14 ms·
Is Stack Overflow allowing ads to use fingerprinting to track users?
- pavel_lishin 7y agoBut won't somebody think of the poor businesses who'll surely be driven to ruin if they can't track my every step? These people keep shitting in the well, and yelling at us for buying bottled water.
- mrspeaker 7y agoI think if the next few years are going to be entertaining. At the moment a handful of shitty companies are abusing their ability to track users - but for me (and I think for many non profit-affected nerds) the outcome seems clear: ANY AND ALL third-party script have to go. Even when that means losing all the third-party goodness (CDNs, analytics, cloud providers...) that we've come to depend on. Yep, they save an uncountable amount of time and effort - but at the cost of tracking users' every step... We can't have one without the other!
- tgsovlerkhgsel 7y agoThird-party should not be the qualifier here. Cloudflare's CDNJS sets, by default, crossorigin=anonymous and subresource integrity. Add a "Referrer-Policy: no-referrer" header, and all the CDN sees is either a) nothing, because the client has the resource cached or b) a request for a certain version of jQuery without knowing where it came from. If you think this is a good idea because it enables technical enforcement, do you also want to ban static.example.com? Because if you don't, you'll soon have pointstothirdpartyadserver.example.com. If you do, you'll have https://example.com/proxytothirdpartyadserver/ https://example.com/proxytothirdpartyadserver/ instead... This is not a problem that can be completely solved on a technical level. Enforce the hell out of GDPR and see the problem shrink.
- jraph 7y agoIt sounds like mitigating the CDN problem could be done like what the Decentraleyes browser addon does: replacing CDN hosted files by local versions. What are the difficulties for a browser to provide such a feature by default?
- tgsovlerkhgsel 7y agoYou need to decide which CDN files to ship locally, you need to store them, do the initial fetching, etc. There is already a system for all of that. It's called the browser cache.
- tjoff 7y agoThere is nothing inherent in any of those that require tracking. Nor scripts that run in the browser.
- JaggedNZ 7y agoHonestly, if all third party scripts are blocked, the ad networks will just start making their participant sites serve the javascript direct and/or run local applications to proxy the data back to them. And unfortunately most management will force the changes through, because they want in on that ad revenue gravy train.
- hermanradtke 7y agoThis is much harder to do, especially in larger enterprises where changes can take months. This includes updates and bug fixes. If this is where we push the industry, it will be a huge win for users.
- Doxin 7y agoI'm willing to bet that IF this happens it'll amount to a lot of companies just including something like this on every page: <?PHP echo(file_get_contents("http://google.com/nefarious_crap.html")); ?>
- artificial 7y agoCorrect, one method is via a subdomain to serve the 3rd party through. Bummer is when it’s mixed with data so blocking it isn’t as straight forward.
- XCSme 7y agoThe ad networks only satisfy the market demand. Makes sense that if you are an ad publisher that you want to get the best ROI on your ad budget, so if you can choose between two ad networks, one of which shows your ads to random users and another one which shows your ads only to your target audience, while having the same cost per impression, you will choose the one that brings you most revenue. Business don't care how those "target audiences" were created, but they want access to them.
- quicklime 7y agoIs it not possible to create an ad network that only supports static targeted ads? The ad network itself can run its own JavaScript, but I don't see any reason to allow the advertisers themselves to run scripts inside ads, other than to make the ad look a bit flashier and interactive.
- zeta0134 7y agoIt's perfectly possible. The problem is that these very scripts the ad network are serving are what people are objecting to. Exactly these scripts, and exactly this tracking. It creeps people out.
- XCSme 7y agoI think the best solution so far is for advertisers to just purchase banners on the sites their target audience is on, just like in the old days. Maybe use something like BuySellAds to find and buy "directly" from that niche site, but BSA is pretty bad.
- pavel_lishin 7y ago> The ad networks only satisfy the market demand. I could not give less of a shit about justification of bad behavior by invoking market demand, if it leads to me finding a turd in my drinking water. Unless, of course, it leads to the dawning of understanding that maybe the Econ-101 understanding of supply-and-demand is a spherical-cow level of analogy that rapidly breaks down when it encounters the real world, and that regulation isn't a toxin.
- nine_k 7y agoIt takes relatively little rep to get the "opt out of ads" privilege on SO. It would be great to have an "opt out of ads for $nn/no" option, like Google Contributor. The amount to pay could look uncomfortable, though.
- NobodyNada 7y agoThat only removes the ads that display inline (above the question and between answers), see [0]. The ad that started this controversy was a sidebar ad ([1]). [0]: https://stackoverflow.com/help/privileges/reduced-ads https://stackoverflow.com/help/privileges/reduced-ads [1]: https://meta.stackexchange.com/q/331960/258777 https://meta.stackexchange.com/q/331960/258777
- banana_giraffe 7y agoIt takes 200 rep to get the "Reduce ads" privilege on SO. There is no "opt out of ads" privilege, unless I'm missing something. And while you're right, this isn't much, it still represents only around 9.3% of SO users that have an account.
- situational87 7y agoI love how the onus is always on the end user to find and report the "bad" ads. How on earth did that insane status quo become acceptable and widespread? The user is expected to know how to unminify and read JS in order to figure out if they are being screwed or not? Seriously? The first time I got served malware via web ad was in 1998. I started manually blocking ads by modifying my hosts file that day. Haven't stopped blocking since. It's a broken model, stop forcing it down our throats and stop shrinking the definition of "bad" advertising.
- tedivm 7y agoYeah, if people want to put all the pressure on me to decide which ads are reasonable then I'm just going to block all ads and move on.
- DoctorOetker 7y agowhat is the copyright status of all the user contributions on all the stack exchange platforms? I would love to see a decentralized p2p stack exchange platform with LaTeX support, i.e. a stand-alone client...
- monksy 7y agoIt's not just with bad ads. It's been with: - Technology projects and features ("oh well you have to advocate for x and y feature") - Public policy (scooters being pushed on to people)
- EpicEng 7y ago>- Public policy (scooters being pushed on to people) I'm not sure what you're getting at here. Policy changes will almost always be reactive. Should we just defacto outlaw everything?
- dvdhnt 7y agoI think the GP is saying that in most cases, constituents probably didn't ask for (in this case) scooters. They were most likely lobbied for by the companies who offer them or by some extremely small subset of the public. Your point seems to skip over the fact that policy creation itself should be reactive - sparked by an obvious public need or because of a prediction backed by science.
- softwaredoug 7y agoRemember when many of these businesses started out with a “don’t be evil” mindset? The incentives always end up chasing the money in the end...
- jasonsb 7y agoIs it possible to take an investment and continue to follow this mindset? Bootstrapped companies can afford to do it, but investors will not be happy to find out that they are losing money.
- JohnFen 7y ago> investors will not be happy to find out that they are losing money. You can run a business ethically without losing money. I think what such investors won't be happy about is that you aren't making money fast enough.
- TeMPOraL 7y agoWhich is kind of a point of taking VC money; if they wanted you to grow sustainably, they'd tell you to get a loan from a bank. These days I treat "took VC funding" as a negative when evaluating whether to commit to using a service.
- cj 7y agoI miss the days when you could simply buy an ad spot on a specific site for X days/months (no targeting, except when choosing what site to buy ad space on, an no javascript, just regular banner ads). Is there still a market for these kind of low-tech ad buys these days?
- nopriorarrests 7y agoYou can probably do it, but your competitor who do target users will end up with $30 CPA and you will get $300 (or worse). So, unless you are ok with x10 user aquisition cost, you will quickly stop doing it.
- TeMPOraL 7y agoI wonder why more people don't try to do this, and use that fact for marketing - as in, "we actually have a semblance of a moral compass, please shop with us".
- nopriorarrests 7y agoBecause it does not work. The cost is paid by customer, and he is looking for cheaper service/product. And your competitor can always claim that 10% of client aqusition cost is donated to fight climate change... and then you stand no chance ;)
- bryan_w 7y agoTo say nothing about the fraud. If you can't link clicks to buys, you will quickly find yourself paying for bot clicks
- pavel_lishin 7y ago/u/cj specifically lamented the lack of pay-for-time, not pay-per-click. Of course you have to track to accurately reward on a pay-per-click basis - that's why pay-per-click is a shitty model.
- 7y ago
- srbby 7y agoCynical pov: if you don't use an ad blocker, you know you are exposing yourself to this. Why get upset at all?
- wool_gather 7y agoSO used to have non-evil ads and a lot of people who do use blockers whitelisted them on that basis. No more, I guess.
- w84it 7y agoHow does this work technically ? Usually when you submit an ad to a network, you dont get to use your own js or even remote images. Is it the ad network and not the advertiser doing this ?
- JohnFen 7y agoIt's almost certainly the ad network. But the advertisers willingly joined the network, and the site willingly uses the network, so they get blame as well.
- TeMPOraL 7y agoIn fact, all three should get the blame, as all three are in a position to fix the problem.
- manigandham 7y agoAds do contain JS and remote images and almost anything else. That's how most banners and video creatives are run. They're only limited when buying very defined formats like text-based search ads.
- 6gvONxR4sf7o 7y agoIsn't the definition of fingerprinting something to personally identify you? There's only one person connected to every fingerprint, and it's there to identify you across websites. That's what PII means to me. How can stack exchange say fingerprinting isn't collecting PII? I wonder what they would call PII.
- srbby 7y agoHow can I take your fingerprint (IP, user agent info, etc) and trace it back to you as a person?
- 6gvONxR4sf7o 7y agoHow can you take my literal fingerprint and trace it back to me as a person? Or even my name? There are tons of people with my name. It's still PII. You do it by matching it up to other records with my fingerprint or name.
- IshKebab 7y agoYou can go to my ISP with a warrant and ask for their records. Which means that interestingly an IP address is only PII if the entity that holds it can lawfully request that information. https://www.whitecase.com/publications/alert/court-confirms-ip-addresses-are-personal-data-some-cases https://www.whitecase.com/publications/alert/court-confirms-... Using that logic, a browser fingerprint would also be PII if the ad network can use it to determine who you are, or presumably if they can link it to other PII.
- 7y ago
- JohnFen 7y agoHmm... this appears to be an intentional and conscious decision on the part of SO. I guess that means I'm done with SO.
- jakeogh 7y agoBad conclusion. Web browsers are written to be fingerprintable. They are deliberately anti-user. Expecting web pages to "just not" is pointless. The solution is to fix the browser.
- jhayward 7y agoIt is ironic that just after I read this item I opened Safari and discovered that the latest update (Safari 13.0) had removed all protection from trackers, malicious advertisers, and unwanted media that I had previously used. So without notice I would be exposing my computer to those hostile elements if I hadn't noticed. This is not what I want - Apple has done a bad thing.
- u-dissolve 7y agotosdr.org (Terms of service; didn't read) is a website that simplifies website's Terms of Service and Privacy Policy to make it easier for people to read. Stack Overflow is given the lowest rating (class E) in terms of user rights. (For reference, even Google has a class C rating.) Here are the worst points taken from SE's privacy policy: * This service allows tracking via third-party cookies for purposes including targeted advertising. * You agree to defend, indemnify, and hold the service harmless in case of a claim related to your use of the service. * This service forces users into binding arbitration in the case of disputes. * Many third parties are involved in operating the service * The service may use tracking pixels, web beacons, browser fingerprinting, and/or device fingerprinting on users. * Blocking cookies may limit your ability to use the service * You waive your right to a class action lawsuit * This service can share your personal information to third parties * The court of law governing the terms is in a jurisdiction that is less friendly to user privacy protection. * The service can sell or otherwise transfer your personal data as part of a bankruptcy proceeding or other type of financial transaction. * The service uses your personal data to employ targeted third-party advertising * This service retains rights to your content even after you stop using your account https://tosdr.org/#stackoverflow https://tosdr.org/#stackoverflow
- SnarkAsh 7y agoThey also promised a profile option you could use to opt-out of arbitration... but never actually implemented it. https://meta.stackexchange.com/questions/333388/what-is-the-status-of-the-secure-electronic-opt-out-of-the-mandatory-arbitration https://meta.stackexchange.com/questions/333388/what-is-the-...
- manigandham 7y agoMost adtech is RTB (real-time bidding) where ad slots are auctioned off and filled as you load the page. SO (and publishers) have no real control over the ad payload that comes back. There has been progress to use sandboxed iframes but there's still JS running inside those placements. The JS won't be going away, it's part of a long supply chain of data, verification, viewability, anti-fraud and other layers baked in. For those saying publishers should do 1st party ads, that would lose them most of their income due to operational and sales overhead and doesn't really prevent everything anyway because they still have to accept the ads advertisers want to run, including the JS from vendors. However the situation is slowly improving. Adtech has weathered through adblocking, native ads, anti-tracking tech but has failed to police itself because of a lack of consequences. Now there's finally regulatory pressure with GDPR, CCPA, and more that will finally force a change from the outside. I expect many of these issues to be greatly reduced within the next 1-3 years.
- Analemma_ 7y ago> SO (and publishers) have no real control over the ad payload that comes back. That's not my problem, they could choose not to use those platforms. If they can't feasibly guarantee the integrity of the ads they serve, then my logical response as a user is to just block them all by default.
- manigandham 7y agoYou're also free to not visit those sites.
- alkonaut 7y ago> For those saying publishers should do first party ads, that would lose them most of their income Yes? Does that make it less likely? Less needed? No If publishers can buy targeted ads with fraud detection, they will. But when they can’t (because the idea of the auctioned third party js blob finally dies) there will be money in dumber ads. What might happen of course is that if someone wants to spend $X on ads that are dumb and untargeted they might as well buy a spot on the side of a bus. Do there would be a flow of ad money back from the web to traditional advertising.
- cmroanirgo 7y agoIt seems like our browsers need a sandbox mechanism for 3rd party js to restrict a) dom access b) ajax Of course, I use uMatrix for that at the moment, but it'd been better if we, as users, can tell what sites are actually interested in providing privacy, by hobbling advertising antics from the get go.
- flaka 7y agoHere is a radical concept for the majority of the hn readership: companies need money to survive. Sometimes the money comes from promoting other companies products, based on your likes and habits. Now go back to your desk, please the manager, and in between jira tasks process what you just read.
- 100100010001 7y agoI think devices need better security. Anything that JavaScript can access should be set to default values where they all equal null. Only once a user allows a certain website to access certain data will that data become available to that website. If every browser did this along with the apis for cellphones then users can finally regain control of what is collected.
- luxuryballs 7y agoAm I the only one who doesn’t care about this kind of tracking stuff? Like I really don’t care, is there some reason why I should? I feel like the worst thing that can happen is I get shown more relevant ads. If I use Adblock then it’s irrelevant, but if I don’t then what’s wrong with having targeted ads? A court has already ruled an IP address is not a person, they don’t really know it’s me, it’s just a construct they created that they think is me.
- rednixion 7y agoThe "premium" aggregators I've seen used in some enterprise software campaigns can be extra nasty, I had someone at work forward me a link(over IM) that a competitor sent them targeting our userbase(our company name was in the title of the page, contents of the page was why they were better) since mailing to in email on our domain seemed odd; they sent me a "you visited our site, now call for a demo" email a few minutes later that had my full name, a week later they called my parent's house asking for me (guess it was the only historic phone number associated with my name). Ever since then I have viewed tracking data as unacceptable because the likelihood of misuse is only dependent on how much someone is willing to pay an aggregator to turn a small ID indicator into a person. Also another court has ruled differently about whether or not an IP address is PII: http://curia.europa.eu/juris/document/document.jsf?text=&docid=184668&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=1406323 http://curia.europa.eu/juris/document/document.jsf?text=&doc...
- luxuryballs 7y agoThankfully I am in the US because the EU is nuts. Isn’t it their fault all these websites have a stupid cookie warning? People should just accept the fact that using a web browser means cookies.
- Doxin 7y agoWhile historically the cookie warnings were only an annoyance these days they often have a (working!) option to reject cookies, giving those popups at least some purpose. Really though setting cookies isn't the problem, and you don't even need to show a popup according to EU law. You only need that popup if you use the cookies for nefarious things such as sending tracking information to ad networks. Setting a cookie for functional things such as remembering logins has always been allowed without a giant-ass disclaimer and nothing has changed in that regard.