Cname cloaking, a disguise of third-party trackers
medium.com
medium.com
(Disclosure: I work in ads; speaking only for myself)
For tracking and invasive device tracking (WebGL, plugin enumeration, Canvas, audiocontext, WebRTC, WebSocket-based portscanning of your LAN CIDR acquired from WebRTC, ...) there's Shape and Distil that both do inline reverse proxying.
What's the data on folks actually saying no to these popups / clickthrough alerts?
I used to skim the relatively few permission / yes agreements (ie, this will auto sign you up for XX), but now they are showing up so many places it's not practical anymore I don't think?
Even https://europa.eu/ (the official EU website) has a cookie banner at the top of the very first page you hit. And instead of the website asking me - I normally just block cookies if I don't want to share them.
Update: I went and found this[1]:
> this provision means that companies will process only the data absolutely necessary for the completion of its business and limit access to personal data to only those employees needing the information to complete the process consented to by the data subject
[1] https://www.techrepublic.com/article/the-eu-general-data-pro...
Google has pretty much checkmated content-blockers in that they control the servers, the OS, and the clients used by an overwhelming majority internet users and service providers, alike.
location /adtech/ {
proxy_pass https://adtech.example/;
}
What additional trust are you thinking about? HttpOnly cookies are already sent when you use the subdomain approach.at least if you cname definitelynotads.yourdomain.com to js.ads.com, the javascript running on definitelynotads... can't read host-only login cookies on yourdomain.com.
You're right that this does reduce security on some sites: if domain.example doesn't set Domain= on their cookies then ads.domain.example (CNAMED to js.ads.example) won't see the cookies but domain.example/ads would. This is pretty rare, though, because sites you log into generally do need their cookies to work across subdomains.
Except this problem is easier to handle with reverse proxies than with subdomains: with subdomains the cookies are sent whether you want to or not, while with a reverse proxy the site owner can configure it to strip cookies.
So for the purposes of the browser security model, the script already runs in the domain of the host site. It can directly read any non-HttpOnly cookies, and can make any request it likes using XMLHttpRequest to APIs on the host site using the user's cookie without relying on CORs.
The only very minor difference between first and third party script inclusion is access to HttpOnly cookies (depending on the cookie scoping).
Both of the first party script inclusion approaches have mitigations available to the host site: in the proxy approach, the server could filter the cookies before proxying. In the CNAME approach, taking care with cookie scoping could solve the problem. Careless adoption is likely to open security flaws under both techniques.
That’s not a minor difference, http only is used for authentication.
I would not do this work if I thought it was harmful, and if I decided it was harmful there are many jobs I could take instead.
I'm open to being convinced that my work is net negative! I've quit Google before: https://www.jefftk.com/p/leaving-google-joining-wave
I appreciate your engagement in this, Jeff, but I’ve read the post and I agree that it’s rather light in its evaluation of the negative value of ads.
Anyway I guess it’s getting too far off track at this point. Thanks for at least engaging in the conversation, unlike basically everyone. I would love to chat further in private if you have the time. my contact is in my profile.
While this is definitely true for some adtech vendors, none of the work I do is in that category, and to my knowledge none of the work at my employer is either.
(Still speaking only for myself)
Google is and was actively fighting privacy laws[1] (e.g. seeking exemptions allowing them to even track people who consciously opt out of data collection), had a CEO that made no secret about his anti-privacy stance[2], was repeatedly fined[3], also also for violating the privacy of children[4], etc. etc.
How do you reconcile this with your assertion that google and yourself are good players?
[1] https://www.latimes.com/business/story/2019-09-04/google-and...
[2] https://www.eff.org/de/deeplinks/2009/12/google-ceo-eric-sch...
[3] https://www.nytimes.com/2019/01/21/technology/google-europe-...
[4] https://www.nytimes.com/2019/09/04/technology/google-youtube...
From what I've seen on HN, this quote is one of the top offenders when it comes to commenters just dropping it in without further engagement. On well-moderated subreddits like /r/askhistorians, commenters are required to critically engage with their citations instead of just linking them. Likewise I feel we should put a moratorium on responding exclusively with (well worn) quotations on HN.
To be specific: the way you've responded here is trite, dismissive of someone else's perspective by way of judging them for their occupation, and generally lacking in nuance. It's middle brow posturing of insight without the substantive analysis to back it up.
What have we learned as a result of this solemn reminder that some people get paid to do things we disagree with? People are explicitly calling out their affiliations with adtech in this thread; should we abandon discussion with them because you think their paycheck precludes them from being able to be persuaded?
Here's a riposte for you: "The mark of an educated mind is the ability to entertain an idea without accepting it."
The digital marketing/analytics industry doesn't spend a lot of time thinking about how to secure all that data they're collecting, and data breaches are happening more and more frequently. A lot of this data is supposedly anonymized, but often can be tied back to identifying information.
I would consider Google to be an exception here, as they have some of the best security people in the world working for them. But they are just that: an exception. Don't forget that the industry that Google enables is a lot less ethical (and a lot less competent) than Google itself.
There are other downsides too (e.g. the impact of advertising on editorial integrity, and the ethics of using political ads to tip the scales in an election).
Hypothetically if congress could ban both obnoxious and targeted ads (somehow) leaving us with the unpersonalized newspaper model of ads would you be for or against that bill?
This only seems partly right to me. Let's say someone wants to sell fishing equipment. The traditional way of doing this is to buy ads on fishing sites. So now my fishing equipment purchases make there be more writing about fishing; yay!
Then one of the fishing websites decides to put a tracking pixel on their site to drop "fishing website visitor" cookies. They make a deal with a third party provider and get paid a small amount per visitor. Then fishing retailers have a new choice: instead of buying ads on fishing sites they can instead buy ads on any site for users who have one of the "fishing website visitor" cookies. If there were a monopoly fishing site, then this would increase their earnings: while the ad space on their site isn't as valuable, they will set the pixel price high enough that they come out ahead. It's not a monopoly, though, so the price of the pixel gets driven down through competition, and money that would go to fishing sites instead goes to the publishers that people who spend money on fishing equipment visit.
In this case I see how it's worse for fishing sites, but not how it's bad for consumers: their willingness to buy fishing equipment translates into support for all the sites they visit, and not just the fishing sites.
But there are also many niches that don't have economic tie-ins, or have ones that are far weaker than "writing about fishing" and "buying fishing equipment". In a world with targeted advertising, these niches do better, because of overlap between audiences. A "let's have better housing policy" blog can show ads for fishing equipment, vacations, HVAC supplies, or whatever else visitors have shown interest in on other sites.
Additionally, targeted advertising increases the total amount of funding available for online content, because people with niche interests are available to be advertised to in more places. Seeing ten fishing ads once a week when you visit a fishing site vs seeing twenty fishing ads spread over the course of the week, etc.
So, yes, niche publishers in lucrative niches would make more money if we only had context-based advertising, but I don't think niche publishers overall, publishers overall, or consumers would be better off.
(Disclosure: still speaking only for myself)
(I don't work in adtech, but I have sold technology to adtech companies.)
So if we would stop with ads everywhere, we can save the planet.
Here's my speculation about how this would change people's purchasing:
* Products would be a lot stickier. A lot of advertising is about trying to move people between competitors, or keep them from moving. Sometimes it's an explicit "here's a way we're better" (ex: company advertises that they don't charge unpopular fee X), other times it's a more general "you should think positively of our company" (ex: we agree with you on political issue Y).
* Relatedly, it would be much harder to get many new products started. Say a startup makes a new credit card that keeps your purchase history private: right now a straightforward marketing approach would be (a) show that other credit cards are doing something their target audience doesn't like, (b) build on their sense that this isn't ok, and (c) present the new card as a solution. Without ads they would likely still see uptake among people who were aware of the problem and actively looking for a solution, but mostly people would just stick with the well-known companies.
* Reviewers would be much more trustworthy. There's a long history of reviewers getting 'captured' by the industry they review, ex: https://www.fastcompany.com/3065928/sleepopolis-casper-blogg...
* Purchases of things people hadn't tried before would decrease, both things that people were in retrospect happy to have bought and things they were not. One of the roles of advertising is to let people know about things that, if they knew about them they would want to buy. But "buy stuff they don't need" isn't a great gloss for this, since after buying the products people often like them a lot.
This is just my guesses; I work on the technical side of ads and don't have a great view into their social role, and even if I was in a role like that it would still be very hard to predict how the world would be different with such a large change. Where does your picture differ from mine?"
(For 'saving the planet' I think a carbon tax would make a lot more sense.)
Every day that becomes less and less of an option and presenting it as an option is disingenuous. Are you seriously suggesting that people live without search engines?
I think it's valid to question the role of cars in our society even if the critic took a car to the meeting, for example.
As for living without a search engine, people have gone through much worse for their moral beliefs. I personally don’t see the moral issue at all, but if you feel so strongly about it—-then yes I expect you to sacrifice your own interests for those beliefs and not just go around making cheap condemnatory statements.
Going back to adtech, I more or less equate it to the tech you alluded to, as well as global tracking, NSA-sized surveillance, and a complete disregard for "privacy", regulations and civility. Would any self-respecting person follow their neighbors around, write their every moves on a notebook, and sell that to the highest bidder? It's literally what is being done by those tracking giants, on a much bigger scale (and Google does track your every move, or does its best to do so).
I feel like I'm distancing myself more and more from conventional Internet platforms as a result.
I don't see a good way to do that, at least.. a way that's practical to actually enforce. As it is, the FTC is fairly toothless and is better at offering guidelines than policing.
> as it does in every field except for the web
Well.. that's just because they have dedicated account executives and sell advertising through a combination of direct solicitation and much smaller amount of "walk-in" business, that's not practical for all creators or formats.
> Web is the one weirdo market with tracking.
This has always been the holy grail for advertising, the other industries put up with statistical "audience modelling" only because they have to; however, working in one of those 'other fields' I can tell you.. our account executives will take as much direct tracking data as they can get. e.g. "Have you installed our Radio App?!"
> Make that illegal and it will be good like all the other markets.
I feel like we lost the fight a long time ago.. I remember when the 'Flash Blocker' plugin was a great tool. Unfortunately, too many modern sites are entirely reliant on JS in a way they never really were for Flash and the idea of using 'Script Blocker' that's on by default makes navigating the web exceptionally difficult.
It's too bad, because it's probably the right solution.. why should the sites we visit have the right to execute programs on my computer by default?
2012-02-19: Almost every major retailer, from grocery chains to investment banks to the U.S. Postal Service, has a “predictive analytics” department devoted to understanding not just consumers’ shopping habits but also their personal habits, so as to more efficiently market to them. “But Target has always been one of the smartest at this,” says Eric Siegel, a consultant and the chairman of a conference called Predictive Analytics World. “We’re living through a golden age of behavioral research. It’s amazing how much we can figure out about how people think now.” -- http://www.nytimes.com/2012/02/19/magazine/shopping-habits.h...
2016-02-28: Pass a billboard while driving in the next few months, and there is a good chance the company that owns it will know you were there and what you did afterward. Clear Channel Outdoor Americas, which has tens of thousands of billboards across the United States, will announce on Monday that it has partnered with several companies, including AT&T, to track people’s travel patterns and behaviors through their mobile phones. -- https://www.nytimes.com/2016/02/29/business/media/see-that-b...
2019-03-07: Location-tracking technology can now monitor people so precisely that retailers know, for instance, which customers visited a fitting room but never made it to the cash register. -- https://www.cnbc.com/2019/03/08/how-retailers-can-track-your...
I'm disappointed at webmasters who push garbage from their sites.
Only solution is criminalizing this behavior. In no other context is stalking a person against their will and consent permissible in a "free" society.
If you're unwilling to do that, just set your DNS servers to the Adguard servers (https://adguard.com/en/adguard-dns/overview.html) and you get most of the same benefit, though obviously without the control that the Pihole offers you. On Android devices, you can go to Settings - > Wifi & Internet - > Private DNS and set "Private DNS provider hostname" to dns.adguard.com (or your own exposed Pihole server, if you're so inclined) and get the same benefit when you're on LTE.
Mozilla for example is going to force everyone to use CloudFlare as a Resolver
I should not have to dig deep into the internals of Firefox to opt-out of sending all my traffic to CloudFlare, a company proven time and time again to be pro-censorship and anti-competitive
At least a browser might have a user setting to disable it.
Keep in mind you're on HN-- we tend to be a more technical population :). If you're interested I found this on StackOverflow via Google: https://unix.stackexchange.com/questions/144482/iptables-to-...
You'll have to Google how to set up iptables/telnet or ssh on your router yourself, assuming it supports it.
The next game will probably be mitming these devices by flashing a new CA store.
There is no general solution to running an openly adversarial app/device in your network.
Even still filtering based on SNI will work for a long time yet. Yes, ESNI is on track to becoming to a standard but support for legacy devices/browsers means it to will rely on network tests for support - so it can also be disabled.
Do you have any evidence that they're going to force anyone to do that?
https://twitter.com/selenamarie/status/1175092910200483840?s...
Shameless plug: https://GitHub.com/yegle/your-dns
Firefox's choice isn't the best but you can disable it. Set network.trr.mode to 5 in about: config, which means disabled and deliberately configured as such. Then Firefox won't ever try to use DoH.
As others have pointed out, you can also use other resolvers than cloudflare's, through network.trr options.
it acts as a pihole and a lot more (firewall, device vlan isolation, vpn termination, etc). i have these hosts files [2] loaded into its DNSmasq config.
I've a couple of questions, though:
1. Do you run one unbound instance per configuration, or share among multiple configurations per user or...? The reason I ask is, sometimes the latencies are too high, 2000ms+. Should I be creating less configurations per account?
2. How could nextdns combat ad-networks resorting to DoH: https://1.1.1.1.com/dns-query?name=example.com&type=AAAA
Re: nextdns-cli: I think you may have misunderstood my question. I was more curious abt how the backend worked: Do you run one unbound instance per nextdns-configuration?
Re: DoH: I was pointing to the fact that XHR request to 1.1.1.1 (or any DoH provider that supports application/dns-json) can now resolve domain names. In this case, there's no reliance on either browser's DoH resolver or resolver set by OS / AccessPoints / VPNs.
For trackers to use DoH, they could certainly perform XHR requests to resolve a domain, but they won't be able to use it to perform a request from the browser. You may use http://<ip> instead of http://<domain>, but this has two issues:
1. You won't be able to use virtual hosting (the Host header is gone), and thus you need one IP per "service", which is doable but harder, more custom and more expensive.
2. You won't be able to use HTTPS, except with an expensive certificate that is somewhat harder to setup.
As most websites are HTTPS now, a non HTTPS tracker would rase mixed content errors. Not to mention that this IP would quickly be blocked by browser based ad blockers, and IPs are harder than domains to change.
And all this is doable without DoH, you just embed the IP the ad library embedded by the site.
I guess, XHR aside, mobile or desktop apps making DoH requests (to https://ipaddress) is something that can't be blocked by DNS based ad-blockers? A firewall might do the trick.
In order to make an XHR to 1.1.1.1 you need to be running javascript. But the whole goal of these CNAME and other evasions is to run javascript (aka not get blocked by browser extensions and such). So they already need to achieve their goal before they can make the XHR. Since they've already achieved their goal, why are they bothering with additional complexity?
Adblocking browser extensions could probably block XHR DoH requests that have adcompany.com in the query parameters.
This isn't really specific to DoH. Any database that can be queried by an XHR could be used instead of DoH for this purpose.
In general though, DNS filtering + client filtering is an awesome combo.
Given that no reasonable legislation will likely pass against adtech, I'll be stuck buying rpis as gifts again for the next several years.
By using random, frequently updating CNAME's it effectively defeats the mechanism Pihole uses.
You could still block IP addresses of the advertisers, but often time's they don't do BGP, so they aren't going to have blocks under the same ASN you can simply block.
It's a nuanced and challenging problem for sure.
My experience is with DNSMasq, but should apply to PiHole.
I'd noticed that several ads networks were utilising massive numbers of hosts at a specific domain (limited to advertising). If you're using a simple /etc/hosts blocklist, you'd have to individually block these. The alternative DNSMasq affords is to block entire domains or subdomains. This is remarkably effective.
But ...
... if ads and content are being served from the same domain, you'd have to switch to a DEFAULT DENY plus EXPLICIT ALLOW rule. So you'd have to blacklist all of "example.com" except for the valid hosts, say, "webserver.example.com", "css.example.com" and "nonhostile-js.example.com", to enable assets from those specific hosts.
Another alternative, which would probably work reasonably well against CNAME attacks, is to simply deny all traffic at the IP level to the CNAMEs' targets.
Since the goal of the advertiser is to make a small number of hosts or hostnames appear as a large number of their client domains, you still have an effective lever to apply in blocking access. But you'll need to use IP-level blocking (firewall), rather than the until-now useful and largely effective DNS-based blocklists that have become popular.
As a technical countermeasure.
Regulating the everloving hell out of these practices, and/or suing both tracking firms and their clients, is another possible approach. And I think it's going to take both technical and collective social and legal methods to address this.
Suppose you load example.com/article. Ad Agency serves ad/tracking assets from example.com/article/Zqj7MOm.js. When you reload, it serves from example.com/article/llc9h76.js. How do you block it? You can't. Getting this to work in a pluggable fashion is an implementation detail (maybe some on-the-fly statistical generation of URLs + passing nonces to and from Ad Agency as a mitigation for spoofing by example.com). Another way to implement it is a custom URL router that dynamically reverse proxies to Ad Agency on the generated ad trojan horse URL. The only reason this hasn't happened yet is because still very few people use adblock, esp. on mobile.
P.S. please don't do this.
Ad companies could move to only paying when ads result in a sale, but that only works if there's a sale that can be tracked. If I click a BMW ad and then buy one in the showroom that's really hard to track.
What is to stop ad tech companies creating a cryptographically secured reverse proxy device[1] that clients can install in their network between the web server and requests from the internet?
The ad tech company only has to trust that their device is secure and the company that sells their website doesn't have to give up control of their domain or anything else.
They would have to isolate the ad tech device from the rest of the network and only allow it to communicate to the web server inside the network and the ad tech server outside their network. If something goes wrong with the device then it is trivial for the web serving company to bypass it.
-------
As is mentioned in the grandparent comment, this allows anything to be done to the content being served from the website and not only domains cannot be trusted, individual URLS cannot either. Ad blockers will have to rely on examining the content directly even more than they already do. This would make it much less scalable for the ad blockers to deal with, they have to identify ad content individually, by their signatures or page structure in the best case, or examining arbitrary code behaviour in a worse case. Ad blockers may then have to deal with identifying ad content which changes as fast or faster than new ads appear, which is a lot worse than the relatively few(and relatively static) domains, URLS, bits of HTML and Javascript that are there now. Ad blockers may lose eventually due to incomputability, but who knows.
-------
[1] Using a TPM is one possibility
- Disable JavaScript
- Render SPAs off-site (or in some sandbox with a different network interface) and return the static HTML and CSS
Good enough to read news articles
Found on [1]
(not affiliated with any of those in any way, I'm just a user of Adguard home)
[0] https://adguard.com/en/blog/disguised-trackers.html [1] https://www.reddit.com/r/pfBlockerNG/comments/e0bsto/defence...
[1] https://git.frogeye.fr/geoffrey/eulaurarien
With third-party trackers: https://hostfiles.frogeye.fr/firstparty-trackers-hosts.txt
First-party trackers only: https://hostfiles.frogeye.fr/firstparty-only-trackers-hosts....
As an open-source DNS implementer, I know this has already been done, since my DNS server (MaraDNS’s Deadwood recursive resolver) has the ability to refuse to resolve DNS names with bad IPs via ip_blacklist.
The reason I implemented this is to block NXDOMAIN redirects (when using an ISP’s DNS server and mistyping a domain name, instead of getting “nothing there”, it goes to an ad-filled “search” page provided by the ISP), but the implementation scales and it should work for blocking a large number of rogue CNAME redirects like this one.
I’m sure others have implemented something similar out there (I will let someone who knows the pihole ad-blocking DNS server, not to mention NextDNS, better than me tell us how they do this), and I’m sure Firefox, if they do not do so already, will allow ad/privacy blockers to know the IP of a given name to allow blocking at the browser level.
With IPv6 that's as impractical as blocking "rogue" FQDNs.
One way to do this is to have multiple hash tables: One for single IPv4 addresses, one for IPv4 /24 ranges, one for single IPv6 addresses, one for /64 IPv6 ranges, and one for /48 IPv6 ranges. Note that while the hashes have (generally speaking) a “big O” of 1, we need to perform one additional operation per range size. IPv4 /32 and /24 blocking requires two lookups, and IPv6 /128, /64, and /48 blocking requires three lookups.
The response in this case will all but certainly be an increasing tendency to apply IP-level whitelists, and deny or at least limit traffic until it's demonstrated trustworthyness.
Much as port-based firewalling progressively closed off virtually all service access other than HTTP/HTTPS, and a few other exceptions, bad actors will likely limit the effectively-reachable scope of IP address space itself.
A while back ago malware started to use a scheme similar to fast flux, but rather than changing the IP address they used a chain of cnames to hide the malware network. In order to combat this researchers developed detection tools to find algorithmic generated domain names and flag them as suspicious at the resolver layer. I would expect to see the same mitigation method to travel into ad-blocking.
This is my recipe for browsing the web. Blocking specific cookies. Blocking all third-party cookies. A1llowing specific third-party cookies. Still, in recent months, I have noticed some have started getting smarter. So I block js there.
But every browser is different with ease of use. Love brave browser capabilities. Like Chrome ease. Hate Firefox features. So using extensions to fill in those gaps.
In most cases, people don't want to commit a portion of their monthly budget to a specific website for the rest of their life. I don't know how often I read Ars Technica, but it's probably a couple of articles a month. That is worth maybe $0.10 to me, so they can never collect that profitably. They use ads because then I "pay" whenever I visit, without having to approve any payment. More people visit, they automatically get more money.
I wish there were some sort of globally-accepted micropayment system. With the billions of cryptocurrencies floating around, it surprises me that nobody has attempted this yet. I buy $10 of cryptocurrency. It gets loaded into my web browser. The webserver says "hey, you have to pay for this". My browser asks me if I want to do that. If I pick yes, then the server sends me the rest of the HTML after it agrees that the money was in fact transferred.
(The closest thing I've seen to this are Twitch "bits". That is a micropayment platform that seems to be working pretty well, but it's used by the same people that want to pay their favorite content creators a stipend and so real-money recurring subscriptions are just as good. For that reason, I'm not sure we can infer much from that model, except that people will buy value in bulk and then dole it out to individuals at random intervals... which is pretty interesting if you think about it.)
I think what is stopping this from being a thing is not any technical issue, but rather just greed from the content creators. I am sure that anyone that sells a subscription service is making money from people that have forgotten to cancel or don't get the maximum value out of their subscription, and it's probably a lot of money. Nobody is going to give that up.
I also think advertisers pay too much for ads. I bet the "brand awareness" ads aren't worth nearly as much money as they pay. Meanwhile, publishers are making a lot of money off of selling impressions, and are probably hesitant to turn off free money from dumb people. Remember, serving an ad requires no input or investment from the end user; the website loads, they get money. If there were "brakes" applied every so often ("are you sure you want to pay the content creator using your real-world hard-earned cash?") revenue would go down.
So I think the problems here are:
1) Advertisers want to advertise. If you remove your publication from the list of places where they can get something advertised, they'll go elsewhere. The money won't be removed from the ecosystem, and your competition will be enriched. That's not strictly a PROBLEM, but your investors will not be making happy faces at you when you leave money on the table. Only some sort of law could change that, and there will never be any such law.
2) Publishers are making a lot of money on unused subscriptions, so they continue to push subscriptions over micropayments.
A lot of people are making content worth paying for. It's just that we can't afford it, but the advertisers can.
More broadly, though, I agree with your comment and think there are additional unlisted problems.
I pay for Ars Technica because they offer an amazing cross-format (HTML, RSS, PDF, etc) clean browsing experience for paying customers plus sent a branded Yubikey plus had clear online cancel buttons instead of hoops like other publishers. In my personal utopia, every news site would be served in this cross-format ad-free fashion.
I honestly wish they'd send a new branded Yubikey every year so I'd always have an important branded physical reminder of their existence as its the best and most useful tschotske I've received as a thank-you-for-subscribing gift (and probably likely so for others in the HN crowd).
Ars Technica is one of the few sites I regularly visit directly (just like I visit hckrnews.com to often and directly). Just like here on HN, I directly visit for the content curation and occasional comment (both of which is better than social media algorithms).
Which lead me to the consideration of a third problem...
3) Users try before the buy. You can only begin the process of receiving money after they've read enough content.
I'm surprised I haven't seen more cryptocurrency-based $1/week type subscriptions to unlock the content/features/etc for a week at a time (or perhaps forever, if a user sent enough cryptocurrency).
If we get rid of these privacy invading ads and micropayments/subscriptions don’t take off in a big way (I don’t think they will) then one or two things must happen
1) advertising money remains even though ads are dumber (less narrowly targeted, more fraud etc)
2) there is a lot less money to go around so there must simply be less content.
I think the answer is somewhere in between. I don’t think it’s a pessimistic view that maybe 75% of sites not only risks disappearing but perhaps should. The abundance of “free” content is what makes people unwilling to pay for quality.
Sites and ad networks have being engaged in a abusive relationship with users for a long time now and it's wrong to expect them to not try to protect themselves. If you want users to stop blocking your ads then stop serving them ads worth blocking.
Here is a demo video:
https://twitter.com/konarkmodi/status/1198412297842184192?s=...
There needs to be an organization that imposes ad guidelines(like only specific formats, not being intrusive, etc) for both websites and ad companies. They should verify the ads/websites based on user reports and if they find something, to kick the company out.
All companies that follow those guidelines should be whitelisted by ad blockers, probably something implemented at browser level.
Otherwise is just a useless chase.
Also, ads can be placed teh same way they were in newspapers - the ad company would submit ads to the content creator, who would manually chose which ads to include, and where.
As for the online services needing ads to keep lights on:
1. The pervasive dragnet that the online ad-industry has birthed is a massive reason behind content-blocking.
2. Ads are freq used to spread source of malware, scareware, spyware, ransomware, fake-news among other totally unreasonable things.
3. The end-users should be free to chose what they want to view and what they don't. The service providers are free to refuse service.
4. The tracking that goes on is so covert that it seems to me that it is borderline unethical [4].
5. The online ads business is a scam [5]?
---
[0] https://news.ycombinator.com/item?id=20767891
[1] https://news.ycombinator.com/item?id=20700914
[2] https://news.ycombinator.com/item?id=21497488
[3] https://news.ycombinator.com/item?id=21525592
If we want to push for guidelines on acceptable ads, how about starting with these?
https://bostik.iki.fi/aivoituksia/random/no-stalking.html
(Yes, I have brought these up recently elsewhere.)
I suppose we are going back to the roots
White lists in hosts file with ips and good sites
Yes
Or DNS
How can I block cookies with uMatrix for sub domains like *.domain.com for any site?
PS: I assume that just temporary solution. Because nextsstep is just hosting some js from "analytics" on main domain and/or solutions like cloudflare for e-commerce / google news / etc.
And for filtering that bs we need deep filtering and api inside JS VM
I would like to point out that it has never been the case for Google Analytics and possibly other trackers. The developers of a website are supposed to copy/paste the Google Analytics snippet directly into their own JS, such that GA has access to first-party cookies. And then GA phones home some tracking data leveraged by this first-party cookie.
Blocking third-party cookies never blocked this kind of tracking. You needed to block the domains that the script requested via AJAX. But it is indeed made difficult with CNAME Cloaking, because the domains requested are subdomains of the current domain, and can be changed regularly as explained by the article.
There is no end-game solution against tracking. It will all come down to tracking companies ordering websites to install some library directly in their back-end and pass it user data as well as behavioral data captured from some other library installed in the front-end. Tracking data will pass through applicative pipes and it will be impossible to block reliably.
That's fear mongering. The ad company can't pester their clients to make changes to the DNS on a regular basis. I'd say that anything beyond initial setup would be unaccepted to most clients. And clients won't give control of their DNS to ad company, so automation is also not really possible.
Also, because this setup is substantially more friction than a simple 3rd party tracking "just copy-paste this code", I'd guess it will only be used by high profile clients.
This all means that while annoying, it shouldn't be too hard to find and add these subdomains to the ever-updating ad url blacklists.
Many DNS providers have APIs.
>And clients won't give control of their DNS to ad company, so automation is also not really possible.
Sure they will. Or they'll use another party that does it. They already add JS from the ad provider that does god knows what to all their pages, and give full control over their content to Cloudflare. So why wouldn't they give an ad provider API access to their DNS?
So dnsdelegation.io can just request certificate for the domain you've delegated via cname from any CA.
I mean is there any replacement for them, not using cookies? Because cookies seems to be the only global storage for user identification data. Since tracking script was hosted on their domains (and included into websites with script tag), cookies were shared across all site, that included that tracking script. IMO when they switch to CNAME trick, they will loose this capability.
> Instart Logic will detect when the developer console opens, and cleanup everything then to hide what it does. I had to trick IL's script into thinking the dev console was not open to take the pic above.
>While this is considered bad practice for a website to set cookies as accessible to all subdomains (i.e., *.website.com), many do this.
>In that case, those cookies are automatically sent to the cloaked third-party tracker.
That is a distinction without difference. The security implication is storing any data with website.com!
Currently it's just dnsmasq with a huge blacklist, and I guess it doesn't support checking the whole CNAME chain against that list, which would be really cool.
That doesn't help if dnsmasq only checks the incoming request against the list, and not the whole cname chain of the result.
The browser API used by uBO returns the last CNAME in the chain. I consider the DNS lookup itself to be an non-issue overhead-wise in uBO because:
- The browser would need to do it anyways
- DNS lookup results are cached at both the browser and uBO level
Furthermore would the Firefox Multi-Account Containers https://addons.mozilla.org/en-US/firefox/addon/multi-account... with container per site prevent such tracking (has to be done manually ATM) ?
By possible I do not mean technically possible, but feasible in the resources required maintaining the list as well as good enough user experience.
Seriously.
We'll look back at the good old days when ads were mostly just banner ads.
Idea: Start paying for content and support the sites that offer this option. The entire concept of adblocking lives on borrowed time: hoping your content creators are making enough money off the suckers that don't use adblockers.
It's hard for me to envision legislation that wouldn't just be a clusterfuck as the government encroaches further onto our internet.
You used to have domain.com and declare ns1.domain.com pointing to your host so it would show domain.com instead of host.com
There doesn't appear to be a huge market for services that do little/no tracking, as users are all unaware of the tracking that services do to begin with, so they would not even notice the difference.
"What Is Your Bank’s Security Banking On?"
FIS, Fiserv or Jack Henry ... collectively control approximately 70 percent of the market for bank core processors (according to FedFIS.com, Fiserv is by far the largest).
https://krebsonsecurity.com/2018/03/what-is-your-banks-secur...
Covered at HN:
Until your proxy is hacked, I suppose.
Resistance is feudal.