15 ms·
How tracking pixels work
- pfortuny 7y agoVery nice and simple explanation. Worth reading if you still do not know. I am not a bot despite sounding like one.
- lawn 7y agoThat's what a bot would say.
- Rainymood 7y ago>Safari and Firefox both block many third-party cookies by default (which is why I had to change Firefox’s privacy settings to get this experiment to work), and as of today Chrome doesn’t (presumably because Chrome is owned by an ad company). Wow. I am very strongly considering switching to Firefox now, just from this paragraph.
- Jallal 7y agoActually, this has been a strong focus of Mozilla foundation for years. The good news is that Mozilla has done a lot of refactoring / rewriting of its FIrefox codebase during the last year, and Firefox is now on par with Chrome regarding the technical aspects.
- lordnacho 7y agoFF also makes it easy to run tabs in their own containers. They've thought a lot about privacy. Plus they fixed their issues with performance, so it works just as well as the other browsers on my mbp.
- the_real_sparky 7y agoI was highly amused just a few days ago when a 1080p60 YouTube video was not playing correctly in Chrome (dropping frames), but played perfectly fine in Firefox. Resource utilization was not the problem on that machine. I tried restarting chrome, disabling extensions, etc but it seemed to just be some weird bug. I will also take a moment to rant about the fact that YouTube allows you to select from a bevy of lower resolutions, but doesn’t allow you to select a lower frame rate. Many times I would rather watch a 1080p30 video on slower hardware instead of the 720p60 I am forced into selecting.
- mojomark 7y ago> I will also take a moment to rant about the fact that YouTube allows you to select from a bevy of lower resolutions, but doesn’t allow you to select a lower frame rate. Many times I would rather watch a 1080p30 video on slower hardware instead of the 720p60 I am forced into selecting. I've thought about this too. I'm not certain, but I suspect this has to do with streaming video compression, specifically the fact that most video compression schemes I know of are temporal (i.e. they can eliminate the need to transmit a lot of data based on unchanged or productively changing pixels between consecutive frames). With a lower frame rate, the probability that pixels in consecutive frames being related decreases. That's my guess anyway.
- leni536 7y agoIn these cases 1080p30 is typically available. AFAIK there is a setting, only available to logged in users. If you are not logged in then youtube-dl is also an option. I also used a browser extension before to reenable the lower framerate options, but it stopped working.
- prox 7y agoFirefox even has its own Facebook container these days. I recently went to a website which had 250 (!) tracking cookies for marketing purposes... As you might suspect it was ridden with ads.
- hollander 7y agoI don't understand why they don't have the same for Google. The FB container does not only force the facebook and instagram sites into that container, but keep the rest out, and disable buttons on websites that open in other tabs. Google is such an obvious candidate for this, but maybe their relationship with Google comes into play here?
- Monory 7y agoThere is, in fact, a Google Container extension: https://github.com/containers-everywhere/contain-google https://github.com/containers-everywhere/contain-google https://addons.mozilla.org/en-US/firefox/addon/google-container/ https://addons.mozilla.org/en-US/firefox/addon/google-contai...
- Spivak 7y agoThe Google container is less useful than just manually putting your Google session into a container because I would assume you don't want all your searches to go through your logged on session.
- onreact 7y ago250? Geek Tyrant injects 400 just for marketing and 500+ in total! I stopped recommending them.
- jefftk 7y agoIf you block third party cookies without having built out fingerprinting prevention, trackers switch from cookies to fingerprinting, which on balance is probably worse. And if you prevent that, sites need to serve ads without any information about the user they're serving them to, and make about half as much money. Chrome is working on fingerprinting resistance and developing privacy preserving APIs that can replace third party cookies: https://www.chromium.org/Home/chromium-privacy/privacy-sandbox https://www.chromium.org/Home/chromium-privacy/privacy-sandb... https://blog.chromium.org/2019/08/potential-uses-for-privacy-sandbox.html https://blog.chromium.org/2019/08/potential-uses-for-privacy... https://www.blog.google/products/chrome/building-a-more-private-web/ https://www.blog.google/products/chrome/building-a-more-priv... (Disclosure: I work on ads at Google, speaking only for myself)
- mherrmann 7y agoI would assume that trackers always do what's in their best interest. Your claim that fingerprinting is both just a fallback and probably worse for the user thus does not add up to me. Wouldn't they always use fingerprinting if that is more powerful? > Chrome is working on fingerprinting resistance and developing privacy preserving APIs that can replace third party cookies And what will their (business and thus vital) interest in doing this probably be? Probably not what's in my, the user's interest. But what's in their customers' interest - advertisers. > I work on ads at Google Well... (Thank you for the disclosure though.)
- lopis 7y agoChrome doesn't need fingerprinting at all. If you are using that browser, you are already being tracked at all times. So by implementing fingerprinting resistance in the most popular browser, Google can thus hurt the competition while merrily continue their tracking business as usual.
- Consultant32452 7y agoYep, on the occasion I need to use chrome it's very upset by the fact I'm not logged into my Google account. I'm sure most users log in. So Google really, really knows who you are.
- colourgarden 7y agoMy immediate reaction to your comment was "How do you not know that?!" (I'm sorry.) However, if people frequenting a tech forum are not aware of the privacy benefits that Firefox has been pushing for a long time now, we as "tech folk" have a responsibility to push out the message. So you can find out more about Firefox tracking here - https://blog.mozilla.org/blog/2019/09/03/todays-firefox-blocks-third-party-tracking-cookies-and-cryptomining-by-default/ https://blog.mozilla.org/blog/2019/09/03/todays-firefox-bloc... And the Firefox Facebook Container may also be of interest - https://www.mozilla.org/en-US/firefox/facebookcontainer/ https://www.mozilla.org/en-US/firefox/facebookcontainer/ Hopefully, you're now reading replies to your initial comment in Firefox!
- CoolGuySteve 7y agoI knew Firefox was working when within about 6 weeks of switching over on my computer and phone (along with using DuckDuckGo and the Facebook container feature), I started getting ads telling me to practice law in Pennsylvania and to fix my weird sideways penis. Both of which were thankfully completely off target. Apparently those two categories are the birdshot of advertising.
- maroonblazer 7y agoGenuine question: why do you prefer ads for things that are irrelevant to your interests over ads that aren't?
- ryukafalz 7y agoNot GP, but: for me it’s never been about the ads. Poorly targeted ads are a sign that the advertising companies don’t have that much data on me, which is what I really care about.
- sixothree 7y agoNeither of those things you described are useful to me in any way. I would prefer the one that has respect for my privacy.
- 7y ago
- cj 7y agoDoesn't Chrome have a "Block third-party cookies" setting (disabled by default) that you can enable in Settings > Site Settings > Cookies and site data > "Block third-party cookies"? I'm under the impression that Safari and Firefox have this enabled by default. Is the only difference that it's disabled by default in Chrome?
- ishitatsuyuki 7y agoSafari and Firefox both have a blacklist of known trackers in addition to cookie blocking. Not only that, these browsers also fight against other means of fingerprinting.
- saagarjha 7y agoSafari does not have a blacklist of known trackers; it generates one dynamically based on tracker-like behavior it sees as you browse.
- randlet 7y agoEven if it's true it's a huge difference. Very few people are going to a) think about this issue and b) know the right terms to google for a solution and/or c) dig around in their browser settings to find the setting.
- vanadium 7y agoIt feels telling that Firefox puts their Enhanced Tracking Protection settings pretty close to upfront as possible, and Chrome’s “Block Third Party Cookie” setting is for all intents and purposes to a non-technical user, both buried and off by default.
- kalev 7y agoThat paragraph alone just made me decide to switch to Firefox. In only 30 minutes, it blocked 120 (!) tracking cookies.
- acolumb 7y agoI use Firefox and what is ironic is the integration with Pocket - an on-by-default service that has tracking pixels [1] [1] https://getpocket.com/privacy#passive https://getpocket.com/privacy#passive
- mirimir 7y agoHuh. I didn't know that. But I've always disabled it, on general principles.
- incomplete 7y agonice, quick intro in to how this crap works. combining DNS blackholing, plus adblockers and firefox or brave will make the biggest difference. :)
- deleted 7y ago[deleted]
- MandieD 7y agohttps://jvns.ca https://jvns.ca is full of explanations that bridge the gap between general, layperson understanding and actual technically applicable knowledge. She’s helped me relearn the Linux/bash ecosystem after a decade of absence.
- guessmyname 7y ago@jvns you can fix that ugly content overflow [1] with this: .entry-content code { word-break: break-all } [1] https://i.imgur.com/ajiycSw.png https://i.imgur.com/ajiycSw.png
- modernerd 7y agoHeads up that there's a repeated word in the first sentence too: "I spent some time yesterday talking to a reporter yesterday" Thanks for the post — I enjoyed it!
- bestouff 7y agoThat's all nice, and I thank Firefox for blocking all these, but once there are too many browsers or extension doing the blocking, I wonder what will prevent sites to implement tracking server-side instead of client-side ?
- vimda 7y agoServerside doesn't have access to my tracking cookies. It has to be a request initiated by my browser to the third party domain
- close04 7y agoThey will definitely keep tracking users based on info available to the server, like IP address. However that is orders of magnitude less precise than what is in place now.
- voidmain0001 7y agoIs it less precise? http://uniquemachine.org/ http://uniquemachine.org/
- close04 7y agoIt certainly should be. You can make it much more precise with the tracking mechanisms that browsers like Firefox are blocking now (tracking pixels, 3rd party cookies). It's the difference between having a snapshot in time available to a specific site vs. a whole history across the internet. Facebook can't show you customized ads if all it can recognize is that it's you. It already knows who you are, you told it by logging in, now it needs to know everything you're doing everywhere else so it can connect all those dots to you. This can't work if all it can say is "this is definitely voidmain0001 from their home computer but I know nothing else about them". The only way is to share that tracking between companies which is more difficult and still more limited in scope than 3rd party cookies. I know you are voidmain0001 here and can read all your comments. But if I have no idea who you are on amazon.com so I can sell you your favorite tech in my ads then the usefulness of this information is limited. Just as a rule of thumb, if those mechanisms weren't adding to the precision then nobody would have invested so much in constantly developing them. P.S. The site above keeps failing half way for me. "Computer says no" type of thing.
- saagarjha 7y ago> tracking pixels: it’s not the gif, it’s the query parameters Sometimes it’s also the base URL too.
- Doxin 7y agoExactly, You're just a mod_rewrite away from serving a single gif under infinitely many names. All you have to do is include a unique name in every email, and then look through your log files to see if anyone came for that gif. Tracking pixels are a pretty ancient technique and for good reason. It's basically no effort at all to set up the basics, and only a tiny bit more effort to get fancy at it and stick the accesses in a database instead of in the server logs.
- tinus_hn 7y agoThe first party website can’t see the tracking cookie so now tracking is compartmentalized for every first party and there is no more tracking across sites. Quite a win.
- scarejunba 7y agoHey, I ran one of those trackers once. Good stuff, though you only captured one aspect of the domain. Enabled lots of content. Good times, good times. There are a couple of other use-cases other than the 3rd party ID-syncing use-case without a 3rd party cookie. You can record information through one of the client-side onboarding providers on their side. Though, to be honest, they have pretty big latency.
- EducatorDirTeam 7y agoVery good information
- mkolodny 7y agoIf anyone's curious about why tracking pixels use a gif, here's a great explanation: https://stackoverflow.com/a/6639140 https://stackoverflow.com/a/6639140
- tyingq 7y agoYou can do a png instead of a gif. It would be ~68 bytes instead of ~35 bytes. A webp image would actually be 1 byte smaller than the gif. So perhaps Google will move to that if Safari ever caves and supports it.
- antsar 7y agoI was going to say: isn't "Content-type: image/webp" one byte larger than "Content-type: image/gif", making this useless? But apparently 204 No Content allows you to omit Content-type. Leaving this up in case anyone else was wondering :)
- pirsquare 7y agoIn most cases, you can simply just return 204 status code (for empty response) to shave away the bytes used to serve 1X1 pixel. The pixel is simply there to make the request.
- anujkrajput 7y agothanks for sharing good information
- vassilyk 7y agoThis article is brushing a lot of stuff very fast. In reality there is much more to it: 1. You don't need to visit Facebook properties for them to link your activity to you. Unless you're a brand new user and they have never finger printed you... 2. Referrer might be in the pixel tracker, but there is way more to that, including product IDs, product costs, your stage in the funnel (have you Added to Cart but not Purchased?), product category, etc. 3. Everytime a Facebook owned property (or piece of: Like button, FB connect) is 'used' by a device you use, then you can be sure the relation between you and that Pixel call is made (ahem, improved). Install the Chrome Extension Facebook Pixel Helper, and check what happens when you use an ecom site. You'll be amazed to see what is shared with Facebook (no PII though).
- rconti 7y agoIn particular it would be interesting to go into why and how these 3rd party trackers get included on a page. I mean, the answer to both is obviously "money", but how does it work in practice? Old Navy agrees to implement a facebook tracking pixel in every page? Or it comes "for free" with a like button? etc.
- propogandist 7y agoThe Like button primarily allows Facebook to monitor your presence across the internet. Tracking pixels can be deployed on a page by page or site-wide level (included like analytics scripts) to enable remarketing or retargeting. The site-wide implementation will, for example, enable URLs that meet %string% to be grouped into a "segment". And then you can serve specific ads to that segment while excluding others
- vassilyk 7y agoIt's part of the onboarding of any Facebook Ads user (i.e., advertiser) to implement the Facebook Pixel on their site. Without it you're not going to achieve much on Facebook as you need to feedback their system when a particular ad had an impact so that they can model the ad delivery accordingly and get you more converting users. Whatever your conversion is (viewing a page, registering, purchasing).
- jen729w 7y agoI don’t see how, in 2020, any conscientious member of this site could justify their use or advocacy of Chrome. It’s an evil product peddled by an evil company for evil means. The alternatives are as good if not better from a usability perspective. Safari is great if you’re a regular Mac user. Firefox is great if you’re a dev on any platform. Chrome is toxic evil that needs to die for the good of humanity.
- throwawaymath 7y agoI guess this will probably be unpopular on HN, but... I still use Chrome. I don't feel the need to "justify" my use of Chrome. I like Chrome. I care about internet privacy - I use ublock origin and have JavaScript disabled by default, and only reenable it for sites I really care about. But I don't really have strong opinions about internet browsers. I used to use Firefox, but a few years ago I started using Chrome and just found it to be better for my habits. I like the tight integration between Chrome and my Google account. I use a Google Home and several Nest products at home (granted they're on their own VLAN). I use GSuite for my personal email, and Google domains for my domain names. Chrome is just another drop in the bucket, and I can't be bothered to change it. I also tried using other search engines, and somehow still found Google to be more helpful for me despite everyone saying DuckDuckGo has reached parity. I guess that makes me morally compromised, or supporting a "toxic evil" or whatever, but I just don't care that much. I'm self-aware in my apathy, I guess.
- Pigo 7y agoDon't let them make you feel bad about yourself. It was a little overboard in my opinion, I thought they were about to say you're a Nazi if you use Chrome. Knowledge is power, just be aware of what is going on with your apps and make a judgement call for yourself. Lately I've been enjoying going to brick and mortar stores and don't go to Facebook at all. Who still uses Facebook? And if I end up seeing an ad, I don't let it ruin my day.
- zo1 7y agoTo be fair, one of the biggest reasons I still kinda stick to Chrome is due to its speed when it comes to Google products and other "web apps". Maps, Outlook365, Gmail are all absolutely horrendously slow on Firefox on Linux. And seeing as the entire web is going down this schmancy route of making everything under the sun a bloated, interactive "PWA/WebApp", it puts as in a corner when it comes to wanting to avoid using Chrome.
- willvarfar 7y agoIts only a matter of time before the ad companies make their tracking unblockable e.g. by hosting something critical to the page, e.g. "make the webpage download jquery.js from our mirror, and you get all this tracking that can't be blocked!" Isn't this happening already, and if not, why not?
- kasey_junk 7y agoAd companies very much are building out cdn so they can do this. But it’s a complex marketplace and e-commerce/media folk are very reluctant to cede control. Amp is probably the ad tracker cdn that has been most successful.
- k__ 7y agoI was working for a web analytics company 5 years ago that would build in-house/on-premise solutions. The on-premise solution allows an easy setup of reverse proxy tracking, which isn't blockable in any way. I know a few companies who run well known sites that use this technique and I could imagine every one with money does it like that.
- 1f60c 7y agoThis is called CNAME cloaking[0] and it’s already happening in the wild[1]. [0]: https://medium.com/nextdns/cname-cloaking-the-dangerous-disguise-of-third-party-trackers-195205dc522a [1]: https://9to5mac.com
- y42 7y agoGood and short description, but it's only a little part in digital marketing. This is just retargeting, an old hat. You can do even more sophisticated things, like predicting what's the best next step in the sales funnel. In general, every step you take before you purchase online is recorded to build your customer journey. And there's a lot more data, like referrers, user agent, times and so on.
- jc01480 7y agoThis crudely represents one way law enforcement and intelligence agencies (friend and foe) identify targets for further analysis. Think about ways this is weaponized a little more. We saw an example of this in the US Navy prosecution of Gallagher for war crimes.
- saagarjha 7y ago> This crudely represents one way law enforcement and intelligence agencies (friend and foe) identify targets for further analysis. What, using tracking pixels?
- annexrichmond 7y agoEver since I enabled Dark Mode on Mac I started seeing so many 1x1 white tracking pixels on recruiter emails. Now I’ve disabled loading images by default in my email client.
- oneeyedpigeon 7y agoI think I assumed 'tracking pixel' was just a metaphor — you mean they're literally serving 1x1 images? Why not 0x0 images? Why not a single transparent pixel?
- ojagodzinski 7y agoBecause no one thought that the background would change or something like dark-mode would appear ;) 1x1 image was "good enough".
- oneeyedpigeon 7y agoI remember learning ~20 years ago to always set `background-color: #fff` since, in those days of Netscape, a user could easily customise their browser's default background color. It was very useful to have someone on the dev team who was weird enough to have done just that! :)
- garaetjjte 7y agoWell, you still can.. (browser.display.background_color in Firefox)
- oneeyedpigeon 7y agoSure, but that's why I said "easily" - iirc, it was more an end-user feature than a power-user one.
- C4stor 7y agoAll of tracking pixels I've worked with come with a css attribute "hidden", so they don't actually show except in some edge cases.
- Endy 7y agoThank you for sharing this. I work with marketing tech, and having this laid out allows me to share with them a little more of the tech that we rely on. And, it allows me to remind them that our work is utterly terrifying in terms of privacy. That's (part of) why I use Pale Moon, I have control of what gets downloaded or sent to servers.
- tzs 7y agoDo any browsers or popular blockers object to these things if they aren't setting cookies? I've used a 1x1 transparent image on many pages on my site for a long time, with a simple page identifier attached to the URL, such as "?index" for the main page. This was simply for convenience in analyzing logs. If I wanted to know which of those pages were visited in the last N days, it was a simple matter at the command line to take the logs for those data and make a quick report that counted how many times that image was fetched, broken down by page identifier.
- thdrdt 7y agoSo Google is hosting fonts because they are a nice company that is just providing us with free fonts? Think again. If you block tracking pixels you should also block the loading of external fonts. Extra bonus: fast loading pages. Some CDN also exist for this reason.
- rconti 7y agoHuh, I had never heard of remote fonts. https://collinmbarrett.com/block-web-fonts/ https://collinmbarrett.com/block-web-fonts/
- DevKoala 7y agoNot only fonts but any resource.
- lern_too_spel 7y agoThe font resources are hosted on a cookieless domain and sent with caching headers. None of this applies. The reason Google is hosting fonts is to make the web an attractive platform, so they can monetize you in other ways.
- thdrdt 7y agoSo my IP address never ends up in their logs?
- lern_too_spel 7y agoIPV6 privacy extensions make IP addresses have very little tracking value, but this article is about tracking pixels, and Google Fonts clearly don't apply here. If you set your Referrer-Policy headers correctly, Google doesn't know which pages your users are visiting.
- bungie4 7y agohttps://decentraleyes.org/ https://decentraleyes.org/ Recommended by privacytools.io
- 7y ago
- tfang17 7y agoWould also recommend Brave for privacy-conscious users.
- peter_d_sherman 7y agoA future web browser will allow fine-grained access control for 1x1 pixel images (and other objects) that are retrieved from other domains...