Report: YouTube adding user-traceable ID tag to links shared off-platform
twitter.com
twitter.com
I get that "Use a real computer" isn't helpful though, so I'd recommend getting an app like NewPipe since you can use the "share" button there to copy the video's URL with the current timestamp included to your clipboard or paste it directly into apps of your choosing.
Edit: Got the story wrong. Wadsworth was just a commenter with an opinion and someone who worked at youtube had a sense of humor.
https://old.reddit.com/r/pics/comments/kxfxy/and_so_ends_20_...
https://old.reddit.com/r/pics/comments/kxfxy/and_so_ends_20_...
Post on reddit by person who added this feature: https://old.reddit.com/r/wadsworth/comments/l461y/today_i_ma...
YouTube will have ?v=[SOME ID] so you can't reuse the question mark.
...and if you didn't think this wasn't one of the goals of that trend, now you do. Those in power hate it when people can consume information from and communicate outside of their sanctioned methods.
We saw it coming when they started dumbing down browsers and hiding things from users --- not because the majority wouldn't use them, but to deliberately make users less inclined to learn.
Nearly 10 years ago(!) when that started happening, I made a comment here about how many YouTube users at the time realised what was the important part of the URL (the video ID) and began to use that in comments: https://news.ycombinator.com/item?id=7678729
The vast majority of users have no idea what an address or address bar is, let alone a Universal Resource Locator. Hell, most users don't understand files and folders in a computing context either.
As much as I hate how iOS, Android, MacOS, and presumably even Windows these days are obfuscating the file system and nearly everything pertaining to it, I do think it's a necessary step in the right direction. Most users do not address, and as computing hardware and software engineers, designers, and nerds we have an obligation to provide computers that all users can easily understand.
What differenciated the Middle Ages from the Enlightenment periods is the understanding that people aren’t that stupid, we don’t have to hide the Bible behind Latin, we can translate it to the local language and they’ll learn by themselves instead of going through clercs, and the same goes for law, physics, sciences and philosophy.
And we’re much better off with populaces able to make decisions for themselves (ie copy from the URL and drop one letter by mistake) than dumbing down everything to have control over them.
There is point where dumbing down technology doesn't make it meaningfully more accessible but just serves to harm users. Hiding the URL bar is past that point.
Why? Because I'm not confident I can type their URLs properly and any typos are a one-way ticket to Scam City. Chances are reasonable Google has the correct website URL. Bookmarks, you say? Can't be arsed.
Between inconvenience, unintuitiveness, and "I ain't got time for this" mentality it's no surprise why file system structures are obfuscated away.
googles no1 spot has become scam city hundreds of times for big namens just this year alone
>Bookmarks, you say? Can't be arsed.
in the time you complained about this problem of your own creation you could habe bookmarked your top 20-50 visited sites.
off topic but i see more and more "I'm too lazy to do x" where the solution would be easier than just being "lazy"
Did I really type in amazon.com correctly? Not amazn.com? amazon.cm? Or some other stupid typo that will send me straight to Scam City?
In that time I could have gone to Google (which is my browser home page), typed in something vaguely resembling "amazon", and the first or second link will be amazon.com 99% of the time.
I ain't got time.
Don’t get me wrong, I’m all in for a dev-switch which would enable scripting and open up everything in OSes. But tell me how you are gonna do that without scammers telling grandmas “Copy this thing to here, yeah…”. Currently the dev switch is e.g. a Mac and $99/year, for iOS.
No wonder Chrome wants to hide all that...
Those who don't want clean link manually, can use link cleaner apps or uBlock origin in browser.
I used to see ads occasionally on YouTube before they tried to crack down. The irony lol.
Pure bliss.
But Twitter doesn’t appear to do it anymore.
At least on Apple devices, it allows you to “paste” things in surprisingly unlikely places. With some finesse, you can even add custom actions on MacOS like passing it to a shell script that downloads and then pipes it into ffmpeg or whatever. Yeah I use it a lot
The fact that Google has to resort to this is amusing. To me it means they can't do it any other way and are now leaving themselves wide open for us the techies to strip that tracking ID; which we absolutely will do.
Things must be getting desperate somewhere in HQ.
Good.
Also there’s no treachery afoot here… go ahead and remove it, the stakes here are very low.
As for the indistinguishable URLs, you have a solid point there but I'd think there would be a lot of outrage because people want those URLs to generate previews when pasted in pages, social media comments etc.
Not to mention all the false positives generated by people embedding such URLs.
So I think for now we're safe on that front, they would poison their own well if they went ahead with encoded URL identifiers, happily.
But again, I am very amused that they just outright added "?si=..." -- to me that reeks of desperation and I have to admit that I enjoy it when Google is struggling.
I don't think it means that (although I wish it did): it's just another connecting datapoint, and more connecting datapoints are always good from their perspective.
(I think it's helpful to think about these things from Google's perspective: they're running a service that ~billions of people access and share daily. 95% or more of those people won't know how to strip those identifiers; the 5% or so that do are put on the slightly-less-happy-path for social graph discovery.)
What I am saying is that they chose a very lame way to do it and this robs them of very valuable data they could get from those 5% and I'd argue that they really would want to know how you and me are moving and discovering stuff when we're outside YouTube.
Trying hard not to have the protagonist syndrome here but I'd think they are more interested in how the non-couch-surfers do stuff.
Though a very good counter-argument would be that they can now target ads better and probably gain slightly higher conversation regardless of us the 5% stripping the tracking parameter, and that would still be a huge financial win for them.
All in all, my stance is: let them have it, but I still find it reassuring that they are not even covert about it which gives us a lot of options on how to deny them.
Finally, there's the possibility of various browsers and addons to start automatically removing the tracking parameter, though such movements usually take years.
If you want power and customizability, check out Request Control.
uBlock Origin can also block this by adding the following rules (Dashboard > My Filters tab):
! tracking param https://twitter.com/OldRowSwig/status/1732112446943269347
||youtube.com^$removeparam=si
||youtu.be^$removeparam=siI think a better approach though is to whitelist allowed attributes rather than blacklist disallowed attributes. For example, if you get a URL starting "https://www.youtube.com/watch?" then the only allowed attributes are v, t, etc and everything else would be stripped.
[1] https://github.com/ClearURLs/Rules/commit/f4d52da5902640d4d0...
Host: *.youtube.com
Path: /watch*
Types: Document
Action: Filter
Check "Filter URL Redirection"
List of Trimmed Query Parameters: v t list index time_continue
Check "Invert trimming"
'time_continue' is used when you navigate to Youtube from an embedded video. 'index' is used in playlists.
[0] https://addons.mozilla.org/en-US/firefox/addon/requestcontro...
This is purely an extra data point; without it, there is 0 attribution for which user is responsible for a link to a video causing that video to go viral, besides the referrer header.
They have experimented with other ways to do this in the past. For example, they used to have a direct friends list on YouTube where you could share videos to specific friends or groups of friends at once.
Reddit too, but I don't have a news source for it. I can only share a link I came across: https://reddit.com/r/dataisbeautiful/s/LCv7yIwiVF
If you click on the link, you can see all the tracking parameters in the URL bar. Whosever link this is used the official Reddit iOS app to generate the unique URL.
Edit: found a you.be link of mine with the `si` param from August 23rd.
When it became news https://old.reddit.com/r/webdev/comments/15ukrpi/what_is_the...
It'd be awful, but Google nowadays is willing to do shitty stuff like this and atrocious stuff like engage with the military too (because obviously the only flaw of project maven was being discovered)
Instagram and TikTok have already been doing this for years.
Tracking /s/ link:
https://www.reddit.com/r/Blind/s/xxQGmFcPSS
Leads to the following:
https://www.reddit.com/r/Blind/comments/17atlg7/my_6_week_ol...
Ironically I've only seen it work best when removing tracking from Firefox's own links. https://mastodon.social/@lazycouchpotato/111480927753796790
The URL gets a little longer, but a format-preserving encryption scheme might be able to help a bit.
Not that I want to give them any ideas.
But remember that this isn't being done for security; it's just adding a minor barrier to casual removal of the tracking information. And if users really want to circumvent it on the links they generate all they'd need to do is copy the regular URL instead of using the Share button.
(Again, not that I want to see them do any of this.)
At that point, why even replace it with something common? Just use the uniqe urls always.
If 20 year old keys remain valid and URLs encrypted with them still work, you’re not getting any value out of key rotation. If an old key leaks or is cracked, the entire system is useless.
Remember the point of encryption here is basically integrity - to verify that the parameters were generated by the site’s own share capability.
Indeed, rotating the key here serves very little benefit.
Thinking out loud: I suppose if they strayed further from the light and started restricting timestamp linking to share button URLs they might want to rotate the key to frustrate anyone looking to generate anonymous timestamp links. In that case, you could do something like include some indicator of which key was valid on the day it was uploaded. That limits the blast radius of a leaked/cracked key to the ability to generate timestamp links for all videos created during that period. Still low stakes, but now we need care more about integrity. Also, I wouldn't be surprised if updating the video ID scheme is a huge ask, so at that point a new DB might be the easier solution.
Tracking copy pasted like is an old techniques that also allows them to build a unofficial friend graph between cookie profiles.
Google are relentless with their surveillance and are always looking for sneaky new ways to track people.
I believe Douyin is the most notorious of them all. Each video doesn't expose unique ID at all. Every link is a short link uniquely bond to your device/app/browser.
If you click that link and it opens in the TikTok app, it'll tell you exactly who shared it and asks you to follow them...
Very annoying to have to remember to do that though.
SO goes so far as to give you little notifications and achievements whenever a certain number of unique visitors follow one of your shared links.
Chinese tech giants have long been ahead of the curve in terms of privacy infringement compared to various Western countries.
The practices of YouTube are already outdated in China. For instance, China's largest video platform, Bilibili, prefers to compress video links containing a large number of tracking parameters into short links, making it impossible for you to use something plugins to remove tracking parameters.
I share links to things when I'm logged in, but I want to ensure that the receiver has no way of tracing back the sent link to my Reddit identity.
Until then it was just &feature=share but now its a full ID. Yikes.
i am yet to come across it for youtube, but unsurprised. i wonder why there was no reporting on the other cases.