Live data from Hacker News

Google Tag Manager, the new anti-adblock weapon (2020)

chromium.woolyss.com

681–690 of 902 posts

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#681
post #93
post #80

Earlier quoted context omitted.

Just block the GTM js from loading, it'll stop it easily.

The big change they are suggesting is that the gtm code is no longer accessed via a predictable Google domain, rather it is requested through a subdomain of the parent site.

uBlock already blocks stuff like Plausible analytics based on what's in the code, even if it runs on the parent site. Would this be any different?

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#682

I'm the author, good to see this on HN, raising awareness on the topic I don't know who made the translation and when it was made, but the original article in french ( https://pixeldetracking.com/fr/google-tag-manager-server-sid... ) contains more information on recent GTM "improvements"): mainly on how you can easily change JS library names and detailed instructions on how to host your container in other clouds or s…

> I don't know who made the translation and when it was made

This page was saved with SingleFile (I'm the author of SingleFile). Therefore, I can tell you that this page was produced on Tue Dec 08 2020.

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#683

Disclaimer: I am a data analyst. I consult companies in regards to ethical data collection. But I also know of black sheep. I don't have a problem with websites measuring what I view, click, add to cart or buy. I want them to be able to see what doesn't work in terms of user experience. And if they do marketing I even want them to be able to see from which source of traffic (aka marketing effort) how many conversions…

Similarly, I want to be able to show my users ads. They're not really bad ads, but otherwise I lose money on providing service. And then we risk the "youtube paradox": keep showing more ads to your ad watching users so they subsidize the growing number of ad blockers, but this causes more to use ad blockers so show even more ads.

Can't you just switch out the users for bots that watch the ads without adblockers and then gradually switch out the content for ads to keep the growing number of bots busy? That way you can also show really bad ads without anyone complaining. win win.

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#684

Earlier quoted context omitted.

To my observation, there are no sites with more than a dram of content on them that haven't been compelled by GDPR compliance to put an obnoxious cookie banner up. If you've found some, please share.

If you need to set a cookie for the correct operation of your site, then you don't need a cookie banner. The banners are a middle-finger to the GDPR.

... but "correct operation of your site" is in the eye of a judge and can't be evaluated before someone brings suit, so "better safe than sorry" behavior (at the cost of user time) is completely predictable.

... It's not even clear that it's safe to log IP addresses in the style of a default Apache configuration on a static website without user consent.

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#685

I read the original article back when it was published in November 2020[0]. This is what led me to introduce new static network filter options: - strict1p, strict3p [1] - header=, experimental, disabled by default [2] I used Simo Ahava's blog as test case, and with these new options, I could craft a filter to block the Google Tag Manager script on Simo Ahava's blog. However due to the lack of more test cases, no more…

Thanks for adding this comment. My immediate reaction when seeing this was that I thought it looked familiar to previous conversations I saw a while back. But I didn't know for sure that they lined up exactly, and I wasn't looking forward to doing the research to find out.

> All the new filter options introduced above can't be implemented with declarativeNetRequest.

My understanding was that stuff like CNAME uncloaking was already unsupported in Chrome[0]. Of course, Manifest V3 won't make the situation any better though.

[0]: https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#686
post #542

Earlier quoted context omitted.

... in the tech-commentary echo chamber, perhaps. The outside world is more apathetic than hostile to it.

It shouldn’t be on the todo list of the average user to be knowledgeable on this subject, just like the average consumer should not have to be an expert in airbags to expect the ones installed in their car to work.

I think there's a huge assumption implied in an analogy between airbags and user tracking. Airbags save lives. Anti-tracking guards against some hand-wavey philosophical concerns regarding privacy (in an inconsistent fashion, even... It's hard for me to buy that we need to make user-behavior tracking for ad targeting illegal in a world where user-purchase tracking for credit reporting is legal).

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#687
post #542

Earlier quoted context omitted.

... in the tech-commentary echo chamber, perhaps. The outside world is more apathetic than hostile to it.

It shouldn’t be on the todo list of the average user to be knowledgeable on this subject, just like the average consumer should not have to be an expert in airbags to expect the ones installed in their car to work.

The motto of some people on this website when it comes to unethical behavior in tech seems to “Well, most people didn’t actively try to stop us…”

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#688

This kind of data collection abuse is why I think we need more addons like AdNauseam [1]. Unlike uBlock Origin, it's not available from the Chrome web store anymore, which is a good sign that Google hates these types of addons more than they hate simple blockers. Blocking A/AAAA domains with custom URLs to prevent tracking is almost impossible, so instead let's flood the trackers with useless, incorrect data that's n…

I worked for a agency a couple of years ago, when, out of the blue, tracked data contained tons of random data instead of the expected UTM parameters. It took us a while to figure out what was happening. It was some kind of obfuscating plugin that was messing up well known tracking parameters.

What I want to say is: stuff like that could actually cause a lot of fun on the other side.

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#689

Disclaimer: I am a data analyst. I consult companies in regards to ethical data collection. But I also know of black sheep. I don't have a problem with websites measuring what I view, click, add to cart or buy. I want them to be able to see what doesn't work in terms of user experience. And if they do marketing I even want them to be able to see from which source of traffic (aka marketing effort) how many conversions…

> marketing departments act ethically

Impossible. All marketing is inherently unethical. At best it's got massive conflicts of interest everywhere: who trusts the opinion of someone who's being paid to say good things about a product or service? I want to talk to real humans with real experiences and real opinions, not paid for ads and testimonials.

Marketing at its worst is kind of an undefined thing because they reach new lows every day, there's no limit they won't cross. It's gotten to the point I consider advertising to be abuse if not mind rape. We don't tolerate people assuming they have arbitrary access to our bodies, and our attention and cognition are absolutely part of our bodies and deserving of respect.

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#690

Earlier quoted context omitted.

This pops up regularly, but AFAIK it's not correct. The law is much more fine grained than the USA PII concept. IP addresses are only personal data (PD) if you are capable of using them as identification mechanism. If you don't they are not. This also means that something that is not PD for you, can become PD when you give it to someone else. Or that 2 items which are not PD themselves, become PD when you combine the…

Incorrect. In the "Breyer" ruling[0] the highest European court concluded that dynamic IP addresses are PII (not just personal data, and not just data), as there is an abstract risk that combining IP addresses with other data can lead to identification of a user. The ruling explicitly said that the mere risk of such an identification is enough, not that such an identification has to actually happen. Subsequent ruling…

This is a very interesting legal document, and I'll have to take the time to read it slowly before I can judge it.

It centers around this line:

   ... not PD for you, can become PD when you give it to someone else
and claims that, as this potentiality can always be fulfilled, you should consider it PD. This would invalidate the first part of the post, but is still not enough to make a default deploy of a logging http server illegal because of the 6.1(f) legitimate intrest rule. In fact, things like 21.1(b) might make it obligatory.

Now we are in lawyer 'interesting question' territory which costs a lot of money, and I still don't think you'll need to worry, because you're not violating the spirit of the law. Personally, I'll go on depending on 2.2(c)

Post reply on HN