4 ms·
There are a lot of tactics in use today. For logged in users, it's trivial to match users across sites with an email address or a phone number. If you're clic
by marketingtech 6y ago
There are a lot of tactics in use today.
For logged in users, it's trivial to match users across sites with an email address or a phone number.
If you're clicking between sites, there may be a unique ID appended to the outbound URL (on Google there's a gclid URL parameter). This ID will be logged on the destination site and can be continuously passed around to identify the same user on multiple sites.
If they don't need perfect matching, they'll use IP addresses, user agents, and other fingerprinting techniques for fuzzy matches.
- 1vuio0pswjnm7 6y agoUsers should not stay "logged in". Always log out when done. Keeping tabs open, not logging out, is allowing much more tracking to be done than would be possible otherwise. Disabling Javascript and using a forward proxy, it is easy to not send User Agents and other points needed for fingerprinting. Tracking IP address is expected and will always be acceptable. All the rest is stuff users are voluntarily transmitting even when it is not necessary, making tracking much easier and more productive for the marketers. There are many tactics to make tracking much more difficult and more expensive. However, few are using them.
- grishka 6y ago> Users should not stay "logged in". Is this the reason why so many websites log you out on their own? Like, you go to do something on a website that requires an account but you see a login form instead. No one wants that. Everyone hates that. IMO if you're using the concept of time in your session management code, you're doing it wrong.
- 1vuio0pswjnm7 6y agoI should be more clear. First the comment is directed at users, not developers. I am referring to sites that can keep you "logged in" by sending a cookie that is then saved across sessions. By "sessions", I mean, for example, you can "disconnect" from the network and as long as you still have the cookie when you re-connect, days, weeks , months, even years later, you are still "logged in". You do not need to send a password again. The cookie has replaced the password. This may be convenient but it opens possibilities for tracking (not to mention security issues) that you would not have, for example, if you were just sending a password each time you log in. Do bank websites let you "stay logged in" for hours, days, weeks, or longer because you have some cookie you received when you logged in some time in the past. Are they "doing it wrong".