The IAB loves tracking users but hates users tracking them
shkspr.mobi
shkspr.mobi
It seemed to be completely obvious to me even decades back, that the + scheme would be trivially parsed and reversed.
So I don't use it and just keep on making completely new aliases. So amazon gets amazon@example.com. If I'm not going to pay for anything on this account it also gets a random name from a random piece of well known media, like "Donald Duck", and all the data filled in randomly to ensure that it's not googleable, and doesn't correlate with any accounts anywhere else.
The bigger issue I see is the desire to link everything to a phone number. Even stuff made for privacy, like Signal.
I’ve had quite a lot of third party junk mail with this kind of stuff on it over the years.
Yep, I've had my youtube account since before Google bought youtube in 2006. Just this week I noticed that I am no longer able to put URLs in the descriptions of videos I upload to youtube. I have to "verify" by giving them my phone number before any clickable URLs are allowed in descriptions. But apparently all URLs are clickable URLs. Additionally, even videos I uploaded in 2008, if I go to edit their descriptions now and I originally included a URL, I cannot submit it.
Phone number "verification" is nasty. I suppose this is the end of my almost 2 decades of using youtube to host videos.
As for email spam prevention, I've run my own mailserver with a domain since 2011. I give each service an actual unique email address and then just catch-all emails sent to my domain. It works great.
> to put URLs in the descriptions [...] Phone number "verification" is nasty
Spam is a huge problem for any large platform with free accounts, and there aren't a lot of good options to prevent it. One set of mitigations is around increasing the cost of an identity. Email addresses are infinite and free, but working phone numbers are limited and usually cost money. So gating spammer-desired activities on phone numbers makes sense from their perspective. They could get a similar effect by requiring a credit card number, but people hate that even more.
If you'd like to work around this, I'd suggest getting another number for just this. Google Voice will give you one for free, and the Burner app will do it for $5/month if you sign up via web. Or in my case, my ISP gives me a free landline number with my internet service, which is great for this sort of thing.
In many parts of the world, getting a phone number requires recording your government ID with the carrier (and burners are illegal, though usually for the carrier not the consumer), so the calculus then becomes “to prove you’re not a spammer, give up everything about your identity that was or ever will be known”. Which, no.
(There’s a reason why Russian democracy activists are divided between a “use Signal, everybody else is dodgy as all get out” camp and a “fuck no, don’t use Signal, doxxing you will be slipping $20 to a random SIM card salesman” camp. But parts of Western Europe are the same, and some are even ahead on e.g. unavailability of anonymous stored-value cards for transport or mandating testimony against yourself wrt encrypted storage.)
1. Despite this, spam thrives on Google.
2. What happened to using AI to fight spam? Trained and intelligent humans can discern spam without knowing identity.
3. This still won’t prevent other email providers sending spam to Gmail.
4. Safety is often used as justification for more $$$.
Because there are two independent components to such a system: {increase cost of identity} + {protect privacy of identity}
When it's offered/justified to combat spam... the implication is that the solution will deliver both promises.
In reality, the first (concept of identity) gets built, marketing/sales realizes they can abuse the hell out of it for their ends, the second (privacy protection) gets overruled at the VP/C* level, and any privacy protections are quietly never implemented.
This happens again. And again. And again.
Google is probably the best case ethical scenario here, in regards to having standards around privacy data stewardship, and even they abuse it frequently when the profit is too large to ignore.
The only reasonable takeaway is that any system that permits mass tracking is too dangerous to privacy to allow to exist, and all should be opposed.
Or, as GDPR does, render companies liable for omissions from a privacy perspective.
The most ridiculous part of this phone-verification BS is that many companies (e.g. Twitter, Discord) let you create an account without it but will then demand a number at some point later. This only hurts real users because spammers can just switch IPs and create a new account that they can use for a while.
> Google Voice will give you one for free
And what information do you have to give Google for that number so that you can avoid giving your phone number to Google?
Beyond the moral argument, it’s easy to be in a situation where you get locked out because you no longer have access to a temporary phone number etc.
Heck, if I wanted ethical purity, I wouldn't be here contributing free content to YC. But I think the net good outweighs the net harm, so here I am.
> 1. Some people do not own phones, or do not wish to provide you with their telephone number when asked. Do not require a user to provide a phone number unless it is essential, and whenever possible try to provide a fallback to accommodate these users.
What a bunch of hypocrites.
And note that a phone number is the number for calling a telephone, not some jumped-up pager. They want a mobile number so they can send you SMS messages. I hate SMS, and I deplore it's use as a part of any kind of security protocol.
If you don't intend to speak to me, you don't need my phone number. If you do, then my (VOIP) landline will serve you fine.
I would amend that just a little: If I don't intend to have you speak to me, you don't need my phone number.
Is "your policies must be fully consistent with any advice given in any of your open source repos" really a standard we should hold big companies to? Because if we treat open-sourcing a text file of recommendations as the company making a statement or commitment to that effect, companies will be way more limited in what they allow their engineers to make public this way. With chilling effects that go beyond semi-humorous recommendations. ("Do you really want to try to open-source this library? You know how frustrating Legal and PR can be to deal with...")
I don't think that term means what you think it means.
What I'm trying to say is that there is a thing that is positive and we'd like to see more of (companies releasing things as open source) and there is an adjacent thing that we are considering pushing back against (companies including things in their repos which conflict with their actions). While it should be possible to discourage only the latter, in practice the effect would spill over to the former.
Youtube pivoted from "just" hosting videos to a community though, to the point where you won't get any views unless you are on youtube and play by their rules and network effects.
Where it gets hairy is when you want to do live streaming…
You can have all the bandwidth in the world, but the magic that Youtube does is mainly dealing with the users' bandwidth, for example, it switches video resolution on the fly when it notices that frames are going to have to be dropped soon.
linux?
a $5 vps running any webserver and an sftp client on your phone will do.
As a user I can only hope that more people do stop using YouTube, preferrably choosing something that serves video files directly instead.
> As for email spam prevention, I've run my own mailserver with a domain since 2011. I give each service an actual unique email address and then just catch-all emails sent to my domain. It works great.
This works but only because running your own mail server is too uncommon for anyone to care about. If it was more common, the advertisers or other privacy violators would specifically check for catch-all domains and then strip the entire local part of the email for your user id.
This way dropping the suffix drops those e-mails in my spam folder. Them normalizing the address makes my spam filter more efficient - and I would like to thank them for it.
I'm sure there's a lot of "underground" data transactions happening where the source of data is obfuscated.
If you have a Facebook account, and live in GDPR-land, go check which companies illegally passed on your data (https://www.facebook.com/adpreferences/ad_settings -> Audience based advertising) and report them!
And of course with such a small fine it's basically guaranteed they will continue breaching it since it makes them way more money.
These days I host my own mail server and use . as the sseparator, which has been working well for years.
Although a trick could be if you setup your service to run "service+username@example.com" then depending on how they implement their normalization, they'll chop off the username for you and track themselves.
And it still has the advantage that I can remove an alias and it's not obvious what the main account it leads to is.
And what kind of centralization are you talking about? Sharing it with other companies? I'm as pessimistic about these things as they come but even to me that seems incredibly unlikely.
If you do something obvious like use amazon@example.com at amazon, you should expect them to add a rule that blah_blah_anything@example.com gets cleaned up to "@example.com"
It seems like a very error prone thing to do automatically, while reaping little in return for the effort. How much do advertisers stand to gain by adding special case heuristics for "people who might be using an unshared email domain with a per-site local-part?"
If I give my email as me+amazon@gmail.com, normalizing it to me@gmail.com is just applying a bit of common knowledge about how an email service with billion(s?) of users handles the + sign in the local-part of an address. It's a carve out, but it's totally deterministic (for Gmail at least) and applies to a lot of users.
If I give my email as amazon@2d0d4809.com, normalizing it to @2d0d4809.com involves guesswork about that specific domain. I don't think normalizing away the + sign in the first case implies we should expect the latter to get normalized into a single identity as well.
Of course if you have "@gmail.com" that's not going to have any value vs the identity-validated alternative. But at the bargain bin end of the ad selling universe does "amazon@2d0d4809.com" that has never been seen anywhere except amazon have more value than "@2d0d4809.com" that has been seen recently in a handful of other places consistent with use by a single person? It's obviously not an identity-validated ID class, so it's not going to demand identity-validated bids. But having a tracking history might add a tiny bit to the bid. So I wouldn't put it past people to use that rule.
So it doesn't really matter much whether I go with amazon@example.com, or john.random@example.com.
To deal with that for good you'd need a pretty large set of domain names to use for this purpose.
I’ve been using my own domain since the late 90s, and I’ve never run into this.
Which is all kinds of ironic, because I'm old enough to remember when free emails like hotmail.com and gmail.com were rejected by a lot of sites!
I guess maybe that edge case is not nearly as bad for the advertisers as failing to link the same person, so it's tolerable?
However it appears the IAB UID2 README says to only normalize pluses/periods for gmail.com addresses: https://github.com/IABTechLab/uid2docs/blob/main/api/README....
Periods are more of a Gmail-specific thing, but as you mention merging two people once in a blue moon is not a terrible price to pay for an analytics system, it’s not like it’s going to send mail to these addresses.
We do support your own catch-all subdomain, but that is just to cover the use case of having to come up with an email mask on-the-spot. If you are filling in a web form, best to use an email address that looks exactly like the email addresses of other Relay users.
I was expecting to see that, too but in more than 15 years of running my own mailserver i don't think i have had an attacker that has removed the suffix when trying to phish me. These attacks are automated. Your address is just one of many that is being harvested and sold to someone else who conducts the phishing campaign.
The problem with most of those tricks is that they can be countered in some way, so I feel this is one of the areas where your security has to rely to some extent on obscurity (or the fact that it's too rare in the wild to be worth countering).
But I do have a question, have you found a programmatic way to create aliases / a provider that offers an API for that? Because that seems like one of the main usability downsides to your approach.
Some clients will display the "raw, as received" email if you ask them too. GMail has a "Show Original" menu item for example. In there, you will find "Received: ... for <XXXXXX@gmail.com>". The exact form does vary between systems, but it's almost always there.
That it also prevents ad tracking is even better.
I have a throwaway SIM for that
However, there is none of that. Just that the IAB does not want to make it easier for users to escape their tracking (which, given their purpose, is unfortunately entirely expected). What justifies "But it hates users tracking them."?
It's quite sad to see. It's also the reason I'm using somethingunique@domain.tld;, if cyberstalkers start normalising to a domain, they'll only hurt their own business.
Often enough the content is there but just hidden until the JS loads for ... reasons, idk.
Defeatism here helps noone.
I guess that's the nefarious explanation, but there's a more benign one: if you want to correlate user behavior, you need some sort of normalization, otherwise john.doe+apple@example.com and john.doe+amazon@example.com would show up as different "people" and cause match rates to suffer. Sure, getting tracked isn't great, but it's not exactly the hypocrisy rage-bait that the OP is implying.
But if you think that will happen I have an East River transportation startup in New York that is seeking an angel investor.
So you want to keep cost per impression up. You would not want to saturate and devalue.
Better to play 10 ads at 10c each vs 20 ads at 4 or 5c, as high ad load impacts users propensity to return to the service.
In a logical world, yes.
In a capitalist world, that revenue target goes up every year. Apple became the richest company on earth selling hardware, yet here they are now drowning their software with ads.
So would I; they're disfiguring ugly.
So would you ban shop signs? What about a shop-sign that simply said "Cafe"? Or "Meals"? That would be the end of chain stores (which I would not regret).
I don't mind shop signs; I do mind posters all over the street-scene.
The Post Office delivers about 4X as much unaddressed junk advertising pizzas and estate agents than real mail, and I object to that. In this country (UK), anyone can stuff whatever junk they like in your mailbox; in the US, I believe only USPS can put anything in your mailbox. Are USPS allowed to deliver unaddressed pizza fliers?
The best argument in favour of advertising is that it makes it possible for a new entrant to a market to make an impression; without it, markets would always be dominated by incumbents, give or take the occasional surprise. I don't know how to capture that benefit, without ending up with the whole world covered in billboards.
> The best argument in favour of advertising is that it makes it possible for a new entrant to a market to make an impression; without it, markets would always be dominated by incumbents, give or take the occasional surprise. I don't know how to capture that benefit, without ending up with the whole world covered in billboards.
I don't think that argument holds much water as ads require a big capital investment. The main reason new entrants need to advertise is because the incumbents are already advertising so you neeed to compete there just to get back the base level of engagement.
Where? I use Apple hardware basically exclusively. Are they that good in hiding the ads, or are you exaggerating a bit?
- App Store (biggest offender)
- Apple News
- Stocks
This year they'll be rolling them out into Apple Maps as well.
In practice, it's not of course, but that's the answer you'd get if you ask them.
There's a reason these things are opt-out rather than opt-in.
The answer to marcus0x62's question - why would a person want advertisers to correlate their behavior - is that they wouldn't, and if they want to advocate for their own self-interest they should install an ad blocker.
Nobody asks for the steak’s opinion when planning a BBQ.
They don't, which has been shown in studies. What has been shown is that showing the same things people already bought give people regret which increases total amount of purchases.
In other word, the goal is to not to give users a good experiences watching ad's. It is to make them buy more, which is an orthogonal goal.
Govt: “I need IP addresses, ideally cellular and known public wifi, of a person using this email address”.
Data broker: “Here’s the list including the most recent cellular IP address associated with that person at this timestamp and their most used public wifi locations.”
Govt: “Hey, cellular provider, where is this subscriber right now?”
Provider: “Here’s the lat/long, last seen 1 second ago. Happy hunting!”
>Sure, getting tracked isn't great, but it's not exactly the hypocrisy rage-bait that the OP is implying.
That in and of itself is nefarious.
Ultimately they cannot win this fight.
Users can tell which site gave away their email address by using the variants discussed. It's not tracking in the same sense, but it does allow tracking who respects privacy. It also allows throwing away junk mail where someone required an email address just to (for example) make a sale or use their wifi.
The reason my email address for this site is `+ycombinator@...` is that I can track when dang decides to go rogue and sell my email to a Nigerian Prince.
Think of it like sousveillance.
Even some big companies aren't immune to a dodgy contractor walking off with a contact list.
Then when you receive spam/unsolicited marketing emails, you can see to which email the spam was sent, and therefore which company sold your data.
This suggests the only way to keep this behaviour is to have your own email hosted and use a truly different email per service.
Nothing, I think, since there’s no indication the normalized email will be used to send email.
The normalization is for connecting together identities against the wish of the user, which is a different issue.
Wow, that's pretty scummy behaviour! I wonder what the rationale is behind this?
People are constantly trying to use any service for illicit purposes. A somewhat-easy way to deal with that is to just ban them. Because an email address is used as username and an email address usually maps 1:1 to a person, this means you just got rid of a Bad Person.
This breaks if access to new email addresses is trivial. You now have to invest actual effort into validating that a new account isn't someone trying to do bad stuff.
Or you can just block all the services providing easy access to email addresses and outsource the issue to big providers like GMail and Apple. It's a lot less effort, and you'll lose near-zero legitimate customers...
I'm not inclined to give any service the benefit of the doubt here until there is some evidence that Apple emails are indeed being used for this purpose. I haven't seen any such evidence (but I'm open to it).
For others a domain, a mail provider works best with catch-all.
This sort of "normalization", being both just plain evil and just plain stupid, is grounds for me to never touch a system attempting it with a 10 foot pole - and grounds for me to apply the same treatment to such a system's creators. If you are simultaneously too evil and too stupid to understand that email address normalization is a horrible idea that should never ever be done, then I want nothing to do with you. If you think that comes across as rude and uncivil, well, so does mangling the email address I supply (and violating multiple IETF RFCs in the process) for the sake of surveillance and spam.
Meaning that I get spammed with AARP ads everywhere I go because my email address gets "normalized" to be the same as Grandpa George... and we both get spammed with Bad Dragon ads everywhere we go because both our email addresses get "normalized" to be the same as Dildo Daddy Dave.
Fuck that and the horse it rode in on. Targeted advertising is a blight on society.
I agree. But I doubt they care.
I still get some spam. It's totally mis-targeted. Currently in my spam folder: Ads for edible oil can filling equipment, and for ammonium sulfate nitrate fertilizer from China. I don't farm.
Spammers just don't seem to bother with targets not tracked by Google and Facebook any more. It's an upside to the ad monopoly.
"Not on facebook or google... must be a farmer"
Works great with Bitwarden's new username generation feature. I can create new accounts in a push of a button now.
# Account sorting set "domain_name" "acct.ninja"; if address :domain "To" "${domain_name}" { if address :localpart :matches "To" "+" { set :lower :upperfirst "addr" "${1}"; set :lower :upperfirst "subaddr" "${2}"; if not address :domain :contains "From" "${addr}" { fileinto :create "SPAM"; } else { fileinto :create "INBOX.Accounts.${addr}.${subaddr}"; } stop; } elsif address :localpart :matches "To" "*" { set :lower :upperfirst "addr" "${1}"; if not address :domain :contains "From" "${addr}" { fileinto :create "SPAM"; } else { fileinto :create "INBOX.Accounts.${addr}"; } stop; } }
What does HN say, do we trust them for this?
It displays this caution twice:
"Note: this choice may limit your ability to access ad supported content."
> UID2 is a framework that enables deterministic identity for advertising opportunities on the open internet for many participants across the advertising ecosystem.
Can we get stochastic therapeutic benefit from watching them thrive as a tight knit community in cutting edge plexiglass dormitories, please?
There's a reason these people live in gated communities and don't let their kids use their apps.
Given the turmoil that the "Elon Jet Tracker" created it seems like tracking still pisses these people off despite their wealth and gated communities/etc.
Time for trackers for pro-tracking execs, politicians and incompetent regulators (such as the previous head of UK's privacy regulator who did zero substantial enforcement during 4 years of blatant GDPR breaches, or whoever is heading the corrupt Irish DPA who's in cahoots with Facebook)?
All bills which gather or correlate data must be applied such that their provisions first be applied to legislators.
Or something like that
Email and phone number matching is part of their core service offered by Oracle’s Bluekai, one the largest data-broker platforms in the world [2]. They have most large global companies using their platform.
> You can convert users' email addresses and phone numbers to SHA-256 hashed IDs called oHashes and send them to the platform. They will be synchronized with the network of user profiles that are linked together in the Oracle ID Graph, which is used to manage IDs and user attributes for all Oracle Data Cloud platform customers.
> This synchronization optimizes the targeting and communication of your users across desktop and mobile devices and media execution platforms. oHashes enable you to increase your offline to online match rates, connect your Responsys platform to the Oracle Data Cloud platform, and execute cross-device targeting.
…
> the [normalization / oHash] function enforces UTF-8 character encoding, lowercases all characters in the email address, verifies that it has the “@” symbol, and removes all special characters, punctuation, and spaces.
…
Both Google and FaceBook also expect clients to send phone + email (hashed) to build retargeting lists from customer data. They each have a different name for the feature [3]
[1]https://twitter.com/WolfieChristl/status/1288467207333318656...
[3] https://twitter.com/WolfieChristl/status/1288252803341783041...
[2]https://docs.oracle.com/en/cloud/saas/data-cloud/data-cloud-...
You need one to use Play Store on Android. At least I think you need a GMail one. Even if not, the Play Store and the Android OS itself make it seem like you need one, from the second you turn a brand new phone on. The funneling is quite heavy here.
(Heavy enough that almost everyone in my family uses a GMail account mostly just for the Play Store. My wife and I pay for Fastmail, some of other members of my immediate family have primary e-mail with a local free mail provider, but everyone found it easier to use an old (or make a new) Google account with their Android phones, instead of figuring out how to make it work with non-Google e-mail.)
This greatly confuses the Gmail and Outlook web UI but the accounts work.
FOr example, amazon@mydomain.us, nytimes@mydomain.us, citibank@mydomain.us, etc.
I have done this for years, but now gmail recipients are rejecting my email as spam. (I've gone through multiple iterations with the DNS configuration at the host, but fundamentally the IP address is tainted other customers on this provider using it to send spam. I shouldn't have to fork up for a dedicated whitelisted IP address just to get functional email). As a result now I have a dedicated @gmail.com address just for those folks and businesses.
I'm surprised the world, and most especially the tech community, embraced gmail so quickly. Yes, it's a great interface, yes, it's free, but from the start they said they would be scanning content and collecting infomation from email content. WHy are we OK with that?
It used to be even more comfortable using the "virtual identity" extension its author gave up maintaining it after Thunderbird 68
Sometimes I wonder if Mozilla don't realize of what their extension API redesigns are costing the world or if their just don't care...
The specific user who responded with "we thought long about this update and ultimately as it stands today it is not a change we would like to add" uses their @users.noreply.github.com email for Git, but their employer and hometown are public on their profile, and a quick search gives you the mail address. While I live nearby, I don't intend on paying them a visit, plus it seems to be a shared office highrise, but I might just write them a strongly-worded letter.
Additionally as others have mentioned I'd imagine a lot of websites who do permit these addresses are already "normalizing" the address anyway and storing that instead
This is not a gmail trick. It has been in common usage at least since the very early 90s (but may predate that), it was a fairly universal convention.
This means that anyone who registered an account with a + address could no longer access their services. Hope nobody forgets their password for that one critical service that doesn't let you change your email address!
hn@foobar.com, github@foobar.com, twitter@foobar.com, homedepot@foobar.com, etc.
I currently use Protonmail and have been very happy with them, though I’ve been eyeing Hey!.
It’s so easy to add/filter/map/organize many domains/aliases per account.
And they allow arbitrary rules for processing incoming mail, so you can use characters other than the plus sign. And you can also take addresses that have been compromised by spammers and route them right to your spam trainer, so that spammers help improve your defenses.
I don't relish the prospect of getting tons of mail to <random-name>@mydomain. I do actually check my spam folder; I'm afraid that if I used a catch-all, that would become impractical.
I have aliased all the email addresses I know leaked to a special mail box that marks every email it receives as spam. The rest just ends up in the normal mail filtering system.
Probably should move towards random usernames instead of service@domain.tld at some point, oh well.
I did a lot of work on iCloud’s “Hide My Email”, and I’m involved (the DRI for) quite heavily in other privacy-focused work at iCloud. It’s something I feel strongly about.
It's not worth trying to retaliate because these things come from addresses that aren't monitored, for the 99% case...
I do make a point of telling people how shitty the company is though.. Like Tesla for example :)
It's generally fine to talk about something already public, and say you worked on it - there are projects that haven't released yet that I've worked on, and I absolutely will not talk about those until they are :)
Oh and none of the involved entities ever acknowledged the leaks. I'd also be highly interested in the rates other people encounter.
I get a ton of spam, but they ALL are sent to my publicly listed email address in my git commits. I'm seriously considering turning that email into a honey pot.
The other however has leaked, but that's because it's designed to - it's for social media where the email is available for use and has been abused by third parties.
1. It is against IAB terms of service for partners to store a map of UIDs to PII (email and phone). Many clients do NOT want to share PII with DMPs, and so IAB also allows clients to submit SHA-2 hashed PII for identification. So if you are afraid of UID implementations selling your email, all I can say is that its against the terms of service to do so in conjunction with a UID
2. UID2 DSP Workflow implementations must provide an opt-out endpoint to them so that your UID won't be used in targeted advertising if you choose. This does not require them to purge your UID from their records or any info associated with it, but they must ignore that info in bid requests if you have requested to opt-out.
3. IAB is currently the main provider of UID2, but the system is designed so anyone can become a provider. IAB may not be the one handling your PII or UID. It is intended to be a decentralized system to solve the coming death of proprietary 3rd party tracker cookies.
Philosophically, we the users must accept that the price of free content is advertisement. If we want to continue to receive content, we must consent to some level of tracking and targeted advertising, or we must become okay with paying a monthly subscription for internet content. Without targeted advertising and a decentralized RTB ecosystem, there is no open internet; Google and Facebook will dominate everything, and small sites will be unable to compete
And you realize that third party cookies are gong away because people don't want to be tracked across different organizations, right? That means working around that limitation is the IAB and those working with them being actively malicious.
> Philosophically, we the users must accept that the price of free content is advertisement.
Nope.
> If we want to continue to receive content, we must consent to some level of tracking and targeted advertising, or we must become okay with paying a monthly subscription for internet content.
Absolutely not.
It is human nature to create and to share. People have always created and shared - long before parasites like the advertisement industry have inserted themselves into that process.
This argument is even more ridiculous for the internet where content is primarily created by users which receive no or almost no revenue from the ads shown by the platforms hosting their work.
> Without targeted advertising and a decentralized RTB ecosystem, there is no open internet;
There was an open internet before targeted advertisement.
> Google and Facebook will dominate everything, and small sites will be unable to compete
Google and Facebook are advertising companies. They dominate because of advertising.
UID2 came from TTD IIRC.
I'm fine with context-based adverts based on and next to the content I'm reading, and have actually found some good products & services that way. But the tracking is not ok in any form (and from what I've read, basically doesn't work and is also defrauding the advertisers), so anything to destroy that model would be a net benefit to society.
This is the best solution because it severely negatively affects the ecosystem.
Publishers make less, so they crank up the ad density for the remaining users. That increases user resentment and suppresses the per-ad cost, enabling much crappier ads to run on the website. That also increases user resentment and suppresses the per-ad cost, and the glorious cycle continues.
The advertiser is getting screwed, but the other parties will work really hard to explain it away to them. "You're getting great engagement with the creative -- you clearly just need to improve the landing page experience."
For me, my balance is that I'll run an ad blocker and whitelist sites that (a) create original content and (b) don't abuse me as a viewer.
I used to run a website that made money off of ads, and specifically ran an adblocker to avoid being banned by Google for mistakenly clicking on my own ads. Worked so well that I just left it on everywhere else.
I was thinking of something like the Blue Frog anti-spam system that automated complaints to get people taken off the system. I know they generated so much heat that they became retaliation & DDOS targets and shut down, but it seems something along the lines of automating complaints & defensive actions might have a role...
Let's assume you willingly opt-in to tracking but for whatever reason want to be tracked under "h.a.n.solo+iab@example.com" and not "hansolo@example.com" (because maybe example.com doesn't strip out + and . characters, so the two addresses are actually separate users), them not allowing you to change it back to your real address (without their normalisation process) might be a breach of the right to rectification as they'd be holding inaccurate personal data about you.
Of course this is all completely philosophical as GDPR enforcement is not only severely lacking but is nowhere near technical enough to dig into such detail.
In addition I recently laid out plans for "disposable aliases" with a machine generated random string as local part for users in our shared domains (like c1to.me). So one could use an alias when signing-up with a service. Once the service is not relevant - Just delete the alias. All comments and suggestions are welcome. =)
Registering, account management etc. will require JS - Simply to provide better UX.
There are no 3rd party libraries or references (except on pages handling payments via Stripe) in use and the JS is not minified. No 3rd party trackers either.
The proper way to do that is progressive enhancement.
Receiving a proken page and demands to turn on JS is pretty much the worst UX you can come up with.
TLA collisions of the nerds.
There are reasons not to care. For instance in the threat indicator space false negatives (a threat which is not caught) doesn't cause nearly the pucker as a false positive (something which is not a threat which is flagged as one). Their calculus and minimum may be driven by somewhat different objectives, because their audience is advertisers not security practitioners.
You can still 1:1 addresses to purposes and if you see crosstalk you can draw conclusions. Their normalization is lossy; that's the point.
The cynic in me notes that given the absolute lack of originality in password choice, similar lack of entropy could be seen in 1:1 mappings and perhaps they can infer that if you're hansolo@ and they're example.com, that the email address you'd use is han.solo+example@. The cynic also says: that's on you.
But damn, I'm looking better all the time: https://github.com/m3047/trualias
You are talking about IAB. At no point in the process is IAB is concerned about you, the user. This move is intentional.
BTW they've already been fined for other scummy behaviour https://proprivacy.com/privacy-news/iab-consent-popups-ruled...
Now, on the topic, this basically violates GDPR (anything that would reasonably allow individual identification needs consent and the user must be able to object to it).
Also, I'm not saying the workaround here, but assuming that you still want to use GMail (seriously?) this can still be frustrated (hint: Garfield Mail).
https://github.com/IABTechLab/uid2docs/tree/main/api#email-a...
https://spreadprivacy.com/protect-your-inbox-with-duckduckgo...
Back in the invite-only beta days, I signed up for a firstName.lastName@gmail.com address. It appears that years later someone else signed up using the same first and last name but without the dot, and that they are distinct gmail accounts.
This account has become my junk address, because I can’t trust it.
Too much fun, telling his wife about his porn-viewing habits and other miscellaneous secrets.
I don't use email anymore, but I maintain this account just because it pisses him off... I think this high-up at some tech company (that shares my same name) secretly expects me to just hand over the account I signed up for fifteen years ago, now... not happening, Mr. S.
HideMyEmail on iOS
masked emails on Fastmail
Firefox relay
DuckDuckGo email protection
NB. I am a casual use of uBlock. I have nothing against it. However like other alternatives it may have limitations that are worth considering.
At the very least we have to consider devices and applications that do not support uBlock Matrix/Origin.
With respect to those that do support it, a company making large profits from advertising that controls a particular application, like a web browser, or that controls a particular operating system, like a graphical mobile or desktop one that no user ever compiles themselves, can "remove support" for uBlock at any time.
Options for setting a default gateway and setting DNS servers are arguably even more prevalent on devices than support for uBlock. Presumably companies making large profits from advertising could remove support for DNS settings and default gateways from the operating systems they control, however this seems much less likely.^1
Where no user-configurable firewall is available on the device, we can sometimes use DNS settings, i.e. wildcards, to point DNS traffic to a DNS server we control. We can configure the DNS server to block/allow certain DNS traffic. We can also use the DNS server to point all HTTP traffic to the proxy.
The DNS server and the proxy can be running on the loopback of the device or they could be running on the gateway, where the gateway is another computer that we control.
What is needed to disrupt this UID API from IAB. Is DNS enough. Do we need to filter URLs for certain JS files. Do we need to filter cookies.
"All UID2 endpoints use the same base URL.
Environment Cloud_Region Code_Base_URL
Testing AWS US East (Ohio) us-east-2 https://operator-integ.uidapi.com
Production AWS US East (Ohio) us-east-2 https://prod.uidapi.com
Production AWS Asia Pacific (Sydney) ap-southeast-2 https://au.prod.uidapi.com
Production AWS Asia Pacific (Tokyo) ap-northeast-1 https://jp.prod.uidapi.com
Production AWS Asia Pacific (Singapore) ap-southeast-1 https://sg.prod.uidapi.com
For example, https://operator-integ.uidapi.com/v2/token/generate"
Source: https://github.com/IABTechLab/uid2docs/blob/main/api/v2/READ...
In authoritative DNS, a wildcard entry such as
*.uidapi.com 1 IN A 127.0.0.1
would send HTTP requests for these UID API endpoints to the loopback.This is is the same effect as using a hosts file like the StevenBlack one. Except some applications may ignore /etc/hosts.
In dnscache, djb's recursive DNS server, creating a one line file like
echo 127.0.0.1 > dnscache/root/servers/uidapi.com
would send DNS lookups for these UID API endoints to the loopback.(NB. AFAIK, unbound does not by itself support wildcards.)
What about uBlock.
uBlock relies on certain lists maintained by various third parties.
For example,
https://raw.githubusercontent.com/StevenBlack/hosts/master/d...
https://codeload.github.com/easylist/easylist/zip/refs/heads...
https://malware-filter.gitlab.io/malware-filter/urlhaus-filt...
https://raw.githubusercontent.com/gorhill/uBlock/master/asse... (lists contained therein)
I perused some of these lists looking for the uidapi.com endpoints.
It's possible I missed something but I only got one result:
cdn.uidapi.com in the StevenBlack hosts file
I think all the third party lists are great, however those require constant dillgence and there are so many now it is becoming confusing.
Personally I find whitelists that I control are easier for me to manage. I also find that on Android, NetGuard is more useful than uBlock. They do different things. I find NetGuard is more versatile.
The number of domains that I need to access is much smaller and grows at a slower rate than the number of domains on the internet that need to be "blocked".
As is sometimes done in firewall rules, using DNS I "block" all domains by defult and add A records for the domains I actually need to access.
1. There are numerous open source operating system projects that could provide those traditional, basic features to any user who wanted them. As it happens, such companies have relied considerably on such non-commercial, open source projects to create their own commercial, advertising-friendly versions.