They also have lots of information about users in aggregate ("people who bought this also bought x") which they got by collecting data about their users. Can they use this?
Covering my entire webpage I'm trying to research something else at with a full-page Amazon ad for a product I already bought just because I expressed interest in that product by buying it is not okay. Thus, I block all ads elsewhere to avoid that sorta thing.
Works pretty well for me, but it's sad I should have to jump through as many hoops as I have to to avoid such crapware being forced upon me. Ads I'm not wanting literally steal a portion of my allotted bandwidth and give me less than zero value in return. Perhaps advertisers should start paying us for our valuable time, attention, and bandwidth?
You may not be, but this is within what they cover in the report Vivaldi is recommending: https://www.forbrukerradet.no/wp-content/uploads/2021/06/202... (it's a good read, and there are a lot of things they object to even with only first-party tracking)
> Perhaps advertisers should start paying us for our valuable time, attention, and bandwidth?
They don't pay you directly, but they pay the site you're visiting, and in most cases that's why the site is able to afford to create the content you're reading and show it to you for free.
Edit: It is a sorta good read… Just be nice if these sorta situations could more easily find some kinda valid balance instead of always escalating outta control to both extremes until laws have to get made… Lawmakers are rarely to be trusted to get these sorts of situations right anymore…
I've been using the Internet and networks long enough to understand how this stuff works. There's a certain degree of tracking that is literally unavoidable (without semi-extreme measures like TOR for one example at least) simply by the nature of how networks work. I know that by using any service online at all, I'm necessarily parting with some data about myself. Any data that's collected in that transactional networking sense I'm kinda largely okay with because it's just part of how things work by their very nature.
The stuff that bothers me is the excess of spyware, hundreds of kilobytes of tracking scripts, invisible pixels, browser fingerprinting, and other shady junk that's been bolted on by advertisers with no concern whatsoever for any harm it may bring to the network, the consumers, or often even themselves, as long as they make enough to cover the costs and make a profit. I understand the logic of it, but I don't necessarily agree with it in many cases. For me it's really all about how respectfully the entire situation is handled. Advertise at me in respectful ways, you probably don't get blocked (at least by me). Abuse me in any way, and I tend to get uppity with my adblocker and start thinkin' hard if I even need your site or service at all.
> "They don't pay you directly, but they pay the site you're visiting, and in most cases that's why the site is able to afford to create the content you're reading and show it to you for free."
See, the sites that aren't abusive with their advertising though actually find their way out of my adblocker for that exact reason. Because I'm fine with them making money ethically. Sites/services that implement abusive advertising practices not only get the ads blocked, but often get themselves blocked out of my "sites of interest". ;)
Problem is when a company use data that the user did not explicitly opt-into sharing with them, to then diminish their user experience of consuming the web by for example stuffing tons of targeted ads on every major site on the web, leading to barely usable sites and intelligence insulting outcomes.
Great, we just banned TCP.
I'd definitely consider a system which collects all information that are exposed in a TCP stream a surveillance tool
I consider it less surveillance-y if a single employee is remembering me. Although I do sometime wish I could delete some embarrassing moments at the store, but I guess, as long as they don't gossip about it between employees... :)
A hypothetical example: suppose it becomes a legal nightmare to have even heavily censored webserver request logs retained for any period of time if your company does any advertising at all. That is, even if you have no intent or even ability to use those logs for advertising purposes, it might be a lot of work to prove that to the law, unless you take the hopefully-easier route of literally never advertising. "Boo hoo, companies have to prove they're not breaking the law", you might say; as is usually the case with these kinds of regulations, demonstrable compliance might be totally practical for bigger companies but a massive barrier for smaller companies, which on the margin means the difference between success and failure for quite a few businesses that would've otherwise created a lot of value.
That specific scenario probably wouldn't happen, I hope, but that's far from the only plausible failure mode! I would like to believe that we can figure out a good definition with relatively little value destroyed in the fallout if a law like this comes into effect, but it's almost certainly not going to be a single sentence.
to possibly downplay it or imply otherwise because the collected information may (or may not) benefit the user is just spin.
DPA is I assume Data Protection Act (UK): https://www.legislation.gov.uk/ukpga/2018/12/contents/enacte...
Any ad which uses data about an individual, without full transparency about the data being used, to target them as an individual OR where such data is collected and stored and associated with an explicit or implicit identity.
I think this can be done. I just don’t have the domain expertise to do it, and haven’t seen a proposed definition that made sense. The only intuition I have is around ephemeral versus permanent profiling.
For search based advertising we use the search query and location (taken from the country the user chooses in settings - and that can be "None" in which case we just use the search query). The language of the search query could be used rather than IP. Key for us is to never store IP and never pass on any part of it.
I think this might hold the key. The law likely doesn’t need to try to regulate advertising per se, but instead the types of data advertisers are allowed to retain (or access).
Maybe a first step is creating a definition of an advertiser, requiring registration (not licensing) and the annual filing of the inputs their algorithm uses? All inputs, even the most banal? This assumes defining advertiser and algorithm and inputs is easier than what we’re trying to ban.
Some of the unintended side effects (which aren't necessarily bad) include ending virtually all store loyalty programs.
>In this context, we use the term ‘surveillance-based advertising’ as a blanket
>term for digital advertising that is targeted at individuals or consumer
>segments, usually through tracking and profiling based on personal data.
This is ridiculous. If I am trying to advertise an Elixer IDE, then I don't want my advertisements shown to any random person on the internet. The majority of users on the internet are not even developers. I want to be able to advertise to a consumer segment which consists of people who are interested in Elixir. "Surveillance" is essential to internet advertising.
The definition in the report is poor. Yes, you always need to advertise to a segment. No, you don't have to spy on users to do it.
How? Make a website about something and select advertisements that are relevant to the sort of people who are probably interested in the topic of the website. ReadTheDocs has already spun off an ad business that advertises tech stuff to readers of ReadTheDocs because it's reasonable to assume that is the audience that is perusing ReadTheDocs pages.
Assuming you are running an ad network you kind of have to in order to prevent ad fraud. Also by reducing that data you know about someone's interests is the knowledge that they have visited a site at least you will not be able to pick as good of an ad compared to if you had more data.
Provide one example that can not be solved without surveillance.
An easy fix with surveillance is to rate limit people based off their IP address. Without surveillance though there is not much you can do. Scale up your infrastructure to try and out scale the attack? Implement a global rate limit that locks regular users from being able to sign in?
This is your best argument why we have to track and profile every human on the planet around the clock?
This is totally surveillance. Just because we delete data after a while, it doesn't mean I didn't surveil you, nor does it mean I haven't used that data I got from you for my own benefit.
>This is your best argument why we have to track and profile every human on the planet around the clock? You just asked for an example. If you are suggesting that my argument is to prevent abuse of systems I would say that it justifies tracking every person on the planet.
It is not. I connected from some IP because I wanted to use your website, at the very least you have to remember my IP address for some time to send me your website back. And if I want to access your website and it will be only available if you store my IP address for a few minutes to fight off attacks, then this is a use of my IP address that I welcome because it is for my benefit. And if you really want to, just store hashes of the IP addresses [1].
Just because we delete data after a while, it doesn't mean I didn't surveil you [...]
Sure, surveillance is not defined by the amount of time you store some data. If you store my shipping address for years it is not surveillance, if you store my IP address for one second to add an entry to my record in your database that I just visited the website it might be surveillance even if you do not permanently record my IP address. But I never claimed that the amount of time you store some information is a or the relevant criterion
[...] nor does it mean I haven't used that data I got from you for my own benefit.
Also irrelevant. If you store my IP address for a short time or my shipping address for a long time in order to send me the website I requested or my order than this benefits you because you will make some profit from my order.
Relevant for whether something is surveillance or not is whether I approve what you are doing. If you track my position day and night in order to show me ads for businesses nearby it is surveillance unless I specifically requested this. If you track my position because I am using a fitness app and requested to record my run, then it is not surveillance.
[1] For IPv4 this is of course essentially pointless. But maybe you could come up with a more elaborate schema than simple hashes, maybe salt them and rotate the salt every few minutes or whatever. But you will probably not gain much besides added complexity.
Pick a more sensitive area than your IDE, say medicine targeting erectile dysfunction, sexual or religious preferences, etc. You may find that being allowed to collect that data, especially covertly, just to save some money suddenly doesn't look reasonble at all.
But surely I should be allowed to covertly collect any data about you if it enables some savings for me. After 15 comments insiting it's OK you should only approve of this.
The first thing I would do is look outside to collect information on who in outside thereby infringing their privacy.
>Also suggesting that an IP based rate limiter is the same as the surveillance in question is very disingenuous
Recording people's IPs is definitely surveillance.
>say medicine targeting erectile dysfunction, sexual or religious preferences, etc. We may be able to connect drug sellers or churches with people if we know that information.
>But surely I should be allowed to covertly collect any data about you if it enables some savings for me.
Sure you can. Go ahead.
Looking at someone doesn't infringe on their privacy. Taking a picture of that someone and storing it in a permanent fashion, might. To prevent abuse/DOS you only need to do the first (which does not constitute "surveillance" or loss of privacy), not the second.
> Recording people's IPs is definitely surveillance.
It's not surveillance if you are not tracking anything else other than IPs (i.e. no other behavioural data associated to it).
Either way, you still have not provided an example where surveillance is required to prevent abuse: I can simply store hashes of "bad IPs" (or ASNs) to blacklist... no need to store any information that could lead to an actual person (like an actual IP address).
We'll there's your problem. First you show a complete lack of understanding of the issue, from its basic concepts to the practical manifestation and consequences, and then you conclude that it must not be a real issue.
This technique can be used to justify anything. Burning books? Sure, it's like burning extra processed wood, totally okay, go right ahead.
Ignorance is not a defense.
Also can you send me your medical data and search history? I mean you're OK with sharing this data and said nothing about it being ok only if I can do it covertly. Better yet, give me your name and address and I'll just grab that myself so it's not too much of a bother for you. It's just so I can serve cheaper better targeted ads to you.
I mean refusing and backing out now would just be hypocritical and completely undermine the case you so unsuccessfully try to make wouldn't it?
Regardless, consider a DDoS attack. If every new request is coming from a different IP address, how do you continue providing service to your legitimate customers while blocking that malicious attack? Knowing the attacker's IP addresses doesn't do you any good... because they can just keep using new IP addresses, and blocking the old ones doesn't do any good.
This is where heavily surveillance-based systems like Google CAPTCHA often come into play, and I have very mixed feelings about those.
There are some non-surveillance-based captchas like this one[0] that I saw on HN awhile back, and I hope those become successful.
To complete the metaphor Amazon would use the address you gave them to help improve their business in some sense without asking you if it's okay. Similar to how web masters don't ask if it's okay if they write what pages we access into logs is okay.
>Knowing the attacker's IP addresses doesn't do you any good... because they can just keep using new IP addresses, and blocking the old ones doesn't do any good.
Then we should try to find any patterns with the traffic that we can use to try and filter it out. This is a place where fingerprinting is useful.
>friendlycaptcha
This just slows down bot spam instead of testing if someone is a bot. Someone posting spam to your site once a minute is still annoying.
I'm not going to waste my time further on this thread after making this one last point.
> This just slows down bot spam instead of testing if someone is a bot. Someone posting spam to your site once a minute is still annoying.
Google CAPTCHA is trivially bypassed all the time. Do you really think it isn't? Sometimes using services like Amazon Mechanical Turk, sometimes using simple computer vision. It doesn't test whether someone/something is a bot either... it just tests whether they can pass the CAPTCHA. It certainly doesn't test whether they're part of a DDoS, nor does it test their intentions to find whether they are good or malicious. It's just a CAPTCHA, but it also uses a lot of surveillance... and as I said, I have mixed feelings about that. I didn't mean for this to become the point of the thread, it is definitely off topic.
The idea of Proof of Work CAPTCHAs is that you can actually make it more expensive for an attacker to solve those than it would be for the attacker to solve Google CAPTCHAs. Obviously, this is still an area of debate and research.
I'm not exactly sure what this means. I used to be all for total privacy, but I found that future to not be sustainable. Perhaps I'm just jaded, but privacy just gets in the way.
>This whole thread is about surveillance based advertising being bad.
Well this part of the thread isn't. It's talking about how surveillance improves services by allowing them to deal with abuse.
>In no way is using an IP address in a firewall a form of surveillance. It isn't. The IP address isn't being associated with any other data, it's just some numbers floating in space, disconnected from any human being.
Wrong. I am using your IP as part of a scheme to fingerprint you. I want my rate limit to limit each person separately. An IP address is just a somewhat decent way to approximate that.
>The idea of Proof of Work CAPTCHAs is that you can actually make it more expensive for an attacker to solve those than it would be for the attacker to solve Google CAPTCHAs.
This has to be carefully balanced with the user experience. No user in going to want to wait 5 minutes to post when they can just have a Google account with a good reputation and just click a checkbox.
That's not your decision, I decide what matters to me, whether I want my privacy or this nebulous sustainability, whatever this is suppose to be.
Wrong. I am using your IP as part of a scheme to fingerprint you. I want my rate limit to limit each person separately. An IP address is just a somewhat decent way to approximate that.
Then let me turn this around, if using my IP address in this scenario is surveillance, then don't do it. If it is necessary, then ask me for permission, can we use your IP address to fight off attacks and ensure the availability of our website or do you prefer that the website might not always be available due to attacks? And the same applies if you want to rate limit all users, offer the choice between not using your website or opting in for IP based rate limiting. It's that easy.
In that scenario, it seems like advertisers would pick up on that pretty quickly when they realize the conversion rate on that supposed traffic is terrible and doesn't warrant the inflated price. In the case they're using an ad network, the network could ban the page owner from their network if they see this pattern from them. Since page owners are materially benefiting from the network, proof of identity should be (probably is? I don't work in the space) applied between the page owner and network to prevent repeat fraud via identity laundering.
> you will not be able to pick as good of an ad compared to if you had more data.
In theory I lean towards agreeing. I was arguing for tech-powered hyper-personalized ads back when I was studying advertising 2008-2012 (and did a bit of "stealth marketing" in that period where I built relationships with bloggers to share our product before the term "influencer" had hit the mainstream vocabulary).
In practice, advertisers do not personalize ads. Facebook has become pretty good about selecting ads that map to my interests thanks to the reach of their spy network, but the ads themselves still aren't personalized at all (they take my interests into account, but not my spending history to realize that I don't have the budget for what they're trying to sell me) and my conversion to a sale because of them is still very, very low.
Instead of selling space by impressions or clicks, we use length of time (monthly) and find it to be a good way to prevent ourselves from trying to game impressions with clickbait or clicks with fake users.
1. Page owner / Ad network / Ad space auction market middleman fakes clicks to get click revenue
2. Page owner's rival fakes clicks to devalue ad spots
3. Advertiser's agency fakes clicks to make numbers go up
4. Advertiser's rivals fake clicks, to waste advertiser's budget
5. Ad networks 'accidentally' classifying legitimate clicks as fraud, to reduce payouts to page owners.
1. Clicks are not charged for, so increasing clicks does not change the cost.
2. The only question available is how much you pay and how much you make. Page owner's rival could attempt to confuse you but there's not actually a difference between paying $1000 for 0.1% of ads shown in July, getting 100 clicks out of 10000 impressions and making $2000 vs paying $1000 for 0.1% of ads shown in July, getting 10000 clicks out of 19900 impressions and making $2000.
3. Shorter 2: Numbers are irrelevant unless they have a dollars/euro/yen/pound sign before them.
4. Clicks to not come out of the advertisers budget.
5. Surveillance advertising enables this fraud by attempting to distinguish between real and fake traffic. If you are paying for something that is robust to that, then the fraud is irrelevant. In particular, it doesn't matter if 0.1% of ads displayed to bots are yours and 0.1% of ads displayed to humans are yours if you've paid for 0.1% of ads to be displayed to be yours using a random rotation.
The only thing like any of these hacks that seems relevant is that a very crafty adversary might be able to determine your traffic rate and identify the timeframe they need to request to particularly target a certain ad, making more of the 0.1% of displays get shown to a bot. But this is easily handled by using a secure random rotation rather than say a round robin rotation. In any case, I can independently verify the efficiency of my spend by getting a sim card that the ad network doesn't know about and repeatedly reloading the page for a month. If I receive only 0.01% of displays because some third party or the network is trying to defraud me I now have pure evidence that they aren't upholding their side of the deal. If they try to verify humanity before deciding what to do, then they can just say "no, we identified these requests as coming from a bot and graciously didn't display your ad to them". What can you do? The existence of surveillance is not in the interest of the advertiser who is concerned about fraud.
(If you don't trust your network, any fraud on their part isn't going to get solved of course. But then having less data is an advantage. There will be fewer variables so it will be easier to catch, and the capital requirements will be simpler --- code and business partners vs code, business partners and user surveillance data --- so it will be easier for a trustworthy competitor to emerge.)
Harder to pull off than advertising at people who might actually want to see the ads? More risk and complication than the growing backlash against advertising in general entirely because of shady advertising practices? More risk and complication than having to keep track of various countries' and states' laws re; privacy?
> "For example, what if a web master decides they don't want to have ads on their site anymore. Whoever just paid for that space gets screwed."
Existing contract law already covers this in most places. If you paid for ads to be displayed for a certain time period and they are not, then there's been a contract violation.
Not all users of Elixir hang out on Elixir forums. There are plenty that spend the majority of their time on the internet elsewhere.
>and I certainly don't want ad companies that are following me on random websites to know that I'm a programmer who is interested in Elixir or any other data about me.
Why not? Systems can become more efficient if they know you better.
Because it's a privacy risk. Such information can be used to identify me and used against me.
Good. We can make things more efficient.
>used against me
How could someone for example knowing you like Elixer use that knowledge against you? It's not a big deal.
Not op but I've not clicked a single ad intentionally since Ads exist on the internet. I don't consider them a trusted source for recommendation and why should I? Why should anybody? Ads violate my attention and that's what they're made for. They do not help you find the best product. They want you to find THEIR product. Everybody knows that.
The privacy issues are the dangerous topping here.
You are in the minority then. I personally have clicked on ads and have found products that I was interested in.
>I don't consider them a trusted source for recommendation and why should I?
I am not saying you should. Ads just allow people to get the word out about something.
>Ads violate my attention and that's what they're made for.
This is a poor mindset. If you go to a public place are all of the people there violating your attention because you can see and hear them?
You don't happen to work in the industry? Because I know nobody who clicks on Ads. Maybe some of them do but they don't admit it which says a lot about doing it.
The only people I've ever met who said things like you did work for the advertisement industry since they're the only ones who believe that. They have to.
> I am not saying you should. Ads just allow people to get the word out about something.
How is this a justification for the intrusive, secretive and sometimes even abusive behaviour? There are other ways to "get the word out" out there. Healthy ways.
> This is a poor mindset. If you go to a public place are all of the people there violating your attention because you can see and hear them?
Sure they do if they jump right in front of my face and yell about some product I might be interested because I just came out of a shop and they've been watching me doing it and writing down how I look.
You and me both. I actually actively block ads on the Internet except on the very few sites that have earned my trust (https://readthedocs.org/, DuckDuckGo, etc) or sites where the advertising is directly connected to my existing purpose (to buy a thing) such as Amazon, eBay, Humble Bundle, etc. Everywhere else gets the block because they simply can't be trusted anymore.
Because I didn't give them permission. I've no issue with anyone who willingly trades their privacy/digital footprint in return for services.
I don't want to. I will happily pay money for services I want. But, in all practical ways, the choice has been taken from me. It's impossible to have an online life without Google, Facebook, and myriad others hoovering up my every digital footstep.
And before someone says "ad-blockers" - I use them. And I decline cookie consent on every site I visit. It's tiresome, but I do it. Though even that marks me out: a signal in the noise. Even the act of trying to reject the surveillance economy helps that industry segment me.
It's obscene, and something needs done about it.
I don't think this is really worthwhile. It's akin to reporting every Google/fb ad as "I don't want to see this/this isn't relevant to me". Easier to just block ads/cookie consents from ever appearing, and set cookies to automatically delete after tab closure.
This is ridiculous. And it is your problem. Why should I allow any company to track and profile me and everyone else only so that you can save on your advertising budget?
As a side-line, this’d probably cut back on a lot of click-bait trash articles. It, likely, would help bring the signal-boise level of the internet at large back to something more useful.
Well, I can dream, anyway..
Than don't run ads. Essentially nobody is interested in seeing ads, targeted or not.
It's a waste of money for me. The ad network will not be able to make money from having them click the ad.
I don't give a fuck how much money it costs you or if the ad network goes bankrupt, why should I?
The user's time will be wasted because they are not interested in what I am selling.
As I said, then don't run ads if you actually care about wasting user time. Even if you have a conversion rate of 10 % you are still wasting time for the other 90 %.
It's a lose lose lose situation.
I would consider it a win if all ad companies go bankrupt and I never have to see an ad again.
I want to create more win win win situations where everyone benefits. Tracking and profiling is needed to increase the rate that this happens.
This is not win win win, this is win win win LOSE - a few users get a product they want, you get some sales, the ad network gets your ad budget, and everyone else gets nothing but being tracked and profiled.
I'm not interested in what you're selling. In general, I'm 100% not interested in anything anyone is selling through advertisements. Where can I indicate this, so that advertisers stop wasting their money on me?
And that there is why sites like https://readthedocs.org/ do this strange thing called ethical advertising. Instead of spying on me, they advertise things at me I am genuinely interested in, intuited by the fact that I'm reading technical documentation, and they do it in an unobtrusive way, rather than splat themselves in front of the content I'm trying to read such that I can't even read it at all.
You wanna advertise at me? Come find me on sites where your product is a good fit for my interests and advertise at me respectfully rather than supporting a corporate surveillance state that I want no part of. I for one will continue to block ads everywhere I browse except those that manage to respect me as a fellow human.
Then just advertise on sites that usually have developers?!
And, as the person being advertised to, I absolutely want you not to be able to do that. Why do your desires trump mine?
Surveillance is not essential to internet advertising. Because it’s not essential for advertising. Newspaper ads didn’t come with such invasive models, nor did radio adverts, or even TV ads.
If advertisers on the internet can’t figure out how to make a surveillance free advertising model work, then I’d much prefer those businesses to die.
Now, you just advertise in appropriate blogs.
If there are no appropriate publications for important topics, hey! Guess what! They have their business model back!
This is known as contextual advertising.
Surveillance is not essential to internet advertising – in fact neither ROI, effectiveness or perceived relevance (when compared to all alternatives, including contextual advertising) has never been proven.
Indeed, win-win that ads are targeted. Easily done on search engines because the query shows intent. Less obvious on the wider web but then perhaps it's the advertisers job to identify their market rather than rely on ad-network datapoints on visitors.
CPM/CPC ad payments are of course ripe for abuse by automation. CPA not so much.
Could potentially argue that the surveillance is essentially to make targeting more convenient for advertisers rather than being implicitly required to advertise. Market forces and ROI are surely the best measurement which CPA does a better job of doing. The problem with CPA is the trust required in order for the ad network to be paid.
> I want to be able to advertise to a consumer segment
This sounds like a you problem.
And you shouldn't get to push surveillance on me to solve it.
I don't want to be advertised at at all, let alone be stalked round the web so you can do it better.
I don't care at all that any advertising I see might be better targeted, it's all an annoyance as far as I'm concerned anyway. The idea that I should be happier if I'm getting 'relevant' ads, like I should thank you for surveilling me so you can spam me better, is absolutely laughable.
Surely you can buy ads in subreddits, or on specific tags on Stack Overflow?
Mate, you want one thing so world wide spying is ok for you ? So r. lack in imagination !
Just try to imagine what would be WWW (or other "medium") without that data hoarding... You want to ad IDE, for devs, for particular lang ? Just give money straight to forum of your interests owner. And...... DONE ! Or journal, paper, zine or whatever but do it directly.
That businesses curently DO NOT EXIST becose everything goes to Google ! And - biggest stupididy of last two centuries - to "businesesee that "model" enables". Just self serving monopoly giving away penies.
You see ? Your "survivalence is necessaary" is just lack of imagination. Literaly, current "system" prohibits new inventions and development.
Becouse where are money there are new companies/startups created. End where money are filtered via giant sucker there not much improvement can be build.
I'd bet over 70% of developers run some kind of adblocker. I personally run adnauseam[0] and I will NEVER click on an ad.
I think you are missing the point. As a user, my basic response to "my job is harder if I don't do surveillance" is I don't care. If you say that you can't do a certain type of advertising without surveillance, then my response is find another job. There are lots of interesting problems out there to work on for fun and profit. Find another one.
Or, stay in advertising and target ads based on what I am doing right now. If I read an online journal about mountaineering, show me ads for mountaineering equipment. Sure, it may be less effective (and boring), but us users are fine with that.
Advertisers don't have a right to take away my privacy so they can do what they want. This disconnect keeps coming up over and over. Just because an industry has become large does not inherently make it appropriate.
This is essentially what is going on in the internet. Metadata collection = Surveillance.
Maybe it's even worse. There are third-party analytics tools which send out any key-stroke you do, even if you don't submit any form.
It has become the new normal. Take todays article in Ars Technica on Audacity (https://arstechnica.com/gadgets/2021/07/no-open-source-audac...). The author has no complaint about the fact that a tool for local editing of audio files reaches out to the internet to send data about the user and seemingly defends this on grounds that it is opt-in. That's fine but that code is needlessly there. There's no reason whatsoever for it. And I am tired of being told that surveillance is for my benefit. No, it's not. It's solely for the benefit of the surveillor.