Safari now blocks Google Analytics on sites, new Privacy Report feature shows
appleinsider.com
appleinsider.com
There does not appear to be a change between Safari 13.1 and Safari 14 for how it handles GA. I have tested it myself.
With Safari 13.1 Apple made a change [1] to their Intelligent Tracking Prevention that blocks all 3rd party cookies for cross site resources.
The only change in Safari 14 appears to be that it reports which domains have had cookies blocked. The Google Analytics beacon is still sent by the browser.
Benedict Evans (cited in article) since deleted his tweet, but this article seems not yet to have been updated.
[1] https://webkit.org/blog/10218/full-third-party-cookie-blocki...
Do you imply that Apple is putting up a misleading interface in the new version of Safari where GA appear blocked while it actually isn't?
That's a pretty bold assertion and the provided link is irrelevant on that.
Again only looking for more information maybe I didn't get your point at all because I'm not in the SEO field.
> The Google Analytics beacon is still sent by the browser
This is what I'd like some clarification about.
Wether policy changed or if it is just a UI change is another subject. Do they actually block GA or not? And if not does the UI mislead users to think otherwise?
If any tracking oriented company wanted to overcome this for nefarious reasons they wouldn't be able to do that without explicit help from the visited website who would then become legally liable. (For example by including in the beacon call a hash of personal identifier like IP or e-mail disrespecting RGPD and such).
Is that a good enough layman understanding of the stakes here?
Apple's ITP affects both 3rd party HTTP cookies and 1st party JS cookies. There does not appear to be anything but a UI change between Safari 13.1 and 14, from my initial analysis.
GA primarily utilises 1st party JS cookies. If you have GA on example.com then the cookie will be stored against example.com. On of these cookies stores a unique ID for you as a user.
GA will then send 'beacons' (GET requests to Google endpoint, with data passed in URL parameters) for pageviews and other events. Your unique ID is included in these URL parameters, which allows the various events from you to be joined up into a 'session'. That has not changed.
What ITP did previously (just over a year ago, I think) is limit the age of these cookies to auto delete after 7 days, meaning that if you leave a site for more than 7 days your new session won't be able to be joined up with your previous session. That is still the case.
If it is of interest I have a deck [1] that discusses this (link goes to the relevant section - skip to slide 71 if you just want to understand the ITP impact on GA).
I'll caveat this a bit - I've not done an in-depth analysis. The person I strongly recommend following for expert updates on this topic is (my friend) Simo Ahava [2] - he is an authority of GA and the impact of ITP.
[1] https://www.slideshare.net/TomAnthony/browser-changes-that-w...
https://support.google.com/analytics/answer/1011397?hl=en
"If all [data sharing] settings are OFF, your Analytics data is only used to provide and maintain the Analytics service."
Of all tech companies I'd feel most secure with Google being the stewards of my data.
Of course, they upped their game since then, but their sheer size will always make them an interesting target and they have to fail only once.
And that's only based on what we know currently from security incidents.
I don't share the same confidence for all my data that is floating around carelessly in some government spreadsheet somewhere, though.
Also a lot of websites, especially personal ones, are in violation of ePrivacy. You may not need GDPR consent for analytics, qualifying for a legitimate interest, but you still need a cookie banner when dropping cookies for analytics.
The market is clear about it, analytics have to be first party and privacy preserving.
If the system is designed well, in a lot of cases the users won't be receiving the resource from your server, they will be receiving it from a) their browser cache, b) their local network cache, c) their ISP's cache, or d) a CDN. Your server logs might be showing several thousand hits while the number of times a page is actually shown to somebody might be tens of thousands of hits.
Server logs are great for logging what is happening on your server, but awful for understanding your user base.
I wouldn't worry about a) too much, as you've already counted them, most sites are "one time use", and those that aren't usually have some interactive or time-sensitive feature that requires short (if any) ttl on any caches not under the site's control. d) is true, but also is somewhat under the site's control and should provide numbers.
Most people use GA for a rough picture of "how many people visit my site?", and stats from any CDN will most likely be enough for that. And browser caching doesn't really concern those people, because most visitors aren't returning visitors.
There is a high correlation between a usage pattern being interesting and likelihood of it making a representative appearance in the logs.
Understanding usage patterns shouldn't depend on knowing absolute numbers. Assuming "dumb" content is cached relatively uniformly, the usage patterns itself should be sufficiently inferable from the logs. For the non-dumb content, why would consumption of highly dynamic endpoints have distortive cache utilization at all?
To add more, how often high-resolution usage data really translates into actual product improvement? What percentage of sites have that much traffic to justify engineering hours spent on micro-growth-hacking based on this level of data?
You can setup some sort of pixel that's never cached and that transmits the page via query params, but then the implementation isn't reliable and a PITA.
If you have your own server, something like Matomo.org works better.
I love this feature in Safari. You open a new tab or browser window and there is a message area letting you know what is being blocked.
I am sick and tired of large tech companies like Facebook, Google, Amazon, etc. making money off of my data with scant benefit to me.
Not to pick on Facebook and Google, but I only use them now (well, almost) for paid services. I happily pay Facebook for Oculus Quest hardware and entertainment. I happily pay Google for music, books, movies, and Google Cloud Platform (which I personally like much better than AWS).
I believe that this would limit GA's ability to store data in cookies on my system (user or session-based attributes). GA could still create unique identifiers based on my user or session-based attributes and store those IDs on their own servers, then call them back up when I revisit the site.
I'm still coming up to speed on this, maybe someone with more experience could correct or clarify my statements.
Google Analytics stores a first-party cookie with a unique ID for each user. This is used to de-duplicate traffic from the same user to the same domain. This cookie not shared across websites. If you go to example.com and website.com, those are two different first-party cookies without views into each other.
Optionally, Google Analytics can be configured correlated this with a third-party cookie from google.com for advertising purposes. This allows the website owner for example.com to connect a user converting on example.com to that same user having seen or clicked an ad on google.com. It also allows the website owner to target ads on google.com towards users based on their activity on example.com
Previous iterations of Safari's ITP have outright blocked the third-party cookie, and have limited first-party cookies based on whether they're HTTP cookies or JavaScript cookies.
GA primarily utilises 1st party JS cookies. If you have GA on example.com then the cookie will be stored against example.com. One of these cookies stores a unique ID for you as a user.
GA will then send 'beacons' (GET requests to Google endpoint, with data passed in URL parameters) for pageviews and other events. Your unique ID is included in these URL parameters, which allows the various events from you to be joined up into a 'session'. That has not changed.
Apple's ITP affects both 3rd party HTTP cookies and 1st party JS cookies.
The main impact of ITP on GA is to limit the age of these cookies to auto delete after 7 days (usually), meaning that if you leave a site for more than 7 days your new session won't be able to be joined up with your previous session.
There is an edge case where ITP 3rd party cookie limits will directly block GA JS cookies, which is when it is running inside an iFrame (hat tip to Simo [1] for alerting me to this), in which case the JS code may not be able to set a cookie and will not fire a beacon.
[1]: https://twitter.com/TomAnthonySEO/status/1275524965077524482
[2]: https://twitter.com/SimoAhava/status/1275151672218705922
I like the fact that open source and managed analytics which is privacy-sensitive is becoming a thing.
When looking for a privacy-sensitive analytics service I stumbled on https://plausible.io/ which checked my boxes at the time. I imagine that there are more out there.
1) Which analytics can a website employ that is not geared toward enriching the analytics platform developer by violating site visitor privacy?
2) Do those analytics mechanisms have any kind of aftermarket, such that third-party developers integrate it into publishing platforms that publishers use.
3) What do those analytics mechanisms and the associated tooling cost?
Matomo: #1 Secure Open Web Analytics Platform https://matomo.org/
For publishing systems, couldn't wordpress report back analytics data to itself, on its own domain? Something like that existed but i'm not sure if it was using Jetpack servers or not. If this isn't already possible, it seems like an obvious thing for someone privacy concious to build.
You can turn off the cookies too, anonymize IPs (the default actually) and if you do that you don't even need GDPR consent or cookie banners.
I don't mind this but I hope they've partnered with Apple and not sold out.
https://www.theverge.com/2019/1/15/18183653/duckduckgo-apple...
I do have a iCloud email address, but on a desktop I have to leave the browser and open up an email client. I only open email clients while at work cause I have to.
Even Adobe is now in analytics business.
I think they do this to encourage people to turn off FF or other tracking protection. Instead they lost an enterprise license renewal as I was “encouraged” to look elsewhere.
With ad and taking blocking becoming more popular all the time, there will reach a tipping point where the data is unreliable enough that ROI can no longer be proved with it. It will be interesting to see what happens then in this space.
Alternative attribution models, more insidious fingerprinting?
Like for a small site I've made for fun. The only way I can easily know how many users visit is via Google analytics.
Well easily that is.
I get that people like statistics, but if you share it with a third party, it can safely be condemned.
By privacy I understand not sharing data with the public or with the oppressive regimes when it may lead to harassment, firing or arrests of people.
But using my data to sell me some watches or bike parts? I'm in.
I advertise on Facebook but I can't see anyone's searches or current location. Although I can target people who are interested in LGBT or people who have been to SFO recently. If they like my post, I can also see their name and photo.
That seems reasonable to me.
I've had to use safari on Mac. Sites are constantly trying to auto download dmg files (executables on mac) of malware. The most common ad is saying your mac is broken and needs to download an antivirus (that's fake and trying to get you to download a virus). Top google results for "download vlc" or equivalent search is pointing to fake websites distributing malware.
All of this is the result of ads, analytics and mac detection.
I've tried to setup ublock origin on safari but apple blocked safari extensions and doesn't allow to replace safari fully with another browser.
I am a small publisher, Safari users are demonetized , untracable, i might just say to them gtfo.
If you need to track your visitors without thinking about their privacy, perhaps your business model isn't great.