Is Stack Overflow allowing ads to use fingerprinting to track users?
meta.stackexchange.com
meta.stackexchange.com
The first time I got served malware via web ad was in 1998. I started manually blocking ads by modifying my hosts file that day. Haven't stopped blocking since.
It's a broken model, stop forcing it down our throats and stop shrinking the definition of "bad" advertising.
It's been with:
- Technology projects and features ("oh well you have to advocate for x and y feature")
- Public policy (scooters being pushed on to people)
I'm not sure what you're getting at here. Policy changes will almost always be reactive. Should we just defacto outlaw everything?
Your point seems to skip over the fact that policy creation itself should be reactive - sparked by an obvious public need or because of a prediction backed by science.
It's not that we should outlaw everything. It's that there's a civilized way of introducing innovation which involves sorting out main issues before deployment, and then there's the Uber way which involves dumping externalities left and right on the unsuspecting populace, while showing the middle finger to local regulations because "we have venture capital money therefore we make the rules".
I propose the Uber way should be banned and punished with extreme prejudice.
I'm not arguing here, just thinking it through... What is the alternative? Do I need to haggle with literally every city I want to have a presence in? Even though there's no law against doing what I want to do? Seems like the scooter rental business would simply never exist in the first place, it would be a huge deterrent.
There is, or at least there are in case of Uber, pretty much in every city around the world. I'm not that familiar with the regulatory situation of scooter business in general, but there are a law against littering, and the scooters end up as trash in the cities, creating danger (e.g. to people with no or low vision) and having to be picked up by the police.
In my city (Kraków, Poland), a few startups recently decided to clone the Uber-for-scooters and it turned out to be a huge nuisance. Some interesting tidbits include:
- A few weeks after deployment, the city announced it's calling an emergency meeting about the scooters, because apparently none of the companies bothered to come and talk the parking situation through.
- A lot of noise in the media was created by the blind community, who reported instances of people tripping over scooters left on the sidewalk.
- A friend tested available scooters few months ago, and his report mentioned bad technical condition, and low-quality and sometimes broken brakes.
- Deployment in Kraków and other cities triggered an upcoming update to traffic rules, in which electric scooters will get reclassified as motor vehicles, i.e. forced to drive on the road. And rightfully so, because they reach dangerous speeds and pose serious risks to pedestrians.
- Speaking of which, there were at least two confirmed deaths in Poland caused by these scooters, and it's not even half a year since deployment.
Where to park them and how they can safely participate in traffic are two basic issues that absolutely should have been talked through with the officials before. I'm only disappointed the companies involved weren't just banned by fiat.
FWIW, in my experience in dealing with relevant people, the city of Kraków is quite supportive of innovations in the city space. But one has to actually go and talk with them. Apparently, in their desire to be first to market, these companies didn't.
EDIT: My wife was almost hit by some careless electric scooter driver while being 9 months pregnant. She didn't tell me back then to not upset me. And perhaps for the best. If they hit her, I'd be suing and campaigning to get them off the sidewalks.
There is. Chicago introduced them with a claim that everything will work out. They won't do anything against them. There's lots of documentation about it. They've actually put out press releases ignoring the issues associated with it.
It’s just that Uber’s tech scales to national and global scales relatively quickly making mass haggling necessary and since that’s pretty difficult you end up with the externalities being dumped on unsuspecting populaces since Uber’s not going to do that mass haggling.
Instead, Uber pushes the haggling initiative onto the towns and municipalities when it used to be the other way around.
Not sure about solutions or alternatives.
Stack Overflow is given the lowest rating (class E) in terms of user rights. (For reference, even Google has a class C rating.) Here are the worst points taken from SE's privacy policy:
* This service allows tracking via third-party cookies for purposes including targeted advertising.
* You agree to defend, indemnify, and hold the service harmless in case of a claim related to your use of the service.
* This service forces users into binding arbitration in the case of disputes.
* Many third parties are involved in operating the service
* The service may use tracking pixels, web beacons, browser fingerprinting, and/or device fingerprinting on users.
* Blocking cookies may limit your ability to use the service
* You waive your right to a class action lawsuit
* This service can share your personal information to third parties
* The court of law governing the terms is in a jurisdiction that is less friendly to user privacy protection.
* The service can sell or otherwise transfer your personal data as part of a bankruptcy proceeding or other type of financial transaction.
* The service uses your personal data to employ targeted third-party advertising
* This service retains rights to your content even after you stop using your account
https://meta.stackexchange.com/questions/333388/what-is-the-...
These people keep shitting in the well, and yelling at us for buying bottled water.
Even when that means losing all the third-party goodness (CDNs, analytics, cloud providers...) that we've come to depend on. Yep, they save an uncountable amount of time and effort - but at the cost of tracking users' every step... We can't have one without the other!
Cloudflare's CDNJS sets, by default, crossorigin=anonymous and subresource integrity. Add a "Referrer-Policy: no-referrer" header, and all the CDN sees is either a) nothing, because the client has the resource cached or b) a request for a certain version of jQuery without knowing where it came from.
If you think this is a good idea because it enables technical enforcement, do you also want to ban static.example.com? Because if you don't, you'll soon have pointstothirdpartyadserver.example.com. If you do, you'll have https://example.com/proxytothirdpartyadserver/ instead...
This is not a problem that can be completely solved on a technical level. Enforce the hell out of GDPR and see the problem shrink.
What are the difficulties for a browser to provide such a feature by default?
There is already a system for all of that. It's called the browser cache.
If this is where we push the industry, it will be a huge win for users.
<?PHP echo(file_get_contents("http://google.com/nefarious_crap.html")); ?>I could not give less of a shit about justification of bad behavior by invoking market demand, if it leads to me finding a turd in my drinking water.
Unless, of course, it leads to the dawning of understanding that maybe the Econ-101 understanding of supply-and-demand is a spherical-cow level of analogy that rapidly breaks down when it encounters the real world, and that regulation isn't a toxin.
This is not what I want - Apple has done a bad thing.
Is there still a market for these kind of low-tech ad buys these days?
And your competitor can always claim that 10% of client aqusition cost is donated to fight climate change... and then you stand no chance ;)
what are you talking about?
Lets say you are running SaaS for Azure admins. Do you want to buy the top banner on slashdot.com for the whole month, no targetings at all, for 50K/month, or you only want to show yor ad if user was interested in at least 2 stories with azure tag, for 5K/month?
Automatic (aka highly targeted) ads are more effective, not x1000 less.
Now Reddit just sells generic key-word targeted ad-space and it's really not worth it anymore as you are selling your soul to an algorithm that doesn't know your audience.
Yes, but often you have to contact the web site directly.
I wouldn't be surprised if some of the non-Google ad companies like Exponential will do this, too. They did it before Google existed. They might still have that ability.
Gorsh, sure sounds hard to be a marketer. Sometimes you have to do some work.
Though Codefund sells itself as an ethical advertiser. Something I would have previously considered an oxymoron. But here we are.
CodeFund is what we consider "ethical" and different from Carbon Ads and other ad networks because (1) we do not allow 3rd party scripts, (2) no cookies accompany ads, (3) we are 100% open source (gitcoinco/code_fund_ads), (4) we only work with advertisers that provide relevant products and services that are good for the developer community, and (5) we literally do not store any private data, including IP addresses.
I recommend reading https://codefund.io/blog/countering-negative-press-how-ethic...
Speaking of ethical practices, why is there a notification icon on a blog, and why is it having a seizure? :).
They would hold weekly/monthly auctions for a "Sponsored Server" slot (your listing shows at the top of the page). Can't remember if it was weekly or monthly, but I recall prices being around $7-8k per slot. This was just implemented on the website as a super simple auction, you could see all bids and could only bid higher and the auction would expire at some set time.
Then there was an even more low-tech layer around it all - people would rent their spots to smaller servers that couldn't afford to outright buy a slot. This was implemented as... Google Sheets with one cell for each hour time slot, with the sheets being linked to on various forums. You just sent a message to the Skype contact if you wanted to buy an hour or two, and for a couple hundred bucks you, too, could show off your server in your very own temporary minecraftservers.org sponsored slot.
You can run a business ethically without losing money. I think what such investors won't be happy about is that you aren't making money fast enough.
You do it by matching it up to other records with my fingerprint or name.
https://www.whitecase.com/publications/alert/court-confirms-...
Using that logic, a browser fingerprint would also be PII if the ad network can use it to determine who you are, or presumably if they can link it to other PII.
Take a step back for a second -- why is it problematic to be able to link information to someone's real-world identity? Because who I am -- my address, my name, my face, and so on, is very difficult to change. It's a problem because once you've linked an activity to me in the real world, it's now permanently pinned to my identity.
So with that in mind, what is the difference between tracking where I live and stalking me in the real world, and tracking what devices I live in and where I go online? In both cases, you're taking away my Right to Hide, and forcing me to use a single profile that I can't walk away from or operate outside of.
Certainly, the difference isn't that the real world is harmful and the digital world isn't. You can abuse, stalk, price-gouge, censor, and deny service online just as easily as you can do it offline.
If you have a persistent identifier for me, that links only to me, that allows you to recognize me on every website I visit, and if I can't escape that identifier, then you have already traced that information back to me as a person. Knowing my name or my address doesn't matter, those are just facts about me. 'I' as a person am the persistent identifiers that point at me.
They then give that data to Facebook who some days later records a visit from user srbby with the fingerprint XYZ, so they know that "srbby" with phone number 123455 (which fb has) visited site ABC.
Also, your aunt has your phone number in her contact list and she (as a few other people, to make it certain) lists a name "Bob Smith" for it, so FB can link that user "srbby" Bob Smith phone# 123455 visited site ABC.
Afterwards they sell that data to some ad agency that combines it with location data from either your cell phone provider (the major US cell providers sell such data) or some driving or taxi app to note your travel patterns and extract where you live and work.
So they know that fingerprint XYZ has the following (long) list of user accounts, visits sites like ABC, has that particular phone number, most likely is called Bob Smith, and most likely lives in such and such address and works at ACME Inc (or drives there every morning for another weird reason). For some fingerprints some of that data will be wrong, but it's mostly accurate, and definitely accurate enough for their prposes.
They don't really give all that data around to every advertiser just because (well, not for free), however, whenever an ad "auction" asks "heeeey, who's going to bid the most for which ad for fingerprint XYZ?" then this is the profile that's going to be used to make the winning, most targeted bid.
an IP address is actually an example of something that could be both PII and useful to tracking your browser, but there are practical and legal drawbacks to try to do that.
"Ahh yes. Sandra will be ovulating soon. We can charge a premium to present just the ads she needs right now."
I also don't know about "sites" offering "PII" back to ad networks based on a fingerprint match. but I could be wrong about that or maybe people are using a more expansive definition of PII.
https://news.ycombinator.com/item?id=18988289
(I know it's Bloomberg, but still.)
Of course, I use uMatrix for that at the moment, but it'd been better if we, as users, can tell what sites are actually interested in providing privacy, by hobbling advertising antics from the get go.
Also another court has ruled differently about whether or not an IP address is PII: http://curia.europa.eu/juris/document/document.jsf?text=&doc...
Really though setting cookies isn't the problem, and you don't even need to show a popup according to EU law. You only need that popup if you use the cookies for nefarious things such as sending tracking information to ad networks. Setting a cookie for functional things such as remembering logins has always been allowed without a giant-ass disclaimer and nothing has changed in that regard.
It would be great to have an "opt out of ads for $nn/no" option, like Google Contributor. The amount to pay could look uncomfortable, though.
[0]: https://stackoverflow.com/help/privileges/reduced-ads [1]: https://meta.stackexchange.com/q/331960/258777
And while you're right, this isn't much, it still represents only around 9.3% of SO users that have an account.
The JS won't be going away, it's part of a long supply chain of data, verification, viewability, anti-fraud and other layers baked in. For those saying publishers should do 1st party ads, that would lose them most of their income due to operational and sales overhead and doesn't really prevent everything anyway because they still have to accept the ads advertisers want to run, including the JS from vendors.
However the situation is slowly improving. Adtech has weathered through adblocking, native ads, anti-tracking tech but has failed to police itself because of a lack of consequences. Now there's finally regulatory pressure with GDPR, CCPA, and more that will finally force a change from the outside. I expect many of these issues to be greatly reduced within the next 1-3 years.
That's not my problem, they could choose not to use those platforms. If they can't feasibly guarantee the integrity of the ads they serve, then my logical response as a user is to just block them all by default.
Yes? Does that make it less likely? Less needed? No
If publishers can buy targeted ads with fraud detection, they will. But when they can’t (because the idea of the auctioned third party js blob finally dies) there will be money in dumber ads.
What might happen of course is that if someone wants to spend $X on ads that are dumb and untargeted they might as well buy a spot on the side of a bus. Do there would be a flow of ad money back from the web to traditional advertising.
I'm not so confident about this. At least, I haven't seen any serious efforts (or even proposals) from the industry in that direction.
Privolta (our startup for 1st-party privacy-safe ads): https://www.privolta.com/
There are many others. Regulation always creates opportunity.
What I have been seeing out of the industry (primarily what the IAB has been talking about and Google's "privacy sandbox") doesn't rise to the level of protecting privacy yet. Perhaps someday, but right now what it looks like is that they're seeking ways to continue an inherently privacy-invading business model while minimizing the impact of potential regulation.
But, and this is an honest question, where are the actual proposals to require that?
The proposals are the implementation. The enforcement comes from regulation.
> The enforcement comes from regulation.
Indeed. It appears that strong legislation is the only realistic solution -- but that seems doubtful to me as well, since the big players have been, and will likely continue, working as hard as they can to ensure that any legislation will be token at best.
That's not an improvement, because manipulating matter involves using up more resources. For all their problems, on-line ads harm the climate less.
That said, I of course welcome anything that can roll back the current state of on-line advertising. Even dumb on-line ads would still be more profitable than physical ones, and since advertising is a zero sum game, I don't expect the publishers to really lose money on that.
Which is why I won't be allowing JS to run anytime soon.
Usually when you submit an ad to a network, you dont get to use your own js or even remote images.
Is it the ad network and not the advertiser doing this ?
They're only limited when buying very defined formats like text-based search ads.