, is that the abusers are not punished and deterred, but instead encouraged to escalate the potency of their behaviour. Anti-tracking technology is preventing pick-pocketing by expecting people to ride in armoured cars. This should be part of the solution, but we also need deterrence. Laws like the GDPR should in theory help, but sadly enforcement with regard to tracking consent has been lacklustre, and consequently and predictably the law is widely flaunted. This makes the mitigating technical measures all the more necessary, yet they are not a panacea.
- joes223 7y agoI think the today's adtech is more like video cams installed in everyone's house and squads of criminals that do targeted raids based on information obtained from those video cams. First people figured that such cameras exist. Then they started installing steel doors. Now they're removing those cameras.
- skybrian 7y agoThis new initiative seems to be about some changes to Chrome that were overlooked due to hazy justifications that seem to have distracted everyone. I'm guessing the justifications are especially unclear because Google doesn't want to upset advertisers. But how about we look at the technical changes they're announcing, rather than how they justify them? - Forcing websites to explicitly mark cross-site cookies, or they get blocked for cross-site usage. They also seem to be hinting at adding better ways to clear cookies in Chrome. [1] [2] - Further attempts to block fingerprinting. (Vague, seems hard?) These seem like... good things? The SameSite initiative makes CSRF attacks harder. Maybe not big news or as strong as you'd like, but in the right direction? [1] https://web.dev/samesite-cookies-explained/ https://web.dev/samesite-cookies-explained/ [2] https://tools.ietf.org/html/draft-ietf-httpbis-cookie-same-site-00 https://tools.ietf.org/html/draft-ietf-httpbis-cookie-same-s...
- 0xffff2 7y ago>Forcing websites to explicitly mark cross-site cookies, or they get blocked for cross-site usage. Why does anyone even allow third-party cookies anymore? I've had them disabled for years at this point, and I can count on one hand the number of times it's been noticeable, and I think there was only a single time I actually found it worthwhile to enable third party cookies to access the site.
- mormegil 7y agoJust a piece of anecdata: a (large) bank we work for struggles with this all the time. Because of historical/branding reasons, they use several different domains. The services used to be quite independent, so everything used to work fine. Because of PSD2 APIs and other developments, they moved on to a central (SSO) authentication page, used from all services on various domains (needing the common authentication cookie). Since then, we fight with the various privacy protections, people blocking third-party cookies, etc. (I'm not saying it's technically impossible to solve, or even saying it's wrong to block third-party cookies. Just... we'll have a lot of work to do, as everyone moves in that direction.)
- deleted 7y ago[deleted]
- jiveturkey 7y agohttps://www.blog.google/products/chrome/building-a-more-private-web/ https://www.blog.google/products/chrome/building-a-more-priv...: > Some ideas include new approaches to ensure that ads continue to be relevant for users 'nuff said
- lazyeye 7y ago"Hide your evil"
- doe88 7y agoFunny how Google paints itself as the somewhat Justice Scalia of web privacy using originalist arguments to make its point. Personally I never been impressed by these constructions and in this case to the extent that it would be rightly interpreted I would be more a living web privacy kind of person anyway. I ultimately think in the web as in the constitution it is disingenuous to think framers would have envisioned at its conception all use cases and especially all potential abuses.
- bgdnyxbjx 7y agoOn top of the generally absurd claims made in the official Google post, that writing was just terrible. Comma splices all over the place, sentences starting with So and But, very strange tone and wording in some things. Did anyone edit this? Oh and I love the “thank you in advance for your help” lol what?
- thetinguy 7y agoStarting a sentence with conjunction is not grammatically incorrect. https://www.merriam-webster.com/words-at-play/words-to-not-begin-sentences-with https://www.merriam-webster.com/words-at-play/words-to-not-b...
- deleted 7y ago[deleted]
- bgdnyxbjx 7y agoSo you are saying that this was a totally fine way to write? But it sounds very awkward and sloppy to me. Maybe, it’s just me.
- nvrspyx 7y agoI mean, you just used both of the ones that you mentioned in this comment alone, unless that was intentional. I think it sounds fine, so long as the writing is not intended to be super formal.
- einhverfr 7y agoIt's almost like Google wants to track and deliver advertising. Almost like they have some financial interest in determining user behavior so they can deliver more targeted ads. Almost like they are an adware company. Nah, can't be that. That would be like a conspiracy or something......
- standyro 7y agoThis letter lost me really early on: >> "There is little trustworthy evidence on the comparative value of tracking-based advertising." This is flat out wrong. Google and Facebook have proven that there are BILLIONS of dollars on the table for the value of "tracking-based advertising" As an engineer who used to work in ad-tech, making appeals to reason to these companies won't help. There's a lot of money flowing in this sector, and unless large internet companies see the value in changing their ad-based business models, the only thing that will dissuade them are shifts in public opinion, laws, and policy. Or a rearchitecture of the web, which I'm all for :)
- kodablah 7y ago> This is flat out wrong Only if you assume value == money. The question is not whether advertisers will pay extra for tracking-based advertising (your definition of "value"), the question is whether they are getting what they're paying extra for (what others are considering "value"). That someone pays for extra for something doesn't not necessarily mean it's worth it.
- amazingman 7y agoWhile I agree with you philosophically, you are using a different definition of “value” than the parent, i.e. you are talking past the point of the parent comment.
- prepend 7y agoNo value to users. I don’t get value out of tracking-based advertising. The best ads are still search-term based where ads help me find. There’s no to little evidence that tracking based ads benefit the user. (although it’s clear that it makes tons for advertisers)
- harry8 7y ago> (although it’s clear that it makes tons for advertisers) Is it? Please link! Thanks.
- 7y ago
- prepend 7y agoI feel so bad for the author of this post. I would love to bump into and chat with the author 10 years from now at some conference and learn about the arguments that went into why this was written. I wonder if the director of chrome engineering has drunk the koolaid enough to believe this? Or whether they feel really bad about carrying water to pay the bills.
- musicale 7y ago> We find this passage from Shoshana Zuboff’s The Age of Surveillance Capitalism to be apt: “Demanding privacy from surveillance capitalists or lobbying for an end to commercial surveillance on the internet is like asking old Henry Ford to make each Model T by hand. It’s like asking a giraffe to shorten its neck, or a cow to give up chewing. These demands are existential threats that violate the basic mechanisms of the entity’s survival.” This quote is hilarious, but if, as the article suggests, privacy-invading, tracking-based ads aren't much better than content and region-based ads, presumably advertising companies like Google could abandon it and still provide similar value to their customers. It might even save time, resources, and money since they wouldn't need to put as much effort into tracking.
- diegof79 7y agoI felt a dejavú while reading Google statements. It remind me a time when Microsoft published statements about how harmful was OSS for software innovation.
- zygimantasdev 7y agoThat sounds like an interesting read - could you provide a link?
- insulanus 7y agoThis might be a good starting point: https://www.pinsentmasons.com/out-law/news/open-source-is-bad-for-business-says-microsoft https://www.pinsentmasons.com/out-law/news/open-source-is-ba...
- JMTQp8lwXL 7y agoIs there someway it'd be possible to develop a browser that fingerprinted as identically as possible for everybody? Surely we have different IP Addresses, but we can make things like querying for viewport dimensions the same.
- tortemp7163 7y agoThe TOR browser already achieves this. All TOR users have an identical fingerprint.
- deleted 7y ago[deleted]
- undoware 7y agofantastic essay. thank you
- joes223 7y agoI believe that this is a part of a well funded campaign against Google by some of its rivals or enemies. Oracle? Regardless, whoever is implementing this attack, they're doing a fantastic job. Google's business is basically connecting Advertisers (wolves) with Users (sheep) and the most important part of this business is to keep this ecosystem stable. Someone's apparently found a way to destabilize this system: wolves are getting bigger and greedier, while sheep is dying out. The only solution here is to cut the population of wolves, but Google is still in denial and lies to itself that maybe the extinction can be stopped by formalizing the process of chasing sheep.
- burnaway 7y agoThere are people with strong beliefs and opinions they are ready to fight for - within the frame of their daily job, using their free time, their own money etc. All this without being enthralled to a "bigger entity", as a part of a conspiracy, serving a special interest playing power games, or simply someone paying them. I am one of those people, in agreement with this post, I can see the OP being in this category as well. If this is all too surprising for you that is a reflection on you.
- deleted 7y ago[deleted]
- auslander 7y agoThat surveillance economy strongly reminds me Tobacco industry. It was cool and trendy until everyone woke up and regulated it to death, as it should be. GDPR is just the beginning.
- choppaface 7y agoWhat if Google is so entrenched in this position because they see a ton of evidence? What if Google is “right”? I tried out Google’s non-personalized ads for a while, and wow the ads were bad, especially on YouTube. Not like irrelevant but downright obnoxious. But wait, we’ve seen this before! A couple years ago, Google noticed that ads were starting to get downright atrocious and started fighting them. One relevant blog post: https://blog.google/technology/ads/building-better-web-everyone/ https://blog.google/technology/ads/building-better-web-every... Why Google oh why are ads so bad? Because advertisers got more evil? Yes and no. Google got more evil advertisers as all the good ad money went to Facebook’s properties. 2012 https://www.emarketer.com/newsroom/index.php/google-edges-closer-facebook-display-advertising-twohorse-race/ https://www.emarketer.com/newsroom/index.php/google-edges-cl... 2019 https://www.emarketer.com/chart/217028/facebook-vs-google-share-of-total-us-digital-ad-spending-2016-2020-of-total-digital-ad-spending https://www.emarketer.com/chart/217028/facebook-vs-google-sh... Google’s recent blogpost is frustratingly “right”: given the opportunity cost of bad ads, an average user is better off opting in to higher-quality tracking-targeted ads. BUT! That is only because Google the ad company lost the good content. And sadly, Google the software company owns the browser, so they have to make do in a Google world. This isn’t even an issue about privacy. It’s about a company overtly misrepresenting the interests of its users in bad faith. No different than Uber tacking on the $1 “safe rides” fee as a pure margin generator rather than as protection for riders.
- burnaway 7y agoYou need to consider some users A) don't want to see ads at all (exhibit A: lot of posters in this thread) B) rather see "dumb" ads than personalized one if it comes through individual level tracking and profiling (that's me). From this perspective no amount of evidence can convince me they are "right" and I have no wish to contribute in any way to "betterment of ad quality" for the price it is proposed. This is comment is no reflection on the rest of your argument btw, just addressing the premise.
- feanaro 7y ago> You need to consider some users A) don't want to see ads at all Exactly. I'm really stupefied with arguments that I'm "better off" by opting for tracking ads. Why am I better off? What good does it do to me? It almost seems like these arguments are coming from some other world which I am not living in.
- airnomad 7y agoI find it amusing how commenters on HN are so privacy-sensitive while good share of software industry today supports, depends on or directly is involved in people tracking, this way or another.
- yjftsjthsd-h 7y agoEh... some of the industry, sure. I work in a B2B company, others work in hardware devices, etc. I'm not sure what the relative proportion might be, but it's certainly not the whole industry.
- airnomad 7y agoGo talk to your marketing team and you would be amazed by level of tracking those guys doing or should be doing in order to win the market. I work in a very boring niche for a small company and you'll receive email from us and we'll know what ads you clicked to find us 1 year ago and that we'll keep your entire browsing history and utilize it to tailor our messaging and that's just a begining of it. And our budgets are fraction of what huge online advertisers spend. Modern digital marketing wouldn't be possible without tracking and that's just how it is. If we make it harder via regulations, we'll just make it more expensive and that's all. Kind of similar as drugs - demand is so strong that supply is going to be there no matter what you do.
- anticristi 7y agoCan someone explain me if this isn't (technically speaking) and uphill battle? Let's say all browsers implement first-party isolation and anti-fingerprinting, won't tracking simply move server-side? "Hey AdTech Network. Here is the server from Free Newspaper. Can you send me an add for Free Newspaper user X at IP Y?" "Hey Free Newspaper. Oh, that guy? I just saw him buying a flight ticket at Flight Aggregator. He is definitely Flight Aggregator user Z. Here is a targeted ad."
- cameronbrown 7y agoIt's totally possible and why IP addresses are PII. If you've got enough websites working together it's probably possible to reconstruct their browsing history, and I would guess even more accurately than with client-side tracking (where blocking cookies and adblockers at least give you some control).
- anticristi 7y agoSo then why are people so annoyed about Google not implementing anti-tracking technology, instead of being annoyed at legislators not regulating tracking à la GDPR?
- cameronbrown 7y agoI don't know. But it seems to me there's a lot of misdirected anger in the air. Trump is investigating FAANG yet nobody is willing to give him the benefit of the doubt there. If everyone was screaming at government then maybe something would change.