A proposed standard now under discussion at W3C, dubbed simply “Attribution” aims to redefine how ad effectiveness is measured across the web. This proposal would centralize measurement of ad effectiveness under the control of major platform players, including Google, Apple and Meta. While “Attribution” is framed as a privacy win, in practice it would shift more advertising onto low-trust content and AI-generated slop.
HN user
dmarti
https://blog.zgp.org/about/
I'm linking my keytrace.dev: did:plc:ipaj5witaxhuy4uxlhib7bft
A certain amount of hustle and overselling by inventors and new companies has always been a thing. What’s unfamiliar in recent times is the combination of large, oligopoly companies with the failure of those companies to make an effort to go legit as they grow up. While American business culture has always celebrated “fake it ’til you make it,” we have pivoted to “make it, then fake it even harder.”
This is a great idea for getting more people blogging. Are there going to be RSS feeds?
Is each browser process dedicated to a single customer, or do you clear cookies and other state (localStorage, cache, Chrome advertising features...) between customers?
Google Chrome has another "AI training" API that has been there for a while -- document.browsingTopics() -- this is for passing information about your browsing history to ML on the Google side. Hard to be sure about what information about you can be inferred from this.
It might also be a good idea to block or warn about sites using that one.
More info: https://noyb.eu/en/google-sandbox-online-tracking-instead-pr...
https://github.com/w3ctag/design-reviews/issues/726#issuecom...
You can have the most tricked-out, up-to-date protections on your client, or in a proxy between your client and a web site...and if that site is using server-to-server tracking they can get around it.
https://www.facebook.com/business/help/2041148702652965?id=8...
Yes, Facebook Conversions API is server-to-server, so it circumvents the privacy settings and tools on mobile platform or browser.
https://www.facebook.com/business/help/2041148702652965?id=8...
Research using a browser extension or web proxy can't see CAPI tracking.
(CR study co-author here)
The tricky part, though, is that even with your client-side settings and privacy tools set up 100% right, any company that has your info can still send it to Facebook server-to-server, with "Conversions API."
https://themarkup.org/pixel-hunt/2023/08/02/help-us-investig...
WA MHMD is a game changer because private right of action. Doesn't rely on the attorney general or a dedicated privacy agency to take action -- private lawyers can.
(Technically not the first privacy law with private right of action because the Video Privacy Protection Act has one, but that law was originally passed to cover videotape rentals and the courts are still working out how it applies to video content on the Internet)
The companies it's mainly good for are those who have personal data but are not required to register as a data broker. So if you have a brand with content, forums, retail, events, or whatever and can collect info on people, then by pure supply and demand the market value of your audience data goes up.
No, they're regulated under the federal FCRA, not state law.
FLoC as a source of fingerprinting bits has been an issue in W3C discussions of the project.
https://github.com/WICG/floc/issues/69
As a fingerprinting surface FLoC has similar properties to the Battery Status API -- not stable for the same user over long intervals, but can be used to help match pageviews from different domains that were close in time.
https://www.schneier.com/blog/archives/2016/11/firefox_remov...
Advertisers don't bear the costs of fraud. Intermediaries don't bear the cost of fraud.
Fraud is priced in. It drives down the value of all ad inventory in the market.
The costs of fraud end up being borne by legit publishers (who have to compete with fraud for the same ad budgets) and with copyright holders (whose work gets copied onto bottom-feeding sites.)
http://blog.aloodo.org/posts/thank-you-for-supporting-fraud/
Part 2 of the article is at: http://www.scylladb.com/2016/04/29/io-scheduler-2/
ScyllaDB web person here. If I made it so that you could block one script and get a home page without the horizontally scrolling thingy (but have all the other JS stuff work including syntax highlighting and graphs), would you come back? ( dmarti@scylladb.com )
"just run an ad blocker" is the new "just run a firewall". You need to check if you got something with real tracking protection (Adblock Plus doesn't, out of the box). http://blog.aloodo.org/posts/adblockers-myths-facts/
The "acceptable ads" criteria are here:
https://adblockplus.org/en/acceptable-ads#criteria
If you make a modern-looking long-scrolling article that has an ad somewhere in the middle, it's not "acceptable". If you get a crappy CMS that splits every article into 9 pages with an ad at top and bottom, then it is.
The main weird thing is that 3rd-party tracking is "acceptable" (!)
(I recently added some details on the problem to the Aloodo tracking test, because users have started to assume that ad blockers fix everything. http://blog.aloodo.org/posts/adblockers-myths-facts/ )
Tor Browser Bundle is working on this: "Design Goal: All Tor Browser users MUST provide websites with an identical user agent and HTTP header set for a given request type. We omit the Firefox minor revision, and report a popular Windows platform"
https://www.torproject.org/projects/torbrowser/design/#finge...
Maybe just make their User-Agent the standard?
(author of the original article)
That creeped out feeling is your brain letting you know about an information asymmetry -- someone knows more about you than you know about them. When you feel creeped out in a market setting, it's a warning that you're likely to get a bad deal.
Response to some earlier comments on the article:
http://zgp.org/~dmarti/business/arguments-for-targeted-adver...
Exactly.
Ad fraud is not just a waste of energy (like TV ads playing to no viewers). It supports bad stuff on the Internet at the expense of good stuff.
* Ad fraud is now the number one malware payload.
* Low-quality impressions show up on copyright infringement, comment spam, and other problem pages.
* When advertisers buy programmatically on markets that include both legit and fraudulent inventory, publishers pay for fraud in the form of lower CPMs.
More in response to the original article: http://blog.aloodo.org/posts/thank-you-for-supporting-fraud/
The remaining hard part is the adapter layer to enable the extra applications such as the issue tracker to use the Git repository for storage. Joey Hess has a good article about Git "databranches" here: https://joeyh.name/blog/entry/databranches/
There is already a lot of fraud on ad networks. This probably won't affect the raw amount that much. The main effect will be to make it easier for existing fraud to hide.
The problem is that out of these three choices:
* highly intermediated advertising ("adtech")
* user privacy
* fraud control
...we can only have two.
Relevant article: http://openp2p.com/pub/a/oreilly/ask_tim/2003/bountyquest_10... Tim O'Reilly: "some months after we'd awarded the bounty, splitting it three ways for prior art that wasn't completely on the money, someone sent in a killer piece of prior art. I still have it on my bookshelf, in the odd event that Amazon loses its senses and sues anyone else over 1-click."