即将进入您网页浏览器的广告卡特尔
The advertising cartel coming to your web browser

原始链接: https://blog.zgp.org/the-advertising-cartel-coming-to-your-web-browser/

包括 Meta、Google 和 Apple 在内的主要科技公司正合作开发一种名为“Attribution Level 1”的浏览器广告衡量系统,旨在将广告展示与用户购买行为关联起来。尽管该系统被包装为一种使用聚合数据而非个人追踪的隐私保护工具,但批评者认为该提案存在根本性缺陷。 该系统缺乏选择加入(opt-in)的同意机制,且通过人为偏向搜索、社交媒体和应用商店广告,进一步巩固了大型科技公司的市场主导地位。由于该标准优先考虑“漏斗底端”的转化广告而非品牌建设内容,这可能会导致收入从独立网站和新闻机构流失,从而造成社会损害。此外,该系统还忽略了环境影响和数字主权等更广泛的问题。 作者主张,隐私是一个无法通过个人设置来管理的集体性问题。由于这些公司实际上是通过技术标准在为自身利益进行游说,因此该提案应当被叫停。如果项目继续推进,用户至少必须保留通过浏览器插件管理或阻止此类追踪的权利。归根结底,这个“归因卡特尔”是一个借技术创新之名,行破坏竞争与隐私之实的利己机制。

此 Hacker News 讨论帖探讨了一篇批评新型浏览器广告归因标准(如 Attribution Reporting)的博文。 讨论主要集中在三个观点: * **对批评的质疑:** 有评论者认为,该博文本质上是对广告归因本身的变相批评,而非针对新型隐私浏览器标准的具体问题。 * **“行业垄断”的担忧:** 另一位参与者指出,当谷歌、Meta 和苹果等科技巨头在“隐私”倡议上合作时,用户应保持警惕,因为这很可能是在维护行业利益而非消费者利益。 * **技术影响:** 一位用户解释了该新系统的运行机制,将其比作传统 HTTP Cookie 的改进版——浏览器充当了跨站点跟踪广告展示并为广告商生成转化报告的中心存储库,这可能会进一步加剧跟踪的中心化。 总体而言,评论者对于这些新的浏览器标准是真正的隐私改进,还是大科技平台在隐私幌子下维持归因权力的更高级手段,存在分歧。
相关文章

原文

When Meta, Google and Apple agree on a “privacy” feature, watch out.

The three companies (along with Mozilla, which is on one of their “ad features in the browser” kicks again) are drawing up a built-in advertising measurement system, called Attribution Level 1, as a standard feature of web browsers. The system is intended to measure the effectiveness of advertising by enabling advertisers to correlate “impressions,” the occasions on which someone saw an ad, with “conversions,” when people bought something.

Don’t look for a section on permissions or consent in that document, by the way. There isn’t one. And nothing about nerd lawyer stuff like “opt out of sale” or “objections to processing” in there, either. The Big Tech companies want a two-track system, where other companies’ ad features are required to do all the privacy regulation hassles, but the browser’s own built-in tracking feature is something that people have to find the right setting for and turn off.

Unfortunately, this is not just a chapter in Big Tech’s ongoing antitrust saga. The attribution cartel is on track to perpetrate real harms to users, including:

  • Built-in advantage for search, social, and app store advertising: More money for Big Tech, less for legit sites and other ad-supported resources.

  • Added incentives for riskier tracking: Obfuscating the source of a sale makes it easier to get a payoff from tracking practices that would be seen as problematic on their own.

Those consequences are unavoidable because of the proposal’s narrow, mathematical privacy goals, which are a mismatch for the kinds of privacy harms that people experience in the real world. In the “Privacy Considerations” section, the proposal says,

The main privacy goal of this API is to ensure that providing sites with the ability to perform attribution does not improve their ability to perform cross-site recognition.

The system is supposed to produce aggregated measurements while making it prohibitively difficult for an advertiser to discover whether any one person who bought something is the same person who saw an ad. Technically, the way it works is that a script running on a site with ads asks the browser to record an ad impression. Then the browser keeps a record of ads seen from all the sites you visit. Later, when you buy something, the retail site can ask the browser to generate a “conversion report” that can be passed to a centralized aggregation service. The aggregation service can then give the site some aggregated results, in a way that does not reveal whether any individual who bought something ever saw a particular ad or visited a particular site.

So why are the same companies that are notorious for tracking people so fired up about it? The problem is that the attribution tracking won’t be functioning in isolation. It has to interact with other technologies and business models. Even if the browser developers can pull off their ambitious goal of preventing “cross-site recognition,” the proposal would make life worse on the real Internet.

Problem one: Over-rating search, social, and app store ads

Marketing data expert Rick Bruner explained this best.

Lower-funnel media naturally appear more effective because they intercept demand after it has already been created elsewhere. Search is the classic example. Brand advertising may create the demand, but the search click gets the attribution credit because it occurs closest to the sale.

And the shift isn’t just a matter of a Big Tech squeeze on smaller companies, or an oligopoly tax on everything you buy. The attribution cartel threatens us as citizens, too. Many advertising-supported media have positive externalities—they benefit even people who don’t use them. Corruption thrives where newspapers shut down. Meanwhile, the negative externalities of Big Tech are too numerous or too content-warning-worthy to list here. The average person in the USA has about $1200/year spent on advertising intended to reach them. Where do you want “your” $1200 spent?

So can’t I just turn it off?

Privacy is a collective problem, not an individual one. Attribution cartel reports will end up filtered through friendly academics and presented at every privacy law hearing at every state legislature in the land—look how small businesses depend on Big Tech to make sales, you shouldn’t regulate us. Even though professional marketers already know the attribution cartel is offering “little better than voodoo” and “just a surface for the media sellers to commit fraud”, professional marketers won’t always be in the loop. Lobbying dirty tricks are a thing, and every browser running this system will act as a little lobbyist for Big Tech.

This post is already getting too long, so I won’t cover all the extra problems besides the big two.

  • There’s no estimate of the environmental impact of all the extra processing. For people trying to use the web responsibly, and for marketing departments tracking their carbon footprint, that’s a big omission.

  • Centralizing on a few big companies in the USA is going the opposite direction from the toward digital sovereignty. (It is the World Wide Web.)

What to do about it?

It’s time to stop. Give the authors some recognition for their mathematical achievement—some of the ideas might be useful elsewhere, maybe forecasting energy demand without revealing who’s home—and then archive this thing. None of this stuff is inevitable. Even Google was able to shut down the similar “Privacy Sandbox” project when it got too much regulator attention. By now W3C should have learned the lesson that all those boring “competition policy” slides and meeting announcements at groups like the Linux Foundation, Interactive Advertising Bureau, and Institute of Electrical and Electronics Engineers are there for a reason. If you try to YOLO the antitrust bureaucracy, big companies doing forum shopping will take advantage. Say what you want about the lysine price-fixing conspiracy, at least they booked their own meeting rooms and didn’t use an existing organization.

Back when commercial open source was first booming, and corporate sponsorship of community events was a big thing, there were quite a few open bars at all-ages events. Events managers quietly started coming into compliance with the alcohol laws before any consequences made the news, and W3C still has the opportunity to do the same. Cutting off surveillance oligarchs from colluding might be a little harder than cutting off some overserved teen hackers from the adult beverages, but the principle is the same.

Worst case, if the attribution cartel does get its way, at least add the functionality to allow attribution tracking to be managed by extensions the way that all the other ad stuff is. A majority of people in the USA use an ad blocker now, and the number one reason is now privacy, not annoyance. Users who have been told that they can protect themselves by installing Privacy Badger, or uBlock Origin with the right filter lists, should not have that advice rendered invalid on a technicality.

Most of the articles about this kind of stuff are structured as a Feedback sandwich: an introduction about how great it is that some big company is doing something for privacy, the actual content of the article, and then a positive conclusion about how we can all work together on future privacy projects. But I’m not getting paid for this, this is my personal blog, and scam culture is everywhere, so that’s all for now.

联系我们 contact @ memedata.com