Live data from Hacker News

Removing email registration improved retention

solitaired.com

131–140 of 180 posts

Re: Removing email registration improved retention

#131
post #83

Earlier quoted context omitted.

But you are not sharing your email with fb. The user already shared it with fb. I am only telling fb, if you have this user with this email, show him an ad. I really don't see the problem. Much better a targeted ad than ads about porn, casinos, viagra or poker.

Regardless of whether Facebook has my e-mail, services providing them with a hashed version of it for advertising purposes still allow Facebook to tell "this hash is associated with these services" even if they never had the original un-hashed email. They can combine it with all the other information they have (stolen from people's contacts which may have the unhashed e-mail along with my name and potentially phone n…

Things get murky in this area (or perhaps not, the lawyers will figure it out in time).

If Facebook is only using something like a hash of an email address in order to target ads at specific Facebook users at the request of one of their advertisers, they are probably only acting as a data processor for a very specific purpose that might be acceptable for both Facebook themselves and the advertiser under the GDPR rules.

If Facebook does anything else at all with that data, their role probably changes from a GDPR perspective. The hash is personal data, since by definition it's being used to identify a specific person. If Facebook is using the data they have associated with that hash -- for example, anything they know about the business that provided it -- to build up more of a profile on their users, they are probably now a data controller, possibly as well as a data processor in connection with the original targeted ad process. Then you get into questions about whether Facebook's users have given their suitably informed consent to Facebook or there is some other lawful basis for whatever processing is happening.

Obviously if businesses were providing actual email addresses to Facebook or if Facebook were using that data to do things like building shadow profiles on non-Facebook users, that would be another level entirely. And AFAIK, the custom audience tools on marketing platforms like Facebook typically do accept directly uploads of literal email addresses, phone numbers or other identifying details for the audience to be targeted, so maybe the discussion about hashing above is all moot anyway.

Re: Removing email registration improved retention

#133

Earlier quoted context omitted.

> Ads do not. There are plenty of scams and malware being spread through ads. Furthermore ads are a parasite that wastes most people's time for no benefit with no official way for them to opt-out (a lot of services don't allow you to pay money to opt-out); it'a a cancer on society. > Especially in this case where PII data is not being provided to the advertising company. You are literally talking about capturing e-ma…

The emails can be hashed, turning it into a pseudo-anonymous ID. It is debatable whether that is PII. It probably comes down to whoever can afford the better legal representation.

Hashes are not a panacea. I see them being suggested as solution for anonymization of ip addresses/domain names/urls/file names/emails all the time but these people that make said suggestions are either clueless or are arguing in bad faith. It is extremely easy to brute-force the majority of said hashes. (in addition to that I doubt that anyone is passing hashed emails as it would make it slightly inconvenient to send emails to said accounts)

Re: Removing email registration improved retention

#134
post #92

>you can target them on Quora, Reddit etc as well. This is one of the reasons I stopped giving out my primary email address for user signups. I use a service called Blur which allows for unlimited "masked" emails to be created, allowing me to give companies read-only email addresses. In the four years I've had it I have created 378 email addresses. If I'm including the email addresses that I've already deleted, the l…

I registered a domain name that’s basically just a UUID, and pointed it’s MX records to my self-hosted email server (you could also point it to Google Apps or Fastmail). Everything before the UUID domain is just the name of the service, so something like hackernews@e913ff00...xyz. If someone sells out my email address, I can instantly burn it by just adding a sieve rule since they’re all unique. I even know who sold…

I heard that some services have started rejecting email addresses that contain their name.

Re: Removing email registration improved retention

#135
post #62

Earlier quoted context omitted.

No, one implies a causality that the other doesn't.

It's not a causality, it's a pre-filter. So, of the people who passed filter A more are likely to pass filter B. Today's XKCD was basically about this (in the Alt text) https://m.xkcd.com/2357/

desktop version: https://xkcd.com/2357/

Re: Removing email registration improved retention

#136

Earlier quoted context omitted.

I registered a domain name that’s basically just a UUID, and pointed it’s MX records to my self-hosted email server (you could also point it to Google Apps or Fastmail). Everything before the UUID domain is just the name of the service, so something like hackernews@e913ff00...xyz. If someone sells out my email address, I can instantly burn it by just adding a sieve rule since they’re all unique. I even know who sold…

I heard that some services have started rejecting email addresses that contain their name.

How hard would it be to set up a SQLite database or use a simple cipher?

Re: Removing email registration improved retention

#137
post #92

>you can target them on Quora, Reddit etc as well. This is one of the reasons I stopped giving out my primary email address for user signups. I use a service called Blur which allows for unlimited "masked" emails to be created, allowing me to give companies read-only email addresses. In the four years I've had it I have created 378 email addresses. If I'm including the email addresses that I've already deleted, the l…

If you're using gmail, plus-suffixing is a low-effort but effective countermeasure: username+servicename@gmail.com gets delivered to username@gmail.com.

I have about a 20% failure rate where email address validation fields reject the + character

Re: Removing email registration improved retention

#138

Earlier quoted context omitted.

> you target Facebook/Google ads specifically at that email address That is scummy as hell and might even get you in trouble when it comes to the GDPR if you're operating in the EU. If I sign up for your web service the last thing I want is Facebook/Google knowing that fact.

This is a core feature of every ad platform I've seen and is absolutely not a violation of the GPDR since users are giving consent when they signup. You've signed up for a web service and never seen ads on other sites for it ? Very strange.

No way. If I sign up to, say, a mailing list, or make an account using my email address, I am NOT giving my consent for that site to use my email for targeted marketing (other than the specific mailing list I signed up for).

Re: Removing email registration improved retention

#139

Earlier quoted context omitted.

I would much rather get an ad from someone I shared my email address with than whatever random businesses decided to pay google/facebook/etc the most

I used to think that way too, then changed my mind. I'd rather get random, un-targeted, irrelevant, and even annoying ads from companies that have no idea who I am or that they're even advertising to me. Less creepy that way, also more likely to result in the serendipity of learning new things outside my filter bubble/what the algorithm predicts for me. Sometimes in order to find the real signal, you have to accept t…

While it may be less creepy, it's nearly impossible to break even running advertising this way. And until there is a way to promote a business, especially a new business, without some form of marketing, it's a necessary step in the online ecosystem. In the old days it was possible to fire blind ads and do okay. But as the costs continued to climb it became more important to be able to target your audience in a more accurate way. Retargeting/remarketing has become a very powerful tool in this process.

The last thing in the world I want to do is pay real money to put ads in front of someone that has no intention of buying and no interest in becoming a customer.

It's bad enough that the primary platforms are making the process more and more of a black box where they control every aspect of the marketing process.

Post reply on HN