Live data from Hacker News

Browsing your website does not mean I want your spam

medium.com

211–220 of 251 posts

Re: Browsing your website does not mean I want your spam

#211

Earlier quoted context omitted.

> It used to be totally fine for one shopkeeper to mention to another that he saw a customer looking for a particular item. I dunno. If a shopkeeper kept detailed records of everything you've ever bought or looked at, and gave that info away, it would be pretty creepy.

Supermarkets do that. It's actually scary how much data they collect and what they can do with it. Target managed to figure out when people were pregnant: http://www.forbes.com/sites/kashmirhill/2012/02/16/how-targe...

Much like RMS, I use a friend's discount card (and pay in cash) at the grocery store for this reason. Will a purchase of soda and cookies be linked to me and impact my health insurance cost down the road? Will targeted Mountain Dew ads make their way into every website I visit? Probably not, but I'd rather be sure.

The self-checkout machines only ask for the phone number, with no id challenge. I get the discounts + no tracking, my friend gets more gas points, and the store is left wondering why he buys so much toilet paper.

I wonder how long it will be before they start cracking down on this somehow, and how far they'll take it.

Re: Browsing your website does not mean I want your spam

#212

I am really beginning to hate browsing the web these days... Especially poop up dialogs asking for my email as soon as the mouse cursor leaves the active browser screen. With an average of 20 browser tabs open, while one is loading I often go to click on another to check on something, and this instantly triggers a flurry of popups begging me to stay/subscribe. Also the retargeted ads that follow me everywhere now. MO…

And you don't use an adblocker yet?

It feels like ad-blockers are less and less effective at blocking ads these days, in particular I don't think any of them block these annoying JS popups.

Re: Browsing your website does not mean I want your spam

#213

Earlier quoted context omitted.

Even for Gmail users, the + notation will handle this well. foobar@gmail.com and foobar+SearsSoldMyEmail@gmail.com will both direct to the same location, and relatively few resellers have the sense to strip the extra data.

The problem with the + notation is twofold: First, not all places accept the + character; second, you've now revealed your actual e-mail address (since foobar@gmail.com is just as valid as foobar+dontspamme@gmail.com). I use a subdomain with catch-all, like me.example.com. Everybody is fine with subdomains and then I can use companyname@me.example.com. Using that format doesn't expose my actual e-mail address and mak…

You can use dot as well: foobar.dontspamme@gmail.com

Re: Browsing your website does not mean I want your spam

#214
post #62

Earlier quoted context omitted.

The problem with the + notation is twofold: First, not all places accept the + character; second, you've now revealed your actual e-mail address (since foobar@gmail.com is just as valid as foobar+dontspamme@gmail.com). I use a subdomain with catch-all, like me.example.com. Everybody is fine with subdomains and then I can use companyname@me.example.com. Using that format doesn't expose my actual e-mail address and mak…

> First, not all places accept the + character Additionally you cannot send an email from foobar+dontspamme@gmail.com. If you aggressively use the + character for legitimate signups but need customer support they may not be able to find your account as easily (e.g. "we couldn't find an account associated with e-mail foobar@gmail.com").

> Additionally you cannot send an email from foobar+dontspamme@gmail.com

Um. Why not?

Re: Browsing your website does not mean I want your spam

#215
Privacy Badger is pretty good at blocking things like this -- it watches out for domains that are third-party for more than one site, and blocks requests to them. Does require some tweaking for genuine CDNs (and indeed comes with a yellow-list of common domains that will receive requests but not cookies) but generally very useful.

https://www.eff.org/privacybadger

Re: Browsing your website does not mean I want your spam

#216
post #196

Earlier quoted context omitted.

> Although I suspect this would just start a new style arms race of obfuscation similar to adblock, etc. We could use AI to detect and remove ads, perhaps combined with collaborative filtering.

And what would the advertisers do next? That would just further the arms race.

Well... So what? I mean, just because an arms-race exists doesn't mean participation is futile or counterproductive.

("But Thog, bigger sharp stick will just mean angrier dangercat. Is club race. Why ever do?")

Re: Browsing your website does not mean I want your spam

#217

> This transaction breaks a core promise using the internet: just because I visit a website doesn’t mean I consent to getting spam from it. No it doesn't. There is no core privacy premise of the internet, and certainly not one that everybody used it signed up for. I'm not condoning this behavior, but we're in territory that we don't have prior art for. It used to be totally fine for one shopkeeper to mention to anoth…

> It used to be totally fine for one shopkeeper to mention to another that he saw a customer looking for a particular item. When you do it at scale, the old rules don't apply. The on-line equivalent of that would be e-commerce sites sharing their detailed analytics data with each other. What was described in the article is more alike to a shopkeeper saying to another, "Did you see that woman in red scarf? Her name is…

And rather than just telling your shopkeeper friend, you sell this to anyone and everyone you can.

Re: Browsing your website does not mean I want your spam

#218

Earlier quoted context omitted.

And you don't use an adblocker yet?

It feels like ad-blockers are less and less effective at blocking ads these days, in particular I don't think any of them block these annoying JS popups.

uBlock Origin has never failed me. Even for annoying "non-ad" crap like that.

Re: Browsing your website does not mean I want your spam

#219
post #207

I just love the amazing "Terms of Service" that all of these ad companies have, letting you know that by virtue of loading an HTML page you've consented to have your personal information of ANY caliber spread all over their ad network, their "partners" networks, and to anyone else with a buck and a server, and immediately absolve themselves of any responsibility for what that might mean in terms of information fallin…

The legal enforceability of browsewrap is questionable. Certainly if it's not prominent enough, it would be a weak argument.

The problem is while our metaphorical airline is still able to get away with this, luggage is getting lost and people are getting killed.

I legitimately would love to see how much identity theft can be traced back to these fly-by-night companies and their shady ass practices.

Re: Browsing your website does not mean I want your spam

#220
I personally switched to the following policy a year or two ago to avoid all this crap: 1) NoScript extension filtering everything except the base domain => no third party scripts are allowed except when I explicitly allow them 2) Cookie Whitelist extension to allow cookies only from domains I choose, only when I need => no third party cookies allowed, ever 3) µBlock incase the webpage tries to load iframe ads 4) a unique email address per service (like amazon.[5 random chars]@mydomain.com) so if all else fail and your address gets in the hands of somebody who should not have it, you know where it came from and can expose them
Post reply on HN