06 Aug 2026

Previously: Arguments for the attribution cartel

One of the arguments for the attribution cartel is that in-browser attribution tracking will somehow displace other forms of ad measurement. Because reasons, I guess. Or because the cartel members believe that they can convince people that everyone else’s ad data collection needs consent—or at least those fake “consent” dialogs that the Irish regulators will let you get away with—and somehow the attribution cartel doesn’t.

The problem with that argument is that there have already been two big opportunities for substitution effects to happen. And they haven’t.

Why so little marketer interest in an in-browser ad measurement system?

The problem is that for the attribution cartel, the system has a limited set of acceptable outputs. The Google and Apple systems would have had to agree that the best-performing ads are on Google and Apple properties.

Likewise, whatever W3C ends up standardizing on, the attribution reports will have to agree with the ad placement decisions already made by the Facebook and Instagram algorithms, by Google’s Performance Max, and by whatever Apple is going to be doing as they continue to enshittify over there. Imagine an attribution report that contradicted the optimal placements decreed from above, and gave credit for sales to legit independent sites instead. That would be like writing a biology paper contradicting Trofim Lysenko back when he was a big shot.

Since marketers can predict that the attribution reports are going to hide the halo effects of the likely most impactful ad placements, and just back up what the cartel members were saying anyway, there was little interest in the Google and Apple systems, and there will be little interest in the new one. The attribution cartel members have reasons to do what they’re doing—but they have to do with lobbying and consolidation, not benefits to legit advertisers or legit ad-supported sites.

More: Are ya winning, son? How the attribution cartel is getting privacy nerds and adtech execs to agree on something.

31 Jul 2026

previously: paleoenshittification and a path to adoption for MyTerms

The European privacy organization noyb has filed a complaint over a common web annoyances. This one is a little more extreme than most: 1,741 “informed” consents with one click?! GDPR complaint against dict.cc filed. Who has 1,741 “partners”? Anyway, this claimed “consent” to data collection by all these “partners” is stored in the following TCF string.

CQoKcgAQoKcgAAJAGBENCpFsAP_gAEPgACiQMttR_G__bWlr-bb3abtkeYxP9_hr7sQxBgbIkm4FzLvW7JwGx2EZJAyatiIKmRIAu3DBIQNlHBDURUCgKIAFryDMaE2U4TNKJ6BkiFMZIytQCEhvm4tjeQCZ4ur_9kc0mB-t7dr-2dzyy6hHn3a5fmS1UJSdIYesDfv-ZhOS-9IEd-x8v4v4_EbpEm8eSVn9pGtp4jc6Yns6dBmxt-Tyff6Pn_f71fW7X_ve_n3zv8oXn7rr6-__f3-7___-b_-___b-__7Z_zM_37_v_YMttR_G_9bXlv-bBX4btkOYxf9_gD7sQxBAbIomYFzLqW5IwC32ETJEiaMCIIGRAAo1BBIAEpEBhEREChCIAVLxDsAE0Q4TtIAeBkgDMZYiBQAEhPi4tjWQCZ4Op-dUd0iQ2s5Nr22VyyWbAjn3KteOSVUJicKYMFHetuYhMQ-vIU93RK9otI_MbpEkIYARv9lWpl4TYa4vnKVpqxNeRydMSffdFz3fW7RO3a-91k-uqSV_rb4uXW5m__bNn_f138_f_7Z7_1x-3Zf_f__4AAAA.IMttR_G__bXlv-bb36btkeYxf9_hr7sQxBgbIsm4FzLvW7JwG32EbJEyatiIKmRIAu3DBIQNtHBjURUChKIAVrzDsaE2U4TtKJ-BkiHMZYytQCEhvm4tjeQCZ4ur_90d0mR-t7dr-2dzy27hnn3a9fuS1UJydKYetHfv-ZhOS-_IU9_x-_4v4_MbpEm8eSVv9tWtt4zc64vv6dpuxt-Tyff6f__f73fW7X__e__33_-qX3_r76-___3______f__________9_________4A.f_wAD_wAAAAA

If I visit the site from the complaint using a European VPN endpoint, Yes, I went to that site with VPN to Europe on and ad blocker off, and ended up seeing a gross fungus treatment ad. Yeech. The things I do for privacy research and click the obvious button to make the annoying dialog go away, this is what gets stored in the browser. And no, I won’t say that I “consented” because I’m still not informed enough about this industry to give informed consent in all but a few cases.

But why 1,741 partners? Because of the way that this stuff works in Europe right now.

  1. A site gets a Consent Management Platform (CMP) – a third party script that powers the annoying “consent dialog”/“cookie banner”

  2. A person with up-to-date knowledge of the site’s data practices carefully configures the CMP to match the…lol, no, somebody clicks various options in the CMP menu until the errors and warnings stop, which is how you end up with “1,714 partners” and other ludicrous messages to end users.

  3. When a user visits the site and clicks the CMP “consent” button, the CMP stores a record of “consent.” (This can be in TCF, or in a related format called Global Privacy Protocol that wraps TCF along with other strings that apply to non-EU jurisdictions.)

  4. Any company that is somehow processing the user’s information has to check the record from step 3.

There’s no step in the process for MyTerms, and the way it’s set up makes it look like a MyTerms check is not needed at all. No decision-maker at the site is going to see any need to get contractual permission to do some data processing that, as far as they can tell, they “already have consent for.” (It’s fake consent because Irish politics, but people settle for it.)

So a way to get more sites interested in MyTerms is something like a step 3.5.

  • Detect when a CMP is generating a TCF or GPP string.

  • Where the string indicates “consent” to anything that would be disallowed by any of the possible MyTerms contracts that the user has indicated they would accept, modify the string to remove the conflict.

This filtering or masking step is not going to produce as good of a result as a full MyTerms transaction that both user and site participate in, but it at least takes a step to prevent the data practices most inconsistent with the user’s preferences (and safety), and gives the site an incentive to upgrade to full MyTerms instead of just filtered GPP.

Different MyTerms implementations might approach GPP and TCF integration differently.

One possibility is to provide a surrogate script for the CMP and prevent the annoying “consent” dialog from ever showing up.

Or implement the CMP API to provide a filtered result to callers.

I’m sure that other possible approaches exist, too. The only approach to GPP and TCF that I know for sure won’t work is ignoring them.

Related

Toward Harmonizing MyTerms (IEEE 7012) with GPC and GPP by Doc Searls.

Bonus links

Ukrainian Drones Disabled Over 30% of Russian Oil Refinery Capacity — FT by Vladyslav Khomenko. (This is a campaign by a low-budget country that is itself under constant attack from the air, against the largest country in the world. It’s past time to assume that future belligerents will have the option of ending all oil refining and LNG exports anywhere they choose, at relatively low cost.)

I Am Quietly And Perhaps Foolishly Optimistic About The Future Of Video Games Journalism By Luke Plunkett. Just as it was clear in 2006 that paying for magazines was a dying business proposition, even as some clung on to newsstands, so too does it look in 2026 that relying on Google search and online ads to sustain journalism is just as terminal. So while things are currently stuck in this painful limbo, where a handful of old websites are dying while new websites struggle to be born, I think the more success you see from subscription-based publications (like our friends and former colleagues at outlets like Defector, 404, Hell Gate, Rascal and Mothership), the more the idea that quality writing has to be paid for will take root among a wider audience, and a rising tide will start lifting more boats. (fwiw, I’m an Internet optimist too, and I even have a good answer to the question: Where will the money to pay for subscriptions come from?)

The Last Small Step for Art on MetaFilter links to The Last Museum. (Now more than ever there’s no excuse to use a slop illustration for a blog post.)

AI’s finally expensive enough to make Wall Street nervous by Elizabeth Lopatto. (Google management has been used to sitting back and raking in the cash from the network effects of search and anything that can be illegally tied to search—possibly the easiest business model in the world to keep going after someone does the hard work of coding a search engine in the first place. Now they’re trying to sell a high-capex, low-differentiation LLM service. Related: Ben Thompson is wrong: US frontier labs are right to be panicking by Larry Salibra. Take the examples he gives: “Claude Code” and “Codex.” As any reader of Hacker News will tell you, Claude Code is already yesterday….in fact, it’s last week. Yesterday was Codex, and Cursor is ancient history….The situation is the same with non-technical users who are seriously using AI. Today, they’re using Claude Cowork but yesterday they were all using Manus. And before that, they were using Perplexity…Sure, the mass market consumer user who asks “AI” a question a few times a week might have downloaded ChatGPT or Doubao when they first heard of AI and never switched to anything else. But those users usually don’t pay much if anything at all and will hardly bail the labs out of their sinking ships.)

30 Jul 2026

In The Hidden Cost of China’s Free A.I., Tal Feldman writes,

A.I. models are very different from the usual inexpensive imports we buy from China. These products must promote the interests of the Chinese government. Propaganda and false claims are baked into them.

Whoever supplies the world’s A.I. will shape how the world thinks. As these models get smarter and more autonomous, we are outsourcing more and more thinking to them. That “cognitive offloading” must not go to models that were designed to promote a foreign government, no matter how inexpensive they are.

Two problems with that. (Aside from letting the AI shape how you think, which, yikes. But the influence is already there, and we have to expect that it will persist.)

First of all, the choice is not between propaganda AI from the PRC and some hypothetical, honest red, white, and blue AI from the good old USA. The average American has more in common with a random propaganda commissar in China then with the deeply weird TESCREAL investors, founders, and CEOs who run the AI operations here.

Second, as more and more legal opt-outs apply to LLM training sets here, the US-based AI firms will rely more and more on vibe CMS automated paraphrased versions of US and European news and culture. Legit publishers will opt out the copyrighted works they own or distribute, in the hopes of training license deals. Big AI firms will pay a few publishers for PR value, but mostly settle for first-generation lossy copies.

And a lot of that free training material will have been run through someone’s PR filter. For example, a reputation management firm could make a site that mostly generates high-fidelity paraphrases of legit news, but folds in positive mentions of the firm’s clients. Almost everyone wins: big US-based AI gets freely crawlable tokens, the client gets their crimes buried in LLM-generated answers, most news consumers get an adequate free paraphrase. Meanwhile, though, AI operations in the PRC will be able to train on material that’s one generation fresher.

The problem isn’t so much that “our side’s” AI is better than theirs, or the other way around. Every LLM is going to have embedded biases, for a variety of reasons. Propaganda and copyright-related biases are only two.

Bonus links

A fundamental flaw leaves LLMs strikingly vulnerable to attack by Will Douglas Heaven. In a series of experiments that looked at what was going on inside a handful of different models, the researchers found that LLMs seem to identify the role of a specific chunk of text not by the tags around it but by the style of that text and the words it contains.

Boomers Can’t Stop Gifting Their Grandkids AI-Generated Slop Books by Miles Klee. In addition to books featuring kids, some parents have complained of being fleeced by vendors selling AI-produced books not labeled as such on Amazon, irritated by their children’s exposure to puzzles and games riddled with AI’s mistakes, and just plain dismayed by the proliferation of the AI aesthetic across content targeted at kids. (Another good reason to go to story hour at the library—legit children’s book recommendations.)

Pluralistic: The stupidest imaginable excuses for surveillance pricing (30 Jul 2026) by Cory Doctorow. [Y]ou can direct the AI to automatically run a series of small experiments to discover the maximum markup each group will stomach under which circumstances. This works without you having to direct the AI to rip off certain groups of people – it will simply find the most vulnerable people and rip them off the most….This works so well that Google has announced that it is their plan for making a profit off of AI, after losing hundreds of billions of dollars on chatbots. (But however fast the price discrimination works, the price of the price discrimination machine has to keep going up faster than that.)

Meta’s Tepid Revenue Outlook Undercuts its AI Spending Spree by Kendra Barnett. (Revenue is up 28% year over year. Conversions are up 15.7%. Do the math—the customer acquisition cost crunch continues. It’s not evenly distributed, though. Highly Meta-dependent advertisers such as Oddity Tech (ODD) are hurting more, while advertisers with better options are less affected.)

Meta is royally screwing up its smart glasses rollout by Victoria Song. (I don’t know anyone who owns these things, or participate in any group or space where they would be tolerated. Is there some filter bubble of extremly surveillance-positive Instagram users that I’m totally disconnected from?)

Steve Jobs in 2011: ‘We Build Products That We Want for Ourselves, Too, and We Just Don’t Want Ads’ by John Gruber. (None of the current Apple execs could stay at the company if they tried to hold the line against enshittification. Mr. Market wants enshittification to happen everywhere, and even if Apple can buy the best of everything else, they’re stuck with the same investors as Packard Bell. More from John Gruber: The Ads on Apple News Continue to Suck, but at Least There Are a Lot of Them)

Older people’s media literacy can be boosted in just 60 minutes – new study by Saffron Howden, Janet Fulton, and Sora Park. To find solutions through media literacy, we focused on older people (aged 55+) who are known to be more vulnerable to misinformation, have fewer media skills, and feel less confident in their media abilities. We recruited our study participants from across Australia through libraries, the news media, and social media.

Tesla is juicing its China sales by Larry Salibra. When I was shopping for a car in Hong Kong, all of the Chinese EVs dealers required that I book a test drive days in advance. The Tesla showroom, in contrast, let me do a walk in test drive because they weren’t busy. They also offered me something none of the Chinese EV dealers did: 7 year financing at 0.99% interest per year. This made the Tesla which had a higher sticker price, actually less expensive because HKD (which is pegged to the USD) loses value at much faster than 0.99% a year.

26 Jul 2026

The prophet Jeremiah once asked,

Wherefore doth the way of the wicked prosper? wherefore are all they happy that deal very treacherously?

Every generation of people perceives a collapse in ethical behavior, and if the trust level of human civilization had really been sliding that badly for so long—the book of Jeremiah was written 2600 years ago—nothing would be left for us by now.

That perception of decline is not surprising, considering that most people respect norms of honesty and reciprocity, but the transgressors tend to attract more attention. Often, people who comment on moral collapse are older adults comparing their experiences with their own peer group to the crimes of the younger, higher-profile 30 under 30 crowd.

So we can’t just go by vibes, by our feelings of how much of a rip-off everything is now. We have to take a step back and look at the stats. And this time, possibly because of how network effects amplify the impact of a few big companies, it’s a real problem.

According to the FTC, people in the USA lost $2.1B to social media scams in 2025. Internal documents from Meta, which owns Facebook, Instagram, and WhatsApp, estimated that the company is involved in about 1/3 of successful scams here.

And Meta isn’t the only company that designs an Internet platform to work better for scammers. Google tweaks their systems and policies to benefit scams, too. The FBI warns,

Cyber criminals use advertisements that imitate legitimate companies to misdirect targets conducting an internet search for a specific website.

Google Search is a major scam risk because of some choices in software design and ad policies that make their platform work better for scammers and worse for those trying to catch them. As Prof. Tressie McMillan Cottom wrote, we are now living in a scam culture.

Scams weaken our trust in social institutions, but their going mainstream—divorced from empathy for the victims or stigma for the perpetrators—means that we have accepted scams as institutions themselves.

Google and Meta are large enough, and have enough impact on how people and companies find each other, that their internal collapse in business ethics has an oversized impact on the whole economy.

The ways that big companies profit from online fraud is pretty complicated, but I think I can explain it if we work backwards. And the better we understand how scam culture has been coded into everyday business practices, the better we will be able to roll it back.

The auction

Most online advertising, legit or criminal, is placed using some kind of auction. Probably the best known is the system behind Google’s search ads, which Edelman et al. explained in Internet Advertising and the Generalized Second-Price Auction: Selling Billions of Dollars Worth of Keywords.

Every time there is some opportunity to show an ad to you—whether it’s because you did a web search, scrolled a social media feed, or visited a web site with ads—some computer program in a data center somewhere acts like a very fast auctioneer, selling off the ad space to the highest bidder.

The bidders in the auction are AI, using three different kinds of information to “decide” how much to bid.

  • Context: where the ad will appear

  • Intent: what you’re doing (if a bidder infers that you’re shopping, the ads reaching you go way up in value)

  • Personal information: some other qualities about you that a bidder has collected or inferred.

If you notice that you get different ads on search engines or social media from other people, you have probably been classified differently from them, so different bidders are bidding high enough to win the auctions.

Why Facebook and Google tolerate scams

The auction mechanism explains why Meta and Google seem so incompetent at filtering out the scam ads. An auction generally gets higher prices when there are more bidders. And the ad auction is no exception. (How is it that social sites make it so easy to tag people who appear in photos, but they somehow can’t spot a bank logo in an ad and alert the real bank?)

Meta estimated that they get 10% of their revenue from illegal and policy-violating ads—but that doesn’t mean that scammers are responsible for 10% of their revenue. All of the legit advertisers are paying more, too, because every time “their” AI bidder participates in an ad auction, it has to go up against not just legit competitors, but scammers too.

No wonder that, as Bob Sullivan explains, Facebook’s algorithm pushes people into the arms of criminals. Meta and Google refuse to take some basic steps to make it easier for law enforcement and consumer organizations to spot scam advertisers, or for their real advertisers to spot their fake competitors.

Know the scam, avoid the ad?

I’m fortunate enough to avoid some kinds of online scam ads. For example, I rarely see those urgent Microsoft warnings, you know, the ones that will put you on the phone with a “tech support” person to talk you through installing a computer virus.

I don’t get those tech support ads because AI bidders can infer that I keep up with computer stuff. But I’m sure that there are plenty of scams I would be more likely to fall for. I’m probably about as gullible as average if a scammer could figure me out—maybe a realistic urgent alert related to an upcoming trip?

In general, the less accurately I can be targeted, the better. I probably won’t get any fewer scams by being misclassified, but I’d rather get scam ads that I’ll laugh at than scam ads I’ll click on.

In order for the scam problem to flourish, though, the scams must be getting matched up to the people likely to fall for them.

Normal companies passing targeting data

The Big Tech companies collect some data about what you watch and do on their sites and apps. But a lot of targeting data comes from a place you wouldn’t expect. It’s actually provided to the Big Tech platforms by normal small businesses.

Why?

Companies that advertise with Google and/or Meta are encouraged to share their customer information.

For example, they can report when somebody bought something, or send a customer list to the Big Tech company to train the AI to find people similar to their customers to show ads to. They can even report on who’s reading what pages of their web site.

And because of the built-in auction mechanisms on the platform, every advertiser ends up sharing information with every other advertiser. Every customer list that you appear on helps to train the AI to target you for ads you’re likely to respond to—including the scam ones.

Doing legit businesses a favor

People who do online marketing are family members and citizens, too. They don’t want to support Big Tech’s noisy, resource-sucking data centers, social media mental health harm, or other corporate crimes, any more than the rest of us do.

But sometimes Big Tech companies make it hard to justify not spending money with them. And it’s hard to speak out in the marketing meeting and say, “our company should do the right thing.”

But over time, privacy cases can help change that.

When a marketing person has trouble justifying moving the budget away from Big Tech and into legit marketing projects, the benefit of avoiding legal issues can shift the balance. It’s sort of like the struggle by people with disabilities to get the accommodations required by the Americans with Disabilities Act. Being able to point out the risk of legal action can help a business decision-maker do the right thing.

Next steps

The Big Tech companies want people to think of the Internet as some kind of lawless zone, and they throw around scary terms like “Section 230” to try to make people think that the fix is in, and there’s no point going after a scam at the source. But when you dig into the files from the California Legislature and the courts, that’s not how it is. Regular people are making progress in the courts against scammers and their enablers. If you want to learn more, please get in touch.

25 Jul 2026

Programmatic Platforms Champion Transparency, But Not If It Means Giving Activists Access by Anthony Vargas. (I said I would let you know when it’s safe to turn off your ad blocker, and nope, still wretched hive of scum and villainy. This story is about good ads sneaked onto bad sites—but every time that happens, it leaves some good site with an ad slot to fill, so more of the bad ads get served. The industry has existing tools, often already standardized, just doesn’t want to use them.)

Apple Updates Its Advertising Policies by Nick Heer. (More news from how Apple is on the enshittification curve the same as any other company.)

The political polarization of health outcomes in the USA by Elizabeth Elder and Neil A. O’Brian. Roughly half of this new health gap is due to people changing their ideology over time, with new entrants to the conservative coalition being less healthy than new liberals. But another sizeable share is due to people who were already liberal or conservative diverging more in health over time. (Maybe William James was right about the cash value of beliefs, and some people are just invested in lower-return asset classes?)

Experience Better Browsing: Introducing Native Containers in Firefox 153 (This is part of the easiest way to containerize and mostly de-enshittify YouTube, now part of the browser.)

A decade after the ‘Godfather of AI’ said radiologists were obsolete, their salaries are up to $571K and demand is growing fast vy Marco Quiroz-Gutierrez. Over the last 10 years, the number of active radiologists in the U.S. has grown by about 10%, said Christoph Herpfer, an economist and business administration professor at the University of Virginia’s Darden School of Business who studies health care finance and physician labor markets. We actually have a huge shortage of radiologists. So the exact opposite of this prediction has happened, he told Fortune.

Book publishers sue Google for copyright infringement over Gemini AI training by Emma Loffhagen. The publishers argue that Google repurposed books that had been supplied for limited services such as Google Books, Google Play Books and Google Scholar. Those services allowed Google to use the works in specific ways – for example, to display searchable snippets or sell ebooks – but not, the lawsuit claims, to copy them for training commercial AI products.

Please Stop Making Me Opt Out of AI by Reece Rogers. (not likely. Number must go up.) Related: https://マリウス.com/the-rise-of-the-bullshittery/), The Lies They’re Telling Towns And Tribes About The Benefits Of AI Data Centers by Karl Bode, The Pollution Being Churned Out by AI Data Centers Is So Severe That It’s Almost Incomprehensible by Victor Tangermann.

Please, I Beg You, Do Not Fill My TV With Pregnancy Ads by Victoria McNally—associate editor of AdExchanger. (Marketing people know that this stuff is creepy as hell, and counterproductive for the brand, but they’re so cohesive as a group that it will take a swift kick from outside to stop the slide into chickenization.) Related: Where Did It All Go Wrong For Agencies? by Brian Jacobs.

Google’s new use of IPs in Europe by Alan Chapell. Hooray, Google imposes yet another compliance tax on companies using their services. Accordingly, anyone running a third-party CMP supporting Adsense must surface Feature 3 in Google’s vendor entry before August 3 or risk understated-disclosure exposure and limited-ads degradation (not to mention legal liability). (Somewhere in Mountain View, Google lawyers are passing the bong and laughing their asses off about being able to make people do all this stuff. I got it, I got it, make them quack like a duck next, they’ll totally do it!)

Meta’s AI advertising dreams have become a nightmare for brands by Lara O’Reilly, Sydney Bradley, and Lucia Moses. Meta is pushing advertisers to use its AI tools — and results are proving chaotic: strangely twisted limbs, gibberish writing, or entirely changed products. Meta’s response to brands: That’s on you, not us. (Don’t worry, when Meta takes control of how the ad results get measured across all media, these ads will turn out to be the best ads ever.)

22 Jul 2026

The attribution cartel is in Digiday, in a series by Ronan Shields.

I’m quoted, about the proposal’s biggest privacy problem.

“You get this paradoxical increase in user privacy risks, because the proposal obfuscates and rewards attribution fraud,” he told Digiday, adding the proposal’s current guise actually “creates more incentives to collect more data on more people in order to sneak ads in front of those who are about to buy anyway.”

And so is Angelina Eng, formerly VP of measurement at Interactive Advertising Bureau (IAB) U.S.

“There is no one-size-fits-all solution, and there is always customization,” she explained to Digiday, urging the importance of the ability to slice and dice data across time periods and portfolios without browser-imposed constraints or privacy budgets limiting combinations.

(The “privacy budget” feature is part of how “structural advantages” to large scale are built in to the proposal.)

So if both the free-range privacy nerd (me) and the adtech measurement expert executive are against the attribution proposal, could that mean that the attribution cartel is doing something right?

Unfortunately, no. The big companies in the middle are just taking such a big bite that it’s unacceptable to both ends.

Adtech people and privacy nerds are on opposite sites on a lot of issues, but fundamentally most members of both groups are proponents of decentralized decision-making. Markets, stigmergic learning, competition, all that good stuff.

The Big Tech companies are approaching the problem differently. In the surveillance oligopoly model, prices—instead of acting as an information-carrying medium—serve only as an output of an ML system that collects data from both buyers and sellers. The operator of the ML system can sit back and collect all the consumer surplus (which is really the only source of revenue remaining that’s large enough to justify all those data center investments, just saying).

meme version of this blog post

There is well-known criticism of economic central planning, but every so often someone predicts that this time it will be different, and central planning will totally work because now we have better information technology for central planning. This time, that supposedly enabling technology is “AI.” The Attribution proposal is not an economic central planning platform all by itself, but it’s a step toward the cartel members’ planned economy goal. Instead of a variety of advertising decision-makers evaluating the performance of different ad media for different purposes and different audiences, the cartel will be able to provide one centralized report, which will, of course back up the placements made by its own algorithms.

My view is that advertising should be an economic signal between independent players in an economy. Cory Doctorow summarizes the other side of the argument as “Facebook has built a mind-control ray out of Big Data, and we can sell anything to anyone”.

So it’s not a surprise that adtech people and privacy people are on the same side on the attribution cartel issue. If the atttribution cartel can be beaten—and it can, the freedom-loving side beat the Clipper Chip and the Fritz Chip and this time they don’t even have a chip—then the privacy nerds and the IAB can go back to arguing about cookies and stuff in the context of a market economy. I’m looking forward to that.

Bonus links

LG to Ban Residential Proxies from Smart TV Apps by Brian Krebs. App makers looking for ways to monetize their creations can turn to residential proxy providers, which pay developers to include SDKs that turn the user’s device into a residential proxy node that is rented to paying customers. In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and file utilities.

Apps targeted at US troops contain Chinese and Russian code by Dell Cameron. The largely unregulated advertising industry that tracks Americans online treats civilians and service members mostly the same—unless there is profit in telling them apart—despite evidence that exposure can reveal troop deployments, unit movements, and the routines of personnel within intelligence facilities and hardened shelters where nuclear weapons are believed to be stored. (Also a risk for defense manufacturing workers, utility repair crews, and first responders: Surveillance risks and the TIDALWAVE report)

21 Jul 2026

I have been starting Firefox with temporary throwaway profiles (for research and testing purposes), and wrote this to make it a little faster.

Based on the article Bypassing the Profile Manager from MozillaZine. This is the “unlisted profile” feature.

And the temporary profile directory gets cleaned up when the script exits.

Bonus links

The Python you learned isn’t the Python that exists today. by Reuven Lerner. Covers dataclasses, collections, and even gets into uv which I have not tried yet. (So far I’m getting by with whatever Python modules are packaged by the distribution.)

What the World Should Learn from Australia’s Social Media Law by Ravi Iyer, Jonathan Haidt and Zach Rausch. (Have you ever seen a Big Tech big shot sending their kid to an expensive private school where they get extra social media time?)

We Need Modern Car Equivalents To Those Old ‘Twin Cam’ Badges And Luckily I Have Some by Jason Torchinsky. Here’s a good idea: if you are stuck with a car that uses some kind of miserable subscription service so you can have access to things like heated seats or whatever, may as well let everyone know your pain, right? Put that shit right on the back of the car!

US Companies Are Realizing That Chinese AI Models Are Way Cheaper, Ditch American Ones by Frank Landymore. Meanwhile, China Is Cracking Down on AI Companions Because Not Enough Babies Are Being Born by Maggie Harrison Dupré.

Gen Z is pushing back against AI – a reminder to all of us that the future isn’t written by Siobhan Lyons. Speaking at the University of Central Florida, property developer Gloria Caulfield declared AI is the next Industrial Revolution. The humanities graduates, already burdened with debt and job insecurity, responded with a torrent of boos. Former Google CEO Eric Schmidt and Big Machine Records CEO Scott Borchetta were also booed as they sang the praises of AI at graduation ceremonies. Their bemused reactions reflect a growing generational divide when it comes to AI adoption.

The Slop Doctrine by Alice E. Marwick. While Republicans and Democrats are growing suspicious of AI at roughly the same pace, right-wing politicians and influencers have embraced AI slop in a way that the left has not. Why?

Meta glasses celebrity backlash: the fans hate them by David Gerard. Related: The Backlash Is So Strong That People With “Pervert Glasses” Are Afraid to Use Them in Public by Maggie Harrison Dupré. (ICYMI: Maggie Harrison Dupré author RSS feed on Futurism)

15 Jul 2026

previously: A BATNA for MyTerms

Looking back at the history of the IT industry, it’s possible to find instances where vendors did to their customers some of the same kinds of shenanigans that oligopoly companies are doing to everyone today.

An early example of paleoenshittification was the decision by Sun Microsystems to remove the C compiler from its Solaris operating system. An OS, as a two-sided platform for developers and users, is in a position to do the enshittification cycle, and Sun did it early. The Unix software scene was the subject of an enshittification run long before artists and writers experienced one on Facebook. Sun tried to get people to pay to rebuild their own C programs long before Meta tried the same for reaching people’s own audience. Yes, many Solaris users started paying for the compiler that they used to get with the OS, but others were able to slip out of being caught in first-stage enshittification—maybe because old-school Solaris didn’t have the infrastructure, licensing, or anticircumvention law to lock out or put a toll on other compilers. The removal of this key development tool was one of the key events in the popularization of a copyleft-licensed replacement, gcc. More info in Nick Moffitt’s $7 History of Unix.

Without that move by Sun, and other attempts at enshittification of Unix, the software freedom movement and open source software business might never have gone mainstream. So for those who dig rhyming history, it’s tempting to make the analogy: MyTerms and the tools that support it are to the enshittifying web of today as the GNU licenses and tools were to Unix. But the rhyme needs to hang together. The GNU tools were initially distributed first on tape, then CD, in a convenient form for building and installing on existing Unix systems. The “autotools” that mystify the developers of today were a pragmatic response to the need to work with what’s there in order to get adoption.

Today, IEEE, IAB, and W3C are all trying to address similar problems with how personal information gets used on the web, and everybody has gaps. The winning approach will be the one that can best embrace, extend, and ameliorate where necessary, the other two.

That starts with understanding the territory.

MyTerms is not unique in offering an automated way to do the paperwork necessary for processing personal data. On a technical level, data collection on typical web sites operates not directly under control of the site ToS, but using an Interactive Advertising Bureau standard called GPP, which stands for Global Privacy Protocol. (Not to be confused with GPC or GPL.)

GPP is an existing machine-readable way—with open source documentation and sample code—for browsers to tell sites that

  • the user in in a jurisdiction that requires consent, and consent has been obtained

  • the user is in a jurisdiction that recognizes opt-outs, and no opt-out is in effect

  • the user is in some other jurisdiction, do as thou wilt shall be the whole of the law

And all of those options can apply to a bewildering grid of purposes and vendors.

Although MyTerms relies on contract instead of consent, it solves a problem that from the company point of view is already solved. Companies that process your data already have machine-readable permissions that they rely on to process your data, because they already check GPP.

From the company point of view, there is zero reason to check MyTerms for permission to do something that GPP already says is allowed.

So the path to adoption for MyTerms has to account for the widespread existing reliance on GPP. MyTerms can de-enshittify your web experience, but can’t get adopted everywhere all at once, any more than C programmers could go from proprietary Unix to a complete “GNU System” of all freely licensed software all at once.

We have to look for key influence points to work with what’s already there.

Fortunately—because GPP is open source, along with a bunch of handy tools for working with it, it will be pretty straightforward for MyTerms implementations to also support GPP.

Detect sites where GPP is in effect and modify any consent or no-objection entries that are obviously in conflict with the MyTerms contracts that the user is willing to accept. This means a little extra work is required to map the MyTerms licenses to the permissions that can be expressed in GPP, but when that’s done, a new MyTerms user can start getting value from their MyTerms tool even on non-MyTerms sites.

That would leave the MyTerms/GPP hybrid providing more privacy protection than GPP as deployed today, but not delivering the full benefits of MyTerms—kind of like how installing GNU tools on Solaris solved the immediate problem of building C programs, but you still needed a licensed copy of Solaris to run them. But it gets the MyTerms situation from (stable, no MyTerms) to (unstable, some MyTerms) on the way to the full MyTerms stack. For sites, the decision to adopt MyTerms would go from no effect to a better option than just MyTerms to GPP (lossy) encoding. And users could get a similar immediate benefit to what Rewarded Interest offers—the confusing, annoying “consent” dialogs disappear.

More: 1,741 partners

Related

Rewarded Interest is taking a similar approach, in a way. Making the “consent” dialog go away is an easy-to-explain benefit for users.

Some people will be more satisfied with the Rewarded Interest approach (share an identifier I control, make the ads personalized, try to get me a piece of the action) and some will be more satisfied with MyTerms. The status quo, where nobody quite gets what they want and everybody has to click an extra thing, is a distant third.

Bonus links

The Reverse Information Paradox by Satya Nadella. (Sharing data enables the recipient to compete with or work against you. Probably kind of an obvious point but news to see the CEO of a company with “cloud computing”, surveillance advertising, and “AI” businesses making it.)

In the Social Ban Era, Where Will Gen Alpha Spend Time Online? by Amy O’Brien. (Generations aren’t cohesive, and this one is split along the AI-maxer/AI-hater fault line along with all the others.)

13 Jul 2026

Normally when I go on about the attribution cartel I try to focus on the privacy problem, because even though the anticompetitive side is important, some antitrust regulator somewhere will pick up on it eventually. And this is not a situation where antitrust and privacy are in tension. As Robin Berjon wrote, Competition & Privacy: It’s Both Or Nothing.

Sometimes, though, I’m just all, damn, dude, you said that part out loud? The Big Tech companies have corporate training for talking about doing crimes, but it looks like Mozilla doesn’t have their own Stringer Bell, and ends up taking more “notes on a criminal fuckin’ conspiracy” than the other cartel members would probably like.

In an interview with Martin Thomson from Mozilla about the W3C Attribution API, Alan Chapell asks,

Critics have indicated that the privacy-budget mechanism favors large platforms whereby a single mistaken query can lock a small advertiser out, a constraint only a dominant firm could enforce. Does the design assume a power imbalance between platform and advertiser, and if so, does it entrench one?

And the answer is one that I’m going to archive just in case.

I want to acknowledge that this is one of the hard parts. Large platforms have more data to use, so they are able to slice that data in more ways than the little guys. With noise, you can’t slice what you get into thousands of pieces unless you have many thousands of people involved. Or, more likely millions. Small players need to be more careful and make fewer queries. And a mistake will wipe out more of their potential learnings as a result.

On top of that, big players will be better able to develop the discipline necessary to get more out of the system. More people, more resources, all that.

We spent a lot of time thinking about this problem. But we concluded that this was one area where attempting to levy a technical control was unwise. Competition law — as ineffective as it has been in stemming the rise of monopoly power in this market, and others — has a better suite of tools available than we do.

Right now, the best I can say is that there are no structural advantages provided to large players, other than what they obtain naturally. I understand that this might be disappointing, but it’s the pragmatic outcome in this case.

Let me check my notes here. Nope, not one of the members of the attribution cartel is Mother Nature. The “obtain naturally” has nothing to do with nature as we know it—it’s a reward to scale that results from the design of the attribution tracking system.

Oligopoly is hard-coded in—as a result of decisions made by and for the oligopoly companies. And of course it’s “pragmatic” for those who already dominate the online advertising market to design a system to keep dominating it.

When not to use the feedback sandwich

How did things get so far? Part of it has to do with the way that people responded all professionally to Google’s “Privacy Sandbox”.

The “feedback sandwich” (say something nice, make your critical point, say something else nice) is appropriate for many business contexts, but not that one. An intern who puts their private key in a script needs to be handled differently from a transnational corporation doing a multi-year plan to extend its market dominance. But every “Privacy Sandbox” op-ed was basically in the following format:

  • Super stoked that Google is exercising such great leadership in privacy. All hail Google’s wisdom!

  • Maybe Google is doing some tiny little crime that they could maybe think about doing a little less, or if not that’s fine too

  • We look forward to doing free QA work for Google to test every morsel of code that drops down to us from on high.

(Yes, I wrote some stuff that ended up getting squeezed into this format, and no I don’t have the pre-edit versions, they’re in document history at a former employer.)

That whole saga set a bad example. Sometimes an “open source project” is a bona fide open source project, sometimes it’s the form of an open source project on top of a scheme with existing goals that are incompatible with the public interest. Think before you click.

Bonus links

Tech billionaires are shielding their children from the products that made them rich by Marco Quiroz-Gutierrez. (This is not just billionaires. Also applies to regular programmers, data scientists, and managers.)

Do Smart Glasses Have a Surveillance Problem? by Amy O’Brien. (Good example of social fragmentation I guess—I don’t know any group or space where Meta glasses are considered appropriate.)

12 Jul 2026

Apple as a company has a lot of advantages. They have their pick of

  • retail locations

  • suppliers

  • employees

Whether they want to hire an engineer who can design an efficient, safe power supply, or get the exact right countertop for the company’s convenient location right in Grand Central Station, Apple has more optionality than anybody. But the one place that Apple is on an equal footing with the rest of the industry is the owners. Investors want “number go up.” So enshittification comes for everyone.

In John Ternus Should Reverse Apple’s Slide Down the Advertising Slippery Slope, John Gruber writes,

Here in 2026, search results in the App Store not only show paid ads — frequently for casinos — but the search results are visually dominated by paid ads now that Apple has added a second ad to results. Apple News+ is a paid subscription that offers a genuinely great value for the number of paywalled publishers whose content it includes, but articles on the News app tend to include the weirdest AI-generated ads on the Internet. (How many young blond women am I supposed to believe need hearing aids?) And — at this writing, still “coming soon” — Apple is launching ads on Apple Maps. Apple Maps remains free of charge to use, so according to Tim Cook, we’re not the customer. We’re the product. Or, if you prefer, our frustration is the product.

He makes a strong case that Apple needs to back off on the ad revenue squeeze. People will see the ads and assume that Apple is doing the same creepy, risky stuff that Meta and Google do.

So let’s just concede that the upcoming ads in Apple Maps are completely private. How many users are going to believe that? Or assume it? I think very few. People see ads and they think “I’m being tracked.” When Apple starts showing ads in Maps, many — perhaps most — users are going to think they’re being tracked by Apple and their location “is being sold” to advertisers.

That’s true. People are creeped out just as much by “privacy-preserving” ads as by the regular kind. It’s not just anecdotal.

But there’s one part missing. It’s not that Apple’s privacy math wizards are right and the users are wrong. The “Privacy Preserving Ad Measurement” that’s built into Apple Safari (the setting for it is hidden under “Advanced” which should be a red flag) is privacy-preserving only if you analyze it as an isolated math problem. Like the W3C attribution cartel proposal, the Apple feature gives dishonest players an incentive to “snipe” the reporting by serving ads to Safari users likely to buy soon—and the best way to pick those likely buyers out from the crowd is with extra, riskier tracking.

This whole situation is another good example of how regular people are better applied behavioral economists than Internet Thought Leaders are. And the latter group is increasingly out of touch. (While high-profile LinkedIn posters are shocked about what they see as the new-found uncertainties of Big Tech jobs in 2026, the content moderators, search quality raters, drivers, and other “TVCs” have been living the precarious employment dream for a while now.)

So John Gruber is half right. Apple can keep a premium position, and win in the long run, by losing the shitty ads—which are seen by their customers as a dirty business with no place on a high-end device. But that forward-thinking decision would not just be sacrificing a real privacy technology for PR purposes. The so-called “privacy-preserving” ad tracking systems have their own risks, and need to be regulated appropriately.

(Quick tip for John Ternus. If you do zorch the ads to make the device feel more like the experience of an Apple Store and less like the last days of Fry’s, the enshittification pressure from the investors will return soon enough. But if Apple can switch out CPUs you should be able to smoothly swap out the owners, too. Take advantage of the fact that you make the best all-around personal finance device, add a “buy stock” button—and hook it up to buy a share that has extra voting rights but pays all dividends in store credit. Align the interests of owners and users enough to resist the pressure to festoon Apple products with ads or whatever other awful growth hacking thing starts trending next.)

Bonus links

You’ll Own Nothing and Be Happy: Why It’s So Hard to Break John Deere’s Control Over Farming by Matt Stoller. (Maybe the 404 Media story on right to repair was too good to be true?)

Mastodon, The Only Good Choice by Tim Bray. Why does email stay reasonably healthy? Because nobody owns it. Anyone on any server can communicate with anyone else on any other….Mastodon’s like email that way. Plus it does all the Post and Repost and Quote and Follow and Reply and Like and Block stuff that you’re used to, and there are thousands of servers. (Like email, the spam filtering and other moderation decisions get made in a decentralized way, so it’s possible to have a Mastodon experience that’s hella worse than Big Tech “social media” too. But read the whole thing, I’m happy to help people get started.)

Valve Explains Why It Doesn’t Subsidize Its Hardware Platforms The traditional console model is to sell hardware at a loss and make up the revenue with subscription services or by selling games that are locked-in to the hardware, reads part of Valve’s blog post. We think this can make sense for a single business in the short term but that open ecosystems are better for customers over the long term. (Seems like some of the locked-in console brands are having drama—the Steam Machine looks more future-proof.)