The hidden perils of cookie syncing
freedom-to-tinker.com
freedom-to-tinker.com
It's definitely not the choice I would have made, but I got massively outvoted.
I wouldn't even say that it's a function of maximizing ad revenue. If you wanted to maximize ad revenue, you'd run Google Ad Exchange, not, say, media.net or AdSense. AdX actually has reasonable policies around cookie syncing. Website operators do many things poorly as far as revenue optimization goes--invading my privacy is not step one for them to increase revenue.
The really big players are sensitive to the PR backlash and behave somewhat reasonably. The people out of the limelight do the really sneezy things. I think it is reasonable that most people do not expect hundreds of third parties to have their browser history dating back several years. Perhaps you trust the NYT to know your political leanings, but you don't expect that data to leak to third parties.
On AppNexus, you can buy pixel segments of users with certain diseases. That's fine, if a little creepy, until you think about how easy it would be to deanonymize that data.
Even very trustworthy actors get this wrong, btw. The government of Ontario's human rights website was, until recently, pixelling every visit to their site courtesy of the ShareThis widget, including sensitive topics like transgender rights. There was no profit motive there, just oversight on the government's dev team.
Is it naive to expect that when you visit a government page about transgender rights, you won't be added to a list of people presumed to have gender dysphoria, which a third party then sells to other third parties?
Curious people may want to research "data leakage", which is a developing field in the ad ops world to prevent some of these harmful scenarios.
* https://addons.mozilla.org/en-US/firefox/addon/self-destruct...
I additionally isolate websites where I need to log in into their own profile using a shell script for each along the lines of the following:
chromium-browser --app=http://facebook.com/ --user-data-dir=/home/jewel/work/facebook-profileOn the other hand, add-ons like Ghostery work much better.
[1] https://securehomes.esat.kuleuven.be/~gacar/persistent/index...
[2] https://securehomes.esat.kuleuven.be/~gacar/persistent/the_w...
https://www.ghosteryenterprise.com/
It's identical to the adware companies that promise to help remove adware from your computer... but for some reason people keep using it!
Actually, I went one step further than this, I dump that hosts file into dnsmasq and set that as my primary domain controller for the home network. So anything connected via WiFi or ethernet (phones, tablets, laptops, etc) will also have tracking blocked.
As a start, consider that if you turn off third party cookies, logging into gmail also logs you into youtube.com. Yes, both are owned by the same company, but they are clearly different domains and so youtube should be a third party in your transactions with gmail.
That's because you don't sign into youtube, you go through Google's single sign on stuff which is a different domain.
You'll notice that even if you never (deliberately) went to youtube and you have 3rd party cookies turned off, a cookie for "youtube.com" will show up when you sign in. I haven't looked at it carefully, but I think they just put you through a chain of redirects when you click "log in" so that you have a first party relationship with each of the domains they want to sign you in to, and that's when they give you the cookie.