Oracle’s BlueKai tracks people across the web – that data spilled online
techcrunch.com
techcrunch.com
It can be a bit annoying due to eg Recaptcha, but it works fine 99% of the time. Some sites will break, but these are far and few between. I just use another browser for those.
It was upstreamed from TOR and will scope all data (cookies, caches, etc) per domain. It's not a panacea, but definitely a good step.
(about:config , privacy.firstparty.isolate)
I feel like something like this should be the (standardized) behaviour of browsers. Sharing any kind of observable state between domains should require an explicit opt-in with a prompt.
Like: "Privacy Warning: techcrunch.com wants to share your data with facebook.com. Do you want to allow this?"
(such fine grained permissions are a complicated topic of course, but that's a longer discussion...)
Previously it only enabled third-party cookies for domains you had explicitly visited. https://www.theverge.com/2017/9/14/16308138/apple-safari-11-...
"When third-party cookies are allowed, 101 domains can reconstruct over 50% of a user's history and 161 could recover over 40%. Even when these cookies are blocked, 44 domains could recover over 40% of a user's history."[1]
[1] Study back in 2014: https://securehomes.esat.kuleuven.be/~gacar/persistent/the_w...
Add to that web beacons, ads, like buttons, browser fingerprinting via HTTP header, javascript, canvas, plug-ins, add-ons or hardware, keystroke biometrics and gestures on smartphones. Of course, there are also several techniques for e-mail tracking as well as tracking of documents (word, .pdfs etc).
For more details, here is the Firefox bug report:
https://bugzilla.mozilla.org/show_bug.cgi?id=1549587
To enable Dynamic First Party Isolation: in Firefox Nightly's about:preferences#privacy, select "Custom" Enhanced Tracking Protection and "Cookies" = "Cross-site and social media trackers, and isolate remaining cookies". Or just set `network.cookie.cookieBehavior` pref = 5 in about:config.
If you are curious what data is housed in bluekai, here is a 170 page pdf with lists and descriptions of different data providers/vendors: http://www.oracle.com/us/solutions/cloud/data-directory-2810...
When I checked with the disclosure page (give me everything you have on me), after disabling ublock origin for that page, it said they had nothing on me. The truth of that statement is debatable, but it seems to be effective.
Its difficult to actually opt out in full, but we will definitely get to that point in the future. Also if you use niche hardware/software (like netscape on an old linux distro) you're data will just get cleansed out. Nobody does fingerprinting unless you're a spy or in charge of purchasing for a hospital or something, so I wouldn't worry about that.
I'm not sure how long you've been out, but this has changed a lot recently. Many adtech companies (not us) have responded to ITP by building out fingerprinting to continue personalization.
(Disclosure: I work on ads at Google)
I don't know how it was turned off though. Likely ip.
Are you saying that regulation is effective? :)
We're quite literally on a thread involving a product that collected tonnes of sensitive user data without a clear opt-out mechanism while failing to be an effective custodian, after all.
"One record detailed how a German man, whose name we’re withholding, used a prepaid debit card to place a €10 bet on an esports betting site on April 19. The record also contained the man’s address, phone number and email address."
Oracle's data transfer/storage costs are meaningless since this business unit in oracle just exists to establish market share - they're not trying to make money yet. Other company's data costs are what cause oracle to store/deliver less.
But the inherent assumption is that the data is only used for benign ad targeting and ignores the possibility that the data will end up in the wrong hands like it has here. The response seems to be "{{ad tech company}} has some of the best developers in the world and they want to protect that data!". Except leaks like this are inevitable. So long as tracking is a thing, data will leak, and hostile actors will abuse it.
It doesn't even have to leak. HR departments and shady government agencies could just buy it (or legally seize it). PR firms could dig through protester history and smear them so very easily.
I then ask them, "Is it working? Do you really see advertisements online that mostly show you things that are meaningful to you? Are online ads more relevant to you than what you see on TV or hear on the radio?"
The honest always answer "No."
Overall, I don't see it as being remotely worth the trade-off.
The honest answer is a lot, and none.
When I watch Redbull TV I see zero hearing aid adverts. That's about the only commercial TV I watch. Likewise when I more frequently watched commercial TV 15 years ago, I didn't see a ton. In the years since, the demographics of network TV viewership have shifted massively and the over 65 crowd is massively over-represented. As demographics switched advertising switched.
I suppose when I occasionally go to CNN or CNBC for news, I see hearing aid advertising, but the sites I generally frequent (should) know their readership better than blast us with that sort of advertising.
Which is ultimately the point context based advertising delivers 90% of the benefits of target/ tracking based advertising without the performance degradation, risks, and other nonsense.
There are a lot of caveats like this where price and business reasons play a role. If it weren't a $20B industry then your logic would probably ring more true.
What you are missing here is by giving people the ability to advertise to New York Times users offsite takes income from the Times. If you read the NYT or you are the New York Time, this should be concerning. As a reader, you want the the value of their brand to flow back to them so they can continue doing better work.
Advertising hasn’t been enough since the late 2000s. More monetization options arised and were rapidly adopted because news venues were hungry for them, when they figured that reservation (buying ads on a specific website with no control on delivery and performance) was declining. The creepiness of all this, and the sense of entitlement of a large part of the audience, fueled the rise of Adblock, which required even more creepiness and gave birth to the present cat&mouse game.
My point wasn't that you shouldn't subscribe to the content you want—you should. It was that I have zero interest in sacrificing anything to lower advertising costs for some random company. Nor do I care to increase Google/ Facebook's earnings potential because they spy on me.
The campaign to normalize thinking of onesself as a consumer is so good, I often hear my fellow citizens replace the noun "people" with the noun "consumers".
that's a script.
View-source
Ctrl-f "pixel"
:-)
This seems really odd to include, given Techcrunch's use of pixels, and whatever their own covert pixel tactics may be...invisible pixel images are part and parcel when you start talking about pixels in general. (Edit: The author seems to have addressed this)
Also, is that _Kai_ as in the Japanese word for ocean? Or is it _Kai_ as in meeting?
Perhaps the entire word is a Japanese derivative, with buruukai meant to connote a gathering of nervous, fearful Oracle executives? Not the most auspicious reading...
https://www.blueoceanstrategy.com/what-is-blue-ocean-strateg...
So because TechCrunch does something bad, that makes Oracle doing the same thing not bad?
Yes, it's hypocrisy at the macro level. But it's not an excuse for either party.
Not sure how that changes the effect of the article. One would think the content of the article is what matters.
Perhaps this is just another example of shooting the messenger.
3rd party cookie impressions can be sent to a company like LiveRamp to identify what websites users have visited (in theory only in buckets, but that's trivial to bypass). With the exception of the very largest websites, you could see traffic to many, many websites and tie it back to an individual user (even if their IP changed, etc.).
Companies like FullContact and People Data Labs offer the ability to take the few pieces of information you have a user and get their other info (eg; verify email using name and address, or get social media profiles, etc.).
The problem is no matter how good you are about using VPNs, clearing cookies, etc. the weak link are the websites you're forced to give some info to. Many of them will well you out even if their TOS say otherwise.
CogoLabs?
Can you prove that?
(0[1-9]|1[0-2])/(0[1-9]|1d|2d|3[01])/(19|20)\d{2}
If the day you were born is between 10-29 it will not validate as a proper day.Almost all of the respondents indicate that they would choose the "free" version. I was surprised that the feedback was this one-sided, especially after making the tradeoff salient (and especially for a browser plugin that sees every page you visit). Apparently most people just don't care about their privacy.
Also, it's not $2 but $50, for users wary of automatically extending monthly subscriptions.
Maybe you said your free version would use targeted ads - which I'm fine with personally.
It's selling data or being dishonest about how the data is used that I have a problem with, so maybe the problem is that your users trust you so they are comfortable with you having and using their data.
We can take this one step further with the proposed TURTLEDOV browser API (https://github.com/michaelkleber/turtledove), at which point the ad network doesn't learn your interests and Fiat only learns you were interested in buying a car if you click on an ad.
Or with the proposed FLoC browser API (https://github.com/jkarlin/floc) where your browser uses on-device clustering to present an interest category instead of the ad network learning interests server-side.
(Disclosure: I work on ads at Google, and am friends with the folks behind these proposals)
This can be brutal for applications like credit worthiness, but I'm still worried about mistakes in data used for more mundane decisions like who to offer a discount to or which passenger to bump to business class.
Everyone using this data knows it contains inaccuracies, but it is much much better than not having any data at all.
These two things, 3rd party and 1st party data, are very different. Stored differently, different user access, different rules, etc. If Oracle accidentally made all their client's 1st party data public they'd get sued out of existence.
The real issue is the poor security practices of this company, especially under Oracle's watch, and how much data is shared by partners. BlueKai can't get personal details unless someone shares it with them.
Historically speaking, I don't know any entity that has been sued out of existence for these kinds of things. Usually after the media cycle everything is back to normal.
> Tech giant Oracle is one of a few companies in Silicon Valley that has near-perfected the art of tracking people across the internet. The company has spent a decade and billions of dollars buying startups to build its very own panopticon of users’ web browsing data.
Doesn't that exactly describe a big conspiracy?