4 ms·
Couldn't they just be proxied through a first party server?
by qlm 5y ago
Couldn't they just be proxied through a first party server?
- _Algernon_ 5y agoThat would be more effort than including a single html-script tag to import google analytics. I have hope that most parties would decide that the extra server load and difficulties would make it not worth it.
- nimish 5y agoYou underestimate the desire for precision tracking, unfortunately. Hiding behind custom subdomains is common. Stepping up to cloaking it to be delivered from the application is more effort but it'll happen.
- blibble 5y agoif you as the ad network don't connect to the end user directly: how can you be sure you're not being defrauded by the site owner?
- earthboundkid 5y agoYou overestimate the technical ability of publishers. Frankly, it’s pathetic to rely on a third party’s hot linked JavaScript, but no one can be arsed to understand how it works, so they just add the tags to GTM instead of realizing that they could trivially implement A/B testing or whatever themselves.
- deleted 5y ago[deleted]
- MarkSweep 5y agoSome trackers are having people setup CNAME records on their domains, so the tracker cookies appear to be first party: https://arxiv.org/abs/2102.09301 https://arxiv.org/abs/2102.09301
- dudus 5y agoTBH that is the future. tracking won't die will just evolve to become harder to block.
- neurostimulant 5y agouBlock Origin on Firefox is able to perform CNAME uncloaking to block this shenanigan.
- FridgeSeal 5y agouBlock Origin already performs CNAME decloaking and blocks this approach, it’s pretty cool.
- deleted 5y ago[deleted]
- Qub3d 5y agoFor anyone else who wanted to know more like me, here's a good rundown: https://www.reddit.com/r/uBlockOrigin/comments/f8qnpc/ublock_origin_1250_with_cname_uncloaking_is_out/ https://www.reddit.com/r/uBlockOrigin/comments/f8qnpc/ublock... Note that CNAME uncloaking only works on Firefox; chromium-based browsers do not support the required API.
- gbil 5y agoAnd for me this is one of the reasons - probably the biggest - that I don't want to buy an ipad. Because it doesn't allow to run the full blown firefox I've spent hours debating moving to ipad instead of android tablet and it ends to 1. lightning instead of usb-c (can't afford the ipad pro) but ok I can live with it and 2. firefox which is just a blocker
- cookiengineer 5y ago> uBlock Origin already performs CNAME decloaking and blocks this approach, it’s pretty cool. ... which in return is a static list of domains which needs to be regularly updated, and therefore is not really failsafe. uBlock0 uses Adguard's scraped dataset [1] as a fallback source to do this, as Chrome Extensions cannot make DNS requests without a DNS-via-HTTPS endpoint. Firefox, however, has provided the `dns` API [2] to do requests via the native OS resolver (which in return is also not failsafe due to being unencrypted plain-old-manipulateable DNS UDP requests) [1] https://github.com/AdguardTeam/cname-trackers https://github.com/AdguardTeam/cname-trackers [2] https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/API/dns https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
- cultofmetatron 5y agostill more effort than before. twiddling with server configs requires more work than inserting a js snippit.
- amluto 5y agoThat would partially defeat the purpose. First party adds see first party cookies, so they have no inherent cross site tracking ability.
- asiachick 5y agoAnd yet facebook is already do something along the same lines by adding fbcid=<trackingnumber> to every outbound link and then the site that receives the link can report back "I saw fbcid=<trackingnumber>". Sure it makes 3rd party tracking require more trust but wouldn't some analysis tell you if your client is trying to game your ads for revenue etc...?
- manigandham 5y agoCross-site tracking via cookies (and 3rd-party cookies in general) has already been dead for years.