First Ad Fraud != Fraud. It is low grade hacking.
Second. Trading the privacy of every iPhone user so that advertisers can prop up a sketchy/ poor industry is a terrible trade.
As someone alt-tabbing in from real fraud investigation work, no, it doesn't. Banning burner phones and reducing banking privacy regulations would move the needle there, but those aren't even on the radar.
"Someone's script opened a page" isn't fraud. Someone built a script specifically to spam click a competitor's ads, by contrast, is.
Getting around a ban is not Fraud.
Regardless, a cross app ad identifier is not needed to prevent this. There are ways within your app to save data per iOS user (this is not cross app data, it's specific to your app) which would allow you to prevent this. You could use sign in with Apple/ Google/ Facebook. You could require emails. etc etc.
Apple already has a privacy-preserving solution for that:
EDIT: I believe Apple's DeviceCheck API is what the parent refers to. Thank you!
Not his solution, but just grab the identifierForVendor off UIDevice and ban that.
Alternatively:
> "Using DeviceCheck API’s, in combination with a server-to-server APIs, developer can set and query two bits of data per device. It will also maintain the user privacy, by not disclosing any user or device information, which is the priority point for every Apple user and most point of concern of every mobile user."
https://codeburst.io/unique-identifier-for-the-ios-devices-5...
So if you want to exclude/ban a user, you can use the IMEI+account, but outside of excluding a user from using your service, you cannot access IMEI+account.
User privacy is preserved because there's no singular ID for advertisers, and services can still ban fraud because if it's present they can use the IMEI+account to ban a user.
Maybe even have that built into the OS? The app can ban someone based on an IMEI+account, but the IMEI+account info stays on the device. The device just certifies that the combination is unique without exposing that info to the app, and the app can still ban that hardware/account, so the user would need to buy new hardware to get around the ban.
https://nshipster.com/uuid-udid-unique-identifier/
The easiest is with the identifierForVendor property of [UIDevice] which identifies that specific device for your software, but is not shared with other vendors. So you can ban Bob's iPhone across all your apps, but that ID isn't useful to other vendors.
Maybe that opens up some opportunities as well, but that's not necessarily particularly appetising for businesses that aren't focussed around those areas of opportunity.
At the extreme, imagine if every person has a unique identifier that was automatically sent whenever they used any device: preventing ad fraud would be really easy, and you would have essentially zero privacy. At the other extreme, imagine if every device looked exactly the same, with no user agent, no IP, no cookies, no way to tell my traffic from yours. In that situation, people would have pretty strong privacy, but if you had headless browsers loading the ads on your site no one would be able to tell that those views were not from real users.
As the GGP says, removing IDFA shifts the balance toward both privacy and fraud. See https://blog.cloudflare.com/cloudflare-supports-privacy-pass... and https://web.dev/trust-tokens/ for attempts to separate these.
(Disclosure: I work on ads at Google, speaking only for myself.)
So, Apple’s decision is looking even better to me now.
Removing of IDFA should close the gap between big players like Google, Facebook etc vs others.
Then how would third parties with no access to first party data compete when there's no more third party data would be something I'm curious for you to explain.
I think after removal of IDFA, smaller ad networks will steal some of big players mobile market share. And mobile advertising will not move to search based advertisement as much as you think. Maybe some revenue will shift there, but I think lose on mobile side will be bigger.
Google’s ability to protect its core revenue stream is squarely in the “not impacted” category when it comes to Apple's IDFA move.
There is literally nothing in the world I care about less than this.
Advertisers pay publishers to show their ads to real users. Publishers run their sites because they receive money from advertisers. We visit the sites because they're diverting/informative/useful/etc. If the advertisers can't tell whether their ads are instead shown to robots, the whole thing falls apart.
I like the trust tokens proposal as a way to exclude bot traffic without tracking: https://web.dev/trust-tokens/
This seems like a problem with the current model of ads being paid for by impression/click, and switching to a model where ads are being paid for the time they're being displayed (pay X to have your ad appear here for Y time) the problem goes away.
Furthermore, the current advertiisng model also suffers from this problem even beyond malicious intent. Is it fraud if a real user "looks" at the ad but actually looks away from their screen? If they mute the sound? If they don't speak the language the ad is in? Etc.
I don't think it does. How does the advertiser know what the spot on the site is worth without traffic estimates? See my response to chongli downthread: https://news.ycombinator.com/item?id=25431138
> Is it fraud if a real user "looks" at the ad but actually looks away from their screen? If they mute the sound? If they don't speak the language the ad is in?
None of these are fraud, because the ad is in front of a real user.
Fraud here doesn't mean "the ad doesn't perform as well as the advertiser hoped for some reason" it means "the ad was not actually shown to real users on the site, contrary to the agreement between the publisher and the advertiser".
Someone once told me how they got a bunch of cheap/used phones and just left them all running an app that shows ads. They'd glance at the phones now and then to see if they needed to "interact" with them to keep the ads rolling.
To me, if your system relies on being able to tell most internet users apart, that sounds extremely close to processing personally identifiable information.
What users actually care about protecting your propaganda based business model though? Sounds like it's pretty much your problem and you want to reduce privacy to make manipulating their behavior a bit more profitable.
Honest question, I am not trying to be obtuse, but in this context can you more specifically define fraud? Is it just "ad fraud" as defined here: https://www.clickcease.com/blog/what-is-ad-fraud/
I get why businesses should care about ad fraud, but why should I, as a consumer care about it? Frankly I don't even want to know about my traffic, let alone yours.
As for why you should care about it, see my response to thesuitonym below: https://news.ycombinator.com/item?id=25431866
2. The IDFA is just a simple static UUID. It cannot do a very good job at preventing fraud. There is no way to validate anything about it or affirm that it ties to a genuine device.
2: On a single request, yes. But users typically make very large numbers of requests over time. The pattern of requests that you'd see from a real user looks pretty different than what you'd see from a bot.
Of course they look different over time, isn't the problem here that same data can be used to do statistical analysis for other purposes than fraud prevention?
But yes, of course IDFA can be used for things other than ad fraud detection.
Advertiser fraud is hardly the only type of fraud. It happens with services you directly pay for like ridesharing and food delivery as well. The cost of fraud becomes another cost for a service provider and prices for all users need to be raised to offset losses from fraud.
For smaller businesses without the brain power to combat fraud, their margins will be greatly hurt by fraud, making it harder to compete.
I'm in favor of what Apple is doing myself, but it's definitely a legitimate unintended consequence of this measure.
What would be useful is if Apple became the gatekeeper for tracking fraud and companies could report ephemeral identifiers for fraud that only Apple can de-anonymize and then Apple provides fraud scores for ephemeral identifiers on account signup.
Do you think iPhone users care that Apple is implementing anti-tracking?
It's becoming a real concern for normal people - they don't understand what it is or how it works but they really don't like it.
I was in shock when I saw it on Instagram on my brand new iPhone (switched from Android) which has all mic permissions off by default. So some 'smart' device in their home must of heard us. Some advertiser somewhere must have my voice profile hooked up to my Instagram account by now and they somehow share it in an "unidentified" way.
Edit: We need further research into these 'impossible' ads to see if devices from different software OS' and companies are listening and grabbing detail and showing ads based on what are supposed to be 100% private conversations.
You might have not googled it yourself, but I bet the person you had that conversation with did. If the conversation took place in real life, then that person's device was in physical proximity to yours (i.e., location data tracking; for example, if you enter a room full of people who googled tons of stuff about a certain subject, expect to see ads around that subject popping up on your device in the near future, even if you didn't google anything about that subject before and aren't planning to do so in the future). You also probably exchanged contacts and called (or texted) each other about other stuff in general (probable, but not necessary for the scenario I am describing). And if the conversation took place online, then it is even easier. Here you go, you just created a social link between yourself and the person who googled stuff about aircraft hangar gravel. In which case, it isn't surprising at all that you got that ad.
So in a sense, you are correct, it wasn't a coincidence. But I heavily doubt it has anything to do with smart devices listening and analyzing to what you said at all. It is much more trivial and less creepy to simply utilize your social links to figure out what kind of ads to display to you than listen in and try to analyze your conversations. More reliable too.
Facebook literally knows who your friends are. If your friend is interested in something there’s a good chance you are too.
Maybe not all of us, but for me it's an important and differentiating feature.
What we don't really care about is hypothetical thinking about wether we care from people that apparently don't care.
I don't think they know each setting that is available, but they without doubt have the impression that "Apple is better with privacy"
A stable identifier makes identifying this sort of behavior much easier.
(Disclosure: I work on ads at Google, speaking only for myself)
When you use a service that is funded by advertising, the service only gets that funding because the advertisers trust that they are getting their ads in front of real users. Some advertisers are able to precisely measure the quality of their traffic, for example by seeing whether the traffic they get buys things, but most are in businesses where that's not possible (no one clicks on an ad for Coca-Cola and then places an order for Coke). Ad fraud means that advertisers are less willing to pay to be shown on the service, so the service's funding decreases.
Very likely, less funding for the service hurts you as a consumer: they are probably spending their funding in support of the site. For example, I believe that the ads here fund the moderators.
> why should you be allowed to spy on me - who never defrauded any advertisers - to fix your problem?
See my response to wil421: https://news.ycombinator.com/item?id=25430453 I think that fix here is some thing like https://blog.cloudflare.com/cloudflare-supports-privacy-pass... or https://web.dev/trust-tokens/ that allows detecting and preventing fraud in a privacy preserving manner.
But you cannot make this my problem by saying "let me spy on you. or your shit gets more expensive, or sites have to close". That sounds too much like "an offer you cannot refuse". I will not surrender my privacy for failed business models.
The same couldn't work with the internet because essentially every ID would be known to potential bad actors, as they'd be tracking every single one of them (among other data points) and can easily defeat the rotation of those IDs based on other data points which don't change.
Define "hurt".
I'd rather make a decision to pay $5/month for a service than to be the product and get spied on
This cannot be an afterthought—it must be the central question all advertising skeptics must start with.
That might be legal for the moment but it is in no way moral.
Democracies are bought on advertising.
Hiding the price of the user's attention is not a positive side effect to the user. Hiding who buys the user's attention is not a positive side effect to the user. Hiding how many other people's attentions are also being sold is not a positive side effect to the user. All of these are detriments to the user.
How, exactly? It's entirely opaque to the user.
At a minimum, you should offer a free, ad-supported version alongside a paid, ad-free (and tracking free) experience.
But what is a fair price? That depends on the traffic, but we are positing that detection of "is this a real user" is not possible, right?
Traditionally, advertisers have gone by Nielsen style ratings for broadcast media (pay people to track what they consume, extrapolate) and circulation numbers for print media. In our hypothetical world the former would still be possible but the latter wouldn't. Unfortunately, in addition to being really inefficient, if you pay people to track what they consume you will essentially never compensate niche publications. This strongly promotes centralization.
Privacy Pass / Trust Tokens / etc seem much more promising to me?
Couldn't the price just be based on the actual payoff the advertiser gets (aka increased product sales)? The publisher is incentivized to set the maximum price that the advertiser will pay, and the advertiser is incentivized to get the most bang for their buck, so at the very least they would never pay more than what the ad brings them in terms of revenue.
Over time, this should reach an equilibrium. Niche publications may have to charge low prices at the start as they build their reputation among advertisers, but I think that's a worthwhile price to pay if it means better privacy and eliminating a problematic advertising model of CPM/CPC (where fraud is possible and tracking is required to battle it).
Getting the initial price is going to be hard, but over time, rates will start to become known.
Ok I agree that ad fraud is hurting publishers, as a secondary effect hurting consumers but the damage consumer getting in this current system is much much bigger. This is like saying you continue taking 5x damage, cause 1x damage to your publisher will effect you negative.
Ad spend as a percentage of GDP has been surprisingly constant for the past century. IOW, companies do not spend more on ads just because they can better target their potential customers, nor will they spend less if they lose that ability.
A lot of content, especially newspaper/magazine articles, at least here in Germany, already are paid-only, either through subscriptions or both subscriptions and alternatively microtransactions (mostly more in-depth reporting). The UK Guardian and the German taz employ voluntary payments/subscriptions with some success last I heard. US media seems to be pushing a lot more for subscriptions now ("you got free 3 articles this month")
Creators on patreon and on OnlyFans (NSFW) seem to be making good money off of subscriptions, on a smaller scale (and if they sell a product that has some demand, of course).
Relatedly the greater independence of creators from advertising would in turn mean fewer ads, which in turn means potentially more competition for the available ad space again and thus potentially higher prices.
If someone in state/country X buys something from a site in state/country Y, both X and Y may levy taxes on that transaction.
Many have thresholds for small businesses, where you don't have to collect taxes if your total business volume is below some threshold. For US states, the threshold is often of the form "more than $T total sales OR more than N sales".
With microtransactions, it is easy to exceed N sales even though you are not actually collecting much money, and then the costs of preparing and filing your quarterly sales tax reports can exceed your revenue.
Advertiser supported sites don't suffer from this problem. If someone in X visits a site in Y and Y gets payed by an advertiser for showing an ad to that person, the site does not have to worry about taxes in X, and in Y the ad revenue will just be income that gets dealt with on their income taxes.
Until we can get microtransaction-friendly cross jurisdiction sales tax reform microtransactions are going to have limited viability, at least for sites that want to operate legally.
Most content I consume is, like your comment, already shared by users without them receiving any compensation for it. It is usually someone who is not the content creator that profits from content on the internet.
Personally, I use ads as a signal to avoid buying certain products. If the ads are too prominent and omnipresent, it's an indication for me that I would be paying quite a premium on their marketing. But that's just me.
Your channel efficiency unavoidably goes down, which increases your cost of customer acquisition because your other channels cannot pick up all of the slack.
Increasing the cost of customer acquisition is going to be bad for your business. You will either need to reduce costs (by hiring less, for example), or increase your prices.
I think people are misconstruing me here. I'm not saying Google advertising is somehow fundamentally necessary to the economy. I'm just saying that it is straight up incorrect to think that there aren't legitimate downsides to removing their ability to police fraud.
But there are also (potentially huge and beneficial) opportunity costs. We will never see alternative business models which are not viable in the existing ecosystem.
The tracking part isn't necessary for fraud detection not even for conversation tracking. It's only necessary for "personalized ads" aka spying on users.
Living in an advertising-saturated and/or privacy-deprived world is also a "cost" borne by members of society.
Because economics. I know this intimately. I have a product we manufacture and sell on Amazon along with other channels. And if I am saving $1 on a customer acquisition, I am lowering my price one dollar because that would mean I can sell more at the same profit. Because if I try to keep that extra dollar, my competition will lower their price. Basically the cost of keeping that saved dollar is more than the gain from lowering the price a dollar. That’s how competition is supposed to work.
I know my cost of goods sold and my cost of sales down to the penny and have a pretty good idea of the elasticity curve for my product: if I lower my price by $1, I would sell x more bottles. However if I lower my price by $1 right now, I would decrease in profitability unless my costs also decreased by $1. There is a point on the curve that represents the optimal price.
It would seem that fundamental microeconomics is something not taught in many schools and that’s tragic because you get statements like “who’s to say this decreased expense is going to be passed down to consumers.” Because competition is what makes this statement silly in principle.
I don't really think that the students are the ones being "helped" when google gets paid $90 a click on student loan refinancing queries. They end up paying that $$ in the end.
Ad fraud really isn't my problem. So why should I be mercilessly tracked by everyone just to make your job easier?
So why are they deploying the term? Because it's a great way to deflect thinking about a core failing of their business logic. We've known since the day of banner ads that 'views' are a tremendously flawed metric, so blaming online agents for WHY they're flawed lets them deflect blame.
The fact that we're in this thread trying to parse semantics when consumers don't even have a seat at the table when deciding where we should fall on the tracking/privacy spectrum should tell you all you need to know about how the industry operates.
As someone who doesn't use an iphone it's really frustrating that online services are starting to expect one for this reason when it hasn't been necessary in the past.
I also wouldn't be surprised if there was a burden of "good faith effort" required to show that you've taken measures to prevent frauds.
They’re not supposed to do that. Their dogmatic refusal to see the writing on the wall is ridiculous.
Apple's privacy changes might seem like a good idea from the outside, but essentially or paradoxically leads to higher entry barriers for new competitors and cement the role the actual players have.
However, we do not have experience with so-called "big tech." It is relatively new, iPhone came to light in 2007. So I regard Apple's measurements as another experiment, and we will see how things further evolve.
Honestly, who cares if the barrier of entry for a shitty business model is raised. And can see only upside to this.
Also: boohoo
(I like where your head is at, fraud is just hard)
Those are not exempt from the GDPR either. Granted, at the moment there’s very little enforcement around these (especially IP addresses despite their huge tracking potential) but once enforcement is stepped up there shouldn’t be any difference whether it’s a FAANG or a small company doing it).