Live data from Hacker News

GDPR will pop the adtech bubble

blogs.harvard.edu

151–160 of 454 posts

Re: GDPR will pop the adtech bubble

#151
post #111
post #78

Earlier quoted context omitted.

How is this related to GDPR or the adtech bubble?

Because it makes doing business with europe illegal. Sanctions are war. GPDR isn't war, but depending on who looks over the laws in europe, giant part of our economy will be illegal to europe also.

Or you could avoid adtech and misleading clickbait, which everyone hates

Re: GDPR will pop the adtech bubble

#152

Earlier quoted context omitted.

Yes, it explicitly mentions it, because it's actually very often true. Of course there are plenty of examples where it would be extremely difficult to link to an individual, but there are tonnes of examples where it's extremely easy. GDPR says that because it's sometimes easy, you have to consider it personal data. Again, it's not always saying an IP address is a personal identify. It just is often enough.

> Again, it's not always saying an IP address is a personal identify. It just is often enough. Well, that's not what you said or implied. I'm just thinking of all the cases in the US were the defense is you can't assume that an IP address ties to a specific person. Anyone could use the computer, or someone could attach to an open wifi. Basically, if the legal argument is the IP address can be associated with a person…

I said they can be used to identify an individual in a moment in time. That's correct.

Can it always identify an individual? No. Is the standard of identification good enough for a criminal case? Certainly not. But why are you comparing these? The GDPR is a standard about privacy and data protection; a UK postcode (like a zip code in the US) is considered personal data for exactly the same reason.

Re: GDPR will pop the adtech bubble

#153

Oddly, I think the article underestimates the size of the change coming. I think one side affect of the surge of IT into advertising, is that it has become easier to measure exactly how well advertising works. By and large, it doesn't, very well. I am reminded of this, from Paul Graham, about his time at Yahoo: http://www.paulgraham.com/yahoo.html "...The reason Yahoo didn't care about a technique that extracted the…

> By and large, it doesn't, very well. I know Twitter isn't known for being the best at advertising, but it was made exceptionally clear to me that online advertising is a massive bunch of lies when I did my GDPR Twitter data export and it included me in a bunch of incorrect, non-sensical and contradictory ad targeting groups. Twitter claims I: * Own a cat, dog and other animal (I don't) * Have between $100k- $999k l…

Facebook believes I'm african-american (I'm not)

Re: GDPR will pop the adtech bubble

#154
post #49

Earlier quoted context omitted.

>Fraud? Malware? What does this have to do with adtech? A lot, actually. There are many vectors in which adtech and fraud/malware intermingle: > XSS Attacks: When your website loads HTML into a page without encoding it first, someone can insert HTML script tags that your browser will parse successfully, allowing arbitrary Javascript to execute in your browser. Malicious actors will then usually redirect you to furthe…

> XSS Attacks Not true with safeframes The latter two can happen on the internet in general, third-party advertising is in no way a unique delivery vector.

>safeframes

Safe frames are not the general solution that you make them out to be.

First, site owners have to actively choose to use safeframes. My personal opinion, just based on people I've spoken with about this, is that most businesses and individuals who run websites treat their ads as a black box and their security as an afterthought. This means any solution for security that isn't by-default and that non-technical site owners have to turn on themselves, with near total certainty, isn't going to be protecting users.

Plus, not all ad networks support it as of June 2017 [1]. In my view, it's less a solution than a "literally-crafted-by-the-ad-industry" [2] externalization of responsibility for users getting hacked due to poor network policing.

[1]https://www.monetizemore.com/blog/should-you-use-dfp-safe-fr...

[2] Page two of https://www.iab.com/wp-content/uploads/2014/08/SafeFrames_v1...

Re: GDPR will pop the adtech bubble

#155

Earlier quoted context omitted.

> By and large, it doesn't, very well. I know Twitter isn't known for being the best at advertising, but it was made exceptionally clear to me that online advertising is a massive bunch of lies when I did my GDPR Twitter data export and it included me in a bunch of incorrect, non-sensical and contradictory ad targeting groups. Twitter claims I: * Own a cat, dog and other animal (I don't) * Have between $100k- $999k l…

> I was very disappointed that the Google and Facebook data exports don't contain this data. Facebook has it available, if not in their Download Your Information tool. Go to Settings -> Ads -> Your Information -> Categories.

Mine says "You do not have any behaviors in your ad" preferences. https://i.imgur.com/giAxfiF.png

But interesting page. Looking at the "advertisers who have added your details to their targeting list" it again shows how bullshit this industry is:

    * Playstation in 19 countries
    * Musicians which I definitely don't listen to, like Keith Urban, Post Malone, Jack White, YBN Nahmir, and Ziggy Marley, whoever these people are.
    * Pages like "Top Kickstarter Watches" and "Top Kickstarter Inventions"
    * A bunch of restaurants that I've never been to, but are in the same complex that I used to live in (thanks whoever sold/'shared' my email, literally probably my former real estate agent)

Re: GDPR will pop the adtech bubble

#156

Completely oblivious and ignorant here: If a company has no official office in Europe, how does this affect them? All advertisement and business focus is say only in the US, is it business as usual? What if an EU citizen decides to sign up? Are US companies forced to deny customers not par of say an IP block (half assed method I know, but just speaking in general)?

I work in the USA, as a sysad. The company I work for has a social media product.

We've have had European and African citizens who've signed up. And that was more than enough for us to discuss "How do we make our stuff comply with the GDPR?". If we ever considered in starting up in Europe, us ignoring the GDPR is tantamount to writing them off before even thinking of them.

We also do things the right way. Deletion requests aren't treated as "ignore kthxbai", but all data is zeroed out then nightly purged from the DB. And I really think, with how current society is slowly turning against orgs like facebook, the way we're approaching this is one avenue of right ways.

Re: GDPR will pop the adtech bubble

#157
post #33

Earlier quoted context omitted.

So is your position that website owners should have no visiblity at all on their visitors, and no way of knowing how many people are using it?

They can know how many people, as long as they don't store personal information. Keeping a counter doesn't require consent.

Keeping a reliable counter of meaningful interactions is hard without personal data to correlate unique users.

Re: GDPR will pop the adtech bubble

#158

Earlier quoted context omitted.

Under GDPR guidance, IP addresses are considered personal data because they can be used to identify an individual in a moment in time. Personal data consists of things that identify individuals, but also things that can be used in conjunction with other information to identify individuals. You might not like that, but the regulators are pretty clear on this point.

> Under GDPR guidance, IP addresses are considered personal data because they can be used to identify an individual in a moment in time. That's actually the most frightening thing I've heard in a long time. Does the GDPR actually make that connection? If so, it literally links people to an IP address, rather than simply a connection. If that line is accurate, I'm surprised it hasn't been mentioned before, associating…

No, the GDPR does not actually link people to an IP address. The GDPR never even refers to an IP Address, and where it refers to an Internet address, it is clear it's referring to email addresses.

The ICO (furthermore) has given guidance that they don't think an IP address is uniquely identifying an individual, and have confirmed this to me on the phone.

Where you get into trouble is in transmitting your browser logs/activity to a third party who wants to keep them for their own purposes (e.g. Google). In this circumstance, you have to let people know that you've done this, and to transmit their preferences that you receive onward.

Re: GDPR will pop the adtech bubble

#159

Earlier quoted context omitted.

I have visited a drugstore to buy some vitamins yesterday. They have handled me a touch-screen where I had to check a checkbox (saying that I agree to allow my medicines shopping history to be stored and analyzed to track my health (which I obviously don't want them to do actually)) and an electronic signature tablet with a stylus where I had to put my signature. This was a mandatory condition for continuing using a…

That's a good question, I don't know if it's valid to offer discounts and such in exchange for consent. It goes against the EU principles ("personal information cannot be conceived as a mere economic asset"), but I'm not sure if the law actually prevents it.

> personal information cannot be conceived as a mere economic asset

I wonder why not? Personal information is useless for most people, they give it away for free to the state institutions and the police wont even ask your consent. Some websites and services have found a way to make money off it, in exchange for free services etc. Why is this an ethically unacceptable proposition?

Re: GDPR will pop the adtech bubble

#160
post #14

From one of the references in the article: The Google consent interface greets site visitors with a request to use data to tailor advertising, with equally prominent “no” and “yes” buttons. If a reader declines to be tracked, he or she sees a notice saying the ads will be less relevant and asking to “agree” or go back to the previous page.

Adtech is a joke. Even targeted ads are so irrelevant to the point where I don't think most people can tell if they're random or not. Except when the creepiness kicks in, because they show you ads for this one thing you googled a week ago. Google can't get it right. Their ads suck, and their Youtube suggestions aren't much better. Amazon can't get suggestions right in their own store. The whole ad industry is a joke.…

I honestly think this is very, very user dependent. Mainly because if Google's ad tech wasn't working, they wouldn't be making so much money....

You, I, and everyone else on this site don't represent the average user. Personally whenever I Google something out of curiosity as a one-off thing (e.g. "lyrics to Rasputin by Boney M" or "0-60 of a Golf GTI") I switch to in-cognito, just because I've noticed that Google isn't currently tracking stuff like that by IP. This way I don't get recommended Boney M videos in YouTube or adverts for cars I don't actually have an interest in elsewhere. And that's on top of uBlock, Disconnect, Privacy Badger, and a Pi-Hole on my home network. But I work in cyber security and I am in no way a "normal" internet user. Same with TV, I'm a cord-cutter with Plex running on a VPS: meanwhile everybody I know who doesn't work in tech just watches TV normally.

Pretty much everyone on this site saying "advertising doesn't work" is right that it probably isn't as effective for them because they've been taking counter-measures for years, but millions (possibly billions) of normal internet users do click on ads, or have their purchases influenced by ads.

I do agree with Patreon and Netflix, they're fantastic business models. Add Spotify to the mix too: although the renumeration they give to artists is laughable, it's a fantastic platform which has gotten me to actually pay for music for the first time in about a decade.

Post reply on HN