With advertisers switching to 1st party cookies it will get harder to avoid tracking, unfortunately.
With advertisers switching to 1st party cookies it will get harder to avoid tracking, unfortunately.
It also deals with 1st party cookie tracking. It clears cookie/storage on every page load as long as it detects that you're not logged in to the website (still buggy) using machine learning (NLP).
The next minor version (under development) will also allow you to block websites/domains from appearing from google search results, facebook feed, twitter feed and basically the entire internet.
It also blocks cookie/gdpr banners on websites.
(Signup on mobile does not work for now)
You can also add summaries/TL;DR for any link on the internet (right click) so others dont have to click.
The latter part won't prevent bad behavior, but it will force that behavior to be proxied -- which carries technical, financial and legal implications that will cause companies to be more careful about their downstream redirects.
https://pi-hole.net/2020/01/19/announcing-a-beta-test-of-pi-...
Maybe DNT should return as respected feature within browser and user choice shouldn't affect the access to the content but only its form.
But I would prefer a PTM (please track me) header with legally binding semantics.
Tracking only pays if you can track a huge number of people and sell ads to a huge number of advertisers. The profit per tracked user is too small to pay for running a criminal enterprise.
Moving to a different jurisdiction is impossible as your customers (the advertisers) and the sites/apps where ads are placed would still be breaking the law.
True, most illicit ads tend to be non-targeted. But some criminals do things like blackmail, fraud, espionage, etc. using tracking data.
> Moving to a different jurisdiction is impossible as your customers (the advertisers) and the sites/apps where ads are placed would still be breaking the law.
That all depends on the specific business model, business partners, and their presence. Regardless, what I describe is not conjecture, many companies are shuffling around data to avoid GDPR rather than comply.
https://www.theguardian.com/technology/2018/apr/19/facebook-...
A different company without a physical presence or business partner in the jurisdiction in question, might have little to no incentive to follow the law.
In the end, even if companies are breaking the law, or even if they are fined, your data won't be protected unless they actually change their behavior as a result. Calculated non-compliance is a commonplace strategy for corporate legal compliance.
Like with tax compliance, this will always be an arms race. But if the law raises the bar, they will jump a little bit higher on average.
It doesn't have to be perfect. Privacy is not black or white, and trackers themselves are anything but perfect.
I recently looked at the list of what Google thinks I'm interested in. It's funny. Supposedly, I have a particularly strong interest in vehicles and buying cars. In fact I don't even have a driving licence, never owned a car, never will.
The list goes on and on like that. They must have rolled the dice to come up with things like "Flowers" and "American Football". I feel my privacy is completely safe with these geniuses :)
It's the more targeted uses of fingerprinting and data collection that are scary. If you're a person with lots of money or influence, there's already someone out there who is specifically trying to collect data about you in particular. Those people and organizations are looking at the data in much more detail than mass marketers.
There would be ways to get control over this, but law is slow.
0: https://www.gdpreu.org/the-regulation/key-concepts/legitimat...
Pushing all this through the legal system will take some time but the watchdogs in different countries are not sitting idle.
[1] https://fil.forbrukerradet.no/wp-content/uploads/2018/06/201...
If, and I say If, these gangsters ever get hit with major fines, and we get the simple yes/no option that a few pages have, then it will be better.
Right now, the ad industry (or should i say Mafia) is trying to actively circumvent this legislation
The problem with fines against Google (and Facebook, too) is that it's peanuts for them. They just factor this in the same category as "legal costs", and it never affects them even remotely.
Actually stamp down on the sites taking the piss. Without teeth, GDPR is useless, but so would any other toothless solution be.
Once one of the big players that don't do this and instead have it e.g. opt-out are actually fined, I suspect more sites will begin to behave correctly.
It's also one of the reasons why people have become so acutely aware of the problem. When the umpteenth site asks you to consent to over 200 ad providers/trackers, there's clearly something wrong.
Compare the request map for CNN from
- Dulles, VA: 511 requests https://requestmap.herokuapp.com/render/200123_JH_ed7b9b27df...
- Paris, France: 77 requests https://requestmap.herokuapp.com/render/200123_87_39fdca38ac...
I don't know if it's for sure because of the cookies/gdpr law, but there is a clear difference, and that's a big win in my opinion.
How can they connect one website's cookies to another's?
All I can think of is fingerprinting, but afaik you can't really be sure "who's that" since fingerprinting filters people out, and isn't good enough to target a single individual.
I guess they can improve it, but there are ways to work around it too, it will probably be easier to fix fingerprinting than blocking 3rd party cookies.
Its seems that if 1st party cookies were as good they would have switched to it by now.