Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's like my accountant reading my receipts to create my tax return versus a sleazy salesman sneaking a peek at them to find new ways to sell me stuff.


It's more like your accountant preparing your tax return for free in exchange for aggregating data about your receipts and offering you goods and services you may be interested in.


Let's split the difference. It's like your accountant preparing your tax return in exchange for using that tax return to develop a model of your spending habits. The value of this model is more than the cost of them doing your tax returns, and in fact is such that if you were simply to collect that data yourself, sell it on the open market, and spend a portion of the proceeds on the tax prep service, you would end up with profit, and the tax prep service would still exist.


> if you were simply to collect that data yourself, sell it on the open market, and spend a portion of the proceeds on the tax prep service, you would end up with profit, and the tax prep service would still exist.

Economies of scale; the market for that data would not exist if individuals collected it themselves to sell. Hence would break down.

Phrased another way; this data about 1 person is relatively valueless.

(I like the rest of your example BTW; just disagree with your conclusion)


> The value of this model is more than the cost of them doing your tax returns

It's likely the value Google got out of scanning your email wasn't worth that much in terms of modelling profiles for ads.

Probably because having both your search history and "anonymized" Google analytics, plus the sea of data that comes from owning Android is more than enough data that Google/Doubleclick needs.

From a purely capitalist perspective I'd bet the utility of them scraping this data no longer outweighs the privacy costs.

But at the same time Google is still scanning attachments for child porn and likely other data out of national security interests. And they still can access your data on a case-by-case basis which from a FISA perspective is a rubber-stamp away from accessing your data from 2 hops away from someone who may or may not have done something bad.

I personally will not weigh using Google vs any other email service in terms of privacy any different after this measure. But I still appreciate their efforts to reduce the "standard pratice" nature of scanning private email. If I do use anything Google-related I will not associate my personal identity in any way with the service, which is still requirement for Google play.

You can still use a fake gmail account and prepaid Google gift cards bought with cash to disassociate your identity from using the service. Although that's still well beyond the investment the majority of people are willing to make.

Regardless privacy comes at a cost these days. Good OPSEC > trusting cloud services privacy policy. You can either not use the services or invest in protecting your data when using them.

I will still cheer on Google's efforts to make those of us who care about privacy live's easier. I'm not naive enough to ignore how their business model works but that doesn't mean they always have to take the easy route and hand everything over without considering the costs - as many ISP/Telecom companies seem to do.


Eh? That assumption of "not associating my personal identity" doesn't actually work. Your profile IS your personal identity, and can be associated trivially. If not algorithmically, then via one connecting piece of information supplied by various databases and no such agencies. You're living in a dream.


> Your profile IS your personal identity, and can be associated trivially.

I'm hardly new to his stuff and to say it's trivial is nonsense. Most people make it trivial but it's not trivial to associate identities of people who put basic effort into obscuring them.

Merely disconnecting your primary profiles from your online activity is enough to throw most mass-surveillance/drag-net stuff off, aka 99.9% of advertising firms and most government programs.

If you're an activist or someone interested in keeping your internet activity private then the bar is far higher (and the targets of which are ever expanding as governments and private organizations get better at this stuff). FBI agents, or likewise in your country of residence, have plenty of forensic tools at their disposal to connect disparate identities. It takes some real time investment and requires being super careful to evade these measures. But I'm not talking about that here. I mean the average person in 2017.

I've personally done the total anonymity stuff as an experiment so I know what that takes.

Having studied many documents from the various global national security organizations and being fortunate to have dated a defense attorney in the past who engaged with police surveillance reports on a daily basis for their work I'm convinced that even basic privacy measures such as never using your real identity when using internet services, creating full legitimate sounding backstories (and subsequent online profiles) for your fake identity, and changing the ID you use often enough will throw off most basic surveillance measures.

I'm not doing anything to get people really invested in uncovering my online identities, as most people aren't, which is what I'm talking about.

The simple fact is the vast, vast majority of people reuse the same username (and passwords) across the internet and use their real name and emails everywhere. So it's really not hard to track people online from an LEO or 4chan doxxing perspective.

But I'm not convinced you have to be isolated from the utility of most online (cloud) services. You just have to invest in using them intelligently to not associate your actual identity with the services.

Ad companies aren't interested in deanonymizing people anyway. They are looking for low hanging fruit and there are more than enough people to fill databases who fit this profile. So I'm not that concerned about those who don't.


It's not trivial to match any arbitrary profile with an offline identity, but it is possible to cluster pseudonymous profiles into "almost certainly the same individual" by patterns and peculiarities in how they use their devices. If the same patterns later show up for an identified user, they can be linked with high probability.

With the sites Google runs plus running their own JavaScript on a sizable fraction of other people's web pages, they can pick up a lot of patterns, many of which would be inaccessible to police and intelligence surveillance.

Some people have nervous habits like moving the mouse around, clicking/tapping on whitespace, scrolling up and down, etc. Some always/never use the scrollbar. Some always/never open links in new tabs. Some tend to put the adjective before/after the noun in their searches. Some will rapidly open up the first 5 search results in new tabs. Some always disable instant search, and some of those change their settings to 20 or 50 or 100 results. Some use search features like the calculator, searching for "weather", stock symbols, etc, and others never do.


> Ad companies aren't interested in deanonymizing people anyway.

Seems to me that there is a huge monetary aspect to matching online activity with real identity.

"deanonymizing" is trivial but ad tech is poison to any level of "privacy", filter bubbles and fake news propagation.


I disagree with you, but from the perspective that my email contains the history of every transaction I have ever made, all of the newsletters I sign up to, and, for another 3 days, ~50% of my conversations, since I do a good chunk of my communicating over gChat.

Consumer preferences change over time, so google is far more interested in the thing I bought yesterday than the thing I bought 4 months ago, so being able to read my emails is still a current interest of theirs.


Amazon's receipt emails stopped including an itemized breakdown. Perhaps this is for customer privacy or perhaps so Google can no longer scrape Gmail users' purchase histories.


True, but seeing as I often order one thing or two at a time, the email subject line from Amazon still gives away the goods


> if you were simply to collect that data yourself, sell it on the open market, and spend a portion of the proceeds on the tax prep service, you would end up with profit

Hmm. Could you sell it on the open market? If so--if the margins for the ad-supported model like Google's are in fact as big as they appear--why isn't there a Google competitor who provides exactly the service you describe: some kind of opt-in system where they collect data (via, say, a browser extension), sell it to advertisers, and pay you a cut?

One generic answer to "why does the market not offer [some seemingly reasonable thing]" is inefficiency: maybe there's some cartel system at work where all major advertisers are hoarding the revenue for themselves. But I find that pretty unconvincing, since the whole market _seems_ to be otherwise quite competitive, and with low barriers to entry.

Perhaps a more likely theory is that if you were to offer a "we pay you for personal data" competitor, you'd face massive fraud--a la click fraud--in which attackers would pretend to be real users in order to get paid for searching (or whatever), and that the subsequent need for identity verification would become so burdensome as to eat away any profits.

Anyway, an interesting thought exercise, but I think one can broadly conclude that either:

1. There are real obstacles to paying people the "fair" price for their data, such that the current system is in fact fairer than it appears. 2. The entire market is unfair due to a cartel or similar (though like I said, I find this fairly unconvincing). 3. This is a great idea and you're the first to have it, so you should start a company that does exactly this. ;)

No?


> Could you sell it on the open market?

surely the profit would be too small to fool anyone


Take a look at Basic Attention Token and the Brave browser.


Interesting. How do they protect against clickfraud, though? Paying the user seems to me (somewhat naively, because I'm not super familiar with clickfraud) to increase the incentive for abuse, since you don't have to run a malicious website to do it.

One of the obvious advantages of the Gmail model seems to me to be that free email is less fungible than cash, though of course abusers resort to spamming and other practices to monetize the resource.


I think this EXACT thing is what Credit Karma is doing with free tax returns:

https://www.creditkarma.com/tax


...Are you aware it would be quite a worthy idea, offering an accountant in exchange of business data?


No way that's true. The data is not worth as much as the eyeball on the ad itself.


gmail can still advertise to me in the hypothetical scenario above, but if they want to do so in a targeted way, they would have to buy my data from me first.


I'm sorry, I'm from Slashdot. Can you write this in the form of a car analogy?


> and offering you goods and services you may be interested in.

Sounds like a sleazy salesman to me.


> offering you goods and services you may be interested in

The thing is: never, not even once, has Google offered me an ad with goods and services I was interested in.


ok, maybe Gmail ads have been irrelevant to you. but surely you've done a google search and been presented with interesting goods and services?!?!


Anecdata: in the past 5 years or so the number of relevant or interesting search ads Google has shown me can be counted with one hand.

- If I'm searching for technical documentation, I couldn't care less about all the random consultancies or shitty-SaaS-of-the-day trash that populate the ad slot(s).

- If I'm looking for technical details on a piece of malware or vulnerability research, the last thing I want to see on the page is a goddamn AV junkware full-frontal.

- If I'm searching for details on some car models ... why the fk is google shoving insurance ads on my screen real estate?

And so on. As far as I'm concerned, online advertising is a stripmined toxic dump. Only the shittiest swindlers and shadiest extortion artists remain.


>- If I'm searching for details on some car models ... why the fk is google shoving insurance ads on my screen real estate? //

Brand marketing. It may not work on you, but it works in general.

Personally I consider myself pretty imune to marketing but when you think "who else should I check to switch my car insurance to" then that brand is going to pop up if it's been fed to your brain enough. Indeed when you're looking at a list of similar offers the one that's associated with a name you already know will seem somehow more trustsworthy, it's an insidious finagling of a brand in to your brain drip by drip. Why do they do it? It works.


The only times I clicked on those was:

1. the site was actually what I typed in the address but forgot to add .com etc

2. by accident


Here's a real life example. It's like Credit Karma who prepares your tax return for free, but then uses the info to help target you for ads on credit cards, loans, etc.

[this is exactly happening]


If its about offering me goods and services that I may be interested in, then ad blocking is a useful feature for both me and the advertiser. If I am not interested in any goods or services then no offering or aggregation is needed.

On the other hand, if its about offering me good and services which other companies want me to become interested in, then we have a different deal going on.


It's more like your accountant preparing your tax return for free in exchange for aggregating data about your receipts and offering you goods and services you may be interested in.

Hmm. I could actually see that working, as a spinoff of concierge services offered by companies like American Express.


can your accountant prepare your taxes without looking at your receipts? no. can webmail provider provide you email service without asking your emails? sure he can


how about:

my accountant preparing my tax return for free in exchange for... inviting ...a sleazy salesman [to] sneak a peek at them and find new ways to sell me stuff.


That's not very accurate. It's more like:

Your accountant prepares your tax return for free. They also have a lot of boxes of flyers provided to them by people who want to sell things. After preparing your tax return, they use their knowledge of your return to choose which flyer to put into the envelope. They then send that envelope back to you, and when you open it to read your tax return, there's a flyer for something else paperclipped to the front with a note saying "Thought you might find this interesting."

(In particular, the accountant is only one who sees the information in your tax return.)


Unfortunately for you the accountant uses an insecure lock on the office door.


if you accountant was a computer.

We have to stop this madness of thinking that "John READS my diary" means the same thing as "The function fread() READS nitems objects". Those don't mean the same thing except in a metaphorical sense. It's insane.


It's not about who reads it, it's about who has access. If a system has access to read my email as plain text, it means anyone who owns or can get access to that system can read my email.

Some one wrote fread, it could've been john, and john absolutely could be reading your email. Look at the what happened with ubers god mode.

That said the value of gmail for me exceeds the risk of people I care about reading my email getting access or having access. However my(and probably your) subjective view on the value of your emails is absolutely subjective.


Of course access is the important thing.

But then again, in the context of the story, it doesn't change anything. Google still has access to your email. That it is not "reading" for the purpose of ads is just a minor thing that doesn't impact your privacy/security in any way (in the terms that you are describing).


Probably easier to hack any other mail provider than hack into Google and own it so badly as to being able to read emails in plaintext.


Madness? - remember not long ago when unroll.me was selling your email data to Uber?


yeah, that's a horrible thing. But again, not the same thing as me reading your journal. I'm just claiming that you shouldn't mix those two things.


why does it matter? Google has access to read my email, and if they want (or are pushed to), they can single me out and then go and read them. Sure, 9/10 times it's a bot reading my emails, but there's nothing stopping them from doing it.


it matters exactly because of what you are saying.

You do have protections against someone reading your email at Google. Both from a expectation of privacy, but also from a company perspective. You also do have some non-expectation of privacy (if, for example, the US government wants to read your google email, they can ask for it and they eventually will).

The day someone with a brain and an opinion on Kim Kardashian at Google reads your email, there is a HUGE difference from when Google is "reading" your email for ads/spam/spelling/whatever.

You don't want to blur that line being wishywashy with language. You want to know that difference. The fact that it could happen is why you need that clear separation between "machine reading" and "a person reading".


> You do have protections against someone reading your email at Google.

And those protections are bullshit.

I have no guarantee that they are not reading my email. If a bot has access, a person has access, and people abuse their access all the time.

In fact, there have been cases of googlers reading peoples email. And I'm not blurring any line, I'm stating: Gmail can, has been, and will be abused. To pretend that is not the case is, frankly, naive.


I know this is cold comfort, but every single production data access is audited at Google, and that's after one signs more NDAs than you can shake a stick at to even get logs access in the first place. Each incident, with David Barksdale being the worst, has made them lock down logs, PII, and production access at a level unprecedented of any I've seen (including HIPAA shops).

You're correct that the possibility exists, but any Googler inhales heavily and makes sure their paperwork is in order before accessing prod. The warnings that are displayed are not unlike those when you're removing a nuclear core on a starship. It's scary. They want it that way. You need a damned good reason to even look at subject lines in the inbox (like fixing a bug involving subject line rendering that only appears with a user's specific subject line, for instance), and clicking a message is almost certainly a walk. Like, within the day.

They do take this seriously. I wouldn't call it bullshit. The protections I observed were in place before Snowden, so I imagine it's even more rigorous now.


I'm sure they have a lot of checks, but that doesn't really matter if:

A) they can be bypassed, as they have been in the past

B) they can be compelled to hand that data elsewhere

So I'm calling bullshit. Until it's impossible for them to look at my data, then they aren't taking it seriously.


You're calling bullshit on what, exactly? I'm providing you perspective on the very thing you're hypothesizing about from firsthand experience.

What is your technical solution for operating Gmail without any Googler having the ability to access some aspect of your data? It's email on the Web. Handling that e2e is pretty much intractable, and cleartext or nearly-cleartext with online keys has to exist somewhere even without the Googley things they do to data. I might posit that building a functional service with that requirement would be impossible for the Gmail case and many others (but I'm ready to be proven wrong).


>> They do take this seriously. I wouldn't call it bullshit. > You're calling bullshit on what, exactly?

really? your firsthand experience is nice, but your ignoring that those methods don't work.

> What is your technical solution for operating Gmail without any Googler having the ability to access some aspect of your data?

They can use any of the current zero-knowledge encryption methods. This isn't anything new and has been around for a long time. There's no need for Google to have those keys.

Encryption isn't a new problem for email, it's already a thing.


what's the use case you are worried about? Tell me a story. Who is accessing your date, for which purpose, when, how much, etc... and explain how Gmail is a bad solution because Google "can read it".

Yes, Google does not offer you protection against the Government. That is a true statement. But that doesn't mean that it's all or none. There are so many privacy rights before "a warrant request". And news flash, unless you are extremely good at securing your own mail server, even then you are not protected against a warrant.

Those checks are not bullshit. Every single security system "can be bypassed".


The use case is pretty obvious by now: people trying to manipulate me (ads), overreaching government intrusion, and invasions of privacy.

I never said that Google just sends everything over to them, but they can come and access my data without me ever knowing, and that's a problem. Just because there are (imo broken) checks in place does nothing to negate that fact.

Those checks are provably bullshit by the previous breaches. If they weren't bullshit, there would never have been breaches.


as I said, government intrusion can't be defended as is. Name one web technology that is government intrusion proof. Fuck that. Name on technology that is so. Air gapping isn't. Granted, air gapping allows you to at least know about it. But that's that.

"invasions of privacy" is not a use case. Give me details. By whom? Your partner? Your coworker? 4chan? Your mayor? Russia? What information are they getting from you? Why? It's very likely that whatever use case you come up with, you are better defended with 2auth gmail than with whatever other solution.

That's a problem with the web. In 15 years, and not counting legal government requests, there were what? 3 cases of email data breaches that were caught? 5? That's your "provably bullshit"? What do you use on your life that has a lower failure rate than this?


> as I said, government intrusion can't be defended as is.

yes it can. zero-knowledge encryption is already a thing.

> Name one web technology that is government intrusion proof.

Apparently the iPhone is. pgp encryption is another one. I'd suggest brushing up on basic security before saying things like that.

> "invasions of privacy" is not a use case.

Why not?

> By whom?

By anyone that I don't authorize. Sure, that could be my partner, coworker, any government authority, etc.

> What information are they getting from you?

Are you serious? If you don't even understand that threat model, then again, I'd suggest looking in basic security models.

> you are better defended with 2auth gmail

2auth gmail is orthogonal to the issue. That's an security method. Currently Google does that but still can grant access to anyone they want. That's a problem that 2auth doesn't address.

> not counting legal government requests

Why not? Why remove a legitimate security issue from the discussion?

> 3 cases of email data breaches that were caught

I have no idea how many have been caught, once again, that's orthogonal to the issue. How many examples doesn't matter. It's that they do have access and can do it whenever they want.

> What do you use on your life that has a lower failure rate than this?

That's a completely illogical argument. "We shouldn't ensure privacy/security because other things in life fail more often" makes no sense.


> Apparently the iPhone is

If you are referring to the San Bernardino phone thingy, the FBI withdrew the request exactly because they did access the phone by themselves. It just cost more money.

> pgp encryption is another one

lol. Isn't there tons of reports claiming that PGP leaks too much metadata? And that the NSA is collecting those? And that there's no reasonable way to use PGP without leaking those (like hidden-sender whatever).

> > "invasions of privacy" is not a use case. > Why not?

Because I want specifics. Just saying someone "invaded your privacy" doesn't tell me anything. Tell me a full story: entity X did Y to know Z from W. And show me how using gmail made W more unsafe on that case. And what I'm trying to tell you, is that there are two cases:

- legal government related. In which case Google can't (and won't) protect you. It's a fair claim. If you are doing something that the US government wants to know about, don't use gmail. But most things won't protect you from that anyway. Ask Dread Pirate Roberts about it. :)

- non-government related. In which case you are better protected with gmail than most things you can reasonably do. Ask Hillary Clinton. :)

> That's a completely illogical argument. "We shouldn't ensure privacy/security because other things in life fail more often" makes no sense.

Where did I say we shouldn't ensure privacy/security? What I'm refuting is your claim that "it's bullshit because it failed once". Gmail does a better job than most other things. Most things in your life fail more often than that. And most things don't evolve security/privacy wise as well as gmail does.


> the FBI withdrew the request exactly because they did access the phone by themselves

As far as I saw, that was just speculation. Any source on that? I'm inclined to believe it, but if true: why do they want the encryption removed rather than just snooping that data on the sly? It's better if your victims think they are secure.

> lol. Isn't there tons of reports claiming that PGP leaks too much metadata? And that the NSA is collecting those? And that there's no reasonable way to use PGP without leaking those (like hidden-sender whatever).

Possibly. But if so, I haven't seen them. Sources please.

While meta-data is absolutely useful, contents are even more useful. Just because something has one security issue doens't mean that we should give up security altogether.

> Because I want specifics

What specifics? Do you want me to make up a story about how someone could use information to attack someone else? or to use existing examples: http://www.cnn.com/2013/10/04/world/americas/silk-road-ross-... https://cpj.org/blog/2017/06/how-surveillance-trolls-and-fea... These are just 2 examples I pulled from a 5 minute search.

This isn't anything new. Having access to communication is pretty much the basis for espionage. If you don't see how that applies.... I'm not sure I can help you.

> legal government related. In which case Google can't (and won't) protect you

That's my point. They can protect you, they choose not to. Zero-knowledge encryption is still a thing. Just because Google doesn't use it doesn't mean it's not possible.

> non-government related. In which case you are better protected with gmail than most things you can reasonably do. Ask Hillary Clinton. :)

Only if Google can't access that data. If they can, it's much easier to bypass encryption and just ask Google to hand it over. Google can solve this problem but chooses not to.

> Where did I say we shouldn't ensure privacy/security?

When you say that gmail should be trusted. There are clear privacy/security holes with their model that you are ignoring. That's what this whole discussion is about.

> What I'm refuting is your claim that "it's bullshit because it failed once"

A) It didn't just fail once.

B) Failing just once proves that the system is not secure, and needs to be fixed. Failing multiple times from the same attack vector proves that they aren't taking security/privacy seriously, because they won't fix the root problem.

> Most things in your life fail more often than that

... so? Whether thing A fails more often than thing B has no bearing on whether thing B can and will fail.


I don't understand why seeing an ad is so bad. So a sleazy salesman is more annoying because they are in your way. But if you're going to see ads anyway, I'd rather they be relevant!! Can soemone explain why given that there will be ads either way they actually prefer irrelevant ads?


Here's why I prefer irrelevant ads:

1. Targeted ads catch my attention better. Frequently I don't even notice or remember irrelevant adds.

2. Targeted ads are almost always, SEOed (if you will) to me; that is, they seem relevant, they offer the solution needed to fix the precise problem I'm discussing in the email chain, I click, I read, I would buy, but I realize that the product offered is nothing like what I've been reading about on the landing page.

3. Targeted adds are much more effective at convincing me to spend money on stuff or services that I could have lived without.

Sure, I should toughen up mentally against ads, but until I do, I protect myself from ads that will manipulate me and one way to do that is to prefer irrelevant ads when I need to see them.


I'm curious how you make a living and whether the business you're in relies on advertising to sustain itself. Perhaps I'm reading too much into your post, but I detect a value judgment that businesses trying to be businesses (i.e., selling you stuff) is a bad thing.


It's a bad thing if the business with the biggest advertisement budget wins, rather than the business with the best (or most fitting) product.


Relevant ad is euphemism for "ad that makes you buy stuff you would happily not own otherwise". Since ads in general work (they make people buy more or different stuff) and you can not objectively evaluate whether you was influenced by ads, it is rational to avoid them.

Practically, once add service knows I am women, it insist on showing me ads for menstruation cups everywhere I browse. I also find juxtaposition of baby accessories and relaxation bullshit on metal, programming or games site mood killing. When they know less about me, I actually get less weird more neutral less crappy ads.


>Relevant ad is euphemism for "ad that makes you buy stuff you would happily not own otherwise". Since ads in general work (they make people buy more or different stuff) and you can not objectively evaluate whether you was influenced by ads, it is rational to avoid them.

Umm - you should avoid getting information because it might influence you to buy things ? There's nothing wrong with what you said, in an ideal world ads would be just that - informing the customer about your product - and influencing their decisions with information. The psychological marketing tricks to make a thing more attractive is also a value add.

Problem is it's easy to be misleading, create disinformation and it can be very profitable - that's what leads to shitty borderline fraudulent ads we have.


Umm - you should avoid getting information because it might influence you to buy things?

UMMMMMMmmmmm - yes?

Obviously?

If you wouldn't let a salesperson barge into your house, interrupt your reading to try and convince you to get discount eye surgery, why would you let that happen in visual form?

in an ideal world ads would be just that - informing the customer about your product

This is not anything like an 'ideal' world. One human has such limited attention, that you could spend every second of your lifetime attending to a different product and do nothing else, and you still wouldn't cover them all. And companies still wouldn't be happy with this ridiculous limit case, they'd still want a greater share of your attention and wallet. You, us, individually, mean nothing except a source of coins.

If we want to mean anything to ourselves, defence against the dark arts is necessary.

The psychological marketing tricks to make a thing more attractive is also a value add.

The psychological marketing tricks to make a thing more attractive is abusive and parasitic. Ideal brains would search for what they need, and buy the most fitting thing. Human brains which can be manipulated are a weakness we all share - and we should all be kind enough not to abuse this fact of each other any more than we have to.


>Ideal brains would search for what they need, and buy the most fitting thing.

That's not really how things work - there are certain things you need to accomplish other things where your reasoning partially applies but even then it's debatable. But then there are things you do for pleasure - and how you value those things can be completely separate from their physical properties.

For example there was a study[1] where they gave people 5 vine samples, a cheap wine with 5$ price tag, same wine with a 45$ price tag, 90$ vine and the same 90$ vine with a 10$ label, and a correctly labeled 35$ vine. They found that reported enjoyment and measured fMRI activity went up with price even for same vine. Plenty of similar studies that show similar effects for branding, etc. So these things actually create value even if they don't physically change the product - you end up enjoying it more and it's purpose is your enjoyment.

I mean most of the high end stuff ends up being blowing smoke up your ass to make you feel good about paying 2-10x markup, even when the quality is superior they bundle the bullshit and inflate the price extra because they know you'll pay.

[1] http://news.stanford.edu/pr/2008/pr-wine-011608.html


They are not creating value. They just mislead.


Ads are not information. They are not factual. Psychological marketing does add at value to me, just like being manipulated in person does not add value to me.


Like I responded below, psychological marketing effects like branding, exclusivity, etc. have been shown to increase peoples enjoyment of products in multiple studies.

Being manipulated can also add measurable value to you. For example if a doctor gave you a sugar pill for some condition and the placebo effect helped you get better - would you say that it added no value just because the sugar pill physically did nothing ?


> I'd rather they be relevant

Corollary: if you can't show a relevant ad, HOW ABOUT NOT SHOWING AN IRRELEVANT AT ALL?


Actually, it is not a corollary.


Would you prefer the party trying to trick you into buying crap you don't need to have more or less information about you?


> I don't understand why seeing an ad is so bad.

Ads are an insidious and highly effective form of psychological warfare. They play on human fears, insecurities, neuroses and instinctual weaknesses in order to part people from their hard-earned time and resources.

You might say the ads just bring their attention to needs they didn't know they had. I would say the opposite, that they create needs where there none existed to begin with.


Why try to pretend Google is nice to you? If their spam filter gathers the most relevant words and keep them stored for admins to look for the sake of tuning or whatever and maybe the admin also works in the ad department, perhaps checking on your email isn't for ad targeting.

You need to give up on your content the day you started using gmail, no matter what the TOS says.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: