Especially because the web is full of Privacy notices people agree to, and I guess in some of those people actually agree to have their anonymous browsing data connected to their real identities.
651 karma · joined April 15, 2019
Especially because the web is full of Privacy notices people agree to, and I guess in some of those people actually agree to have their anonymous browsing data connected to their real identities.
Privacy International did a piece on this kind of ad-tech data survaillance and they were saying "Here is the shocking details what an ad-company knew about me when I asked them to share everything with me in line with GDPR"
Then I emailed Privacy International, asking: How did they even knew your real name?
To which they replied "Oh, yes, we forgot to add that to the article, I actually gave them my name and my cookies, so they could tie all their cookie IDs to my name"
PI promised to add this "small detail" to the article. They never did: https://privacyinternational.org/long-read/2433/i-asked-onli...
They also promised to write an article about the implications of pseudonymous data and the possible link to real identities, which they also never did.
Please share more information.
Did that require the user to be logged into FB?
Originally my address was breached by Dropbox and Kickstarter.
It took me many months to switch over, as I did not have a complete list of all services I had registered with.
So for many average people switching email adresses is often a very difficult task, so people keep them even in light of breaches.
More important for the average user is to have a good password management system and know whether a certain password has been hacked.
But we all know that financial decisions aren't being made by engineers.
So from that perspective, how is ad-tech a problem for privacy?
Personally I always hoped they would simply copy Privacy Badger and develop an algorithm, instead of relying on a black list.
I came to the conclusion for a corporate project it's a very elegant way to make money, as theoretically it's a win-win for everone involved.
But there is one big problem, especially for smaller projects where the people who write the content also manage the website: Subconciously you start identifying with the products you recommend.
It's easy to lie to yourself. Like one guy on the github thread, suggesting
> "Another benefit of more income from affiliate: We could fund small privacy open source software / service projects in form of donations, too.
If the project would be able to even fund other projects with running on affiliate money, then it would also be possible to live off donation or a shop and simply focus on your own project.
There is only one way of having a project that sides with the users: Actually getting the money directly from the users.
With affiliate links the products you recommend become your customers, so you start to become accountable towards them, and the users become your product.
This happens slowly over time and mostly subconsciously. At first everything seems to be ok, but at one point all the relevant questions resolve around how to please the affiliate customers.
It just bloocks a couple of known scripts based on the disconnect list.
Of course they don't tell us in their marketing posts.
But most of them are directly financed by Google and have almost no common ground (e.g. Opera, Firefox).
And unfortunately no single player involved can gain much by going against Google. What would Microsoft gain from forking? Nothing.
I think 10 years in the future we might see WebKit and Blink merge together into a single core engine.
Modern Capitalism almost dictates this development, as corporations strive to save money at all costs.
The only real nuisance is uBO and the future possibility that someone comes along and uses Google's own software to eliminate their core business model.
Basically in this entire environment if an extension does not take part in extracting money out of people, it becomes a problem for most parties involved.
Someone at Google in the higher ups probably realized at one point that giving the user so much freedom and control could theoretically backfire enourmously.
Google indirectly controls ABP, but they want the ABP model to apply to all blockers, so that they both get money from non-blocking users as well as from blocking-users.
In the perfect world of Google content-blocking does not exist beyond mere visual ad-blocking of the most annoying ads.
ABP already allows cookies and network connections, so google still knows everything about those users.
Personally I use a combination of pi-hole, third-party cookie blocking and uBO, which takes care of basically all cross-site tracking. But when I recently had a look at another system of someone who uses ABP I noticed that the blocking really is only visual, theres still a profile that is being sold to data brokers, you just don't see the stuff they recommend to you.
The default settings of ABP are also extremely anti-user.
ABP/Eyeo is a wolf in sheep's clothing.
uBO users on the other hand are basically invisible to the survaillance capitalists.
Still not blocked on Google Safe Browsing.
- Google Safe Browsing
- Pihole including a couple of regularly updated malware lists
- uBlock Origin
It looks like Safe Browsing and pihole do not yet have this on the blacklist.
Thanks to Chromium, we are seeing a diverse range of projects emerging that cater to different groups.
Although the Dissenter extension, while a good idea, is essentially dead, there are basically no lively discussions.
So what's the point of using their product? Most users seem to think of it as a statement.
The idea of including BTC payments is certainly interesting, but it will fail, too, in the sense of Gab Browser not becoming succesful beyond a very small niche group.
Brave has been working for years to create actual incentives for the platform to flourish, it is beyond me how the Gab team thinks they can pull something similar off without any working incentive systems.
And Brave is not censoring anything. It is extremely difficult to build systems that protect user privacy, this has been ongoing for years, but not having user data is the whole point of the Brave project. If they fail with this, they won't be succesful.
The whole point of the Gab Browser is to protect free speech, even though strictly speaking no one has limited their free speech on a browser level, they could get the same free speech with using Chromium+Dissenter extension.
The idea with the Browser is to anticipate possible future censorship by Google, certainly legitimate.
Since they do not care about data, they haven't gone to great length of making sure they don't get any user data. If I remember correctly, every url visited in the Gab browser is sent to Dissenter, that's how the extension works.
The aggressivenes with which the Gab team goes against Brave on Twitter, wile taking all of their hard work without a single 'thank you', is what annoys me the most.
They seem to think free speech means everyone fighting for sensible solutions need to be "on their side", and everyone who isn't with them is against them.
I refute this picture of humans.
Silencing developments with ignoring them would actually do Gab a favor, whatever that means exactly. The term "hate group" is not clearly defined, anyway, and a propaganda-term in itself, and a tool of so-called 'hate'. .
Due to this I suspect that the Gab browser will only get a following in a certain sphere, i.e. ideologigcal Gab followers. Otherwise you can simply use Brave or Chrome.
There was criticism by Eich et al. who noted that Gab is sending all kinds of data back home.
Gab seems to be focused on providing a service to their followers, without having the actual technical expertise to create something solid based on true privacy.
(I.e. it doesn't matter when we collect the data because we are actually on the right side of the fence)
Nevertheless I am excited to see where all of this is going and I welcome any additional browser, which is good for creating a competitive market.
The fact that Gab can, without much knowledge, "create" a browser interface within days shows how great Chromium is for the advancement of the open web.
The only thing that needs to be solved is the governance of chromium with it becoming the de facto standard on the web.
The industry used fingerprinters, but for one it didn't really help them make more money (because you want to track users, not systems), and there was a big backlash.
Quote about canvas fingerprinting:
"Comparing our results with a 2014 study [1], we find three important trends. First, the most prominent trackers have by-and-large stopped using it, suggesting that the public backlash following that study was effective. Second, the overall number of domains employing it has increased considerably, indicating that knowledge of the technique has spread and that more obscure trackers are less concerned about public perception. As the technique evolves, the images used have increased in variety and complexity, as we detail in Figure 12 in the Appendix. Third, the use has shifted from behavioral tracking to fraud detection, in line with thead industry’s self-regulatory norm regarding acceptable uses of fingerprinting."
[1] G. Acar,C. Eubank, S. Englehardt, M. Juarez, A. Narayanan,and C. Diaz. The web never forgets: Persistent trackingmechanisms in the wild. InProceedings of CCS, 2014.
Other references:
[10] W. Davis. KISSmetrics Finalizes Supercookies Settlement.http://www.mediapost.com/publications/article/191409/kissmet.... [Online; accessed 12-May-2014].
[15] Federal Trade Commission. Google will pay $22.5 millionto settle FTC charges it misrepresented privacy assurancesto users of Apple’s Safari internet browser. https://www.ftc.gov/news-events/press-releases/2012/08/googl..., 2012
Prevalence:
- 1.4% for canvasfingerprinting
- 0.325% for canvasfont probing
- 0.0715% for WebRTC
- 0.0067% forAudioContext
The above were found only on the most shady of all websites, and good content blockers block all those scripts.
My bet is GDPR was the death blow for this kind of scripts. For small companies without a room full of lawyers data has become a liability.
So fingerprinting is now basically in the hands of google, amazon, etc.