Live data from Hacker News

GDPR will pop the adtech bubble

blogs.harvard.edu

41–50 of 454 posts

Re: GDPR will pop the adtech bubble

#41

Earlier quoted context omitted.

What site you run and why you need to log my personal data(IP,browser,other identifying data) do you have good reasons to keep it forever or you purge it after you analyze it?

How is IP and browser personal data ? If you think it is, you should not be on the internet.

Anything and everything that’s about a person in any way is personal data.

Re: GDPR will pop the adtech bubble

#42

>Since tracking people took off in the late ’00s, adtech has grown to become a four-dimensional shell game played by hundreds (or, if you include martech, thousands) of companies, none of which can see the whole mess, or can control the fraud, malware and other forms of bad acting that thrive in the midst of it. Fraud? Malware? What does this have to do with adtech? >And that’s on top of the main problem: tracking pe…

The laws would hopefully stop the tracking of users. IS there a good reason why you can't analyze the page you put your ad in and decide what category on ads will fit, so on tech pages put tech related ads. Tracking me and creating a profile on me should be illegal. Showing ads is perfectly fine

KYC.

Google almost rabidly doesn't want to connect who is sponsoring with what they're sponsoring.

I'm an ad network that does (some) tracking of users. I make it a point to connect advertisers with the publishers I work with because I know all of my publishers. I think this service has value.

Whilst I charge substantially more than Google does, I'm confident I don't participate in any ad fraud. If a Google rep. suggests they don't serve ad fraud, let me know, because I have proof otherwise.

Re: GDPR will pop the adtech bubble

#43
post #2

And that’s on top of the main problem: tracking people without their knowledge, approval or a court order is just flat-out wrong. The fact that it can be done is no excuse. Nor is the monstrous sum of money made by it. I use Piwik ( https://github.com/matomo-org/matomo ) and track visitors without their knowledge or consent, because I need analytics. Piwik is also configured to respect the "Do not track" header, so o…

Yes, that is wrong. You MUST tell your users that you are tracking them, and what the data you collect will be used for.

Re: GDPR will pop the adtech bubble

#44
post #2

And that’s on top of the main problem: tracking people without their knowledge, approval or a court order is just flat-out wrong. The fact that it can be done is no excuse. Nor is the monstrous sum of money made by it. I use Piwik ( https://github.com/matomo-org/matomo ) and track visitors without their knowledge or consent, because I need analytics. Piwik is also configured to respect the "Do not track" header, so o…

Serious question: What are the odds of someone offical even noticing that you are in violation of GDPR? It's not like they'll enforce GDPR and collect $7.89 in fines from small businesses.

Why would you care about someone official? I'd care more about a bot that is set up to save the officials some work.

Re: GDPR will pop the adtech bubble

#45

Earlier quoted context omitted.

The laws would hopefully stop the tracking of users. IS there a good reason why you can't analyze the page you put your ad in and decide what category on ads will fit, so on tech pages put tech related ads. Tracking me and creating a profile on me should be illegal. Showing ads is perfectly fine

> IS there a good reason why you can't analyze the page you put your ad in and decide what category on ads will fit, so on tech pages put tech related ads. There isn't and this is what many people do. But that isn't the argument is it? Can you tell me why observing what people do on my website is unethical and why it should be made illegal? Also can you explain why information that is placed on my server belongs to s…

If someone has access to your laptop and downloads their photos onto it, who do those photos belong to?

Good analogy! They belong to the person who took them, as per copyright law, not to the owner of the laptop.

Re: GDPR will pop the adtech bubble

#46

>Since tracking people took off in the late ’00s, adtech has grown to become a four-dimensional shell game played by hundreds (or, if you include martech, thousands) of companies, none of which can see the whole mess, or can control the fraud, malware and other forms of bad acting that thrive in the midst of it. Fraud? Malware? What does this have to do with adtech? >And that’s on top of the main problem: tracking pe…

>What a compelling argument /s. Is it wrong if I sit on my porch and record in a notebook the hair color of different people? Is it wrong if I observe that one of my coworkers has a Harley Davidson sticker on his laptop? As far as I know, there's an invasion of privacy tort in common law: https://torts.uslegal.com/intentional-torts/invasion-of-priv... P.S. I am not a lawyer.

I do not see how that applies to observing people when they have no reasonable expectation of privacy. And when using all these websites I'm pretty sure they put at the top of the ToS that they will be using your information.

Re: GDPR will pop the adtech bubble

#47
post #2

And that’s on top of the main problem: tracking people without their knowledge, approval or a court order is just flat-out wrong. The fact that it can be done is no excuse. Nor is the monstrous sum of money made by it. I use Piwik ( https://github.com/matomo-org/matomo ) and track visitors without their knowledge or consent, because I need analytics. Piwik is also configured to respect the "Do not track" header, so o…

Serious question: What are the odds of someone offical even noticing that you are in violation of GDPR? It's not like they'll enforce GDPR and collect $7.89 in fines from small businesses.

A good question. But that’s not how these things work. The law has to be self enforced or it’s useless - since as you say, how will small to medium businesses ever be caught violating?

Megacorps comply because of mega fines.

Small business comply because their owners or future buyers are a larger Corp who fears that their sub-subsidiary might be in violation, causing a future mega fine.

So small businesses who care about the value of their company follow these rules. It’s almost exactly the same reason small business buy software licenses. It’s not of fear of fines but because otherwise they don’t look like a serious company.

I question I have been wondering is how many companies will leave some violations such as data in backups - simply because removing it is too expensive so it’s a risk worth taking. I honestly haven’t understood how backup of data fits into the requirement to delete data of a certain age?

Re: GDPR will pop the adtech bubble

#48

Earlier quoted context omitted.

What site you run and why you need to log my personal data(IP,browser,other identifying data) do you have good reasons to keep it forever or you purge it after you analyze it?

How is IP and browser personal data ? If you think it is, you should not be on the internet.

IP and browser information are definitely PII, which is Personally Identifiable Information. Those are PII, because they can be used to personally identify an individual.

Re: GDPR will pop the adtech bubble

#49

>Since tracking people took off in the late ’00s, adtech has grown to become a four-dimensional shell game played by hundreds (or, if you include martech, thousands) of companies, none of which can see the whole mess, or can control the fraud, malware and other forms of bad acting that thrive in the midst of it. Fraud? Malware? What does this have to do with adtech? >And that’s on top of the main problem: tracking pe…

>Fraud? Malware? What does this have to do with adtech?

A lot, actually. There are many vectors in which adtech and fraud/malware intermingle:

> XSS Attacks:

When your website loads HTML into a page without encoding it first, someone can insert HTML script tags that your browser will parse successfully, allowing arbitrary Javascript to execute in your browser. Malicious actors will then usually redirect you to further unsafe pages that will initiate more downloads or (depending on circumstances) compromise your active user session or credentials. All you need is an ad network that didn't take precautions for a malicious ad and you're serving malware to all downstream users.

>True Clickbait with a malware payload:

Less common nowadays in the sense I mean: Ads that are literally designed for you to click on them, giving the same result as above. We're talking things like "Punch out Osama Bin Laden!" from the early 2000s or "Click here to win a prize!" affairs, where there's no reason a user ought to be clicking on the ad except that they were, quite literally, baited into doing so.

>Normal Clickbait with a malware payload

Create some "interesting content", that just happens to also do all of the above. Miracle cures, "BIG cost savings", poorly vetted porn-ads, and so on. A lot of internet chum is of this type, and there's a great article analyzing it [1]

>Literal Scams:

Many ads presented on websites prey on low information individuals, the elderly, or the young, all of whom are less likely to know any better.

My point is, all of the above is served, with some regularity, over many ad networks today. This means in some sense, many ad networks are responsible for the ads they serve and the damage they cause their users; if not legally, at least morally.

[1] https://www.theawl.com/2015/06/a-complete-taxonomy-of-intern...

Re: GDPR will pop the adtech bubble

#50
post #31

Earlier quoted context omitted.

Under GDPR guidance, IP addresses are considered personal data because they can be used to identify an individual in a moment in time. Personal data consists of things that identify individuals, but also things that can be used in conjunction with other information to identify individuals. You might not like that, but the regulators are pretty clear on this point.

The ICO does not consider IP addresses personal data since more than one person could use a computer in a household.

That seems like a weak argument though. Two humans can also have same name and zipcode. They can also have same personal number and bank account number if they are in different countries. Without tracking and correlation, most information on its own is useless.
Post reply on HN