Live data from Hacker News

Google’s GDPR Workaround

brave.com

511–520 of 629 posts

Re: Google’s GDPR Workaround

#511

Is there any way to improve the matching of ads to the viewer without violating their privacy?

Yes! Contextual Targeting (target based on what I am reading) could work, although the industry seems to be clinging to Behavioural Targeting (target based on who I am). This will become more important for Open Web due to the 3p cookie constraints, regulatory changes etc..., but Google/Amazon/FB are less likely to be impacted. In fact Contextual Targeting predates the current approaches, but it became less important…

Mind sharing which company you work for? I'm interested in scaling contextual, privacy-focused publisher targeting solutions.

On the PG/PMP side, the usage is obvious, but I'm also curious what it will take for publisher-provided data to be trusted in the open exchange environment where historically advertisers and DSPs have tended to not trust the publisher-supplied categorization.

Re: Google’s GDPR Workaround

#512

Earlier quoted context omitted.

Well, the “right” workaround is an opt-in system. But that would drastically reduce the number of qualified ad prospects, reducing their wholesale value, killing the online ad business, drying up the websites themselves who exist for this revenue (some/many of which are trash, but not nearly all). I don’t think we can have it both ways, or at least it is very difficult and we don’t have a great compromise solution.

I don't think the EU, or consumers in general, are terribly interested in "compromising" with the ad-tech industry.

Not that I support the ad-tech industry, but those consumers probably are interested in having their favorite websites being kept alive. Which implies that they might indeed be interested in "compromising" with ad-tech industry.

Re: Google’s GDPR Workaround

#513

Earlier quoted context omitted.

No, a data processor is any entity that collected personal data gets passed on to and where it is processed as part of the business arrangement. An ad network that receives personal data is definitely a data processor.

> No, a data processor is any entity that collected personal data gets passed on to and where it is processed as part of the business arrangement. I'm relatively sure that there's another part: it's data processing for the client (here: Google) and the data cannot be used for other purposes. In this case, they don't process data for Google, they process it in cooperation with Google for the ad-buyers. Google also doe…

You are misreading the GDPR badly. A data controller can only pass on PII to a data processor. That is, any entity receiving PII from a data comtroller automatically is assigned this role by law. There are no alternative roles that could assumed instead. This means that a data processor must obey the rules laid out for it by the GDPR or it is in violation.

Re: Google’s GDPR Workaround

#514

Earlier quoted context omitted.

(hint: users just don’t care about privacy, except for the HN crowd). I'm not sure that's true: uBlock Origin has twice as many installations as Brave does. You might say "oh, but that's just blocking ads!" But if you don't block ads, privacy problems are going to spring out of the woodwork like nobody's business. That is, they might not care about privacy by name, but they certainly care about it in effect.

I’d say the vast majority of uBlock users care about user experience. The current ad experience sucks. Most local newspaper sites, for example, are unusable because of ads. But if it still preserved their privacy behind the scenes and didn’t significantly improve their experience, the install base on uBlock and other ad blockers would be near 0.

Highly doubtful

Re: Google’s GDPR Workaround

#515

Earlier quoted context omitted.

I don't think the EU, or consumers in general, are terribly interested in "compromising" with the ad-tech industry.

Not that I support the ad-tech industry, but those consumers probably are interested in having their favorite websites being kept alive. Which implies that they might indeed be interested in "compromising" with ad-tech industry.

Given the popularity of ad-blockers these days I'm not sure they're as interested as you think they are.

Re: Google’s GDPR Workaround

#516

Earlier quoted context omitted.

This log [0], right? Did you miss in the article that it's the `google_push` identifier that's being used for syncing between adtech companies? If you search for it (AHNF13KKSmBxGD6oDK9GEw5O0kvgmFa3qM30zpNaKl72Og), you can see it being included in requests to lots of different adtech firms' domains. [0] https://brave.com/wp-content/uploads/files_2019-9-2/sample_p...

There is unfortunately no way to prevent that part. BidRequest Data [0] and Request Time is already enough to fingerprint the user. "Google prohibits multiple buyers from joining their match tables." part is not technical, it is contract based. [0] Sample Data from Bid Request ip: "F\303\006" user_agent: "Mozilla/5.0 (Linux; Android 7.1.1; Pixel XL Build/NOF26V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924…

>There is unfortunately no way to prevent that part.

It being technical impossible or infeasible does not give them license to not follow the law.

Either they comply with the law or they don't. I'm not a lawyer, but it certainly doesn't look like they're following the law here.

Re: Google’s GDPR Workaround

#517

Earlier quoted context omitted.

This is a problem because companies can use this ID to correlate private user data, without anyone's knowledge or consent. There are companies that specialise in sharing user information. Some of them work by only sharing data with companies that first share data with them (an exchange). If you got this Google ID, and you had a few other pieces of information about the user, you could share that data with an exchange…

Considering google_gid is valid for you for 14 days only. It is very unlikely to build a profile around it.

I have no doubt that if you had a record of my browsing habits for 2-3 days you could readily identify who I am the next time you have my browsing habits for that period of time.

I wouldn't be surprised at all if 2-3 hours of active browsing was enough for this.

Re: Google’s GDPR Workaround

#518

Earlier quoted context omitted.

Is it really? If Alice tells Bob she has diabetes and Bob tells Charlie, is Bob in violation of GDPR?

Are Bob and/or Charlie the name of a person or of a company? How you're using it, it sounds like Bob or Charlie in your mind is a person. I might be wrong in interpreting it that way. If so could you give another example where Bob and Charlie are companies and the information of Alice is part of a transaction.

GP's comment paints Alice/Bob/Charlie as people:

>If Alice tells her coworker Bob that she had diabetes, it's not a HIPAA violation for Bob to tell Charlie.

I was responding to the parent comment's claim that it's not a HIPAA violation but rather a GDPR violation.

Re: Google’s GDPR Workaround

#519

Earlier quoted context omitted.

Well, the “right” workaround is an opt-in system. But that would drastically reduce the number of qualified ad prospects, reducing their wholesale value, killing the online ad business, drying up the websites themselves who exist for this revenue (some/many of which are trash, but not nearly all). I don’t think we can have it both ways, or at least it is very difficult and we don’t have a great compromise solution.

I don't think the EU, or consumers in general, are terribly interested in "compromising" with the ad-tech industry.

I know that I'm not interested in "compromising" with the ad-tech industry. They've been spending too much time and money attacking my defenses against their terrible practices for me to treat them as anything but an attacker.

Re: Google’s GDPR Workaround

#520
Presumably ads are so valuable because people click through them and go on to purchase.

I realise I am in a minority, but I have never clicked on a digital ad and went through to buy something, and I never will.

The minute I see ads on a webpage, I automatically associate that site with trash. (Please take note HN :))

It is as if humanity cannot be trusted with technology. This creates a certain "ceiling" for us in terms of development as a species. Such a shame.

Post reply on HN