Web Giants Threaten End to Cookie Tracking
online.wsj.com
online.wsj.com
This highlights the dangers of the seemingly harmless social widgets. Anyone who doesn't already, I highly recommend using a plugin such as ghostery[1] to block them.
It does use a cookie to track your preference. The default is to enable them (since most users are not tech savvy enough to know they want them off, and those same users wouldn't easily find a button to turn them on).
Second way, and probably the best, would be to go to its store page, and in the URL will be the extension ID; for Ghostery, it's "mlomiejdfkolichcflejclcbmpeaniij". Now, just find that in your Chrome installation directory, e.g. for Win7 the extension would be located at %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\.
The last way would be to intercept or otherwise directly down the .crx file (curl, wget, etc.), which is just a compressed zip archive. You can do the same for FF extensions as well, those .xpi files are just zip files.
They're also an ad (analytics?) company. I just don't trust them.
Using libraries like this makes that interaction absolutely explicit, with minimal loss of ease of use, which means that nothing is shared until that explicit signal that the user wants to share.
The mere loading of the widget sends a signal to Facebook that you visited the shoes page. You don't have to interact with the widget for the info to be sent.
Ghostery blocks the widget from loading.
How does this even work? Is the shoe seller placing some kind of JavaScript snippet on their website in order to allow Facebook to track users? Is this coming from their "Like" button?
More information straight from Facebook: https://www.facebook.com/help/186325668085084
It's usually obvious to spot the CDNs and avoid the spies.
It breaks a lot of things initially, but after a while, the sites you use often are properly whitelisted, and it isn't a pain anymore.
A lot of the time it's a big pain to get it working right (say, to watch a video on a news site), but that's simply the price I have to pay in today's web to retain at least a bit of privacy and security.
If anyone wants to make a neat extension, it seems like all these extensions could be combined into one with a slightly better user interface. If you want to make it really spiffy, the black/white listing for these could be shared in a distributed hash table with some sort of voting/trust mechanism.
It seems that the more locked-down hardware manufacturers may have accidentally stumbled upon a kind of end-user workflow that may actually work for controlling what they want to share with the web!
https://www.requestpolicy.com/ and https://addons.mozilla.org/en-US/firefox/addon./RequestPolic...
"On Wednesday, Microsoft quietly announced in a blog post that the company will give marketers the ability to track and advertise to people who use apps on its Windows 8 and 8.1 operating system on tablets and PCs. The company will do this by assigning each user a number—a unique identifier—that monitors them across all of their apps. (The system doesn't block cookies in Microsoft's Internet Explorer Web browser.) Industry players think Microsoft-powered smartphones and Xbox game consoles will be a natural extension of the system, but Microsoft kept mum on the question."
IIRC they had to make it opt in after user backslash.
Earlier this year, Apple Inc. also began offering advertisers the ability to trail and target users through a unique ID on smartphones and tablets.
In earlier versions of iOS, people were using the device UUID which allowed tracking across apps, but using the UUID isn't possible any more, so tracking is now only possible within one app.
identifierForVendor is not shared across vendors, but it is shared across apps from the same vendor.
identiferForAdvertising is shared across all apps, but it is not shared between devices and can be reset at any time by the user. (I think the user can suppress it altogether, but I'm not 100% sure.)
Instead, Apple provided two alternatives:
* A vendor-specific identifier that is shared among all apps created with the same vendor prefix (essentially, coming from the same company). This provides what most devs need for identifying users within their apps and even across apps.
* An advertising identifier that is shared across all apps. This is intended for tracking, but Apple also provides a couple privacy protections for users: (a) users can set a flag asking apps not to perform tracking with this identifier, and (b) users can reset this identifier whenever they want –- the equivalent to clearing cookies.
Facebook requires you to be logged in to do anything, so there's nothing new here.
Microsoft assigning unique IDs to its Surface devices doesn't really matter because nobody uses them.
This may be part of the lack of technical background in the article, but how do Facebook widgets on people's sites track whether you are logged in to Facebook if not via cookies? The mechanisms I know, user agent and IP address, don't seem reliable enough to replace a session cookie.
I notice in a comment further up that Apple has two separate IDs. One for advertising and one for tracking users of a vendor's applications. Should this browser ID system have two separate IDs, one for securely identifying a user and another for advertising? The secure ID would have to be unique per website, otherwise phishing schemes just became ridiculously easy.
So instead of having pretty much anyone on the Internet tracking you by default you will have pretty much anyone on the Internet tracking you through Google - except for people Google doesn't like. And in the Apple world Apple will be the gatekeeper and so on.
I don't see how this is an improvement.
And thank god for Firefox for keeping these people in check.
The thing is, even Google services (Search, Analytics, etc) and Facebook (the Like Button, etc) use cookies to track users. It's still fundamentally the same thing. The difference is that by logging in to the same service (Google, Facebook, etc) on difference devices and browsers, they can "link" the cookie data together for a more complete picture of your online activity.
Adding to this cross-cookie data, these services can include data from their actual services (Google Search, the Facebook Social Graph, etc), and are starting to include data about the Apps you use (in their respective ecosystems). It's a nice bundle of data they can sell to advertisers (indirectly, via ad targeting).
The scarier question is: will the tracking be enabled at the client/device level? Will your Google or Microsoft web browser (or OS) directly collect and track information about your browsing? Or will it still be limited to "web tracking" (with enhanced ability to connect cookie data across multiple devices)?
Its wording is broad enough to include alternative approaches of individually tracking users.
If I visit your website, you'll log details about what I'm doing. That's kinda how it works.
This "pop up a massive cookie warning on every fucking website" is worse than advertising that start up playing sound. Worse than the original 'problem'.
BTW The EU are now planning to ban powerful vacuum cleaners in their ever further reaching quest to limit freedom.
http://blog.notevencode.com/posts/html5-eme-is-not-a-drm-sta...
Is there something here I'm missing? I spend more time browsing the web on my Android phone than my PC and I've never ran into any issues with "cookie-driven" features.
Cookies obviously work in mobile browsers, but browsers are only a part of the picture on mobile.
If people stop getting their money's worth with advertising on Google then Google will lose money.
And they are already severely limiting 3rd party cookies. Even Mozilla's in on the action: http://www.computerworld.com/s/article/9240218/Mozilla_again...