Firefox browser will block the IAB's DigiTrust universal ID
digiday.com
digiday.com
> [IAB Tech LAB svp of Membership and Operations said:] “They believe no third party can be trusted. We take a different position: that trust should be established directly between consumers and the brands, and publishers they trust, and with the third parties that those brands and publishers trust.”
Question to that guy: What act specifically would establish that trust? My browser downloading JavaScript from half a dozen companies that I've never heard of?
Or is their position that by opening a link to some web page, I declared my boundless, irrevocable trust in that site, all third-parties that site delegates to, all third-parties those third-parties delegate to, etc etc as infinitum?
Where else in life do you get this understanding of "trust"?
Why is the company called TrustX instead of AdX, if that's what they're dealing with? Maybe so that they appear more innocent when they show up in your browser warnings or cookie alerts? That's the kind of "trust" they're hoping to exploit.
The infosec "trust" is not something earned or even verified, but an assumption that something is not malicious. Imagine a fortress: inside of the walls is called "trusted", outside of the walls is "untrusted". So a trusted CA merely means a certificate inside your fortress' walls that an attacker can't modify.
It's not even that. It's just a statement of fact. The things that you put in positions where they can fuck you are de facto the things you trust. You might know for a fact that they are untrustworthy garbage, but you're still trusting them.
This doesn't imply anything about the contents that can be transferred over the TLS connection. Could be malware. The other side could leak your private data like crazy. That's outside the scope of the TLS chain of trust.
When I use a car I trust the combination of the manufacturer and the regulator to have used parts in a fashion such that they won't kill me. I don't know or trust the individual part manufacturers, that's the automakers job.
There is no equivalent to the doctor, or the automaker, or the regulator here. It is not at all similar.
Similar for the car manufacture, plus there are negligence laws in place if either the hospital suppliers or car manufacturers fail.
There is no FDA or NHTSA for web technologies.
I'm "that guy", and yeah I feel ya about "most press statements". Anyway, here's what we think would be a good start in establishing trust ... do you agree? 1. Consumer visits a website or app they like. 2. Website/app offers standardized privacy preferences/controls that are easy to understand, and apply globally. 3. Consumer indicates their preferences, realistically based on their inherent trust in the website/app ... could be anything from ghost mode ("no tracking at all") to limited ad targeting ("ok, you can retarget me for 3 days only, that's it") to measurement only ("count me as a distinct user, but no ad tracking, profiling, etc.") 4. those preferences are propagated to any/all downstream parties working on behalf of the website/app or the advertiser, all of whom have to submit system-level log file samples daily (a blood sample, if you will) to a central processing system NOT governed wholly by ad industry 5. ongoing data analysis, with data exhaust, provides for open accountability 6. oh, and consumer empirically sees that their preferences are being respected
We'd also love to see a significant reduction in the amount of JS and third-party requests. But these are all hard problems to solve while also maintaining an open web/ecosystem.
Entity visits a website. The website logs whatever they want, subject to GDPR-style rules. They never send the full logs to a third party, and never send individual information, anonymized or not, without a specific business reason that benefits the entity.
Entity creates an account on the website. Now the website gets to display a privacy policy that conforms to GDPR-style rules, and creates the account only with explicit informed consent from the entity. The website specifically notes the jurisdiction in which they operate and the contact method for complaints, inquiries, deletions, and so forth.
No central processing systems, no unified trackers, no cross-site data analysis.
I do not consider any form of ad targeting to be of benefit to me. Therefore, my data should not be sent to any third parties for that purpose.
It's not finished/perfect, but changes a lot of things.
I'll never pass recaptcha, but idc, i installed this on my wife's computer as well and i'm starting to explore a way i can make a ios build using the recent tethered jailbreak for ios devices (besides the most recent releases). One day, It would be fun to try a prank on a day I actually go into the office and exploin a vuln in the old cisco router firmware to try to get installed on other devices on the network and see if how many people actually notice the changes and/or start using the browser because the dont get ads anymore lol
I understand this case, but GP suggests to fake data for all apps. There are apps which are useless without location data. Or worse, you definitely wouldn't want to [accidentally] fake data for some apps, like a "SOS button" app.
If they want to send fake data then they should have the right to do that.
It's my phone, so if I want to set my location to another country I should be able to. Of course this should be on a per app basis.
An SOS button app? This is a niche usecase.
Not at all. In fact, more and more emergency services providers (i.e. the callcenters where 911 gets you) get your location automatically when you call them. I'm not entirely sure though if they only geolocate by cellphone tower, or if the handset also sends location data along with the emergency call. I vaguely remember hearing about this being "supported by all modern phones" or something, so it might be the second. In this case, you absolutely don't want faked location data because it could cost lives.
Those mechanisms are not running as untrusted applications on the OS anyway, I believe most/all of them are implemented in radio firmware.
Of course not everyone will run a Librem (understatement). But interesting ideas might find their way into more mainstream platforms.
I don’t know. It’s a good signal to me, a user, that it’s an app I probably don’t want to be using anyway. Also, it’s the perfect solution to change the supply and demand structure. If people keep using the apps, they won’t know the difference.
Finally, it’s their app and this their price (personal data). You can chose to pay with it or not. Just like with any other currency, the choice is still yours as a consumer, but you are not entitled to the product by default.
There’s a reason selling organs is illegal in most countries, otherwise people end up cornered into a position where they have no other choice.
Regulation doesn’t work (or doesn’t want to work, see the GDPR), the only thing left is guerilla tactics like poisoning the data so the ad-tech scum can’t tell whether they’re being lied to or are getting real data, putting in question the integrity of their entire database and them out of business.
What happens if your GPS is disabled right now and you dial an emergency number? Depending on the OS/phone we could either:
a) live with the consequences, or
b) have a bypass mechanism that can only be enabled for very, very special apps and emergency numbers
s/block/fake/ doesn't change that.
However, if everyone sends them garbage datathen they don't really have anything valuable then. The whole business model falls down.
At some point, our ad partner contacted us letting us know that some of our data was coming from blacklisted IP addresses--AWS, Linode, known bots, etc. Ranges where a human almost certainly isn't actually viewing ads, and told us to fix it asap or get out.
We ended up licensing an IP blacklist. It updates daily, and it comes with both individual IP addresses and cidr ranges. We didn't have time to write a fraud system to ban users, or do this check via our api. So my solution was to check every IP that came in through our load balancers against the blacklist and blackhole it somehow.
Since we were using nginx, I swapped to open resty because that comes with Lua already fully baked in. Next, I wrote a Lua script that just checks if an IP address is in the blacklist. It even had a caching module! That was awesome.
The real hard part was where to keep the IP blacklist. I came up with the solution to use Redis. If an IP address exists as a key in the Redis DB, it's blacklisted. This "if key exists" check is O(1) in Redis as far as I still know. So I wrote a cron job that runs every day to download the new blacklist, expand the cidr ranges, pipe the individual IPs into a second unused redis db, save the DB and restart production redis so it picks up the backup and refreshes its list of addresses. This list was massive, btw, especially when you expanded the cidr ranges, some of which /8. And the Lua script would just run a GET query on redis. If the key exists, open resty would just return a 40x code. Lua+open resty and redis are all super fast so we didn't lose much by checking every single API request this way.
After that, the ad agency was happy and we didn't get booted. But it was a super close call. Basically if redis didn't exist or wasn't as awesome, I'm fairly certain some engineers would have worked a solid 72hrs to write the php needed for an effective ban system that could go into production. I wrote the lua/redis solution and got it into production in an evening. So simple and really fun to write.
If this were to happen to a company getting bad data from a browser, either they'd have to clean up the data or get kicked out as well. Ad agencies pay for this data, so it's not like they're gonna turn into a charity and accept it. I'm sure it also messes up their datasets as well. I can't even imagine what it would take to clean data coming from a known good source/ip but with bad info. Yikes.
Fake data pollutes the stream.
If data is shit, approach dies, because it's not economically viable. If it's just unethical, it will never stop.
To be clear, this system neither recognizes an audience nor can anything of this sort be fully anonymized. A universal ID such as this would recognize every individual member of an audience, not an audience as a whole. Recognizing an audience would look like telling an amazon seller that their product is popular with people who also bought paper towels. Such recognition would be possible from a list of transactions i.e. (paper towels, sunglasses), (energy bar), (dish soap), (laptop, paper towels). In this system there is no knowledge who made what transaction, no universal ID. Any Universal ID can't be fully anonymous because your browsing history is you. You might search for something related to your current residence, your hometown, your workplace and the breed of your dog. These searches alone would be enough to uniquely identify you already, but it would be difficult. Luckily you make boatloads of searches a day, and combining all that data would make your identity much easier to discover. This all assumes your search provider bought in to this universal id system (use DuckDuckGo).
Or basically just stop tracking people online ? And find another way to sell your stuff ? #thinkoutsidethebox
Product-first companies seem to be doing fine – Spotify doesn't exactly have a problem with people not wanting to pay for it.
If you strip all this and just make an old-fashioned public service business, maybe operated by a lean, tech-led non-profit (looking at you Mozilla...) you are suddenly ending up with a pretty cheap (e.g. cents instead of $) service (at least compared to what classic media costs). Maybe you also have to cut corners on things like free xK-Upload, but I think most people (ie consumers) could live with some surcharge there.
At least he's honest about it. If $10 sounds like a lot, you aren't sufficiently scared of ad-tech yet.
So I don't know why Jimmy Wales needs to charge 10$ for his network if he's only interested in sustainable operation. If it's the early adopter package for development expenses, I'm all in, but I don't know how he shouldn't eventually get away with 1 Mio. users paying 10$/per year if he doesn't intend to market it as a a startup/make money in successful startup scales.
A lot of the inventory I buy is now on intent-based sites, and the passive profiles used for cross-site banner display for example, for us, tend to drive the lowest quality conversions.
Advertising can still have a place, but it requires effort to do well (like buying a sponsored post on a subreddit right now). Higher effort though I'd wager will lead to better conversions for all in the long run.
It has since morphed into something else entirely.
There could be a free casual web, for people who just want to check things out or get a general overview, and offers for those with a deeper interest, who maybe spend a lot of time there and have very different demands. What doesn't work is gating casual information.
The scummy company whose entire business is based on violating people’s privacy asks me to create an account and give out real personal information like name and address? Fuck that.
Same thing with paid newspapers, you’re trading off a pseudonymous ID gathered via cookies/browser fingerprinting against which you can defend with ad-blockers to your actual identity you give them when signing up and then logging in every single time. And Google and Facebook just leech off that since their trackers are also loaded on every page.
As a long time ad tech executive, I can state that there are maybe 3 companies that actually add value to the chain. And those companies are not even in ad tech... The entire market is a fraud based on obfuscation and lies and every single member of the IAB committees are nothing but shills and charlatans hoping for some career visibility and personal gain.
What the hell does this even mean?
Good on Mozilla for doing this. I want privacy when I'm on the internet, without having to resort to tor-like schemes
Here is the full quote :
“We know certain companies (Firefox) take the position that there is no sufficient consumer value to justify ‘tracking’ — anonymous audience recognition — of any kind, not even for use in communicating privacy choices,” Mitchell said. “They believe no third party can be trusted. We take a different position: that trust should be established directly between consumers and the brands, and publishers they trust, and with the third parties that those brands and publishers trust.”
clarification: this doesn't answer your question about what he means, this is a critique of what he said.
The problem is that most people wouldn't trust those brands in the first place if they new what shady third parties they enlist.
For now, I commonly allow javascript/cookies on the top-level domain (I am a lazy uMatrix user). This will presumably change in future...
I find that some of those options are excessive, but it's good for the privacy-minded in general. Just change the options based on your threat model.
Unfortunately, that would mean not using Firefox on MacOS, in my experience.
It's always hard to tell whether people think their three letter name is so distinctive nobody could mistake them for anybody else or whether such confusion is instead desirable...
Publishers online and offline have almost never made money without ads. The only diff. is tracking readers is easy online. And that is not probably going to change anytime soon. I don't trust publishers. I trust Mozilla.
Mozilla can't help with that, even if they break up with Big G.
Mozilla deserves our support for other reasons though.
Google: our ad and analytics tracking cookies are first-party cookies if you're using chrome :)