When I said basically the same thing 4 years ago[1], most people seemed to think it wasn't a serious concern or could be easily bypassed. However, after observing how certain types of businesses use the World Wide Web over the past 3 decades, it's obvious what they want: to send an opaque binary blob to the user that nobody can investigate or modify, that gives them full control over what the user sees and is allowed to do. Just like TV.
The only safe response to this is to stop allowing documents (or docs with 3270-styole forms) to embed software in a Turing complete language. Add functionality that is used declaritively, or the answer to "should this be blocked" is undecidable. Give them the ability to run a Turing complete language that renders to a canvas, and adblocking becomes a hard image recognition problem (or requires solving the Halting Problem).
People who don't want to see ads (i.e. a large part of adblock users) are also more likely to engage in toxic (to advertisers and YouTube) behavior, such as intentionally clicking on ads but never buying anything (or even writing scripts to do that), or intentionally avoiding the advertised product, etc.
HBO does product placement too, though they sometimes pretend they don't or pretend it doesn't count when they do it because they do it "pro bono" (The Pope only drinks Coca Cola™ brand Coca Cola Zero™ for purely narrative reasons, and we're going to mention the brand Coca Cola™ explicitly several times by name to drive home the point that the character you enjoy watching enjoys the cool refreshing taste of Coca Cola™ brand Coca Cola Zero™. Don't worry Coca Cola™ hasn't paid us to shill their sugar water, we do it for free! Drink Coca Cola Zero™!)
We have fire tv and Amazon has added more and more advertising to the point it’s nauseating (an ad for Shameless in the middle of a bunch of baby pictures is jarring).
I’d be happy to pay an extra dollar / month to amazon to not see ads there. Actively looking at htpcs that I can put Adblockers on (pihole doesn’t work since ads and content come from same places, I think)
The thing you can buy a la carte is twitch turbo, and that still removes all ads.
source: ex-googler
In most countries, any YouTube user can pay a subscription fee to disable ads. It's called YouTube Premium: https://support.google.com/youtube/answer/6308116?hl=en
This has existed since 2015, so presumably Google employees have it on their personal accounts.
Twitch also removed the ad-free benefit from twitch prime.
A healthy internet is ultimately up to us to build and maintain.
I feel like that's not a real problem. Or, maybe only a problem for services that care more about having a ton of users than being profitable and sustainable.
There are quite a few services (SmugMug, Vimeo, NetFlix, etc.) that charge money, don't have advertisements, and are doing just fine.
It's weird that so many web companies decide to go the sleazy advertisement/tracking/malware route rather than just charge money for the services they provide.
You will find very quickly how reluctant people are to pay for anything despite a few cultural-phenomenon-level exceptions like Netflix.
I'm amazed how many people, like my own coworkers making $100k+, listen to Spotify all day every day yet will endure advertisement after advertisement in their stream of music instead of paying $10/month. If someone isn't even going to pay for Spotify despite it being a central part of their day to day experience, GG to your little service.
I think advertising has played a major hand in shepherding us into this position that divorced us from the idea of paying for content we enjoy. There is going to have to be a major cultural change to bring us back into a healthy relationship with content.
One common response to this is "well, maybe everyone should be hobbyists again making content for free," but surely we can find a better middleground than structuring things such that we depend on people toiling away in their freetime to produce the content we happen to want. For example, I'd rather my favorite content providers be able to feed themselves working on this content. We both benefit: I get to enjoy more content. Depending on hobby work doesn't get us there.
That's absolutely not true, though. People buy stuff all the time. Clothing, shoes, sporting goods, dishes, food, housewares, books, DVDs, etc.
The "freemium" approach Spotify takes is a poor example because they're not charging for their real service of music streaming, but instead to get rid of advertisements. They've moved their own goalposts, and the question isn't "Is streaming music worth $10 a month?" but "Is it worth $10 a month to get rid of this commercial?" If the options were "Pay $10 to stream music" or "Listen to nothing," the results might be a lot different.
> One common response to this is "well, maybe everyone should be hobbyists again making content for free," but surely we can find a better middleground than structuring things such that we depend on people toiling away in their freetime to produce the content we happen to want. For example, I'd rather my favorite content providers be able to feed themselves working on this content. We both benefit: I get to enjoy more content. Depending on hobby work doesn't get us there.
I'm not making that argument, and you're setting up a false dichotomy. There's no reason content creators need to use advertisements and can't charge for their content instead. It worked fine for music and movies for over a hundred years, and books have been using that model for hundreds of years before that.
I'd never pay $10 for a character in a game, but I'd happily pay $15 for a plastic toy that coincidentally unlocks something in a game I was enjoying anyway
There are people who pay for paid password managers when free alternative products available. I myself pay for a number of services (very reasonably priced) when I could have used free alternatives. The difference is the guys I pay don't offer a free edition without ads and nonsense like that. They just build a great software and ask to pay for their effort.
Why go to work, earn cash with your attention, and pay for Spotify when you can directly monetize your attention on-demand in real-time at the rate you consume? That's what advertising allows.
If you do it as a hobby, it's not toiling. It becomes toiling when you do it as work, especially if you have to please advertisers instead of making the content you love.
Also lots of people can't afford all the content they consume today, and would much rather have access with ads than nothing all.
I mean, on the whole, the vast majority of ad supported content is in fact clickbait trash.
Are those special and only run for large streamers? I never see ads on twitch, but the biggest streamer I watch has under 300 viewers.
You may be ad-free for another reason such as a grandfathered twitch prime that will expire when it next renews, twitch turbo, or a subscription to a channel that opts-in to the ad-free sub benefit. You might also just be in a region or demographic where ads aren't being bought, so you wouldn't get any then.
Now, whenever I get an ad, I immediately close twitch and find something on YT/Mixer to watch. I'm training their algorithms to leave me alone.
I get ads when I use Twitch, with the same account, on a stock installation of Chrome (which I use as my backup browser for when I don’t want to figure out which extension is breaking a website). So it’s not related to my account, location, etc.
However, I would argue that it is not actually worse for several reasons. For one, the streamer decides exactly when and how to play ads - so if the ad timing bothers you, you're going to start watching someone else, which in turn creates an incentive to keep streams ad-free or at least run ads at specific times.
The second reason is that the usage pattern of Twitch is different. I go to twitch (if it's a livestream) to actually watch the content, whereas I use YouTube in many cases like I would use an article, skipping through videos and back and forth looking for a specific part or specific information, and if the information isn't there quickly trying the next video. This workflow gets completely destroyed by ads. To the point where if YouTube would somehow force me to watch ads, I would simply stop using it except for the 2-3 weekly videos I actually plan to watch beforehand.
This seems standard: acquire users, then make the service worse for users. (and better for shareholders and/or advertisers)
The problem is that sites trying some insane techniques is a bad arms race.
Sites like the wallsteet journal made a adblock-wall, see ads or don't use the site. That's fine. They can do that. And they lost lots of traffic. But they can decide if they like that.
Websites want a have-your-cake-and-eat-it option -- forcibly show ads, no opt out.
https://support.alexa.com/hc/en-us/articles/200449744-How-ar...
Why ask a vague winky-face question when you can make your assertion instead? Now I have to wait for you to respond just for you to clarify what you were trying to say.
> our traffic estimates are based on data from our global panel, which is a sample of millions of Internet users using one of many different browser extensions. However, we don’t just rely on browser extensions. We also gather much of our traffic data from direct sources, including sites that have chosen to install the Alexa script and certify their metrics. It is this unique combination of data from our global panel, plus data from directly measured sources, filtered through our advanced statistical models that allow us to provide you with robust and comprehensive metrics.
The next anti-tracking technology should include fake tracking.
What makes you say you’re speaking for most of us?
Tracking doesn't mean anything to most people.
That's why I'm not using it personally, even though I'd love to...
then you can go mad on everything outside the container
I don't think that's true, video encoding is expensive. This is not trivial to do without investment in hardware.
Google doesn't just sell ads, they sell targeted ads. Yes, YouTube currently does some processing on every video uploaded. But they only do that once.
Outside accessibility there's also the issue of responsive design, huge SEO impacts, rendering performance... I'm probably missing a bunch.
Lifting a sedan with my bare hands is obviously easier than lifting a 10 wheeler, but it's still a massive problem. Rendering stuff is not the biggest issue.
Gary Bernhardt's talk "The Birth & Death of JavaScript"[1] was an ominous portent of a terrifying future. Unfortunately, some people apparently saw it as development roadmap.
[1] https://www.destroyallsoftware.com/talks/the-birth-and-death...
You can even implement a WASM interpreter in JS.
WASM at least is standardized, so there will be a whole ecosystem dedicated to it. Think IDA Pro for WASM.
> although we've had Emscripten for years
We did. And I didn't see the "asm.js apocalypse" you seem to fear.
WASM is different between Emscripten was always a fun curiosity, and WASM is being "marketed" to developers as "get native app performance in a browser". "Modern" Javascript has been able to deliver this future for a few years now, but it lacked the marketing and tooling to make it mainstream. Flash and Java were attempts to move to that future that didn't pan out.
Having IDA Pro for WASM is all well and good, but doing binary reverse engineering on every single website isn't practical.
The web, as it has been, was nice. We're not going to get to keep it. I'm unhappy with it, but I'm resigned to it.
So WASM doesn't take away anything from us, because we haven't had the "nice" you mention for 10 or 15 years. Sites like HN will stay like this, sites like Facebook will get even bigger. It will happen with or without WASM.
But yes, I do see where you're coming from. You want a less bloated Web, and you're worried that WASM is not going to lead to that, which I pretty much agree with. While I'm saying that cat is already out of the bag and WASM at least has the potential to bring performance improvements over JavaScript (which will be promptly negated by the sites getting even more bloated).
I want a declarative web. I wish there wasn't a VM in my browser. I want a web where my user agent, under my control, dictates how documents are interpreted and displayed.
So much of information security relies on not letting third parties execute arbitrary code on your computer. The price to view "mainstream" websites is increasingly becoming "allow third parties to execute arbitrary code on your computer". I can sandbox that code and perhaps limit the impact to my privacy (though thanks to processor microarchitecture "features" that's increasingly difficult), but I lose virtually all ability to control the presentation experience.
To be blunt: The kind of assholes that delighted in using Javascript to block opening context menus, blocking "Paste" into password fields, etc, have won. That pisses me off. Developers with good intentions who wanted to make something "cool" end up being the architects of the tools that will be used turn the web into cable TV.
Change your `dom.event.clipboardevents.enabled` in about:config to false.
Putting a VM into our browsers, along with sufficient API support to make that VM useful, is what spells the eventual end of the document-based web. I think that future arrived a few years ago and it's just not evenly distributed yet.
That sounds like the worst future possible. I love the fact that I can go to any web page and look at all of the HTML, CSS, JS (even if I need to use a tool to un-obfuscate it). Have you never wondered how someone did something and then looked at their code to find out how they did it? I love being able to use curl and wget to grab a web page. How would that work in a non document-based web? I really think this would be a terrible thing if it actually came to fruition. I truly hope I'm retired or dead before it occurs.
You can easily generate a static document with ads, doing the heavy lifting on the server.
TVs allow the user to mute the audio, switch channels and fast forward past ads in recorded video. What publishers are doing to the web is like sending a control message that reconfigured the TV and disabled some of its functions. "You can't mute the audio, you're obligated to listen to this. Also, we're turning the volume all the way up in order to reach you even if you leave. You can't turn it off either."
Publishers simply don't want users to have any control over the experience. It's their way or the highway.
What if broadcasting companies sent signals during commercials that told the TV to disable these features? "They've enjoyed the movie, now it's time to make them pay. Don't let them change the channel, mute the audio or lower the volume". How long would it take before TVs that didn't follow these intructions entered the market?
Browsers have features publishers don't want people to have. We can download copies of "their" content. We can delete their ads. We can filter out their user tracking malware. This is possible because the browser serves us, not them.
The problem with first party tracking from the PoV of the advertisers is that the feedback they need goes through the site their ad is on so it is possible to be faked: "Yes Mr Advertiser, we really did send x000 ad impressions to {addresses} this day, honest guv'ner."
And from the site's point of view the adverts now become a little more admin to manage beyond just slapping in a reference to 3rd party JS and adding a <div> for that code to target to insert the advert.
Essentially, the ad providers would also become hosting services.
So.. Google AMP?
It also creates single points of failure that did not exist before. If the ad service is down, your content is (potentially) down too rather than just being served without working ads.
Maybe there is a market for a proxy that converts any page you visit to bare and functional HTML with just content and navigation. No ad's, distractions, disfunctional scrolling, etc.
https://en.wikipedia.org/wiki/Proxomitron and other MITM-proxies can do that and more, although the security-paranoid may disapprove (but then again --- what are you more concerned about, what is your threat model, etc.) The recent "security vulturism" and things like DoH and other anti-user ostensibly-privacy things certainly doesn't help.
I’m not sure if it can also enable individual scripts, that might become necessary very soon if this article is an example of what is coming.
Wrap it up with an easy to install bow and easy self updating to keep up with sites (and easy fallback to original sites/links), and I'll never browse the mainstream sites again. There are a couple of things that do this, but none as well as I'd like to see.
Fetching data from such websites is the only thing so far where I've found ES async generators very very useful.
You don't even need a browser. Most of the time simple HTTP requests from node work just fine, and makes tor use safer and more effective since you're not running any foregin JS code, just parsing data. Other thing that improves privacy is that you're downloading everything, so it's hard to see from the service's side what you're actually consuming.
Actually many usual services follow this pattern. List of accounts->list of transactions->transaction details. List of categories->list of articles->article detail. List of product categories->list of products->product detail.
Simple abstraction can get you very far, even with a fairly simple DB schema.
There is also the option of actively attacking the business model of the ad and tracking industry. Ad blockers could simulate lots of "fake" traffic to make ad analytics harder (this is another arms race against attempts to filter out the fake traffic)
This would be awesome!
Mandatory : "Why Rosyna Can't Take A Movie Screenshot"
http://web.archive.org/web/20180919021829/https://www.alexra...
Kind of like climate change, there are actions we all know would help but individually giving up those conveniences is difficult.
And like voting with your wallet, it will be completely ineffectual in actually addressing the problem.
> Kind of like climate change
Another area where the need for comprehensive societal solutions gets dumped on the individual instead, rendering it ineffectual.
I'm a big proponent of top down climate change policy to force change as opposed to hoping if we virtue signal enough people will be shamed into driving a bit less etc.
With regards to Ads I don't take as much a hard line approach as yourself (I remember our last discussion!). I'm very pro ad blocker use but not to go as far as banning them in any way.
Something I've been thinking about is sending a header to websites informing them I'm going to block their ads so they decide not to send me the content if they don't want to. I feel no entitlement to their content as they should not feel any entitlement to what code gets to run on my machine once it reaches me. I might expand on this in a blog post some time soon but it's probably closer to an art project than something actually viable.
I'm impressed. I don't think I ever remember individual usernames.
>Something I've been thinking about is sending a header to websites informing them I'm going to block their ads so they decide not to send me the content if they don't want to.
I've actually played with similar ideas in the past (my more moderate days). But my philosophy at this point is that they can choose to give me the data or not give me the data. And I'm free to do with it as I please as long as I don't distribute it without permission. And I'm even softening up on that limitation.
An advantage of this is we'd skip the whole ad blocker and anti ad blocker charade and gain a metric ton of performance back.
The key parts there are: - single - technical - authority
Watching businesses attempt an integration of a line code anywhere to download the third party tool is painfully hilarious.
Getting them to set up a DNS record to point to you is often so far off the table its playing in the forest with the faeries. Having them pull your code and serve it statically alongside their site... I couldn't imagine
What usually happens is that the marketing team signs a contract then developers copy and paste a JavaScript snippet to embed on the website and move on.
The work arounds require much more intention and the solutions can be hacky like modifying urls in a minified JS file.
If that tracking is blocked, it is invisible to the company especially if only the third party who has access to the data.
Not going through the browser is possible but requires trust between organizations; publishers have an incentive to inflate numbers, and trust has so far been lacking (and rightly so). That may change.
'normal' people are starting to run ad-blockers now, not just tech-savvy users.
https://www.emarketer.com/content/ad-blocking-in-the-uk-2018
https://www.socialmediatoday.com/news/global-ad-blocking-beh...
If you're willing to get cpu/gpu intensive on the page rendering a lot can be done.
Make sure the travel to a different country between clicks. Just in case.
It's a constant cognitive drain on your mental resources. That's even ignoring the fact that almost everyone is influenced by ads to varying degrees.
We reached the point that this is the argument to avoid ads... People will go to such a length to justify blocking ads, it's crazy.
Yes, I also take the Intel Inside stickers off my laptop.
Every once in a while I get a page that buries a CPU core. It's either bad Javascript (most likely) or something mining cryptocurrency on my PC.
The internet will partition: the corporate internet will be what you say, and the independent internet will be people writing and hosting their own content, like the internet of the olden days. Some of them might interact with corporate services via apis.
The independent internet will be small, but it will be enough. If you want to buy something anonymously, go to a shop and pay cash with your phone turned off.
Google is the biggest offender after all their entire business is Tracking and Ads but it seems they get a pass as being an "offender" from most people
Note that "most people" (even individuals) also happily insert Google Analytics snippets on their own blogs or websites. I see that all the time thru uMatrix. So it's far from "Google being a bad actor" alone.
Might as while pile on the bad/abusive actors for causing the scenario that makes people use captchas at all.
I can ask for a lot more, don't worry.
Speaking for myself, I've never been opposed to ads on sites (within reason - popovers are trash), because I understand that creating content costs money, but I don't like all the tracking that comes with them.
But I was actually responding to the parent's comment (this is a threaded discussion, yes?) about how actual first-party ads are less objectionable than third-party tracking.
But thanks for adding your thoughts.
It is more technically challenging to implement. If it becomes necessary, I'm sure there will be plenty of money invested in making it easier for the content providers to participate in such things.
That just moves the goalposts though. People will still deconstruct and reverse engineer the black box, or sniff the lines it uses and attack the traffic. Or anything else. There are countless attack vectors against a device in physical possession. So unless the devices are melting down into slag and can perfectly detect even passive attacks then the advertisers will always lose.
This doesn't stop them from trying. If advertising can be made more expensive then the roi the advertisers will stop. Some will irrationally throw money at the problem way past the point they should've given up but even they will taper off eventually.
Suppose I have an apache module (or the equivalent in some modern http server) that's (a) injecting the necessary code (b) forwarding the traffic information to my nefarious third-party tracking provider. Or, heck, just a third-party solution that consumes my apache logs. It's doing all of this without using the browser itself as a middleman, like the clumsy CNAME masking discussed in the linked Github discussion.
This could never be stopped client-side since one's web browser would have no say.
Only reason this isn't more widespread already is because a lot of web properties don't have full control over their shared hosting environments.
First-party ads are theoretically kinda sorta maybe blockable via various levels of heuristics, which of course adblockers are already doing to various extents today.
But as far as preventing your information from being forwarded behind the scenes, there's no technical solution. Legislation is the only hope to curb it.
Google still has an old help site referencing its log analysis features [1].
> Urchin WebAnalytics Software is discontinued and is no longer supported. All Urchin documentation applies only to the Urchin product as it was at the time of discontinuation, and does not apply to any Google Analytics products or services.
Small community sites are still interesting, distributed web technologies may start to rise, or there's always gophernet...
I'm ready to move on. In my eyes we already lost the www.
I'm already seeing a big use case for having such a (opt-in) domain filtered search engine since there's soo many spammy and SEO-hacking web sites out there.
Also, re: “inline” static images, there could totally be client-side ML-model cosmetic filters that recognize and remove known as images, regardless of how they got to the page. The filter could even just throw a floating rectangle over then, so it wouldn’t even have to understand how they’re made in the DOM. This is the “thermonuclear backup plan” we’ve been expecting to need to pull out for a while now, though advertisers have been lazy about getting sneaky enough to necessitate it.
There are many videos on Youtube recommending stuff. You never know if the author has been paid. Even if you try to detect popular ad networks and services, the ad techniques will also evolve.
If ads were the only source of my income, and my content was unique, I would show the user a "quiz" every 5 minutes, asking him to answer, what is shown in the ads at the moment :D and deny the access, if the answer is wrong.
Those are some rose-tinted glasses. People on forums like HN were always annoyed that they looked like navbar links and you were only clicking them out of confusion with actual links.
If they want to make ads extremely hard to block but reduce privacy concerns, I'm all for that. It puts the discussion back on a more even level, and if you don't like the ads, don't use the service. The only reason I'm okay with running an ad blocker now is because of the privacy concerns. If those were eliminated (which isn't the case in this theoretical situation, they're just reduced) then I'm not sure how to justify running an ad-blocker. To my eyes, it's basically stealing cable or satellite service. I understand other people don't see it the same way though.
Ads need to know what you googled, what you did in the competitors website, 1st party domains are a huge handicap for it.
They either will need excellent fingerprinting or accept subpar tracking.
The max they can do is track you in their website, but that's terrible, they need to know more.
edit: this means the 3rd party server can't know who you are, even if they get your tracking events, they can't know what you did in the other sites.
thats why fingerprinting could fix this, the 3rd party server could find your profile with a good enough fingerprint.
I'm talking about a sameSite cookie made for the publisher, via a proxy on the server.
When a client send you this cookie (sameSite) your server forward it to the ad provider using a RPC call.
The ad provider replies to this call with new data they want you to add to the cookie.
You set the "forAdProvider" cookie on the client, using the data specified by the ad provider.
I don't think that has much value because the ad provider wouldn't know who you are to begin with.
First time you open said website no cookies would exist for the domain.
Then the ad provider wouldn't know who you are.
Ex: Access foo.com and search for shoes, shoe cookies set for foo.com Then access bar.com which hits foo.com for the ad suggestions Now foo.com knows you searched for shoes, since the 3rd party cookies are there.
Now if you do it without 3rd party cookies bar.com wouldn't have any access to the cookies which identify you as a shoe buyer, because those are set for foo.com
I wonder if it is also not how GDPR should have been implemented. Forcing browsers to implement a request for storing tracking data, which would avoid dark patterns in consent forms and would keep websites honest. It would also allow to remember the decision. If you delete cookies when the browser closes, you get asked for the same consent you denied on every visit.
I'm actually hoping it paves the way for more independent publishers that focus on quality content and charging.
Ads have ALWAYS sucked and been a horrible solution to funding news, journalism, etc.
The problem is that ads basically cause other users to defect to platforms that are free (but sponsored by ads).
Just because there are a lot of bad actors and massive amounts of advertising doesn't mean the entire internet needs to go down that path.
Hackers have protected users since years. It's time for politicians to protect their citizens.
If you provide paid content AND try to track me or make even more money with me via ads: goodbye...
On the other hand: If you rely on ads only, it is doubtful that your media-outlet is truly neutral -- would you really do analysis and investigations on your highest paying ad clients (?) -- I doubt it...