News: 1614254645

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ever felt that a few big tech companies are following you around the internet? That's because ... they are

(2021/02/25)


A new extension for Google Chrome has made explicit how most popular sites on the internet load resources from one or more of Google, Facebook, Microsoft and Amazon.

The [1]extension , Big Tech Detective, shows the extent to which websites exchange data with these four companies by reporting on them. It also optionally blocks sites that request such data. Any such request is also effectively a tracker, since the provider sees the IP number and other request data for the user's web browser.

[2]

The extension was built by investigative data reporter Dhruv Mehrotra in association with the Anti-Monopoly Fund at the Economic Security Project, a non-profit research group financed by the US-based Hopewell Fund in Washington DC.

Cara Rose Defabio, editor at the Economic Security Project, [3]said : "Big Tech Detective is a tool that pulls the curtain back on exactly how much control these corporations have over the internet. Our browser extension lets you 'lock out' Google, Amazon, Facebook and Microsoft, alerting you when a website you're using pings any one of these companies… you can't do much online without your data being routed through one of these giants."

[4]

[5]

One of the sites blocked by Big Tech Detective is that of its own sponsor, the Economic Security Project

Let's talk infrastructure

That, perhaps, is an exaggeration. Big Tech Detective will spot sites that use Google Analytics to report on web traffic, or host Google ads, or use a service hosted on Amazon Web Services such as Chartbeat analytics - which embeds a script that pings its service every 15 seconds according to [6]this post - but that is not the same as routing your data through the services.

In terms of actual data collection and analysis, we would guess that Google and Facebook are ahead of AWS and Microsoft, and munging together infrastructure services with analytics and tracking is perhaps unhelpful.

Another point to note is that a third-party service hosted on a public cloud server at AWS, Microsoft or Google is distinct from services run directly by those companies. Public cloud is an infrastructure choice and the infrastructure provider does not get that data other than being able to see that there is traffic.

Dependencies

Defabio made the point, though, that the companies behind public cloud have huge power, referencing Amazon's decision to " [7]refuse hosting service to the right wing social app Parler , effectively shutting it down." While there was substantial popular approval of the action, it was Amazon's decision, rather than one based on law and regulation.

She argued that these giant corporations should be broken up, so that [8]Amazon the retailer is separate from AWS , for example. The release of the new extension is timed to coincide with US government hearings on digital competition, drawing on [9]research from last year.

Digital power is only one of the issues which a utility like this reveals. Site and business reliability is another: if there is an outage with services like AWS or Microsoft's Office 365, the impact is huge. Even if the problem is just advertising scripts or Google-hosted fonts going offline, it can cause errors and performance issues. These are dependencies, and the more a site has, the less reliable it is – though most of the time the reason for problems is closer to home.

Privacy is a third issue and the ubiquity of tracking techniques, not only from these big four tech companies but also from elsewhere in the ad tech industry, is impacting society in unexpected ways. It is a short path from personalised advertising, so someone browsing the web sees ads for things more likely to interest them, to powerful techniques for manipulating public opinion.

El Reg takes it for a spin

What does Big Tech Detective actually reveal? We installed it into Chrome, which requires developer mode and a manual download since it is unlikely to be approved for the official Chrome Web Store. By default the tool gathers statistics, but there is an option to block sites which request data from any of these four companies. Engaging this "traffic lock" means that almost every site will be blocked, as will the search engine. Even privacy-focused search engine duckduckgo, for example, fails because it loads resources from Microsoft.

There do seem to be some flaws with the extension. We tried it on a site which is close to the default you get from an ASP.NET Core application created using an official template in Microsoft's Visual Studio. We were concerned to find that, according to Big Tech Detective, it has a dependency on Microsoft. Looking more closely though, the CSS stylesheet it identified only had a comment in the source code referencing documentation on Microsoft's site. There was no actual data transfer.

Did we find any sites that do not use any of these companies? One was [10]sqlite.org , the official site for the widely used open source database engine, which also serves as a demonstration of how fast and lightweight it is. The site [11]stated that it "handles about 400K to 500K HTTP requests per day, about 15-20 per cent of which are dynamic pages touching the database. Dynamic content uses about 200 SQL statements per webpage. This setup runs on a single VM that shares a physical server with 23 others."

[12]

Big Tech Detective analyses sites you visit. This data is held locally, but data is sent to the extension’s server to map IP numbers to source companies

The official Linux site, kernel.org, also passed, but not that of the Linux Foundation, which reportedly loads resources from Google and Amazon. Items included analytics, fonts and captcha scripts from Google, as well as services running on AWS.

The extension lists all such requests with the full URL of each, which can be instructive. A local newspaper site (a genre notorious for the extent of their intrusive advertising and tracking scripts) apparently made 166 requests to Amazon, 77 to Google and one to Microsoft, all for a single page. Big Tech Detective also blocked its sponsor's site, the anti-monopoly project at the Economic Security Project, reporting links to Google and Facebook (the embedded YouTube video likely did not help).

Big Tech Detective itself has a [13]privacy policy informing us that: "The IP addresses of a requested webpage and the content it loads — for example, Facebook pixels and Google Analytics scripts, fonts, and images — are encrypted with HTTPS and sent it to a Cloud Application Platform called Digital Ocean, which follows a different privacy policy."

The reason for this is to connect with an application that identifies the company behind each IP address, and the policy stated that "Big Tech Detective does not store or retain any information about your browsing history on its servers."

[14]

Opinions on the goals of the sponsors of this project will vary, but as a mechanism for explaining the extent to which the internet depends on and links to resources from a few giant companies, it is effective. ®

Get our [15]Tech Resources



[1] https://bigtechdetective.net/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YDfXrOHApTZvLSLSSGnfGQAAABM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://medium.com/economicsecproj/how-to-break-the-internet-or-why-big-tech-detective-demonstrates-monopoly-online-67c13551e82e

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YDfXrOHApTZvLSLSSGnfGQAAABM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://regmedia.co.uk/2021/02/25/antimonopoly.jpg

[6] https://engineering.chartbeat.com/category/ec2/

[7] https://www.theregister.com/2021/01/11/aws_parler_ban/

[8] https://www.theregister.com/2019/07/16/bernie_break_up_tech/

[9] https://judiciary.house.gov/uploadedfiles/competition_in_digital_markets.pdf

[10] https://sqlite.org/index.html

[11] https://sqlite.org/whentouse.html

[12] https://regmedia.co.uk/2021/02/25/bta.png

[13] https://bigtechdetective.net/privacy

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YDfXrOHApTZvLSLSSGnfGQAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[15] https://whitepapers.theregister.com/

Anonymous Coward

"Dependancies" -- please fix

MiguelC

[1]both spellings [2]are valid but, for consistency, ElReg should use only one of them throughout the article

[1] https://www.collinsdictionary.com/dictionary/english/dependancies

[2] https://www.collinsdictionary.com/dictionary/english/dependencies

razorfishsl

you want to run it against the daily-mail in the UK...

as many as 80-100 for other trackers....

Dogfood

AJ MacLeod

You didn't run it on theregister.com?

Re: Dogfood

Loyal Commenter

NoScript is currently blocking the following on this site:

doubleclick.net (ad spewer)

google-analytics.com (creepy tracker)

googletagmanager.com (also creepy tracker)

As far as the number of things to block to avoid tracking, El Reg is by no means the worst of the news sites. The Independent, for example, has a good two dozen various domains it pulls things from, some of which are obvious advertisers/trackers (there's not a lot of difference between the two any more), some are more opaque.

As a rule, I have everything blocked by default, and then if the web site doesn't work, I allow domains one-by-one. If it won't work without me allowing a domain I have previously explicitly blocked (such as doubleclick), then it's pretty obvious that the purpose of the site is to get advertising revenue, and not to provide any useful information, and I go elsewhere. The same goes for any site that has an "ad-blocker" popup. If it can't be easily removed by hitting F12 and setting the display attribute to none, then I'll go elsewhere.

I'm certainly not going to let any scripts run from such dubious sites as the Daily Heil, the Scum, or the Ex-press, so if something directs me to one of them, I figure I can find the actual information elsewhere anyway, without having to read past the right-wing editorial and interpretation of the facts.

Re: Dogfood

Ozzard

Also admedo.com, ads-twitter.com. And that's presumably *after* my ad-blocker has run its sights over it. Privacy Badger reports attempted trackers from Doubleclick, Admedo, and Google Analytics. At least Decentraleyes is tolerably happy *sigh*.

Re: Dogfood

Alumoi

Strange, no admedo and twatter here. Maybe because I have pihole running on my network?

Re: Dogfood

iron

Unfortunately your NoScript solution is missing two advertising trackers on this site - Twitter and Admedo. I wonder how many it misses on other sites you visit?

Re: Dogfood

alain williams

My NoScript caught/stopped them

Re: Dogfood

Greybearded old scrote

Now you point it out, admedo is loaded from within one of elReg's own javascript tags.

BAD elReg! No Spankings For You!

More to the point, your js will be blacklisted too. I wonder if that will stop me commenting?

Re: Dogfood

Greybearded old scrote

OK, I just tried posting again below, and it works without JS. Well done on that one folks!

Now I'm wondering how neither noscript or privacy badger spotted it. They are up to date versions.

Re: Dogfood

Loyal Commenter

I have Adblock Plus running as well, they are probably cookies from the adverts that aren't being loaded. As far as I am concerned, ads are nothing more than malware vectors.

vulnerable? Who, us?

vtcodger

So all an anarchist needs to do is screw up the routings to four web providers. The web goes down. And western civilization (assuming such exists) is brought to its knees.

Cheerful thought to start the day.

Re: vulnerable? Who, us?

tfb

Alternatively, a serious security compromise at, say, Google & Facebook is a catastrophe.

And while the people who work there are no doubt technically very good, they're not that good: this is going to happen in due course.

Re: vulnerable? Who, us?

msobkow

It already HAS happened, they're just keeping it quiet. Remember that furor a couple months ago where Google suddenly shut down their servers and Microsoft services went offline? That was the emergency cleanup being done... which they're saying NOTHING about because then people would realize the risk is REAL, not just theoretical.

Potemkine!

So the Cloud is safe, secure, magnificent, but everything relies on two or three providers? If they go down everything does too?

Security nerd #21

If Akamai went down, it would probably affect everybody (well non China anyway).

The Internet is held together with gaffer tape, and at some point it will break. Although of course its meant to be resilient, but if all the traffic ends up being routed under some road in Africa / India / Basingstoke (delete as appropriate) ....

Advertising companies just make things worse - I'll be glad when 3rd party cookies are fully banned, although not via Google's intended method please.

Not quite true

Cuddles

From the images, it appears this extension blocks a site entirely if detects a single thing anywhere on the page attempting to load anything from Google, etc. Meanwhile, I block Google, Facebook, and the rest using things like Noscript, and most sites remain perfectly useable. So it's simply not true that the web becomes unusable without them. Lots of sites use them for tracking and analytics, but still work perfectly if you block that part of things while allowing their first party things to run.

So I'm not sure I really see the point of this. Either you use it to block virtually the whole internet because it won't just block the tracking parts of a page. Or you use it to collect statistics without actually doing anything useful at all. Why would you not just use Noscript, ublock, Privacy Badger, or any of the wide variety of other plugins which let you block the important bits and collect statistics at the same time? And are all happily available as official extension without needing sideloading via dev mode. It appears to be much more a publicity stunt rather than something intended to be actually useful.

Re: Not quite true

Loyal Commenter

Plus, of course, there's no way of knowing whether the site in question is passing any or all of that tracking information onto other companies through the back-end; this only applies to things they try to load into your browser, which, as you correctly point out, anyone with any sense is blocking already.

Re: Not quite true

Ben Tasker

> Why would you not just use Noscript, ublock, Privacy Badger, or any of the wide variety of other plugins which let you block the important bits and collect statistics at the same time? And are all happily available as official extension without needing sideloading via dev mode. It appears to be much more a publicity stunt rather than something intended to be actually useful.

The answer to this is actually hinted at in the article

> The release of the new extension is timed to coincide with US government hearings on digital competition, drawing on research from last year.

It's to draw attention to the issue and highlight just what an issue it is at a time when (US) lawmakers are considering the impacts of the lack of digital competition. In that context, the fact that it *breaks* sites in block mode is probably a positive - most lawmakers won't understand a nuanced technical discussion, but they will understand the ramifications of "it breaks if you turn these sources off".

Re: Not quite true

iron

> they will understand the ramifications of "it breaks if you turn these sources off

Simplification is great until you simplify to the point of lying. Many of the sites this extension flags as sending data to BIG IT are not doing so. All it takes is one half intelligent techy to point out a site is hosted on Azure / AWS but not sending data to MS / Amazon and everything from the extension is then suspect and can't be trusted.

I'm all for blocking trackers and preventing Google and FB from doing their creepy thang but this extension is not helping.

Re: Not quite true

Loyal Commenter

You can have your site hosted on Azure, sure. You'll probably be using your own domain name as well, so nothing need be loaded from any Microsoft domain, certainly not any other than the azure domain(s).

The same goes for AWS - you might need to load some "cloudy" stuff from an AWS domain, if that's where your hosting is, and you don't have something sat in-between on your own domain, but you sure as hell don't need to be doing so from an Amazon one.

The whole point of these hosted environments, is that it's your data in your environment, hosted by Azure, or AWS, or whatever. If MS or Amazon started poking around in those environments then people would stop using them and involve the lawyers pretty quickly.

As I said in another post, there's nothing to stop the web back-end of any site from sending your data on to anyone else they like in a technical sense . In the EU, there's GDPR to make it a very expensive mistake to do so, and in the UK as well, for the time being, until the extreme free-marketers in government take those protections away.

Re: Not quite true

Anonymous Coward

> All it takes is one half intelligent techy to point out a site is hosted on Azure / AWS but not sending data to MS / Amazon

Huh?

Re: Not quite true

Kevin Johnston

I suspect this comes from the same thought process as the one in Australia which puts Facebook's nose out of joint.

Continual chatter about these companies and their net presence tends to numb people to just how big they are and it takes an activity like this to shock people into resetting the marker for what big really means on the web

karlkarl

The "big tech" are obviously to blame. However the individual web developers who drag all this stuff in needlessly are also causing this.

I.e rather than host a custom font on the web site, they instead opt to use an external reference to Google's font server. They do even worse things for ads, social media, and the millions of dependencies they cram into their site to do trivial things.

Web developers just need to get better and start showing some discipline like their close developer relatives.

DevOpsTimothyC

It's not just the web developers. Most of the time they are NOT the ones DECIDING to pull in page assets from specific location.

Typically it is someone higher up saying "I want to see stats via tag manager, Make it happen or get another job" Rinse and repeat for Ad's, page optimization tools (marketing departments wanting to make content / layout change without involving dev teams), ratings sites etc

web developers

alain williams

Will do things that are easiest for them and don't care about privacy of visitors.

But this is something that the [1]ICO should clamp down on: it is a privacy breach, data is being taken without users' knowing - this is a flagrant breach of the GDPR as [2]must be specific and informed and [3]freely given . But: the ICO is asleep on the job.

[1] https://ico.org.uk/

[2] https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/consent/what-is-valid-consent/#what3

[3] https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/consent/what-is-valid-consent/#what2

Re: web developers

b0llchit

The EU courts have already determined that IP addresses are private data. Therefore, connecting to places that are not explicitly agreed upon may be considered a breach of the consent rule in the GDPR.

We need a ruling that no third-party content may be loaded until explicit consent is given. And, here the same rule should apply as with cookies, where a blanket take-it-or-leave-it approach is not an acceptable way to handle consent.

Any breach should be very expensive for both web-site owner/operator. Also, the web-site designer(s) and hoster(s) should also be liable if they were not (contractually) instructed to embed third-party content by default in breach of the GDPR.

The Register Javascript Not Required to Read the Register

AnAnonymousCanuck

Otherwise it would not be one of my favourite internet gossip sites :)

AAC

Fetch my cattle prod

Greybearded old scrote

It's about time the GDPR enforcement authorities began wielding the big stick over this. They have the power to fine offenders damn near into bankruptcy, depending on what their profit margins are like.

A few '4% of gross' headlines should concentrate minds quite nicely. Not against Google, but the lazy f...f...fornicators who feed their own customers to the damn creeps. Then we should see a nice riot. Or maybe a stampede.

Re: Fetch my cattle prod

alain williams

It's about time the GDPR enforcement authorities began wielding the big stick over this.

Well: let's do it then. All that it should take is a few of us complaining to the ICO (or whatever you have in your country) to get them looking into this. Unfortunately I suspect that a cattle prod will be needed to wake our supposed protectors out of their slumber.

Re: Fetch my cattle prod

DevOpsTimothyC

> a few THOUSAND of us complaining to the ICO

-- FTFY

I don't see why I should use it

Pascal Monett

I use NoScript. Anything that uses JS on a site I have not authorized is dead in the water.

Not impressed.

There's FAR more than that.

Anonymous Coward

There is a heck of a lot more tracking and data collection that that going on, not all very precise but enough to gather what is known as "atmospherics" - think of it as signalling trends. A simple example: fonts. Out of a 1000 Wordpress sites you may find 5 (and that's optimistic) which are not using themes side loading Google fonts, and Adobe runs a racket like that as well for professional designers (Adobe Typekit).

Going back to Google for a bit, their most audacious scam is asking people to install something from them to prevent being tracked by them..

msobkow

I find the bleating about "monitoring" most amusing. The web was never designed to be secure. Ever. It was designed with all the "security" possible when routing "calls" based on the callers and senders IP numbers: NONE.

But the ignorant masses keep thinking their wishful dreams can be made reality. The same kind of people that think you can legislate science and technology to make it bend to your will regardless of what reality has to say. *LOL*

We are all techies here...

Marty McFly

So I don't need to explain the value of each of these at avoiding tracking...

- Run a Pi-Hole. It is so cheap & easy, there is no reason not to. Shocking how much crap is coming from a home network, especially all the IoT devices. Just what is my SmartTV sharing when the input is set to HDMI1?

- Use a VPN. Some of them allow a DD-WRT router to make the tunnel - so one device license and everything else funnels through.

- Presearch.org I started using it two weeks ago. It is surprisingly good. Built on blockchain and is decentralized. So it is impossible for big tech's "Censorship Culture" to tamper with.

The Poems, all three hundred of them, may be summed up in one of their phrases:
"Let our thoughts be correct".
-- Confucius