What is server-side conversion tracking?
digiday.com
digiday.com
heck, the payment processor plugin probably on that costume's site that's all they needed considering the email came from Paypal, which I assume you have an account with. an IP address lookup table internal to Paypal would do it alone.
It's ingenious. The incentives are set up entirely against you. The people who know and care the least about privacy decide what to do with your data, and they are enticed to hand it over by the promise of tracking ad spend, i.e. the promise of making their jobs easier and of making their success quantifiable.
Or could it be beaten by high privacy browsers like Brave and a system of shuffling through and sharing random anonymous online identities with strangers like Tor does with IP?
Just to confuse the hell out of the ad platforms…
What would the legislation even be though?
That can be combined with other sources that the Web site vendors have contract with, including so called knowledge databases, that can correlate such information.
People that keep arguing for native being less secure than Web, just because they can use telemetry, have no idea to what extent marketing engines are able to extract information from each HTTP request.
Additionally, if you ever log in, correlation can be made with older stored logs, thus even if surf anonymously afterwards, the same IP range can be mapped to you, even if it isn't guaranteed to be correct.
This stuff is done because it works.
> This stuff is done because it works.
Yes. Annoying some people is only an externality. It's cheaper to apply those techniques to everyone, even if the actual target is a small subset of people vulnerable to being exploited.
But, as always, just because you can, doesn't mean you should. Just because it works, doesn't mean it's right.
"How Target Figured Out A Teen Girl Was Pregnant Before Her Father Did "
https://www.forbes.com/sites/kashmirhill/2012/02/16/how-targ...
fyi I work at Google but not on Ads.
However, I do think there is an inherent creepiness involved in the amount of tracking involved to achieve that level of targeting. Normally, as a person who is not terribly privacy minded, I'm not thinking about this tracking that watches everything I do. That is, until I had an experience like the top comment. I ripped the mic out of my Amazon FireTV remote that day. It made me uncomfortable that my conversation left the room without my knowledge or consent. (I realize this was Amazon, not Google, but they all do this sort of thing.)
Edit: I think ad targeting has to achieve a delicate balance of serving potentially helpful ads, while not alerting the target that they are part of the Matrix.
It is a great ideal but this narrative is pretty much anti HN sentiment on Ads.
Moving all of the tracking and data sharing server-side means there is nothing you can do to stop it other than simply not visit sites that use it and even that isn't so simple because how are you supposed to know if they have implemented server-side tracking other than maybe a vague mention in the ToS or PP?
They may not use it for nefarious reasons (one can argue if unwanted targeted ads is or isn't) but that data may leak either directly or via a 3rd party who purchased it.
Then you have a situation where you have all this product and personal history which could be embarrassing and be used for blackmail.
Can you delete this data? Do you know everything they are tracking?
Someone else said it best, this is a cyber stalking industry.
For getting good targeted ads, you need to know a lot about targets. And that knowledge can be used for other things than just selling ads.
It can be used by politicians to target specific groups, it can be used by scam artist to get access to more susceptible people. It can be used by business, like payday loans, cc companies, lotteries, etc. to target people that are in already bad place, to dig a hole even deeper (and that already happens today). It can be used to target people who are whales in one microtransaction whatever, to spend on some other etc. It can be used by bad governments to target people with specific viewpoints, smear campaigns, find dissidents etc.
They all need same kind of data. And even if you collect that data for one purpose today, doesn't mean it cant be used for something else in 10 years time. Just because Google might not sell that data right now, doesn't mean it wont in the future.
I would have a lot less problems it it was just ads, but it's really not.
People don't like it - people don't like that form of targeting. It may not be clear why they have issues with it, but they do.
At my kids school, if someone is repeatedly doing something to you that you don't like, then it is classed as a form of bullying.
If someone at your kid's school told you that the teacher repeatedly made them do homework, would that be bullying? Of course not. Just because some people don't like targeted ads does not make it antisocial. You just don't like it, which is fine. Don't read the email.
By the way, I may or may not have placed a bunch of hidden cameras in your house. What's that, antisocial? No, no. I swear it's going to be convenient for you. You may get a disturbing email from a company I sell the footage to at some point, by the way. Just don't read that email, ok?
I'm not arguing that all data collection is ok. I'm just arguing against the point that all data collection is not ok.
Well, I also do my Internet browsing from home. What are you doing in my house with your ads and trackers?
Adtech industry is stepping on quite a lot of norms indeed. Not surveilling people in their homes is one that's commonly violated. That a HTTP user agent is free to interpret and present the response from a HTTP server in any way it (and the user) sees fit is another, this one frequently fretted about, and users are being bullied over it.
(Another one would be consent - this one got enshrined into law in the EU. It annoys adtech people so much that they deploy every possible psychological manipulation trick to deprive users of their agency without crossing the legal line - and quite often with blatantly illegal practices. When confronted, they try to shift the blame for their techniques to regulators who are "forcing" them.)
I do respect you for telling people here that you work for them, though. I just hope you will ask yourself every now and then if it still feels ok to do so. That's often a pretty good indicator of whether or not it is ok. Sometimes a better indicator than the law, even.
In a world with personalized advertising, you can avoid those ads forever. In mediums without personalized advertising, you can't watch a sporting event without seeing a beer ad.
Then again, personalized exclusion opens the door to many types of discrimination - like not showing job or housing ads to people with certain traits.
All that to say, the tech can be used for both good and evil. It needs to be managed by regulation, and not by technical feasibility.
Alas, this is not how the real world works. Everyone on the advertising side has an incentive to exploit my weak sides, so I can't trust advertisers in general. And so they spy on me, and I'm desperately trying to protect myself.
Your hypothetical reality is an unstable equilibrium. Our actual reality is a stable one. So even if, by some miracle, the stars aligned and the hypothetical suddenly became real, it would very quickly degenerate into our current reality. "In paradise, the first one to pick up a stone becomes Genghis Khan", and all that.
So, in conclusion, adtech industry needs to be burned out by regulatory means like the cancer it is, until what remains can be reshaped into a construct that provides value to the society.
The regulation people want, such as even stronger GDPR, is effectively almost a technical feasibility block on these things. Any other attempt is always going to be behind the technology curve and thus significantly less useful. Moreover politicians will add in exceptions for their top donors and friends. This is harder is regulation that doesn't get into deep weeds.
Unfortunately most other arguments against targeted ads don't have these properties and just restate the arguers convictions in various ways, with increasing levels of anger and certainty.
Here's how I think about it though. Targeted advertising allows some businesses to exist that otherwise would not exist. In order to justify banning it or labeling it as unethical, we should show that there is some harm done that outweighs the benefits in terms of job creation and innovation. So far the examples of tangible harm I'm familiar with are rare and far less in magnitude than the value creation enabled by targeted advertising. What's more , all those harms can be mitigated, and it's in the best interest of large advertising platforms to mitigate so they they have better products. That's why Facebook and Google have spent more on basic research into privacy preserving computation and analytics than any other company.
It's not that all targeted ads are bad or good. It's that we can make them good and keep the benefits without any of the harm. I don't see examples like "I got a personalized email" as inherently harmful, so I'm looking for justification specifically for beliefs like that one.
Unfortunately it also funnels billions of dollars into hate sites ($2.6bn+ in the article I saw last week)
It also funds schemes like this that may be technically brilliant contribute little to the web, and extract money from advertisers without giving much back
https://mobile.twitter.com/TedFrench/status/1425414187455496...
(buy's old domains names with good ranking, recreates the site, rewrites the content to boost it's ranking, runs ads and then sells it)
"I’m far from a copywriter, but the content added was informative & above everything else, answered the search query in full. I can blitz out 10k words a day of garbage content easily, but it’s worth putting in extra effort and writing better content, even if there's less of it."
This isn't an example of somebody taking advantage of ads to scam anyone. Maybe you disagree, but my take is that this is a legitimate business that provided real value to it's users and happened to use some gray hat SEO to grow.
> Targeted advertising allows some businesses to exist that otherwise would not exist.
That's true, but in the argument, it carries the implicit assumption that those businesses existing is a good thing. But this is often not the case. Plenty of businesses exist only because they can dupe enough people with hyper-targeted ads.
More importantly, though, advertising is an ecosystem. Companies buying ads are only part of the money flow. The more problematic part are the companies showing those ads. There you can find many[0] examples of companies that should not exist, and yet they do, because there's money in showing ads. Those companies always have some kind of bait to lure viewers onto their sites, where they'll be subject to ads. Because of the ad money, those sites displace legitimate efforts that try to provide actual value in the same space the ad-powered sites just use as their bait.
It's a long topic, and this is just one small aspect of it.
--
[0] - In my personal opinion, it's vast majority of sites displaying ads.
How about neither?
It is not a 1:1 replacement for tracking pixels and lacks some of those creepy features (you're unlikely to get tagged if you simply browse a website without giving up any personal info), but it offers new ones as well (the ability to send arbitrary data to an ad platform).
It would be a remarkably narrow law that made it illegal to do something client-side but not server-side. AFAIK it's usually about what data you collect and how you use it, not precise details about how it was collected and stored along the way.
Server-side allows businesses to defer the data transfer until it's known whether specific consent is granted or revoked. It also allows you to more easily keep a record of the data shared with other parties in the event that a user withdraws prior consent or invokes a right to be forgotten. You then have the ability to tell your partners to also delete those data points.
Due to cross-site “third-party” cookies being disabled in modern web-browsers and the HTTP Referer [sic] header being unofficially deprecated the only way for websites and ads to work together is by either IP address tracking or visitor fingerprinting.
IPv4 address tracking is a blunt instrument that is next to useless when visitors are using ISPs with CG-NAT. But IPv6 makes every device addressable - and thus - followable. I imagine that eventually CPE (home internet modem and router) will offer some kind of IPv6 address randomisation system on a per-TCP-connection basis, though they’d all share the same 64-bit prefix (I think?) so it doesn’t mitigate per-residence tracking.
(EDIT: Ah, so IPv6 does have privacy protection by rotating autoconfigured addresses on a regular basis: https://www.internetsociety.org/blog/2014/12/ipv6-privacy-ad... )
————-
I do believe the end of third-party cookies is going to make internet advertising significantly less profitable and more and more ad-funded sites will either add paywalls or shut-down.
I’m surprised Google went this way, actually - I’d have thought a less-harmful way of protecting users’ privacy with balancing the need for attribution in advertising could be accomplished by, for example, auto-nuking cross-domain cookies after 24-hours.
Do you _really_ thing the OP didn't know that???
I'd say it's pretty dang official now: https://digiday.com/marketing/cheat-sheet-google-extends-coo...
Don't forget the actions of other browser-vendors too, like Apple's Safari and Mozilla's Firefox, both of which have severely curtailed third-party cookies - and Google Chrome's Incognito mode also disables all third-party cookies.
> They just kicked the deadline forward another year or two while they test out alternatives.
Right, but the deadline still exists.
For the ad platforms, this lets them optimize their ads for better performance when they know which user profiles converted.
For advertisers, it's used for directional guidance on the platform, e.g. ad campaign A converts at 3x the rate of ad campaign B.
The famous quote in the industry is "Half the money I spend on advertising is wasted; the trouble is I don't know which half." This method gives you a better idea of which money is wasted, at least compared to something like a TV or a print ad.
It gets more complex when you're advertising on multiple channels. For instance, if you see an ad on FB, Google the product, then buy it, both will take credit for a conversion even though your business only had one sale. There are more scientific methods for modeling advertising results from multiple channels [1], that leverage control groups (say you run a Google ad in New York and a TV ad in California and monitor which market sees a bigger spike in sales).
The reported ROAS is all over the place on FB right now. It goes from previously 1 = 100% return on investment. Now it sometimes says 10X numbers like 70, which I assume is of the data they could measure 70% roi.
It seems to 'automagically' combine the offline conversion data with standard FBQ but I have no idea the match rates for the server-server data I send in and also importantly if it de-dupes.
I've tried to experiment with voting data in the past, I want to try that more this election. Run get out the vote ads and optimize for actual early votes.
Wait. Whose data is it, Google?