24 comments

[ 2.2 ms ] story [ 63.0 ms ] thread
It seems to me that this is cross-site tracking of the sort forbidden by WebKit (Safari)'s and Firefox's tracking prevention policies:

https://webkit.org/tracking-prevention-policy/

https://wiki.mozilla.org/Security/Anti_tracking_policy

If Repixel can identify someone as a golfer with joint pain because they visited a golfing website and an unrelated joint pain website, that sounds like tracking an identifiable user across multiple first parties.

Should Safari and Firefox ban Repixel?

they don't "ban" domains based on this policy. they just don't make their cookies available to the cross origin requests as per the ITP browser changes: https://clearcode.cc/blog/intelligent-tracking-prevention/#I...

so Firefox and Chrome are making changes which basically limit the effectiveness of this technique.

It's a Facebook approved app through and everything stays within Facebook's ecosystem. Check it out: https://blog.repixel.co/2019/07/01/facebook-and-gdpr-complia...
To someone like me who has not used Facebook in over half a decade and finds the organization creepy, this is most certainly the opposite of a selling point.
As long as I'm seeing ads, I'd rather them be relevant. Just my $0.02. But if you're avoiding the platform altogether I get that.
Sorry if this comes off as rude, but do you have a financial relationship with repixel?
> As long as I'm seeing ads, I'd rather them be relevant.

Fair enough. My preference is different. I don't care about seeing ads, and I couldn't care less if they're "relevant" or not. But I strongly object to the data collection required to target ads and want it to stop.

That sounds backwards. If my ad blocker fails and I'm forced to see an ad, I want it to be as irrelevant as possible to minimize its effect.
Safari's tracking policy is in large part intended to protect users against the Facebook ecosystem (even though, yes, it is not specific to Facebook or any other domain and just establishes policies for technical behavior): https://www.theverge.com/2018/6/4/17427000/wwdc-apple-safari...

> Cross-site tracking is tracking across multiple first party websites; tracking between websites and apps; or the retention, use, or sharing of data from that activity with parties other than the first party on which it was collected.

I think that having Facebook share tracking information with Repixel and in turn with Repixel's customers counts as "sharing of data from that activity with parties other than the first party on which it was collected," no?

Where are you seeing that sentence that you quoted? I'm curious to take a look. I don't see it in the verge article that you linked to. Apologies if I'm missing something.
Sorry, that was unclear. That sentence is from the WebKit/Safari policy which I linked earlier in the thread. (The Verge article is a synthesis of the stated policy and the fact that the WWDC presentation clearly had a screenshot of blocking Facebook cookies.)
All good, thanks for clarifying! I'll take a look tonight.
Firefox is willing to add specific technical countermeasures to specific domains that are attempting to bypass the tracking policy: "If a party attempts to circumvent the technical solutions we’ve outlined in this policy, we may without notice add additional restrictions to that party to prevent the circumvention." It seems they use the list of tracking domains at https://github.com/disconnectme/disconnect-tracking-protecti... .

(Safari, as far as I can tell, tries to avoid having site-specific policies, so maybe the question is "What is Repixel doing that is exploiting a security bug in Safari, and how can Safari fix it?")

This “guide” is just an advertisement for their product.
I think there is value in posting this sort of advertisement to HN, because it reliably leads to a good discussion of how to subvert it as a user :)
I assume this is something uBlock Origin will take care of for me?
Yeah you'd be covered. This is another way of retargeting, and as far as I understand, you'd be opted out globally.
I still don't get it. So I'm paying the site owner for the pixel and FB for the ad?
It's kind of like display advertising, but less spammy because it works in the background. Instead of reaching the site owner's audience through a banner on their site, you pay them to tag their visitors (through their Facebook pixel) and reach their audience on Facebook/Instagram.
I received the following email apparently sent by Repixel's CEO John Evans on the 4th of December. I've already reported it to HN's moderators:

<quote>

Hi Edward,

I noticed you’re a big contributor on Hacker News and I was hoping to get an article seen by the community. Would you be open to taking a look at a piece of my content, and if you find it interesting, consider posting it? I would do it myself but I think your karma points would give it an extra push. Happy to return the favor if there’s anything I can do for you in return!

Best, John

</quote>

I'd have concerns about this firm's services, practices, and ethics.

You are an influencer and these kind of approaches happen all the time. I think this allowed networking behaviour.
As a pseudonymous nym, quite literally the only stock I have are the facts and reasoning I post, and my past record.

I'm not willing to compromise either.

Ah sorry about that! I was having trouble getting my articles seen so I figured reaching out to a handful of power users with more karma points (like you!) would help. In my defense, this is best practice in other forums like Product Hunt so I thought reaching out respectfully would be okay here too. And I saw no asking for upvotes/comments in the forum guidelines but didn't see anything against asking for a submission :)

In any event, my apologies again for the troubles. I have ironed this out with the moderator (who has adjusted the guidelines) and I've paused my emailing. I wasn't aware of the rule, but I am now.

I'm new here so not trying to start an argument. But hopefully where I'm coming from makes sense. Reaching out simply felt logical to me, not unethical.