764 points•lmbbuchodi•10 days ago•395 comments•

395 comments

thih910 days ago
I am once again happy that the EU is fighting practices like these via legislation.

Some outcomes can be annoying, but the net result is still positive, for the consumers and their data privacy at least.

dmix10 days ago
The adtech/data broker business is still very lively in EU. The last time I read into it a year or two ago the consensus seemed to be the privacy gains over the last decade have been modest at best. There was a few big name trackers that were forced to narrow data collection but the general ad/location tracking and data broker business is still mostly the same.

https://arxiv.org/abs/2411.06862

https://netzpolitik.org/2025/databroker-files-targeting-the-...

singularity200110 days ago
Do the big guys sell to the small guys? Like if I'm a shady small company trying to buy as much information as I can about a certain user, will I freely get the data from X and Facebook and Google?
buzer10 days ago
There are multiple reasons for it. One of the major issues is that some DPAs pretty refuse to enforce GDPR (e.g. DPC in Ireland). Hopefully the changes to cross-border enforcement that are coming in force next year will help with this as it at least has some deadlines unlike currently.

Another issue is that controllers generally do not need to change their behavior before the final lawful decision which can take a lot of time to go through the court system, especially if it needs CJEU referral. And once the decision comes in force they can often make small changes and restart the whole process.

Also another issue is that DPAs do not often initiate the investigations themselves (unless breach is involved), they only happen at the request of data subjects and not that many people bother making complaints or follow them up. Just yesterday I had to follow up with 9 page reply to the controller's response to the DPA inquiry.

Additionally ePD and GDPR enforcement is sometimes split between different agencies. In those cases GDPR agency tends to wait for ePD case to be solved before investigating the GDPR aspects, often because the ePD consent validity will affects e.g. GDPR legal basis analysis.

thih910 days ago
Perhaps, perhaps not. Big trackers reducing data collection is a win in my book. OpenAI is not doing ad personalization for the EU customers. There are no Flock cameras.

It’s an ongoing fight for sure but it’s some fight at least.

fooker10 days ago
> Some outcomes can be annoying

I'd classify mandatory encryption backdoors as an industry crisis rather than an annoyance.

dspillett10 days ago
Which has nothing to do with the stalking of the adtech industry, unless you are suggesting that the EU might sell access to the keys to the likes of OpenAI?

[though you are not wrong that encryption backdoors are a backwards step on individuals rights to privacy]

patrickmcnamara10 days ago
When has the EU mandated encryption backdoors?
jampekka10 days ago
> I am once again happy that the EU is fighting practices like these via legislation.

As long as you manage to navigate all the dark patterns and not accidentally give your "informed consent".

dspillett10 days ago
Malicious compliance (or as it more usually is malicious noncompliance that has not been sufficiently punished so the slimy buggers feel free to continue) is something you should blame the stalkers of adtech for, more than the EU. The legislators could perhaps have made the definitions less wavy, and been harder with enforcement, but that doesn't make it all their fault.
einpoklum10 days ago
Is it now? Are Alphabet, Microsoft, Yahoo and Meta's platforms and call-home products illegal for exposure to EU residents? i.e. Google, Bing, Facebook, WhatsApp, MS Office and such? Are these companies' C-suite people wanted, to be charged massive breaches of user privacy?
ljm10 days ago
Seeing some legitimate executive accountability would be lovely in this day and age, but even fines going into the billions of euros are still just the cost of doing business in a ridiculously lucrative space. That they also happen to dominate by oligopoly.
mavsman10 days ago
To me, this quote just about sums it up:

> The mechanism is standard adtech. What has no precedent is running it on an AI chat product.

As someone who has been well aware of this mechanism for quite some time, I still feel icky anytime I re-read the details of it.

What a time to be alive.

jsrozner10 days ago
People think they're interacting with an "intelligence," when actually they're just getting a maximally optimized Weizenbaum feed. We're living through the sloppification of the human mind.

See e.g., https://www.science.org/content/article/ai-chatbots-are-beco...

brianleb10 days ago
Could you define (or link) to what "Weizenbaum feed" means/references? Too obscure for me but I'm interested. Thanks.
trial310 days ago
humorously, my regular iPhone on a residential home network failed the cloudflare AI bot detection and i can’t read that article
anigbrowl10 days ago
You're in for a big disappointment when you interact with People™
gxs10 days ago
Or both, you know. An intelligence that also spies on you

Why is it so black and white?

ben_w10 days ago
What's the old quote from WW2?

  I couldn't help but notice how each successive headline reporting our glorious victories seemed to draw closer to Tokyo.
Something like that.

Well. I can't help but notice how each successive headline reporting how this "scam"/stochastic parrot/"scare quotes intelligence" seems to be solving more and more things that were but a few years ago widely regarded as being indicators of high intelligence.

Being highly convinving is one of the things on that list.

clickety_clack10 days ago
Whenever I say something like “that’s a cool feature, but to do it you would have to build spyware”, everyone else is just like “the cat is out of the bag ¯\_(ツ)_/¯”. (I don’t build spyware, or work on projects that do).

It blows my mind that people don’t care about the world they are building with this stuff. It’s a real tragedy of the commons. People see these collaborators from different wars and regimes and think “I’d stand up against the bad guy”… well I’ve got news for you if you build spyware, you are not the person you think you are.

kltlp10 days ago
This is the best retort to the bag-escaping cat ever:

https://gowers.wordpress.com/2026/09/17/why-i-didnt-sign-the...

"Nothing is worse to the demise of a society, than people who want to convince you that the cat is out of the bag and will not go back in, while the cat is being violently shook out of the bag at the same time."

mat_b10 days ago
> It’s a real tragedy of the commons

Seems more like a real tragedy of private enterprise.

We used to assume that the surveillance world would be built by government (1984). But it turned out to be equally likely to be built by the free market.

bluefirebrand10 days ago
> It blows my mind that people don’t care about the world they are building with this stuff. It’s a real tragedy of the commons.

When I ask people about things like this, I hear a lot of "If I don't build it, someone else will"

My goal isn't just to refuse to build this stuff, it is actively to resist the people who are.

I don't have much influence though

mitxela10 days ago
Well, some people care and some don't. The people who care don't get to work on the technology.
brookst10 days ago
I'm pretty unhappy with this, but are ChatGPT or Facebook really "the commons"?
saghm10 days ago
Yeah, this is just standard third-party cookie functionality, which has always been sketchy. It honestly seems like it was only possible by accident; browsers have long prevented sites from reading cookies from other domains, but it seems like the people working on early specs might not have considered the ramifications of being able to set cookies for domains other than your own. A couple decades ago it might have seemed like no one would have any reason to set a cookie they couldn't read.
hansvm10 days ago
Maybe 3 decades ago people had excuses, but the latest decade of cookie abuses have been designed by people who not only knew better but who took that better world into account as they buried it away from the general public. The fact that half a million developers think CORS is a server security measure isn't an accident.
gloryjulio10 days ago
A lot of the Meta/Google folks jumped ship to Openai/Anthropic. This kind of work is expected
cma10 days ago
> What has no precedent is running it on an AI chat product.

Meta?

luke544110 days ago
MDN lists how different browsers prevent this: https://developer.mozilla.org/en-US/docs/Web/Privacy/Guides/...

Firefox, Brave and Safari do. Chrome and Edge do not.

mokre10 days ago
That’s not fully protect you. They still can match short living third party identifiers with their domain cookie or device_id from app. It is not 1-1 matching but works relatively good with modern itp.
luke544110 days ago
This would work for an ad shown on ChatGPT and then clicked on (or in the ChatGPT app).

But it would not give ChatGPT information about which other sites are visited.

Of course there would be non-cookie options like fingerprinting (also via IP) that would allow tracking non-the-less.

So you might be talking with OpenAI about your marriage problems and then based on the IP the OpenAI ad network would start showing ads for divorce lawyers on unrelated sites you browse to that display ads.

The solution to that would be using a VPN.

skybrian10 days ago
Not an accurate summary. That link actually says:

> Google Chrome doesn't block third-party cookies by default, only in Incognito mode, or when users explicitly set it to block third-party cookies via chrome://settings.

Looks like the settings let you block all third-party cookies and add exceptions for specific sites, which seems a bit awkward but could be made to work.

Alternatively, you could run OpenAI in its own profile, or look into what extensions might do.

gruez10 days ago
>Looks like the settings let you block all third-party cookies and add exceptions for specific sites, which seems a bit awkward but could be made to work.

The fear over blocking third party cookies breaking stuff is severely overstated. I have it disabled by default and I don't think I've ever seen any website breakages. The most is office365 nagging me to click on links so it can authenticate across domains.

troupo10 days ago
> Google Chrome doesn't block third-party cookies by default, only in Incognito mode

And the focus on cookies only is also intentionally misleading. Tracking is not just cookies. Chrome will track you in Incognito mode.

nicce10 days ago
I think that if they don’t block by default, is quite significant. Chrome + Edge has superior marketshare and then add the % people who have no idea what these mean and don’t change defaults.
zulban10 days ago
Not sure what point you're trying to make. Do you think politely asking an ad company to disable ads on their browser is a reasonable thing to spend your effort doing?
Andrex10 days ago
I was going to say, wasn't this supposed to be the default in Chrome by now? But Google reneged on it two years back:

https://www.cbsnews.com/news/google-third-party-cookies-chro...

This disgusts me more than any of their recent news. There needs to be a lot more pressure on them to phase this out.

Maybe this article will be the small snowball that gets that started...

wodenokoto10 days ago
I know people use chat bots differently and I get that companies see value in personalization, but to me it is extremely valuable that I can start a chat without context.

When researching a topic a chatbot can be quite sensitive to certain wording and those can end up steering definitions. Two context free chats on the same topic can go in very different ways depending on how you word things, but when using the notebook feature in Gemini, where every chat becomes part of the context you completely lose the ability to discover if a topic is vaguely defined or have many definitions.

1e1a10 days ago
I never want my new chats contaminated with information from previous sessions for this exact reason.
abustamam10 days ago
2 context free chats can go in very different ways even with the same words sometimes!

I personally like the option to have context free chat or chats with memories. What I dont want is a chat based on memories that I didn't explicitly consent to (ie browsing history etc)

Yhippa10 days ago
My usage of incognito chats using prompts from other sessions has gone way up. I'm tired of it doing the "you're absolutely right" bit for every new piece of information I bring and it completely trying to donate U-turn.
demibabs10 days ago
I feel like having any existing context absolutely poisons the ability to go in a different direction. I’m not sure if there’s a good way to fix this.
duhhhhh121210 days ago
https://www.pangram.com/history/c3ad864f-2a50-4785-a0ef-71f2...

why not use your own words? If you are gonna ai generate this blog, just post the prompts instead.

handoflixue10 days ago
There's a certain irony in linking to someone else and then saying "use your own words". If we follow that, we get a pretty obvious answer: sometimes someone else can express it better and faster.

Most people do not, in fact, want to read raw prompts.

crmd10 days ago
It’s misleading to post model output on a blog, especially when the about says

> This blog is where I write about what I find.

Why not simply include a disclaimer that it was AI model output not his own writing? Because humans don’t like AI writing and the article wouldn’t be featured on as many tech news sites. Hence the sin of omission, the choice to mislead.

scared_together10 days ago
Are you referring to the Pangram link? I’d consider that akin to a reference supporting the comment’s point, not a substitute for the comment’s point.

> Most people do not, in fact, want to read raw prompts.

I wonder if this is really true, and if it will remain true for long. Have you observed someone read another person’s raw prompt? Or observed someone submit both their prompts and their LLM output for review?

Personally I’d be curious about the prompts for a lot of top HN articles which are LLM-generated. It would say a lot more about the human operator’s intent and thinking process compared to the LLM output.

A coworker who spoke English as a second language once screen shared their Claude session during a code review, and it was interesting that their prompts were all in their native language. The guy wasn’t writing an article, and I didn’t understand the prompt anyway, but I still found it interesting as a glimpse into how he uses LLMs.

For this particular article, if the prompt was initially a series of bullet points that wouldn’t be so bad. If there were multiple prompts spent editing and rearranging the article that would be an unusual work by pre-LLM standards. However I’d suggest that instead of dismissing the idea, we could embrace “raw prompts” as a kind of new medium, to cross the divide between pro-LLM and anti-LLM readers.

nicce10 days ago
> Most people do not, in fact, want to read raw prompts.

I also wonder what is the energy consumptiom difference between the prompt and fetching website.

devilsdata10 days ago
If you can't be bothered writing it, why should I be bothered reading it?
mannanj10 days ago
I'd rather read raw prompts. Most people can consume the slop if they wish.
abhis379810 days ago
How is this adding to the discussion? The post in itself is quite informative.
duhhhhh121210 days ago
Do you constantly want to be reading ai-generated content on this site? If so, why not just stay on chatgpt.com and ask it to generate what hackernews.com would look like today? It's adding to the discussion because I feel like the author broke a social contract by probably putting less effort into writing this than I did reading it.
Sharlin10 days ago
Having an LLM generate major parts of text that you (implicitly or explicitly) claim as yours is dishonest and plagiarism and should be brought to readers' attention, and it baffles me that many people just don't seem to mind or see anything problematic about it.
siquick10 days ago
> just post the prompts instead.

Why would anyone want that?

duhhhhh121210 days ago
Because I want to read the author's words, not claude's, chatgpt's or grok's.

Note to folks who have this same thought (seems like many given other comments). Why are you on this site if you aren't here for human-created content? If you want AI generated blogs/posts there are plenty of sites like linkedin, twitter, chatgpt, and claude that will give you meaningless content with a press of a button.

ljm10 days ago
Why would you want n people to compute an AI prompt independently instead of reading the output once? And why would that be better?

At least criticise the article on merit and not some 'let me google that for you' high horse. If it's slop it's slop, but let the votes speak for that.

xmprt10 days ago
> OpenAI's ad collector at bzr.openai.com sets a cookie called __obi, scoped to .openai.com

This sentence is way too much detail and it's literally the first thing you read. I can pick apart most of the sentences in the article. Another one:

> Across 932 decoded sync tokens, 736 carried subject_type: account_user and 196 carried anonymous

This sentence is pointless. What matters to proving that "It works when you are logged out" is to show that the identifier is stable. Why does the reader care about the actual counts.

AI has a tendency to do this which makes AI generated text a lot harder to read. The raw prompts likely don't have the specific websites and cookie names because that's not relevant to the reader or writer for that matter - it's a footnote at best.

scared_together10 days ago
Not everyone would actually send the prompt to an LLM. Some would have the opportunity to see the prompt as its own artifact, devoid of LLM-generated “hallucinations”.

> let the votes speak for that.

The comment you are replying to got a fair number of votes too… Having somebody run a Pangram check saves n people the trouble of doing the same.

slig10 days ago
Why comment if you have nothing good to say?
angoragoats10 days ago
Hello Pot, I would like to introduce you to Kettle.

Read the full thread on Hacker News →

Related stories