• BlackRoseAmongThorns@slrpnk.net
      link
      fedilink
      English
      arrow-up
      1
      ·
      60 minutes ago

      No, websites use CSS for styling and layout, basically how elements should look, behave and how they are placed in relation to each other, CSS can query the browser for screen width and adjust the view in real time.

      As a result, if you resize your browser, it may switch to a taller display style, which is what you want on mobile devices.

      Note: there are many reasons you wouldn’t want to check for device type, this is why display width is used.

  • UnLocoPoco@lemmy.world
    link
    fedilink
    English
    arrow-up
    17
    ·
    8 hours ago

    Another version being used on some news websites (forgot the names) - do you want us to track you or not?

    Me: No

    Website: Fair enough. Pay us 5 dollars in order for us to not track you. OR allow us to track you and you can get access to the article for free

    • sunbytes@lemmy.world
      link
      fedilink
      English
      arrow-up
      27
      ·
      8 hours ago

      I just don’t believe that they will stop trying to track me, no matter how much i pay.

      In fact, the more i pay, the more valuable i am.

      Because the details of a rich sucker are very high value.

      • UnLocoPoco@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        7 hours ago

        True. Same goes for “ad free” streaming platform subscriptions. These days literally almost every streaming platform has introduced additional charges for advert removal even for the top tier plans

      • percent@infosec.pub
        link
        fedilink
        English
        arrow-up
        2
        ·
        8 hours ago

        Yeahhh that sucks that we’ve reached this point. I would actually consider paying some sites for my privacy. If they offer something that I value, then it’s fair for them to be compensated somehow. However, if they offered that option, I still probably wouldn’t trust it.

        Even if the site itself fully intends to stand by their offer, can I trust the payment processor(s), bank(s), etc. involved in the transaction?

        I’m not really a crypto guy, but I wish something like Monero (or whatever privacy-protecting alternative that might be “better” these days) could become more mainstream.

        • Don_alForno@feddit.org
          link
          fedilink
          English
          arrow-up
          4
          ·
          5 hours ago

          When this kind of extortion model started, for a number of german news outlets it was actually proven that they wouldn’t stop tracking, just reduce it.

  • Dale@lemmy.world
    link
    fedilink
    English
    arrow-up
    18
    ·
    10 hours ago

    “We value your privacy” (as a commodity that we can legally sell with or without your permission. Do you want to download tracking cookies now or should we play coy?)

  • Hawk@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    28
    ·
    12 hours ago

    We tested software at work once.

    It would show who visited your website, their socials, their phone number, e-mail and company they work for. You could also open a video that would show their mouse movement and clicks.

    All by clicking accept.

    And all of this assumes they even show that accept button properly. With all the vibe coders, I wouldn’t even trust the button to do anything at all.

    The web is just fucked. Not leaking your fingerprint sounds like an impossible task to me.

    • percent@infosec.pub
      link
      fedilink
      English
      arrow-up
      4
      ·
      7 hours ago

      Yep. It’s also interesting to see teams have conversations about implementing these things without anyone mentioning how creepy it seems. I guess these things are just normalized now :/

      • ricecake@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        5
        ·
        5 hours ago

        Entirely depends on the group. I’ve been in meetings with developers where we agreed it was creepy and pushed back. I’ve also been in meetings with marketing where they said it was normal, and meetings with others who said it was the cost the user paid to use our website. Ignoring of course that we sold stuff on the website, and that part of it was a management system that the users actually paid us money to use.

        They stopped giving me those projects, which was a win for me but arguably a loss for the users.

        I did though for a bit convince people that it was worthwhile to fix the accept/reject not working right, but that it wasn’t a top priority to fix the reject button disabling tracking for all users of the site for the duration of the cookie. (Cookie stored “be creepy” flag. When the user clicked the button it stored a flag in the session so we could statistics, and then read the flag to set the cookie. Someone used the wrong session value and stuck it in the global store used to cache sitewide data, so when it went to see if they opted out it would see if anyone had in the last month. They fixed it after the data was all fucky for a few months and they realized my argument of “who would opt out? It’s just the way the Internet works” was extremely wrong and no one will ever complain about being opted out of tracking)

  • Tja@programming.dev
    link
    fedilink
    English
    arrow-up
    19
    arrow-down
    5
    ·
    15 hours ago

    This is created by someone who has no idea about websites, for an audience who has no idea about websites.

    You don’t need cookies, trackers or any personal data to detect an adblocker.

    It’s like accusing a store of spying for putting anti-theft gizmos on the merchandise.

    • merc@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      5
      ·
      7 hours ago

      It’s like accusing a store of spying for putting anti-theft gizmos on the merchandise.

      More like if you’re trying to see how something fits and the anti-theft gizmo is getting in the way, so you try to move it off to the side. Then you hear a voice over the PA system asking you not to fiddle with the anti-theft device.

    • nibbler@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      5
      ·
      13 hours ago

      Of course it’s spying. Site dishes out an ad-link and observes if it gets loaded (can be done server side). That’s the easiest way that comes to my mind. I’d say closely monitoring the behavior of your customers is spying. Especially as the customer does not know that/if he is being monitored in this way.

      Putting “anti theft gizmos” in a store is also spying, at least if you mean cameras and not a locked cabinet for valuable goods.

      The question is, if we agree that the other party has the right to spy on their users, and if/how the users have to be informed. Here stores have to announce video surveillance with a sign to anyone who enters.

      • ricecake@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 hours ago

        Eh, “did you ask to download something” is about the line where I would draw acceptability. You cannot use a website without them knowing if you made a download request for the content so I’m not bothered by them paying attention to the data to see what I downloaded.
        It’s when you start sharing the data with others, or using that data from others, or adding things to collect information and send it back that I mind.

        If someone did everything on the up and up, they would see my browser request, information that says what it can do that the browser opts to send, and a cookie that identifies the browsing session.
        I’m fine with that because I can clear it or change it at will, and without sharing anything the capability information is less useful than the session cookie.

      • neatchee@piefed.social
        link
        fedilink
        English
        arrow-up
        7
        ·
        12 hours ago

        This is pretty much never done server-side. It would unnecessarily increase server load by requiring callbacks and/or polling. It’s always done in JavaScript or, for really simple setups, CSS.

        Nobody running ads is considering users who block JavaScript wholesale. Not only is it a trivially small percentage of users, but it’s also a waste of time: those users aren’t going to stop blocking JavaScript to display ads anyway. Instead, they’ll just make it so the site fails to render at all if JavaScript is disabled.

        You’ve presented a solution looking for a problem.

        As for anti theft gizmos, they’re talking about the alarm tags and ink packs that get attached to merchandise so it sets of an alarm when you try to leave with it, or the item is covered in ink when you forcibly remove the security tag. These are passive anti-theft security and do not constitute spying.

        Even if we were talking about video cameras, it’s unreasonable to call that “spying”. In order for something to be spying you need an expectation of privacy, which is not present when you’re inside a private business. It would be like calling a security who observes customers a spy. It’s absurd.

      • FishFace@piefed.social
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        2
        ·
        13 hours ago

        It’s far easier to do this all client side. It’s it spotting to detect when a resource load fails and log to the console?

        Spying implies that someone, or at least some process, is watching me and my behaviour. But there is more to it, because that just describes a site working.

        • nibbler@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          3
          ·
          13 hours ago

          but client side requires the client to cooperate. and the client is regularly not under your control.

          I can’t make sense of your second sentence.

          • FishFace@piefed.social
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            1
            ·
            12 hours ago

            The client needs to “cooperate” to do anything, including showing whatever it is says “please don’t block our ads :'(”

            I mean that merely observing behaviour is not spying, because that covers any interaction. So what makes this spying?

                • bedwyr@piefed.ca
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  8 hours ago

                  I am saying we already know they are all spying. So while this humour might not quite fit, it’s still just one step removed.

          • MoonRaven@feddit.nl
            link
            fedilink
            English
            arrow-up
            3
            ·
            12 hours ago

            Unless you’re blocking Javascript, they have control to see what elements are loaded.

      • Tja@programming.dev
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        2
        ·
        12 hours ago

        There’s rfid stuck to merchandise that makes an alarm go off when you exit without paying. Just like the HTML elements that are loaded or not loaded. No spying.

  • bedwyr@piefed.ca
    link
    fedilink
    English
    arrow-up
    3
    ·
    11 hours ago

    ublockorigin blocks the content and leaves them unable to see that you are using it.

    Pretty sure you can still download it directly from their website.

      • bedwyr@piefed.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 hours ago

        Yes, what could stop this fingerprinting, I know firefox has a vpn built in now, not quite sure how much that helps.

        When I use Tor cloudflare hassles me incessantly back on firefox.

    • Killer@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      8 hours ago

      Are you sure about that? I only use ublock origin and still get “can you not block our ads” popups sometimes

      • Final Remix@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        8 hours ago

        Update your filters, and/or couple it with uMatrix for extra fuckery.

        Can’t bitch about my use of an adblocker if I also block your fuckin’ scripts.

      • bedwyr@piefed.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 hours ago

        Huh, really? Idk. I don’t see any, like at all. I am on firefox, it works better with that browser I read tell.

  • stoy@lemmy.zip
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    2
    ·
    16 hours ago

    I have said it before and I’ll way it again, an adblocker has gone from simply being a nuisance blocker to being an essential tool for not only privacy but also security.

    My counterpoint to any website whining about you blocking their ads is this:

    Untill website owners take full legal and financial responsibillity for any dammages the ads presented on their website causes my computer or property due to infected ads or an infected website, I won’t even consider disabling my adblocker, I still probably won’t, but I’ll consider it.

  • neatchee@piefed.social
    link
    fedilink
    English
    arrow-up
    37
    arrow-down
    4
    ·
    19 hours ago

    ok ok ok ok look I use DNS level ad blockers, I’m big in favor of them, but this is the dumbest shit ever.

    Running client side JavaScript that detects when an advertisement failed to load and then popping a request to disable your ad blocker is in no way, shape, or form “spying”.

    Don’t get me wrong, plenty of sites absolutely spy on you, and the ads themselves definitely spy on you.

    But being able to detect that ads didn’t load? It’s completely client side and is not spying 😂

    That last line is just real bad logic.

    • bnn1@thelemmy.club
      link
      fedilink
      English
      arrow-up
      12
      ·
      18 hours ago

      yep for websites that’s literally just checking if their ad element exists in the DOM tree.

      const myAdElementSelector = "#fuckingAd";
      const myAdElement = document.querySelector(myAdElementSelector);
      if (!myAdElement) return "yes user is using adblocker";
      

      simple as.

      or maybe not honestly i don’t know i just wanted everyone to know i know javascript.

      • merc@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        7 hours ago

        You’re running software on my computer to check the state of the web page. That’s spying.

      • Tja@programming.dev
        link
        fedilink
        English
        arrow-up
        7
        ·
        15 hours ago

        2/10, should have used jQuery

        or maybe not honestly I don’t know I just wanted everyone to know I’m old enough to remember classic stackoverflow

    • ShankShill@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      4
      ·
      19 hours ago

      Even without JavaScript, back in my day doing some basic CSS stuff could effectively* do this too.

      *Background showed if image doesn’t. Not hard to work around but did something if ad didn’t load.

      There was better technique using CSS but I ran small band websites for basically free tickets so I wasn’t chasing riches. Just hosting cost. Single small ad was enough.

  • SharkAttak@kbin.melroy.org
    link
    fedilink
    arrow-up
    85
    ·
    1 day ago

    “No no, I’m not a thief, but me and my 1200 paying friends would like to take a look around your house, may we come in?”

  • Bilb!@lemmy.ml
    link
    fedilink
    English
    arrow-up
    96
    arrow-down
    3
    ·
    1 day ago

    A script that shows a modal box or whatever when something fails to load as expected need not spy on you to function, but maybe I’m reading into a funny post more than I should be.

    • deadbeef79000@lemmy.nz
      link
      fedilink
      English
      arrow-up
      49
      arrow-down
      2
      ·
      1 day ago

      You’re technically correct (the best kind of correct).

      It’s trivial to attempt a connection to an ad server and detect the failure and display a dialog.

      The problem is that (publishers don’t want to acknowledge) there’s no difference between advertising and malware.

  • Thebeardedsinglemalt@lemmy.world
    link
    fedilink
    English
    arrow-up
    36
    ·
    23 hours ago

    Site: We noticed you’re using an ad blocker. Ads are how we pay for this site so it can be free for you

    Me: I’m using an ad blocker because without it your site is a barely functional jumbled mess

    Site: Please disable your ad blocker

    Me: Also the last time I visited the site without a blocker my antivirus caught a malicious ad injection.

    Site: 🤡

    • BrownSugarBits@lemmy.world
      link
      fedilink
      English
      arrow-up
      18
      ·
      22 hours ago

      Site: We noticed you’re using an ad blocker. Ads are how we pay for this site so it can be free for you

      “Ads are how we sell as much information about you as we possibly can so that it can be free for you. This sites content is the nectar in our fly trap. Get the fuck into our fly trap so we can extract as much from your humanity as we possibly can”

      • JcbAzPx@lemmy.world
        link
        fedilink
        English
        arrow-up
        10
        ·
        18 hours ago

        It’s not like they ever stopped. If you’re rawdogging ads, you are part of a bot net at the very least.

        • Tja@programming.dev
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          12
          ·
          14 hours ago

          I have never used an adblocker and I’m certain I’m not part of a botnet, as much as I trust my IDS.

    • Cousin Mose@lemmy.hogru.ch
      link
      fedilink
      English
      arrow-up
      7
      ·
      24 hours ago

      When I browse a website without the dialog I assume they’re not disclosing anything, but as a web developer that’s super against this my own websites are dialog free too.

      It’s sad that we expect this behavior from “normal” websites.

      • Seb the goblin@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        23 hours ago

        That’s why I appreciate the few and far between sites that have a banner… That’s just “we don’t track or nuffin’, see here what we do”, so it’s clear that they’ve considered, any potential scripts did load successfully, and they’re hopefully not lying

        • Cousin Mose@lemmy.hogru.ch
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          2
          ·
          23 hours ago

          But if I were browsing a website and that came up it would irritate me too. I’d probably end up blocking that message as well.

          I just want to see the content damn it! 🤣