An industry that unmasks people at scale
vice.com
vice.com
- Store and/or access information on a device
- Personalised ads and content, ad and content measurement, audience insights and product development
- Use precise geolocation data
- Actively scan device characteristics for identification
Whether you click on the "Accept" or "Refuse" button of a webpage's Javascript-powered cookie banner has 0 technical incidence on whether you can be tracked or not. It's like going into a store and telling the clerk "please don't look at me, and when I leave please forget I ever came here".
Or saying "Please don't record me, I don't give my consent". But you are already in there archives. Facial recognise so they know what you like to buy.
I feel these cute analogies make the mistake of equating a human seeing and remembering you (maybe even writing your name down in a notebook) with a machine doing the same thing.
There's significant qualitative differences, mainly that the machine has perfect memory and can effortlessly share and collect your information with other machines.
That only makes the point for which the analogy is used stronger though.
* Store information on a device.
Cookies cannot:
* Personalize ads (they can store identifying information that can be used to personalize an ad, but something else has to actually ask your browser for the data) * Actively scan device characteristics * "Access information" Cookies don't do that. Code (Javascript in the browser usually or something on a web server) that might use data from a cookie does.
A great talk I once heard focused on the idea that given there are (let's use a nice round number) ~4 billion humans on earth, your identity only has 32 bits of entropy. Every piece of information about you can be put in terms of how many bits of your identity it reveals.
Gender? ~1 bit. Zip code? 15+ bits. Your phones serial number would be 30+ bits (assuming some wiggle room for resale or multiple users).
I think every country wants to monitor its citizens and those that have the technology actively do so. It is indeed responsible not to get fooled by marketing when those countries say they don't.
For example:
* Brazil: https://iapp.org/news/a/an-overview-of-brazils-lgpd/
* Canada: https://www.globalcompliancenews.com/2020/12/24/canada-watch...
* India: https://hbr.org/2019/12/how-india-plans-to-protect-consumer-...
* China: https://www.lexology.com/library/detail.aspx?g=47e4d6ec-f5fe...
* Indonesia: https://www.dataguidance.com/notes/indonesia-data-protection...
* Japan: https://auth0.com/blog/the-new-japanese-privacy-law-what-bus...
None are exactly the same, but each includes many similar constraints to the GDPR, notably for the GP's point: no processing of personal data without consent. Together with the EU, those easily cover more than 50% of the global population.
I wouldn't be surprised if the US made an attempt at something similar soon. If not it feels like another area (see also: socialized healthcare, gun control, the metric system) where US norms could end up out of step with the rest of the developed world.
They might not be able to figure out my address, but your device is not anonymous.
Ads (bottom of the page) Advertising ID and Personalization
I too have 'opt out of ads personalization' enabled, but the description is: "Instruct apps not to use your advertising ID to build profiles or show you personalized ads."
The effect and meaning SHOULD be: default: give each app a fake value when this is called (configurable to always nil, random, or 'static per app') and also instruct them to ignore the value.
Reset advertising ID is text at the top, the opposite end of the screen from the ID displayed, and it is not obvious this is a 'button' text. That's a dark pattern to me.
However, it should soon appear as a 0'd string. (Because, obviously, it was still being used for that purpose).
> Starting in late 2021, when a user opts out of interest-based advertising or ads personalization, the advertising identifier will not be available. You will receive a string of zeros in place of the identifier. [1]
[0] https://www.theverge.com/2021/6/3/22466531/google-android-ad...
[1] https://support.google.com/googleplay/android-developer/answ...
How much would that help combat this stuff?
(Ignoring Google themselves, since they don't need your AID to track you anyway)
Generally speaking, your advertising ID is linked to a bunch of other technical information used to profile you. So when you change advertising ID, the systems in use can generally correlate that, and have a history of IDs that are linked into your profile.
1. Nearly every app stores an ID identifying installation of the app on your phone. When the app starts up, it sends this installation ID and your new AID to the server which now has both old and new AID. To prevent this, you must uninstall all apps, change your AID, and then reinstall apps. Deleting app data is insufficient because app install times are unique and easily obtained from app file timestamps. Android apps that have access to "external storage" will send file hashes to the server and identify you instantly.
2. When you sign into an app, it sends your IDs to the server which now has your old and new AID.
3. If you use an app that talks to a physical device, the physical device reports its serial number or unique network address. The app sends this to the server with your new AID. Any app can silently search for such devices on your network and extract their ID numbers. Examples of physical devices: fitness bands, anything BlueTooth, printers, remote-controlled lights, NFC tokens, and find-my-keys tokens.
4. If you use WiFi without a shared proxy (a VPN) then any app or even any website can simply send your (device type, IP address) pair to the ad network for de-anonymizing. No need for IDs at all. The moment you launch any ad-supported app on such a non-proxied Internet connection, the app will link your new AID to your identity. This happens when you connect to Wifi at work or friends' homes. Most VPN software fails open, so apps can get your IP address for a few seconds when the phone restarts and every time the VPN service is down or momentarily interrupted. Working around this takes knowledge and effort.
Once one app company sells your (Old AID, New AID) pair, this data enters the network of data brokers and is available to all.
TLDR: Changing your AID alone does nothing. Mobile privacy requires a fail-closed shared proxy (VPN), no data sharing between apps, and no reachable devices on the WiFi network.
I apparently couldn't reply to this comment but it's been bothering me: https://news.ycombinator.com/item?id=27771747
This is actually not true. Regular 'vardcentraler' had no such requirement and far from every ward at the hospitals did either.
Some that did enforce visitor's restrictions (some at Lund University Hospital I had experience with) had no mask mandate but relaxed all restrictions in September.
UMAS in Malmo had multiple wards not mandating any mask wearing (including blood test section and endocrine) but enforced it across the street on the women's clinic.
One of my local Capio placed out some boxes of masks well into the reception area and asked people to use them, but it was by no means mandated.
So what you wrote is really not at all true, and it wasn't at all highly irregular. It was just depending on what wards you were visiting, and as for vardcentraler it was a joke.