10 ms·
This Student Project Could Kill Digital Ad Targeting
- huntedsnark 13y agoI am unsure as to what purpose the game aspect serves, if you're installing this is a browser extension couldn't you just give the service access to all your cookies all at once rather than having to 'mine' them? What am I missing?
- Yaa101 13y agoThat it will drown the readers of those cookies, the advertisers, into a sea of fake data, forever fauling up their ability to know who is who.
- PavlovsCat 13y agoYes, but why require users to play a game for that, why not skip that part and just mess with the cookies?
- rogerbinns 13y agoBecause any decent implementation doesn't trust client cookies. Typically the server signs them so the only messing that can be done on the client side is to delete/not send them.
- Kiro 13y agoStill doesn't explain why you need a game. You add your cookies to a pool which randomly exchanges them between users. No game needed.
- rogerbinns 13y agoYou don't "need" a game. The point of the game is fun while screwing with people trying to profile you, but poisoning their data instead. There is a precedent with barcode games of collecting things http://en.wikipedia.org/wiki/List_of_barcode_games http://en.wikipedia.org/wiki/List_of_barcode_games Randomly exchanging cookies with other users (assuming they are even structured that way) is a considerably larger coding challenge than just examining cookies and giving an arbitrary score.
- Yaa101 13y agoI dunno, I haven't made this up, I just have a wild imagination... Besides, I play the hosts game with advertisers.
- austenallred 13y agoThis seems like a very complex alternative to installing Adblock
- bnegreve 13y agoHum, but Adblock doesn't prevent tracking through cookies.
- jbnicolai 13y agoI can recommend looking into ghostery for that.
- subpixel 13y agoExcept that blocking cookies renders much of the web unusable. I use Ghostery and am often finding that videos don't load, sometimes whole pages don't load, etc. I love the idea of a tool that actually uses advertising technology to subvert it.
- andyzweb 13y agomost websites that don't function with cookies suck anyways
- gohrt 13y agoGhostery doesn't block "cookies", it blocks content from blacklisted sites.
- subpixel 13y agoCorrected! (Actually there used to be a 'cookies' tab, if I recall correctly, but no more.)
- graue 13y agoYeah, this sucks. It doesn't happen often to me, but Kickstarter and US Airways' online booking site come to mind as two I've hit a few times that are broken with Ghostery. Which is two too many. Still, I'm willing to put up with the slight inconvenience of just disabling Ghostery on those sites once identified.
- uptown 13y agoSo you're exchanging targeted ads for identity theft?
- andyl 13y agore-writing cookies with misinformation: creative!
- Tichy 13y agoNot sure exactly how it works, but it gave me the thought that making collecting ads into a game could be fun. For example there could be competitions for getting specific ads (the most expensive loan, the weirdest health treatment, and so on...). Maybe this game already does that, not sure.
- arjn 13y agoSo is this a kind of a reverse-Denial-of-Service-by-misinformation attack ? You can bet some people in the Ad industry will insinuate this is a kind of "hacking".
- glesica 13y agoOr claim copyright over the cookies they set in your browser...
- dredmorbius 13y agoThey can try, but copyright covers expressive works of original authorship. Not machine-generated identity tracking.
- dntrkv 13y agoI really don't see the point of this. Who is the target audience for this? Do they really think enough people will use this to the point that it will "kill digital ad targeting"?
- tankbot 13y agoThere is no target audience, it's not available for any audience. There's also no 'they', it's one student who created a program as a class project. It's interesting because the game involves collecting tracking cookies into your browser, so that any site that tries to track you thinks you're everyone in the cookies. It's hard to target a needle in a stack of needles.
- deleted 13y ago[deleted]
- raldi 13y agoOf course not. An honest headline would have been "Student writes game that randomizes your ad-tracking profile." But an honest headline wouldn't have baited as many clicks. (Flagged.)
- Buzaga 13y agoa lot of people hate advertising, ads are everywhere, adding gamification to it creates a cool dynamic where people will take pleasure in sticking it to them, get a boost of privacy feeling and sense of power like(personal example) "oh marketers you want to teach this rails programmer rails? how cute, hadn't caught this one yet" pokemon, man, it's fun. "eating cookies", you know? To me it's a really creative and beautiful idea
- EGreg 13y agoThis might be interesting for you if you are concerned about tracking across sites: http://www.faqs.org/patents/app/20120110469#b http://www.faqs.org/patents/app/20120110469#b
- sweetp 13y agoI use Cookie app from sweetp productions on Mac OSX to deal with tracking cookies, it seems to work well
- kposehn 13y agoInteresting. I have yet to find anything that can really mess up our own targeting algorithms, but I do find what she has done to be quite fascinating.
- X4 13y agoAre you saying that you've counter-measures against this type of attack? Poisened or fake-chunks/blocks have been infiltrated into P2P Networks for many years and P2P networks were able to fight against it pretty well. But I cannot imagine a way how you can take measures against this type of attack. Please tell us more.
- leephillips 13y agoIf the game manipulates cookies only, then all the other methods of tracking users are already immune. And many of the more "sophisticated" marketers have long ago adopted these methods in addition to or instead of standard cookies. I still think this game is a charming idea.
- kitcar 13y agoThere are a few different ways; Flash Shared Objects (https://en.wikipedia.org/wiki/Local_shared_object https://en.wikipedia.org/wiki/Local_shared_object ), using Browser + Machine ID information to make sure cookies are linked to the right machine, etc... - see http://samy.pl/evercookie/ http://samy.pl/evercookie/ for a few different other methods
- aaron695 13y agoSo the idea of the program would be, with enough mis-information it starts working for everyone not just users of the program. (Else there's little point to it) So really it's not about the users it's about stopping them destroying your current accurate data. So all you need to do is identify if a user is a malicious one and ignore them. So how does one identify dodgy data? Benford's Law is one example. Of course this can be fought, but then you fight back and the war begins.
- tokenadult 13y agoFrom the end of the article kindly submitted here: "'In its current state now it's a weapon,' said Ms. Law. 'Do I want it to get in the hands of the Syrian Electric Army? No!' "To be fair, Ms. Law is not the most experienced computer programmer, so she said she needs assistance to make Vortex more secure. She has an undergraduate degree in Philosophy and Photography from the University of Melbourne in Australia, and 'crash-learned' programming." So it sounds like the code base and the security model of this new project need thorough review. But if the project works, we could all have fun with an online game while obfuscating our consumer behavior data. Who would like to contribute to a project like this?
- freshhawk 13y agoA combination of a good game mechanic and good method of poisoning tracking results would get my contributions in a second.
- hmind 13y agoI don't get it, why is obfuscating consumer data a good thing? If I have to see ads, I'd much rather they be relevant things like hosting providers than random things I don't care about...
- gbrindisi 13y agothe point is that you dont want to see ads, you are forced to
- raheemm 13y agoand that privacy data is used to tailor ad serving.
- nemothekid 13y agoIf I don't want to see ads, then I don't use the service.
- 13y ago
- nathas 13y agoIf cookies are being shared, and the users have access to them, what about the cookies from sites with passwords in them...? I don't _think_ I use any sites that do something that dumb, but I'm sure they exist. I would never use this specifically because of that.
- LandoCalrissian 13y agoIt's called FakeBlock.
- lurkinggrue 13y agoThat is one amazing app, That George Maharis is a genius!
- kleinsch 13y ago"Part of the goal is to understand how ad targeting algorithms peg people in specific audience segments. "That's why it needs critical mass, because only when enough people are playing can we start seeing patterns in what kind of cookies or attribute-identifiers companies look for and discriminate with," she said." Doesn't sound like she knows how ad serving companies operate. These days many companies are just storing one cookie with some sort of unique identifier for the user, then storing user profiles, targeting data, behavioral tags, etc in a server-side cookie store. You're not going to be able to gather much data about companies that operate like that by analyzing huge numbers of their cookies, since every user will have a unique cookie.
- hawkharris 13y agoBy providing misleading cookie info, couldn't you make the targeted ads even worse? For example, suppose that the cookies are arbitrarily altered, and they make advertisers think that I'm an older man who's extremely wealthy and takes vacations. Now, whenever I visit travel websites, I'll see higher prices, whereas if I hadn't mislead the advertisers, I might see prices that are more reasonable and appropriate for my age / income bracket.
- freshhawk 13y agoThere's a mention about selecting a "shoe lover profile" when shoe shopping or something along those lines so it seemed to me that this was accounted for. "For instance, if a user decides to go shoe-shopping for summer, he or she could equip their browser with the cookies most associated and aligned with shopping, shoes and summer" You could do the same thing by trial and error switching profiles or some kind of way of sharing "this profile gives low prices at X travel site" information between users.
- raldi 13y agoThe shoe shopper could also just go to http://www.google.com/ads/preferences/ http://www.google.com/ads/preferences/ and add it under the "Interests" section.
- freshhawk 13y agoThat wouldn't affect differentiated pricing based on user profile information. It would get you more ads in that vertical but wouldn't get you the cheapest prices.
- fearlessleader 13y agoThis will work until they just start encrypting cookies server-side.
- qq66 13y agoTargeted ads are actually small businesses' greatest weapon against large businesses. My company, LiveLoop, sells PowerPoint collaboration software. How do we get it in front of users? We buy Google ads. For 50 cents a click we get in front of the narrow sliver of people who desperately want our software NOW. And our users are ecstatic about our product once they start using it -- without targeted ads, they'd never have heard of us. How does Google Apps, one of our competitors, advertise? However they want to. Billboards in Times Square. Super Bowl commercials. Anything they want, really. Startups begin by serving narrow audiences, and targeted ads are today's best way of finding narrow audiences. This may end up hurting the wrong people.