9 ms·
This is cool, but not super useful in 2021. Google and Facebook have already moved their tracking technologies beyond frontend network calls due to a rise in b
by marketingtech 5y ago
This is cool, but not super useful in 2021.
Google and Facebook have already moved their tracking technologies beyond frontend network calls due to a rise in browser-level blocking (browser security policies, international regulations, AdBlock, PiHole, etc). The next generation of tracking tech relies on the backend transfer of data between a website and the ad platform, which is invisible to your own network.
It also shifts the story from "Google and Facebook nonconsensually tracking your every digital move through websites and applications" as described in the article into "websites and applications actively transmitting customer data to Google and Facebook." The websites and applications are no longer passive partners, and they assume the responsibility of managing user consent.
- blakesterz 5y ago> The next generation of tracking tech relies on the backend transfer of server logs between a website and the ad platform, which is invisible to your own network I've not heard of this, what sites are giving logs to networks?
- georgyo 5y agoShipping logs would be an extreme breach in my mind. But I can BS. Without a cross site unique identifier, the logs would not be usable across different sites... Though... I guess a browser fingerprint could be used as a non-centralized method to generate that unique key...
- reaperducer 5y agoLogin name, email address, credit card number. Lots of ways for companies to get together like this to follow you around the web and apps. All invisibly. And you'd never know it.
- willvarfar 5y agoMatching up is called “entity resolution” and reminds me of this recent showHN https://news.ycombinator.com/item?id=28127650 https://news.ycombinator.com/item?id=28127650
- krono 5y agoAnonymous metrics, just the basics to help us keep track of service availability. Oh and a unique device identifier along with some information about your hardware and OS. Well... and your IP and connection times of course. Don't worry though, the marketing websites of the commercial services we use to gather and analyse this data say they're keeping your data very safe and secure! Your privacy means a lot to us.
- robin_reala 5y agoNo no, it’s “we value your privacy” which can be read in a couple of different ways.
- haliskerbas 5y agoAd tech does not need a cross site unique identifier for everyone in order for cross device targeting to work well enough. There’s other tricks of the trade that make it good enough.
- marketingtech 5y agoI couldn't tell you a specific site, but here's an explanation of both Google's and Facebook's functionality. FB: https://developers.facebook.com/docs/marketing-api/conversions-api/ https://developers.facebook.com/docs/marketing-api/conversio... Google: https://developers.google.com/google-ads/api/docs/conversions/overview https://developers.google.com/google-ads/api/docs/conversion... This is also why companies like Tealium and Segment are currently valued at billions of dollars. They provide a single middleware integration point to funnel customer data to the dozens of marketing companies that are now leveraging server-side APIs instead of browser pixels.
- iamacyborg 5y agoNot to forget Google's server side containers in Google Tag Manager. https://developers.google.com/tag-manager/serverside https://developers.google.com/tag-manager/serverside
- pineconewarrior 5y ago"Server Side GTM" is a good starting point for for relevant information
- cloudking 5y agoAll Shopify powered sites have the functionality available to send tracking data directly to Facebook via their API, if the merchant enables it. https://help.shopify.com/en/manual/promoting-marketing/analyze-marketing/facebook-data-sharing https://help.shopify.com/en/manual/promoting-marketing/analy...
- jasode 5y ago>The next generation of tracking tech relies on the backend transfer of data between a website and the ad platform, which is invisible to your own network. But doesn't relying on the publisher's website log statistics instead of the end users' browsers introduce trust and "bad actors" problem? This has been a known "principal-agent" problem[1] for all the decades that 3rd-party ads have existed on the web. I.e. Google getting onclick statistics from web browsers' Javascript and reporting to Google-owned "doubleclick.com" is different from the server logs of "JoeClickbaitContentFarm.com". Doesn't the contentcreator's website have an incentive to falsify the numbers to get higher payments from the ad network? It doesn't seem like website self-reported server stats can fully replace end users browsers tracking. Instead, it augments it. [1] https://en.wikipedia.org/wiki/Principal%E2%80%93agent_problem https://en.wikipedia.org/wiki/Principal%E2%80%93agent_proble...
- marketingtech 5y agoThe data is sent from the advertiser to the ad platform, not from the publisher to the ad platform. The advertiser is incentivized to send accurate data for both performance optimization and for campaign measurement purposes. Ad fraud is a real problem in the ecosystem, but the server-side APIs are actually more secure. You have a private signed backend endpoint rather than public JS that can be injected anywhere and fed fake data by a malicious party.
- jasode 5y ago>The data is sent from the advertiser to the ad platform, not from the publisher to the ad platform. Then we're talking about different things. This thread has packet filtering to prevent user behavior being sent to Google. For example, see recent thread about Google's click tracking: https://news.ycombinator.com/item?id=28672625 https://news.ycombinator.com/item?id=28672625 The key is that click choice data on Google's search results page is never seen by advertisers so your explanation of "next gen tracking is by advertisers calling APIs to ad networks" -- isn't relevant to that scenario. Then another level of tracking underneath Google's visibility of click behavior on its own search page is the website (publisher/contentcreator) recipient of the click. Whether any advertisers see this downstream click statistic on an ad network depends on the particular website. E.g. a content creator website might have tracking that sends data to Google domain "googleanalytics.com" -- but no advertisers.
- mhandley 5y ago"websites and applications actively transmitting customer data to Google and Facebook." Any website doing this for EU users without their consent is going to run into GDPR issues very quickly indeed.
- falcolas 5y agoI'm sure that, like most other consent prompts, it will be opt-out with lots of sketchy dark patterns (like artificial waits) to ensure you don't opt out.
- Nextgrid 5y agoThat's actually still in breach of the regulation. However you are right to have concerns as the GDPR is not being enforced seriously.
- oakfr 5y agoAs mentioned above by @marketingtech, the websites assume the responsibility of managing user consent and therefore are GDPR compliant. This is why browsing the internet feels like filing for a mortgage now. But it's compliant.
- trasz 5y agoSo what we really need is a way to easily and cheaply host “virtual clients”, bots to generate traffic so that real clients disappear in the noise?
- intricatedetail 5y ago> The next generation of tracking tech relies on the backend transfer of data between a website and the ad platform, which is invisible to your own network. Well if that's true then it should be illegal if it's not already. How do you find which sites are participating in this data grab?
- jklinger410 5y agoAs someone who works in ads, this is a spot-on summation of the current state of tracking. And that's without getting into how machine learning can use seemingly unrelated data points to learn more about you than you could imagine. At this point if you have even the most basic connections (US bank account, home owner, gps, insurance, a car) the more sophisticated tracking methods can still learn about you and reach you with a decent success rate. It's just that most companies are using crap ad tech.
- alpha_squared 5y ago> It's just that most companies are using crap ad tech. Including Facebook, apparently. About 90% of Instagram ads were irrelevant to me for about two years. Then I mentioned an interest in photography in a private conversation, now 75% of ads are photography-related.
- justapassenger 5y agoLet's apply occam's razor. What's more likely? 1. You mentioned thousands of other things in your private conversations. They suddenly start to narrow down on one specific one. 2. You're interested in photography, and are using service made to share photos. You follow photography accounts/search on the internet for photography related content, this signal got picked up, you clicked on some ad (by mistake most likely), and signal got amplified.
- alpha_squared 5y agoTo address your breakdown: 1. I distinctly hadn't mentioned photography in private or public messages. Ever. Nor had I tagged any of my camera equipment in any of my posts. Hard to believe, I know, but I created and manage the account with explicit intent and action, preferring to move personal conversations off-platform. 2. I don't follow photographers, and prefer to only follow certain friends. While I don't go to that great an extent of concealing my browsing history, I also make some effort to segregate information flow. Plus, the low-hanging fruit of Firefox + DuckDuckGo + uBlock usually does a decent job of helping with that. 3. In the two years I've had an account, I hadn't seen a single photography-related ad prior to the conversation on photography. Ads typically revolved around random tech products (many of which were irrelevant) and ads for TikTok (zero interest in it). 4. There was a dramatic shift in the content of ads within 24 hours of the conversation on photography. It's conservative to estimate 75% of ads are photo-related. I have a hard time remembering any other ad (a sign of their irrelevancy, in my opinion). 5. Given the demographics of this site, I'd appreciate (for myself and others) if you'd give at least a little bit of benefit of doubt on technical comprehension.
- JohnFen 5y agoYes, this has been a terrible escalation of the battle. It means that, in addition to my other defensive tactics, I also need to be sure not to create accounts, even -- or especially -- free ones.
- chmsky00 5y agoSurely Ycombinator (or others) would never run analysis on comments on HN to spot emerging trends. Is moderating for users or to keep their inference engine simple? I mean the backers of Facebook? The schemers who took back control of Reddit? Surely the most principled of people.
- tinus_hn 5y agoThat’s great because that means there can be no more cross-domain tracking. Which is what was the problem all along.
- bgro 5y agoThis is correct. To expand: things like installed extensions, window size (as well as monitor size), bandwidth and general user speed, adblockers themselves and their individual block lists, and browser are all adding to your trackability profile. I believe you can get specific information about user's operating system (either through legitimate, direct checks or by exploiting features and using process of elimination such as X version of Chrome is only available on Mac) and of course hardware IDs. Your IP is obviously out there as an obvious profile that can build a general picture of you in a very similar way to phone numbers. If you use a VPN, the IPs bought by that can also be profiled to narrow you down. If you’ve seen a denial message telling you to not use a VPN, this can be what’s happening. There are also just official exploit-tier-like features constantly being added. For example, Chrome is adding the ability to see if you're idling on a page. I've noticed some major internet sites compiling this type of information for use in, for example, permabans. Trolls have otherwise been able to use a VPN or just create a new account. This is a large driver of finding new tracking methods outside of just personalized ads. I think a lot of this is in its relatively infant stages. I suspect it'll be 5 to 10 years before people become aware and some newsworthy incident of major abuse occurs.
- numpad0 5y agoIs there an easy way to truly defuse various web APIs and anonymize browsers wrt that, except IP? I seem to be maintaining an almost globally unique setup for years judging by various browser privacy awareness tests, despite being a completely uninteresting person. Should I, for example, use Docker containerized browser exclusively, or somehow use Selenium for all browsing traffic, or do something else drastic to that effect?
- bgro 5y agoThere's so many gotcha-holes that it's nearly impossible to get them all and still have a usable browser. Security updates are also going to keep you updating, and those introduce new unique identity problems. Is there any way to be fully be anonymous online? No. The best you could do is Tor on a privacy focused operating system on a disposable computer on public wifi, but there are still loose ways to track that activity. Or just cameras and transaction logs for buying wifi time or a coffee at that place. If you opt to not buy coffee, employees might remember you as the freeloader. If you pay in cash, you might be that only person who uses cash. Obscurity is the best we can do right now. A virtual setup like docker using a typical setup with a VPN is the current most reasonable solution we have. However, things like your grammar and sentence structure or even going to your profile instead of the home page before starting to browse are always going to be weak points unless you write a bunch of random "AI" to counteract that. But then you're just the weird user doing a lot of random "AI"-like things.
- 1vuio0pswjnm7 5y ago"This is cool, but not super useful in 2021." Why would someone in marketing think this is cool. "The next generation of tracking tech relies on the backend transfer of data between a website and the ad platform, which is invisible to your own network." The transfer of data between the user and a website, Google, Facebook or otherwise, is visible to the user. "It also shifts the story from "Google and Facebook nonconsensually tracking your every digital move through websites and applications" as described in the article into "websites and applications actively transmitting customer data to Google and Facebook."" Why would websites transfer data to Google and Facebook. I dont know perhaps every website is different. But if I were a website I would only send data to Google or Facebook if Google and Facebook already had some data of their own. Users who are actively monitoring the data they send to websites can assume that all websites, including but not limited to Google and Facebook, are sharing user data with each other. That doesnt mean we think they are, but there is no way to verify they are not (or to hold them accountable if they were); thus we know they could be exchanging data, without taking much risk.
- matheusmoreira 5y ago> The next generation of tracking tech relies on the backend transfer of data between a website and the ad platform, which is invisible to your own network. This is a major victory. It proves that technology is effective at bringing about change. It proves we are not powerless. We can force these giants to adapt to us whether they like it or not. > websites and applications actively transmitting customer data to Google and Facebook Now we work towards making that illegal.