45 ms·
Google Tag Manager, the new anti-adblock weapon (2020)
- simpss 5y agoAnything that can be reliably identified across multiple websites can be blocked. So here we'd just block "tag manager web container" no?
- jtbayly 5y agoThe article explains that the info can be transmitted by any JavaScript library.
- Godel_unicode 5y agoHaving spent a good amount of time looking at potential JavaScript malware that ended up being repackaged GTM, I'm pretty confident anyone who says they're "blocking Google Tag Manager" has their head in the sand.
- rhizome 5y agoI've been blocking GTM forever, so I do wonder how this will play out.
- sinuhe69 5y agoMaybe Google till can track the users but what benefit would it bring if its customers can not display ads to the users? Ads are still blocked!
- malka 5y agowell, it is finally time to disable javascript in my browser once and for all. Good riddance to the 99.99% of the internet that rely on it. It is shit anyway.
- transcendrc 5y ago[flagged]
- civilized 5y agoSo long as we're on the topic of fighting ad targeting... if you've never heard of uBlock Origin, you should get it. It's probably the reason YouTube still thinks I'm Hispanic. I love my poorly targeted ads. Easier to ignore.
- jtbayly 5y agoThe article claims ublock origin won’t work on sites that implement this.
- bink 5y agoThe current version doesn't but there's not really a reason to believe it can't be updated. I think the author overstates the complexity of documenting these proxies and URLs for sites that run them.
- Godel_unicode 5y agoYou're going to lose this cat-and-mouse game, it's the same one that gets played with malware C2 domains (except it's worse because both the proxy operator and the actual domain operator are colluding). Add in the zero-cost nature of subdomains as opposed to needing to pay for new DGA root domains and the fact that they can run the whole thing behind e.g. cloudflare to prevent IP blocking? Forget about it.
- ohyeshedid 5y ago> You're going to lose this cat-and-mouse game... History is full of sentiments like that, from power structures that were never able to stop subversion. The game itself is perpetual, so there's always another turn coming.
- garren 5y agoGoogle’s recommending that people set a A record in their own domain for the server, and change the name of the script. Given this, documenting such proxies and URLs and maintaining that documentation doesn’t seem practical. On the other hand, I wonder if you could just block all IP addresses associated with google, or those associated with their cloud/app engine? I suppose that could be handled at the firewall maybe? Are there ASNs google uses specifically for their app engine and cloud computing resources? Others have mentioned that a lot of government agencies rely on google app engine, but it’d be nice to kill all traffic to/from anything google.
- jtbayly 5y agoSo it’s finally come down to “turn off JavaScript, or be infinitely tracked”?
- ehnto 5y agoAnd all cookies, else pixel trackers and serverside analytics can still identify your device. Don't need JS to set a cookie.
- encryptluks2 5y agoThey can identify a device. Without JavaScript, you don't have nasty client-side hints telling sites exactly what OS, CPUs, Graphics Cards, etc. With a VPN and changing your UA, no JavaScript does a pretty good job at preventing sites from tracking you.
- steve_taylor 5y agoUser agent strings tend to reveal the operating system and CPU architecture.
- encryptluks2 5y agoThat is why I mentioned changing your UA. Unfortunately, with JS that is not enough due to client-side hints and other information leaked.
- 88913527 5y agoI'd characterize more as "Turn off JavaScript, and lose access to any site fronted by Cloudflare."
- ehnto 5y agoWhich is a staggering portion of the popular web.
- halayli 5y agoI am not sure OP has the proper background to discuss blocking ad+tracking techniques. Such utilities do a lot more than blocking domains. Blocking domains is just first step as it's the simplest and cheapest win. Signatures/Content inspection being sent can go a long way and can accurately identify patterns.
- nr2x 5y agoThis is a pretty accurate description in my view, it does make blocking significantly harder. [I've got about a decade+ in this highly specific domain fwiw.]
- Godel_unicode 5y agoPihole.
- tgv 5y agoDoesn’t help against server side tracking.
- losteric 5y agoCiting adblock feels like clickbait. Google Tag Manager can't run ads so I don't follow the comparison. Marketing analytics could always side-step anti-adblocking tools through server-side tracking.
- sodality2 5y agoServer side tracking based on what, server access logs? That's not particularly helpful compared to the info you get with clientside analytics libraries.
- matt_heimer 5y agoNo, the gtag in the browser sends all the data to the server-side proxy. Then on the server-side config you can pick which parts of the data to share with 3rd parties. So there is still client side data capture, its just reduced to one component capturing the data.
- coffeefirst 5y agoRight. Everything in the article is wrong. GTM is still GTM and can be trivially blocked; the container itself isn't moving server-side. It's just gained the ability to proxy data to third parties instead of needing to load scripts for every tracker. This is better for performance, and should be explicitly in control of exactly what data is passed on to where. All you really lose is the ability to block a subset of analytics scripts selectively.
- probotect0r 5y agoHow are you going to block it "trivially" if you don't know which script to block? They recommend changing the name of the GTM script, and paired with changing the content slightly, you won't be able to tell which script is GTM and which is actually important to the functioning of the site.
- jacquesm 5y agoYou'll know that after loading the first couple of bytes though.
- jamesy0ung 5y agoHack LocalCDN to inject modified scripts?
- thenanyu 5y agoAs someone who has spent a lot of time on both sides of this, I think this is a great outcome, personally. The most annoying part of ad-tech for me, as a user, was the fact that I was running all sorts of random javascript, any bit of which could blow up performance on my browser. As someone who used to lead an e-commerce operation, I hated running all of this crap in my users' browsers because I knew it would get blocked randomly or cause hard-to-diagnose errors. I eventually moved us to basically this approach using a home-grown solution and everyone was happier. It was even more robust because it just used session/cookie data and didn't require running any javascript execution to work.
- btdmaster 5y ago¿Por que no los dos? (Server-side and client-side spying synergise. Which computer is spending resources transferring telemetry?)
- Raed667 5y agoBeen there, until you're instructed to inject ads in your website, and then you're back to GTM again.
- croes 5y agoThe most annoying part for me is getting tracked against my will. So now it's worse.
- nine_k 5y agoBlocking of feigning responses to particular remote APIs is still better than having to run a bunch of random tracking JS snippets, because without one of them a page just errors out.
- Teever 5y agoIsn't it so strange that if you or I were to do these kinds of things to an individual it would be considered creepy cyber stalking but when companies do it they are rewarded?
- stefan_ 5y agoAny organization still running Google Tag Manager and allowing random marketing people to insert whatever someone told them to in a webinar must be having a death wish when the GDPR exists. You would think security teams would have put an end to that madness years ago but here we are.
- foxfluff 5y agoYou would think legal would have put an end to that madness..
- antattack 5y agoI just use different browser for different activities. I search with Firefox (w/ Ublock, Adblocker) - when I'm ready to buy I use Chrome.
- nine_k 5y agoWhy not just use Firefox containers?
- timbit42 5y agoI use Firefox containers but my Firefox is locked down too tight for online shopping so I use a different browser for making purchases.
- johnny22 5y agofirefox still has profiles, so you could use a profile that's not locked down instead. Although you'd probably wanna use a differnt theme on both to distinguish them.
- Godel_unicode 5y agoWhat do you think this buys you?
- antattack 5y agoFinancial transactions provide more (precise) telemetry for fingerprinting.
- rhizome 5y agoThis is not a well-written article.
- ghoomketu 5y agoPretty sure a big ban hammer is coming for Google with all such shenanigans, especially in trigger happy places like Europe and India who don't like their citizens tracked and are happy to create legislative bans. So you may win the cat and mouse adblock game but what are you gonna do when countries start making it illegal to use GA? (1) (1) https://www.forbes.com/sites/emmawoollacott/2022/02/10/french-regulator-rules-google-analytics-illegal/ https://www.forbes.com/sites/emmawoollacott/2022/02/10/frenc...?
- ulrikrasmussen 5y agoI can't wait for this to happen. Personally I think we just need to ban all targeted advertising based on viewer profiles, even session data such as IP and geo-location. This in turn should severely limit or destroy business models based on optimizing for engagement, as non-paying users are no longer profitable. It's going to cost a lot of people in ad-tech their jobs, but there is no shortage of demand for IT work, so surely they'll find something else to do.
- pmoriarty 5y ago"I think we just need to ban all targeted advertising based on viewer profiles, even session data such as IP and geo-location" I'd go further and ban all unsolicited advertising.
- ouid 5y agoI don't hear these words enough :(.
- drusepth 5y agoIn $current_year, I kind of want to go even further and just ban the Internet.
- eitland 5y agoNot all ads are created equal: The other day I learned from an ad that my favorite 6 year old Bergans jacket can be repaired at a shop next to where I work for a price that is next to nothing.
- gigel82 5y agoGod damn... this is it, this is the end-game. There's no way to fight this unless you customize and maintain blocking scripts for each individual website. Yes, websites could always have done this, but the REST (CDN-bypassing) requests' cost and the manual maintenance for the telemetry endpoints and storage was an impediment that Google just gives them a drop-in solution for :( I think Google is happy to eat some of the cost for the "proxy" server given the abundance of data they'll be gobbling up (not just each request's query string and users' IP address but -being a subdomain- all the 1st party cookies as well). I don't have the time or energy to block JavaScript and/or manually inspect each domain's requests to figure out if they use server-side tracking or not. I honestly don't know if there's any solution to this at all. Maybe using an archive.is-like service that renders the static page (as an image at the extreme), or a Tor-like service and randomizes one's IP address and browser fingerprint.
- deleted 5y ago[deleted]
- ec109685 5y agoApple’s Private Relay blocks this type of cross site tracking. Given this tracking is all server side, third party cookies across sites aren’t possible using this mechanism, and private relay cycles through your IP addresses frequently and uses common IPs across multiple users. Regarding your other point, unless Google execs want to be thrown in jail / sued, they can’t use things like first party cookies for their benefit since that is against their terms of service.
- irrational 5y agoI wonder why Safari is required? I’d be interested in paying for this if it worked with Firefox.
- GekkePrutser 5y agoYeah that would be a useful service that Mozilla could offer and I'd actually pay for. I don't like their VPN as it's too basic in terms of privacy protection and it's much more versatile to just sign up with Mullvad myself because then I can use it on other stuff than just the browser.
- danhilltech 5y agoServer-side tracking has been around for a while (indeed this article is dated Nov 15, 2020; and of course, you could argue simply parsing your Apache/nginx logs to get visitor stats has existed forever). The article I think conflates several different pieces. There's probably a few actual use cases marketers may care about for tagging/tracking/analytics: 1. Simplest: I want to know how many people use my site/app, how many come back, how many are real (not bots), which pages are popular, etc. I'd like to see all this in a nice UI where I can cut and filter the data. 2. Same as #1, but I'd like to do it across devices. Still all within my own site/app, but simply connecting a non-logged in session across desktop and mobile web. Google and FB probably have the largest available dataset on this. 3. I'd like to enrich all this information with data from other sources, for example to target ads, serve ads, etc. Site owners/marketers then try and tackle these in a few ways, the first 3 equally bad: 1. Just dump a bunch of scripts into your site (GA, FB, Segment, whatever). Pros: easy. Cons: very easily blocked, so your data is super biased. 2. Self host some of these scripts, or CNAME them. Pros: maybe a bit better for performance? Cons: still rather easily blocked with content signatures etc. A nightmare to ensure consistency if self-hosting. 3. Run your own JS that sends events to your server, and then your server fans out to whomever. Pros: much harder to block, and likely quite performant. Cons: its unlikely your self built lib is going to give all the same 'features' as GA (features meaning device fingerprinting and so on). 4. Just get everything from HTTP logs. Pros: very performant, can't be blocked. Cons: much more limited data to work with. Personally, I think #4 is the future (and also where we started 20 years ago). What I don't think anyone is doing yet is relaying that data out to all the other parts of the stack: GA, FB, Mixpanel, whatever. If you could solve both - giving users privacy and performance and giving marketers the same tools they're used to - sounds like a win. You might argue "well we'd be missing a bunch of user data", but you're already missing it with adblockers and iOS privacy features.
- Raed667 5y ago> 3. Run your own JS that sends events to your server If your platform is popular enough, those telemetry endpoints will end-up on ad-blockers lists. Then it is up to you, if you want to do an arms race of obfuscation or just accept it.
- danielmorozoff 5y agoForgive me if this is ignorant. Wouldn't an adblock simply need to inject an impersonation payload into the page, so the report would send incorrect attribution to the proxy server?
- sdoering 5y agoIn case of Google it could be (initially) quite simple. Randomly change um-Parameters, gclid-Param and the like. This would at least make marketing tracking more "interesting". Years ago there was an extension that did that for GA and Adobe Analytics at least. But that would only be an arms race. We (analysts and marketing agencies) would obfuscate the params we use and switch that in the server side container.
- anxrn 5y agoWouldn't it be possible for a potential client-side blocker for this to intercept the gtag() method invoked on the client side ("Tag Manager web container"), even if that function is provided by a script hosted on the website owner's domain, as Google recommends[1]? [1] https://developers.google.com/tag-platform/tag-manager/server-side/send-data#update_the_gtagjs_source_domain https://developers.google.com/tag-platform/tag-manager/serve...
- gigel82 5y agoHighly doubtful the method would continue to be called "gtag"; any js bundling / minification would replace that with a randomly generated string, and it's just as easy to randomize the server-side api endpoint url, making this virtually impossible to block (maybe a pattern analysis on the data being transmitted, but that can also be encrypted with random algorithms and keys, beyond recognition).
- anxrn 5y agoYes, it can surely be obfuscated, but ultimately there will be a client-side function with near-identical functionality prevalent all over the web. It's harder, but seems possible to build an extension to identify this function.
- chillacy 5y agoTaken to its logical conclusion, this process reminds me of anti-virus software: finding code signatures and flagging sketchy code.
- foxfluff 5y agoExactly. And the end result might be as bad as antivirus: horrendously slow software with a huge database of heuristics that cause false positives and at the same time let malware through. It's going to suck.
- notriddle 5y ago
- gumby 5y agoI am fascinated that the popular press has described this as Google adding privacy (which is how google describes it of course) where really it’s a massive escalation of their spying network.
- heavyset_go 5y agoI wouldn't be surprised if much of the popular reporting on it are just press releases.
- gumby 5y agoSeems like it, even in the big papers/sites
- jart 5y agoWell it sounds like they're plugging the RCE hole in how ads operate which is even better. That's the real elephant in the room which no one seems to be talking about. With all these zero click exploits I don't want an entire industry to exist that's dedicated to people bidding to run code on my computer. If all that bloat is running somewhere else in the cloud and this tag manager is filtering the information they access so that it's actually just boring marketing analytics then I'd imagine it does a lot to help improve the sovereignty of personal spaces.
- varenc 5y agoApple and Firefox brought this on by killing 3rd party cookies. The reason why client send requests to the 3rd party domain directly is that the cookies attached to that domain are sent and which can track you better! With a server-side request there's no way to use that cookie info. But browsers increasingly limit 3rd party cookies. With 3rd party cookies becoming useless for tracking there's far less to lose by moving all these analytics calls to the server side.
- wmeredith 5y ago> Apple and Firefox brought this on by killing 3rd party cookies. And the ad networks–like Google–brought that on by their user-hostile data collection practices.
- technion 5y agoNote that the Google announcement in question was August 2020. This didn't seem to make any significant changes to the ad-block space when it rolled out, and pretty much every site is still running the Javascript frontend.
- terrycody 5y agoSorry I can't understand the article, but does server side Google tag manager already out?
- rootusrootus 5y agoIf I am reading it right, the article is saying about 1/3 of all web sites on the Internet already use GTM.
- matt_heimer 5y agoUsing Google Tag Manager doesn't mean you are using the server-side tagging. You have to configure it in your account. It is something you have to pay for. If you read the instructions on https://developers.google.com/tag-platform/tag-manager/server-side https://developers.google.com/tag-platform/tag-manager/serve... you have to have GCP billing setup to pay for the App Engine instance running the server-side tagging proxy.
- terrycody 5y agothx for the explaination, btw, do you think server side GTM can let Adsense bypass the adblocker, since it is what claimed in the article. Though after Googled a bit, I can't find a single article/video about this.
- matt_heimer 5y agoSomewhat. Some of the tracking protections center around 1st party vs 3rd party. If the site owner takes the time to configure the DNS records for this server-side proxy then the page is only communicating with 1st party domains so that protection is gone. Next, ad blocker components often target various parts of the URL. By hosting on your own domain the domain name matching patterns that would be used for blocking no longer apply. But the ad blockers can also use just the path or file name portion of the URL to block on. Easylist has a set of lists that are commonly used by ad blockers such as UBlock Origin. The tracking/privacy centric list is https://easylist.to/easylist/easyprivacy.txt https://easylist.to/easylist/easyprivacy.txt which I'm using in UBlock Origin. If you look at it there are lines like '/gtag.js' which might match on the name of the JavaScript file and still block it. Of course site owners might change the name of their script files to a non-default name making it harder to detect. The next step in the arms race would be having more dynamic names for the files and URLs. You could rotate the names of the scripts and endpoints automatically at which point the adblockers would have to preform content inspection or some other strategy which is more resource intensive.
- PeterisP 5y agoThat's why we need generic legislation without consideration of specific technologies, restricting the general goals, not just one particular way to achieve them. GDPR would forbid this tracking without opt-in consent - the fact that you have the technical ability to effectively handle tracking information server-side without support from the user/browser (as for cookies) does not imply that you have the right to do so. We don't have to win a technical fight, we have to ensure that privacy-invasive tracking is not profitable because all the major legitimate megacorp advertisers throwing billions at internet ads are prohibited from using that.
- waynesonfire 5y agothis is great. to block this shit it's now just necessary to disable the "tag container" instead of tracking hundreds of javascript / URLs.
- arvindamirtaa 5y agoI use brave which has a "Brave shield" that disables GTM from loading altogether by default. Would that solve this issue?
- viraptor 5y agoDepends how is implemented. Currently: possibly, but likely not if all the steps were implemented.
- SBF 5y agowell not sure is it good or bad.
- heavyset_go 5y agoI blindly added Google Tag Manager to my sites. This article gave me a reason to remove it, thanks.
- olliej 5y agoYou shouldn’t be adding any google scripts to your site, u less you believe that you have the right to support spying on your users. Google “analytics” is a spyware system that they bribed sites to include with the promise of “knowing your users”.
- heavyset_go 5y agoI used them to set up their Search Console product and didn't think to remove them.
- Animats 5y agoWait, Google wants to proxy the entire internet through Google servers? Just so ad tracking will work? This lets Google spy on the entire session in both directions, right?
- olliej 5y agoAnd also makes it harder for any alternative - you can’t use two different systems to proxy the same content at the same time, and you can’t expect one company to not “protect user privacy” by filtering competitors. Honestly the only reason this is even an option for google is because a bunch of web admins said “I want to know who is browsing my site, and who cares if that lets google spy on every person who uses my site”, and now they’re just offering this “improvement” to spying.
- Animats 5y agoThis was modded down, but commented on favorably. Am I wrong about this giving Google a backdoor into every web site that uses it?
- olliej 5y agoIt’s just another mechanism to maintain their existing spyware systems. What google absolutely depends on is having as much of the web as possible including their code. Essentially: if every website includes some amount of their code it becomes increasingly difficult to block every tentacle. Presumably the goal is that it doesn’t matter if 90% of their crap is blocked by browsers: as long as a single tentacle leaks enough info on any given page they can track you. How true this is in the face of privacy preserving vpns like Apple’s private relay I don’t know.
- charcircuit 5y agoYes, you misunderstand it. Google isn't getting any more information / power than they previously did. What server side tagging does it separates the creation of tags outside of a user's browsers and into a server that is a part of your infrastructure. You can host this tagging server on Google Cloud, but you can also self host it if you choose to. To restate what happens, a website's users send events to a first party tagging server and then that tagging server can communicate with 3rd parties.
- 5- 5y agoi'm using firefox with https://addons.mozilla.org/en-GB/firefox/addon/temporary-containers/ https://addons.mozilla.org/en-GB/firefox/addon/temporary-con... it occasionally gets in the way, but does make things a bit more enjoyable (i can now happily click 'allow all tracking' on all the popups not blocked by ublock -- all that lasts until i close the tab). ideally i should also use something to resist fingerprinting (i.e. randomising fingerprintable features).
- gzer0 5y agoIncreasingly, the only solution I see to this is Apple's Private Relay [1]. "When Private Relay is in use, the user’s device opens up a connection to the first internet relay (also known as the “ingress proxy”). As the user browses, their original IP address is visible to the first internet relay and to the network they are connected to. However, the website names requested by the user are encrypted and cannot be seen by either party. The second internet relay (also known as the “egress proxy”) has the role of assigning the Relay IP address they’ll use for the session, decrypting the website name the user has requested and completing the connection. The second internet relay has no knowledge of the user’s original IP address and receives only enough location information to assign them a Relay IP address that maps to the region they are connecting from, conforming to the IP Address Location preference they selected in Private Relay settings." [1] https://www.apple.com/privacy/docs/iCloud_Private_Relay_Overview_Dec2021.PDF https://www.apple.com/privacy/docs/iCloud_Private_Relay_Over...
- meibo 5y agoTo what is a VPN a solution? It prevents IP tracking, but that's it. The rest of what is described here still works.
- gzer0 5y ago"Private Relay uses both the CONNECT and CONNECT-UDP methods in HTTP/3 to set up connections quickly. For connections to websites that support TLS or QUIC, the initial TLS handshake messages are sent in the same set of data as the proxy request" Would this not hinder the proposed mechanism discussed in the article? Edit: forgive me, for my knowledge of networking is limited and I'd like to learn more if I am incorrect.
- snowycat 5y agoI fail to see how this is any different (for the purposes of getting around google) than any other VPN or proxy service out there. The proposed mechanism is just using a script that comes from the same server as the main website with perhaps slightly changed up code and a different file name to trick up adblockers. It can still fingerprint you without your actual ip address, as it collects data clientside.
- newscracker 5y ago> How can adblockers react? … > Automatically detect these "1st party" calls to the "proxy" server via the URL parameters sent. Except that these URL parameters will change from one site to another, depending on the library used, the page viewed, etc > Detect the javascript library responsible for calls to the "proxy" server to block its execution. Except that you should not simply detect the javascript library provided by Google, but potentially all the javascript tracking libraries, even home libraries. Seems like this would be a great case for AI/ML. I say that in half jest. > Block the IP addresses of these proxy servers. This seems doable, even with the caveats included in it. Even if these measures work on some sites and not others, they would be valuable. Meanwhile, please get your non-tech circle to use ad blockers and/or browsers that support ad blockers on desktops, laptops and mobile. And instruct them that browsers that don’t support ad blockers are from a “be evil corporation”.
- windex 5y agoI should go back to Lynx.
- pabs3 5y agoThe only reasonable way to interact with the modern web is to disable everything by default including images, cookies, CSS, JavaScript, video, frames etc and then develop strategies for interacting with each website. Either in the browser or in reimplemented frontends like nitter/bibliogram or externally using things like yt-dlp, gallery-dl, woob etc. Edit: oh and only contact the web via Apple private relay or Tor etc.
- BugWatch 5y agoI completely agree, most of the Major Websites (TM) are as user-hostile as it gets. But, the "bypasses" (to try to encircle all approaches with a single term) would require constant vigilance and updates, the ever-lasting game of cat & mouse, not to mention possibility of lawsuits or other shenanigans by the said Websites. Honestly, I'd donate certain amount every month and support the effort, if it was a very wide-service/website encompassing, and would give logical end-user easily/very customizable behaviours within options, easy for the everyday Joes, and that it wouldn't treat its power users as garbage. And here's an idea for a starting recipe for every website: a library of set of actions that would run on the first visit and would result in decline/block for each and every cookie category and "partner" (and no, there is no such thing as "legitimate uses", GTFO), since most websites either roll their own ot customize some existing solutions (from what I see), but usually invert/dark pattern options and choices to a certain degree (usually "to hell").
- YaBomm 5y ago
- kryps 5y agoCan we have " (2020)" added to the title?
- deleted 5y ago[deleted]
- urthor 5y agoAll this is doing is redirecting data you already submitted to a website to Google? I don't see any of this as particularly new or revolutionary. Except the implementation, user data was already being hoovered up. Now it's just pipelined better. if you were worried about your data, you have to stop submitting the data to websites. Period.
- easytiger 5y agoUK local newspapers have been bought up by a company called Reach. Most of their sites look the same. On my laptop visiting their home page is burdensome on my laptop. e.g. https://www.mylondon.news/ https://www.mylondon.news/ Looking at firefox's network tabs. It mostly completed after 41 seconds and almost 9MB. In the article pages there are adverts dynamically loaded every couple of lines of text An article page from that site ,e.g. https://www.mylondon.news/news/east-london-news/heartbroken-young-man-took-life-23125948 https://www.mylondon.news/news/east-london-news/heartbroken-... Takes around 1m50s to load at 18 MB. The web is a disaster right now
- soheil 5y agoI always wondered how much negative revenue the adblock extension is generating for Google. It must be in the billions. Crazy to think a simple extension can be involved with that much money.
- eru 5y ago> How has Google been able to impose itself again? As with Google Analytics, the standard version of Google Tag Manager is free (market solutions are generally paid), it is very well integrated with other Google solutions and it is well done. Not sure what they mean by 'market solutions' here?
- viraptor 5y agoFortunately, as bad as this is, I don't believe many companies will implement the worst version of it. (Server side + subdomain + different name scripts) The reason is that we had server-side analytics available for years and virtually every big website still implements the clientside part. If they can't be bothered with that, I don't expect they'll move the whole tag manager any time soon.
- sdoering 5y agoI have to agree. Working as consultant/data analyst none of the clients I know (most of them on the paid 360 version) are anywhere near to switching. Complexity as well as the price tag for the proxy is keeping (even is it would be just a fraction of the 360 bill) keep them from jumping. But mostly the complexity and effort for the migration. If the were to start from scratch they would probably go for it. Additionally most data privacy departments actually have some influence nowadays. They would not stand by if marketing were to implement this and not honoring consent. But there will surely be black sheep.
- pixeldetracking 5y agoCloudflare Zaraz seems to be an easier option unfortunately https://twitter.com/pixeldetracking/status/1495719355987943426 https://twitter.com/pixeldetracking/status/14957193559879434...
- sorry_outta_gas 5y agoMan, screw the web.
- philliphaydon 5y agoSo if the script comes from the owners site instead of Google. And all the rest requests are proxied via the owners site. Would this not result in people forking a browser that looks at http requests before they are packaged and issued to remove tracking data or block the request?
- bgdam 5y agoAnd how do you differentiate between a request that is sending over tracking data and a request that is sending over data required to fetch the page you requested?
- tgv 5y agoIt would seem easier to identify data patterns than script content. After all, tracking is only useful if the data is consistent.
- macinjosh 5y agoAt the end of the day the data is still coming from the client so perhaps the best approach in future would be to find ways to make the data less useful or useless.
- Zardoz84 5y agoWell... At least on Europe it will be forbidden on all European union countries.
- miere 5y agoDo you believe ad-blockers could checksum these scripts or do some sort of pattern recognition - like some anti-viruses do - match and deny these scripts?
- zwaps 5y agoCrazy how evil Google is. Just wow. Since this runs entirely on the domain of the website, it can easily ignore your privacy rights, with Google more or less washing their hands clean of it. Indeed, if we take blocking trackers as expression of consent, the only possible reason this exists at all is to illegally circumvent privacy preferences. In other words, if you work for Google, you are literally working for a criminal organization. How times have changed. It seems the only possible option to retain privacy rights given to us by law (eg in the EU) is to disable JavaScript and cycle IPs or other fingerprinting features. None of that is realistic. As a EU citizen, i hope that our ineffectual administration at least tries to fight this somehow. Of course, there is little hope.
- ornornor 5y ago> privacy rights given to us by law (eg in the EU) > As a EU citizen, i hope that our ineffectual administration at least tries to fight this somehow. Of course, there is little hope. GDPR is thanks to the EU and I wouldn’t say it has no effect. It seems like you’re contradicting yourself with these two paragraphs.
- CommanderData 5y agoGDPR has been a massive win for user/consumer rights. Its a piece of legislation law makers in the US are trying to mimic. Surprisingly the UK are trying to rid or weaken GDPR significantly after brexit. The only way to fix this problem now is through strong legislation.
- wjnc 5y agoDo we really need more or new legislation if there is still ample room for improvement on the enforcement side of GDPR. Just a not so far stretch: all or most of the GDPR supervisors now think Google Analytics is a no-go. Publish this and an intention to fine say 2% of revenue, set an expiration date six months ahead and do a EU-tender for a scraping facility finding all users of Google Analytics. Then in six months, re-scrape and send out the fines. Rinse and repeat. Google Tag Manager could be declared illegal on the outset, with a 5 to 10% fine for Google if they continue to offer it in the EU. Do a top-down assessment of the usage of Google Tag Manager in the largest e-commerce users in Europe. Fine them as well. At the end of the day privacy enforcement could easily pay for itself. (Edit: After typing this I think you were writing from a US perspective. I think GDPR is a big win as well, but enforcement is feeble ;)
- leetwito 5y ago[flagged]
- choeger 5y agoSo it's essentially a keylogger snippet and API with a backend for analytics? Plus some how-to's on how to best hide it? Intentionally acting as a middleman between the publisher and all the shady advertisers? Seems like a slam-dunk GDPR violation to me. What's the next step? Obfuscation of the keylogger and unique snippets for every visitor? That's pretty much malware deployment technology.
- sdoering 5y agoDisclaimer: I am a data analyst. I consult companies in regards to ethical data collection. But I also know of black sheep. I don't have a problem with websites measuring what I view, click, add to cart or buy. I want them to be able to see what doesn't work in terms of user experience. And if they do marketing I even want them to be able to see from which source of traffic (aka marketing effort) how many conversions (whatever comprises a conversion) stems. The problem imho isn't GTM (Google Tagmanager) running as proxy. This would (or at least could) be a data privacy win if done ethically. At least under one imho essential condition: I could be able to run the proxy on any infrastructure that I like. Not only one Google's cloud offering. And on the second essential condition that marketing departments act ethically. They can send the web analytics data to whatever tool they like. But they should absolutely not send my identifying information with it. They should use the proxy as a privacy protector. The same when sending conversion data to the marketing tools. I am OK with the marketer sending information back that a specific ad (not a specific user clicking on a specific ad) led to a conversion. I don't need Meta or Alphabet tracking me personally (or my clients'users) with every click. But I understand the business need to measure the effectiveness of marketing money spent. Solutions like these could be a way to achieve this. If done right. And not done in the way GTM does (only hosting on Google, using an A/AAAA subdomain, grabbing every cookie possibly and so on).
- curiousmindz 5y agoSadly, most publishers are not interested in developing their own proxy solution just for the sake of data privacy. They vastly prefer a ready-made solution that they can just use. Much of the power of the advertising space come from people (publishers, consumers and advertisers) generally choosing the path of least resistance. They don't have the technical know-how and they would only acquire it if there were enough benefits. Sadly, privacy is not enough on its own. I think the solution that can solve all that is when a company acts as a "wall" between consumers and publishers/advertisers. Then, that company can protect the consumer while keeping the user experience as simple as possible. "Sign in with Apple" is one such solution. But of course, it brings its own (different) downsides.
- deepstack 5y ago>The problem imho isn't GTM (Google Tagmanager) running as proxy. This would (or at least could) be a data privacy win if done ethically. At least under one imho essential condition: I could be able to run the proxy on any infrastructure that I like. Not only one Google's cloud offering. Yup that is where rubber meets the road. Would like to offer google as little data as possible. And use as little google products as possible on the web and internet.
- antifarben 5y agoActually this article strengthens my believe that adblockers will even become more essential. I mean, even if the server decides to send some ads, the client doesn't have to show them. Or am I missing something?
- dartharva 5y agoThe client won't be able to distinguish between ads and actual content on the website if both come from the same source.
- bruce343434 5y agomachine learning to the rescue!
- _flux 5y agoAs long as the countermeasures are public, the advertisers can also automatically react to them, if they put enough effort in it e.g. in the form of preparing alternatives ahead of time.
- dartharva 5y agoYeah I don't really see how ad blockers can remain free if they start implementing expensive methods like that.
- HHC-Hunter 5y agoNot sure where you got that from the article, in-fact I get the inverse.
- paulcarroty 5y agoFor sure, guess it's why Brave block it.
- Hard_Space 5y agoWow. I've been talking about this for 15 years. I guess they finally got painted into a corner enough to implement it.
- deleted 5y ago[deleted]
- alkonaut 5y agoIf the standard deployment will be a separate IP in the same range (Google cloud) which is also bound to a subdomain of the site I’m viewing, isn’t that an easily identifiable situation? Couldn’t blockers like unlock just block the subdomain.site.com for every site.com? Or even block all subdomain calls to Google hosts?
- bamboozled 5y agoIt's a good point, those endpoints can't change forever. Ultimately there will be solutions to detect and prevent this tracking just like whatever exists today.
- phkamp 5y agoA great example of "surveillance too cheap to meter" https://queue.acm.org/detail.cfm?id=3511661 https://queue.acm.org/detail.cfm?id=3511661
- teddyh 5y agoDiscussed here a week ago: https://news.ycombinator.com/item?id=30326027 https://news.ycombinator.com/item?id=30326027
- dartharva 5y agoI always wondered why they didn't just do this in the first place. Despite having that much power Google always seemed oddly tolerant towards content blockers even when they were directly a slap on the face of their main offerings. Spoofing ads to act as first-party content through proxies was something I thought they were perfectly capable of making websites do with their existing behemoth network infrastructure. Surprising it actually took so long.
- jacquesm 5y agoIsn't the solution then to recognize the GTM proxy and block anything that tries to talk to it?
- atoav 5y agoAn obvious GDPR violation. So obvious, that you could think they are getting desperate due to the latest developments around Google Analytics and Google Fonts. Don't be evil.
- Karen48 5y ago[flagged]
- 1vuio0pswjnm7 5y agoStupid question: What value, if any, does "Google Tag Manager" offer the end user? By "end user" I do not mean website operator or advertiser. I never ran this stuff. There is no Javascript engine available, there is no DNS and the local forwarding proxy does not forward traffic to Google domains. I am not asleep at the wheel and probably not the target end user. But I always wondered why any end user would want to allow this garbage, assuming they exercised a conscious choice.
- andirk 5y agoGoogle Tag Manager data can be used to optimize your recommendation engine. It can help with Google Ads as well. It is a 3rd party handling some precious and maybe private data, but it has a low barrier of entry.
- charcircuit 5y agoIt benefits the end user by them "hopefully" getting an improved product in the future.
- Svetlitski 5y ago@dang Title should have (2020) appended to it
- deleted 5y ago[deleted]
- EGreg 5y agoDoes this involve a CNAME on a subdomain? If not, how do they track people across domains?
- samwillis 5y agoI run a B2C e-commerce business, and want to offer a little insight into this from the other side. Advertising online has changes a lot over the last ten years, I don’t believe advertisers are particularly happy about it. On Google we almost exclusively just to search result page advertising, very little display network and re-marketing. My comment here is about search result place adverts, with is where Google started and why they are so successful. As an advertiser search result page as arising is amazing, you are paying to get you product in front of people you pretty sure are already looking for it or something like it. When it works it’s magic. Ten years ago when we stated it was super simple, you would bid individually on keywords that people are searching for, and the tracking on your site was only about attributing advert clicks to conversions for reporting. There was no (or very little) data mining and profile building, at least from my perspective as an advertiser. Then came the “shopping ads”, you upload a list of your products and google decided when to show them with their magical ML/AI. As an advertiser you could only use “negative keywords” . Gone was the ability to control properly when your ad was shown. The latest is “smart shopping ads”, it’s a great big magic black box, and all advertisers are bing agreeably pushed towards it, all calls with google advisors are basically sales calls push it on you. Advertisers have basically no control of when their ad is shown, it’s all down to AI/ML. They have also folded the display network and re-marketing into this, you can’t turn that bit off. I am pretty sure the old keyword bidding is on its way out will not be available in a few years. In order for all these new ML based advertising work we have to send google a lot of data, there is no option. They know everything about your business, all revenue numbers, they no exactly how much every business that uses their advertising is making. The level of “spying” on advertisers is frankly amazing, I wish it wasn’t necessary, just as I wish I wasn’t being spied on as a user. Google have made a rot for their own back, they need this data for the ads to work and advertisers have no choice. I believe part of the problem is that the old style keyword bugging relied on advertisers being able to see what peoples search terms were, due to GDPR I think this is no longer possible and so they have to go the ML route. I long for going back to super simple search ads with just simple attribution.
- octoberfranklin 5y agoFolks, this stuff only works because of browser fingerprinting. Google couldn't do this before, because letting the ad-displaying website sit between them and the user meant the websites could defraud google like crazy. This idea isn't new. What's new is that browser fingerprinting got good enough that google can catch fraudful customers by sending fingerprinting scripts through their proxy and watching what comes back.
- transcendrc 5y ago[dead]
- tyler33 5y agomaybe we need better adblockers now, maybe check a hash of javascript files (instead of domain and name) or maybe even something with AI
- jmyeet 5y agoThere is one positive here: if this is widely adopted it means less third-party JS libraries run on your browser. That's better for speed and security. Frankly, Google is probably better at avoiding and fixing vulnerabilities than [insert third party ad network here] is. Plus, as noted, Google will restrict what data is transmitted to third parties like IP address. That's a positive. Fear of regulators is more likely to keep Google in line than it is to some basement operation in Serbia. I actually wonder if third party ad networks want to give up their power to Google in this way. It wouldn't surprise me if they don't. As for the negative... I think the reality is it won't be as negative as people make it out to be. Why? Imagine if this is widely deployed. It creates a single call for all tracking so the adblockers just have to focus on that finding and blocking that call. The article claims this will be difficult. It will be harder but there'll be more incentive. Next, a question: I don't know the ins and outs of GDPR and similar legislation well enough, but doesn't this put Google on the hook for data collection and transmission of that data to third party sites by virtue of them running these "proxies"? Lastly, in general I don't really care if websites run A/B tests. They do this anyway and it's done serverside all the time as is. So that part of this isn't really a big deal. Ad blocking is and will continue to be an arms race with advertisers. This feels like business as usual, honestly.
- FateOfNations 5y agoThe proxy is by default running in App Engine under the responsibility and control of the website owner, so I'd presume it would be handled the same as any other PaaS or IaaS service a company uses. The data sent Google products, like Analytics, via the proxy would still be subject to GDPR as it would if sent directly from the client. Note that they do give website operators the option of running the proxy in their own environment, it's made available as a Docker image.
- transcendrc 5y ago[dead]
- d--b 5y agoDid anyone actually look into the details? It's likely that we can still block this. My thought is: either the link between the frontend and the proxy is completely up to the developer, which means that developers can write whatever they want between the proxy and google. Possibly opening the doors to the proxy sending fake data to google - which I assume Google wants to avoid. Or the data that is being transmitted is encrypted somehow in the browser so that the proxy can't fiddle with it. A smart browser extension could be able to figure out that some encrypted data is being transmitted, no?
- noduerme 5y agoOk. MotherFuckers be pirates. Does this affect me? I have a dozen or so websites for clients running the normal google analytics script on those pages. This article is hard for me to parse, but, it just sounds like the idea of keeping some session alive and serving it off the same backend (if the same backend is calling google...?) I'm probably not understanding what's going on here or how it would affect independent web devs or privacy towards users of our sites (even if we use analytics). Someone explain how this leaks my users info if I don't integrate with any google apis on the back...(?)
- GrifMD 5y agoI’m actually in this industry! So Server Side GTM (SS-GTM) is still relatively new and a bit limited in the number of integrated partners. GTM in itself doesn’t do any tracking, not even Google tracking, its just a manager. So hypothetically you could use GTM or SS-GTM to listen for clicks on a purchase button and then send a hit to your own URL with your own user identifier (or none at all). Google wouldn’t record this anywhere. If you add Google Analytics or Google Marketing tags into your GTM container, then Google would store that data in their platforms. The real concern with privacy advocates is that you lose transparency with SS-GTM. When you run client side GTM, you can see hits going off to Google Marketing, Facebook, etc when a site has implemented those tags, and you could use ad block to prevent those network requests. SS-GTM would only show a request going to client.com/track (or wherever GTM has been set). The privacy benefit is that Facebook and the like cannot set their own 3rd party cookies to track you across the web, however Facebook allows advertisers to pass in hashed PII (like email addresses) to match with users in their database, so if you’re logged in via email, hypothetically Facebook could be linking interactions to you. I have seen very few companies do that yet though, as it’s more complicated to setup that most things and marketing teams aren’t usually made up of engineers.
- noduerme 5y agoThanks! I'm still not sure what the privacy danger is, though. When a customer clicks a checkout form on a site that's usually via a Stripe or Square form, but we do capture a receipt on the backend. If I wanted to, I could send that data to Google now through the tracking API. I don't need to since we log it all locally on the server. Aren't we just talking about another way to inform Google if a page is hit, with some session variable, which would be totally optional to the webmaster?
- nickreese 5y agoThis sort of thing has been hand rolled for at least 10 years in the affiliate space for super accurate tracking/commission attribution. This has always been the endgame. It is also common to name the reverse proxy file things like jquery.js which no sane adblocker would block.
- pcthrowaway 5y agoCan someone explain how they claim that TMS is running on 31.9% of top 10 million Alexa websites if Google Cloud itself only has 7% market share[1] (compared to AWS at 32% and Azure at 19%), if the TMS relies on the site being hosted on Google Cloud? [1]: https://www.parkmycloud.com/blog/aws-vs-azure-vs-google-cloud-market-share/ https://www.parkmycloud.com/blog/aws-vs-azure-vs-google-clou...
- pixeldetracking 5y agoToday, most websites don't user server-side tagging from Google, but the "standard" Google Tag Manager (with 3rd party tags running on the browser)
- ece 5y agoWith PlatformStorage on Android 12, which lets apps share key/values and things like this, it really looks like two steps back, one step forward for privacy if Topics/FLEDGE ever make it to browsers. The cat and mouse games need to stop. A strong privacy law that cracks down on fingerprinting and lets users opt-out of tracking and delete their data really seems necessary. Even ephemeral data collection online needs to be checked. The user should be in control, and be served context-based or random ads, unless they approve interest based ads. The LiveRamps of the world will still be able to collect 3rd party data offline, but it's not anonymous, and can be deleted, at least if you're in CA for now through the CCPA. Most users would likely be fine with consented context-based or interest-based ads, but an option for no analytics tracking or other tracking should be respected.
- qwerty456127 5y agoThis looks like an opportunity for antivirus developers. Now as antivirus software has became less relevant the talents can be reallocated to apply heuristic and signature-based code analysis to protecting web users against tracking. I would gladly pay money to a trustworthy company to sanitize my traffic blocking every bit except what I really need to be there.
- srg0 5y ago> I would gladly pay money to a trustworthy company to sanitize my traffic blocking every bit except what I really need to be there. $0/month -> duckduckgo -> browser-level protection and email aliases $1/month -> Mozilla -> browser-level protection and email aliases (relay.firefox.com) $2/month -> NextDNS -> DNS-over-HTTPS with blocklists and tracking protection $1/month -> Apple -> browser-level protection, Private Relay & Hide My Email Blocking "every bit" is a hard problem.
- ii550 5y agoNaive question? What would happen if we were to block googletagmanager.com at the DNS level AND use uBlock Origin to block all calls to "gtag (...)" functions? Source: https://developers.google.com/analytics/devguides/collection/gtagjs https://developers.google.com/analytics/devguides/collection...
- pixeldetracking 5y agoyou can also change the ressources names: https://www.simoahava.com/analytics/custom-gtm-loader-server-side-tagging/ https://www.simoahava.com/analytics/custom-gtm-loader-server... and you can host the container on your own infra: https://developers.google.com/tag-platform/tag-manager/server-side/manual-setup-guide https://developers.google.com/tag-platform/tag-manager/serve...
- LtdJorge 5y agoIsn't that this what Cloudflare Zaraz is doing?
- pixeldetracking 5y ago
- peer2pay 5y agoI'm not too familiar with the space but this sounds very similar to the solution Cloudflare acquired a few months ago called 'Zaraz'. Looks like this really will be the next level of user tracking.
- pixeldetracking 5y ago
- pixeldetracking 5y agoI'm the author, good to see this on HN, raising awareness on the topic I don't know who made the translation and when it was made, but the original article in french (https://pixeldetracking.com/fr/google-tag-manager-server-side-tagging https://pixeldetracking.com/fr/google-tag-manager-server-sid...) contains more information on recent GTM "improvements"): mainly on how you can easily change JS library names and detailed instructions on how to host your container in other clouds or self-host
- jikoo 5y agoHello pixeldetracking, Excellent article! Bravo. About the translation, yes, it is me! ;)
- gildas 5y ago> I don't know who made the translation and when it was made This page was saved with SingleFile (I'm the author of SingleFile). Therefore, I can tell you that this page was produced on Tue Dec 08 2020.
- easrng 5y agoThank you for making SingleFile, it's been an absolute lifesaver in a project I'm working on. I was having a lot of trouble trying to manually save pages with puppeteer but the singlefile CLI worked perfectly, even with added extensions. (To get extensions to work I had to add --browser-headless=false --browser-args ["--enable-features=UseOzonePlatform", "--ozone-platform=headless", "--disable-extensions-except=/path/to/extension", "--load-extension=/path/to/extension"] )
- KoftaBob 5y agoWouldn't a script blocker like NoScript or uMatrix take care of this?
- xvector 5y agoNo, that's the point
- xvector 5y agoThe engineers that work on this should be ashamed of themselves.
- perlgeek 5y agoFor a pretty long time I believed that many of the privacy and security issues in current tech could have (at least partial) technical solutions. This convinces me more than ever that regulation is necessary and, in the long run, unavoidable. Yes, GDPR rules suck for somebody who has to write software that deals with personal data, but we can no longer act as if good ad blockers would solve the problem for us.
- avodonosov 5y agoBut how can it perform cross domain tracking? The main site can only share with "Tags" the user information from the main site.
- ho_schi 5y agoTLDR I'm fine without JavaScript? I've the impression that JavaScript is worse than ever assumed during early 2000s. I don't criticize the language it is the actual usage scenario which was bad for people and got even worse. Web 3.0 should be server side again with interactive code at all in browser. No interpreter on your computer should ever execute foreign code.
- pbd 5y agowow. insane.
- manigandham 5y agoThere is nothing new about this at all. Websites can collect data and forward it on the backend since the dawn of the internet. Google Analytics has an HTTP API [1] for sending events that's used by plenty of large sites. Consolidating event collection and forwarding to various sources is a large SaaS category with several billion-dollar companies, and one of the biggest success stories is Segment from YC [2]. In past adblocking discussions, many users mentioned that they were fine with ads if they were served by the 1st party without data leakage, but the entire issue is that 1st-party on a technical basis has no bearing on the custody and access of the data itself. The only serious way to protect privacy is through legal doctrine that regulates collection and sharing. Browser-based adblockers were always a short-term technical bandaid to a much broader surveillance problem, but the real solutions take much more work. 1. https://developers.google.com/analytics/devguides/collection/protocol/v1/devguide https://developers.google.com/analytics/devguides/collection... 2. https://www.ycombinator.com/companies/segment https://www.ycombinator.com/companies/segment
- pixeldetracking 5y agoThere is nothing new for the few experts out there (yes Segment has been doing it, yes others also, yes you can do it yourself). But Google proposes it, well, the adoption is not the same... I agree with you on the legal doctrine
- bigpeopleareold 5y agoThis article and thread got me to just install NoScript finally and start using it. It's not only part of an adblocking regime, but also am sick of the persistent nagging over consent walls (me being in Europe), adblocker walls, etc. If the content is meaningful enough, I'll subscribe (like my local newspaper, my only news subscription.) Simple JS and site analytics is perfectly fine for me (and to be fair, not just because I work on analytics software myself, site analytics is a useful tool), but having it bundled in with constant nagging on top of heavily bloated sites and pointless (and sometimes slightly offensive) advertising that even leaks through adblocking gets on my nerves a lot.
- buro9 5y ago> As we have seen, Google does not explain ( https://developers.google.com/tag-manager/serverside/custom-domain https://developers.google.com/tag-manager/serverside/custom-... ) the reason for creating a subdomain of the website for its "proxy" server: > > The default server-side tagging deployment is hosted on an App Engine domain. We recommend that you modify the deployment to use a subdomain of your website instead. The reason is simple: it creates a denial of service attack on DNS block lists used by things like Pi-Hole and NextDNS. Sure, Google knows that some of the subdomains will be blocked for some block lists... but the vast majority won't be blocked on the vast majority of block lists.
- southerntofu 5y agoLooks like the only sane thing to do is to block routes to GAFAM AS directly on your router instead of relying on DNS tricks. I knew people doing that over ten years ago and i thought they were kind of crazy, but in retrospect they were right all along. What if your website is hosted by Google Cloud Engine or AWS, should we block it? I certainly would. Please find a decent host that does not use their customers as human shield/leverage to engage in criminal conspiracies against privacy.
- selfhoster69 5y agoA cron job on the network gateway that creates iptables rules to drop connections to x IPs sounds like a good plan.
- hwers 5y agoBlocking all GCP and AWS hosted sites is about as effective as turning off all javascript. It reduces the usable set of sites on the web to basically worthlessness.
- southerntofu 5y agoI've found the web to be very enjoyable without Javascript. Some sites don't work but fortunately they're usually of the SEO-clickbait kind without any sort of interesting content. I'm already blocked by many providers for using tor, which is a redflag for abusive behavior on their part. I just wish we had a manifesto, automated test suite, and dedicated search engine for websites that respect their users.
- sdfjkl 5y agoSo now Adblockers need to become like anti-virus software, heuristically determining a piece of Javascript as undesirable. The arms race will continue.
- sidcool 5y agoShould add 2020 tag to this article to reflect its date.
- throwawaygjdbsj 5y agoYou didn't think Googles effort to kill third party cookies was to help the people did you? It's a ladder pull.
- tpoacher 5y ago> How can adblockers react? They shouldn't. Perhaps it's time to stop treating a behavioural problem as a technological one. Perhaps instead a movement needs to start where if a website uses these technologies there's a way to inform them they've just lost a customer. Technology can help by automatically detecting these evils, aborting loading the page, then informing the webmaster of their offence, and the community of the offending page.
- janikvonrotz 5y ago"this is america, stupid" This won't be allowed in the EU under GDPR[^1]. [^1]: https://matomo.org/blog/2022/01/google-analytics-gdpr-violation/ https://matomo.org/blog/2022/01/google-analytics-gdpr-violat...
- mkdirp 5y agoWhich is fine, but will it be enforced? So far GDPR rules haven't done a whole lot of damage except make sure everyone knows what a cookie might be. Until the EU is willing to better enforce the GDPR rules, Google will keep doing what they're doing.
- gorhill 5y agoI read the original article back when it was published in November 2020[0]. This is what led me to introduce new static network filter options: - strict1p, strict3p [1] - header=, experimental, disabled by default [2] I used Simo Ahava's blog as test case, and with these new options, I could craft a filter to block the Google Tag Manager script on Simo Ahava's blog. However due to the lack of more test cases, no more progress has been made about this since then. Things that stood out to me when reading about all this: Simo Ahava's refers to the CNAME approach as "vulnerable"[3]: > This way you’ll be instructed to use A/AAAA DNS records rather than the vulnerable CNAME alias "Vulnerable" to what? To uncloaking as I understand it, and by extension, "vulnerable" to users taking steps to protect their privacy. Whether the very experimental solution in uBO ends up working or not, this case shows very well how Google Chrome's Manifest Version 3 (MV3) put a lid on innovation content-blocking wise: All the new filter options introduced above can't be implemented with declarativeNetRequest. === [0] https://www.pixeldetracking.com/fr/google-tag-manager-server-side-tagging https://www.pixeldetracking.com/fr/google-tag-manager-server... [1] https://github.com/gorhill/uBlock/wiki/Static-filter-syntax#strict1p https://github.com/gorhill/uBlock/wiki/Static-filter-syntax#... [2] https://github.com/gorhill/uBlock/wiki/Static-filter-syntax#header https://github.com/gorhill/uBlock/wiki/Static-filter-syntax#... [3] https://www.simoahava.com/analytics/server-side-tagging-google-tag-manager/#custom-domain https://www.simoahava.com/analytics/server-side-tagging-goog...
- GoblinSlayer 5y agoSure that means vulnerable to widespread blocking.
- Vinnl 5y agoFor context, gorhill is the author of uBlock Origin. And for context on MV3, see https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-best-on-Firefox https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...
- danShumway 5y agoThanks for adding this comment. My immediate reaction when seeing this was that I thought it looked familiar to previous conversations I saw a while back. But I didn't know for sure that they lined up exactly, and I wasn't looking forward to doing the research to find out. > All the new filter options introduced above can't be implemented with declarativeNetRequest. My understanding was that stuff like CNAME uncloaking was already unsupported in Chrome[0]. Of course, Manifest V3 won't make the situation any better though. [0]: https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-best-on-Firefox https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...
- mkdirp 5y agoIt is clear Google is finally feeling the hurt from adblockers and the like. That means we are winning. Google knows it's not what people want, but they clearly do not care. In my opinion, if you work for Google on things like this, you are equally to blame. You have Google on your CV, you can easily go elsewhere and find a decent job. Having said that, uBlock Origin, and I'm assuming other similar extensions, offer inline script filtering. The code being served has to have some common code since it's all coming from a single org. What is stopping a filter that includes a filter like this? The issue obviously being that this still prevents DNS filters from blocking Google, which is equally a big issue. Assuming the scripts indeed have some common code that can be blocked, perhaps this is where we start crowdsource filters. Something that runs in the background, and inspects scripts, which then gets posted to a server, validated automatically, and then later served as a block list that anyone can download. [0] https://github.com/uBlockOrigin/uBlock-issues/wiki/Inline-script-tag-filtering https://github.com/uBlockOrigin/uBlock-issues/wiki/Inline-sc...
- was_a_dev 5y agoYes a Google employee could go work elsewhere. But is there an equally well paid position at a more ethical company? As far as I can tell, all FANGs are as unethical as each other
- Perseids 5y agoI don't understand the reasoning here. How does being paid more justify unethical acting? Especially since you are getting by very very well in the tech industry in general. Isn't that like saying "I'm kicking puppies all day, but it's paying enough to finance the second Lamborghini, so how could I decide against it"? (If you were referring to moral offsetting, that could indeed work, assuming you donate enough to charities, but your post didn't sound like that.)
- was_a_dev 5y agoHow does being paid more justify unethical acting? Honestly, it doesn't. But trying to appeal to someone already working in an unethical position isn't going to work - that person themselves is unethical. Like most things, the driving force will be down to economics and prestige. What else is keeping that employee at Google? I doubt it is loyalty
- deleted 5y ago[deleted]
- thrwawy283 5y agoI think it's going to be important to recognize and block javascript/wasm by the bytecode it compiles down to. As far as I know we don't have this ability to "jump into" the process. ublock or umatrix can't be extended to do this currently. You could send the scripts the browser downloads to an outside service for fingerprinting, but doing this in the same browser isn't possible right now. This wouldn't completely stop a server from generating code that compiles to slightly different bytecode. Then the move would be to identify side effects of the execution? Cat and mouse...
- jeroenhd 5y agoThis kind of data collection abuse is why I think we need more addons like AdNauseam [1]. Unlike uBlock Origin, it's not available from the Chrome web store anymore, which is a good sign that Google hates these types of addons more than they hate simple blockers. Blocking A/AAAA domains with custom URLs to prevent tracking is almost impossible, so instead let's flood the trackers with useless, incorrect data that's not worth collecting. [1]: https://addons.mozilla.org/en-US/firefox/addon/adnauseam/ https://addons.mozilla.org/en-US/firefox/addon/adnauseam/
- cobbzilla 5y agoCan uBlock do payload inspection? It would be easy to block an upstream json POST that matches a certain structure.
- consumer451 5y agoI am very interested in this, thanks for sharing. Adding another party into my web browsing is always a tough pill for me to swallow. I am also a noob at reading trust signaling. What are some of the reasons that I should trust this dev and their processes?
- danuker 5y agoYou should not trust them. You can download the add-on and inspect it yourself, if you know some JS. Right-clicking yields this URL: https://addons.cdn.mozilla.net/user-media/addons/585454/adnauseam-3.12.2-an+fx.xpi https://addons.cdn.mozilla.net/user-media/addons/585454/adna... But it seems to include a lot of code, including some uBlock Origin code. Either way, this kind of sabotage might get you banned on Google. Be mindful of the risks, and have contingency plans.
- jeroenhd 5y agoYou should put the same amount of trust in this dev as you should in any other. I myself trust Mozilla's store reviews enough to run the addon, but if you're more conservative with trust, you can inspect the source code and build the addon itself. The addon comes down to a uBlock Origin fork with different behaviour. I believe most of the addon code is actually the base uBlock code base. I haven't seen any obvious data exfiltration in my DNS logs, but then again I'm just another random on the internet. If you don't feel comfortable installing something with a privacy impact as broad as an ad blocker, you should definitely trust your instincts.
- donohoe 5y agoTo be clear, this is not new - many of the comments suggest this is some new front by ads/marketeers against privacy. It's not, it's just being used more. Server-side analytics has been available as an option for decades. You can do server-side GA for a long, long time now. Its generally a bit more of a pain to setup and and can be a bit most costly (depending on your cache/cdn/hosting setup).
- eterevsky 5y agoIt doesn't sound like this technology interferes with the main purpose of adblockers: blocking ads. As long as I don't see any ads, I don't see why I should care how the website tracks my behavior.
- kajal7052 5y ago
- UltraViolence 5y agoBut isn't GTM easily foiled by blocking the domain in NoScript?
- henrydark 5y agoBasically it's time to treat ad trackers and everything involved as viruses. Adblock software needs to start fingerprinting and monitor mutations in privacy-harmful javascript packages
- pl0x 5y ago
- stiray 5y agoWell, I am blocking google tag manager and everything else from google, also forever caching CDNs and disabling caching for everything, for more than a day. Also blocking every domain found on any blocklist including CNAME resolving. And injecting my scripts trough mitm proxy that effectively disable any fingerprinting for my whole home network and all the mobile devices (they are all configured to use the proxy trough ssh tunnel). Some sites dont work. Do you think I care? Do you think I will ssh home and change the settings for your site as it is so special, that I "need" to have its content? Every content is quadrupled on internet and if one site doesn't work, I go to next, I couldnt care less. Someone doesn't want me to be his visitor? I will cry a river (not really), close the tab and find someone else while the site will have one visitor less. (thank you hacker news for playing it fair!)
- everdrive 5y agoDo you have an article somewhere which explains your set up? I would love to block Google tag manager as well, but don't quite know where to start.
- soheil 5y agoWhat if blockers did not allow any js loaded form any cname except the currently loaded one? This would surely break a lot of website that load their js from something like static.example.com but at least would help against server side tracking, perhaps it could be an optional feature that is off by default. Setting up a proxy for the same cname as the current page is loaded on is several times more difficult so I think Google wouldn't consider that as an alternative anytime soon.
- red_admiral 5y agoSo, this means that they can do server-side analytics with just one JS call from the browser. But doesn't adblock still stop them serving any ads to me as a result, as those presumably still come from the ad server's CDN?
- john567 5y agoSo, where I work. I actually manage our Google Tag Manager infrastructure. Our marketing department make change requests that we review and implement. They do not get to do whatever they want. We actually consider it to be a backdoor. It's a useful tool but it should be managed by the people building the product and we have to clean up and remove tracking code when it has served it's purpose.