HNHacker News
TopNewBestAskShowJobs

user17843

651 karma · joined April 15, 2019

submissionscomments
user17843··on I left the ad industry because of data tracking
My question to someone from the ad-industry would be if there are known "intersections" between these anonymised data sets ad-tech is using to sell as much as possible, and companies who buy these data-sets to connect them to real identities.

Especially because the web is full of Privacy notices people agree to, and I guess in some of those people actually agree to have their anonymous browsing data connected to their real identities.

user17843··on I left the ad industry because of data tracking
Nothing makes me think this. But since officially everything is pseudonymous, how would it be possible to have a website dedicated to showing the data someone has about me?

Privacy International did a piece on this kind of ad-tech data survaillance and they were saying "Here is the shocking details what an ad-company knew about me when I asked them to share everything with me in line with GDPR"

Then I emailed Privacy International, asking: How did they even knew your real name?

To which they replied "Oh, yes, we forgot to add that to the article, I actually gave them my name and my cookies, so they could tie all their cookie IDs to my name"

PI promised to add this "small detail" to the article. They never did: https://privacyinternational.org/long-read/2433/i-asked-onli...

They also promised to write an article about the implications of pseudonymous data and the possible link to real identities, which they also never did.

user17843··on I left the ad industry because of data tracking
I have yet to see a real whistleblower report by someone deep into the ad industry revealing whats really going on there. There are almost no details about what's really happening on a technical level (beyond the little things we already know), and whether large data sets are abused in the sense that they get routinely de-anonymised.
user17843··on I left the ad industry because of data tracking
the thing is, in theory all of this data is pseudonymous, or even anonymous, as the industry creates all of these profiles and does not attach real names to it.
user17843··on I left the ad industry because of data tracking
> it even automatically saved the identified user's profile pic from facebook into their database.

Please share more information.

Did that require the user to be logged into FB?

user17843··on New Evidence Suggests Satoshi Nakamoto Is Paul Le Roux
I think it was a combined persona from Nick and Hal, with Nick doing most of the writing in the forum.
user17843··on Firefox Monitor
Have I been pwned prompted me to abandon my old addresses and switch to a provider that allows trash mails and email aliases.

Originally my address was breached by Dropbox and Kickstarter.

It took me many months to switch over, as I did not have a complete list of all services I had registered with.

So for many average people switching email adresses is often a very difficult task, so people keep them even in light of breaches.

More important for the average user is to have a good password management system and know whether a certain password has been hacked.

user17843··on Valve has mutated from a game developer into a financial middleman
If that's the case they would be extremely short-sighted, as their strategy failed and the game is dead now.

But we all know that financial decisions aren't being made by engineers.

user17843··on Valve has mutated from a game developer into a financial middleman
You think the decision to make a fail game like Artifact with the main goal of getting as much money as possible was a software engineer decision?
user17843··on Firefox Follows Apple in Blocking Third-Party Cookies Online
I downloaded it today as a new user and it did not have it enabled.
user17843··on When it comes to privacy, default settings matter
Technically, ad-tracking is not an invasion to privacy per sé, and does not identify a person. It is always connected to a client, and it is illegal to connect the client browsing data to a real person.

So from that perspective, how is ad-tech a problem for privacy?

user17843··on When it comes to privacy, default settings matter
Good question. It would have made everything so much easier. How much work was done on this selective cookie blocking implementation?

Personally I always hoped they would simply copy Privacy Badger and develop an algorithm, instead of relying on a black list.

user17843··on Privacytools.io: Hypothetical possibility of using affiliate/referral links
I once created a project based on affiliate links and I researched the implications of this a lot.

I came to the conclusion for a corporate project it's a very elegant way to make money, as theoretically it's a win-win for everone involved.

But there is one big problem, especially for smaller projects where the people who write the content also manage the website: Subconciously you start identifying with the products you recommend.

It's easy to lie to yourself. Like one guy on the github thread, suggesting

> "Another benefit of more income from affiliate: We could fund small privacy open source software / service projects in form of donations, too.

If the project would be able to even fund other projects with running on affiliate money, then it would also be possible to live off donation or a shop and simply focus on your own project.

There is only one way of having a project that sides with the users: Actually getting the money directly from the users.

With affiliate links the products you recommend become your customers, so you start to become accountable towards them, and the users become your product.

This happens slowly over time and mostly subconsciously. At first everything seems to be ok, but at one point all the relevant questions resolve around how to please the affiliate customers.

user17843··on Net worth of Americans aged 18 to 35 has dropped 34 percent since 1996: study
It already happened, and was called "Occupy Wallstreet". Then identity politics came around and occupied the left.
user17843··on Block Fingerprinting with Firefox
Nope. The linked mozilla blog post clearly talks about the fingerprinting settings, and the comment I replied to did not specify anything related to "blocking underlying techniques".
user17843··on Block Fingerprinting with Firefox
Firefox Fingerprinting protection has nothing to do with real fingerprinting protection, and does not afffect panopticlick results in any way.

It just bloocks a couple of known scripts based on the disconnect list.

Of course they don't tell us in their marketing posts.

user17843··on Google to restrict modern ad blocking Chrome extensions to enterprise users
What i've read is that Gecko is a bit more difficult to understand when it comes to the entire code base, compared wo WebKit or Blink.
user17843··on Google to restrict modern ad blocking Chrome extensions to enterprise users
The problem is the only way to combat Google in this regards would be for smaller players to come together and form an open-source working group based on a chromium fork. (The train has already left the station for anything besides WebKit or Blink, since the lack of accessibility of Gecko means it will never be adopted by anyone else.)

But most of them are directly financed by Google and have almost no common ground (e.g. Opera, Firefox).

And unfortunately no single player involved can gain much by going against Google. What would Microsoft gain from forking? Nothing.

I think 10 years in the future we might see WebKit and Blink merge together into a single core engine.

Modern Capitalism almost dictates this development, as corporations strive to save money at all costs.

user17843··on Google to restrict modern ad blocking Chrome extensions to enterprise users
Indeed, almost the entire ad-blocking market is controlled by the company behind Adblock Plus (eyeo GmbH), who has contracts with Google. It appears they also own AdBlock, and uBlock (not confused with uBO), so during the last years they basically tried to capture the entire market. The fact that Eyeo has >150 employees tells us something about the amount of money to be made from ad blocking. Although they have only published the numbers from 2016, it seems they are quickly approaching around €50 million yearly revenue, with almost 50% of pure profit. For Google this Acceptable Ads Program may be more than a 100 million dollar business.

The only real nuisance is uBO and the future possibility that someone comes along and uses Google's own software to eliminate their core business model.

Basically in this entire environment if an extension does not take part in extracting money out of people, it becomes a problem for most parties involved.

Someone at Google in the higher ups probably realized at one point that giving the user so much freedom and control could theoretically backfire enourmously.

Google indirectly controls ABP, but they want the ABP model to apply to all blockers, so that they both get money from non-blocking users as well as from blocking-users.

In the perfect world of Google content-blocking does not exist beyond mere visual ad-blocking of the most annoying ads.

ABP already allows cookies and network connections, so google still knows everything about those users.

Personally I use a combination of pi-hole, third-party cookie blocking and uBO, which takes care of basically all cross-site tracking. But when I recently had a look at another system of someone who uses ABP I noticed that the blocking really is only visual, theres still a profile that is being sold to data brokers, you just don't see the stuff they recommend to you.

The default settings of ABP are also extremely anti-user.

ABP/Eyeo is a wolf in sheep's clothing.

uBO users on the other hand are basically invisible to the survaillance capitalists.

user17843··on Firefox 67.0 Released
The fingerprint protection this new setting refers to is simply a blacklist of a couple of known JS fingerprinters. Those are not relevant for the majority of users, because fingerprinting with these kind of scripts is only used by a very small number of obscure sites.
user17843··on Keepass.com spreading malware acting as the official password manager site
Update: The sites are now all blocked by https://www.squidblacklist.org/downloads/dg-malicious.acl, which is a list I recommend everyone to put into their pihole.

Still not blocked on Google Safe Browsing.

user17843··on Keepass.com spreading malware acting as the official password manager site
I have my browser that I use for logging into sites behind three layers of security:

- Google Safe Browsing

- Pihole including a couple of regularly updated malware lists

- uBlock Origin

It looks like Safe Browsing and pihole do not yet have this on the blacklist.

user17843··on Mozilla and Google Chrome Refuse to Support Gab’s Dissenter Extension
I too find it very interesting.

Thanks to Chromium, we are seeing a diverse range of projects emerging that cater to different groups.

Although the Dissenter extension, while a good idea, is essentially dead, there are basically no lively discussions.

So what's the point of using their product? Most users seem to think of it as a statement.

The idea of including BTC payments is certainly interesting, but it will fail, too, in the sense of Gab Browser not becoming succesful beyond a very small niche group.

Brave has been working for years to create actual incentives for the platform to flourish, it is beyond me how the Gab team thinks they can pull something similar off without any working incentive systems.

And Brave is not censoring anything. It is extremely difficult to build systems that protect user privacy, this has been ongoing for years, but not having user data is the whole point of the Brave project. If they fail with this, they won't be succesful.

The whole point of the Gab Browser is to protect free speech, even though strictly speaking no one has limited their free speech on a browser level, they could get the same free speech with using Chromium+Dissenter extension.

The idea with the Browser is to anticipate possible future censorship by Google, certainly legitimate.

Since they do not care about data, they haven't gone to great length of making sure they don't get any user data. If I remember correctly, every url visited in the Gab browser is sent to Dissenter, that's how the extension works.

The aggressivenes with which the Gab team goes against Brave on Twitter, wile taking all of their hard work without a single 'thank you', is what annoys me the most.

They seem to think free speech means everyone fighting for sensible solutions need to be "on their side", and everyone who isn't with them is against them.

user17843··on Improving privacy and security on the web
Let me guess: Google will tie the new proposal to a new Chrome setting which effectively identifies tracking cookies according to this new identifier, and will regularly purge them.
user17843··on Mozilla and Google Chrome Refuse to Support Gab’s Dissenter Extension
HN is not doing them a favor, except when you think that HN reader are actually incapable of thinking themselves, and need to be protected from knowledge.

I refute this picture of humans.

Silencing developments with ignoring them would actually do Gab a favor, whatever that means exactly. The term "hate group" is not clearly defined, anyway, and a propaganda-term in itself, and a tool of so-called 'hate'. .

user17843··on Mozilla and Google Chrome Refuse to Support Gab’s Dissenter Extension
While Brave is building from the core to the periphery, i.e. creating something based on solid fundamentals, Gab is taking Brave and polishing it a bit to their liking.

Due to this I suspect that the Gab browser will only get a following in a certain sphere, i.e. ideologigcal Gab followers. Otherwise you can simply use Brave or Chrome.

There was criticism by Eich et al. who noted that Gab is sending all kinds of data back home.

Gab seems to be focused on providing a service to their followers, without having the actual technical expertise to create something solid based on true privacy.

(I.e. it doesn't matter when we collect the data because we are actually on the right side of the fence)

Nevertheless I am excited to see where all of this is going and I welcome any additional browser, which is good for creating a competitive market.

The fact that Gab can, without much knowledge, "create" a browser interface within days shows how great Chromium is for the advancement of the open web.

The only thing that needs to be solved is the governance of chromium with it becoming the de facto standard on the web.

user17843··on Browser Fingerprinting: A Survey
It is not in use because it's basically illegal, and due to relieance on JavaScrip, a simple script blocker can take down your entire business.

The industry used fingerprinters, but for one it didn't really help them make more money (because you want to track users, not systems), and there was a big backlash.

user17843··on Guido blames social media for his decision to abandon the supervision of Python
yes, it's sickening. I do my best to filter out all the like and upvote stuff, but it doesn't really help because it changes the entire atmosphere of a platform and thus affects me too.
user17843··on Browser Fingerprinting: A Survey
No.

Quote about canvas fingerprinting:

"Comparing our results with a 2014 study [1], we find three important trends. First, the most prominent trackers have by-and-large stopped using it, suggesting that the public backlash following that study was effective. Second, the overall number of domains employing it has increased considerably, indicating that knowledge of the technique has spread and that more obscure trackers are less concerned about public perception. As the technique evolves, the images used have increased in variety and complexity, as we detail in Figure 12 in the Appendix. Third, the use has shifted from behavioral tracking to fraud detection, in line with thead industry’s self-regulatory norm regarding acceptable uses of fingerprinting."

[1] G. Acar,C. Eubank, S. Englehardt, M. Juarez, A. Narayanan,and C. Diaz. The web never forgets: Persistent trackingmechanisms in the wild. InProceedings of CCS, 2014.

Other references:

[10] W. Davis. KISSmetrics Finalizes Supercookies Settlement.http://www.mediapost.com/publications/article/191409/kissmet.... [Online; accessed 12-May-2014].

[15] Federal Trade Commission. Google will pay $22.5 millionto settle FTC charges it misrepresented privacy assurancesto users of Apple’s Safari internet browser. https://www.ftc.gov/news-events/press-releases/2012/08/googl..., 2012

user17843··on Browser Fingerprinting: A Survey
One of the referenced studies (1-million study withOpenWPM, the most recent from 2016) notes that the usual fingerprinting scripts have basically disappeared since a public outcry and media attention following a lawsuit.

Prevalence:

- 1.4% for canvasfingerprinting

- 0.325% for canvasfont probing

- 0.0715% for WebRTC

- 0.0067% forAudioContext

The above were found only on the most shady of all websites, and good content blockers block all those scripts.

My bet is GDPR was the death blow for this kind of scripts. For small companies without a room full of lawyers data has become a liability.

So fingerprinting is now basically in the hands of google, amazon, etc.

← PreviousPage 3 of 5Next →