I'd accept that without issue. I don't mind ads, I just can't accept the intrusive tracking, including being retargeted.
You can do much better than "interested in video games or technology" if you know a bit about your users. This tracking makes advertising much less annoying (occasionally veering into useful).
Advertisers will adapt. What you have to accept is more annoying advertising coupled with increasingly error-prone code in both ad-blockers and ad-blocker-blockers. The only one that wins is Moloch; everyone else is worse off.
> What information one can get from someone's browsing history is awfully invasive.
Is it? Advertisers don't get some kind of toast on their phones saying "Joe, 34 from Topeka with a toaster fetish, has just visited your site!" along with pictures of Joe and said toasters. That's a strawman that the anti-tracking people love to hint at, but it doesn't actually work that way.
What actually happens is that advertisers target broad categories. They say, "show this ad to midwesterners who've visited sites about toasters", and that's what happens. There's no secret dossier just waiting to be sold to the highest bidder for purposes always left unspecified.
Yes, centralized trackers do end up learning a portion of your browsing history. But you don't have to accept third-party cookies. You can run with an ad blocker. And you can just reset your cookie[1] state every so often. You can do any of these things. You'll just pay for your paranoia with a shittier web.
[1] Yes, I know about non-cookie trackers. Advertisers stashing information where it's hard to clear are scum. It's up to web browsers to make it easy to flush all server-visible state.
But the likes of Google and Facebook know exactly that. They have it stored somewhere and it's only a matter of time until it gets stolen by organised criminals, religious fanatics or oppressive governments.
The problem isn't that all advertising is bad. The problem is that we visit websites expecting one entity to own and operate it. Instead we get hit by a thousand entities, each with its own privacy policies and agendas. That's unworkable from the consumer side.
Now there is also the debate of whether all sites deserve to be able to run javascript. I say no. But some people here think that even rendering a blog article should require a lot of client side scripting.
You're assuming the server-side scripts won't share data with a central server.
Browser fingerprinting is the only way I can think of, and between the phasing out of flash, java and silverlight, and having javascript disabled by default, browser fingerprinting is pretty much toothless.
I go on site abc.com, which gives me the cookie abc:111 Then I go on xyz.com which gives me the cookie xyz:222
Because of the same origin policy, xyz.com can't access the cookies set by abc.com. Abc and xyz can communicate as much as they want on the server side, they will not be able to tell that abc:111 and xyz:222 are the same user (absent additional information: browser fingerprinting, email address if you have an account on both, etc).
So you visit abc.com for the first time, get an ad image served from the same domain (but was provided from the ad network), have the cookie set, the ID is noted by the ad network.
You then visit xyz.com, a new cookie is generated, which can be tracked by the ad network as the ID is the same.
So you now get tailored/tracking adverts without any third party domains being accessed by your browser...
Well, that is effectively using abc as a tracking server, and abc.com would quickly be added to the adblockers lists. Effectively this is the current model.
The other thing is that I may visit abc.com and xyz.com but this particular combination may be unique to me, i.e. I may visit nytime.com and ford.com which may use the same ad network, but you may not visit nytime.com at all and instead wsj.com.
Browser fingerprinting is a different problem. It does defeat the same origin policy. But I suggest you look at the sources of entropy: https://panopticlick.eff.org/ With javascript off, there is virtually no entropy, just your user agent and HTTP_ACCEPT header. You can't fingerprint a browser at all.
If you enable javascript but not plugins, then the Browser Pluggin details give you some entropy, although looking at the list those a relatively generic and would likely be the same on many machines.
If you enable plugins (flash, silverlight, java) then you have a massive amount of entropy but realistically all of these plugins are almost gone from major browsers.
The ad cookie/ID is then sent from the abc.com server to the ad network (along with whatever data they need to determine what ads were seen/clicked), who collate all the data from wherever their js file is running, thusly allowing them to track you, without any requests from your browser being sent to any other domains other than the ones you directly visit.
If your server has the ability to say "Hey, Jane doe saw your ad just now" when she didnt, thats a recipe for massive fraud.
You might say CPC would work and then just send to unique urls the ad network can track- This too wont work, as it allows the publisher to do things like auto-pop the link, hide it in 1x1 iframes, etc.. Overall its a security and fraud nightmare that involves huge cat-and-mouse games.
Not to mention the fact that the ad networks have no incentive to change. As more inventory drys up, the spends go up with them (competition increases) - Supply and demand, mostly.
I don't give a damn about tracking. All the doomsday scenarios that those in the anti-tracking camp imagine have not come to pass.