Arguments for the attribution cartel

previously: Think before you click

I’m collecting the best arguments for the attribution cartel, and so far I have four. Well, six by now if you count “it’s not third-party cookies” which I probably shouldn’t.

Although the kinds of privacy-preserving measurements that they’re proposing are technically interesting, and would probably work for other applications, it looks like the cartel is just going to make things a lot worse.

(Updated 10 Jul 2026 to include links, quotes, and items 5 and 6.)

1. The attribution tracking is a replacement for riskier data collection.

False. No attribution cartel company has backed off on their own, more intrusive, tracking systems. And if they can get users to accept one ad feature in the browser, they’ll move on to more. Google“Privacy Sandbox” was proposed as an alternative to fingerprinting—then when it achieved some acceptance, Google went on toallow fingerprinting.

In an interview with Alan Chapell, Martin Thomson from Mozilla says,

I’d like to see a whole lot less tracking, collection of email/phone numbers, clean rooms, and the other bullshit privacy apparatus that the advertising industry created. In practice, however, I don’t expect this to change anything significantly. Success here means that some businesses decide that this is enough. That they can get enough information from attribution without having to resort to those other things. If it is only a few who change, that’s a win.

Those few, if any, would be massively outweighed in impact by the Big Tech execs who learn the real lesson: hooray, we got one advertising feature into the browsers, now it’s time to add more.

Appeasement doesn’t work. (In general, better to overreact to the Big Tech value-extraction schemes you do hear of, because they’re doing something you haven’t heard of in thebackground that they would have deserved to catch hell for too.)

2. Attribution reporting math protects privacy.

Only in isolation. In combination with other technologies available on the web, though, theBruner paradox kicks in.

More broadly, I think there is an important privacy paradox embedded here. The specification is motivated by legitimate privacy goals, which I support. But many practical implementations of identity-based incrementality measurement appear likely to increase incentives for more first-party identity harvesting, more authenticated-user environments, more CRM onboarding, and more identity reconciliation infrastructure.

Selling a product or service is hard. It’s easier to identify someone about to buy, then claim credit for the sale. By making the difference harder to spot, the attribution cartel increases incentives for surveillance. For example, a sketchy appliance manufacturer would find it hard to sell a data feed of shopping-related keywords from always-on microphones in people’s homes. But that data could be used to place ads in a way that would look surprisingly effective on the attribution reports.

The attribution cartel would enable the monetization of more surveillance data, from more and riskier sources. (More:Explaining why the attribution cartel is a privacy menace (almost))

3. For legit sites, some attribution data is better than none.

False. The attribution cartel will combine the obfuscated attribution reports from legit sites with the individualized tracking from their own contexts—in a way that makes the legit sites look consistently worse.

Some people suggest attribution cartel tracking as a possible way to measure contextual advertising—supposing some combination of laws and regs that would make it possible for scripts running on web sites to invoke the Attribution API even in situations where they lack a basis for processing that would be required for other ad measurement. That could be appealing if contextual advertising plus attribution cartel tracking were the whole system. But the attribution tracking data will be fed into the same reporting systems as, and be compared to, the individualized tracking on search, social, and app store ads. And it’simpossible on the corporate politics level for the advertiser “dashboard” to produce a result suggesting that the advertiser is spending too much on Big Tech ads and not enough on legit sites.

We can expect that the attribution cartel has learned the lessons of themassive “Privacy Sandbox” revenue hit (Google got too greedy, too fast, last time) and throw some legit publishers a bone early on. A pilot project involving some legit advertisers and legit sites will show encouraging results. Then, as soon as that news cycle is over, the attribution data will go to work “proving” that the cartel’s own ads are a better value than ads elsewhere.

4. If you don’t like the attribution tracking, you can turn it off.

Technically true. But not really the point. The attribution cartel’s data collection is part of a political program, and the reports will be used to show how small businesses depend on search, social media, and app store advertising.

Even if you personally don’t participate in attribution cartel tracking, or believe the reports, the politicians who are supposed to represent you will be swamped with them. And that creates more more work for legit public interest organizations, and more risk of Big Tech-friendly laws.

5. Third-party cookies are bad. The attribution cartel is not third-party cookies. Therefore the attribution cartel is good.

Is that even a fallacy?

6. The attribution tracking proposal is neutral, ad oligopoly is the problem.

The problem is not just that the Attribution proposal works in favor of the existing advertising oligopoly. The underlying problem is that the proposal is so cartel-friendly that it would bring forth a new cartel even if started in a situation without one. With attribution tracking, every party that could do surveillance is incentivized to do as much as possible, in order to feed machine learning systems to claim attribution. And machine learning and lobbying work better at scale, so those parties are incentivized to combine into a new cartel. (More:Attribution tracking on an alternate timeline)

Conclusion

The pressure on the attribution cartel companies is not a situation I would want to be in.Value extraction by Big Tech is non-optional, because…

• They must show startup-like growth in order to maintain high stock prices.

• They already control a majority of an industry, advertising, that grows about as fast as the economy does.

The only way out is to keep increasing the percentage that they’re able to capture. The attribution cartel is one aspect of a larger technological, business, criminal, and political program—ending it won’t stop Big Tech oligopoly entirely, but stopping it will be the same kind of win as the end of “Privacy Sandbox” was—something to build on.

Bonus links

US Supreme Court just blew up EU-US Data Transfers from noyb.eu. On Monday, the US Supreme Court decided in Trump v. Slaughter that the US Federal Trade Commission (“FTC”) may not be independent anymore. Since 2000, the EU has relied on the “independent” FTC as the enforcer of EU-US deals on personal data. According to EU treaty law, such oversight must be independent. In the current EU-US deal, the European Commission relies on the independent FTC 259 (!) times. (The real problem isPatriot and other high-end defense products and collaboration. Until the military-industrial “Eurostack” is well-established, the surveillance advertising industry in the USA will be able to free-ride.)

Do excellent vulnerability reports by Daniel Stenberg. (A great how-to for reporting security issues, from the lead developer of curl, a project that has handled more than a thousand of them.)

Pluralistic: Zuckerberg’s increasingly bizarre war on whistleblowers (27 Jun 2026) by Cory Doctorow. Speaking of thin-skinned, paranoid, wildly corrupt buffoons who will stop at nothing to silence their enemies, how about that Mark Zuckerberg, huh? (As a Firefox user, I want my browser to collaborate with Meta on advertising measurement — nobody, ever) More:Whistleblower Sarah Wynn-Williams sues Meta over attempts to ‘silence’ herThe Steam Machine Is An Iconoclastic Computer Born In Unforgiving Times by Chris Person. (Detailed review of a nifty device. And the price might not be so bad, considering it’s comparable to a homebuilt PC with similar specs, and it might be easier to justify buying one box instead of both a gaming console and a midrange Linux system?)

Browser Opt-Out Tool Shoots for Simplicity, Brings Uncertainty by Christopher Brown. (When surveillance advertisers say they’re confused or uncertain about something, that generally means they’re being asked to do something they don’t want to. Seriously—guys who became instant thought leaders in agentic advertising are somehow faked out of their socks by a one-byte HTTP header.)

US Anthropic ban is best advert for Chinese AI by Alex Lo. (This whole market is giving 1990s Sun Microsystems vs. generic Linux PC. Previously:generative ai antimoats)

How we’ll fight the platform war against Big AI by Anil Dash. In a scenario where there are extremely capable models that cost nothing except for the price of keeping a few servers running, as well as very robust tools that make it effortless to seamlessly switch between models…more and more organizations will shift more and more work away from the Big AI companies, especially as those companies keep raising their prices.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论