Think before you click
Is the “Attribution” proposal at W3C really part of afundamentally wrong direction for the web, or is there a pony under here somewhere, and the proposal is just incomplete?
Instead of rushing to make a decision, W3C members should heed some wise advice:Don’t click. Count! Let’s count to 9 together.
1. The Bruner Paradox. See Methodological concerns regarding Attribution Level 1 and causal measurement. Although the system has some privacy properties when considered in isolation, in the context of the real web it increases incentives for “more first-party identity harvesting” and other problematic practices. So it creates more, not less, privacy risk for end users.
2. Structural bias toward channels positioned closest to observable conversion activity, including search, retail media, retargeting and click-oriented social advertising.The W3C Is Making A Mistake About Measuring Advertising Effectiveness. This proposal tends to drive ad money from legit sites to “lower funnel” Big Tech properties.
3. Incentives to suppress the “halo effect” of running ads on trusted sites. All of the attribution cartel companies areunder pressure to shift ad spend from the “open web” to their own contexts. We might be able to trust the current developers working on the project to stay honest, but we have to consider who might be running this thing a couple rounds of layoffs from now.
4. Problematic USA centralization. In a world where tech sovereignty is trending, this proposal would take a dramatic step to make US-based companies into a new choke point.
5. Sustainability. This proposal lacks a sustainability section. Even an estimate would provide some help to advertisers and agencies that want to report on emissions or general environmental impact.
6. Missing GPP support. Instead of handling the industry-standard Global Privacy Protocol, this proposal creates an extra, error-prone, compliance coding problem for every GPP-using site. This violates W3C’sWeb Platform Design Principles: User needs come before the needs of web page authors, which come before the needs of user agent implementors, which come before the needs of specification writers, which come before theoretical purity. (Considered as a work of mathematical theoretical purity, this proposal might be just fine, but it offloads the GPP detail work onto web sites, and extra risks onto users, when GPP support could have been handled by spec writers and user agent implementors.)
7. A step backward on support for extensions. Google Chrome’s “Privacy Sandbox” implemented achrome.privacy API, which helped users by letting extensions turn the ad features off. But this proposal leaves it off, and makes extensions inject a script.
8. No simulated data. Some of the companies behind this proposal already have conventional tracking data that they could have used to show how the attribution reports would have come out if the system had been in effect. If they had evidence to contradict items 1-3 they could have shown it already.
9. Public policy and lobbying considerations. The attribution reports might be of limited use to Rick Bruner and other professional marketers, but they sure are going to be useful for Big Tech companies making claims about how small businesses depend on them. Everyone who works on any privacy or competition issues is going to have to deal with papers based on this data.
That’s about it. Anyway, please think before you click.
Bonus links
Digital Sovereignty Becomes An Imperative As the US Reads Dutch Emails by Kevin Korte. According to reporting from the Netherlands, Microsoft allegedly shared the names and internal communications of Dutch officials working on EU platform regulation with the U.S. House of Representatives, including email addresses, meeting minutes, and invitations. Those officials were tied to agencies that enforce the Digital Services Act, making the context especially sensitive because the data belonged to regulators shaping Europe’s platform rules.
Valve kills its retail gift card program due to scammers by Kyle Orland. (Gift cards are a security issue for the recipient, too.20 Years of Digital Life, Gone in an Instant, thanks to Apple — Dr Paris Buttfield-Addison)
Landmark German ruling declares Google’s AI Overviews are Google’s own words and makes it liable for false answers by Matthias Bastian. Google adds that AI overviews can occasionally miss context or misinterpret web content, just like traditional search results. But that’s exactly where the Munich ruling disagrees. The court draws a line between AI overviews, which generate new content loosely based on sources, and traditional search results, which list sources with direct quotes. That distinction is what makes Google directly liable, according to the court.