Live data from Hacker News

Open letter: Ban surveillance-based advertising

vivaldi.com

51–60 of 271 posts

Re: Open letter: Ban surveillance-based advertising

#51

Earlier quoted context omitted.

Because I don't want to waste the time of people who aren't interested in my ad in seeing my ad. It's a waste of money for me. The ad network will not be able to make money from having them click the ad. The user's time will be wasted because they are not interested in what I am selling. It's a lose lose lose situation. I want to create more win win win situations where everyone benefits. Tracking and profiling is ne…

You could target the same people by buying ad space in like-minded “venues”. There’s a gaping hole in the market for good “content-linked” advertising, searching, aggregation and so on. Link to content, not people. Work with customers who’re already self selecting, rather than following people around all the time. As a side-line, this’d probably cut back on a lot of click-bait trash articles. It, likely, would help b…

This is DDG’s model, right? Instead of stalking me all around the internet to find out I’m looking for a new car in order to show me adverts for a new car they show me the advert when I search “best new cars 2021” which is probably a pretty solid indicator that I’m looking for a car that doesn’t involve any tracking.

Re: Open letter: Ban surveillance-based advertising

#52

Earlier quoted context omitted.

>No, you don't have to spy on users to do it. Assuming you are running an ad network you kind of have to in order to prevent ad fraud. Also by reducing that data you know about someone's interests is the knowledge that they have visited a site at least you will not be able to pick as good of an ad compared to if you had more data.

What's the fraud scenario? Page owners presenting fraudulent visitor/click-through numbers to advertisers? In that scenario, it seems like advertisers would pick up on that pretty quickly when they realize the conversion rate on that supposed traffic is terrible and doesn't warrant the inflated price. In the case they're using an ad network, the network could ban the page owner from their network if they see this pat…

We sell and host our own advertising which is content-based (office furniture ads on office design content) and think it is a good solution.

Instead of selling space by impressions or clicks, we use length of time (monthly) and find it to be a good way to prevent ourselves from trying to game impressions with clickbait or clicks with fake users.

Re: Open letter: Ban surveillance-based advertising

#53

Earlier quoted context omitted.

>No, you don't have to spy on users to do it. Assuming you are running an ad network you kind of have to in order to prevent ad fraud. Also by reducing that data you know about someone's interests is the knowledge that they have visited a site at least you will not be able to pick as good of an ad compared to if you had more data.

What's the fraud scenario? Page owners presenting fraudulent visitor/click-through numbers to advertisers? In that scenario, it seems like advertisers would pick up on that pretty quickly when they realize the conversion rate on that supposed traffic is terrible and doesn't warrant the inflated price. In the case they're using an ad network, the network could ban the page owner from their network if they see this pat…

> What's the fraud scenario?

1. Page owner / Ad network / Ad space auction market middleman fakes clicks to get click revenue

2. Page owner's rival fakes clicks to devalue ad spots

3. Advertiser's agency fakes clicks to make numbers go up

4. Advertiser's rivals fake clicks, to waste advertiser's budget

5. Ad networks 'accidentally' classifying legitimate clicks as fraud, to reduce payouts to page owners.

Re: Open letter: Ban surveillance-based advertising

#54

Earlier quoted context omitted.

Let's say you run a website with a sign on page. In order to log in a user typically you will run the password through an algorithm like argon2. Verifying a password for an account consumes CPU resources. A malicious may decide to DOS your site by just spamming this endpoint with bogus password to make you waste your time. An easy fix with surveillance is to rate limit people based off their IP address. Without surve…

An IP address being used in the course of providing the service is not surveillance. That's like saying "Amazon knowing where to ship my package is surveillance." It's a bad argument, in my opinion. Regardless, consider a DDoS attack. If every new request is coming from a different IP address, how do you continue providing service to your legitimate customers while blocking that malicious attack? Knowing the attacker…

>That's like saying "Amazon knowing where to ship my package is surveillance."

To complete the metaphor Amazon would use the address you gave them to help improve their business in some sense without asking you if it's okay. Similar to how web masters don't ask if it's okay if they write what pages we access into logs is okay.

>Knowing the attacker's IP addresses doesn't do you any good... because they can just keep using new IP addresses, and blocking the old ones doesn't do any good.

Then we should try to find any patterns with the traffic that we can use to try and filter it out. This is a place where fingerprinting is useful.

>friendlycaptcha

This just slows down bot spam instead of testing if someone is a bot. Someone posting spam to your site once a minute is still annoying.

Re: Open letter: Ban surveillance-based advertising

#55
I think there's a simpler way to achieve this. Force companies who leak personal data to pay reasonable damages to all the individuals involved, on the scale of 10-100 dollars, depending on how much personal info has been leaked.

That would make businesses very quickly reassess how much data they need to keep, and how careful they need to be with it, without requiring any really radical legislation.

Re: Open letter: Ban surveillance-based advertising

#56

Do we have a good proposed legal definition of surveillance-based advertising?

I will employ a spy/cop to follow you everywhere and log everything you do in detail, would you consider it a surveillance? Of course, he will refrain from listening to you talking and won't enter your home. But everywhere else he will follow you at a distance.

This is essentially what is going on in the internet. Metadata collection = Surveillance.

Re: Open letter: Ban surveillance-based advertising

#57

Earlier quoted context omitted.

If it collects any data at all, it's surveillance. Anything else is a loophole.

> If it collects any data at all, it's surveillance Great, we just banned TCP.

Exposing is not the same as collecting though...

I'd definitely consider a system which collects all information that are exposed in a TCP stream a surveillance tool

Re: Open letter: Ban surveillance-based advertising

#58
post #44

Earlier quoted context omitted.

Let's say you run a website with a sign on page. In order to log in a user typically you will run the password through an algorithm like argon2. Verifying a password for an account consumes CPU resources. A malicious may decide to DOS your site by just spamming this endpoint with bogus password to make you waste your time. An easy fix with surveillance is to rate limit people based off their IP address. Without surve…

If someone abuses your doorbell the solution isn't to install a hidden DNA and body scanner in front of your door. Also suggesting that an IP based rate limiter is the same as the surveillance in question is very disingenuous. Pick a more sensitive area than your IDE, say medicine targeting erectile dysfunction, sexual or religious preferences, etc. You may find that being allowed to collect that data, especially cov…

>If someone abuses your doorbell the solution isn't to install a hidden DNA and body scanner in front of your door.

The first thing I would do is look outside to collect information on who in outside thereby infringing their privacy.

>Also suggesting that an IP based rate limiter is the same as the surveillance in question is very disingenuous

Recording people's IPs is definitely surveillance.

>say medicine targeting erectile dysfunction, sexual or religious preferences, etc. We may be able to connect drug sellers or churches with people if we know that information.

>But surely I should be allowed to covertly collect any data about you if it enables some savings for me.

Sure you can. Go ahead.

Re: Open letter: Ban surveillance-based advertising

#59

Earlier quoted context omitted.

> If I am trying to advertise an Elixer IDE, then I don't want my advertisements shown to any random person on the internet. The definition in the report is poor. Yes, you always need to advertise to a segment. No, you don't have to spy on users to do it. How? Make a website about something and select advertisements that are relevant to the sort of people who are probably interested in the topic of the website. ReadT…

>No, you don't have to spy on users to do it. Assuming you are running an ad network you kind of have to in order to prevent ad fraud. Also by reducing that data you know about someone's interests is the knowledge that they have visited a site at least you will not be able to pick as good of an ad compared to if you had more data.

Sell ads based on time periods. "Your ad displayed here for 1 week for this much $$$". Then the only thing that matters is the ROI and it doesn't matter how many bots have clicked on it.

Re: Open letter: Ban surveillance-based advertising

#60
Physical storefronts have over time learned how to optimise their presentation to achieve higher conversion. Initially it was experimentation with layouts, with time they added cameras which helped understand customer behaviours.

This expertise is commonly outsourced to physical marketing companies who dispatch "merchandisers" to your store to help optimise your layout to fall in line with the layouts they have designed based on the experience they have doing this for many different stores.

Some companies would actively seek out target customers, give them cash to conduct surveys for market research.

The barrier to retail taking this to an extreme is physical obstruction and money. It takes time to experiment with layouts, you have to pay people for their insight. It isn't practical to have a Moogle which has cameras analyzing most physical storefronts around the world.

It's a really complex issue as online retailers do make money from online advertising companies and it often matters to them, but the proliferation of the chosen advertising providers few means that everywhere you go they have a presence listening for your user actions.

With that said, these companies don't really want to know you, they just want to ensure they are able to serve relevant ads to someone like you. Collecting personal data is a consequence of there being no other way to group data into uniquely identifying profiles and get those insights on the interests of those profiles.

More often, these companies explicitly don't want to know you. Personal information is a massive liability.

Attempts to anonymise the data are difficult as you will need some kind of unique primary identifier, but you can infer a lot about an identity from seemingly unimportant things like browser resolution.

Post reply on HN