Live data from Hacker News

Brave files adtech complaint against Google

reuters.com

11–20 of 271 posts

Re: Brave files adtech complaint against Google

#11
post #9

A few typos in the article: > Were the regulator to find in favor of the plaintiffs, that could undermine the foundations of the data-driven model on with the online ad industry - forecast by research firm eMarketer to grow to $273 billion this year - depends. with = which The GDPR is the first data privacy regime that foresees heavy fines for serious violations - of up to 4 percent of a company’s global turnover. fo…

foresees is perfectly fine in that sentence.

Re: Brave files adtech complaint against Google

#12
post #10
post #3

This comes at the same time that Malwarebytes starts flagging Brave as malware[1]. [1] https://twitter.com/lukesawczak/status/1039854898068815873

That has nothing to do with Brave, it's just another failure of antivirus / antimalware approach. Nothing new. EDIT: not sure why they prefer blacklisting to whitelisting, anyone know the reasons?

of course it has nothing to do with brave

Re: Brave files adtech complaint against Google

#13
post #7

Its admirable what brave is trying to do. Practically speaking, its one of the best chance we have of creating a new internet where the incentives are more privacy focused. Hope they succeed.

A new internet where $273 billion advertising industry does not exist?

Re: Brave files adtech complaint against Google

#15
post #4

Earlier quoted context omitted.

Generally speaking, ad networks don't sell personal data. That's their secret sauce - selling it is largely counterproductive. I can't call up Yahoo, and ask to buy the personal data of "forapurpose". If I could, it would take me a few million dollars to build a clone of their most valuable asset - their user database. What they sell is ad spots in webpages, when those webpages are visited by people who satisfy some…

Thanks. How does that apply in this case? Does GDPR allow the collection but ban the selling of data? Also, per the article, the complaint claims that the collected information is shared with many other companies. How does that square with what you are saying? Are they sharing it with partners but not selling it to them? Does that make a difference under GDPR?

The OpenRTB spec does contain data that many assume will be found to be personal under GDPR. The IAB is an industry group for people that use OpenRTB. They have built a standard on how to gather and transmit the GDPR consent requirements from publisher through the OpenRTB ecosystem. You can find it at http://advertisingconsent.eu/

Re: Brave files adtech complaint against Google

#16
post #7

Its admirable what brave is trying to do. Practically speaking, its one of the best chance we have of creating a new internet where the incentives are more privacy focused. Hope they succeed.

They're so admirable that they take a 5% cut of your donations to sites you visit and replace ads with their own.

Call me crazy, but in no future can I imagine anyone willingly paying their browser vendor for anything. Brave isn't the future, it's yet another cash grab.

The real future is fully-decentralized websites, and it doesn't require new browsers.

Edit: Fixed inaccuracy pointed out by Brave developer

Re: Brave files adtech complaint against Google

#17

They are arguing that the surveillance core of adtech is a GDPR violation, if I understand correctly. > The complaint argues that when a person visits a website, intimate personal data that describe them and what they are doing online is broadcast to tens or hundreds of companies without their knowledge in order to auction and place ads. It would be great if someone with real expertise in GDPR or adtech could provide…

So the publisher, through a platform, issues a bid request to an exchange with a lot of information in it. The parameters of that bid request contain all kinds of context like the site, the browser or device, etc. Critically, it also includes the cookie. The way GDPR has been interpreted by Google (btw Google is considered to be overly conservative in its approach by the adtech world): Cookies can only be passed by publishers who get consent to collect and pass them, and they must get consent for each adtech vendor. Furthermore, Google will not pass those cookies to anyone else because it can't be sure that the vendor receiving them was given consent by the user. Other platforms haven't done that last part; and some publishers are even saying that they refuse to collect affirmative consent. This is because people interpret it differently. From my reading, Brave seems to be trying to drive for a new interpretation: it's not only a matter of cookies, which is the parameter associated with a user, it's a matter of ALL the info even when it's not related to tracking a single user. My guess is that Eich's hoping to get a court to adopt this new stricter interpretation, but if that were to happen it would mean that the regulators' guidance thus far would be moot and all of the mitigations the adtech world has gone through to prepare would be out the window.

Re: Brave files adtech complaint against Google

#18
post #3

This comes at the same time that Malwarebytes starts flagging Brave as malware[1]. [1] https://twitter.com/lukesawczak/status/1039854898068815873

Malwarebytes has had a few (seemingly) false positives lately. Anecdotally, I was just hit by it falsely flagging BeyondCompare and my password manager. I assume they have just upped the ante of their heuristics, but am still concerned about the fallout, since I am starting to ignore them. Not related, but considering that it does not scan except on demand, why is it ALWAYS running? Who vouches for Mr. Malwarebytes?

Not to mention more aggressive upselling in the free version via popups. Closing the application sends it to the system tray where it will later remind you to "update" MalwareBytes by buying a license.

Re: Brave files adtech complaint against Google

#19
post #4

They are arguing that the surveillance core of adtech is a GDPR violation, if I understand correctly. > The complaint argues that when a person visits a website, intimate personal data that describe them and what they are doing online is broadcast to tens or hundreds of companies without their knowledge in order to auction and place ads. It would be great if someone with real expertise in GDPR or adtech could provide…

Generally speaking, ad networks don't sell personal data. That's their secret sauce - selling it is largely counterproductive. I can't call up Yahoo, and ask to buy the personal data of "forapurpose". If I could, it would take me a few million dollars to build a clone of their most valuable asset - their user database. What they sell is ad spots in webpages, when those webpages are visited by people who satisfy some…

While it is technically correct that ad networks don't sell personal data, it is also irrelevant. It's not the bits that matter, it's what one does informed by the bits. Ad networks sell _actionable insights_ informed by personal data.

An ad network answers the question 'what is the best way to spend $$$ and win this election' _using_ personal data of millions of people, but not _revealing_ the personal data to the paying customer. The paying customer is highly unlikely to have the technical acumen to turn personal data into actionable insights anyways, service readily provided by the ad network. The fact that personal data was not revealed is irrelevant, the end effect was bought by anyways.

The evil is in collecting personal data to begin with, not in the technical manner it is used against the people it belongs to.

Re: Brave files adtech complaint against Google

#20
post #4

Earlier quoted context omitted.

Generally speaking, ad networks don't sell personal data. That's their secret sauce - selling it is largely counterproductive. I can't call up Yahoo, and ask to buy the personal data of "forapurpose". If I could, it would take me a few million dollars to build a clone of their most valuable asset - their user database. What they sell is ad spots in webpages, when those webpages are visited by people who satisfy some…

Thanks. How does that apply in this case? Does GDPR allow the collection but ban the selling of data? Also, per the article, the complaint claims that the collected information is shared with many other companies. How does that square with what you are saying? Are they sharing it with partners but not selling it to them? Does that make a difference under GDPR?

Used to be in adtech- google didn’t provide these things to us. Maybe there were other products we could have purchased, but google just gave us a userid and all the tracking was done on our side. There are definitely third parties we could buy this data from. I left pre gdpr but my vague understanding is google has nothing to worry about in rtb but the adtech companies are at fault here if anyone. Especially if you consider the amount of lawyers google pays vs brave
Post reply on HN