Google Analytics Opt Out
tools.google.com
tools.google.com
I haven't been able to block Youtube ads on my tv for example.
On Android now Proxies don't apply anymore to apps like YouTube, and as these apps also use DoH, there's no way to block ads anymore.
All talk of "security" and "privacy" is false, as always it was all about profit. I honestly wonder if the people at Google working on DoH even knew why management supported their project, or if they genuinely believed they did something good while management secretly realised the potential profits from DoH
The scenario you're describing (DNS-level blocks) could always be circumvented.
On the other hand, if you live in the US and don't override the ISP's name servers, most probably they will spy on you and sometimes even do things like injecting ads into third party websites. This was the thing DoH was meant to solve.
The Chromecast has 8.8.8.8 hardcoded, but recently an ISP started integrating ad-blocking via DNS filtering (with 8.8.8.8 MitM) in their ISP routers. That case actually went to court.
It'll always be possible to do the filtering as prosumer, but the current state of the art of "it just works" ad blockers is something Google is fighting against (also see Manifest v3)
Not every thing that big corporations say they do for security reasons or whatever is a cynical ploy. Do you think they're experimenting with post quantum cryptography in Chrome Canary in preparation to drop a 50k qubit quantum computer on the market sometime soon?
On Android, some of the most popular apps are fake-VPNs which just register your own device as VPN with itself so they can filter ads.
This isn't about the pi-hole, this is about ad blocking becoming "too easy". You can always block DoH. But no ISP can include such a blocker by default easily anymore.
Do you have to block every known DoH server? Looking at Google's DoH certificate they list quite a few hostnames and IPs as Subject Alt Names:
dns.google
*.dns.google.com
8888.google
dns.google.com
dns64.dns.google
2001:4860:4860::64
2001:4860:4860::6464
2001:4860:4860::8844
2001:4860:4860::8888
8.8.4.4
8.8.8.8
Issued by Google Trust Services...The localhost forward proxy I use can distinguish DoH requests from other HTTP requests because the DoH query URL structures used are mostly the same; they follow RFC8484. As of today, it is easy to probe IP addresses for listening DoH servers. The list of "known DoH hosts" is still quite small. Of course this could change.
To be clear, I am defintely not a proponent of applications ignoring user system-wide DNS settings and using DoH to obscure that fact. I have long run localhost root and DNS for myself and have no need for third party DNS, whether ISP or open resolvers.
However, as an end user I see no reason to trust any outgoing HTTPS traffic from applications authored by folks who are agreeable to online advertising as a business model.
The greatest threat I face is online advertising, not DNS lookups associated with malware. With DoH, HTTPS traffic could contain an unwanted DNS request, but prior to DoH it could also contain data to be used for tracking and advertising purposes. I felt the need to start monitoring/MITM'ing the HTTPS traffic on the private networks I control long before anyone proposed DoH. I would guess many corporations and other organisations do the same.
However, as most sites are https nowdays, privoxy is effectively limited to just blocking domains, making it pretty similar to pihole ...
Would you mind sharing the script?
grep "https://www.youtube.com/watch?v=" /tmp/bookmarks.html | cut -b22-64
https://en.wikipedia.org/wiki/Polar_bear_jail
PS: You might enjoy Veritasium (a YouTuber).
The illusion of purity allows corruption to thrive. There are influence teams hired by VIPs who use Wikipedia as simply an extension of cable news/social media. To "get out in front of stories", or if they're late to the game, to scrub/"memoryhole" undesired ones. Wikipedia editing as an amusing hobby for niche nerds is an outdated concept for many topics.
Wikipedia is far too powerful a Persuasion tool to let fail. Its essay-long donation plea's are designed to garner credibility towards innocence. How nefarious could the site be? They're scrounging around for scraps each year!
After all these years of doing that I finally visited the Wikipedia Home page a few weeks ago. I was quite surprised with all the stuff they have there that I had no idea about. That rabbit hole is a lot bigger than I knew about.
I found the actual easiest way to avoid YouTube ads, and maintain support for content providers whose services I enjoy, is to get a Premium subscription. ¯\_(ツ)_/¯
When your are using Google Cast, you don't stream from your device to the TV/Chromecast. Your device sends a package containing the app name you want to open and some basic configuration data and then the TV/Chromecast downloads a web app from Google's severs and opens it with the configuration you provided. Then your device can interact with it.
Edit: I guess maybe you're just talking about on a smart TV.
Note that I'm not against ad blocking in general, but if you use a website a lot, it seems fair to me to remunerate it one way or another, and at least paying for membership is not a business model based on selling your data.
Ublock on PC, youtube vanced on android!
I'd like to understand how opting-out of Google Analytics would spare you much from the massive big data tracking done via other JS libraries, ads, and especially mobile app use.
Go onto any large news site, ecommerce platform, realty/home search site, etc. and look at the network tab in your Web Developer view. Commerce may in good part "run" the world, but that traffic will expand as bandwidth expands; what data will they want to track next? => using cameras and audio everywhere to determine what your mood is, what you're talking about, what you say you want. Anything with a mic or camera could be doing this today, in theory, but the bandwidth isn't there to support it.
How can we avoid this?
Should we stop WiFi and just wire our homes well, then plug-in and enable cellular data only when we sit down or really need it?
It seems almost unavoidable, and that we've become too reliant on these things if privacy is the goal. And the bureaucratic EU policies on privacy seem like a simple game of chess for big data companies; we're responsible for this.
It was blockable, but the author decided to rename the file to jquery.js.
I'm retaining myself to quote the famous "If it looks like a duck, moves like a duck...", but I won't. :-)
That's another reason to use LocalCDN[0].
[0]: https://addons.mozilla.org/en-US/firefox/addon/localcdn-fork...
It is a spectrum, not mutually exclusive.
Ads are inherently 'mal-', in that you didn't ask for them and don't want them.
Javascript provides the '-ware'. And the question is really if they're just there to distract you or do something worse to your machine.
So what Google does with that data? To me it seems GA is just the free incentive to get sites to start using their "marketing platform", it's the entry point for their upsell conversion funnel to selling you Google Ads. The real thing. And GA is a great way to get you to get vendor-locked-in early.
Some cost-effective alternatives off the top of my head
A plain-vanilla GA installation does not connect GA data to any of Google's data. Google is a Processor under GDPR & Service Provider under CCPA, meaning that the data "belongs" to the site owner and Google has no legal rights to use it for their own purposes.
BUT
A key feature of Google Analytics is integration with the rest of the Google ecosystem, including Google Ads (formerly AdWords) and Display & Video (formerly DoubleClick). It is extremely easy to connect GA data with Google's data. Configurations that give Google legal access to the data are easy and common. (If you remarket using GA, Google is not just a service provider.)
From a GDPR perspective using Google Analytics is still problematic because of Schrems II. Any data transfer to a US-controlled entity is troublesome, because the EU has declared that US does not adequately safeguard user data (the main sticking point is the lack of accountability of law enforcement & intelligence agencies to request access to the data). But that's about the US, not about Google specifically.
It's extremely easy and Google do an exceptionally poor job of explaining what's going on under the hood.
> From a GDPR perspective using Google Analytics is still problematic because of Schrems II.
That and the fact that the British regulator last year explicitly called out Analytics as not being valid without a GDPR level of sent before tracking is enabled.
(function() {
var a = document.createElement("script");
a.type = "text/javascript";
a.id = "__gaOptOutExtension";
a.innerText = 'window["_gaUserPrefs"] = { ioo : function() { return true; } }';
document.documentElement.insertBefore(a, document.documentElement.firstChild);
})() window["_gaUserPrefs"] = { ioo : function() { return true; } }By creating a script in the page itself, the "_gaUserPrefs" variable is made accessible to the Google Analytics script.
Which is?
Edit: In the interest of saving time, it looks based on your other comment that you're referring to chrome.tabs.executescript, but code executed this way executes as a content script so it doesn't run in the page context and can't communicate with javascript running on the page.
If there's another way of running code in the page without injecting html I'd love to hear about it, though.
browser.tabs.executeScript({
code: `
window["_gaUserPrefs"] = { ioo : function() { return true; } };
`,
allFrames: true, // And maybe this for good measure?
runAt: "document_start",
});
(Spelled browser for WebExtensions, and chrome for most Chromium-based browsers.)This may well be incorrect or incomplete. I’m not properly familiar with the details here. I haven’t made any browser extensions in the WebExtensions era, all I’ve done is plenty of Greasemonkey scripts, where you can use unsafeWindow.eval() for these purposes (and there, if you instead did unsafeWindow._gaUserPrefs = …, you’d run into a SecurityError when the user code tried calling _gaUserPrefs.ioo()).
[0]: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
Disclaimer: Googler, not on ads.
I've been searching - maybe something like usercontent.css but for javascript that works?
https://news.ycombinator.com/item?id=1378004
Also, as a little personal trivia, I'd like to add that in all these years I never seen this installed on any browser by anyone.
How about no ...
Why would you install this if you already don't trust Google with your data.
If said browser extension actually doesn't track you, this is a non-sequitur.
Hard to argue an extension tracks you if the single only thing it ever does is print "Hello" on top of every page you visit... still that extension would need to be able to access and modify every site you visit by definition.
The exact same thing is happening here.
[1] https://www.reviewgeek.com/45420/over-70-chrome-browser-exte...
I suppose it's possible for Google to push new versions of the plugin, so you'd have to review each of them. Does the user even get notified when a new version is pushed?
This plugin makes no sense, any informed user who cares enough about privacy to install would go for a more generic blocker anyway, such as uBlock Origin
No, but the browser (in this case Firefox) is supposed to check the updates before deployment, even if only superficially.
It's also a double-edged sword, because sometimes there's an important update to the add-on that's stuck waiting to be reviewed, making the add-on useless for a couple of days.
> By the Lord before whom this sanctuary is holy, I will to N. be true and faithful, and love all which he loves and shun all which he shuns, according to the laws of God and the order of the world. Nor will I ever with will or action, through word or deed, do anything which is unpleasing to him, on condition that he will hold to me as I shall deserve it, and that he will perform everything as it was in our agreement when I submitted myself to him and chose his will.
And if you need to opt out of more services:
Equivalent to being told that all I need to do in order to get someone to stop following me is to let them in my house one more time
Just block it (and almost all other analytics) instead of opting out
I use uBlock and the browsing experience is much better. Cannot stand pages with ads anymore.
I stopped using Chrome only because of AMP and made FF my primary.
"Hey, what is this list of language codes that browsers send in the request? Could we use it somehow?"
"Don't worry about it, we already use it to calculate fingerprints."
Any requests to the Google Analytics URL could be cancelled before any network activity, rather than grabbing the file and doing nothing with it.
2. Users do not decide to be tracked. They can only opt out by installing more stuff made by an advertising company.
(Also probably relates to Google and Facebook moving all UK users to USA Ts & Cs.)
I think uBlock is more than adequate in blocking these & so much more trackers which are so prevalent.
That would have been much more efficient than those GDPR banners and dialogs, but will never happen since it will be "too easy" to opt out just like the http "do not track" extension failed for being too powerful.
'Brilliant idea!'
'Here, I've already written the script for you, let's push it to production and keep gobbling on data.'
It applies to small companies just as much as to large companies. However if you're not really marketing to people in EU countries, the GDPR doesn't apply. So a local newspaper in Ohio need not worry about the occasional European visitor, but The Washington Post definitely does
As far as I know GDPR states EU citizens not people within the EU. Member states' laws will cover everyone however GDPR is for EU citizens globally since that is their remit.
> It applies to small companies just as much as to large companies. However if you're not really marketing to people in EU countries, the GDPR doesn't apply. So a local newspaper in Ohio need not worry about the occasional European visitor, but The Washington Post definitely does
Basically you argree with what I wrote but wrote it in a way to make it look like I stated something incorrect. Why did you do that?
Why can't the same thing be achieved by using HTTP headers. E.g. like the do-not-track header was supposed to work?
Or by blocking dns lookups or an ip-range?