|
|
Log in / Subscribe / Register

Security quotes of the week

Just two weeks ago, Belkin announced [plans] to shut down one of its cloud services, effectively transforming its several product lines of web cameras into useless bricks. Unlike other end-of-support announcements for IoT devices that (only) mean devices will never see an update again, many Belkin cameras simply refuse to work without the “cloud”. This is particularly disconcerting as many see cloud-based IoT as one possible solution to improve device security by easing the user maintenance effort through remote update capabilities.
Alexander Vetterl introduces a Light Blue Touchpaper "Three Paper Thursday" on IoT security

As soon as I saw their house I realized exactly what [the NSA's Richard] Ledgett said. I remember standing outside the house, looking into the dense forest for TEMPEST receivers. I didn't see any, which only told me they were well hidden. I assumed black-bag teams from various countries had been all over the house when they were out for dinner, and wondered what would have happened if teams from different countries bumped into each other. I assumed that all the countries Ledgett listed above -- plus the US and a few more -- had a full take of what Snowden gave the journalists. These journalists against those governments just wasn't a fair fight.
Bruce Schneier remembers visiting the house of Glenn Greenwald

As a refresher: the way targeted advertising works is that an advertiser agrees to place an ad and uses whatever system to target those ads to particular groupings of people, as set up by the ad platform. So, if you want to advertise to grumpy bloggers in their mid-40s, you can find a way to have those ads show to that demographic. But the advertiser doesn't get any data from the platform about anyone. The companies are selling access to highly targeted demographics, but it's never been selling data.

That doesn't mean there aren't other companies that do sell private data. There are. Lots of them. Data brokers, telcos, some ISPs, and even your local DMV have been caught selling your actual data. But for some reason, everyone wants to keep insisting that Google and Facebook also sell data, when they never have, and have always only sold targeted advertising in which the data only goes in one direction, and not back to the advertiser.

Mike Masnick

to post comments

Security quotes of the week

Posted May 21, 2020 5:19 UTC (Thu) by pjones (subscriber, #31722) [Link] (1 responses)

> The companies are selling access to highly targeted demographics, but it's never been selling data.
...
> But for some reason, everyone wants to keep insisting that Google and Facebook also sell data, when they never have, and have always only sold targeted advertising in which the data only goes in one direction, and not back to the advertiser.

This is completely at odds with all the facts we've learned about Facebook and Cambridge Analytica. Facebook absolutely did sell the data.

Security quotes of the week

Posted May 21, 2020 9:16 UTC (Thu) by farnz (subscriber, #17727) [Link]

That doesn't fit with what I've read about the Cambridge Analytica case; Facebook allowed CA access to badly thought through APIs, but CA then used those APIs with various "apps" to convince users to hand over access to data. It's just that the badly thought through APIs meant that while a user thought the app had one level of access, it in fact had a lot more access, including to data shared with you by friends.

Security quotes of the week

Posted May 21, 2020 9:27 UTC (Thu) by chatcannon (subscriber, #122400) [Link] (6 responses)

> [...], you can find a way to have those ads show to that demographic. But the advertiser doesn't get any data from the platform about anyone.

Those statements are mutually contradictory. The fact that a user's browser made an HTTP request for an ad that you targeted at a particular demographic tells the advertiser that (the ad platform believes that) the user is in that demographic. Furthermore, real-time bidding provides advertisers with the same information about users that don't even see their ads.

Security quotes of the week

Posted May 21, 2020 9:53 UTC (Thu) by farnz (subscriber, #17727) [Link]

They're not, they're just missing context. The ad is served from the platform's servers, not from the advertiser's servers, so all the advertiser gets to know is that the platform has billed them for the ad, but not which user saw the ad. Similar applies with real-time bidding - the advertiser knows that they won the slot, but nothing more about the user than is exposed via the platform anyway.

Security quotes of the week

Posted May 21, 2020 13:46 UTC (Thu) by jreiser (subscriber, #11027) [Link] (1 responses)

The advertiser might not have (access to) the log entry for the top-level page that is served by the platform, but the top-level page can contain links which reveal much if the user clicks on them. Clicking anywhere on the served page, when combined with the browser's unique ID for the end user who clicked, tells the advertiser quite a lot.

Security quotes of the week

Posted May 21, 2020 15:29 UTC (Thu) by farnz (subscriber, #17727) [Link]

In an ad platform that tries to maintain privacy, there are layers set up so that the ad is entirely served from the platform (nothing unvetted before it gets to the platform, so no arbitrary JavaScript, HTML etc in the ad), and a click on the ad "bounces" you through the ad platform, which can re-anonymise the end user in as far as that's possible with modern browsers.

So while the advertiser can profile the browser in use, they can't link that back to their ad spend directly, making it a statistical challenge to work out which users are in which demographics (as you've only got a timing side-channel, and that's a very slow one, especially since a good real time bidding system lets you "win" bids even when the advert is not shown, and then your monthly bill just includes the ones where the ad is shown).

Security quotes of the week

Posted May 21, 2020 18:26 UTC (Thu) by logang (subscriber, #127618) [Link] (2 responses)

I think the fact that Joe-Politician-Ad-Buyer isn't buying my specific data is far beyond the point. They are buying the benefit of the aggregate of my data collected by facebook and google, which is still harmful.

Facebook and Google have their fingers all over the internet so can sell my Ad view based on completely unrelated interactions between me an unrelated website. If NYT gets away from this and only bases their advertising on my interactions with them and their website, then I think this is a huge step in the right direction. Getting an Ad on NYT's site based on an article I read on that site seems perfectly reasonable. Getting an ad on NYTs site because I visited a product page on Amazon or because Facebook's algorithm thinks I'm about to get married or something horrible like that is creepy and awful. Keep data siloed and distributed.

The problem is that Facebook and Google are selling the consequences of having way to much of our data, not that they are selling the data itself.

Security quotes of the week

Posted May 22, 2020 21:24 UTC (Fri) by rgmoore (✭ supporter ✭, #75) [Link] (1 responses)

There's also an issue with who is getting rewarded. One of the things the advertising giants are doing is taking more and more of the value of placing ads for themselves rather than paying it to the creators of the sites where they're placing their ads.

Back in the days of print advertising, and even in the early days of the web, if you wanted to target your ads, you'd do it by finding a publication that was targeting the same people you were. If you wanted to sell to Linux geeks, you'd put your ads on Linux Weekly News. If you wanted to target shoppers in New York, you'd put your ads in the New York Times. Publications that catered to valuable customers or highly specific markets could get very high rates for their ad space because it targeted so well. Putting your car ad in Road and Track might be many times as valuable per reader compared to putting it in Time, since you were much more likely to be reaching someone who was specifically considering a car purchase.

The modern ad giants have undermined that linkage between publications, advertisers, and viewers. They can know who is a Linux geek, a New York shopper, or interested in buying a car no matter which site they're currently browsing. When someone wants to target one of those groups, they can target them anywhere. Because the targeting is being done by the ad network rather than the publication, the value of the targeting accrues to the ad network rather than the publisher, and the publisher gets less and less money for their ad space.

That's the real dynamic the New York Times is trying to fight, not the privacy based one. Eliminating trackers is about them trying to get the most value from your views rather than giving the value to Google or Facebook. I'm still happy with that outcome- I'd much rather publishers get the value for their publications rather than middle men- but it's not really about protecting your privacy.

Security quotes of the week

Posted May 24, 2020 10:39 UTC (Sun) by Wol (subscriber, #4433) [Link]

The problem is that as the ad giants take more and more of the revenue, there'll be fewer publications to draw in the punters. Without anywhere to place their ads, the ad giants are shooting themselves in the foot. That's something Google always got - don't pollute search results with adverts or your product will walk with their feet.

A similar rule applies here - don't kill your host or you'll die with it. Let's hope they realise it before the publishing industry collapses or goes subscription-only to survive.

Cheers,
Wol


Copyright © 2020, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds