GTM is still GTM and can be trivially blocked; the container itself isn't moving server-side.
It's just gained the ability to proxy data to third parties instead of needing to load scripts for every tracker. This is better for performance, and should be explicitly in control of exactly what data is passed on to where.
All you really lose is the ability to block a subset of analytics scripts selectively.
Essentially I don't understand how possibly could free adblocking lists defeat advertisers or trackers if they truly cared about them: simply have a system running with the latest adblock lists against their test site, and if it is able to filter them, have an engineer make a modification—or have the system automatically pull up a pre-made modification or even generate a new one. In addition, the content-driving JS and the site JS could be bundled in one and obfuscated.
Best functioning filters are secret ones and thus only the technically minded minority has access to them.
ITP, ETP, and plugins that can block requests based on heuristics will make pretty short work of this. In Chrome, come Manifest v3, plugins won't be allowed to.
So... this is all uglier and more complicated than I thought.
Self-hosting by itself might make blocking marginally more difficult, but there are other reasons to do it:
- Browsers these days segment caches by origin, so there's no caching benefit to using Google as a CDN.
- With HTTP2, a first-party request is likely to immediately go through an existing (multiplexed) connection, saving a handshake.
- It's arguably better for privacy, as users and legislators seem to be concerned about links to Google leaking IPs (https://news.ycombinator.com/item?id=30135264).
Not when the script sending data to the server side GTM is a first party one.
I think the key thing here is that ad/tracking blockers often rely on domains or requests being 3rd party. In the past it was more work to hide the 3rd party trackers as 1st party, this makes it easy so its more likely to happen now.