(Not Joking) This was vital to me at work, because I share my screen most of the day and I started getting ads for a Vacation Cruise that was sexual in nature that were unbelievably embarrassing.
https://support.google.com/accounts/answer/2662856?co=GENIE....
I would suggest turning off ALL personalized ads on your Google profile, but in case you like getting ads about Pet products and just don't want your health information shared you can just deselect all the "health", "diet", and "medicine" categories.
It really sucks to target block ads this way and you might even need to stretch to blocking categories like "family and relationships", to get all the ads you don't like.
They're changing how extensions can access web requests, in order to increase user privacy and prevent phishing. This requires all extension devs to change how they handle web requests. ublock is making a stink about how it's "targeting them", despite it being a change that all devs have to make, and you can still block ads with the new version. Adblock plus works fine with the new changes, for example.
More here: https://www.xda-developers.com/google-chrome-manifest-v3-ad-...
It's really not. The new mechanism for blocking ads is extremely limiting - not unlike what Safari provides. While Google's stated intention is to protect user's privacy it just so happens to cripple extensions that pose the greatest threat to Google's business. If Google wasn't one of the world's largest ad companies, perhaps their statements could be taken at face value. But perhaps in that case they would have taken the time to come up with an API that could achieve the goals of both Google and uBlock Origin.
Edit:
> Adblock plus works fine with the new changes, for example.
Adblock plus is an "ad blocker" who's main concern is protecting the interests of "good" advertisers, not those of its users.
uBlock Origin can change how they block ads for the new more secure manifest, just like AdBlock plus does. Even if you don't like ABP as a company it is an example of how it is still possible to block ads on the new more secure Chrome manifest, making it sensationalism to claim otherwise.
So we're throwing the baby out with the bathwater because Google's extension approval process is so dismal it allows through a large minority of abusive extensions, and this is supposed to make us feel better about a change in the API that gives this dismal and apparently near-useless approval process more control over the contents and behaviour of ad blockers?
> uBlock Origin can change how they block ads for the new more secure manifest, just like AdBlock plus does
Which, again, entails UBlock Origin moving from a frequently updated list of blocking rules relying on sophisticated wildcard matching functionality to a hard-coded, fixed-size static list of blocked URLs that are not allowed to contain any wildcards for redirecting to more secure or private versions of content, and which cannot use any other kind of more complex ad-blocking logic. A hard-coded list of dumb blocked domains that is infrequently updated only with Google's approval (via the same dismal process that allowed through 42% of abusive extensions above...) of a complete re-submission of the blocking extension, approved or rejected at their whim and leisure, because live updating rulesets will also be banned "for security".
"UBlock Origin will be able to work every bit as poorly, and be every bit as easily defeated as Ad-Block Plus' unsophisticated, frequently useless filters are, plus its rules will get updated far less often" is, again, not in any way the good thing you seem to be pretending it is.
Just some highlights about this "great" change that you're signing the praises of, discoverable from the very link you posted:
> uBlock Origin heavily relies on pattern matching, and the extension developer stated that it is not possible to retrofit his extension’s matching algorithm to meet the APIs requirement. The API would also require a complete extension update to simply update the filter list, which would be a far too frequent activity considering the frequency with which these filter lists are updated. Of course, these updates would also hinge on Google’s extension review criteria and processes.
Hmmm.
> The blocking list must be present in the extension at install time and can’t be updated without updating the entire extension. This is subject to Google’s extension review criteria and processes. This means you won’t be able to opt-out of something like AdBlock Plus’ Acceptable Ads program, as the proposed new API doesn’t allow for rulesets to be turned on or off in the same extension.
Hmmm.
> declarativeNetRequest’s redirect action can only redirect to a static URL; meaning that you cannot redirect using the new API from a pattern like “://www.youtube.com/embed/” to “https://www.youtube-nocookie.com/embed/%2”. This is pretty much all my Privacy Enhanced Mode for Embedded YouTube Videos extension does, by the by.
Hmmm.
> Some extensions, like the EFF’s Privacy Badger that compiles lists of and blocks web beacons and trackers based on browsing activity (a method that breaks a fair number of websites), wouldn’t survive the transition.
Hmmm.
This API redesign "for security" just so happens to expertly fuck over the most powerful privacy and ad-blocking extensions, while leaving neutered crap like Adblock Plus With Mandatory "Acceptable" Ads working.
None of this is an accident. With Ublock Origin neutered out of usefulness, driving users back to Adblock Plus with mandatory acceptable ads that just so happen to whitelist Google will, of course, be a big win for Google's ad revenue.
It's almost like someone sat down and asked "How can we get rid of ad blockers, without impacting spyware?".
No. The accurate quote is (my emphasis) "According to Google, 42% of MALICIOUS extensions have used the Web Request API since January 2018".[1]
Note that the source for this quote is Google itself, so they picked this one statistic for publication. We do not know what else they found which is not published, i.e. it's potentially conveniently self-serving toward their manifest v3 narrative.
I reiterate: deprecating the blocking ability of the webRequest API will break key parts of uBlock Origin ("uBO"), and will break uMatrix completely, because of the hard-coded matching algorithm of declarativeNetRequest (there are other issues) which is merely an implementation to enforce EasyList-like rules.
I know how uBO/uMatrix extensions work, I wrote them from scratch. If you want to argue why they will work fine, you will have to do better they merely repeating Google's narrative regarding changes in manifest v3.
ABP will be fine because the primary purpose of ABP is to serve as a revenue source for Eyeo GmbH through its "Acceptable Ads" product (of which Google is a partner), which can still function just fine with the declarativeNetRequest API -- as shown by it's Safari iOS version.
I am not alone in my criticism, for instance the EFF: https://www.eff.org/deeplinks/2019/07/googles-plans-chrome-e...
Chrome Web Store allows extensions with remote code execution capability[2], this is the foremost issue and it's the one they could have fixed a long time ago with no API changes. That it has not been fixed is what you should be questioning.
* * *
[1] https://www.xda-developers.com/google-chrome-manifest-v3-ad-...
No it isn’t. Your take is absolutely inconsistent with the on the ground impact of the specific technical changes in Manifest v3.
> and you can still block ads with the new version.
Based on a static, fixed limit of URLs. That cannot be updated without resubmitting the extension to Google for reapproval. Which match using a fixed, dumb matching algorithm that Google alone controls (negating a number of the more sophisticated pattern-matching based rules UBlock Origin relies upon).
> Adblock plus works fine with the new changes, for example.
That the crappy adblocker that has largely sold out to advertisers is unaffected by this change is hardly a ringing endorsement. Ublock Origin’s dev is complaining about this new API precisely because it cripples the much more sophisticated ad blocking rules that are Ublock Origin’s entire advantage over less sophisticated, less performant, less effective ad blockers like Adblock plus.
Having to constantly turn off ad blocker is not only inconvenient but is also slightly embarrassing when I get called out for not looking at things the way a customer would be seeing them.
I think it's safe to say that anyone who is diagnosed as a paranoid schizophrenic is being targeted, which makes it all the more difficult to suppress feelings of paranoia and distinguish actual tracking from coincidences. I doubt there are any people who are perfectly sane driven mad by advertising, but it's quite plausible that it has a negative effect on people trying to cope at the margins.
Gives you everything you seek from a private session
I am extremely cautious to never look up health info without using a VPN and to never discuss health in email exchanges.
After receiving a diagnosis from my doctor some years ago for a condition, a week later I received a targeted snail mail ad for the condition using my full legal name, which only the DMV, my doctor, and the property assessor use. All web stuff, purchases, email, use a nickname instead.
I discussed it with the doctor's office. They said they are HIPAA compliant and wouldn't say more other than referring me to their privacy policy. The privacy policy like ALL medical privacy statements these days contains vague information about "sharing" with third parties and partners in certain circumstances which as written don't appear to be selling private medical data for advertising, but clearly do.
Currently when seeing new doctors I use a fake name, pay cash, and give them a phone number to a phone separate from my normal one, which I bought with cash and never associate with my own name. Works for prescriptions for the most part too since I pay cash for that as well and id is only required for narcotics.
Since then, not so many targeted ads.
I had something similar happen. When I told my doctor, he blamed the drug store chain (Walgreens in this case) for selling the information. I don't know if that's true, but my doctor believes it.
I also get text messages from them that have links that may or may not allow the retrieval of health information, which also bugs me inasmuch as there's no way to opt out (at least not without ending all text messages).
As someone who hates shopping, I've been really disappointed with the quality of ad targeting for the past decade.
The ability to select categories of ads has improved things. But I wish I could just write some rule-based criteria and then take 3 hours, look through a bunch of ads, and give them ratings in order to train personalized machine learning models.
I'm not sure one exists for prescription drugs or mental health services, though--that would be an interesting idea.
1. Get addresses of mental care clinics and offices.
2. Geofence addresses
3. Correlate devices that visited geofence addresses (using LiveRamp data) with devices that saw your ads on Mental Health sites.
4. Bonus, look at the path on the pages to figure out what disease they were viewing when your ad was displayed if you weren't already targeting specific page content.
("absurd" is a strange word to use; it might be nicer to educate without condescension).
> > Correlate devices that visited geofence addresses (using LiveRamp data)
LiveRamp is hooked into a lot of ad services and a user's location information will routinely make its way to them. Played some ad-supported mobile game on your phone while in the Doctor's waiting room? LiveRamp has that location data.
Even if the user doesn't have GPS enabled for the game, they might have it enabled for some other background process that routinely asks for it, like Facebook or Twitter or FourSquare, who package that data for sale. Or you're on the Doctor's wifi, and most stable IPs like that are in location databases. Or they just buy it off your cell phone provider, since many happily sell location information.
LiveRamp is a gigantic business built entirely on knowing approximately where you are any time you interact with their tracking servers.
Location data is so easily available that is largely a commodity now, sources include GPS from "always on" apps like the Weather Network but also apps that are collecting this data without your permission. Apple and Google are constantly kicking apps that do this out of the store.
Also tricks like "local wifi" devices are being used, Apple just reduced apps ability to sniff networks for this reason. There is another response that lists some other data sources, your cell phone company being the worst offender for many reasons.
Healthcare targeting has been severely reduced in the past couple years because of concerns like these. You used to be able to target diseases/interest in diseases/etc but can't anymore.
For example, if you place a cookie recording visits to a specific results page of a mental health test (e.g. a page saying "you got 14-18 points on this test which implies foobar" or get a https://www.hotjar.com/ recording of what the user typed in that test, then that would be blatantly illegal, violating GDPR article 9.1. I'm not even talking about using that data for targeting ads, the default position (if no exceptions are met) is that you're not allowed to collect and store that data.
Collecting user browsing habits is not (in EU) "legal by default" - it may be legal, but it may be not (e.g. if sensitive data are collected as in this case) and it's the duty of data controller to ensure that all the requirements are met - if it turns out that it's too difficult for you to automatically distinguish which browsing habits you are allowed to collect and which not, then the only legal option is to assume that you're not allowed to collect them.
Having your health data not be collected by random companies is an important inalienable right (e.g. privacy as one of the core rights in EU charter of human rights); while collecting and storing browsing habits of other people is a privilege, you're allowed to do that only if you can meet all the required conditions.
*Please don't take this excessively literally.