Explaining why the attribution cartel is a privacy menace (almost)

Previously: there are many paradoxes but this one is mine

The attribution cartel came up on the Monopoly Report podcast again:Alan Chapell interviews Mozilla’s Martin Thomson. Subjects covered include Attribution proposal’s lower funnel bias and the fraud problem. Listen to the whole thing (or read the transcript). And they almost get to why the proposal is a privacy menace.

We understand that there are a number of circumstances in which you have essentially low trust settings that is very common in sort of open web advertising where there’s this low trust setting and you have essentially people in the system that are able to register impressions with these these systems that you don’t entirely trust to do the right thing. And so in in the general sense, you do advertise with them. You you expect to be recording impressions with them, but you fundamentally don’t trust that they will participate faithfully. And you kind of do create these situations, I think, with the design that we’re putting forward where there is that that latent risk. There are impressions that are registered very very late in the process with a specific design to to snipe credit from others and that depends on an assumption of things like last touch attribution styles and various other assumptions but that’s still very common. So we have to acknowledge that there is that possibility in the system. However, we’ve built in a bunch of controls around all of that. And we’ll freely admit they’re not perfect. But one of the things, one of the most basic controls is that if the DSP wants to manage the attribution process, then they’re the ones that ultimately register the impressions and there are controls to ensure that they’re the only ones that are able to do that. And that gives them the ability to put safeguards or in place around having those nasty conversion stealing arrangements. Not perfect, I will freely admit, but not as bad as as some people making it.

I was in suspense. Just one more step to explain the biggest problem with this proposal. Now that it’s clear that some players out there are trying to “snipe credit from others,” what are they going to be doing in order to figure out who to snipe?

Attribution fraud perpetrators are not just placing impressions indiscriminately—that would be counterproductive because on average the results would look weak. Think about it from the attribution fraud point of view for a minute.

In order to snipe snipe, you need to pick rewarding targets.

To pick a target, you figure out who’s about to buy anyway.

And if you’re a cool kid in 2026, the way you figure out who’s about to buy is machine learning.

In order to train the ML system for sniping, you feed it a lot of people’s personal info.

And that personal info doesn’t have to be justifiable, or disclosed, or anything, because the attribution cartel is going to obfuscate the reports. Go ahead and deploy speech to text on a bunch of smart appliances to pick up people talking about shopping lists—the attribution cartel reports are just going to show which ads “made a sale” so the advertiser is going to have no idea. And people end up with more privacy risk, not less.

Anyway, listen to the whole interview. We’re almost there.

On a related subject, a good article from HFT University. The C++ Standard Library Has Been Walking Itself Back for Fifteen Years, and the Receipts Are Public.

The committee is not only failing to remove bad features. It is also continuously adding new ones that no working engineer asked for, championed by individuals who get professional recognition for shipping the proposal, and the result is a language whose surface area expands faster than any single team of implementers can keep up with.

Professional recognition—and advancement at work by participants in standards organizations—should not be determined by scoring goals, getting features into some standardized platform. A paper that describes a feature in thesteelmanliest way possible, and then explains why the platform is not doing it, is more valuable in the long run than anotherBattery Status API or Third-Party Cookie. Just as lines of code is a bad metric for programmers, people who participate in standards organizations should be recognized and rewarded for keeping a standard free of trendy but problematic baggage and explaining why. As I mentioned whenI was on the Monopoly Report podcast, the Attribution proposal has a future as an open-access publication that developers in other fields can work with, even if it’s a bad fit for web advertising. As a wise Muppet once said,Think before you click.

Bonus links

What Does a 13-Year-Old See on Snapchat in a Normal Week? by Brooke Istook. (Yikes. If your kid says they need one of these surveillance apps to communicate with a friend, call the friend’s parents.)

Court filing: Meta says four US states seek $1.4T over claims it designed Facebook and Instagram to addict youth and misled the public; its market cap is ~$1.5T by Diana Novak Jones. A sanction of that size ​has no analog in the history of consumer protection enforcement (Most big companies at least make an effort to go legit, though.)

Alameda Free Library Launches First-Ever Book Con by Karin K. Jensen. (Saturday at the library, see you there?)

Meta’s AI ‘Perv Glasses’ Now Come With Stupid Comcast-esque Usage Restrictions by Karl Bode. (Oh no! Anyway…)

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论