Snippets from the article: > The evidence further reveals that Google allowed [...] > Google has no control over what happens to these data once broadcast [...] Is it possible that Google does have "control" over the data after broadcast, albeit legal control via contracts with advertisers (as opposed to technical control)? Perhaps Google's GDPR compliance strategy relies on the participating advertisers to comply wi…
The real time bidding on ad placements seems like a thing that a user could never give consent to as it's literally feeding your info to a massive ever churning list of companies that get to bid on it. Aka - you land on a site, it send your IP and whatever identifiers it has to 10,000+ companies who all then figure out if they want to bid on showing you an ad.
Google’s GDPR Workaround
481–490 of 629 posts
Re: Google’s GDPR Workaround
#482Earlier quoted context omitted.
You spammed an HN thread with these comments before, which amply explains why you were downvoted. We've been over this topic a gazillion times on this site: https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme... . Astroturfing exists, but imagined projections of astroturfing are far more common, and whatever the effects of the former may be, the latter has an extremely degrading effect on discussion. In fact…
Are you saying I am not able to discuss this true story where it's relevant? In threads where people have discussions that hold Google in a negative light cause they choose to act that way and get caught? My real life story along with the MIT's student story in which there's clear evidence of Stealing IP further details more bad behavior by the big G! Is Hacker News not a place where freedom of speech is welcome? Spe…
Separately, there was an issue with your copy-pasting the same comment about this story repeatedly in a previous thread. That is what I called spamming (not the actual story). Doing that is no doubt what led to your being downvoted, rather than manipulation as you implied above.
In cases where the story is relevant, of course it's fine to discuss it. But I don't see that it's relevant here, and your history of bringing it up in ways that break the site guidelines suggest that the bar for relevance needs to be higher than how you've been drawing it.
But the main point is that you can't make up sinister stories about why you got downvoted ("I can attest...") and post them here. Long experience has shown that nearly all such comments are baseless, and as I just said, they eat everything if you let them. Therefore we mustn't let them.
Re: Google’s GDPR Workaround
#483Earlier quoted context omitted.
The real time bidding on ad placements seems like a thing that a user could never give consent to as it's literally feeding your info to a massive ever churning list of companies that get to bid on it. Aka - you land on a site, it send your IP and whatever identifiers it has to 10,000+ companies who all then figure out if they want to bid on showing you an ad.
Do you have to give consent for each individual third party your data gets shared with? I’d thought that if you give consent for some purpose, the company can use whatever processors it wants as long as it ensures they protect your privacy.
As I understand it, you're correct. The Data Controller (Google) is responsible for getting consent, and the Data Processors (the third parties in this case) don't have to get consent themselves.
However, assuming Google's legal basis for processing your personal data is based on consent (rather than fulfillment of a contract or one of the other legal bases), then Google is required to get your unambiguous, opt-in, and non-coerced consent for each specific way your personal data will be used.
It seems likely that Google is covering themselves by acting as a Data Processor, not Data Controller, and the web site using Google is the actual Data Controller. In that case, the web site, not Google, is the one responsible for getting consent.
Re: Google’s GDPR Workaround
#484Targeted ads are already a serious leak of information. If somebody looks over my shoulder and sees the ads presented to me, they can infer things about me. Also, if a malicious actor targets an ad to a group of people, and some of these people buy the advertised items, then the actor can infer things about those people not necessarily related to the items sold.
Why are so many people that paranoid. No one is gonna destroy your life because they saw your ads
Re: Google’s GDPR Workaround
#485Earlier quoted context omitted.
I confess that I've also never really understood why people are so outraged by the hypothetical it likely presence of actual shills: it's not like the population of non-shill commenters doesn't already produce every stupid and inane take possible. Shills can shift the composition of votes and comments away from a given board's biases (towards their preferred biases), but what does that change from the perspective of…
Critical thinking is one thing, but that's not always or even usually the point of such campaigns. It can be as simple as 'bandwagon effect', which regardless of how silly it is to believe people behave that way, they absolutely do. Few people want to be on the unpopular side of an opinion.
I can't relate to this impulse even a little bit, but believe that it's common. That being said, I don't see how its ubiquity makes it any less a failure of critical thinking ability.
The Internet is a pretty hostile environment for those whose epistemology depends on who's behind the pseudonym: it's not clear to me that shills are going to make these people much worse at thinking and processing information than they already are.
The same goes for those who do have appreciable critical thinking abilities: you shouldn't be credulously consuming the thoughts of any random pseudonym, and the same skeptical habits that inoculate you against dumb ideas from unpaid strangers work roughly as well on shills.
Re: Google’s GDPR Workaround
#486I checked the sample log provided. Below is the google_gid for different publishers, there is no proof of overlap, they have different google_gid for same person. Which is exactly what google describes. [1] I don't understand what Brave claims. d.agkn.com CAESEP-S3Zs5f0_kq11XTCZP_mE id.rlcdn.com CAESEPpf2T4-2AsAR_4rer3RfNs image6.pubmatic.com CAESEB9H3qdV26kxEiz-BJ_TY-M pippio.com CAESEJyqG1Pg1j-_scqW8kDzTkg token.ru…
This log [0], right? Did you miss in the article that it's the `google_push` identifier that's being used for syncing between adtech companies? If you search for it (AHNF13KKSmBxGD6oDK9GEw5O0kvgmFa3qM30zpNaKl72Og), you can see it being included in requests to lots of different adtech firms' domains. [0] https://brave.com/wp-content/uploads/files_2019-9-2/sample_p...
BidRequest Data [0] and Request Time is already enough to fingerprint the user.
"Google prohibits multiple buyers from joining their match tables." part is not technical, it is contract based.
[0] Sample Data from Bid Request
ip: "F\303\006"
user_agent: "Mozilla/5.0 (Linux; Android 7.1.1; Pixel XL Build/NOF26V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Mobile Safari/537.36"
url: "http://www.myfitnesspal.com/food/calories/popeyes-buttermilk-biscuit-29980768"
cookie_version: 1
google_user_id: "CAESEIMlaNwMN-rtiDFzjwNIX6Y"
timezone_offset: -360
detected_content_label: 39
mobile { is_app: false 3: "android" 8: 1 12: "google" 13: "pixel xl" 14 { 1: 7 2: 1 3: 1 } 15: 412 16: 732 18: 70092 19: 3500 }
cookie_age_seconds: 12960000
geo_criteria_id: 9023221
device { device_type: HIGHEND_PHONE platform: "android" brand: "google" model: "pixel xl" os_version { major: 7 minor: 1 micro: 1 } carrier_id: 70092 screen_width: 412 screen_height: 732 screen_pixel_ratio_millis: 3500 }Re: Google’s GDPR Workaround
#487Earlier quoted context omitted.
I confess that I've also never really understood why people are so outraged by the hypothetical it likely presence of actual shills: it's not like the population of non-shill commenters doesn't already produce every stupid and inane take possible. Shills can shift the composition of votes and comments away from a given board's biases (towards their preferred biases), but what does that change from the perspective of…
I think you're overestimating how much people think critically about the news or discussions online. A couple upvoted comments here and there, paid for by a massive corporation, can absolutely influence opinion. I don't want to sound like I think some "smart" people are somehow immune to this - I think everyone, regardless of their education or intelligence, is susceptible to this kind of group-think.
It's still not clear to me that I see why shills are such a cause for outrage, at least at a personal level: if a person's critical thinking abilities are impaired enough of people that they'd have their views appreciably changed by shills' voting patterns, the absence of shills just means they'd be blindly following the whims of online mobs. I can see how this is better, but just _barely_.
OTOH, for those who are capable of basic critical thinking, shills don't seem to have much power: if they make good points, then good, if they don't, then no harm done.
I just don't see how why bad comments are somehow worse when they're driven by payments instead of simply the stupidity of a normal person.
Re: Google’s GDPR Workaround
#488I'm an engineer who has worked on ad systems like this and I'm really struggling to make sense of this article - what hope does a layman have? Here's my understanding: Google runs real-time bidding ad auctions by sending anonymized profiles to marketers, who bid on those impressions. The anonymous id used in each auction was the same for each bidder, which is in violation of GDPR. If Google were to send different ids…
There are companies that specialise in sharing user information. Some of them work by only sharing data with companies that first share data with them (an exchange).
If you got this Google ID, and you had a few other pieces of information about the user, you could share that data with an exchange, indicating that the Google ID is a unique identifier. Then, the exchange would check if it has a matching profile, add the information you provided to that profile, and then return all of the information they have for that profile to you.
So, let's say you're an online retailer, and you have Google IDs for your customers. You probably have some useful and sensitive customer information, like names, emails, addresses, and purchase histories. In order to better target your ads, you could participate in one of these exchanges, so that you can use the information you receive to suggest products that are as relevant as possible to each customer.
To participate, you send all this sensitive information, along with a Google ID, and receive similar information from other retailers, online services, video games, banks, credit card providers, insurers, mortgage brokers, service providers, and more! And now you know what sort of vehicles your customers drive, how much they make, whether they're married, how many kids they have, which websites they browse, etc. So useful! And not only do you get all these juicy private details, but you've also shared your customers sensitive purchase history with anyone else who is connected to the exchange.
Re: Google’s GDPR Workaround
#489Earlier quoted context omitted.
Are you a lawyer? Because this take is quite remarkable, especially given that the overwhelming public sentiment is that McDonalds was heinously negligent, coupled with a lot of supporting but not entirely factual claims to justify that position. I feel like the same people who were jeering at the victim just marched over to sainting her and demonizing McDonalds. The Internet extreme position machine. Everything has…
> The Internet extreme position machine. Everything has to be clear cut aka compression machine. optimized to trigger brains' reward circuitry for accomplishment by 'tidying up' unmanageable landscapes of disjointed data into easily stored and recalled bimodal silhouettes of same.
Re: Google’s GDPR Workaround
#490I checked the sample log provided. Below is the google_gid for different publishers, there is no proof of overlap, they have different google_gid for same person. Which is exactly what google describes. [1] I don't understand what Brave claims. d.agkn.com CAESEP-S3Zs5f0_kq11XTCZP_mE id.rlcdn.com CAESEPpf2T4-2AsAR_4rer3RfNs image6.pubmatic.com CAESEB9H3qdV26kxEiz-BJ_TY-M pippio.com CAESEJyqG1Pg1j-_scqW8kDzTkg token.ru…
This log [0], right? Did you miss in the article that it's the `google_push` identifier that's being used for syncing between adtech companies? If you search for it (AHNF13KKSmBxGD6oDK9GEw5O0kvgmFa3qM30zpNaKl72Og), you can see it being included in requests to lots of different adtech firms' domains. [0] https://brave.com/wp-content/uploads/files_2019-9-2/sample_p...