5 ms·
Please, do NOT link nor read techcrunch.com on hackersnews or elsewhere. It is harmful. Techcrunch is using double redirect trick via https://guce.advertising.
by rdslw 6y ago
Please, do NOT link nor read techcrunch.com on hackersnews or elsewhere. It is harmful.
Techcrunch is using double redirect trick via https://guce.advertising.com/ https://guce.advertising.com/ to plant cookies in your browser as first party ones.
That's right, thats a reason of mozilla firefox ETP 2.0 which you read about today, WHILE most of users and us are currently NOT protected from it: https://blog.mozilla.org/blog/2020/08/04/latest-firefox-rolls-out-enhanced-tracking-protection-2-0-blocking-redirect-trackers-by-default/ https://blog.mozilla.org/blog/2020/08/04/latest-firefox-roll...
- joosters 6y agoI wondered why that has been happening to me too, all techcrunch URLs redirect to advertising.com/* and then stop (extentions / pihole blocking the domain, I guess). Why would any self-respecting website redirect everyone through a domain called advertising.com on each visit? Who thought that was a great idea?
- TavsiE9s 6y agoIIRC Techcrunch is owned by Verizon Media, same as advertising.com. Probably the overlords mandating tighter integration.
- 2bitencryption 6y ago> advertising.com they didn't even put in the effort to obscure their platform even a little bit, huh? not even trying to hide it.
- asadlionpk 6y agoThey probably acquired that domain at the time when advertising wasn't an offense.
- 1propionyl 6y ago"advertising.com" sounds a lot better than "surveillance-and-behavior-modification.com". The term "advertising" has become a euphemism for a much more insidious group of activities which, as it turns out, are useful for advertisement (among other things).
- nickcw 6y agoThanks for explaining this! I have that domain blocked at the firewall so all I see is guce.advertising.com refused to connect. I wondered what it was about and how a techcrunch link could go straight to guce.advertising.com
- shmageggy 6y agoHN should just block techcrunch and associated oath/verizon domains. There are always alternative sources that don't use these flagrant dark patterns.
- neonate 6y agoCan someone please explain this in a bit more detail?
- sdht0 6y agohttps://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Privacy/Redirect_Tracking_Protection https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Pri... has a detailed explanation.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- magicalhippo 6y agoThankfully uMatrix blocks this, so that I don't have to remember.
- bscphil 6y agoWith uMatrix installed I don't ever even see this redirect, I don't think. I suspect whatever script is causing the page to redirect is also getting blocked. Does this normally happen to everyone?
- r1ch 6y agoThe redirect happens at the HTTP level - if you don't see it you may already be cookied.
- bscphil 6y agoSo the mechanism is, I send HTTP request to domain x. If my request doesn't have a specific cookie, I get sent to domain y, which has the cookie, then sent back to domain x? I don't know how I could have gotten it, uMatrix would certainly have blocked advertizing dot com for me. I'll check on that computer and then edit this post. Edit: I'm definitely not sending this cookie, in fact I have cookies completely disabled on this domain via uMatrix. I notice that a guce.js is blocked by uBlock origin. Since I'm not getting redirected, either this is a regional thing, or else they're redirecting using JS as I suggested previously.
- tbodt 6y agoThis is made worse by the fact that browsers don't show the intermediate domains in the address bar during a redirect. They used to, but stopped after attacks were found where you could make the URL in the address bar different from the contents of the page. For example, you could show a phishing site, then redirect to some URL on google.com that takes forever to load, and that would show in the address bar.
- Havoc 6y agoAlso a pain for people with adblocking tech installed
- jiveturkey 6y ago> most of users and us are currently NOT protected from it: available in Safari since 2018. it's part of the ITP feature.