Reddit uses “reddit.com” itself as the endpoint for logging usage data
twitter.com
twitter.com
The ways most sites utilize AJAX and JS, there is just no consistent way to block "tracking calls" vs. blocking requests needed for particular pieces of functionality and data.
I also close the tab if I'm presented with a paywall, a modal newsletter subscription prompt, impossible cookie banners, etc.
I think of it as a "the medium is the message" type of thing, and if the medium is tainted then the message can't be any better, so why read it?
At some point, browsers will gain firewalls and packet inspection and filtering capabilities.
We should be able to inspect the data sites are sending and receiving asynchronously via Javascript. We should be able to automatically delete or redact private information from JSON payloads. What if uBlock Origin could automatically anonymize unique identifiers that some Javascript code is trying to exfiltrate?
This will always be a cat and mouse issue, and unfortunately right now most of the authority is on the server side. The data-driven web that TimBL envisions is just not profitable enough and content has to be heavily intertwined with distractions and trackers to monetise us cattle. See RSS.
Just like if I visit someone's house, I trust them to not look through my bag while I'm not looking, even though they easily can.
And when that trust is gone, it's pretty much gone for good, just like if I go to a venue and find out they rummaged through my coat pockets, I'm not going back.
Maybe not everyone thinks this way, but I sure do. I consider an untrustworthy website to be tainted. It is unlikely to produce enough benefit to outweigh whatever they may be getting up to, whatever it may be. And the sooner I cease investing time in it, the quicker I can find a new alternative and begin building trust with them.
3p tracking masquerading as 1p is here already. Ex A: https://github.com/SukkaW/cloudflare-workers-async-google-an...
DNS-based content blocking was always trivial for trackers to bypass. Deeply integrated plugins like uBlockOrigin in Firefox are the only way out. With "Manifestv3", Chrome's making sure that even that level of integration may not be enough. 70%+ of the 4.5B internet users use Chrome.
For mobile apps... well, the writing is already on the wall.
> I generally assume that whatever website I am on would have a good sense of what I am up to just based on server side logs.
True. We can't stop the site from logging HTTP requests.
Maybe we can find a way to poison that data set though. What if we had a custom reddit client that generated random traffic to random subreddits in the background? Maybe that would pollute their logs enough that they can no longer build an accurate profile out of it.
> if I block 1p logging they might not have a down to the second understanding of how long I am impressing on something
Good. I don't want them to know. They should remain in perpetual uncertainty about whether their mindhacking methods are working.
not exponentially
Say it with me so we can normalize this usage
In any case what year was AI adblock attempted so we can check if this is one of the narrow use cases where exponential performance improvements occurred within computing
“Orders of magnitude” will be more frequently correct and also include “exponential”, whereas “exponential” will be less frequently correct
We don't know that the growth was n^x and not x^n.
Imagine having smart glasses which seamlessly filter out product placement in movies, sporting events, even the ads in the real world. It's a dream come true. Our reality can finally be clean again.
When I sometimes come across ads anyway, they seem like children stories or cartoons...
I don't want them to succeed. I want them gone.
Only then will the web change.
Nothing wrong with simply not wanting to see ads either. They're noise, to be filtered out.
And no, these are not their own ads, they proxy the requests from their own domain to the Yandex Direct ad network. Even worse, there is some evil javascript that tries even different non-sensical HTML element names to try to get past the blockers.
McDonald's ad? Replace it with a McD's Roach Sandwich ad. Facebook ad? Replace it with "Zuck causes Genocide".
We can fight back.
Visible impact on page: empty right sidebar
Blocked requests:
- https://mc.yandex.ru/metrika/watch.js
- https://counter.yadro.ru/hit?unique_data_here
- https://yandex.ru/ads/system/context.js
Actually, it makes me wonder what's keeping these companies that want to serve ads generate JS dynamically server side and include the code for ads in the same file as the main application logic. Then, when you'd block the entire file from downloading because of it containing ad logic, the site would break, so viewing ads would be required to use the functionality.I do feel thankful that toolchains like that don't seem to be in widespread use yet.
First reason is the lack of trust. Or limited trust, if you prefer. That is, SomeCompany may trust AdProvider enough to include their ads in its website, but then again not trust them enough to bundle random external code with their own. Letting the user's browser load from different origins does give you some separation.
Then there's the separation of responsibilities. Say something does break -and not because of blocking-, having the code bundled together makes it very easy to start a game of passing the blame. "It works for us", "We're not doing anything weird", etc. And not only that. There's also the question of who pays for that downtime. SomeCompany is kept from earning money, will AdProvider compensate them? SomeCompany'll probably need to provide evidence that the problem comes from AdProvider.
On the other hand, some websites may already be doing a very similar thing... though it's likely just accidental. I mean, I have experienced a fair number of websites breaking when googleanalytics is blocked and I'd bet it's not intentional, just bad programming.
Well one thing webmasters can do is place wrap an image in an <A> element and the URL is some affiliate link that they control. Good luck blocking that since the image is the first party domain. It's a tactic I've been using for years now, and I've gotten thousands of referrals and confirmed purchases of products.
What website(s) do you run so I can make sure never to visit them?
Of course, my adblocker will still block it, using the block element feature (also useful with nag bars etc).
That sounds great to me; it means getting cross-domain tracking to work would be much harder. Hopefully that means we'll also get ads that are actually relevant to the page instead of random unrelated stuff.
Using a third party for analytics is only a convenience. Given enough effort, any system can build in their own analytics. It's probably just a proxy to something like Segment.
It wasn't until that data became intricate user interactions that were bought and sold, did we worry.
edit: So I guess that gets to where my surprise comes from. I expect first parties to gather all kinds of info about how I use their service. It's even fine. I literally signed up for it.
The next step is to examine the TOS (in this case: Reddit) and see what I agreed they're allowed to then do with that data. ie. sell it so others can sell to me.
Honestly a lot of analytics for an app can be done serverside and client side is just icing on the cake to make the data richer.