Live data from Hacker News

Ask HN: Refusing all cookies, still targeted by ads. How?

news.ycombinator.com

41–50 of 118 posts

Re: Ask HN: Refusing all cookies, still targeted by ads. How?

#41
If you are at all concerned with privacy, why are you using Chrome? It should be no surprise that the browser built by one of the largest data-harvesting companies in the world is pretty good at harvesting your data...

If this is a concern for you, maybe consider Firefox? Then grab some extra privacy-conserving extensions like ublock, adnauseam, privacy badger, privacy possum, ghostery, decentraleyes, clearURLs, IStillDontCareAboutCookies, etc.

I get that this is a work machine and you may not have admin rights to install Firefox but any IT manager worth their salt won't refuse a request to change browser, especially if the motivation is personal security.

If they really don't budge (or you are too welded to the Google ecosystem to part with their browser) then maybe you could look for some of the extensions I mentioned above on Chrome?

Re: Ask HN: Refusing all cookies, still targeted by ads. How?

#42
> maybe the simple answer is that refusing cookies doesn't actually do anything?

I agree with all the other comments that are saying this is probably fingerprinting, but you can check whether refusing cookies is doing anything. Two ways:

1. On a page where you refused all cookies but are seeing targeted ads, open developer tools and go into the "Application" tab. Open up Storage > Cookies. Do you see anything listed? You should see nothing there. You also shouldn't see anything in the rest of storage, since "cookie" consent is really "client-local storage consent".

2. You can check whether cookies were sent on particular network requests, like the ones to the ad companies. Open a new tab, open devtools, open networking. Then paste the URL in the url bar. Find an ad request in the networking tab: do you see a "Cookies:" header? If so, it sent a cookie for you.

Re: Ask HN: Refusing all cookies, still targeted by ads. How?

#43
post #14

Cookies was a simple concept that politicians could glom on to and legislate around, but, yes, they're quite unimportant in the grand scale of things. In the end, you've got two things to work with: Things you can convince the browser to actively identify itself with, and the things you can track regardless. Cookies are in the first category, but they are not alone. You can get things as simple as presenting an entir…

The important bit is that the cookies not only are irrelevant from the point of view of allowing tracking to occur technically, they're also irrelevant from a legal point of view. A company must have your consent to hold and process your information for a specific purpose , regardless of whether or not that is done using cookies or fingerprinting. If you have been presented with a consent popup and have not consented…

This is a critical thing that so many miss. If somebody has a website that doesn't use any cookies, but does send a POST request to www.bigcompanyanalytics.com/send-user-info with a body containing user-identifying information, then that is still illegal if the user has not consented to analytics (if they are in an area that requires opt-in for analytics).

Cookies aren't really mentioned in GDPR or other privacy laws, folks just latched onto cookies as one area that can track users. But really, all personal data is subject to most of the privacy laws, including outbound requests as well as stored data.

IANAL. But for context from lawyers, see: https://ico.org.uk/for-organisations/direct-marketing-and-el...

Re: Ask HN: Refusing all cookies, still targeted by ads. How?

#44
In addition to the non-cookie fingerprinting mentioned by others that can happen, there is a loophole in the GDPR cookie control legislation that allows "legitimate interest" cookies to continue to be placed and tracked when you click Reject All.

You have to edit your cookie preferences for the site (assuming they provide the option) and deselect Legitimate Interest cookies proactively in order to block them.

This recent write-up on Reddit alerted me to this information:

https://www.reddit.com/r/YouShouldKnow/comments/14ddk4u/ysk_...

Re: Ask HN: Refusing all cookies, still targeted by ads. How?

#45
post #14

Cookies was a simple concept that politicians could glom on to and legislate around, but, yes, they're quite unimportant in the grand scale of things. In the end, you've got two things to work with: Things you can convince the browser to actively identify itself with, and the things you can track regardless. Cookies are in the first category, but they are not alone. You can get things as simple as presenting an entir…

I’ve been on a team doing fingerprinting research (specifically entropy sources). It’s amusing that you’re 100% unique and browsing HN commenting about fingerprinting. (You’re exactly a demographic that would be unique.) Most people aren’t unique, far from it. Consider iPhone 14 Pro Max users browsing through a 5G connection. All the users in the same cell look exactly the same. If I had to guess, based on what I kno…

I’m pretty skeptical of this of this fingerprint test. I’m on a 5G connection, in a major city with a completely default current gen iPhone, and it seems to think I’m 100% unique. Which I don’t believe for a second.

Re: Ask HN: Refusing all cookies, still targeted by ads. How?

#46
post #14

Cookies was a simple concept that politicians could glom on to and legislate around, but, yes, they're quite unimportant in the grand scale of things. In the end, you've got two things to work with: Things you can convince the browser to actively identify itself with, and the things you can track regardless. Cookies are in the first category, but they are not alone. You can get things as simple as presenting an entir…

I’ve been on a team doing fingerprinting research (specifically entropy sources). It’s amusing that you’re 100% unique and browsing HN commenting about fingerprinting. (You’re exactly a demographic that would be unique.) Most people aren’t unique, far from it. Consider iPhone 14 Pro Max users browsing through a 5G connection. All the users in the same cell look exactly the same. If I had to guess, based on what I kno…

I tried the amiunique fingerprinter with my iPhone, software updated to the latest version, stock Safari browser, and it said I was unique among all however many users had tried before.

Re: Ask HN: Refusing all cookies, still targeted by ads. How?

#47

You need tracker blocking extensions, and/or a "degoogled" version of Chrome like Thorium or Brave. My usual loadout is Thorium + the EFF's Privacy Badger extension, and sometimes UBO.

can you say why degoogled chromium matters for tracking, or link to a writeup?

The Ungoogled Chromium project itself is a pretty good summary. In a nutshell, Chromium (whether signed in or not) "phones home" to Google for a number of reasons, and the official Chrome builds do it even more (though in harder to observe ways since the changes are closed source).

https://github.com/ungoogled-software/ungoogled-chromium

Re: Ask HN: Refusing all cookies, still targeted by ads. How?

#49

Earlier quoted context omitted.

The important bit is that the cookies not only are irrelevant from the point of view of allowing tracking to occur technically, they're also irrelevant from a legal point of view. A company must have your consent to hold and process your information for a specific purpose , regardless of whether or not that is done using cookies or fingerprinting. If you have been presented with a consent popup and have not consented…

Under which law is this illegal? I'm only aware of legislation that forces websites to ask for consent for storing cookies.

The ePrivacy Directive (collaqually Cookie Law) doesn’t actual specify only cookies. Section 66 of https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... just talks about third parties storing information on equipment:

Third parties may wish to store information on the equipment of a user, or gain access to information already stored, for a number of purposes, ranging from the legitimate (such as certain types of cookies) to those involving unwarranted intrusion into the private sphere (such as spyware or viruses). It is therefore of paramount importance that users be provided with clear and comprehensive information when engaging in any activity which could result in such storage or gaining of access. The methods of providing information and offering the right to refuse should be as user-friendly as possible. Exceptions to the obligation to provide information and offer the right to refuse should be limited to those situations where the technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user. Where it is technically possible and effective, in accordance with the relevant provisions of Directive 95/46/EC, the user’s consent to processing may be expressed by using the appropriate settings of a browser or other application. The enforcement of these requirements should be made more effective by way of enhanced powers granted to the relevant national authorities.

Re: Ask HN: Refusing all cookies, still targeted by ads. How?

#50

Earlier quoted context omitted.

I’ve been on a team doing fingerprinting research (specifically entropy sources). It’s amusing that you’re 100% unique and browsing HN commenting about fingerprinting. (You’re exactly a demographic that would be unique.) Most people aren’t unique, far from it. Consider iPhone 14 Pro Max users browsing through a 5G connection. All the users in the same cell look exactly the same. If I had to guess, based on what I kno…

I’m pretty skeptical of this of this fingerprint test. I’m on a 5G connection, in a major city with a completely default current gen iPhone, and it seems to think I’m 100% unique. Which I don’t believe for a second.

There's only 1.9 million samples in their database, and to be fair, the people who go to that site to test their fingerprint, are probably the kind of user who is going to have a unique fingerprint, notsomuch a common user. So a common user going there is likely a bit unique.
Post reply on HN