Thought you'd opted out of online tracking? Think again
- Reference: 1677828067
- News link: https://www.theregister.co.uk/2023/03/03/online_privacy_tracking/
- Source link:
Legal frameworks like Europe's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) require websites and associated third parties to get consent before collecting and processing personal data.
To help website operators comply with that requirement, vendors like Didomi, Quantcast, OneTrust, and Usercentrics offer what's known as a consent management platform (CMP).
[1]
These firms provide software that websites use to prompt visitors to accept or reject cookies in order to control how personal information gets handled. They claim their respective CMPs allow companies to comply with privacy laws in the US, EU, UK, Brazil, South Africa, Singapore, and elsewhere.
[2]
[3]
As Germany-based Usercentrics [4]puts it : "Surveillance on the internet is real and pervasive – using a consent management platform can make your website a safe private space."
Yet computer scientists Zengrui Liu (Texas A&M University), Umar Iqbal (University of Washington), and Nitesh Saxena (Texas A&M University) devised an auditing mechanism to test the effectiveness of CMP-based opt-out controls and found these platforms don't necessarily ensure compliance with GDPR and CCPA requirements.
[5]
They describe their findings in [6]a paper [PDF] titled "Opted Out, Yet Tracked: Are Regulations Enough to Protect Your Privacy?"
Spoiler alert: No.
"Our results indicate that in many cases user data is unfortunately still being collected, processed, and shared even when users opt out," the researchers state in their paper. "Our findings suggest that several prominent advertisers might be in potential violation of GDPR and CCPA."
In many cases user data is unfortunately still being collected, processed, and shared even when users opt out
Opt-out under the law thus is not all that different from " [7]Do Not Track " – a web specification that allowed browser users to declare the desire not to be tracked, without any consequences for ignoring that preference.
The researchers devised a way to audit opt-out compliance using [8]OpenWPM , an open source web privacy measurement framework. The process involved visiting the top 50 websites in 16 different interest categories (computers, news, sports and so on) to simulate user interest personas.
[9]
They focused on top websites that support both header bidding through prebid.js and opting out using CMPs from Didomi, Quantcast, OneTrust, and Usercentrics (CookieBot) tuned for GDPR and CCPA compliance.
[10]Meta faces lawsuit to stop 'surveillance advertising'
[11]Google dumps interest-based ad system for another interest-based ad system
[12]Data tracking poses a 'national security risk' FTC told
[13]Apple iOS privacy clampdown 'did little' to reduce tracking
Header bidding – a technology Google [14]allegedly tried to kill – is a way for publishers to auction their ad inventory to multiple ad exchanges, known as Supply-Side Platforms (or SSPs), before passing the winning bid on to an ad server like Google Ad Manager. And since header bidding via prebid.js occurs on the client, the researchers were able to intercept and analyze related client-side transactions.
To check whether their opt-outs were being respected, the boffins visited their set of websites with user interest personas (expecting higher bids for ads targeted at those interests) and a control persona – a blank browser profile. They collected bids and network requests from advertisers for both opt-in and opt-out settings, then analyzed the results.
In theory, opting out should reduce advertiser bids to a level comparable to the blank control persona in terms of data usage, client-side data sharing, and server-side data sharing. Alas, that often was not the case.
The leaked user interests are used to target ads to users, despite users' consent to opt out of processing of data as part of the regulations
"Overall we note that under CMPs most personas receive higher bids compared to control when users opt out of data processing and selling under GDPR and CCPA," the researchers observe. "The variability in bid values, particularly higher bids as compared to control, indicates that the leaked user interests are used to target ads to users, despite users' consent to opt out of processing of data as part of the regulations."
The boffins also observe that the opt-out results are not statistically different from opt-in, which they interpret to mean that user content largely has no effect on the processing and selling of data.
However, they do note that some CMPS appear to convey consent more effectively – specifically Didomi.
OneTrust and Usercentrics did not immediately respond to a request for comment.
"Our findings in general cast a serious doubt on the effectiveness of regulations as a sole means of privacy protection," the researchers conclude. "Specifically, even after users opt out through CMPs, their data may still be used and shared by advertisers. Unfortunately, in order to fully protect privacy, users still need to rely on privacy-enhancing tools, such as ad/tracker blocking browser extensions and privacy-focused browsers (e.g., Brave Browser)."
Yet this is asking too much of internet users, the researchers argue. Regulators need to step up enforcement and work on detecting law violations at scale. ®
Get our [15]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZAHTVQZl0KwMVxSH2T70jgAAANQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZAHTVQZl0KwMVxSH2T70jgAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZAHTVQZl0KwMVxSH2T70jgAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.cookiebot.com/en/consent-management-platform-cmp-cookiebot-cmp/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZAHTVQZl0KwMVxSH2T70jgAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://arxiv.org/abs/2202.00885
[7] https://www.theregister.com/2020/10/10/global_privacy_control/
[8] https://github.com/openwpm/OpenWPM
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZAHTVQZl0KwMVxSH2T70jgAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2022/11/23/meta_surveillance_advertising_high_court/
[11] https://www.theregister.com/2022/01/26/google_floc_topics/
[12] https://www.theregister.com/2022/09/09/data_tracking_national_security_risk/
[13] https://www.theregister.com/2022/04/08/apple_ios_privacy/
[14] https://www.theregister.com/2023/01/24/doj_google_ad_monopoly_antitrust/
[15] https://whitepapers.theregister.com/
pihole, uBlock, NoScript, Privacy Badger, Clean URLs and about:config.
Pihole in particular is invaluable - instant ad blocking for just about every device on the network.
Although remember to turn off Firefox's $%@#! DNS-over-HTTPS which if you're not paying attention will helpfully bypass your Pi-hole.
I did say about:config, right?
For those who don't know where to look in about:config.
Go to Settings, under General Settings scroll right to the bottom and click the 'Settings...' button under Network Settings', DNS over HTTPS is on the bottom of the panel that pops up.
well, I use AdGuard Home instead of pihole, it has to be ublock origin, not ublock, and NoScript is in the past for me, I did use the (imo) better umatrix for some time, but now I don't bother.. too much micro management. Throw a dressing of "I still don't care about cookies" on top, and you've got yourself a nice internet experience. (if you use YouTube, don't forget SponsorBlock)
If someone could update the pihole with a sort of an admin option where you could make it substitute the ads with your own content.
Imagine being able to run a campaign between 5pm to 7pm with "Wash the dishes" message seen everywhere someone at home is browsing the internet.
I can't say I'm surprised.
A related element, which continues to baffle me, is the concept of "Legitimate Interest", which you can find all over websites in these consent management systems.
Some times allowing you to nicely decline all these with one button, other times requiring you to scroll through and click every single one of the pre-ticked boxes (at this point of course, you just leave the website), of which I can say I've seen at least 50 on one website alone. And then you press the "Accept all" button by mistake, and now good luck navigating to the consent management system hidden somewhere on the page.
I have no idea what differentiates Legitimate Interest from the general consent-requiring cookies, but surely since it doesn't require active opt-in, surely it can't really be that bad. Surely their legitimate interests run in perfect parallel to my own?
Its difficult because legitimate interest is supposed to cover things like an online retailer providing your name and address to a logistics provider so they can ship a package to you (or just provide a quote), or you consenting to your details being shared with stripe or Shopify for a small retail site. However, as you suggest, an advertiser has a legitimate interest in advertising to you from their own perspective (they aren't pretending that they want to advertise to you, so legitimate is the correct word to describe their interest).
They have a legitimate interest in selling you out to anyone with cash.
And woe betide you if they catch you alone in a dark alley when the kidney transplant market is especially hot.
That's because the prison terms for repeat offenders and global fines aren't high enough for the CEOs yet.
cookies irrelevant
Even though cookies were the most accurate way of tying an ID to sites and adverts, what happens now instead is that every click-through and site visit is tagged with your ID and those clicks are themselves sent to analytical aggregators that use probabilities to tie your social media ID. The cookie laws are irrelevant and simply bypassed.
And yes - the way the opt in/out panes work is a simple logical OR of Allow or Legitimate Interest for you to be tracked.
Some of these opt-in/out tracking panes refer to a long list of 3rd parties who you have no direct control over whether they track you or not.
These analytical aggregators have strict NDAs with the social and search giants so they cannot publicise what they do.
As the researchers found out, the companies are complying with the letter of the law but not the spirit and in some case not even the former, through outsourcing of tracking under NDA and other contractual terms that keep them free from direct accusation of non-compliance.
Consent management is bollocks
The law says that opt-out is the default. Therefore, website owners may not collect data, including opt-out preferences without user's consent. "Consent management platforms" break this contract, not surprising considering that they act as aggregators.
The non personalised ads .
.. is complete bollocks as well.
All mine are set to off, including my phone
Add a REALLY obscure band of the 90s to my Spotify playlist (Sheep On Drugs if you're wondering).
Two days later they appear in my FB feed, despite nothing I follow in anyway relates to an obscure no hit wonder band
So as a test,I added sk8ter boi by Avril Lavigne. Again no way related to Sheep in Drugs or any other band I listen to.....it took a week for her to pop in my Instagram.
Re: The non personalised ads .
You do realise you are now testing El Reg as well, since you just mentioned the bands here? Sneaky.
Re: The non personalised ads .
You have no sympathy for using services that boast proudly of how they trade personal data.
How much is my adblocker costing advertisers?
Can somebody give some idea of how much each advert is being hawked for?
The answer to issues like this is encredibly simple
Fine the transgressors of laws/regulations with a percentage of their revenue.
There isn't a company on earth that will not pay attention to that. If you fine based on their profits then they just shuffle money around in their accounting statements. If you give a fixed fine, it's unfair to the small guys and pocket change to the big guys.
If you fine 1% of their annual revenue these transgressions will disappear overnight.
Finland has done it for decades with traffic fines. It works incredibly well.
"header bidding via prebid.js"
So all this tracking is done via JavaScript ?
Well then, once again NoScript to the rescue.
Why am I not surprised ?
Envelopes
People need to understand that GDPR wasn't created to offer better privacy or to protect user personal data.
First we had the Cookie Law that trained people into clicking consent boxes without reading.
Then we had a GDPR where people who are already trained into clicking boxes without reading consent to processing their data.
Now big corporations have personal data that they can legitimately process and sell and before the GDPR it was a grey area.
I'm shocked. Who can you trust?
/s