Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Google Analytics Opt-Out Browser Add-On (tools.google.com)
68 points by un_montagnard on March 25, 2019 | hide | past | favorite | 41 comments


Why not just respect the "do not track" header?


Because Microsoft made the dumb decision to turn it on by default in IE10, which instantly repelled every ad network that wanted to stay in business and destroyed any chance of it gaining a foothold.


People should stop blaming Microsoft for this.

The only reason ad networks were behind DNT in the first place was because they thought no one would use it and it would be a cheap way to divert attention away from legislation or technical solutions like adblockers. The moment there was any significant uptick in usage for any reason, there would have been a competitive motivation for the networks to abandon DNT.

On-by-default wasn't a problem because it was some kind of fundamental paradigm shift, it was a problem because it meant that the setting would actually be turned on for normal people.

If it were actually about Microsoft breaking a sacred contract or something, it would not have been difficult for ad networks to detect the IE10 agent string and apply browser-specific policies. But for the most part very few companies ever did, because if you're an ad network and you realize you can get away with ignoring privacy settings on one browser, why on earth wouldn't you do the same for every other browser?

DNT was doomed from the start specifically because it relied on advertisers voluntarily participating, and advertisers are never going to disrupt their own business model voluntarily.


> But for the most part very few companies ever did, because if you're an ad network and you realize you can get away with ignoring privacy settings on one browser, why on earth wouldn't you do the same for every other browser?

I see this as a reason to blame Microsoft.

While some point companies would have tried to abandon it anyway if it got popular, there would actually be some barriers to doing that if it was already established. It also would have been easier to add legal teeth after showing the system worked. The IE thing killed it in a fragile early state so we got nothing.


It's not that I disagree that a more robust, established standard would have been more resistant to this attack, I just don't think that you can build a robust, established standard without first getting people to use it. I disagree that there was ever any possibility, Microsoft or not, that this was ever going to turn into something with teeth.

To get to the point where DNT would reasonably be called a widespread standard, people would need to use it. And as soon as people started to use it, ad networks would come up with an excuse to ignore it. My feeling is that Microsoft just happened to be that excuse.

On a more optimistic note, I do think we got a few things out of DNT. We learned a valuable lesson about self-regulation -- so nowadays, Safari and Firefox aren't asking anyone's permission to block trackers and fingerprinting and they're doing it in ways that advertisers can't just decide to ignore.

DNT is valuable in the sense that it's what we can point to when advertisers complain that they don't have a seat at the table anymore.


Let's be real here - privacy by default is how it should be. It would behoove all of us to stop blaming the victims here, which are the people being gently squeezed for all the information possible. Having that header on by default was the sane and reasonable choice.


On or off by default, the header is useless. Including a tracking blocker without any "acceptable tracking" list would be sane. It would have been even more sane if iframes and third-party resources were never allowed by browsers, but that ship has sailed.


>Including a tracking blocker without any "acceptable tracking" list would be sane.

Any reason this hasn't been up to the authors of the draft[0] to address that? Comments on a forum are likely to do nil.

[0] - https://tools.ietf.org/html/draft-mayer-do-not-track-00#page...


Blaming Microsoft is not blaming the victims.


It comes very close, the rhetoric wouldn't be much different if the majority of users turned the option on themselves (for whatever reason).


Yeah how foolish of them to think that people don’t want to be tracked in their browser.


Do you really think that the trillion dollar advertising industry will respect your privacy? They will do whatever they can get away with.


Running uBlock on Firefox.


Remember also to use advanced mode and block other Google domains, like google fonts, youtube, ajax apis etc.


or you can go to uMatrix.

Use decentraleyes to prevent common libraries (like Google ajax) from tracking you across sites.


AFAIK Google Analytics doesn’t collect PII or aggregate that data in any way... or am I wrong?


Not necessarily, but it still does grab a huge amount of data. Internet provider, device, session time, pages navigated during session and even ways to segment users across devices, using that data for testing or ad targeting. Not to mention I was able to unintentionally identify my neighbour browsing on one of my client’s sites using those metrics.


It definitely collects them, as in Google is receiving that information. And just because they don’t show it to you doesn’t mean it’s not used internally in some subtle, undetectable-from-the-outside way (given their bottom line is directly linked to how well they can stalk everyone online to serve them ads).


Whether this is true or not depends on two things:

1. Your definition of PII. PII is defined in legislation in some states/countries, whereas other terms are used elsewhere. Some definitions are very loose, whereas for example, the EU definition of a close/equivalent (simply referred to as "personal data") is extremely strict (some might say too strict). If we take the EU definition, GA definitely collects "personal data" as it is 100% required to provide dashboard data on "unique visits".

2. Even if you take a looser definition of PII, by which Google could potentially provide all GA dashboard features without collecting any PII, you are still giving Google direct access to PII, and explicitly sending them some PII in some situations. So in this case, you're relying on your trust of Google's internal company policies on not storing that data that they receive. Given their track record in compliance with the law on data collection, there is very little reason to trust them.


Do extensions like uBlock Origin and Privacy Badger already accomplish this?


Yes. And perhaps I'm cynical in my old age but if I were Google, I would prefer that people used my extension so I could more easily line-up their browsing habits.


Yes. This is just the officially sanctioned way.


What about all of Google's other trackable properties like googleapis, fonts, and 1e100?


google tag manager, google DMP, doubleclick?


...recaptcha, adwords, youtube embeds, the Chrome permanent login and a dozen others?

Simple, they‘re being used to restore the main cookie. Stuff like this, just as the Chrome adblocker, are just a fig leave for plausible deniability. If you want reasonable protection, use Safari or Firefox with that Origin adblocker and the Multi-Container plugin against first-party tracking.


Last Updated: October 2, 2014


It really doesn't need to be updated, it's setting a simple variable that the script looks for to short circuit.



Running Pi-hole on a RaspberryPi. Game over.


Except on the off chance you leave the house.


Ublock Origin on Firefox mobile does the job.


Surprise! It doesn't work on Chrome mobile.


Chrome mobile doesn't support any extensions.


Firefox mobile does.


Which is why it's my main browser on Android. It's really nice.


Is there a way to still opt out on mobile?


Use Firefox, it supports extetensions.


Honestly just classic Google..


I feel like this is related to GDPR but in my opinion it doesn't follow the spirit of the law.


It doesn't even follow the letter.


unlikely since it was last updated in 2014 :p

*edit: according to another comment someone else posted




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: