4 ms·
Would you consider IP address enough to de-anonymize most people? Why not?
by VikingCoder 6y ago
Would you consider IP address enough to de-anonymize most people?
Why not?
- cmroanirgo 6y agoDefinitely not. Case 1. Fixed home broadband often allocates a single IP that the household might have for weeks, months or years. There might be only one person in the house, and even if not it's easy to build a profile across websites visited on how many live there, what time they're active, etc. Case 2. Mobile broadband often allocates IP seemingly based on the tower you're connected to (in my country, I can notice this effect). So, looking at the surface of the you'd think it arguable that mobile IP is anonymised... Unfortunately, people are creatures of habit and ping the same towers repeatedly. So it's still possible to track. In short, if there's value to be had in storing any value (like an IP) for ad related purposes, then there's more than a good chance personal information is leaking.
- SpicyLemonZest 6y agoRight, that's the point. Chrome will send "enough PII to de-anonymize" no matter how careful they try to be, because your IP address is very often enough.
- staticautomatic 6y agoI wouldn’t and I’ve professionally sourced and brokered PII. It may be the case that you could match up IP’s with other fingerprinting and/or PII but I’m not sure how. I’ve never seen a broker with a PII data product that would even accept an IP as an input, and IP geolocation is famously inaccurate. This strikes me as theoretically possible but totally infeasible unless you have access to some very special data. I’ve always assumed it was possible and that someone was likely doing it but I was never able to determine how with data that could be acquired through the usual channels.
- VikingCoder 6y ago1) Log in to your gmail 2) Switch to incognito mode, and go to some website that has Google ads on it It would now be possible for Google to figure out that the ad was served to someone from the same IP address that recently was logged in with your gmail account. Any health care website (for instance) that has PII on it probably stores IP addresses at some level, to try to detect DoS attacks, etc. If someone wanted to join that data, IP to PII, they could.
- staticautomatic 6y agoI can't disagree that's it's possible for Google to match up all the stuff it has on people and can get from others. In fact, I made that same assertion in another thread some time ago and got super down-voted over it. However, there are lots of totally legal scenarios in which two parties match up and combine data on a user containing PII. I also would like to know if you believe there's something ethically wrong with combining data, provided it's legal and doesn't violate a privacy policy. You haven't said so explicitly but that seems like the implication.
- VikingCoder 6y agoEspressosaurus made the assertion that it would be easy for Google to not collect enough PII to de-anonymize anyone (in Incognito Mode). I'm pointing out that if you: 1) log in to your gmail 2) Switch to incognito mode and go to a website that has Google ads on it And if Google has recorded your IP address in both those interactions (of course they have - everyone does), then Google has enough information on most people to de-anonymize them. Therefore, what Espressosaurus said is absurdly wrong and should not be taken seriously by anyone. Let's focus our efforts on saying how Google can analyze and use the data, rather than on whether they're allowed to gather it in the first place. Because it's ridiculous to pretend you can stop Google, or any website for that matter, from collecting IP addresses of logged-in users.