Live data from Hacker News

WebKit Tracking Prevention Policy

webkit.org

111–120 of 254 posts

Re: WebKit Tracking Prevention Policy

#111

Earlier quoted context omitted.

But it needs to be public. “Trust, but verify.”

Why does it NEED to be public? So the bad actors can know how they are being caught and mitigated and can circumvent again and again?

The bad actors just need to open their own website in webkit to check if they are being blocked in some way. They will always know if a particular tracking strategy they are using is not working. So there is no harm in making the list public.

The benefit of making the list public is that blocking tech is in some sense of the word censorship. The public needs to know who is being blocked to ensure transparency and to ensure that WebKit is not using their blocking technology nefariously.

Re: WebKit Tracking Prevention Policy

#112

Earlier quoted context omitted.

The problem is that by doing that, you’re skimming the top percentile of your user base with the most purchasing power. You’re much less attractive to advertisers then.

The same argument could be made arguing against the launch of YouTube Premium.

YouTube has essentially monopolized video (especially being that Netflix has no adverts). YouTube knows that from that position, it’s competing only with adblockers.

Re: WebKit Tracking Prevention Policy

#114

Earlier quoted context omitted.

For some reason people just have an aversion to paying for stuff they use. Facebook's revenue per user is less than 7$, I don't use facebook, but do not mind paying that little for something I use instead of getting tracked wherever I go. Similarly Google's service that I use like gmail and photos are easily worth about 7$ per month. I would pay if they said they will stop tracking me. I don't know about youtube.

The problem is that by doing that, you’re skimming the top percentile of your user base with the most purchasing power. You’re much less attractive to advertisers then.

Notice how the NY Times has subscriptions.

Re: WebKit Tracking Prevention Policy

#115
post #36

Earlier quoted context omitted.

We are not presently manually curating a specifically targeted mitigations list. Just saying we might in the future. We did do a one shot rollback of HSTS super cookie abuse in the past, but that’s it.

But it needs to be public. “Trust, but verify.”

OK, that's good feedback if we ever need targeted mitigations in the future.

Re: WebKit Tracking Prevention Policy

#116
post #64

Earlier quoted context omitted.

> Didn't people make money off internet advertising before the modern surveillance-marketing complex? What happened to it? Non-contextual advertising still exists, but it's perceived as less effective, so there's a lot less money in it. I don't know if that perception is correct, but I do remember back when a common complaint from people was that the ads they saw weren't relevant to them. It's also not just targeted…

> Non-contextual advertising still exists, but it's perceived as less effective, so there's a lot less money in it. I don't know if that perception is correct, but I do remember back when a common complaint from people was that the ads they saw weren't relevant to them. As far as I’m aware, the current state of advertising is people either being too creeped out by ad suggestions to buy anything or still feeling like…

Back in May I was looking for a new apartment. Via what’s app I requested the agent ask the landlord to put window restricters on the windows as they do not have window grills.

I never googled it searched or said anything in Facebook. Since the day after I requested this from the agent. I’ve had window restricters and grills show up in Facebook advertising.

I find it creepy that what’s app is meant to be private and encrypted when clearly it’s not.

Re: WebKit Tracking Prevention Policy

#117

I expect that tracking will just move to being proxied server side. It will be more annoying for the people setting it up but services will spring up to help. Little will change in the advertising and tracking space.

It's actually pretty hard to do this. You still need some way to consistently identify the same user across different sites. Stateful tracking, fingerprinting, and link decoration are the only ways we know of to do this and we have our sights set on all of them.

Re: WebKit Tracking Prevention Policy

#118

Earlier quoted context omitted.

Sure, but YouTube doesn't stop tracking you when you pay.

But what does that mean? YouTube keeps a history list, which I download and periodically reset. If it didn't I would need to add some sort of Firefox add-on that remembered which videos I'd seen. What else are they "tracking"? Does YouTube have tracking on other sites (like Facebook, Twitter etc)? I haven't seen anything like that. You can switch the history off, I presume that would work even without Premium, but it…

if youtube isn't tracking me in malicious way, why would I pay them to stop them from tracking me?

but the error here is conflating a tool with a legal person. Google will track me no matter how much I pay them for any of their services, including YouTube.

the situation at the moment is that no-one believes that a corporation who offers a free service is going to not track you because you pay for the premium version. so (a) I'm not going to pay Google or Facebook to get the premium version since it is not going to be untracked and (b) Google and Facebook aren't going to detrack their premium services since no-one believes that's going to happen anyway - the value add is removing ads/playing with the screen off/etc not the absence of tracking.

the best you can do is pay a third party to offer you some service Google or Facebook offers for free, thereby reducing your exposure. for instance, Google surely knows the content of many emails sent to me, but not all of them, since I pay for email from another provider; or I'm strongly considering paying for a substitute for Google docs, except that I don't like unpredictable monthly USD payments.

Re: WebKit Tracking Prevention Policy

#119
post #47

Earlier quoted context omitted.

Didn't people make money off internet advertising before the modern surveillance-marketing complex? What happened to it? I mean, maybe the answer is that those ads were only profitable because of the novelty factor and now that we have metrics we know they don't work, or at least don't work anywhere close to how much they cost. But I do miss things like the webcomics running their own ad network, Google's textual ads…

There is also the ongoing escalation between adverrtisers and fraud. Creating an incentive to collect ever more data to detect ever more sophisticated forms of fraud.

How is fraud handled for TV advertising? Or print? This isn’t some weird new problem. The truth is that ad-tech wants to track you to make your profile more valuable, however, a less valuable user doesn’t mean advertising doesn’t work, it just means the bottom-feeding middlemen get a less profound payday.

Why not just flip the model from eyeballs and clicks to actual ad effectiveness? Newspaper car ads have this down to a science. They don’t count “clicks” of their newspaper ad — they see how many customers come in asking about a car in the ad.

If I have an airplane website and someone wants to advertise to people who like airplanes. I can suggest a price of $1000 and if the advertiser wants to spend the money, they do. I might charge $1000 because I have a lot of visitors or just because I want to. That’s the price I set for whatever reason I set it. If an advertiser doesn’t want to spend that, they can choose not to. If they want to measure effectiveness, they can do it by offering viewers of that ad a discount code or something. When the code is used, they know they got that customer from my ad. Once they’ve validated that their ad “works” and the acquisition cost works, then they’ll keep paying my rate — no bot influence at all. No real chance of fraud because there wouldn’t be any money in it. Publishers would actually have an incentive to sell your product because they want to justify their ad rates. No need for tracking either.

Advertising works and it can be both more effective and privacy-respecting. Ad-tech has turned vast swaths of the Internet into a cesspool. It doesn’t have to be like that.

If you are a publisher and have actual content humans care about, ditch the ad networks and start selling your pixels directly to relevant advertisers.

The problem is that the incentives for fraudsters and publishers are aligned under the current model: more clicks equals more money, the actual advertiser who is selling something gets to pay that fraud tax. Perhaps advertisers should start seeking out relevant content and offering to buy space directly, refusing to deal with “networks.” Their acquisition costs would go down, that’s for sure. Harder to scale, but so what, you have a higher yield effort for a lot less money.

Re: WebKit Tracking Prevention Policy

#120
post #20

Earlier quoted context omitted.

> Google Analytics Website analytics should not rely on cross-site tracking. Breaking any cross-site tracking ability of GA is unambiguously good for users. > Google Ads conversion tracking Apple already proposed a mechanism of privacy-protecting click attribution. If Google doesn't want to use that, it's because they don't respect your privacy. Again, unambiguously good for users. > Using same login across different…

That click tracking spec is useless for advertising at scale. It only supports up to 64 campaigns is what I remember as the worst offender, somewhere in my comment history is a bit more when I first read the spec.

It offers 6 bits of campaign ID with the intention that campaigns need to be bucketed. Maybe it could be a bit more, but if it was, like, 32 bits, it could be used as a user ID.
Post reply on HN