Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This log [0], right? Did you miss in the article that it's the `google_push` identifier that's being used for syncing between adtech companies? If you search for it (AHNF13KKSmBxGD6oDK9GEw5O0kvgmFa3qM30zpNaKl72Og), you can see it being included in requests to lots of different adtech firms' domains.

[0] https://brave.com/wp-content/uploads/files_2019-9-2/sample_p...



There is unfortunately no way to prevent that part.

BidRequest Data [0] and Request Time is already enough to fingerprint the user.

"Google prohibits multiple buyers from joining their match tables." part is not technical, it is contract based.

[0] Sample Data from Bid Request

  ip: "F\303\006"
  user_agent: "Mozilla/5.0 (Linux; Android 7.1.1; Pixel XL Build/NOF26V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Mobile Safari/537.36"
  url: "http://www.myfitnesspal.com/food/calories/popeyes-buttermilk-biscuit-29980768"
  cookie_version: 1
  google_user_id: "CAESEIMlaNwMN-rtiDFzjwNIX6Y"
  timezone_offset: -360
  detected_content_label: 39
  mobile { is_app: false 3: "android" 8: 1 12: "google" 13: "pixel xl" 14 { 1: 7 2: 1 3: 1 } 15: 412 16: 732 18: 70092 19: 3500 }
  cookie_age_seconds: 12960000
  geo_criteria_id: 9023221
  device { device_type: HIGHEND_PHONE platform: "android" brand: "google" model: "pixel xl" os_version { major: 7 minor: 1 micro: 1 } carrier_id: 70092 screen_width: 412 screen_height: 732 screen_pixel_ratio_millis: 3500 }


>There is unfortunately no way to prevent that part.

It being technical impossible or infeasible does not give them license to not follow the law.

Either they comply with the law or they don't. I'm not a lawyer, but it certainly doesn't look like they're following the law here.


There is unfortunately no way to prevent that part.

Well there's absolutely a way: single-source JS and no CORS.


Lol.

:/


Like stopping? I do not do that and am surviving last I looked.


> There is unfortunately no way to prevent that part.

“there is no way for google to operate under the GDPR and provide targeted advertising” ?

i’m inclined to agree :/


> There is unfortunately no way to prevent that part.

Couldn't each buyer get their own "auction ID" as well as their own "user ID"? Am I completely misunderstanding things?


Also another benefit of google_user_id vs Google's Ad Manager cookie is, it expires after 14 days. So after 14 days, you will get new google_user_id for same user. So syncing between adtech companies does not have much value.


You are implying that this mechanism is already used by adtech providers, we have no proof. Those players are often competitors that are not working together so they won’t share their user data (not a user identifier, only a “page load” identifier). If they want to sync their user ids (because one is buying inventory from the other), they can launch a cookie sync between themselves (same process as with google_gid, persistant user identifier, much more efficient)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: