In our case we were going to use fingerprinting to prevent sweepstakes fraud. People would enter multiple times despite the rules specifying you can only enter once. A lot of people were not sophisticated so much of it was easy to detect (eg same contact info but different email). Some were less easy to detect so I figured fingerprinting could help.
I never finished it so it was never tested in a live environment. We wouldn't have shared the info with anyone except in the case of fraud so I don't see it being a problem.
In the same way that a vendor can't force you to honor their intention for you to view, read, and seriously consider the ads sent alongside their content, you can't force them to honor your intention to maintain privacy when you're visiting their servers. If it's fair game for you to mangle their content inside the browser before it gets presented to you, it's fair game for them to ask your browser to send back some bits so they can derive benefit they want. It's your responsibility to select a browser/extension combo that is providing the level of privacy and anonymity that you desire.
There's a bit of an escalatory reciprocal at work here; users demand more and more for free, and companies are left with fewer and fewer ways to get consumers to consciously pay for their goods and services.
I have never worked in adtech or user tracking, but I understand the mindset of those who do, and I don't feel that it's at all inherently evil, as some people make it out to be.
Part of the reason that sophisticated spam operations like private link rings and social media astroturfing are a required part of today's web marketing toolbox is because users are doing everything they possibly can to avoid seeing advertisements alongside their content. All this accomplishes is that ads migrate from explicitly-labeled boxes on the side of the page to the content sections, as "sponsored stories" on news sites, astroturfed comments on blogs, and stuffed product reviews on ecommerce sites.
I don't think there's anything necessarily wrong with end-users running an ad blocker extension if that's what they want to do, and by no means am I suggesting any restriction on their freedom to do it. I run such an extension myself (though I usually wait until I come across a particularly egregious site to install it).
But by the same token, I don't think there's anything wrong with a company attempting to extract what data they can from a user's interaction with them, as long as it's voluntarily given by the user or the user's browser. There is no reason that they shouldn't be free to attempt to fingerprint individual users who are visiting their site, especially since in most cases, the goal is to enhance user experience by providing ads they might actually find relevant instead of asinine.
Just my two cents. I know it doesn't fit everyone's favorite narrative of "business trying to make money are evil", but I think this group of frequently-maligned developers deserve someone to stand up for them once in a while.
For example, if you're a delivery service and you store delivery history, you put your customers at risk of being burgled.
So the ethical attitude would be to avoid collecting and storing anything you can avoid.
I don't think that this type of fingerprinting is necessarily any more insidious/risky than any other ordinary activity one can undertake online. That's not to say that data is not valuable to someone with malice, but I don't think it's so especially dangerous that it's inherently inappropriate to collect it. Ultimately, it's the user's responsibility to find a browser that has strong identity protection features and use them properly if it's a major concern for them.
Things like storing a Flash cookie obviously contradict a user's intention, but I don't see that as automatically unethical just because the user would prefer if it didn't happen. At least not any more unethical than contradicting the publisher's intention of displaying ads.
User A doesn't mind seeing ads, but user A doesn't want to be tracked by corporations that sell personal information so she clears cookies on each browser exit.
User B hates ads because reason (malware, performance, distracting, etc), so he uses an ad blocker. He doesn't care about fingerprinting across sessions so he doesn't bother clearing cookies.
Do you see how you are are throwing user A under the bus because you have a problem with user B?
There is no excuse for trying to correlate users trying to maintain privacy as a response to an entirely different group of users using ublock.
Servers are not committing any ethical violation by attempting to track unique user identities through non-disruptive utilization of normal browser features like cookies, plugins, and ETags.
The unifying thing is that companies want to display ads, but users don't respect that want and employ technological solutions to block ads. That's all well and good.
But by the same token, when a user wants to browse anonymously, there is no reason that servers shouldn't utilize the resources that are regularly available in a typical client-server exchange to attempt to identify the user.
The only contrary argument is that companies should be forced to respect the user's wishes, just because the user wishes for it. That's not how the world works. If the user is concerned that their browser may be leaking information, they should take responsibility and ensure it isn't. It's not on the company's head to ensure that the user's wish for privacy is respected any more than it's on the user's head to ensure that the company's wish to display ads is respected.
Are you okay with that logical conclusion?
>The only contrary argument is that companies should be forced to respect the user's wishes, just because the user wishes for it. That's not how the world works.
It actually is how much of the world works. What ends up happening is people with no regard for ethics keep abusing this until regulations get passed to force people to stop doing things they know people don't want.
No. That's not the logical conclusion; it's the extremist conclusion.
The difference is that with things like cookies and ETags, the browser is designed to return that information back to the server.
The server is not engaging in any malicious injection of foreign binaries or hijacking of program behavior. It's not doing anything to break outside of its allowed permission sandbox. It's using intentional, supported functionality in a non-disruptive manner. The only thing is that some people don't like that some of that functionality allows them to ascertain a user's identity after the user has cleared his/her cookies (ignoring here that the much larger privacy concern is the nearly-constant IP address of the user's home internet connection).
If that's the complaint, and in this case, it is, then there is no fault from the server. The user should ensure that his/her browser is making those privacy controls available. Ignoring the problem and shaming companies for making the connection misplaces blame and allows the problem to remain, exploited only by those whose intent may actually be malicious.
Obviously, there are many malware vendors who use their software to track users. I'm not defending them, nor am I defending those who exploit security bugs to get at data that they're not supposed to be able to access. That's not the case now; all of the fingerprinting methods discussed up to this point are fairly simple and do not involve coaxing software into any bad or illegal behavior, nor do they involve executing any spyware on the client machine.
>It actually is how much of the world works. What ends up happening is people with no regard for ethics keep abusing this until regulations get passed to force people to stop doing things they know people don't want.
No, it's not as simple as something "people don't want". Ethics are not about wants and conveniences, they're about behaving in a fair and honorable way. That's not the same as, and in fact it's sometimes the opposite of, what a customer may demand. Companies have obligations to non-customers as well.
Today, customers are demanding that web publishers make all of their content available at no cost and with no ads. If we take the attitude that "if you don't want users to strip out your ads with client-side software, don't publish it online", it's just as fair to say "if you don't want companies to correlate your visits with server-side software, don't leak information that allows them to do so".
If there's beef to be had with anyone here, it's the browser manufacturers who can't seem to figure out a way to engage in a normal conversation with a peer without leaking data that can be used to uniquely identify the user on the server-side.
It's not ethical to correlate a user's sessions using etags when they have cleared cookies and caches (or set DNT header). You are expressly behaving against the user's wishes, and there really is no difference in exploiting the browser in other ways to reveal other personal information.
>Today, customers are demanding that web publishers make all of their content available at no cost and with no ads.
Did you even read my original comment? Privacy sensitive people and people that don't like ads are not the same set of people. Stop using ad blockers as a justification for unethical privacy violations.
You don't see a difference between analyzing the data a browser gives back during normal operation and exploiting security bugs to force browsers to give up information that is supposed to be private? They're tracking your session based on the data that your browser normally sends. They're not crossing any boundaries or stealing any secrets.
The difference between using ETags and exploiting a bug to get secret information is that ETags were never meant to be secret or private. No one thinks they're "personal information". They're normal information that happens to be useful for uniquely identifying a user, as are Flash cookies.
The customer can ask politely not to be identified, but there is no reason that companies have to automatically consider that an ethical obligation just because customers wish it was that way. Customers also wish everything was free.
If you feel browsers should support completely untraceable sessions, that's a feature request. It's not an ethical violation on the part of others that they're not imagining this feature already exists.
>Did you even read my original comment? Privacy sensitive people and people that don't like ads are not the same set of people. Stop using ad blockers as a justification for unethical privacy violations.
We're not talking about specific people, we're talking about general principles. If ad blockers are not unethical in principle, then neither is server-side session tracking, because both stay 100% within the technical bounds without coercing any information from or disrupting the ordinary operation of the other party.
It seems that your conception of ethics really does boil down to "the customer wants it", so it's going to be hard to continue this conversation.