Live data from Hacker News

Cname / DNS based third party tracking

arxiv.org

41–49 of 49 posts

Re: Cname / DNS based third party tracking

#41

Websites that use CNAME to forward their main domain to some tracking company, basically give their entire domain away, I don't see how that is a good secure way to track your users.. DNSCrypt-proxy (and even pihole these days I believe) are actually capable of blocking forwarded CNAME requests. Setting up such system for network wide adblocking is not complicated at all, see: https://github.com/notracking/hosts-bloc…

Repique always has a worth of a tryout, if you are tired out using these tool set.

https://github.com/AZ-X/pique

Re: Cname / DNS based third party tracking

#42
post #39

Earlier quoted context omitted.

NextDNS.io (sort of pihole as a service) unwraps those too. From the linked PDF: “Other tracking countermeasures operate as a DNS resolver, and return a bogus IP address, e.g. 127.0.0.1 when the domain name matches an entry from the blocklist. As this defense works at the DNS level, these can also consider all the intermediary resolutions to CNAME records, and return a bogus IP address if any of them resolve to a dom…

Too bad it doesn't support RouterOS from Mikrotik.

Well, it likely does, in the sense that you can associate a public IP with a configuration, and just put the DNS server entries where you normally would.

And if your IP is dynamic, it supports reversing that public IP from a dynamic hostname service.

Re: Cname / DNS based third party tracking

#43

Earlier quoted context omitted.

I just use an HTTP client that does not automatically load resources nor run Javascript. Using such a client, the user, by voluntarily typing the name of a website or following a URL, decides what to retrieve (a page, e.g., index.html), not the web developer. If the website developer is allowed to decide what the user involuntarily retrieves, then it stands to reason a website seeking revenue through online advertisi…

> I just use an HTTP client that does not automatically load resources nor run Javascript. For interest, what do you use? A standard browser with plugins, or a specialised client?

For making HTTP requests, I use a variety of commandline programs, mostly non-custom. For reading HTML I use links, mostly. For reading other formats I use UNIX utilities. These are all small programs that I can easily edit and re-compile if something annoys me and I want it removed.

Today's "standard browser" that runs Javascript is an omnibus, overly complex, kitchen sink program that is inextricably linked to the online advertising industry. Online ads and tracking generally do not work without the help of one of these so-called "standard" browsers.

Re: Cname / DNS based third party tracking

#44
post #32
post #31

Earlier quoted context omitted.

Is there a non-underground FightClub? :) Also, fighting back against ... what exactly? Ads? The Big FAANG? This is not the way. It's either beat them at their game (not likely), or building/supporting/using alternatives (eg. Signal, Mastodon, maybe substack? nebula? Librem/microG/LineageOS?), but ultimately it's politics. If "HN thinks" they are too powerful, then "HN has to" influence and persuade people in order to…

> fighting back against ... what exactly? Personal data harvesting. Its like feeding frenzy right now. > This is not the way. It's either beat them at their game (not likely), or building/supporting/using alternatives (eg. Signal, Mastodon, maybe substack? nebula? Librem/microG/LineageOS?), but ultimately it's politics. This is the way lol. Beating them is the only way that actually works, right now. Politics will ta…

Users are willingly giving away their info, they don't care. The vast majority won't ever install an adblocker. And piHole and other complicated defensive tech is great, but irrelevant.

There's no need to put tech into laws. The law is about privacy and consent. Do not call/spam/contact me without my consent, and don't even store/put my contact into a database without my consent. ( https://en.wikipedia.org/wiki/Nothing_About_Us_Without_Us )

Sure, the next step is culling those mindless consent popups.

> Politics will takes decades [...]

It's the only way that really works. Informing people and building a movement.

Otherwise just hiding in the noise makes no real difference to our lives. (Because our friends, family, neighbors, coworkers, etc. will be still tracked, targeted, etc. They won't setup a piHole.)

Re: Cname / DNS based third party tracking

#45
post #44
post #32

Earlier quoted context omitted.

> fighting back against ... what exactly? Personal data harvesting. Its like feeding frenzy right now. > This is not the way. It's either beat them at their game (not likely), or building/supporting/using alternatives (eg. Signal, Mastodon, maybe substack? nebula? Librem/microG/LineageOS?), but ultimately it's politics. This is the way lol. Beating them is the only way that actually works, right now. Politics will ta…

Users are willingly giving away their info, they don't care. The vast majority won't ever install an adblocker. And piHole and other complicated defensive tech is great, but irrelevant. There's no need to put tech into laws. The law is about privacy and consent. Do not call/spam/contact me without my consent, and don't even store/put my contact into a database without my consent. ( https://en.wikipedia.org/wiki/Nothi…

> It's the only way that really works. Informing people and building a movement.

I see. You underestimate or don't think that tracking today is the issue. Whats leaked cannot be unleaked. So far big tech only uses it for ads. Tomorrow it'll use it for banking, insurance, job applicants assessments, like Social Credit System in China today. Data sources are enormous, movement, friends, calls, chats, emails, purchases, searches and so on. "Person googles for drinking problems periodically since 2014."

So when it does become an issue in real life, it'll be too late, all data is already collected and processed into profiles.

And not only our data. Every school kid with Chromebook and Google account.

PS: Did you see this episode? If not, its my favourite, fun and scary at same time :)) https://en.wikipedia.org/wiki/Nosedive_(Black_Mirror)

Re: Cname / DNS based third party tracking

#46

Websites that use CNAME to forward their main domain to some tracking company, basically give their entire domain away, I don't see how that is a good secure way to track your users.. DNSCrypt-proxy (and even pihole these days I believe) are actually capable of blocking forwarded CNAME requests. Setting up such system for network wide adblocking is not complicated at all, see: https://github.com/notracking/hosts-bloc…

NextDNS.io (sort of pihole as a service) unwraps those too. From the linked PDF: “Other tracking countermeasures operate as a DNS resolver, and return a bogus IP address, e.g. 127.0.0.1 when the domain name matches an entry from the blocklist. As this defense works at the DNS level, these can also consider all the intermediary resolutions to CNAME records, and return a bogus IP address if any of them resolve to a dom…

Your reference, NextDNS's discussion of their approach and how it differs from others, is from 2019 and no longer correctly represents how pihole works. Pihole has handled this since release 5.0.

Re: Cname / DNS based third party tracking

#47

Earlier quoted context omitted.

Ya, blocking requests is a bandaid for preventing tracking. The only way to stop this permanently is to address the root cause. As far as I can tell that would be through permissioned browser api access. The UX might become a bit unwieldy though Google’s idea of limiting the number of bits of identifying info revealed might be a way around that. But then there is the issue of sites blocking access when more bits of i…

(Strict OT) hm? So the Trick of Computerpeople is simple and knowingly to block requests to prevent abuse ? That reminds me, of the arrogant young, wanting to compete boasting at 'social' -media, keeping -critics-(crossed) 'hater' away and small, while advertising (in self-interest) for so called 'social'-media to selfish gain their own position (on 'social'-media) ?! Heading: 'Inclusion' -so 'This 'generate and isol…

I'm having a hard time understanding.

But from your first sentence I gather you think my comment is trying to justify the current business practices of ad driven tech companies. It is not. I fundamentally disagree with that revenue model, at least how it primarily exists today, for many reasons.

One can work at changing the system which allows such business models to exist but typically that is much harder than working within the system to mitigate some of its effects on the individual. Working to change the system typically has much wider effects while working within the system typically has much narrower effects (one must opt in) and as such some or many may be left out.

My comment is about what one pragmatically might do when working within the system.

Re: Cname / DNS based third party tracking

#48
post #36
post #31

Earlier quoted context omitted.

Is there a non-underground FightClub? :) Also, fighting back against ... what exactly? Ads? The Big FAANG? This is not the way. It's either beat them at their game (not likely), or building/supporting/using alternatives (eg. Signal, Mastodon, maybe substack? nebula? Librem/microG/LineageOS?), but ultimately it's politics. If "HN thinks" they are too powerful, then "HN has to" influence and persuade people in order to…

> [not IP address] Are you saying an IP isn't / can't be personal data or am I misunderstanding the sentence?

Kind of yes. In case of a single site storing their own visitor logs (with or without some kind of correlation cookie) is not personally identifiable. At best it's a device.

It could becomes PII or personal data if that same IP then gets correlated to name, address, birth date, etc.

I'm aware that the GDPR for example considers anything personal data that is "related" to an identifiable natural person, but cookies and IP addresses can only become that "indirectly" if someone watches you and your network traffic. (Or retroactively, if someone with that IP and session cookie provides more information during that session.)

Essentially I argue that in a system that doesn't do profiling, doesn't even have the ability to ask for more personal data (eg. name), cannot link IP to a person. So in that system IP address is not personal data.

Re: Cname / DNS based third party tracking

#49
post #45
post #44

Earlier quoted context omitted.

Users are willingly giving away their info, they don't care. The vast majority won't ever install an adblocker. And piHole and other complicated defensive tech is great, but irrelevant. There's no need to put tech into laws. The law is about privacy and consent. Do not call/spam/contact me without my consent, and don't even store/put my contact into a database without my consent. ( https://en.wikipedia.org/wiki/Nothi…

> It's the only way that really works. Informing people and building a movement. I see. You underestimate or don't think that tracking today is the issue. Whats leaked cannot be unleaked. So far big tech only uses it for ads. Tomorrow it'll use it for banking, insurance, job applicants assessments, like Social Credit System in China today. Data sources are enormous, movement, friends, calls, chats, emails, purchases,…

I typed a long reply, then haven't sent it for a few days ... and now this happens: https://news.ycombinator.com/item?id=26367747

Basically my view is that we urgently need to focus on the real world outcomes, what GDPR actually did. Consent about any storing and processing, so consequences all the way up and down the chain. Data controller, processor(s) and sub-processor(s), and so on.

The technology of data-drivenness is here to stay. Businesses will use it. Consumers will consent to almost anything for a few cents of discount. And that's the next problem. So it'd be great to simply make a few basic marketing data techniques opt-out and very much make the rest require a review/permit from some authority.

----

That said I don't have much to compare "tracking today" against or with. I don't like advertisements in any form. (Billboards, TV/radio/podcast/youtube ads, native or not. Targeted or not.)

Also there are already profiles, databases, and they would be without adtech too. (Just look at China, there is no Google, but they have a surveillance state. Sure, baidu/qq/tencent/alibaba are all having their adtech, and probably the central government have access to whatever they want.)

Big tech or not, there are already fewer protected classes (in labor law) than there should be. Plus if an employer wants to fire someone, they will find some bullshit reason anyway.

Similarly, banks already require a lot of data, a signed paper to verify employment, past transaction history, and there's the whole positive-negative credit score. (And people gladly give consent to receive a small fractional percentage better interest.)

You are likely aware that many non-protected data categories correlate very highly with the protected ones. This puts many people at a disadvantage. (Yet at the same time not everyone has the same income, so not everyone has the same ability to service a loan. Of course the problem is very deep, because we know that the huge income inequality is also very much not because some of us happens to value income a lot more than free time, while some of us value free time more than income, which would lead to a "natural income inequality distribution".)

Tech (big or not) is simply manifesting deep(er) problems. Sure, this is not a reason to not regulate tech. (Quite the contrary.) But I still think keeping things in perspective is important.

Post reply on HN