5 ms·
Unfortunately this won't do much anymore, as Facebook and others are transitioning to server-side data transmission. Businesses now log data onto their own serv
by marketingtech 6y ago
Unfortunately this won't do much anymore, as Facebook and others are transitioning to server-side data transmission. Businesses now log data onto their own servers, then transmit it directly to adtech companies so that your device never directly touches the adtech server.
- judge2020 6y agoSource? The first rule of adtech is to not trust your publishers to not defraud you.
- sithadmin 6y agoThe first rule of running a megacorp is to tell your customers to take a hike if they don't like your terms.
- mr-wendel 6y agoNo, that's the second rule. The first rule of running a megacorp is... oh, wait.
- marketingtech 6y agoFB: https://developers.facebook.com/docs/marketing-api/conversions-api/ https://developers.facebook.com/docs/marketing-api/conversio... Google: https://developers.google.com/adwords/api/docs/guides/conversion-tracking https://developers.google.com/adwords/api/docs/guides/conver... This is also why companies like Tealium and Segment are now worth billions of dollars. They provide a single integration point that funnels events to dozens of marketing companies' server-side APIs.
- KirillPanov 6y agoWhy doesn't that qualify these Tealiums and Segments as "adtech servers" worthy of blocklisting? Sounds like they make the blocklist-curators' job easier.
- isbvhodnvemrwvn 6y agoYour browser doesn't talk to them. The sites you visit do.
- KirillPanov 6y agoThen we're back to the First Rule of Adtech. If "the sites you visit" are the ones talking to Tealiums and Segments, it is trivial for "the sites you visit" to lie about the browser IP address and make it look like requests are coming from all over the world instead of just one box sitting under $FRAUDSTER's desk running a script.
- brundolf 6y agoI think there's confusion here about personal data collection vs ad serving/metrics. Publishers have no reason to be fraudulent about the first one.
- jtsiskin 6y agoThis isn’t publishers displaying ads and reporting how many views they get, this is to associate visitors with ads seen on other surfaces (Facebook, Google) for retargeting (show future ads to people who visited your landing page) or measurement purposes (for people who saw ad A, how many people eventually made a purchase?)
- grishka 6y agoHow do they track people across sites then?
- marketingtech 6y agoThere are a lot of tactics in use today. For logged in users, it's trivial to match users across sites with an email address or a phone number. If you're clicking between sites, there may be a unique ID appended to the outbound URL (on Google there's a gclid URL parameter). This ID will be logged on the destination site and can be continuously passed around to identify the same user on multiple sites. If they don't need perfect matching, they'll use IP addresses, user agents, and other fingerprinting techniques for fuzzy matches.
- 1vuio0pswjnm7 6y agoUsers should not stay "logged in". Always log out when done. Keeping tabs open, not logging out, is allowing much more tracking to be done than would be possible otherwise. Disabling Javascript and using a forward proxy, it is easy to not send User Agents and other points needed for fingerprinting. Tracking IP address is expected and will always be acceptable. All the rest is stuff users are voluntarily transmitting even when it is not necessary, making tracking much easier and more productive for the marketers. There are many tactics to make tracking much more difficult and more expensive. However, few are using them.
- grishka 6y ago> Users should not stay "logged in". Is this the reason why so many websites log you out on their own? Like, you go to do something on a website that requires an account but you see a login form instead. No one wants that. Everyone hates that. IMO if you're using the concept of time in your session management code, you're doing it wrong.
- 1vuio0pswjnm7 6y agoI should be more clear. First the comment is directed at users, not developers. I am referring to sites that can keep you "logged in" by sending a cookie that is then saved across sessions. By "sessions", I mean, for example, you can "disconnect" from the network and as long as you still have the cookie when you re-connect, days, weeks , months, even years later, you are still "logged in". You do not need to send a password again. The cookie has replaced the password. This may be convenient but it opens possibilities for tracking (not to mention security issues) that you would not have, for example, if you were just sending a password each time you log in. Do bank websites let you "stay logged in" for hours, days, weeks, or longer because you have some cookie you received when you logged in some time in the past. Are they "doing it wrong".
- croes 6y agoDoesn't this bear the risk for the businesses to violate the GDPR because they actively transmit data to a third party?
- marketingtech 6y agoThere are different responsibilities for the "controller" and the "processor" under GDPR. Facebook and Google are recognized as processors in this situation. The websites that send them the data are the controllers and are subject to the vast majority of the regulation, while the processors can assume that the controller has obtained user consent until informed otherwise. It's legally important to recognize that Facebook and Google are not blindly sucking up data from around the internet. Websites/apps are actively transmitting this data to them and other adtech platforms for their own benefits.
- croes 6y agoThat's what I meant. Before the companies that used Facebook und Googles tracking have denied any responsibility because they just embeded the tracking scripts. So in their view any violation was Facebook's or Google's fault. But now they are the active part collecting the data and transmitting it intentionally to a third party.