Disclaimer: I am the jaded creator of Twicsy, a Twitter picture engine with many millions of visitors over its lifetime, and I apparently missed the boat on this trends and had to shut it down.
Disclaimer: I am the jaded creator of Twicsy, a Twitter picture engine with many millions of visitors over its lifetime, and I apparently missed the boat on this trends and had to shut it down.
Think of Giphy images as a giant, organically shared version of web tracking software. Which complements the coverage of the FB Pixel[2] well, as it worms its way into privacy-conscious areas they might not have FB Pixel coverage such as private communications and security/privacy-minded apps. And without implementing something like a proxy server to pre-cache/sanitize images and strip tracking identifiers in both directions, it's a tracking vector that's hard to keep out of your app without introducing user friction.
Given that cynical viewpoint, the valuation makes a ton of sense.
[1] https://support.giphy.com/hc/en-us/articles/360032872931-GIP...
[2] https://www.facebook.com/business/help/742478679120153?id=12...
It really is getting to the point that if you want privacy, don't touch anything owned by the top 5 tech companies. Better yet, only use Open Source. I never used to be a OSS only person, but the past few months I've started to go that way.
Signal's integration is specifically engineered to _not_ do this: https://signal.org/blog/signal-and-giphy-update/
Also the Signal service could do a transparent TLS MitM between the app and Giphy instead of a passthrough TLS tunnel and the user apps would be unaware. In fact from that page I'm not sure they're even doing a tunnel anyway.
I wouldn't even call that cynical. It's just the state of things.
It's waaaaay more efficient nowadays and way more creepy, but it's not a new invention.
It's behavior is no different from Windows 10 telemetry. The keyboard does not even work if you disable one of the underlying telemetry services in the app (if you have a rooted device).
edit: apparently wrong/outdated information.
For Discord, while they initially used Giphy and has a /giphy command, it now uses Tenor too in the GIF picker.
There's also all kinds of shenanigans that they can play in the process of serving that request to harvest other meta data and help fingerprint you. Which Giphy's privacy policy mentions is already done to an extent, in the form of dropping cookies while servicing your request. Cookie abuse itself is a bit of a losing battle, as browser vendors increasingly layer on limitations and restrictions for cookies. But they're far from the only method of fingerprinting possible during the servicing of a web request.
Developing such a tool might be valuable for privacy-conscious application developers.
[1] Can't find a page specifically detailing it, but [2] gives a basic synopsis on it in the context of allowing GSuite admins to whitelist internal domains from routing through the proxy.
Not if the app developer proxies the encrypted traffic.
That way the app dev does not know the content and the third party does not know which original IP requested it.
This is akin to the Signal-Giphy implementation.
Paraphrasing: emojis serving as web bugs.
Acquisitions often happen after some value is lost from the company being acquired, like when Microsoft bought Nokia or when Yahoo bought Tumblr.
[1] https://docs.adobe.com/content/help/en/analytics/technotes/v...
However, that doesn't stop carriers from inserting something at the start of the stream that the client doesn't see. It would need to be coordinated with the origin server, but that's already true for HTTP header insertion. Sending a pre-handshake blob to a TLS server that isn't expecting such a blob would fail hard though, rather than going on its merry way like an extra header usually would.
But you still see nondescript references to the capability in places like that that up-to-date Adobe Analytics doc, and the carriers aren't trying to use legal means (a la lobbying) to slow down the uptick in HTTPS traffic and preserve their revenue stream. Which leads me to presume they've developed technical solutions that are compatible with HTTPS traffic. They can't really use the spray-and-pay method[2] they were using. But all bets are off when they destination site and the carriers are coordinating with each other, as that coordination can involve technical modifications to facilitate it in addition to just the whitelisting itself.
[1] https://www.ghacks.net/2015/08/31/are-mobile-carrier-injecte...
[2] Some carriers would inject a header into all traffic, and any interested party could slurp them up. But you'd have to pay the carrier to access any of the other information the carrier had for that particular identifier.
Theres been this fake (steal) it till you make it, wild west approach to growth. Youtube, Buzzfeed, Imgur. You just host anybodys content regardless of if the poster is the owner, and once you get to scale, then you handle copyright and creating your own content so you arent as dependent on external creators.
But in Giphys case, they never have to take the extra step. Because they are so short, they are much more likely to pass fair use, and they can just host anybodys anything, barring some illegal fringes, without having to pay for the rights.
Incredible. What a strange time we live in.
This makes me wonder, does Disney have any say if someone uploads a home-made Mickey gif that is controversial or otherwise damaging to their brand?
I don't think this is quite fair to YouTube. They've spent hundreds of millions of dollars developing ContentID. It's not perfect, but it's without a doubt the most sophisticated system to date. It's a difficult problem, but I don't see how you can say they've "thrown up their hands".
You can say what you like, but that's genius level politics-business IMO.
Am I responsible when stolen goods are sold from my stalls?
I own and operate an RV park. Someone is selling illegal drugs from one of the RVs.
Am I responsible for the illegal drug sales?
You might not be liable for the sale itself but, depending on the details, you could definitely still have serious legal risk.
https://www.nolo.com/legal-encyclopedia/criminal-acts-activi...
fair use is an affirmative defense, where you say "yes i stole it, but the government should not protect the content owner from me," similar to "yes i injured them, but it was self defense and they do not deserve compensation."
[1]intellectual property violations are not theft in the strictest sense of the word, they don't remove the original. stealing in this context is colloquial.
Without intellectual property law, you would be free to copy anything. The barrier to copying is the government. The free pass to flaunt their rule, when qualified, is also the government.