Live data from Hacker News

Google’s GDPR Workaround

brave.com

601–610 of 629 posts

Re: Google’s GDPR Workaround

#601
post #11

Snippets from the article: > The evidence further reveals that Google allowed [...] > Google has no control over what happens to these data once broadcast [...] Is it possible that Google does have "control" over the data after broadcast, albeit legal control via contracts with advertisers (as opposed to technical control)? Perhaps Google's GDPR compliance strategy relies on the participating advertisers to comply wi…

> Is it possible that Google does have "control" over the data after broadcast, albeit legal control via contracts with advertisers (as opposed to technical control)?

That distinction is important. I’m happy that privacy advocates are realising that platforms having access to enforceable contracts is key–too many are quick to paint platforms as the source of the problem and not an agent who, with the right tools, could organise a market.

Facebook has suggested having an independent court what is acceptable content in their platform. Google could think about delegating the control of how its IDs are used to an independent entity with the power to audit its partners’ data practice properly.

Re: Google’s GDPR Workaround

#602
post #522

Earlier quoted context omitted.

Why should we give ad-tech their one millionth chance to "do the right thing"? They've proven time and time again they cannot be trusted.

it isn't about giving ad-tech any chance of anything, it is about websites that are liked and used by people (most of whom have either no means or no desire to support those websites with money directly) being able to sustain themselves in order to exist.

To be honest, that doesn't matter to me. I think that websites who inflict the ad-slingers on their readers are showing great disrespect to and disregard for their readers.

Re: Google’s GDPR Workaround

#603

Earlier quoted context omitted.

The time of validity and how hard it might be to build a profile are not factors in whether or not this is legal under GDPR. Here's the actual text from GDPR on pseudonyms and synthetic keys of this type[1] > The principles of data protection should apply to any information concerning an identified or identifiable natural person. Personal data which have undergone pseudonymisation, which could be attributed to a natu…

> The pseudonym (gid) is itself considered PII under GDPR. I know of multiple systems that use a UID but throw away a user’s information, including the UID mapping, when the user leaves. This allows historic metrics to be retained without ever identifying a user who isn’t still using the system. AFAICT, guids are a grey area.

I don't mind that at all, so long as that replacement is never shared with other entities.

Re: Google’s GDPR Workaround

#604
post #11

Snippets from the article: > The evidence further reveals that Google allowed [...] > Google has no control over what happens to these data once broadcast [...] Is it possible that Google does have "control" over the data after broadcast, albeit legal control via contracts with advertisers (as opposed to technical control)? Perhaps Google's GDPR compliance strategy relies on the participating advertisers to comply wi…

> Is it possible that Google does have "control" over the data after broadcast, albeit legal control via contracts with advertisers

I don't actually put much faith in such "control".

Re: Google’s GDPR Workaround

#605
post #342

I checked the sample log provided. Below is the google_gid for different publishers, there is no proof of overlap, they have different google_gid for same person. Which is exactly what google describes. [1] I don't understand what Brave claims. d.agkn.com CAESEP-S3Zs5f0_kq11XTCZP_mE id.rlcdn.com CAESEPpf2T4-2AsAR_4rer3RfNs image6.pubmatic.com CAESEB9H3qdV26kxEiz-BJ_TY-M pippio.com CAESEJyqG1Pg1j-_scqW8kDzTkg token.ru…

which is the "workaround" to the gdpr the article badly describes (probably because brave upcoming ad network will do the same but more workaroundily) now those are used to match a 3rd party id. you just need a gdpr_workaround schema in your data base with two columns user-id, google-random-id with N-1 records indexed both ways. gdpr has restrictions on pin pointing a single person. this is effectively doing that, bu…

> probably because brave upcoming ad network will do the same but more workaroundily

AFAICT Brave's plan is to send a block of potential ads to the client and use a client-side machine learning algorithm to choose specific ads. So the claim is that none of client events, inferences from the algo, nor ad choices travel from the client to the ad networks. (But ad networks retain their crazy microtargetting which I guess is the selling point.)

Even if Brave were to choose the blocks of ads based on geolocation and other install-time/runtime data which they then sell to third parties, it's still significantly less data leaking from the client's browser compared to, say, a default Chrome install. But them storing/selling that would be a clear GDPR violation as well as going directly against all their explicit public claims so far.

What is your understanding of Brave's upcoming ad network that leads you to believe it requires a surreptitious GDPR violation?

Re: Google’s GDPR Workaround

#606

Earlier quoted context omitted.

Yes, we can do contextual targeting, but after that, what are the ways to improve upon the outcomes (from an advertisers standpoint) without violating privacy?

Depends on the outcomes/metrics they’re interested in. For instance, I genuinely believe that targeting based on content is less dangerous from brand safety/brand perception perspective. How about conversions, sweet $$? I think replacing audiences with a semantic targeting model (nlp) could perform almost as good (if not better). Behavioural Targeting performance is overrated (feel free to look it up, esp. CPM vs. co…

Well.. I'm totally OK with the efficiency in online-advertising being low. My point was that after a certain point, there is no way to get a better ad-to-viewer match without violating privacy. Google was never on the right side of privacy, and given the business they're in, they never will be.

Re: Google’s GDPR Workaround

#607
post #318

I think the HN community, and most consumers, tend to look at things from only one angle. Imagine you start work at some small shop that manufacturers widgets for consumers. What would you do when you have to advertise your product? You'd have to turn to Google is a similar company. Are there any real alternatives? (I am asking because I really want to know) I say this because I am in this position now. I have to fig…

You advertise on a website for widget fans. That's how it successfully worked for a long time. The whole targeted advertising is to allow adtech companies to identify users of the "widget fans" site, and then advertise to the same people, but on another, cheaper site.

Targeting existed long before computers. The difference today is the massive amount of very personal data being collected on people without their knowledge or consent and the risks it puts on them.

Imagine if you went back to say the 1920s, and you told a marketing director that you could install a one-way mirror room and back door into every household in the country, and staff them all with analysts who will secretly observe people in their homes 24 hours a day, 365 days a year. People would think you were crazy. In fact, I bet most people today would be completely against that idea, yet wouldn't realize that what companies like Google and Amazon are doing today is effectively the same thing, except _much more_ invasive.

Re: Google’s GDPR Workaround

#608
post #581

Earlier quoted context omitted.

There are regular comments by declared employees of quite a few companies including Google on HN. The commenting and vote/flag brigadeering around subjects that center on one of these companies is such that many subjects are either voted off the homepage entirely or the participants in the thread get downvoted/upvoted to better support the company position or narrative. This is all quite in the open.

What is the 'quite in the open' evidence you have of this?

The profiles and declarations of 100's of users of HN.

Re: Google’s GDPR Workaround

#609

Earlier quoted context omitted.

The alternative is to spend hundreds of hours finding widget-related websites, trying to contact the owner(s), negotiating what ad spots are available, what ads are acceptable to run, and what pricing/terms will work for both parties, then managing that relationship over time to ensure ads are actually being displayed, being paid on time, contracts renewed, etc. It's definitely possible, but you're just doing everyth…

> It's definitely possible, but you're just doing everything manually that ad networks do for you. You've just explained how contexual ads used to work, which doesn't need all the invasive surveillance modern internet users have to put up with.

Yeah and there's a reason the tech moved on from that. It was a LOT of work on both ends to negotiate and monitor the relationship. Instead now we have a central broker who both parties work with that has set up a computerized way to manage these relationships.

Personally I think the solution that lets us keep ad supported content and easy ad placement would be for Google to force companies to provide bots they could run internally so the profiles never leave Google's datacenters and strictly monitor the output so the buyer bots don't leak information back to the companies. I think that would do a lot to alleviate the privacy concerns and breaches and is honestly how I though ads were being sold for the longest time instead of profiles being sent to companies buying placement.

Re: Google’s GDPR Workaround

#610

Earlier quoted context omitted.

The alternative is to spend hundreds of hours finding widget-related websites, trying to contact the owner(s), negotiating what ad spots are available, what ads are acceptable to run, and what pricing/terms will work for both parties, then managing that relationship over time to ensure ads are actually being displayed, being paid on time, contracts renewed, etc. It's definitely possible, but you're just doing everyth…

> It's definitely possible, but you're just doing everything manually that ad networks do for you. You've just explained how contexual ads used to work, which doesn't need all the invasive surveillance modern internet users have to put up with.

Just so long as I don't have to have relationships with dozens or hundreds of hosts.
Post reply on HN