csmp.week5.slides
csmp.week5.slides
cookies
recipe for
cookies...
see cookies!
• in chrome, open the console (windows = Ctril + Shift + C, mac = Cmd + Option + C) open
chrome dev tools • Application > Storage > Cookies and select a site View, add, edit, and delete
cookies
1
In 2021, Google’s ad revenues totalled US$209.49 billion worldwide, followed by Meta at
US$114.93 billion and
Amazon at US$31.16 billion. According to IAB Europe, already in 2016 behavioural targeting
accounted for 66 % of all digital advertising and contributed to 90 % of growth in digital
advertising. Unpacking ‘commercial surveillance’: The state of tracking - decent overview What is
Bidstream Data?
What is Cookie Syncing and How Does it Work?
2
included several segments relating to reproductive health, including some involving pregnancy
tests, contraceptives, and infertility.
Race and ethnicity showed up frequently among the demographic data targeted by the segments.
Some of the most colorfully described audience segments came from consumer credit agencies
Equifax and Experian. Segments are branded with alliterative names like “Silver Sophisticates” and
“Progressive Potpourri” that reflect the political and socioeconomic makeup of the household.
Some of these brand-name segments promise a package of economically stressed individuals to
target with names like “Struggling Elders” and “Tight Money.”
Consumers are packaged according to their location history and movements. Advertisers were
offered segments that appeared to target people based on where they shop, work, and visit,
including those who go to state capitol buildings, congressional offices, federal agency offices, and
locations like defense contractor and gun manufacturer headquarters.
tracking examples
Q. In pairs: can you think of examples of unethical tracking e.g. in terms of profiling,
advert targeting etc)?
med trackers
Study: Online trackers follow health site visitors
Unaccounted Privacy Violation: A Comparative Analysis of Persistent Identification ofUsers Across
Social Contexts
bbc story
UK councils’ benefits pages push credit card adverts
FOR SHARING: Council cookies
FOR SHARING: UK councils breakdown.xlsx
payday loans
Your Social Networking Credit Score. “Big data” can help determine who really deserves a loan. But
there are dangers.
• Wonga, an extremely ambitious online payday-lending company based in London, even
considers the time of the day and the way a candidate clicks around the site in determining
whether to grant a loan Wonga: What makes money lender tick?
• People borrow money from Wonga by applying on its website. This offers a swift decision and
then transfers the money into a bank account within 15 minutes.
• Its key feature is that it combines information about potential customers in a massive in-house
credit scoring operation. Errol Damelin said his computers use artificial-intelligence software
to collect and digest up to 8,000 different pieces of information about applicants to decide if
they should be offered loan
Wonga data breach ‘affects 245,000 UK customers’
Wonga goes into administration: The payday lender has been crippled by compensation claims
from customers as a result of irresponsible lending
Brightbeam
N.B. you might need to temporarily switch off adblockers if you have them installed
Brightbeam is a Firefox extension which allows you to visualise the 3rd party trackers and to export
the data. It was originally developed by Mozilla and has been adapted by the Digital Methods
Initiative.
Here’s the link to install the firefox brightbeam add-on (it will only install in firefox).
3
There’s a useful animated gif of how it works on the lightbeam github (although note that this is
the old version of Lightbeam, not Brightbeam). Basically it visualises the trackers as a network. In
this case, the circles are the
websites and the triangles are the trackers.
• play around, visit a few websites - you should quickly be able to see which sites have which
trackers (triangles) in common. You may be surprised by how many trackers there are on
some sites.
• look at a specific set of sites e.g. ones you regularly visit, or sites to do with a theme like
healthcare, or some other grouping
• see what you can establish in terms of the tracking that’s going on You can export the network
for gephi using Save Data (GDF)
themarkup / blacklight
Blacklight: A Real-Time Website Privacy
Inspector The High Privacy Cost of a “Free”
Website nested trackers examples -> good
journalistic stories!
canvas
fingerprinting key
loggers
4
tracker control
5
TrackerControl for Android
tracker control github
TC Slim (Google Play Store)
• export • traffic
exodus
• exodus db https://exodus-privacy.eu.org/en/
abortion data
• The Supreme Court’s decision last week overturning the nationwide right to an abortion in the
United States may have sent worried people flooding to Planned Parenthood’s website to learn
about nearby clinics or schedule services.
• But if they used the organization’s online scheduling tool, it appears Planned Parenthood could
share people’s location — and, in some cases, even the method of abortion they selected —
with big tech companies.
• An investigation by Lockdown Privacy, the maker of an app that blocks online tracking, found
that Planned Parenthood’s web scheduler can share information with a variety of third parties,
including Google, Facebook, TikTok and Hotjar, a tracking tool that says it helps companies
understand how customers behave. You scheduled an abortion. Planned Parenthood’s website
could tell Facebook. The organization left marketing trackers running on its scheduling pages
• The company selling the data is SafeGraph. SafeGraph ultimately obtains location data from
ordinary apps installed on peoples’ phones. Often app developers install code, called software
development kits (SDKs), into their apps that sends users’ location data to companies in
exchange for the developer receiving payment.
• Sometimes app users don’t know that their phone—be that via a prayer app, or a weather app
—is collecting and sending location data to third parties, let alone some of the more
dangerous use cases that Motherboard has reported on, including transferring data to U.S.
military contractors.
• Edwards said “SafeGraph is going to be the weapon of choice for anti-choice radicals
attempting to target
‘out of state clinics’ providing medical care.” Missouri is considering a law to make it illegal to
“aid or abet” abortions in other states.
Data Broker Is Selling Location Data of People Who Visit Abortion Clinics
• Google’s original promise, made in July 2022, came shortly after the supreme court’s decision
to end federal abortion protections. The tech giant said it would delete entries for locations
deemed “personal” or sensitive, including “medical facilities like counseling centers, domestic
violence shelters, and abortion clinics”.
• In four out of eight of the tests, the route to the Planned Parenthood was retained in the
device’s location history, though the name of the clinic was scrubbed.
• Police and law enforcement agencies have also made increasing use of a novel category of
search warrant called “reverse search warrants”. In that category are geofence location
warrants, which police use to come up with a list of suspects by seeking out information on all
users whose devices have been detected in a certain place at a certain time.
• Google announced that it planned to change the way it stored location history data for all
users in a way that could render responding to geofence warrants effectively impossible.
Google promised to delete location data on abortion clinic visits. It didn’t, study says
6
• A Muslim prayer app with over 98 million downloads is one of the apps connected to a wide-
ranging supply chain that sends ordinary people’s personal data to brokers, contractors, and
the military.
• Some companies obtain app location data through bidstream data, which is information
gathered from the real-time bidding that occurs when advertisers pay to insert their adverts
into peoples’ browsing sessions. Firms also often acquire the data from software development
kits (SDKs).
• The SDK then collects the app users’ location data and sends it to X-Mode; in return, X-Mode
pays the app developers a fee based on how many users each app has. An app with 50,000
daily active users in the U.S., for example, will earn the developer $1,500 a month, according
to X-Mode’s website.
• Motherboard used network analysis software to observe both the Android and iOS versions of
the Muslim Pro app sending granular location data to the X-Mode endpoint multiple times.
• The data transfer also included the name of the wifi network the phone was currently
collected to, a timestamp, and information about the phone such as its model, according to
Motherboard’s tests.
Leaked Location Data Shows Another Muslim Prayer App Tracking Users
• Salaat First (Prayer Times) is an app created to help Muslims with prayers; reminding them
when to pray, the position to take to face Mecca, and nearby mosques. For all that, the app
needs to access and identify users’ location.
Muslim prayer app Salaat First was tracking users
Muslim prayer app ‘sold users’ tracking data’ to contractor linked to US government agencies:
7
• Breaking up big tech (Google, Facebook etc)
• whistleblowers protection
real time bidding
example from OpenRTB
8
Using the Wayback Machine and Google Analytics to Uncover Disinformation Networks
week 5 - close