Adblock Plus gives Facebook users a way to block its extended tracking efforts
tech.eu
tech.eu
Am I the only one bothered by the silliness of "Do Not Track"? Or even worse, the EU cookie law?
You have a browser that leaks all kinds of info[1] about itself, tells everyone where you came from (sends referral), takes cookies from strangers like an untrained dog, making you uniquely identifiable and instead of fixing that, you ask everyone on the web to please disregard that info your browser just volunteered. How is that not completely backwards?
AdBlock, RefControl, and Disconnect, or their equivalents should be built into modern browsers. And maybe do something about the user agent, fonts, etc, too?
Don't educate users. Fix it.
Sure, there's some technical steps that can be taken but there's also a social or cultural dimension to what behavior is popularly accepted fro companies.
This is what a browser with (or more appropriately, on) DNT is doing. Long way from camouflage.
And offline, we should also employ techniques like randomizing MAC addresses in mobile devices. Just like you lock your car even though it's illegal to jack it.
Don't worry, there's a startup that's "fixing" that[0].
Nomi uses the MAC address of your phone to identify the brick-and-mortar venues you visit. It's opt-out for consumers, and the only way to opt-out is to register your MAC address with them[1].
The browser shows where you are coming from, similar to you walking from one store that sent you to a second store. The browser's identifying marks are more like the color and type of your vehicle. The ID around your neck? That really is more like a company that would use facial recognition, or tagging your phone and tracking that.
What websites do is exactly what the parent described, like to a T. Often stores track you inside the premises though for marketing and display purpsoes, or so I've been told.
Yeah; it's called my face.
If the shopkeeper kept a logbook that recorded all of that, and then he published said logbook to other companies, you might feel that this was going a bit further than the social contract between you and the shopkeeper allows.
Though not a perfect analogy, the shopkeeper and you having small talk -- without anyone writing things and keeping the records forever -- would be tantamount to the server keeping the values in a transient fashion (i.e. for the duration of the request or session and then dropping them).
Hmm no. It's just harder to do but they are working on it. Any big shop uses tons of tracking on every level. Pay by CC or use your fidelity card, facial tracking, MAC address of your phone. In London a company was providing the phone tracking service on the streets, installed on their bins, until they got shot down by the government.
The world on the street is exactly as cynical as the one online. It's the same world. Online it's just easier to track people even more, so they get tracked even more.
It's a matter of cost/benefit to the businesses, that's all. When a business can track customers cheaply and finds the data useful, they just do it:
http://www.nytimes.com/2013/07/15/business/attention-shopper...
Why do you think the buzz around big data exists ? Its not just for curing cancer ; its mostly to track and model individual consumer behavior.
In the end, I think the way forward should be to do our best to prevent our browsers from leaking such information, but also to punish people who, against our explicit wishes, take advantage of any small mistakes we make when we protect ourselves.
By analogy, it's probably not smart to go into a bad neighborhood at night alone with no protection, a large amount of cash and a flashy suit, but that doesn't mean that it's a silly thing to try and deter robberies and assaults on a societal level (either with social strategies like shaming and shunning or with violent strategies like law enforcement or retributive violence) - to the extent that it's cost-effective to do so.
*Edit:typo.
0. [page visited]
1. Does the page contain GA tracking ID?
no: do nothing
yes: add it to the database and replace it with another randomly chosen ID from the databaseCan you describe in more detail how google could detect that the GA identifier has been swapped and how to prevent detection?
But again, not an expert and I could easily be missing something crucial.
The voluntary standards were never going to work since the interests of the parties involved are diametrically opposed. The voluntary systems only work for the ad companies if a very small number of users take up the option and if privacy remains a niche issue. As soon as developers looked to apply DNT broadly, they baulked.
Trust is also an issue. Facebook previously said that although their share buttons are hosted on the same domain as facebook.com, meaning cookies are sent - that they are not storing or tracking user web browsing data. They now are using that data, and very little was made of the reversal.
The same reversal or business changes could turn on DNT in the same way. With DNT the sites still receive the cookies and can still store the data. They are able to comply with DNT for a period and then later reverse their position and still use the old data for targeting (and a DNT header is one more data bit that says a lot about a user).
There are now a number of competing opt out standards. None of them really work and they each have problems, but companies need to be able to say they let users opt out whenever they announce a new tech that encroaches further into our lives (Facebook use aboutads, the NAI has their own, Google has its own, most of the aggregators have their own, there are other efforts to sync opt-out).
The solution is to cut the problem off at the head and solve it with software. Browsers and that are easy to use in terms of specifying who you trust (like installing an app) and that don't ever make third-party requests by default. Now that the pretense of negotiating a solution has been dropped, effort can go into developing better software control for users and tech solutions - since none of the current offerings are perfect (which is excusable).
[0] http://www.theverge.com/2013/7/5/4496852/adblock-plus-eye-go...
There is a single checkbox in the options to toggle the whitelist, as well as a link to filter list being used and documentation.
You broke your experience. If you turn off your car's engine and the brakes and steering stop working, that's not the engine's fault, it's yours.
The general point being the most websites I visit I am just reading text. Yet, I usually have to allow a few secondary domains (that serve JS and data), before the text gets into a form better than soup.
Why should anyone spend time rewriting their entire UI to run on a server and hack up rendering for you because you don't wish to run their UI code?
So when people show their work (implicitly asking for critique), I think it is perfectly appropriate critique to point out if the static content (information) that matters cannot be displayed without Javascript. You don't need to run an UI on the server for me. No, you don't need to hack up rendering for me. My browser renders things itself. I want the browser to render things for me, according to my preferences. I don't need your rendering. My browser is my UI. Just give me the content in the right format so it can present it for me, with the interface that I am accustomed to and in charge of.
But since those web designers probably monetize their content through the same ad networks we're trying to block it seems like a catch 22.
Welcome to 2014.
https://addons.mozilla.org/en-US/firefox/addon/adblock-edge/
almost makes me want to switch to firefox completely and use adblock-edge.
(disclaimer: I run a 5k DAU social network with no ads).
maybe site-owners should pressure ad-providers to provide a track-free service ?
Of course you could argue the moral and inconvenience cases as sites make these judgements when choosing advert networks already but "a bit of tracking" does not have the same moral weight to most as "porn and gambling" or "the annoyance of pop-ups/unders and drive-by install attempts" when deciding where they are comfortable to take money from.
Without the latter the ads being compulsory is just enforcing advertising on your users without knowing if they even want it.
Also it is much easier (for a non-technical user at least) to just skip the ads on the web using browser plug-ins, than it is to get around them in an app, so to an extent this extra work may be wasted and the number of people who take up the "pay for no ads" option might not be enough to warrant the work that goes into maintaining it.
There are some sites that offer the "ads or pay" option so it presumably works out worthwhile for some sites, but I've not seen it often.
The problem [for me] is not the advertising as long as it's reasonably done (static, textual, non-invasive). It's the fact that every third party has their own behaviours, and I have no idea what any of them are. I instead must rely on the judgement of the person running the site - and most of them appear fairly unaware of the privacy implications associated with both advertisements and analytics services.
I agree that ad-supported is terrible. But how else? I'm hopeful for donation-crowdfunding and simple, liquid micropayment options online. But I don't know that that could significantly displace ads.
Very true. This says something about how we as a society values those works and how our economic organization discourages some kinds of work/content.
They're the wrong tool for the job. They're for blocking ads. So they'll block ads that are not leaking your info (for your use case, a false positive) and will not (not necessarily) block other means by which you're being tracked (for your use case, a false negative).
Use something like RequestPolicy (https://addons.mozilla.org/en-US/firefox/addon/requestpolicy...) or PrivacyBadger (https://www.eff.org/privacybadger) instead. That way, you're not blocking ads per sé — though a side effect of using RequestPolicy is that you won't see much ads — you're blocking the leakage of information to third parties instead.
Using blanket ad blocking sends the wrong signal to site owners, and creates little incentive to do the 'right thing' — it lets the "bad apples" (which I imagine to be something like 99% of the online ad businesses) spoil it for the one percent that does value your privacy, with no way for anyone to improve. Using ad blocking for privacy reasons is not completely effective (false negatives) and worse, it's punishing individuals for the behaviour of the flock.
=========================================================
Edit: Found the perfect example of the false-positive and false-negative I'm talking about above: http://www.gentoo.org . Harmless ads — just images inside html <a> anchors, loaded from the domain in the site URL. Not leaking anything. The ads help an organization I support.
So what does AdblockPlus do (default settings)? It blocks them. What does RequestPolicy do? It lets them through.
For video I use dedicated apps with off-line caching. For email I have IMAP. I get news via RSS. Anything longer than 1 page, I save and read on Kindle latter (including HN discussions). I have off-line version of Wikipedia.
I have it set up in quite a restrictive way so by default a site level scope is created and only image/css is allowed. It means I have to take anywhere from a couple of seconds to a few minutes to enable things a site needs to function, but I much prefer that to having tracking cookies, social media buttons, obnoxious adverts etc.
Also the Adblock site claims you can also block a few annoyances specific to Facebook[0]. Is that actually the case? I thought Adblock just used element hiding.
[0] https://github.com/gorhill/httpswitchboard/ [1] https://facebook.adblockplus.me/en/
I think Firefox has always been able to do this.
Of course everyone in my other browser sessions is tracking me between sites, but it isn't linked to my social profiles and such.
TBH I don't really care about the tracking of me. The thing that I find annoys is the combined tracking of me and my contacts: I don't like the idea of them trying to track other people through me.
For instance Google does maintain such non-cookie-based user identities. I'd be highly surprised if Facebook didn't as well; your data is just too valuable to pass on such easy fixes.
The browser fingerprint isn't going to help them though.
Of course the only real solution (other than cutting yourself off completely) is for there to be a stable, secure, reliable, non-tracked, ad-free alternative that enough people use - and that isn't going to happen unless you have a spare high improbability generator handy.
This doesn't seem like anything new, just a reaction to the news that Facebook is going to expand what they do with the data they collect.
(I'm a Ghostery developer)
Go to ad block settings. Add a custom one, give it any title you want. Put this in for the URL:
https://easylist-downloads.adblockplus.org/fanboy-social.txt
I use Adblock and love it dearly. I don't have to watch annoying ads on youtube or deal with intrusive banner ads suggesting I a guide on how to make $5000/day at home in an instant.
I do sometimes want to see ads, and that's when I google something and I want to actually see the advertisements. This is a good sign for google although overall, adblock will slowly cannibalize their ads
The entire movement is pissing against the wind. Tracking is how these companies make money. This is their motivation system. A "low" of current online physics is "tracking makes money".
As such, it's a waste of energy. Change physics first.
That's what this fixes. By pushing back against tracking, we will force websites to use other ways to make money.