Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm completely cool with ads; what I'd like to see is the ability to block analytics, for example one-pixel transparent gifs as well as javascript "sources" consisting of one character of whitespace.

I can do this with the hosts file but that requires that I jailbreak my device. Most are not going to want to do that.

I'm also concerned about "mobile analytics" in which SDKs are offered free of charge to app developers so they can determine how users operate their apps. However the data centers are quite costly to operate; _someone_ must be paying for all that.

I expect mobile analytics can be blocked in the hosts file as well but it isn't so straightforward to determine the hostnames to blackhole.



> The new Safari release brings Content Blocking Safari Extensions to iOS. Content Blocking gives your extensions a fast and efficient way to block cookies, images, resources, pop-ups, and other content.

It seems like this feature isn't really just "ad blocking", it's the ability to write any kind of blocking extension. So a plugin that blocks analytics should be pretty doable.


http://lwn.net/Articles/646339/

privacy.trackingprotection.enabled

Works on Firefox on desktop and Android.

Speeds up browsing 40% on particularly obnoxious sites.

(AdBlockPlus also works in Firefox Android.)


> I can do this with the hosts file but that requires that I jailbreak my device. Most are not going to want to do that.

Alternatively, VPN to a home router and filter all traffic there, for TV, desktops, laptops, mobile.


Do you find your browsing speeds increase when you do this? I ask because I'm assuming the page loads faster without the ads but it must be offset (to some extent) by the VPN connection. Also, can you link to any examples on setting this up on an Android device?


Here's an example: pfSense 2.1.5 (which can be run in a Xen VM) with Android, iOS, Windows and Linux clients, https://blog.andregasser.net/how-to-configure-ipsec-vpn-on-p...

I'm still setting this up so don't yet have field data on performance, but 4G LTE ping times are about double the latency of home broadband, http://blog.catchpoint.com/2014/01/15/theres-no-avoiding-net....


Filtering in this way does provide a significant speed hit if you choose to use your home router but nothing is stopping you from using a VPS instead.

For me the primary concern is privacy and security and using the always on VPN is the best way I've found to protect what I value.

Nothing gets out without my expressed consent, just the way I like it.


Are you using Android or iOS? There seems to be flakiness on iOS8 where the VPN gets disconnected during a change between WiFi and Cellular, or if the device is locked.


I'm using android.

The VPN can drop out when I change networks, but it reconnects in less than a single second under good conditions, and that's not an exaggeration. I use a plain ipsec xauth VPN.

Having tried both ipsec with l2tp and openvpn SSL VPN, ipsec is the only one I can get to reconnect in under a second. All the others take at least 5 seconds to complete a handshake.


You don't need to VPN. A DNS server works as well as a hosts file and is much faster than putting every request through your network.


Good point. VPN can be used to deliver the ad-blocking DNS server to multiple mobile devices, enabling access to VPN-hosted files while leaving most traffic on the cellular network.


Why do you think creators shouldn't be allowed to know how many people are reading their content?


Why do you think you need anything other than the HTTP server logs to find out that number?


> Why do you think you need anything other than the HTTP server logs to find out that number?

All server logs tell you is that some user agent loaded the page. They tell you absolutely nothing about whether that computer was actually a person, or if that person actually read the article.

I don't understand all the hate around analytics. Data is how better decisions are made.


>> All server logs tell you is that some user agent loaded the page. They tell you absolutely nothing about whether that computer was actually a person, or if that person actually read the article.

Why the hell should you get to know what I'm doing with data you've provided me?

I asked for a page, you sent it to me, our relationship is over until I decide to contact you again.


Tracking that kind of information is the worst kind of surveillance there is. You see it as profitable data, but lots of things are profitable or useful, and sometimes society sees things as going too far and those things get restricted or banned. Breaking into people's homes is useful, even if you don't take anything; this distinction is so significant that just the violation of someone's property was made into it's own, separate crime.

The problem is that technology has made the personal boundaries somewhat harder to define, and this is being made worse by the fact that there are a LOT of people that are ignorant about how that technology actually works and a lot of businesses that are finding it really profitable to take advantage of this ignorance. Analytics, for example.

Baring any specific contracts[1], the transaction that is implicit when someone clicks on a link is that their computer will request some other computer (identified by the host in the URL they clicked on), with the expectation that the other side may (or may not) send a document (or document-like thing) back in reply. Unfortunately - and unknown to most people - the technical nature of HTML and especially Javascript have made it easy to include 3rd parties into construction of the page, and for the transaction to continue FAR longer than the initial click+download. As part of that increase in scope, many people have now decided that they have some sort of right to this extension, a right to run Turing complete code on other people's CPUs, and a right for 3rd parties to be involved. None of that exists - we haven't signed a contract - and just because you found a technical trick that lets you accomplish this kind of surveillance doesn't mean you should do it, or that it is morally right.

Asking you for a page obviously consents to you knowing about that request. Logging information about people without their knowledge or consent makes you an overly-nosy neighbor at best, and a stalker that should face criminal charges at worst. The truth is probably somewhere in between those extremes.

Why does this matter? Because as you say - data is how decisions are made. Data wants to be aggregated and aggregated data is an attractive nuisance to people that want to exploit that data. Do you really want to have the fact that you spent N hours reading on some topic to be known whatever government we end up having in the future? Do you think your insurance companies are interested if you read various topics that interest them? There are incalculable potential problems with storing personal data, simply because we cannot predict what subset of that data will be problematic in the future. By logging data at all, you are creating this future - and that makes you an enemy of those of us that still value privacy. I suggest that your business model needs updating. Maybe it only requires being clever and finding a socially-responsible way to make those same decisions. Maybe some business models are pathological, and need to go away. I don't think those lines are perfectly clear yet, so I wish you luck should you choose to pursue a different path.

Oh, and because this is about analytics, that means Google in most cases. A single party. One would think the potential monopolistic issue would be enough to stop using their analytics services. Anyway, if you truly want to learn about what this backlash is about - which is a backlash against all aspects of "surveillance as a business model" - then I recommend watching the link I have posted here several times recently of Aral Balkan's recent talk[2], as he explains things in far more detail. If you have any sense of privacy left, it might just terrify you.

[1] if one side is highly ignorant of what the contract's consequences are, I consider that a contract made in bad faith

[2] https://projectbullrun.org/surveillance/2015/video-2015.html...


Stop conflating analytics with 3rd-party surveillance.

They're entirely separate issues.

Again: why should I, as the first party content creator, not be allowed to know how you engage with my content?


As many of us have said, it's fine to analyse server logs. Also, you have the burden of proof backwards. Why do you think it's ok to hide spying on what people do with your content. Again, at best this makes you a creepy/nosy neighbour. The book author gets to know that they sold a book, not how long it took you to read it.

You could consider this similar to the concept of "1st sale" - once you hand over data, it's the other parties business - and not yours - what they do with it. If you want further control over what the recipient does with your stuff, negotiate that up front in a contract. I recommended against that, because aggregation is dangerous.

As for 3rd parties, you know very well that "analytics" meas "google-analytics" to most people. Besides, one of my points was that you, an independent 3rd part, building up a database of what people have been reading is an attractive nuisance to governments with national security letters about PRISM. You are also creating a moral hazard where you will be tempted to sell that data, which has been the "monitizing" method of choice for a while now.

Are you saying you are not going to create any additional risk for your customers? That you won't misuse that data? (even though it is impossible to predict what "misuse" is) That you wouldn't sell your the list of what people have been reading to the government or an insurance company? Are you saying that you are willing to pull a LavaBit and shutdown your company and face whatever charges the government throws at you for doing so to prevent that data from leaking out? What about your security - data exfiltration is common.

No, you're not. Obviously. I wouldn't believe you even if you said yes. So the way to prevent this kind of risk is to make sure that the violations of personal privacy didn't happen in the first place.

Unfortunately, your salary probably depends on one a surveillance business model, so there it is unlikely that I will be able to convince you of much in this area.

// clearly you didn't watch that talk that I linked to...

[script]

Now that you have finished reading this comment, please reply with how long it took you to read, your current IP address, your browser's USER_AGENT (and any other interesting HTTP headers). You should have no problem doing so, as that is exactly what you're doing to others with analytics.

[/script]


> Besides, one of my points was that you, an independent 3rd part, building up a database of what people have been reading is an attractive nuisance to governments with national security letters about PRISM.

I am not a third party. In no world is the person who actually gave you the content a third party.

When you're on my website, you're in my theater. In my store. The idea that you shouldn't be monitored while doing so is ridiculous. A store owner doesn't need to negotiate a contract with everyone who visits to put up a camera.

[response] I spent approximately 2 minutes considering your comment and opened it twice.

My current IP address is 108.30.103.76.

Here are the headers you requested:

  accept:text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
  accept-encoding:gzip, deflate, sdch
  accept-language:en-US,en;q=0.8
  cache-control:no-cache
  pragma:no-cache
  user-agent:Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.124 Safari/537.36
  x-ua-device:tablet-ipad


> When you're on my website, you're in my theater. In my store. The idea that you shouldn't be monitored while doing so is ridiculous. A store owner doesn't need to negotiate a contract with everyone who visits to put up a camera.

That's a ridiculous analogy. I own the computer your content is being displayed on. I am not in your store--you are in my home.

You are like a traveling magazine salesman. I open my front door and you offer me a magazine sample. If I take it from your hand, close the door, and sit down to read it in my home, you are not authorized to come in through the back door and watch me, or walk through my yard and spy on me through a window. And do not complain if I put up curtains that prevent you from watching through binoculars from across the street. You are not entitled to access the inside of my home.

The model you propose is akin to a bait-and-switch. "Hey, want some free content? Great, enjoy! What, you want privacy in your home? Hey, you took the content, so I'm entitled to do whatever it takes to observe you consuming it." If you are not content with my having taken the content you offered, then do not offer it.


the analytics that concerns me is in fact 3rd-party surveillance.

I once attended a talk by three mobile analytics vendors; what they were promoting were _free_ SDKs that would enable me to log how my users actually used my iOS App - what screens they visited, what buttons they tapped and so on.

I thought that was quite cool and could see how it would enable me to design a better app.

What led to my increasingly growing concern is that their SDK is provided absolutely free of charge to mobile app developers, and that their service is backed by an entire data center.

Not just a box but thousands of machines. That costs a lot of money to equip to operate and to staff.

Given that the SDK is free to developers, someone has to be paying for all that data.

Our disconnect here is that you are in the position - on the web - of a mobile developer who wants to know what buttons get tapped.

My concern is that your use of analytics enables someone else, someone unknown to me, to purchase my behavioral profile.


"Data is how better decisions are made" is the problem, not the solution.


I'm completely cool with the analysis of one's own web server logs.

What I'm not cool with is Hacker News knowing that KindGirls is my favorite website of ill repute.

Consider the challenge faced by closeted homosexual presidential candidates.

Analytics is also used for credit scoring. That is, suppose I were to hang out at sites that covered asset protection, bankrupcy. There are all kinds of ways to beat debt collectors, most of them perfectly legal and while well-documented they are not well known.

Were I to apply for any manner of loan after hanging out at all these sites, my loan would not be approved.

If you don't believe me I can dig up the specific company that offers this "service" however not just now as it will take me some time to find it again.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: