Maybe that opens up some opportunities as well, but that's not necessarily particularly appetising for businesses that aren't focussed around those areas of opportunity.
Maybe that opens up some opportunities as well, but that's not necessarily particularly appetising for businesses that aren't focussed around those areas of opportunity.
At the extreme, imagine if every person has a unique identifier that was automatically sent whenever they used any device: preventing ad fraud would be really easy, and you would have essentially zero privacy. At the other extreme, imagine if every device looked exactly the same, with no user agent, no IP, no cookies, no way to tell my traffic from yours. In that situation, people would have pretty strong privacy, but if you had headless browsers loading the ads on your site no one would be able to tell that those views were not from real users.
As the GGP says, removing IDFA shifts the balance toward both privacy and fraud. See https://blog.cloudflare.com/cloudflare-supports-privacy-pass... and https://web.dev/trust-tokens/ for attempts to separate these.
(Disclosure: I work on ads at Google, speaking only for myself.)
To me, if your system relies on being able to tell most internet users apart, that sounds extremely close to processing personally identifiable information.
This seems like a problem with the current model of ads being paid for by impression/click, and switching to a model where ads are being paid for the time they're being displayed (pay X to have your ad appear here for Y time) the problem goes away.
Furthermore, the current advertiisng model also suffers from this problem even beyond malicious intent. Is it fraud if a real user "looks" at the ad but actually looks away from their screen? If they mute the sound? If they don't speak the language the ad is in? Etc.
I don't think it does. How does the advertiser know what the spot on the site is worth without traffic estimates? See my response to chongli downthread: https://news.ycombinator.com/item?id=25431138
> Is it fraud if a real user "looks" at the ad but actually looks away from their screen? If they mute the sound? If they don't speak the language the ad is in?
None of these are fraud, because the ad is in front of a real user.
Fraud here doesn't mean "the ad doesn't perform as well as the advertiser hoped for some reason" it means "the ad was not actually shown to real users on the site, contrary to the agreement between the publisher and the advertiser".
Someone once told me how they got a bunch of cheap/used phones and just left them all running an app that shows ads. They'd glance at the phones now and then to see if they needed to "interact" with them to keep the ads rolling.
There is literally nothing in the world I care about less than this.
Advertisers pay publishers to show their ads to real users. Publishers run their sites because they receive money from advertisers. We visit the sites because they're diverting/informative/useful/etc. If the advertisers can't tell whether their ads are instead shown to robots, the whole thing falls apart.
I like the trust tokens proposal as a way to exclude bot traffic without tracking: https://web.dev/trust-tokens/
What users actually care about protecting your propaganda based business model though? Sounds like it's pretty much your problem and you want to reduce privacy to make manipulating their behavior a bit more profitable.
So, Apple’s decision is looking even better to me now.
Removing of IDFA should close the gap between big players like Google, Facebook etc vs others.
Then how would third parties with no access to first party data compete when there's no more third party data would be something I'm curious for you to explain.
I think after removal of IDFA, smaller ad networks will steal some of big players mobile market share. And mobile advertising will not move to search based advertisement as much as you think. Maybe some revenue will shift there, but I think lose on mobile side will be bigger.
Google’s ability to protect its core revenue stream is squarely in the “not impacted” category when it comes to Apple's IDFA move.
2. The IDFA is just a simple static UUID. It cannot do a very good job at preventing fraud. There is no way to validate anything about it or affirm that it ties to a genuine device.
2: On a single request, yes. But users typically make very large numbers of requests over time. The pattern of requests that you'd see from a real user looks pretty different than what you'd see from a bot.
Of course they look different over time, isn't the problem here that same data can be used to do statistical analysis for other purposes than fraud prevention?
But yes, of course IDFA can be used for things other than ad fraud detection.
Honest question, I am not trying to be obtuse, but in this context can you more specifically define fraud? Is it just "ad fraud" as defined here: https://www.clickcease.com/blog/what-is-ad-fraud/
I get why businesses should care about ad fraud, but why should I, as a consumer care about it? Frankly I don't even want to know about my traffic, let alone yours.
As for why you should care about it, see my response to thesuitonym below: https://news.ycombinator.com/item?id=25431866
Advertiser fraud is hardly the only type of fraud. It happens with services you directly pay for like ridesharing and food delivery as well. The cost of fraud becomes another cost for a service provider and prices for all users need to be raised to offset losses from fraud.
For smaller businesses without the brain power to combat fraud, their margins will be greatly hurt by fraud, making it harder to compete.
I'm in favor of what Apple is doing myself, but it's definitely a legitimate unintended consequence of this measure.
What would be useful is if Apple became the gatekeeper for tracking fraud and companies could report ephemeral identifiers for fraud that only Apple can de-anonymize and then Apple provides fraud scores for ephemeral identifiers on account signup.