Live data from Hacker News

Every Major Advertising Group Is Blasting Apple for Blocking Cookies in Safari

adweek.com

141–150 of 169 posts

Re: Every Major Advertising Group Is Blasting Apple for Blocking Cookies in Safari

#141
post #110

Earlier quoted context omitted.

The end result for the customer is that the ad industry will switch to cross-device tracking for everyone. Right now, you had an option to opt-out, by setting cookies to block. You were relatively safe. Now the default will become a net of machine learning algorithms which can track you cross-device without requiring cookies. It is not possible to safeguard against that, unless you completely randomize your online br…

Interesting point: If the despicable ad industry "ups their game", it might get harder to evade. What techniques exist in that space? Anything beyond browser footprints ( https://panopticlick.eff.org ) and super cookies? Any reasonably realistic suggestions for evading tracking in that scenario?

Learn a few new languages, browse on each device thinking with that language. It could be enough to fool some algorithms.

Re: Every Major Advertising Group Is Blasting Apple for Blocking Cookies in Safari

#142

Were there a publicly-traded company that manufactures small violins (preferably the one that makes "world's smallest"), I'd go long on their stock right now. I mean, who do they expect to persuade with this? Is there anyone not tied to the adtech industry shouting, "Damn you, Apple, and your assault on open web standards!" 'cuz me, I'm thinking, "without even reading the article, if the ad industry is upset about it…

There's definitely truth to this. However, website developers who rely on this data to monetize their sites with ads will suffer.

Re: Every Major Advertising Group Is Blasting Apple for Blocking Cookies in Safari

#143

Earlier quoted context omitted.

Good arguments. None the less, i think it's usefull to know the age, sex and interests of readers ( small client websites with some blogs). Religion, political affiliation, your living arrangements, your relationship with your family, ... are none of the concern. But i'm not sure that people are unhappy that ads are there. They just don't want to see them, without knowing why they are there or that it's privacy relat…

I work in advertising. I've even worked literally trafficking ads. Targeting any more specific than a good contextual match is usually a waste and not any more effective. Advertisers do not need this information and should not be given it. The agreement is that they show an ad in return for you seeing the page, that does not (and should not) mean that they get access to any more information than is absolutely necessa…

I work in advertising. I've even worked literally trafficking ads.

+1 from me for admitting it. That's the first step. Good luck!

Re: Every Major Advertising Group Is Blasting Apple for Blocking Cookies in Safari

#144
post #31

> When Apple first announced the limitations to cross-website tracking in June, the company said the changes are meant to improve trust with users, explaining that “users feel that trust is broken when they are being tracked and privacy-sensitive data about their web activity is acquired for purposes that they never agreed to.” This! I switched from Windows+Android to the Apple ecosystem in 2015. Because I love so ma…

Privacy is important, but breaking the functionality of cookies is the wrong way to address it. Not all cookies are used for tracking. Be prepared to start losing your settings in web apps or being logged out after 24 hours if you use Safari. What's more, the claim that Apple is doing this for the sake of user trust is a lie. The real reason they're breaking the functionality of cookies is the same reason they refuse…

> They're deliberately trying to hold back web technology so that people will be forced to create and use native apps instead.

If that was the intent they wouldn't have already killed the native APIs for device identifiers ages ago.

Re: Every Major Advertising Group Is Blasting Apple for Blocking Cookies in Safari

#145
post #31

> When Apple first announced the limitations to cross-website tracking in June, the company said the changes are meant to improve trust with users, explaining that “users feel that trust is broken when they are being tracked and privacy-sensitive data about their web activity is acquired for purposes that they never agreed to.” This! I switched from Windows+Android to the Apple ecosystem in 2015. Because I love so ma…

Firefox (w/ ublock origin), Firefox Focus, and the various on device VPN-style ad/tracking blockers (I use DNS66, there are others) make Android much improved over system defaults if you are concerned about tracking or ads. None of them require root or other non-stock-OS modifications.

Re: Every Major Advertising Group Is Blasting Apple for Blocking Cookies in Safari

#146
post #110

Earlier quoted context omitted.

The end result for the customer is that the ad industry will switch to cross-device tracking for everyone. Right now, you had an option to opt-out, by setting cookies to block. You were relatively safe. Now the default will become a net of machine learning algorithms which can track you cross-device without requiring cookies. It is not possible to safeguard against that, unless you completely randomize your online br…

Interesting point: If the despicable ad industry "ups their game", it might get harder to evade. What techniques exist in that space? Anything beyond browser footprints ( https://panopticlick.eff.org ) and super cookies? Any reasonably realistic suggestions for evading tracking in that scenario?

There is probabilistic vs. deterministic cross-device tracking.

Deterministic assigns a unique device identifier to each device and then uses more data to connect device IDs to an individual.

Probabilistic cross-device tracking uses machine learning algorithms to match up devices and identities. For this they can use basically any data that you happen to give them, including behavioral data (you check a website both at home and during transit on your mobile phone, you use the mouse to select text during reading an article, you accidentally gave an application access to your location data and they have resold this, etc.). Probabilistic cross-device tracking can work with and without cookies. Of course ad companies employing these techniques for their customers claim very optimistic accuracy, but know that the accuracy is at least accurate enough to provide them with useful tracking data on individuals. This accuracy will go up if you push ad companies in a corner and confront them with a 10% (or whatever marketshare Apple browsers have) non-cookie-able surfers (as opposed to a fringe small sample of users that block cookies and did so for years).

When cookies got banned/required permission in Europe, European websites just started buggering everyone to accept cookies before you were able to read what you were coming for. While everyone already had the option to only allow cookies from trusted domains, now everybody gets pestered with giant pop-ups. Companies also switched to server-side analytics/tracking, or started requiring log-in to track you.

If cookies were accepted, one could just join a cookie swap program to mess with the advertisers. Probabilistic cross-device tracking is very hard to avoid, as not using javascript and a general browser like TorBrowser is also an informative fingerprint. And you can't realistically change your browsing habits, which exposes you to gender and age identification (they need this to identify individuals in a household using a single IP).

Re: Every Major Advertising Group Is Blasting Apple for Blocking Cookies in Safari

#147
post #124

Earlier quoted context omitted.

> Make compromises that are reasonable. When it's so easy to use a community-vetted Linux distribution, I think "reasonable" gets shunted down a layer. It's not all or nothing. Every reasonable step counts.

> community-vetted i wonder if this sort of confidence makes you less-safe. something like this should've prevented heartbleed, in theory, right?

It's not confidence that I'm secure, it's a belief that this software development process makes me more secure.

You and your friend down there seemingly have more faith that a closed source process, what, would have identified this bug before it was deployed? Why? That it would have been found by good actors first? Why? That it would have been fixed promptly? Why? Announced with disclosure of its existence and ramifications? Why?

It's not a money question for this stuff either. There are hundreds if not thousands of paid engineers for known good-actors all working to break and responsibly disclose security issues in the same software stack I use.

The only thing you know about the comings and goings of closed source software is when public disclosure happens (and it's later fixed). Why would I be more confident in that process? It's not good enough.

Re: Every Major Advertising Group Is Blasting Apple for Blocking Cookies in Safari

#148

Were there a publicly-traded company that manufactures small violins (preferably the one that makes "world's smallest"), I'd go long on their stock right now. I mean, who do they expect to persuade with this? Is there anyone not tied to the adtech industry shouting, "Damn you, Apple, and your assault on open web standards!" 'cuz me, I'm thinking, "without even reading the article, if the ad industry is upset about it…

I work on a checkout product that is implemented as a third-party iframe. We set a cookie so that a user can have their information remembered for the next time, so that if you've shopped at merchant A, you won't have to fill out your information again when you want to shop at merchant B or C. We don't use it to track you or profile you, it's literally just to make it easier for you to check out (which makes our merchants happy because they see less drop-off). We have a very simple and obvious way of opting out of this, directly in the checkout itself, if you for whatever reason don't want to be remembered.

Unfortunately, because most people don't visit us in a first-party context, we are classified as a tracker, so we can't read our cookie anymore. The result being that our customers have a worse experience. If they want to get prefilled, they'll now have to go through this weird redirect song and dance so that we can interact with them in a first-party context.

So yeah, while I'm generally for enhanced privacy, I think this specific implementation is harmful. I think that all it achieves is that it consolidates the ability to track users to a small number of giants that you routinely interact with in a first-party context on a daily basis (Facebook, Google, etc).

Re: Every Major Advertising Group Is Blasting Apple for Blocking Cookies in Safari

#149
post #110

Earlier quoted context omitted.

Interesting point: If the despicable ad industry "ups their game", it might get harder to evade. What techniques exist in that space? Anything beyond browser footprints ( https://panopticlick.eff.org ) and super cookies? Any reasonably realistic suggestions for evading tracking in that scenario?

There is probabilistic vs. deterministic cross-device tracking. Deterministic assigns a unique device identifier to each device and then uses more data to connect device IDs to an individual. Probabilistic cross-device tracking uses machine learning algorithms to match up devices and identities. For this they can use basically any data that you happen to give them, including behavioral data (you check a website both…

Probabilistic cross-device tracking uses machine learning algorithms to match up devices and identities

Is there any application of machine learning that isn't evil? Genuine question. It seems to be exclusively used to exploit people.

Re: Every Major Advertising Group Is Blasting Apple for Blocking Cookies in Safari

#150
post #84
post #65

Earlier quoted context omitted.

> Not all cookies are used for tracking. No, but third-party cookies are basically used for tracking. A legitimate site does not depend on a third-party cookie to handle features or login. At all, full stop no ifs, ands, or buts. I'd point out that in the case of DocuSign signing sessions powered by iframes that without being able to set this third party cookie prevents the session from loading. Probably the only use…

Aren't the site in the iframe uses its own cookie? (So it doesn't count as 3rd party, no?)

That's not how it works. Even if you're setting the cookie on your own domain, if you're embedding your site in an iframe on a different domain, you won't be able to read your own cookies from within the iframe after this change.
Post reply on HN