<?xml version="1.0" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://blog.zgp.org/feed.xml" rel="self" type="application/rss+xml"/>
		<title>Don Marti</title>
		<link>https://blog.zgp.org/feed.xml</link>
		<description>Personal blog for Don Marti</description>
		<item>
			<title>More attribution cartel Q and A</title>
			<link>https://blog.zgp.org/more-attribution-cartel-q-and-a/</link>
			<guid>https://blog.zgp.org/more-attribution-cartel-q-and-a/</guid>
			<pubDate>Thu, 23 Apr 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p><strong>previously:</strong> <a href="https://blog.zgp.org/attribution-cartel-q-and-a/">Attribution
cartel Q and A</a></p>
<p>Some more questions and comments on the attribution cartel came up
after my AdExchanger piece on <a href="https://www.adexchanger.com/data-driven-thinking/what-happens-when-the-attribution-cartel-meets-advertisings-halo-effect/">What
Happens When The Attribution Cartel Meets Advertising’s Halo Effect?</a>
ran.</p>
<p><strong>Doesn’t the attribution cartel have better privacy properties
than other ways of measuring advertising?</strong></p>
<p>In theory, yes. Attribution cartel proponents claim that their system
makes it prohibitively hard to match the person who saw an ad
(impression) to the person who bought something (conversion).</p>
<p>But all the <a href="https://blog.zgp.org/attribution-cartel-update/">big problems with
the attribution cartel</a> are still there if you assume</p>
<ul>
<li><p>the design is perfect</p></li>
<li><p>the design is implemented perfectly in large browser
codebases</p></li>
</ul>
<p>Designing a system without meaningful protection from fraud creates
incentives to do fraud. And adfraud is not a “victimless” problem. The
Big Tech companies assume adfraud isn’t a problem, because it’s
revenue-positive for <em>them</em> and the costs fall on other
players—but in practice, a high-fraud environment means not only that
legit sites are under-compensated and advertisers fed misleading data,
users are at greater risk. (I covered that problem in <a href="https://www.adexchanger.com/data-driven-thinking/the-hidden-dangers-of-privacy-preserving-attribution-and-a-smarter-solution/">The
Hidden Dangers Of Privacy-Preserving Attribution – And A Smarter
Solution</a>.)</p>
<p>The mathematical properties of this one proposal in isolation aren’t
enough to justify a claim that it “provides better privacy.” It has to
be understood in context. Like <a href="https://en.wikiquote.org/wiki/Dune">the man said</a>,</p>
<blockquote>
<p>A process cannot be understood by stopping it. Understanding must
move with the flow of the process, must join it and flow with it.</p>
</blockquote>
<p>Put the Attribution proposal up on a poster, award it a math prize,
and I’ll give it a round of applause. But don’t put it out on the real
Internet where it will cause all kinds of grief. And it could still have
design or implementation problems after all that. Remember TURTLEDOVE
came out on January 16, 2020 and the “Malicious match key provider
attack” didn’t happen until March 24, 2023. (<a href="https://blog.zgp.org/google-privacy-sandbox-timeline/">Google
“Privacy Sandbox” timeline</a>)</p>
<p><strong>Can organisations the size of attribution cartel member
companies really keep so much fraud a secret?</strong></p>
<p>The Big Tech companies love to <a href="https://www.npr.org/2026/04/23/nx-s1-5797855/meta-layoffs-10-percent-staff">run
yet another season of the layoffs reality show</a>, and inside knowledge
of attribution fraud would be like an immunity idol on Survivor, right?
Squirrel away one notebook (make a few copies) and you’re resting and
vesting as long as you can stay quiet.</p>
<p>But complex reporting fraud issues can happen without any one person
seeing the big picture. That’s because <strong>the revenue-positive bug
effect</strong> is a thing. Any large software system will have more
tickets than people (or bots) can actually fix. Some are going to end up
in backlog for a long time. And when you’re talking about ads, the bugs
that go to the head of the list are those that have a big negative
revenue impact. Revenue-positive bugs are low priority.</p>
<p>The highest-priority and politically easiest bugs to fix will be
those that make the attribution cartel reports different from the
“Performance Max” or other Big Tech algorithm. Failure to show a halo
effect for ads on legit sites might not even get flagged as a bug. The
most obvious example is the whole <a href="https://www.niemanlab.org/2018/10/did-facebooks-faulty-data-push-news-publishers-to-make-terrible-decisions-on-video/">pivot
to video</a> situation, but it can even happen at legit publishers. <a href="https://www.usatoday.com/story/money/2022/03/09/gannett-ad-mistake-human-error/9447107002/">Gannett
had a long-running, likely revenue-positive, bug</a> that caused ads to
be erroneously reported as running on the wrong site.</p>
<p>The difference between the Gannett bug and a hypothetical
revenue-positive bug for an attribution cartel member is that outside
researchers could see Gannett’s.</p>
<p>I don’t claim that the attribution cartel members will be able to do
technothriller-level secret-keeping, but they won’t have to. Complexity
and incentives will take care of it.</p>
<section class="level2" id="bonus-links">
<h2>Bonus links</h2>
<p><a href="https://ember-energy.org/latest-updates/chinese-solar-exports-double-in-a-month-to-hit-record-high-amid-energy-crisis/">Chinese
solar exports double in a month to hit record high amid energy
crisis</a> from Ember Energy. <q>Fifty countries set all-time records
for Chinese solar imports in March 2026, with a further 60 seeing the
highest levels in six months. Exports to Africa rose by 176% compared to
February 2026 to reach 10 GW in March 2026, while exports to Asia
doubled to reach 39 GW—both new all time records.</q></p>
<p><a href="https://www.theverge.com/tldr/915176/nft-metaverse-ai-weirdos">Silicon
Valley has forgotten what normal people want</a> by Elizabeth Lopatto.
<q>In the place of problem-solving technology, companies have jumped on
successive bandwagons like NFTs, the metaverse, and large language
models. What these all have in common is that they are not built to
really solve a market problem.</q></p>
<p><a href="https://arstechnica.com/security/2026/04/crypto-scam-lures-ships-into-strait-of-hormuz-falsely-promising-safe-passage/">Crypto
scam lures ships into Strait of Hormuz, falsely promising safe
passage</a> by Jeremy Hsu. <q>MARISKS identified one ship as having
potentially fallen victim to crypto scams after it attempted to pass
through the strait on April 18, although Reuters was unable to confirm
that information. The incident supposedly occurred during a brief window
when Iran claimed it was allowing ships to undergo inspection to pass
through, but the ship in question turned back after Iranian military
forces fired upon it.</q></p>
<p><a href="https://www.wired.com/story/ai-generated-maga-girls/">This
Scammer Used an AI-Generated MAGA Girl to Grift ‘Super Dumb’ Men</a> by
EJ Dickson. <q>A med student says he’s made thousands of dollars selling
photos and videos of a young conservative woman he created using
generative tools. He’s not alone.</q></p>
</section>]]></description>
		</item>
		<item>
			<title>We still have time to save the halo effect</title>
			<link>https://blog.zgp.org/save-the-halo-effect/</link>
			<guid>https://blog.zgp.org/save-the-halo-effect/</guid>
			<pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p>I’m still on about the attribution cartel, and
got in AdExchanger again: <a href="https://www.adexchanger.com/data-driven-thinking/what-happens-when-the-attribution-cartel-meets-advertisings-halo-effect/">What
Happens When The Attribution Cartel Meets Advertising’s Halo Effect?</a>
Last time they let me cover <a href="https://www.adexchanger.com/data-driven-thinking/the-hidden-dangers-of-privacy-preserving-attribution-and-a-smarter-solution/">The
Hidden Dangers Of Privacy-Preserving Attribution</a> (plot twist: it’s a
privacy menace) and this time it’s all about the halo effect.</p>
<p>What’s the halo effect? It turns out that in a world where social
science results are hard to replicate, and marketing results even
harder, one consistent effect is that ads work better in trusted
contexts.</p>
<ul>
<li><p>Comscore: <a href="https://www.comscore.com/Insights/Presentations-and-Whitepapers/2016/The-Halo-Effect-How-Advertising-on-Premium-Publishers-Drives-Higher-Ad-Effectiveness">The
Halo Effect: How Advertising on Premium Publishers Drives Higher Ad
Effectiveness</a></p></li>
<li><p><a href="https://world-media-group.com/moat-analytics-reveal-that-quality-journalism-eclipses-industry-benchmarks-for-attention/">Moat
Analytics Reveal that Quality Journalism Eclipses Industry Benchmarks
for Attention</a></p></li>
<li><p>Newsworks: <a href="https://newsworks.org.uk/research/attention/">High-attention media
delivers greater profits for advertisers</a></p></li>
<li><p>The Trade Desk: <a href="https://www.thetradedesk.com/insights/premium-media-report">The
value of advertising on premium media</a></p></li>
</ul>
<p>Meanwhile, the attribution cartel companies are all about doing
things the other way around: getting the most lucrative possible ad onto
the cheapest, crappiest possible content. (ICYMI, ad “safety” at Google
<a href="https://blog.zgp.org/another-ad-safety-report/">keeps getting
worse</a>, and the Meta ad scams are bad enough that there’s now <a href="https://advocacy.consumerreports.org/press_release/consumer-reports-backs-bipartisan-legislation-to-combat-predatory-online-scams/">bipartisan
legislation to combat predatory online scams</a>.)</p>
<p>I wrote that from an advertiser point of view, because AdExchanger,
but the attribution cartel is a risk to everyone.</p>
<ul>
<li><p>It’s not just a problem for advertisers who want accurate
reports, as <a href="https://www.linkedin.com/posts/rickbrunernyc_what-happens-when-the-attribution-cartel-activity-7452059225368768512-nL1p">Rick
Bruner wrote on LinkedIn</a>.</p></li>
<li><p>It’s not just a problem for the publishers who deserve a fair
share of the revenue for the advertising results they help
drive.</p></li>
</ul>
<p>It’s bigger than that. Attribution reports help decide whether
advertising budgets get spent on legitimate ad-supported resources that
benefit the people being advertised to—or if Big Tech can divert ad
money to support slop, misinformation, scams, privacy violations of all
kinds, and some of the worst people on the Internet.</p>
<p>If you just read the headlines, it looks like <a href="https://blog.zgp.org/google-privacy-sandbox-timeline/">Google’s
“Privacy Sandbox” project</a> to centralize control of advertising
within the browser is over. But the process continues, now with Apple
and Meta involved too.</p>
<p>The time to deal with it is now, before attribution cartel reports
become part of an easy or default path to justify spending good
advertising money in bad places.</p>
<p>By the way, I thought I might be the first person to mention Shrimp
Jesus on AdExchanger, but it turns out that Shrimp Jesus has already
been in AdExchanger. They keep up with this stuff. So check it out: <a href="https://www.adexchanger.com/data-driven-thinking/what-happens-when-the-attribution-cartel-meets-advertisings-halo-effect/">What
Happens When The Attribution Cartel Meets Advertising’s Halo
Effect?</a></p>
<p><strong>Previously:</strong> <a href="https://blog.zgp.org/attribution-consent/">Attribution and
consent</a>, <a href="https://blog.zgp.org/why-turn-off-firefox-ad-tracking/">why I’m
turning off Firefox ad tracking: the PPA paradox</a>, <a href="https://blog.zgp.org/terminator-ending-for-privacy-sandbox/">a
Terminator ending for Google “Privacy Sandbox”?</a>, <a href="https://blog.zgp.org/performance-max-preserving-attribution/">Performance
Max Preserving Attribution</a>, <a href="https://blog.zgp.org/attribution-cartel-update/">Attribution
cartel update</a>, <a href="https://blog.zgp.org/attribution-cartel-q-and-a/">Attribution
cartel Q and A</a></p>
<section class="level2" id="bonus-links">
<h2>Bonus links</h2>
<p><a href="https://www.westwoodone.com/blog/2026/04/13/marketers-vastly-understate-the-sales-effect-of-creative-and-significantly-overestimate-the-impact-of-targeting-3/">Marketers
Vastly Understate The Sales Effect Of Creative And Significantly
Overestimate The Impact Of Targeting</a> by Pierre Bouvard. <q>To
determine what actually drives advertising effectiveness, we turn to one
of largest and most prominent studies ever conducted on sales
effect…</q></p>
<p><a href="https://www.adexchanger.com/data-privacy-roundup/why-a-1967-privacy-law-is-powering-a-new-wave-of-ad-tech-lawsuits/">Why
A 1967 Privacy Law Is Powering A New Wave Of Ad Tech Lawsuits</a> by
Allison Schiff. <q>That reality is shaping how companies think about
risk and about settlements in general.</q></p>
<p><a href="https://suewallst.com/lawsuits/oddity-tech-ltd-class-action-lawsuit-odd">ODDITY
Tech Ltd. Class Action Lawsuit – ODD – Investor Losses &amp; Lead
Plaintiff Deadline</a> <q>The company’s direct-to-consumer model
depended heavily on paid advertising ecosystems and the auction
mechanics that determined where, how, and at what cost its ads appeared.
That dependence matters because ad auction quality directly affects cost
per click, click-through rates, and ultimately customer acquisition
costs. The complaint repeatedly emphasizes this causal chain: better
auctions produce lower acquisition costs, weaker auctions do the
opposite. Investors allege this operational dependency was not a side
note, but the hidden fault line beneath ODDITY’s premium
valuation.</q></p>
<p><a href="https://futurism.com/artificial-intelligence/national-today-ai-plagiarizing">A
Prominent PR Firm Is Running a Fake News Site That’s Plagiarizing
Original Journalism at Incredible Scale</a> by Maggie Harrison Dupré.
<q>We’re not the only target. Once we started looking into National
Today, we realized that it’s doing the same thing to countless other
publications, ranging from top newspapers to local newsrooms across the
country: stealing their original reporting and using it to publish a
torrent of what appear to clearly be AI-generated articles, complete
with bizarre errors and hallucinations.</q> (related: <a href="https://blog.zgp.org/vibe-cms/">A Vibe CMS</a>)</p>
<p><a href="https://pivot-to-ai.com/2026/04/17/objection-ai-venture-capital-tries-to-block-bad-press/">Objection
AI: venture capital tries to block bad press</a> by David Gerard.
<q>These guys are rich, powerful, and sort of stupid. The same bunch of
guys has long been trying to reinvent journalism from first
principles—because, as centres of power, they don’t like adverse news
coverage.</q></p>
<p><a href="https://www.fastcompany.com/91519302/byd-nail-test-why-this-54-billion-innovation-is-terrifying-western-auto-executives">The
Nail Test: Why this $54 billion innovation is terrifying Western auto
executives</a> <q>That question would consume eight years of R&amp;D. A
lab burned during the process. The team lost equipment, prototypes,
months of iteration. What they did not lose was the data. They rebuilt.
They ran the test again. And again.</q></p>
<p><a href="https://www.afterbabel.com/p/seven-lines-of-evidence-against-social-media">The
Case Against Social Media: Seven Lines of Evidence</a> by Jon Haidt and
Zach Rausch. <q>Knowing that thousands of jury trials were on the
horizon, we laid out our argument like a hypothetical civil trial,
asking our imagined jury this question: Are social media platforms
dangerous consumer products whose design has led to a variety of harms
to young people? We call this the Product Safety Question. We present
seven lines of converging evidence showing that these platforms are
causing harm.</q></p>
<p><a href="https://news.bloomberglaw.com/litigation/server-side-tracking-to-shape-future-of-pixel-privacy-litigation">Server-Side
Tracking to Shape Future of Pixel Privacy Litigation</a> by Ufonobong
Umanah. <q>Server-side tracking might reduce litigation risk but isn’t
likely to eliminate it entirely, attorneys say.</q></p>
</section>]]></description>
		</item>
		<item>
			<title>Have you filed your compliance taxes?</title>
			<link>https://blog.zgp.org/have-you-filed-your-compliance-taxes/</link>
			<guid>https://blog.zgp.org/have-you-filed-your-compliance-taxes/</guid>
			<pubDate>Sat, 18 Apr 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p>Got Google Analytics or Google ads on your web
site? Don’t forget to check some important compliance instructions, in a
<a href="https://www.linkedin.com/posts/jennifer-l-vercellone-esq-12a75b26_privacy-consentmode-googleanalytics-share-7450683193483075584-G2j5/?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAADA5AB-3AkcEQ3MbnZEay0KC4KhHZFy1Q">LinkedIn
post from Jennifer L. Vercellone, Esq.</a> And remember, “Each Google
platform (GA4, Ads, GMP) must be configured to honor those signals.”</p>
<p>Read the whole thing. As far as I can tell, here’s the list of things
to check.</p>
<ul>
<li><p>Google Consent Mode (version 2, that is. If you set up version 1,
it’s past time to upgrade. <a href="https://steve-yegge.medium.com/dear-google-cloud-your-deprecation-policy-is-killing-you-ee7525dc05dc">Googlers
can’t get promoted by keeping old stuff working</a>, so do your
part)</p></li>
<li><p>Consent Management Platform (which must support the
above)</p></li>
<li><p>Google Analytics</p></li>
<li><p>Google Ads</p></li>
<li><p>Google Marketing Platform</p></li>
</ul>
<p>Now remember to set up “Basic vs. Advanced Consent Mode”.</p>
<p>And “Consent Mode reflects your CMP—it does not override it. And each
Google platform must be configured to act on those signals.” See the
list above.</p>
<p>There’s no “consent mode” in the law, but “consent mode” has to be
upgraded—because of code churn on the Google side—and a CMP to
configure, and multiply by the number of different Google services
you’re using. Yes, this is a lot of Jira tickets, or whatever you use.
And if you get one wrong, you <a href="https://www.youtube.com/watch?v=L397TWLwrUU">lose</a> the
compliance game.</p>
<p>This set of changes is due before June 15, 2026. But don’t worry.
Google will put out another set any day now.</p>
<p>No, Google doesn’t set up their services to keep sites on the right
side of the law by default. No, they don’t even have one illegal/legal
switch that you can flip for all the Google services at once. They put
work on the advertisers, publishers, and app developers.</p>
<p>When Google <a href="https://www.404media.co/google-microsoft-meta-all-tracking-you-even-when-you-opt-out-according-to-an-independent-audit/">tells
404 Media</a>,</p>
<blockquote>
<p>This report is based on a fundamental misunderstanding of how our
products work. We honor opt-out provided by advertisers and publishers
as required by law.</p>
</blockquote>
<p>they might be correct, in a sense. If advertisers and publishers read
the right documentation and do what it says, or hire the right team of
compliance nerds, then maybe it is possible to use Google services in a
way that complies with the law. But often people leave things set up in
a way that…</p>
<ul>
<li><p>passes more information to Google</p></li>
<li><p>is technically illegal</p></li>
</ul>
<p>…and Google can be shocked to discover non-compliance along with
regulators.</p>
<p>The conclusion to Vercellone’s LinkedIn post explains.</p>
<blockquote>
<p>CMP, Consent Mode, and each Google platform must be configured as a
system—not in isolation. Misalignment at any layer = compliance and
measurement gaps.</p>
</blockquote>
<p>A normal company wouldn’t be able to get away with dumping all this
work on others. If one plumber hooked up your water heater to shock you
in the shower, you could call a different plumber. Plumbers have to
compete, and they read the building code for you.</p>
<p>But Google, because monopoly, just gets to sit back and do monopoly
stuff. Google has figured out how to avoid consequences of CCPA-style
privacy laws, while still getting a lot of the extra personal data that
comes with breaking the law, and putting all the costs, and the risks of
non-compliance, onto publishers, app developers, and advertisers. Google
shifts the compliance tax onto smaller companies, just as <a href="https://www.buzzfeednews.com/article/kenbensinger/amazons-race-to-build-a-fast-delivery-network-the-human">Amazon
did with the risks of operating delivery vans on a micromanaged, tight
schedule</a>.</p>
<p>Well played, Google.</p>
<p>Naturally, this whole disappointing situation has, as they say,
important lessons for policy makers. Drafting a CCPA-clone, or near
clone, privacy bill is copying a game level that Google has already
beaten. Future laws can and should offer a compliance tax cut to legit
companies. <strong>More:</strong> <a href="https://blog.zgp.org/what-california-got-wrong-on-privacy-laws/">what
California got wrong on privacy laws</a></p>
<section class="level2" id="bonus-links">
<h2>Bonus links</h2>
<p><a href="https://www.fastcompany.com/91528808/shuttered-startups-are-selling-old-slack-chats-and-emails-to-ai-companies">Shuttered
startups are selling old Slack chats and emails to AI companies</a> by
Ella Chakarian. (Corporate “agentic AI” is being trained to copy failed
startups? What could possibly go wrong?)</p>
<p><a href="https://newrepublic.com/article/208746/silicon-valley-humiliated-democrats-tech">How
Silicon Valley Humiliated the Democrats</a> by Alexis Goldstein. (Coming
soon: the <a href="https://blog.zgp.org/attribution-cartel-update/">attribution
cartel</a> humiliates the mainstream media the same way?)</p>
<p><a href="https://techcrunch.com/2026/04/14/how-the-rewards-app-freecash-scammed-its-way-to-the-top-of-the-app-stores/">Freecash
Was More Like Scamcash</a> by Sarah Perez. <q>On Monday, after being
contacted by TechCrunch for comment, Apple pulled Freecash from its App
Store. As of Monday afternoon, the app was still listed in the Google
Play store. (It has since been removed).</q></p>
</section>]]></description>
		</item>
		<item>
			<title>Another ad safety* report</title>
			<link>https://blog.zgp.org/another-ad-safety-report/</link>
			<guid>https://blog.zgp.org/another-ad-safety-report/</guid>
			<pubDate>Fri, 17 Apr 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p><strong>Previously:</strong> <a href="https://blog.zgp.org/google-ads-shitshow-report-2024/">Google Ads
Shitshow Report 2024</a></p>
<p>It’s <a href="https://services.google.com/fh/files/blogs/global_2025_adssafetyreport.pdf">Google
Ads Safety Report {PDF)</a> time for all who celebrate, and, excuse me,
but yikes.</p>
<p>The report is down to three pages from the six they put out last
year, and this time it’s mostly a Google Gemini fan post. (Yes, the same
LLM that’s behind the <a href="https://www.nytimes.com/2026/04/07/technology/google-ai-overviews-accuracy.html">91%
right</a> AI Overviews feature.)</p>
<p>I’m going to repeat the point I had last time: if a company is trying
to brag on exposing people to less bad stuff, and they’re reporting the
amount of bad stuff they blocked, they’re losing. When you ask how many
rat turds are in the chocolate chip cookies, and the answer is “we swept
up 99 million rat turds at the bakery last year!” that doesn’t make you
want a cookie any more.</p>
<p>Look at your spam folder some time. A lot of stuff in there that’s
obviously going to get blocked, because lots of people who are bad at
doing crimes on the Internet try to do crimes on the Internet (maybe
they bought a software package or training course that doesn’t work).
The number blocked is always going to be high and not a good indication
of the actual safety level. The meaningful metrics to report are on how
much of the bad stuff got through—which Google never puts in these
reports, because they let a lot through. By design. Features of Google’s
ad system, such as <a href="https://blog.zgp.org/how-google-can-go-legit/">Ads Transparency
Center and the trademark policy</a>, are set up to give an advantage to
deceptive advertisers.</p>
<p>So, the numbers aren’t that helpful, but let’s compare to the <a href="https://services.google.com/fh/files/misc/ads_safety_report_2024.pdf">2024
report (PDF)</a> anyway.</p>
<p><strong>2024:</strong> 5.1 billion ads removed, 9.1 billion
restricted</p>
<p><strong>2025:</strong> 8.3 billion blocked or removed, 4.8 billion
restricted</p>
<p>So if you add it up, they caught 14.2 billion in 2024 and 13.1
billion in 2025.</p>
<p>Are people really making 1.1 billion fewer policy-violating ads? If
the number being made were going down, then why do legit small
businesses keep getting <a href="https://searchengineland.com/small-businesses-compete-google-ads-462009">priced
out, as seems to have been the case in 2025</a>?</p>
<p><strong>2024:</strong> 39.2M+ advertiser accounts suspended.</p>
<p><strong>2025:</strong> 24.9M+ advertiser accounts suspended.</p>
<p>What about bad sites? In 2024, Google took “site-level enforcement
action” against 220,000 publisher sites. <strong>Update:</strong> there
is a “publisher sites actioned” number for 2025, which is at
“245k+”.</p>
<p>Pages are probably hard to compare across years, since it has gotten
so much easier to <a href="https://blog.zgp.org/vibe-cms/">vibe CMS</a>
a normal-looking article page. So I would expect more. But:</p>
<p><strong>2024:</strong> 1.3 billion pages taken action against</p>
<p><strong>2025:</strong> 480 million plus</p>
<p>Google’s biggest problem still seems to be sending people to malware
from search. There is a “Malware or Unwanted Software” number for 2025,
which is at “2M+”</p>
<p>For 2024, “Malicious or unwanted software” was at 19.3M.</p>
<p>Are malware operators really cutting back on Google Search campaigns,
or is Google just catching fewer of them? A real “Ad Safety Report”
would check in with security firms to see if their customers are getting
more or fewer malware installs from search.</p>
<p>But even on the numbers that are easiest to make Google look good on,
they’re not doing so well year to year. That’s not a surprise—safety is
losing a game that they Google didn’t design for safety to start
with.</p>
<p>Anyway, if you are keeping a file on why your household or workplace
has ad blocking set up to protect people from Google ads, save both PDFs
along with the <a href="https://www.ic3.gov/PSA/2025/PSA250424">FBI
alert</a>.</p>
<p>(And yes, from the state legislature point of view, this is a good
reason why we need working Right to Know: <a href="https://blog.zgp.org/inquiring-minds-have-a-right-to-know/">inquiring
minds (have a right to) know</a>)</p>]]></description>
		</item>
		<item>
			<title>Updating assumptions for blogging in 2026</title>
			<link>https://blog.zgp.org/updating-assumptions-for-blogging-in-2026/</link>
			<guid>https://blog.zgp.org/updating-assumptions-for-blogging-in-2026/</guid>
			<pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p>First, I used to assume that if the RSS feed is
valid, the links are good.</p>
<p>But there’s the possibility of a “works on my machine” feed. Not
going to mention a specific company here, but I spotted a feed on an
HTTPS site but with HTTP localhost links.</p>
<pre><code>    &lt;title&gt;Funded Startup Blog&lt;/title&gt;
    &lt;link&gt;http://localhost:5150/blog&lt;/link&gt;
    &lt;description&gt;Awesome technology and business insights from our innovation journey&lt;/description&gt;
    &lt;item&gt;
      &lt;title&gt;Our thing works with some other company's other thing&lt;/title&gt;
      &lt;link&gt;http://localhost:5150/blog/please-googlebot-dig-these-keywords&lt;/link&gt;</code></pre>
<p>See the problem? The links work fine when they preview on localhost
with the dev server running, but on the real Internet, not so much. And
the feed is <a href="https://validator.w3.org/feed/">technically
valid</a>, just not really working.</p>
<p>So for now I am doing this.</p>
<pre><code>def fix_url(source, dest):
    "For sites that leave localhost links in the production RSS feed"
    "Replace the scheme and netloc"
    sp = urllib.parse.urlsplit(source)
    dp = urllib.parse.urlsplit(dest)
    if dp.netloc.startswith("localhost:") or dp.netloc.startswith("127.0.0"):
        logging.info("fixing localhost link to %s" % dest)
        return urllib.parse.urlunsplit([sp.scheme, sp.netloc, dp.path, dp.query, dp.fragment])
    return dest</code></pre>
<p>This is not going to be right in all cases (it doesn’t work if they
use a different virtual host for the feed) but for what I have found so
far it’s better than letting the localhost links be.</p>
<p>The second assumption is a little tougher to give up. Read <a href="https://aramzs.xyz/noteworthy/the-internets-most-powerful-archiving-tool-is-in-peril/">The
Internet’s Most Powerful Archiving Tool Is in Peril</a> from Aram
Zucker-Scharff.</p>
<blockquote>
<p>Whatever you think about our machine learning overlord corporations,
there’s no doubt that they are sucking immense value from journalists
and giving almost none of it back. The only tool media companies really
have in their arsenal is blocking.</p>
</blockquote>
<p>I used to be able to assume that I could link to something from here,
and if the original went away, I could swap in an Internet Archive link.
For example, in <a href="https://blog.zgp.org/before-surveillance-capitalism/">Before
surveillance capitalism and surveillance advertising, there was
surveillance marketing</a> I found what I think is the earliest use of
the term—not by academics or privacy advocates, but by Mark Cameron in
Marketing Magazine.</p>
<p>But now any halfway awake web publisher is going to block archives,
Common Crawl, and other services, to try to keep their pages away from
the deeply unsympathetic AI tycoons. (If you want a recipe for <a href="https://theonion.com/man-who-threw-molotov-cocktail-at-sam-altmans-home-claims-he-was-following-chatgpt-recipe-for-risotto/">risotto</a>,
go to the library or find a legit human-tested recipe site.)</p>
<p>So that means if I link to something but I don’t have a local copy,
it need to be an error. This way, if making an archive.org link doesn’t
work, I can put up the local copy if it’s a <a href="https://blog.zgp.org/fbi-update/">government work</a> or out of
copyright for some other reason, or replace the link with a fair use
excerpt.</p>
<p>I’m not going to automate it, since a lot of sites are going to be
good enough at avoiding scrapers that they could avoid whatever I could
set up. But now there’s one more task to add to the new page build
process.</p>
<section class="level2" id="bonus-links">
<h2>Bonus links</h2>
<p><a href="https://theconversation.com/what-australia-must-learn-from-ukraine-about-drone-technology-and-the-future-of-warfare-280466">What
Australia must learn from Ukraine about drone technology and the future
of warfare</a> by Clive Williams. <q>Increasingly, wars are now being
determined by the capacity to produce and deploy large numbers of
unmanned systems at relatively low cost.</q> (Another lesson seems to be
to use cheap energy sources that make it much harder for a drone or
missile to destroy equipment worth more than its own cost. <a href="https://www.pv-magazine.com/2026/03/31/philippines-accelerates-grid-entry-for-1-28-gw-of-solar/">Philippines
accelerates grid entry for 1.28 GW of solar</a> by Patrick Jowett.)</p>
<p><a href="https://www.exchangewire.com/blog/2026/04/15/ad-techs-bielefeld-problem-what-if-none-of-it-is-real/">Ad
Tech’s Bielefeld Problem: What If None of It Is Real?</a> by Shirley
Marschall. <q>At no point does something definitively real have to
happen. Only something measurable and convincing enough. Clicks resemble
engagement. Conversions resemble outcomes. Optimisation resembles
improvement. Each layer validates the next, and as long as the outputs
remain plausible, the system holds together. Yes, that’s the bar now.
Not truth. Not causality. Just plausibility.</q> (It may be worse than
that. The conventional adtech tracking might be hella accurate for more
surveillable subsets of the customer base, but result in “data-driven
insights” that don’t apply to the whole real-world set of customers,
because some are set up with privacy tools and settings to feed less
data into the system. More: <a href="https://blog.zgp.org/triple-taxation-on-surveillance-marketing/">Triple
taxation on surveillance marketing</a>)</p>
<p><a href="https://www.vox.com/future-perfect/485295/austin-national-rents-declining-yimby">How
Austin’s stunning drop in rents explains housing in America</a> by
Marina Bolotnikova. <q>Austin is hardly the only city that has tried to
unfetter homebuilding to ease its cost of living. But it is remarkable
for the sheer breadth of reforms it’s adopted…</q></p>
</section>]]></description>
		</item>
		<item>
			<title>Attribution cartel Q and A</title>
			<link>https://blog.zgp.org/attribution-cartel-q-and-a/</link>
			<guid>https://blog.zgp.org/attribution-cartel-q-and-a/</guid>
			<pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p><strong>Previously:</strong> <a href="https://blog.zgp.org/attribution-cartel-update/">Attribution
cartel update</a></p>
<p><em>(Updated 19 Apr 2026)</em></p>
<p><strong>What’s attribution and why does it matter?</strong></p>
<p>Attribution is the process of correlating events, such as exposure to
advertising, to an outcome, such as a sale. Usually people say
“impressions” for the event and “conversions” for the outcome. See <a href="https://www.iab.com/wp-content/uploads/2016/10/Digital-Attribution-Primer-2-0-FINAL.pdf">Digital
Attribution Primer (PDF)</a> from IAB.</p>
<p>The current state of attribution can be split into two tracks,
paywalled vs. free: Paywalled is more <a href="https://www.centralcontrol.com/about/about">scientific</a>, and
the free kind is what advertisers get from Google and Meta. More on
that: <a href="https://rjionline.org/news/big-tech-is-squeezing-advertising-jobs-and-companies/">Big
Tech is squeezing advertising jobs and companies</a></p>
<p>Attribution matters because it guides advertising decision makers in
determining where ad budgets get spent. Ad money can support legit sites
and other resources that help the people being advertised to, or end up
supporting parties that work against the interests of the people being
advertised to.</p>
<p><strong>How is the attribution cartel defined? Who’s in and who’s
out?</strong></p>
<p>The cartel members are some well-known companies that agree to
operate an ad tracking scheme that will not require consent or be
subject to objections or opt-outs. To get a peek of how this would work,
a recent version of Firefox shipped with both an attribution tracking
preference (on by default) and Global Privacy Control. But turning on
GPC did not turn off attribution tracking.</p>
<p>A non-member is any company where consent, objections, and/or
opt-outs apply to all of their personal data practices.</p>
<p><strong>What would be the impact of the attribution cartel on web
publishers and advertisers?</strong></p>
<p>Giving large platform companies control of attribition would tend to
aid their current tendency to shift more advertising onto low-trust
content and AI-generated slop. <a href="https://www.adexchanger.com/data-driven-thinking/what-happens-when-the-attribution-cartel-meets-advertisings-halo-effect/">What
Happens When The Attribution Cartel Meets Advertising’s Halo
Effect?</a></p>
<p><strong>Is “attribution cartel” a negative or pejorative
term?</strong></p>
<p>No. The term “attribution cartel” reflects a Neutral Point of View.
The attribution cartel meets all the <a href="https://en.wikipedia.org/wiki/Cartel_theory#Constituent_characteristics_and_exclusion_criteria_for_cartels">generally
accepted criteria for a cartel</a>, according to their own meeting
notes.</p>
<ul>
<li><p>The members are, at the same time, partners as well as
competitors.</p></li>
<li><p>The members of a cartel are independent of each other…there have
to be at least two participants and they determine their interests
autonomously.</p></li>
<li><p>The members of a cartel know each other; they have a direct
relationship, in particular they communicate with each other.</p></li>
</ul>
<p>A negative term would be something like “attribution racket” or
“attribution conspiracy”. It is recommended to avoid using those, and
also to avoid terms biased in the other direction such as “attribution
community”.</p>
<p><strong>What’s Apple doing in the cartel? Aren’t they all privacy and
stuff?</strong></p>
<p>A lot of individual developers at Apple have been trying to protect
their users from privacy problems on the web and from sneaky practices
by iOS apps for quite a while. But in the big picture, management can
justify participation in the attribution cartel by how it will move ad
spend into Apple’s own ad system. Just out: <a href="https://www.businessinsider.com/apple-gets-serious-about-its-advertising-business-2026-4">Apple
Gets Serious About Its Advertising Business</a> by Lara O’Reilly.
They’re limiting non-cartel tracking while building up an <q>Apple
Business</q> tool that integrates Apple’s own attribution tracking,
which you can still turn off but it’s <a href="https://blog.zgp.org/turn-off-advertising-measurement-in-apple-safari/">buried
under “advanced” somewhere</a>.</p>
<p>The idea is to drive more money into App Store ads instead of to
legit sites. If Apple didn’t control attribution, their app store ads
would show a negative halo effect, because the <a href="https://appleinsider.com/articles/26/04/17/app-store-scams-are-getting-worse-and-apple-isnt-doing-enough">App
Store is full of fraud</a>, so in the long run they need to either clean
up or take control of attribution measurement.</p>
<p><strong>The Attribution proposal looks complicated. Who’s going to
run all that nerd stuff?</strong></p>
<p>The point is to integrate into a system that both places ads (on slop
and right-wing bullshit, naturally) and reports back that the decision
to place ads there was the optimal thing to do. See, for example, <a href="https://www.adexchanger.com/platforms/meta-is-launching-an-easy-button-for-capi/">Meta
Is Launching An Easy Button For CAPI</a>. The “open web” attribution
data will feed into a system that shows how low the ROI for open web is
compared to Meta’s whatever latest <a href="https://cyber.fsi.stanford.edu/publication/lawful-awful-control-over-legal-speech-platforms-governments-and-internet-users">lawful
but awful</a> thing is.</p>
<p><strong>But, technically, do the cartel members really need
consent?</strong></p>
<p>Questions like this help explain why the idea of <em>g</em>—like the
real-world equivalent of one number for “intelligence” in Dungeons and
Dragons—is bogus. See <a href="https://medium.com/incerto/iq-is-largely-a-pseudoscientific-swindle-f131c101ba39">IQ
is largely a pseudoscientific swindle (Argument Closed) by Nassim
Nicholas Taleb</a>. Google is the best example. So every time Google
gets caught doing some kind of crime, their immediate response is
something like, <strong>well, actually, if you were as smart as us you
would be able to see that we went right up to the line of what’s a
crime, but technically we didn’t cross it.</strong> Rachel Myrow at KQED
asked, <a href="https://www.kqed.org/news/12079887/what-is-the-point-of-californias-privacy-laws-if-big-tech-ignores-them">What
Is the Point of California’s Privacy Laws if Big Tech Ignores Them?</a>
and the response from Google was,</p>
<blockquote>
<p>This report is based on a fundamental misunderstanding of how our
products work. We honor opt-outs provided by advertisers and publishers
as required by law.</p>
</blockquote>
<p>Google took this approach to the antitrust cases, too, and we’ll see
how that <a href="https://www.adexchanger.com/antitrust/for-google-advertisers-who-overpaid-the-monopoly-dont-hate-arbitrate/">works
out for them</a>. They set up an intricate box inside which they may or
may not be doing crimes, but you need to be Google level smart to
understand the contents of the box. When a counterparty has limited
processing power, and understands that their capacity to understand
Google is always going to be less than Google’s ability to increase the
complexity of what’s inside the box, the counterparty has to fall back
on the useful heuristic of just assuming that the box contains a crime.
High <em>g</em> doesn’t necessarily mean a high score in the
communications or market flavors of “intelligence”.</p>
<p>There’s sort of a version of <em>falsus in uno, falsus in
omnibus</em> effect going on here. When a cartel member’s obvious
choices have a high crime level (for example, <a href="https://blog.zgp.org/winners-don-t-click-search-ads/">sticking
malware links into search results</a>), then a counterparty can use that
to assign a predicted crime level to the company’s more impenetrable
actions. Having high <em>g</em> and high propensity to crime is like
being good at dealing three-card monte: your win percentage is going to
be high, but most people in a position to choose whether or not to play
will choose not to play.</p>
<p>Attribution cartel members will be able to prove to themselves and to
each other that “they don’t need consent” and are allowed to ignore
objections and opt-outs, but they’re not trustworthy enough to prove it
to non-members of the cartel.</p>
<p><strong>How did the attribution cartel end up at W3C?</strong></p>
<p>At the time that Google was choosing where to host their “Privacy
Sandbox” proposals, W3C was still part of MIT, and had a <a href="https://www.w3.org/policies/antitrust-2017/">really minimal
antitrust policy</a>. And Google managed to get a bunch of obvious
anticompetitive tricks in pretty early on. It could have turned into a
real mess, but fortunately the Competition and Markets Authority in the
UK got involved. (see <a href="https://blog.zgp.org/google-privacy-sandbox-timeline/">Google
“Privacy Sandbox” timeline</a>)</p>
<p><a href="https://www.inma.org/blogs/ideas/post.cfm/3-swedish-publishers-support-decision-to-expel-meta-from-iab-sweden-membership">Meta
has been expelled from IAB Sweden because of their persistent fraud
problem</a> but W3C, even though it is now a separate legal entity and
has <a href="https://www.w3.org/policies/antitrust-2024/">upgraded the
antitrust policy</a>, still has a kind of old-school Internet “assume
good faith” attitude, which doesn’t work for the kind of companies that
are members of the attribution cartel.</p>
<p><strong>Why did the CMA release Google from their “Privacy Sandbox”
commitments when Google was still active in the attribution
cartel?</strong></p>
<p>Good question. James Rosewell, in a <a href="https://www.linkedin.com/posts/rosewell_one-for-the-competition-and-markets-authority-activity-7452774798344048640-eV3C?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAADA5AB-3AkcEQ3MbnZEay0KC4KhHZFy1Q">LinkedIn
post</a> writes,</p>
<blockquote>
<p>The government appear to have interfered and guided the CMA to go
slow on enforcement. That’s not what UK voters and tax payers expect
from government, no matter the party in control.</p>
<p>If Rt Hon Rachel Reeves is serious about economic growth she needs to
take advice from the people that know how to deliver it.</p>
<p>After all the CMA’s 2019 study into digital markets found the cost to
every household in the UK due to the excessive costs of digital
marketing from Google and Meta Facebook’s control over advertising was
£500 per household per year.</p>
<p>That’s over £1000 today per household per year.</p>
</blockquote>
<p><strong>What’s the Eurostack angle again?</strong></p>
<p>The attribution cartel issue becomes important when you look at
possible interactions between news sites that cover politics and the Big
Tech companies that have their own political points of view. Right now,
the attribution cartel members aren’t as loud about their politics as,
say, “X” (the former Twitter) but it’s not going to be realistic to rely
on them to be impartial. <a href="https://themarkup.org/election-2020/2020/10/29/facebook-political-ad-targeting-algorithm-prices-trump-biden">Facebook
Charged Biden a Higher Price Than Trump for Campaign Ads</a>, and the
Trump administration is doing substantial advocacy for the attribution
cartel members, the bill for which will come due at some point.</p>
<p><a href="https://app.sciencesays.com/p/keep-your-ads-away-from-toxic-content">Research
shows that ads perform less well on “toxic”</a> or brand-unsafe
contexts, but in the current political environment the attribution
cartel members will tend to avoid “brand safety” measures in the same
way that ad agencies do: <a href="https://www.adweek.com/agencies/ftc-cracks-down-on-ad-giants-over-alleged-brand-safety-collusion/">FTC
Orders WPP, Publicis, and Dents to Stop Alleged Brand Safety
Collusion</a>. For the attribution cartel, this would mean assigning
more favorable attribution numbers to pro-Trump or anti-EU content.</p>
<p><strong>How should state privacy laws handle the attribution
cartel?</strong></p>
<p>The big asks are the same as for any other adtech/martech. We need an
effective right to know (RtK), and we need the right amount of private
right of action.</p>
<p>State legislators mainly need to be looking at the impact of the
system, and the potential harms, and considering those independently of
whether the system is labeled with “privacy” terms. Just claiming the
“privacy” label, or mathematical properties of a system in isolation,
should not let it avoid the same legislative attention as other systems.
Or more.</p>
<p>It helps to look back at the <a href="https://www.propublica.org/article/facebook-advertising-discrimination-housing-race-sex-national-origin">Facebook
housing discrimination saga</a>, which started in 2016 and took a while
before Meta actually started obeying Federal law. Real-world privacy
harms are harder to track down when Big Tech obfuscates them. State
legislatures need to make sure we have effective RtK including
inferences, and a common sense level of private right of action.</p>
<p>When in doubt, keep the law simple and general and leave as much up
to the jury as possible. (The Flo case was <a href="https://blog.zgp.org/common-sense-one-bullshit-documents-zero/">common
sense one, bullshit documents zero</a>.)</p>
<p><strong>More:</strong> <a href="https://blog.zgp.org/more-attribution-cartel-q-and-a/">More
attribution cartel Q and A</a></p>
<section class="level2" id="bonus-links">
<h2>Bonus links</h2>
<p><a href="https://theconversation.com/in-the-face-of-rampant-ai-is-data-poisoning-a-new-form-of-civil-disobedience-280146">In
the face of rampant AI, is ‘data poisoning’ a new form of civil
disobedience?</a> by Claire Tanner, Mor Vered, and Sam Cadman. <q>Acts
of sabotage have also long been central to collective action against
injustice. In fights for labour rights, workers have employed diverse
tactics to reduce efficiency and productivity. This has ranged from
hotel workers putting salt in sugar bowls to farm workers breaking
machinery. Data poisoning can be viewed as a modern version of these
historic actions.</q></p>
<p><a href="https://www.theatlantic.com/ideas/2026/04/illiberalism-not-inevitable/686778/">Illiberalism
Is Not Inevitable</a> by Anne Applebaum (If we are on the timeline where
democracy and free markets win here, will the attribution cartel
companies be able to pivot back to mainstream corporate politics and
expect to be able to memory-hole this phase they’re going through?)</p>
<p><a href="https://cleandataalliance.substack.com/p/why-privacy-compliance-wont-save">Why
Privacy Compliance Won’t Save Us</a> by Jay Mandel. <q>At some point,
the question stops being how to manage the system and becomes whether
the system deserves to exist at all. Surveillance as a default is not
inevitable. It is a design choice. And like all design choices, it can
be replaced. The real question is no longer whether we can make the
current system safer.</q></p>
<p><a href="https://www.centralcontrol.com/news-posts/2026/4/7/why-geo-rcts-beat-user-level-tests-for-ad-sales-measurement">Why
Geo RCTs Beat User-Level Tests for Ad Sales Measurement</a> at Central
Control. <q>When a media company runs your incrementality test, they
control the randomization, the exposure data, and the reporting. It’s
the classic vendor-grading-its-own-homework problem. This is not an
accusation of bad faith. It is a structural problem that no amount of
good faith resolves.</q> (Also applies to big platform companies—and
they have more people who are good at math.)</p>
<p><a href="https://www.adexchanger.com/data-privacy/what-regulators-talk-about-when-they-talk-about-ad-tech/">What
Regulators Talk About When They Talk About Ad Tech</a> by By Allison
Schiff. <q>Companies also need to make sure their data practices line up
with what they’ve told people in their privacy policies. Offering
privacy controls doesn’t mean much if, behind the scenes, you’re
collecting, sharing or retaining data in ways that contradict those
promises.</q> (To any high-<em>g</em> reader still with me, that doesn’t
mean make the message so complicated there’s no obvious crime, it means
make the message so simple there is obviously no crime. Or at least no
more than usual.)</p>
</section>]]></description>
		</item>
		<item>
			<title>Links about AI bug reports</title>
			<link>https://blog.zgp.org/mlp-2026-04-14/</link>
			<guid>https://blog.zgp.org/mlp-2026-04-14/</guid>
			<pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p>AI bug reports, so hot right now. See <a href="https://lwn.net/Articles/1066581/">A flood of useful security
reports</a> by Daroc Alden. This is not just a Claude Mythos thing. <a href="https://mtlynch.io/claude-code-found-linux-vulnerability/">Claude
Code Found a Linux Vulnerability Hidden for 23 Years</a>. Also not just
an Anthropic thing. Sashiko, <a href="https://lwn.net/Articles/1064830/">which is generating useful info
on kernel bugs</a>, uses Google’s Gemini. See <a href="https://bexelbie.com/2026/04/01/whats-in-a-sashiko-review.html">What’s
Actually in a Sashiko Review?</a> by Brian “bex” Exelbierd. <a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier">Small
models also found the vulnerabilities that Mythos found</a> by Stanislav
Fort. <q>This points to a more nuanced picture than <q>one model changed
everything.</q></q> See also <a href="https://garymarcus.substack.com/p/three-reasons-to-think-that-the-claude">Three
reasons to think that the Claude Mythos announcement from Anthropic was
overblown</a> by Gary Marcus.</p>
<p>Greg Kroah-Hartman <a href="https://www.zdnet.com/article/maybe-open-source-needs-ai/">told
Steven J. Vaughan-Nichols</a> that as of about a month ago, AI bug
reports are not just slop. <q>Now we have real reports. All open-source
projects have real reports that are made with AI, but they’re good, and
they’re real. All open source security teams are hitting this right
now.</q> And Thomas Ptacek writes, <a href="https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/">Vulnerability
research is cooked</a>.</p>
<blockquote>
<p>Vulnerabilities are found by pattern-matching bug classes and
constraint-solving for reachability and exploitability. Precisely the
implicit search problems that LLMs are most gifted at solving. Exploit
outcomes are straightforwardly testable success/failure trials. An agent
never gets bored and will search forever if you tell it to.</p>
</blockquote>
<p>Even if you believe that the LLMs will eventually be able to fix
security issues in an automated or semi-automated way, there’s still a
period of time coming up when much more human bug fixing will be needed
to deal with the “flood.” Any codebase (open source or proprietary)
comes with a short position in maintenance programmers, and all this LLM
bug report news means the short squeeze is on.</p>
<section class="level2" id="bonus-links">
<h2>Bonus links</h2>
<p><a href="https://united24media.com/latest-news/for-the-first-time-ukrainian-unmanned-systems-capture-russian-position-without-infantry-or-losses-17874">For
the First Time, Ukrainian Unmanned Systems Capture Russian Position
Without Infantry or Losses</a> by Katherina Popilnichenko.</p>
<p><a href="https://www.airandspaceforces.com/drone-incursions-b-52-base-strategic-installations/">Drones
Incursions Over B-52 Base Spark Concern</a> by Greg Hadley.</p>
<p><a href="https://futurism.com/artificial-intelligence/ai-college-students-homogenized">College
Students Losing Ability to Participate in Class Discussions Because Due
to Offloading Their Thinking to AI</a> by Joe Wilkins.</p>
</section>]]></description>
		</item>
		<item>
			<title>Attribution cartel update</title>
			<link>https://blog.zgp.org/attribution-cartel-update/</link>
			<guid>https://blog.zgp.org/attribution-cartel-update/</guid>
			<pubDate>Sat, 11 Apr 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p><strong>Previously:</strong> <a href="https://blog.zgp.org/terminator-ending-for-privacy-sandbox/">a
Terminator ending for Google “Privacy Sandbox”?</a></p>
<p>Things seen pretty quiet over at the attribution cartel. It’s not
secret like the <a href="https://en.wikipedia.org/wiki/Lysine_price-fixing_conspiracy">lysine
thing</a> was—they have a GitHub repository at <a href="https://github.com/w3c/attribution">w3c/attribution: Attribution
API</a> and everything. They’re still going, as far as I can tell, but
not getting a lot of ink.</p>
<p>The attribution cartel is learning from the <a href="https://blog.zgp.org/the-end-ish-of-google-privacy-sandbox/">failure
of Google’s “Privacy Sandbox”</a>. Where Google’s 2019-2025 project was
noisy, the attribution cartel is quiet. Where Google tried to do a full
ad stack in one browser, the attribution cartel is doing one key piece
of the stack across multiple browsers. So far, it seems to be working.
My best guess as to why is, as they say, <em>all this</em>. The
companies involved have so <a href="https://en.wikipedia.org/wiki/Flood_the_zone">flooded the zone</a>
that dumping one more load can happen without attracting much attention.
With the whole <a href="https://en.wikipedia.org/wiki/Artificial_intelligence_and_copyright#Training_AI_with_copyrighted_data">“AI”
infringement situation</a>, the fraud and malware crisis on <a href="https://blog.zgp.org/winners-don-t-click-search-ads/">search</a>
and <a href="https://pressgazette.co.uk/platforms/facebook-scam-ads/">social</a>,
and <a href="https://rjionline.org/news/the-traffic-and-revenue-crisis-for-news-is-a-symptom-of-big-techs-economy-wide-trust-collapse/">Big
Tech’s economy-wide trust collapse</a> in general, it’s not a surprise
that this thing is moving but not raising much of a stink.</p>
<p>So what’s so bad about the attribution cartel?</p>
<p><strong>Fraud part 1:</strong> Designing attribution tracking without
fraud protection wastes advertisers’ budgets and deprives legit sites of
revenue.</p>
<p><strong>Fraud part 2:</strong> What’s worse is that fraud creates
incentives to “front-run” conversions, so adds more incentives for risky
data practices. For example, a future fraud operation would be able to
“win” attribution by running a covert speech-to-text app using smart TV
microphones to identify households already about to buy. Turning on the
mic isn’t part of the “Attribution” proposal but “Attribution” provides
the incentive and cash-out mechanism to give more players a reason to do
it. (More: <a href="https://www.adexchanger.com/data-driven-thinking/the-hidden-dangers-of-privacy-preserving-attribution-and-a-smarter-solution/">The
Hidden Dangers Of Privacy-Preserving Attribution – And A Smarter
Solution</a>)</p>
<p><strong>Failure to pass attribution to trusted legit sites:</strong>
<a href="https://www.adexchanger.com/data-driven-thinking/what-happens-when-the-attribution-cartel-meets-advertisings-halo-effect/">What
Happens When The Attribution Cartel Meets Advertising’s Halo
Effect?</a></p>
<p><strong>Boundary testing</strong> probably best describes the <a href="https://blog.zgp.org/google-privacy-sandbox-timeline/">Google
“Privacy Sandbox” saga</a> and is happening again. On August 22, 2019,
Google <a href="https://blog.google/products-and-platforms/products/chrome/building-a-more-private-web/">pitched</a>
“Privacy Sandbox” as an alternative to fingerprinting. The deal was if
people accept some in-browser adtech, then Google won’t have to
fingerprint them. After the project had gotten some momentum, though,
Google changed their policy to <a href="https://blog.lukaszolejnik.com/biggest-privacy-erosion-in-10-years-on-googles-policy-change-towards-fingerprinting/">allow</a>
(and for practical purposes, encourage) fingerprinting. The “Privacy
Sandbox” project may have been completely sincere from the point of view
of the individual Googlers advocating for it in public—but it was part
of a program of centralization of power.</p>
<p>There is a lot of online advice about how to handle boundary testing.
See <a href="https://mylatherapy.com/blog/the-psychology-of-chronic-boundary-testing-why-people-push-limits-and-how-to-protect-your-peace/">Why
People Push Boundaries &amp; How to Protect Your Peace</a> by Brooke
Sprowl. In general, it’s good to clearly communicate the boundary and
consequences for violating it as early as possible. Thanks to early and
creative development of spam filters, the Internet of the late 1990s and
early 2000s did a much better job with setting and enforcing boundaries
on acceptable email practices than today’s Internet is doing on modern
Big Tech schemes. But there’s still time to get out in front of this
one. On the optimistic timeline for the attribution cartel, widely
adopted privacy tools are already set up to block it before the browser
origin trials start.</p>
<p><strong>Breaks Right to Know:</strong> A common feature of privacy
laws is right to know (RtK). Sometimes called a data subject access
right. Policy makers and Big Tech have different interests here.</p>
<ul>
<li><p>Big Tech wants to profile you and deliver deceptive,<span class="aside">ICMYI: <a href="https://www.regulations.gov/comment/FTC-2023-0047-0066">Mark
Cuban’s FTC comment.</a> <q>Why are online platforms like Google,
Facebook and others accepting these ads? By definition, the use of
images from Shark Tank are copyright violations and they all have
technology available to identify fraudulent ads that they <em>choose not
to use</em></q> (emphasis added)</span> personalized ads and offers. (<a href="https://blog.zgp.org/living-with-a-bigger-ad-duopoly/">they have
to, because growth stocks</a>) This goes for everything from small-time
personalized/surveillance pricing up to fraud and large-scale political
misinformation.</p></li>
<li><p>The drafters of privacy laws typically want to expose deception
and discrimination, so they give us a variety of RtK options. Although
RtK can be time-consuming, it’s <a href="https://blog.zgp.org/inquiring-minds-have-a-right-to-know/">effective
as part of a research program or for some kinds of
lawsuits</a>.</p></li>
</ul>
<p>The attribution cartel recognizes that a well-designed RtK will
expose a lot of illegal or actionable practices. So the “Attribution”
proposal hides discrimination by moving measurement into complex ML
systems. Right now the “Attribution” proposal covers only measurement,
not ad placement. But it measures high-discrimination and
low-discrimination placement choices on an equal basis.</p>
<p>For example, say an employer has disability and language prejudice in
the hiring process, and uses two demand-side platforms to run ads for
seasonal employment. One DSP uses a conventional ad placement
methodology. The other DSP uses ML to avoid running ads to people with
disabilities and speakers of certain languages. The “Attribution”
proposal lets that discrimination ML hide in the same way that it lets a
front-running attribution fraud operation hide. If someone suspects that
they aren’t getting certain job or housing ads, the conventional adtech
system gives them a thread to pull on, and sometimes they can make a
case out of it. Adding “privacy-preserving” math to attribution tracking
obfuscates the evidence, allowing Big Tech to keep serving the
advertisers who prefer to discriminate.</p>
<p><strong>Forum shopping:</strong> Attribution cartel members chose to
work in a forum where Big Tech is present, but advertising experts and
smaller competitors are not. Current best practices on how to measure
advertising results (check out <a href="https://www.centralcontrol.com/how-to-guide-georct">Geo RCT
Guide</a> from Central Control and discussions of attribution
requirements at the IAB Tech Lab’s <a href="https://iabtechlab.com/project-rearc/">Project Rearc</a>) don’t
match up very well with the capabilities that the attribution cartel
offers. That’s not surprising—Central Control is working for their
clients, as are many IABTL members, and the attribution cartel is
working for the attribution cartel.</p>
<p><strong>Platform oligopoly is built in.</strong> Key features of the
proposed system assume a power imbalance between large platform and
small advertiser. One example is the so-called “privacy budget.” If an
advertiser makes a mistake on one query, they can be locked out of
future queries regarding the same ads. A large monopoly or oligopoly
company—the kind of firm that can <a href="https://ag.ny.gov/sites/default/files/letters/multistate-letter-on-account-takovers_ltrhd_1.pdf">fail
to provide user support and make users go to the Attorney General for
account issues</a>—can enforce this kind of one-sided requirement on a
smaller advertiser, but in an environment where advertiser, publisher,
and intermediary companies are of similar size, that doesn’t work. The
power imbalance built into the “Attribution” proposal would lock us in
to a centralized, oligarchic Internet future.</p>
<p><strong>Attribution reporting criteria don’t match market
norms.</strong> When people participate in markets, they want trusted
counterparties to have more information, while protecting information
from being disclosed to parties they don’t trust. For example, you
probably want your local newspaper to have more information on you than
some random site that your uncle sends you a link to, or a <a href="https://thenextweb.com/news/x-advertising-boycott-lawsuit-dismissed-garm-antitrust-2">creepy
social site</a> you click on a link to. The attribution cartel doesn’t
match this expectation, so facilitates <a href="https://blog.zgp.org/surveillance-commodity/">commodification</a>
of ad contexts.</p>
<p><strong>User research:</strong> <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4736957">Jereth
et al.</a> found similar <q>perceived privacy violations</q> for a
browser-based advertising system as for conventional third-party
cookies. and <a href="https://georgetownlawtechreview.org/no-cookies-for-you-evaluating-the-promises-of-big-techs-privacy-enhancing-techniques/GLTR-01-2025/">Martin
et al.</a> found <q>misalignment</q> between <q>privacy-enhancing</q>
techniques and the privacy that people expect. Some users found
conventional cookie tracking more acceptable than the more complex
system. <q>[F]or improving services across contexts, consumers judged
the use of raw data as more appropriate compared to using inferences
based on that same raw data.</q></p>
<p><strong>Environmental impact:</strong> <a href="https://www.theguardian.com/commentisfree/2026/apr/12/the-guardian-view-on-ai-politics-us-datacentre-protests-are-a-warning-to-big-tech">Protests
against data centers in the USA</a> are somehow one thing that a divided
nation can agree on. The attribution cartel is proposing burning a lot
more cycles than conventional adtech/martech—not to get privacy as
experienced by people, but in order to add some mathematical properties
that (see user research above) people don’t want. (W3C already had a big
argument over proof of work for identifiers—<a href="https://www.theregister.com/2022/07/01/w3c_overrules_objections/">W3C
overrules Google, Mozilla’s objections to identifiers</a>—and the
attribution cartel is setting things up for another round of
sustainability debate.)</p>
<p><strong>Single country dependency.</strong> At a time when more and
more IT decision makers are looking for alternatives outside the USA (<a href="https://techcrunch.com/2026/04/10/france-to-ditch-windows-for-linux-to-reduce-reliance-on-us-tech/">France
to ditch Windows for Linux to reduce reliance on US tech</a>—that’s a
big project.) <span class="aside"><a href="https://www.npr.org/2023/01/23/1150791939/casablanca-war-movie-film-refugees-nazis">Play
<i>La Marseillaise.</i> Play it!</a></span> the attribution cartel is
going the other direction.</p>
<p><strong>The attribution cartel ate somebody’s pet cat in
Ohio!</strong> Just seeing if you were paying attention. (Watch, this is
going to be the one fact from this page that makes it into the “AI
Overview.” Oops.)</p>
<p><strong>“Pivot to Video” again…really?</strong> Laura Hazard Owen at
Nieman Journalism Lab <a href="https://www.niemanlab.org/2018/10/did-facebooks-faulty-data-push-news-publishers-to-make-terrible-decisions-on-video/">said
it best</a>. <q>News publishers’ <q>pivot to video</q> was driven
largely by a belief that if Facebook was seeing users, in massive
numbers, shift to video from text, the trend must be real for news video
too — even if people within those publishers doubted the trend based on
their own experiences…</q> (Making decisions based on
<q>authoritative</q> numbers from Big Tech has been tried, and
publishers and advertisers are not solidly in <q>fool me twice, shame on
me</q> territory. Read the whole thing.)</p>
<section class="level2" id="conclusion">
<h2>Conclusion</h2>
<p>Oligarchs lie about obvious facts.</p>
<p>Broligarchs lie about obvious facts, then insist that they only sound
wrong because you’re not “technical” enough.</p>
<p>That’s not the standard of proof that’s needed here. Markets depend
on shared understanding between counterparties. Advertising has to be
understandable enough that there’s obviously very little crime—not so
complicated that there’s very little obvious crime.</p>
</section>
<section class="level2" id="bonus-links">
<h2>Bonus links</h2>
<p><a href="https://www.seismic.org/blog/we-ve-seen-this-movie-before-what-history-tells-us-about-ai-s-%E2%80%98inevitability%E2%80%99-argument">We’ve
Seen This Movie Before: What History Tells Us About AI’s ‘Inevitability’
Argument</a> from the Seismic Foundation. (The <q>Five Narrative Moves
That Repeat Across Industries</q> sound familiar.)</p>
<p><a href="https://cleandataalliance.substack.com/p/the-evolution-of-deception-when-scams">The
Evolution of Deception: When Scams Stop Looking Like Scams</a> by Jay
Mandel. <q>Technology has closed the gap between what is real and what
is fabricated so effectively that our biological instincts can no longer
keep up. Modern scams are no longer isolated acts of trickery. They are
industrialized systems of deception, optimized at scale.</q></p>
<p><a href="https://prospect.org/2026/04/06/why-were-removing-our-programmatic-ads/">Why
We’re Removing Our Programmatic Ads</a> by Mitchell Grummon. <q>Online
advertising is bad for users, publishers, and even advertisers. The only
beneficiaries are the Big Tech platforms. We’re doing something about
it.</q></p>
</section>]]></description>
		</item>
		<item>
			<title>Dawn takes grease out of your way</title>
			<link>https://blog.zgp.org/dawn-takes-grease-out-of-your-way/</link>
			<guid>https://blog.zgp.org/dawn-takes-grease-out-of-your-way/</guid>
			<pubDate>Fri, 10 Apr 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p><em>(point of order: this site is now
provisionally compliant with IEEE 7012: MyTerms. See the end of this
blog post for details.)</em></p>
<p><strong>Previously:</strong> <a href="https://blog.zgp.org/suspicion-and-slop-in-the-rugpull-economy/">Suspicion
and slop in the rugpull economy</a>. I checked the Costco site and
compared prices:</p>
<ul>
<li><p><a href="https://www.costco.com/p/-/kirkland-signature-ultra-shine-liquid-dish-soap-fresh-90-fl-oz/4000247808">Kirkland
Signature Ultra Shine Liquid Dish Soap</a> $9.99</p></li>
<li><p><a href="https://www.costco.com/p/-/dawn-platimum-advanced-power-dishwashing-liquid-fresh-90-fl-oz/4000438985?langId=-1">Dawn
Platimum Advanced Power Dishwashing Liquid</a> $11.59</p></li>
</ul>
<p>Both 90 oz. bottles. (11.59-9.99)/9.99 = 16% price premium for the
big-time brand.</p>
<p>Back in 2012, Consumer Reports compared big brands to store brands
and <a href="https://www.consumerreports.org/cro/magazine/2012/10/store-brand-vs-name-brand-taste-off/index.htm">found
an average of 25% in savings</a>. which means that the big brands had an
average 33% price premium then.</p>
<p>The peak surveillance advertising years have been <a href="https://michaelfarmer.substack.com/p/why-have-most-advertisers-suffered">terrible
for the big, heavily advertised brands</a>. Meanwhile we have seen
growth in A-list store brands—Costco seems to be disciplined about not
releasing a Kirkland contender unless they can do it at a comparable
quality level to the leading brand in the category.</p>
<p>Maybe</p>
<ul>
<li><p>other signals of quality (online reviews?) are relatively
stronger compared to brand advertising?</p></li>
<li><p>investments in surveillance advertising have displaced R&amp;D,
resulting in less differentiated brands on average?</p></li>
</ul>
<p>P&amp;G did not come in to the surveillance advertising era with a
data or IT disadvantage, but surveillance advertising has not been good
to them. So now, what’s the plan here? (If it’s
personalized/surveillance pricing that’s <a href="https://blog.zgp.org/price-of-price-discrimination/">not going to
work any better imho</a>.</p>
<section class="level2" id="myterms-support-in-progress">
<h2>Myterms support (in progress)</h2>
<p>This site now has a <code>.well-known/myterms.json</code> file that
includes the effective date, along with a copy of the existing site ToS.
I’ll update it to add all the other MyTerms agreements that I’m willing
to enter into with a user. <span class="aside">FIXME: download and add
MyTerms agreements</span></p>
<p>From the user POV all you should have to do is save a copy of that
JSON file: <a href="/.well-known/myterms.json">.well-known/myterms.json</a>. This is a
manual process for now, but a browser extension should be able to
automate it.</p>
<p>There is a link tag in the head on this page to let you know the JSON
file is there:</p>
<pre><code>&lt;link href="https://blog.zgp.org/.well-known/myterms.json"
      rel="terms-of-service"
      type="application/json"&gt;</code></pre>
<p>see <a href="https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Attributes/rel">HTML
attribute: rel</a> for info on <code>terms-of-service</code>.</p>
<p>Right now this extremely basic MyTerms setup doesn’t displace
“consent management” overhead for those who feel they need it (but most
sites can get by without it, as <a href="https://github.blog/news-insights/company-news/no-cookie-for-you/">the
GitHub Blog</a> pointed out a while ago.)</p>
<p>Add a browser extension to check and save MyTerms files and you
should be able to get rid of “consent” dialogs too. But there’s still
some record-keeping hassle from the site side.</p>
<p>So eventually a site—or a service provider— is going to have to
extend the MyTerms JSON to include a URL that a user can POST to, with a
record of the contract they accepted, or state that they they rejected
all possible contracts available at the site, and request that the site
should support a different contract. That would make record-keeping
practical for the site, can scale up to more users.</p>
<p>Here’s the code:</p>
<nav><div class="highlight"><pre><span></span><span class="ch">#!/usr/bin/env python3</span>

<span class="kn">from</span><span class="w"> </span><span class="nn">datetime</span><span class="w"> </span><span class="kn">import</span> <span class="n">datetime</span>
<span class="kn">from</span><span class="w"> </span><span class="nn">email.utils</span><span class="w"> </span><span class="kn">import</span> <span class="n">format_datetime</span>
<span class="kn">import</span><span class="w"> </span><span class="nn">json</span>
<span class="kn">from</span><span class="w"> </span><span class="nn">pathlib</span><span class="w"> </span><span class="kn">import</span> <span class="n">Path</span>

<span class="k">with</span> <span class="nb">open</span><span class="p">(</span><span class="s1">'public/web-site-user-agreement/index.html'</span><span class="p">)</span> <span class="k">as</span> <span class="n">tos_in</span><span class="p">:</span>
    <span class="n">tos_html</span> <span class="o">=</span> <span class="n">tos_in</span><span class="o">.</span><span class="n">read</span><span class="p">()</span>

<span class="n">Path</span><span class="p">(</span><span class="s2">"public/.well-known"</span><span class="p">)</span><span class="o">.</span><span class="n">mkdir</span><span class="p">(</span><span class="n">parents</span><span class="o">=</span><span class="kc">True</span><span class="p">,</span> <span class="n">exist_ok</span><span class="o">=</span><span class="kc">True</span><span class="p">)</span>
<span class="k">with</span> <span class="nb">open</span><span class="p">(</span><span class="s1">'public/.well-known/myterms.json'</span><span class="p">,</span> <span class="s1">'w'</span><span class="p">)</span> <span class="k">as</span> <span class="n">tos_wk</span><span class="p">:</span>
    <span class="n">json</span><span class="o">.</span><span class="n">dump</span><span class="p">({</span><span class="s1">'effective_date'</span><span class="p">:</span> <span class="n">format_datetime</span><span class="p">(</span><span class="n">datetime</span><span class="o">.</span><span class="n">now</span><span class="p">()),</span>
               <span class="s1">'tos'</span><span class="p">:</span> <span class="n">tos_html</span><span class="p">},</span> <span class="n">tos_wk</span><span class="p">)</span>
</pre></div>
</nav>
<p>If you want to accept my site ToS you should be able to grab the file
and save it. (First person to do this could have a claim to the <a href="https://en.wikipedia.org/wiki/Golden_spike">golden spike</a> of
MyTerms.)</p>
</section>
<section class="level2" id="bonus-links">
<h2>Bonus links</h2>
<p><a href="https://techcrunch.com/2026/04/10/france-to-ditch-windows-for-linux-to-reduce-reliance-on-us-tech/">France
to ditch Windows for Linux to reduce reliance on US tech</a> by Zack
Whittaker. (Play <em>La Marseillaise</em>! Play it!)</p>
<p><a href="https://www.nature.com/articles/d41586-026-01100-y">Scientists
invented a fake disease. AI told people it was real</a> by Chris
Stokel-Walker. <q>The experiment’s reach has now spread into the
published medical literature.</q></p>
<p><a href="https://heathercoxrichardson.substack.com/p/april-8-2026">April 8,
2026</a> by Heather Cox Richardson.</p>
<p><a href="https://vsquare.org/orban-spying-toolkit-cobwebs-webloc-hungary-spyware-citizen-lab/">Orbán’s
Spying Kit Revealed: Israeli Surveillance Tool Combined with Hungarian
Technology</a> by Szabolcs Panyi. <q>According to Citizen Lab’s fresh
full research paper, <q>Webloc is a global geolocation surveillance
system that monitors hundreds of millions of people based on data
purchased from consumer apps and digital advertising.</q> In short,
Webloc uses smartphone apps’ advertising data for mass surveillance
without the knowledge or consent of users. Hungary is the first
confirmed country to deploy Webloc within the European Union, where data
protection and privacy rules under the General Data Protection
Regulation (GDPR) effectively prohibit such use of personal and
advertising data.</q></p>
<p><a href="https://www.fastcompany.com/91523804/consumer-electronics-are-innovative-but-lack-imagination">Consumer
electronics are innovative but lack imagination</a> by James Greenfield.
<q>The scale of Apple mimicry across the category is remarkable. It
speaks to a lack of confidence beyond the product.</q></p>
<p><a href="https://reversemediaschedules.com/">Reverse Media Schedules
- Powered in New Zealand by dentsu</a> <q>People are willing to pay 2%
less for a brand they’ve seen as litter That makes litter the worst
advertising in the world.</q></p>
</section>]]></description>
		</item>
		<item>
			<title>Suspicion and slop in the rugpull economy</title>
			<link>https://blog.zgp.org/suspicion-and-slop-in-the-rugpull-economy/</link>
			<guid>https://blog.zgp.org/suspicion-and-slop-in-the-rugpull-economy/</guid>
			<pubDate>Fri, 03 Apr 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p><a href="https://eaonpritchard.substack.com/p/where-did-it-all-go-wrong-it-never">Eaon
Pritchard writes</a>,</p>
<blockquote>
<p>By way of a short recap, a big part of the problem of tracking and
targeting is information asymmetry. When a brand appears to know more
about you than you’ve consciously shared, it triggers the same evolved
instincts we use to detect threat, manipulation, or social imbalance. In
evolutionary terms, that’s not a ‘conversion opportunity’. That’s a red
flag to our stone-age minds.</p>
<p>What is designed as ‘relevance’ is not the same as trust (implicit as
it is).</p>
</blockquote>
<p>Personalization and trust tend to have a negative correlation. Rory
Sutherland uses the example of a <a href="https://www.marketingweek.com/richard-shotton-power-costly-signalling/">wedding
ceremony</a>. You don’t go around and tell people one by one that you’re
together, you make a big deal of the celebration. And possibly the
worst-personalized advertising medium, Little League sponsorships, is
the best at trust building. Leagues keep photos and records, making team
sponsorship a bad deal for a fly-by-night company and a good deal for a
business that expects to offer <a href="https://blog.zgp.org/accounting-help-needed/">win-win</a> products
or services in the long term.</p>
<p>Where did it all go wrong? Michael Farmer, in <a href="https://michaelfarmer.substack.com/p/why-have-most-advertisers-suffered">Why
Have Most Advertisers Suffered From Slow Brand Growth Rates Since 2009?
Ten Major Reasons</a>, points out <q>the problem of advertiser growth
since 2009, when 2/3rds of major advertisers saw their sales growth
rates fall to well below the nominal GDP growth rate of 4.7% (2.4%
inflation plus 2.3% real growth).</q></p>
<p>A legitimate company like P&amp;G (2009-2024 CAGR 0.6%) can, to use a
polite expression for slop ads, <a href="https://www.mediapost.com/publications/article/413832/call-for-reinvention-a-conversation-with-pgs-ma.html">create
fast cycle content to drive traffic</a>, but a scammer can always do it
better. A scammer can use the best AI slop service and surveillance
advertising available this minute, but P&amp;G is always going to be a
number of steps behind, because of the levels of approval needed to use
some new AI slop service or ad personalization scheme. Often, by the
time a big company can get on something, it has already been superseded
or <a href="https://www.404media.co/disneys-openai-sora-disaster-shows-ai-will-not-save-hollywood/">EOLed</a>.</p>
<p>Any advertising medium that’s</p>
<ul>
<li><p>worth paying for from the seller side and</p></li>
<li><p>worth paying attention to from the buyer side</p></li>
</ul>
<p>has to be based on something that a legit seller can do better than a
deceptive seller. Too often, legit companies are trying to compete with
deceptive ones in a “move fast and break things” fight that they will
lose. <a href="https://www.campaignlive.com/article/open-letter-end-machiavellian-marketing/1944027">Christina
Garnett writes</a>,</p>
<blockquote>
<p>Customers are more selective because we taught them to be. Their
trust is thin because we diluted the very concepts that once signaled
honesty and care. They can see when outrage is manufactured, when
vulnerability is scripted and when belonging is offered only to drive
metrics.</p>
<p>The tricks aren’t tricking anyone anymore. Consumers just feel
manipulated.</p>
</blockquote>
<p>P&amp;G can make <a href="https://adaged.blogspot.com/2026/03/whats-in-name.html">better
dish soap</a> than other companies, but they’re at a disadvantage in AI
slop and surveillance advertising. <a href="https://www.bjanda.com/blog/relax-its-only-an-existential-threat/">Brian
Jacobs writes</a>,</p>
<blockquote>
<p>If you believe everything you’re told, advertising is really very
straightforward. Give your budget to META (insert the name of your
favourite platform here). Send over your objectives and brief. META (or
whoever) will deploy a magic AI tool, which will design a selection of
ads. The alternatives will be pretested. They will then place the
winning execution across their individual channels.</p>
</blockquote>
<p>Meta advertising works better for a random drop-shipper than for an
established firm with an actual detergent research lab. Meta ads work
fine for a while, if the point is to trick people into voting for crooks
or buying crap. A recent Meta success story, the <a href="https://www.drugdiscoverytrends.com/the-new-york-times-spotlighted-medvi-the-fda-had-already-warned-the-self-proclaimed-fastest-growing-company-in-history/?">“fastest
growing company in history”</a>, is a weight loss scam that makes up
physician testimonials and uses face-swapped patient photos. (See <a href="https://garymarcus.substack.com/p/the-back-story-behind-the-first-18">The
back story behind the first “$1.8 Billion” dollar “AI Company”</a> by
David Marcus.)</p>
<p>Meta’s personalized advertising is auction-based, and we have known
since 2006 that auction-based ad platforms eventually <a href="https://www.nngroup.com/articles/search-engines-as-leeches-on-the-web/">bid
up rates to extract all the profits from the advertisers that use
them</a> (Jakob Nielsen’s analysis applies not just to search, but to
other auction-based designs including RTB and social). If typical
advertisers on Meta’s sites and apps were anywhere near as successful as
the outliers that make the news, then <a href="https://www.joanwestenberg.com/the-passive-income-trap-ate-a-generation-of-entrepreneurs/">The
“Passive Income” trap ate a generation of entrepreneurs</a> wouldn’t be
a thing. And it’s not just the small-timers. Relying on auction-based
advertising is showing up as a problem for well-funded firms too. <a href="https://thenextweb.com/news/allbirds-39m-asset-sale">Allbirds</a>
are canaries in the Meta coal mine, along with <a href="https://blog.zgp.org/the-other-side-of-meta-s-fraud-problem/">Oddity
Tech</a>, which went all in on personalized cosmetics on Instagram.</p>
<p>The winners in the surveillance advertising game are the <a href="https://blog.zgp.org/but-i-want-to-turn-people-into-dinosaurs/">Big
Tech platforms that design for scams</a> and the scammers they enable.
In <a href="https://truthonthemarket.com/2026/03/30/the-myth-of-the-unwanted-internet/">The
Myth of the Unwanted Internet</a>, Julian Morris asserts that the
Internet “solved for trust” by adding user-tracking features. But that
doesn’t describe the Internet as we currently experience it. In fact,
we’re in an <a href="https://rjionline.org/news/the-traffic-and-revenue-crisis-for-news-is-a-symptom-of-big-techs-economy-wide-trust-collapse/">economy-wide
trust collapse</a> because of decisions to add surveillance features
that give deceptive companies advantages over legitimate ones. A 2025
FTC report showed <a href="https://www.ftc.gov/news-events/news/press-releases/2025/03/new-ftc-data-show-big-jump-reported-losses-fraud-125-billion-2024">a
Big Jump in Reported Losses to Fraud to $12.5 Billion in 2024</a>—before
the <a href="https://www.propublica.org/article/trump-doj-immigration-bondi-declinations-criminal-investigations">change
of administration</a> to one that’s more <a href="https://www.techpolicy.press/techs-love-affair-with-trump-grows-stronger-by-the-day/">friendly
to large, deceptive companies</a>. Thanks to decisions by politicians to
prioritize “innovation,” the scammers even have their own <a href="https://bobsullivan.net/cybercrime/gas-station-hero-stops-crypto-kiosk-scams-again-and-again/">payment
platform, “crypto ATMs”</a> and <a href="https://theconversation.com/afrobeats-celebrates-cybercrime-and-its-becoming-a-global-problem-277543">music
scene</a>.</p>
<p>It’s time for a more market-aware approach to <a href="https://blog.zgp.org/happy-privacy-bill-season-in-the-low-trust-economy/">privacy
legislation and regulation</a>. Instead of making the unrealistic
assumption that surveillance advertising has some kind of economic
benefit that needs to be balanced with user privacy interests, we have
to recognize that consumers and legitimate companies are not on opposite
sides, but cooperating players in a game with the goal of making win-win
deals. The opponents are the Big Tech companies and the scammers. And
the problem isn’t specific data practices that could be replaced by <a href="https://blog.zgp.org/pets-and-public-policy/">clever but pointless
math</a>. Privacy people need to bring more and thicker PDFs to the
privacy bill hearings. <strong>More:</strong> <a href="https://blog.zgp.org/advertising-personalization-good-for-you/">advertising
personalization: good for you?</a></p>
<section class="level2" id="bonus-links">
<h2>Bonus links</h2>
<p><a href="https://www.sciencedirect.com/science/article/abs/pii/S0140673626004642">Targeted
advertising in generative artificial intelligence chatbots: a new public
health risk</a> by Kathryn Backholer and Raffaele Ciriello. <q>The
window to act is narrowing. Unlike earlier digital platforms, norms and
revenue models for AI chatbots are still forming, which presents a rare
opportunity to embed health-protective governance before
advertising-driven architectures become entrenched.</q> (Meanwhile, the
public health menace of existing surveillance advertising is already
here—but it already has too many “entrenched” lobbyists to fix
easily.)</p>
<p><a href="https://mccue.dev/pages/3-11-25-life-altering-postgresql-patterns">Life
Altering PostgreSQL Patterns</a> by Ethan McCue. <q>There is a set of
things that you can do when working with a Postgres database which I
have found made my and my coworker’s lives much more pleasant. Each one
is by itself small, but in aggregate have a noticeable effect.</q> (Ever
notice you don’t see this kind of stuff for Oracle? IMHO the “AI”
bullshit explanation for recent layoffs is not the whole story.)</p>
<p><a href="https://www.apmreports.org/episode/2019/08/22/whats-wrong-how-schools-teach-reading">How
a flawed idea is teaching millions of kids to be poor readers</a> by
Emily Hanford. <q>For decades, reading instruction in American schools
has been rooted in a flawed theory about how reading works, a theory
that was debunked decades ago by cognitive scientists, yet remains
deeply embedded in teaching practices and curriculum materials.</q></p>
<p><a href="https://thenextweb.com/news/iran-irgc-18-us-tech-companies-military-targets">Iran’s
Revolutionary Guards just named 18 US tech firms as military targets.
The age of the civilian data centre is over.</a> by Allison Steffens
Herrera. (Related: <a href="https://www.tomshardware.com/tech-industry/iranian-missile-blitz-takes-down-aws-data-centers-in-bahrain-and-dubai-amazon-declares-hard-down-status-for-multiple-zones">Iranian
missile blitz takes down AWS data centers in Bahrain and Dubai</a> by
Jowi Morales.</p>
</section>]]></description>
		</item>
		<item>
			<title>Pay the oracle.</title>
			<link>https://blog.zgp.org/pay-the-oracle/</link>
			<guid>https://blog.zgp.org/pay-the-oracle/</guid>
			<pubDate>Wed, 01 Apr 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p>Would planning assumptions about the war on Iran
have turned out to be <a href="https://houseofsaud.com/iran-war-ai-psychosis-sycophancy-rlhf/">so
wrong</a> if, say, the US government had gone whole hog for prediction
markets instead of LLMs? Well, yes. If there’s enough pressure to get
the “right” answer, any system can be leaned on to produce it. If the
USA had dug up <a href="https://en.wikipedia.org/wiki/Total_Information_Awareness">some
old DARPA research on prediction markets</a> and used it for war
planning, we’d still be in the same situation, only the news would be
about how prediction markets failed, not about how the Pentagon’s LLM
frenzy did.</p>
<p>Instead, the big prediction market news is <a href="https://www.timesofisrael.com/gamblers-trying-to-win-a-bet-on-polymarket-are-vowing-to-kill-me-if-i-dont-rewrite-an-iran-missile-story/">‘Gamblers
on POLYMARKET vowing to kill me if I don’t rewrite Iran missile
story’…</a> by Emanuel Fabian at <cite>The Times of Israel</cite>.
Journalists were offered bribes and received threats over changing a
news story that was key to resolving a prediction market contract. The
big connection between news organizations and prediction markets is not
<a href="https://www.overcomingbias.com/p/insider-journalism">competition,
as Prof. Robin Hanson suggests</a>, or a source of <a href="https://www.fastcompany.com/91523276/fox-is-the-latest-to-add-prediction-markets-as-a-new-data-layer-for-news-coverage">one
more ticker on a crowded news screen</a>, but dependency. A prediction
market needs an outside source of information, or “oracle” to resolve
contracts, which for most kinds of world events markets means a news
site.</p>
<p>The <cite>Times of Israel</cite> situation is a much larger scale
version of a problem that we ran into with <a href="https://blog.zgp.org/bug-futures-references/">bug futures</a>. The
cost of resolving a contract is high relative to the value of the
contract. That applies to both really small incentivization market
issues (does this patch fix this bug?) and big picture markets. Previous
criticism of war markets, such as <a href="https://theconversation.com/gamblers-can-now-bet-on-the-outcome-of-wars-and-thats-a-problem-277374">Gamblers
can now bet on the outcome of wars – and that’s a problem</a>, by
Karoline Thomsen and Douglas Guilfoyle, focuses on the problems of
corrupting decision makers and incentivizing leaks. But <a href="https://aftermath.site/kalshi-mrbeast-insider-trading/">insider
trading</a> is a feature, not a bug. Prediction markets tend to blend
into incentivization markets. Prof. Andrew Gelman <a href="https://statmodeling.stat.columbia.edu/2026/03/06/killing/">writes</a>,</p>
<blockquote>
<p>To put it another way, the ideal for a prediction market is for it to
have high stakes (so that it’s costly to try to manipulate the price)
with bettors being people with no influence on the outcome. But such a
market will be a ripe target for people who can influence the outcome
and for insider trading.</p>
</blockquote>
<p>In general, the possibility of <q>insider trading</q> is a win for
prediction markets—and a good argument for why there should be more
prediction markets—because they could disincentivize people from forming
the kind of large, untrustworthy organizations whose members are likely
to participate in <q>insider trading.</q> But the oracle problem is a
lot bigger. The solution we came up with has two parts.</p>
<p><strong>First, pay the oracle, a lot.</strong> Reporting from a war
zone is obviously costly and risky, but resolving any market is usually
going to cost a pretty high fraction of the money at risk. So we imposed
high oracle fees, which are paid by the winners and disclosed up
front.</p>
<p><strong>Second, make it easy for traders to avoid the oracle fees by
getting out of their positions.</strong> So you end up with a market
that trades in a narrower band of prices (there are no worthless
positions. Even a bet on an impossible event is worth about the same as
the oracle fee, because the holder of the winning side would rather get
their 90% now than hold out for 100% minus a 10% oracle fee at
maturity.)</p>
<p>Oracle fees are easy for an internal bug futures market or other
internal corporate prediction/incentivization market, but for markets on
news events, where the oracle is an outside source, markets need other
options.</p>
<ul>
<li><p>Public sector oracles. Government bodies such as <a href="https://www.ukmto.org/about-us">United Kingdom Maritime Trade
Operations</a> and the <a href="https://en.wikipedia.org/wiki/Bureau_of_Labor_Statistics">Bureau
of Labor Statistics</a> already produce oracle-ready information. And
prediction markets provide an anti-corruption and counterintelligence
check on those. It’s hard to tell if a government agency has a foreign
spy, but an insider trading problem will be more likely to show up in
the market numbers. (For example, <a href="https://www.nbcnews.com/tech/tech-news/democrats-push-trump-admin-prediction-market-insider-trading-rcna265503">the
current US administration is obviously leaky</a>, and prediction market
trading patterns help people decide whether to share information with
it.) So there is a good case for the public sector to provide
oracle-friendly event reports.</p></li>
<li><p>A copyright-like oracle right for news organizations. <a href="https://en.wikipedia.org/wiki/Article_One_of_the_United_States_Constitution">Article
One, Section 8 of the United States Constitution</a> just <a href="https://en.wikipedia.org/wiki/Copyright_Clause">says</a>
<q>securing for limited Times to Authors and Inventors the exclusive
Right to their respective Writings and Discoveries,</q> so an oracle
right would probably work here. <a href="https://newrepublic.com/article/207301/polymarket-kalshi-iran-war-gambling">Partnerships
between news companies and prediction markets</a> are a thing, but
there’s still a free riding problem that an oracle right would help
address. If a news site is not opposed to prediction markets on
principle, it has lots of incentives to seek oracle deals, including
because of the money talks bullshit walks effect. Total money at stake
in contracts for which this site is an oracle could be a useful
qualitative news metric, and a news site that can’t be a reliable oracle
is probably <a href="https://blog.zgp.org/vibe-cms/">unreliable in other
ways</a> too.</p></li>
</ul>
<p>News site revenue is a hard problem, and diversifying revenue is a
big deal. Although a lot of people like <a href="https://blog.zgp.org/micropayments-as-a-reality-check-for-news-sites/">micropayments</a>,
and the ability of a site to get micropayments is a useful crowdfunded
quality check, micropayments have a fundamental problem. Much of the
value provided by a news site is the stories that didn’t happen. Nobody
would pay to read “City Council Didn’t Steal Everything In Town Because
a Reporter Was At The Meetings” but that (unwritten) story is worth more
to the town than the alternative.</p>
<p>It seems like the viable options are either an actively enforced ban
on prediction markets, which would limit the number of people with the
resources and incentives to bribe or threaten reporters, or an
enforceable oracle right, which would give the news organization
additional money to keep reporters safe and honest, and an incentive to
stay accurate and useful as an oracle in order to keep oracle deals.
Otherwise, traders on free-riding prediction markets, whether legal or
illegal and tolerated, have the ability to subvert the news sites they
use, but the news sites have no funding for their defense.</p>
<section class="level2" id="bonus-links">
<h2>Bonus links</h2>
<p><a href="https://kyivindependent.com/opening-the-air-defense-market-defense-minister-fedorov-says-of-new-private-sector-air-defense-units/">‘Opening
up air defense market’ — Defense Minister Fedorov reports 1st drone
shootdown by ‘private sector’ air defense units</a> by Kollen Post.
<q>At the same time, there is little public information on how private
air defense units function and are funded, particularly in their early
phases.</q></p>
<p><a href="https://www.dw.com/en/solar-is-winning-the-energy-race/a-76517556">Solar
is winning the energy race</a> by Gero Rueter. <q>Many early forecasts
greatly underestimated the growth of the solar industry. In its annual
global energy analysis in 2020, the International Energy Agency wrote
that worldwide solar expansion would hit around 120 GW in 2024. In
reality, a whopping 597 GW were installed that year, nearly five times
as much as predicted.</q></p>
<p><a href="https://readwrite.com/vitalik-buterin-warns-prediction-markets-risk-corposlop/">Vitalik
Buterin warns prediction markets risk sliding into ‘corposlop’</a> by
Suswati Basu. <q>In his view, platforms are drifting toward what he
called an unhealthy <q>product market fit.</q> Rather than focusing on
surfacing useful long-term insights, many have centered their offerings
on <q>short-term cryptocurrency price bets, sports betting, and other
similar things that have dopamine value but not any kind of long-term
fulfillment or societal information value.</q></q></p>
</section>]]></description>
		</item>
		<item>
			<title>Is it safe to turn off your ad blocker?</title>
			<link>https://blog.zgp.org/is-it-safe-to-turn-off-your-ad-blocker/</link>
			<guid>https://blog.zgp.org/is-it-safe-to-turn-off-your-ad-blocker/</guid>
			<pubDate>Sat, 28 Mar 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p>I think I said I would post here when it’s safe
to turn off your ad blocker. The tl;dr is: <strong>no.</strong> Will
update if that changes.</p>
<p>The long answer is that a dirty business has gotten dirtier. Not only
have the ads gotten heavier (<a href="https://thatshubham.com/blog/news-audit"><q>I went to the New York
Times to glimpse at four headlines and was greeted with 422 network
requests and 49 megabytes of data. It took two minutes before the page
settled.</q></a>) and added <a href="https://stuartbreckenridge.net/2026-03-19-pc-gamer-recommends-rss-readers-in-a-37mb-article/">more
aggressive data usage as they refresh on the page</a>, the business side
is all in on the low-trust economy, too.</p>
<p>Advertising’s hottest club is “principal buying” or “principal
media”—big agency holding companies functioning not just as agencies to
buy ad space on behalf of clients, but trading ad space for their own
account before the client sees it. <a href="https://digiday.com/media-buying/be-an-engineer-to-understand-the-engine-why-consultant-nick-manning-thinks-principal-media-is-anti-marketer/">Nick
Manning explains.</a></p>
<blockquote>
<p>This has been going on for decades, especially in markets like Asia
Pacific, Eastern Europe and Southern Europe. Broadly speaking, what’s
happened over time is that those practices [were] imported into the U.S.
around 2010-2011.</p>
<p>The thing that’s made it happen more recently is that the [agency]
groups started to see their other revenues decline, and this is one way
of arresting that decline — but it’s also easier to do this because you
don’t have to win new clients, you don’t have to pitch, you don’t have
to employ any more people. You just have to set up the financial
machinery to do it.</p>
</blockquote>
<p>A decades-old practice is getting more attention now, because of two
stories.</p>
<ul>
<li><p>Paperwork that has come out in a lawsuit by a former WPP
employee.</p></li>
<li><p>A beef between another large holding company, Publicis, and a
“demand-side” adtech firm, The Trade Desk, with each company accusing
the other of non-transparent practices (and IMHO they’re both
right).</p></li>
</ul>
<p>Covered in <a href="https://www.adexchanger.com/marketers/the-rise-of-principal-media-and-the-end-of-the-agencies-as-we-knew-them/">The
Rise Of Principal Media And The End Of The Agencies As We Knew Them</a>
by James Hercher. Companies that are in a position to get a peek at
principal buying from both sides—as both owners of ad-supported contexts
and buyers of ads—aren’t sold on it.</p>
<blockquote>
<p>WPP’s legal disclosures reveal that none of its top 20 biggest
clients participate in principal media – despite the fact that many of
WPP’s largest brand accounts are themselves the purveyors of principal
media deals on the supply side, including Paramount, Comcast, Uber,
Amazon, Google and Sony.</p>
<p>These brands stand to gain the most from principal media, which
rewards pure volume. They’re also very knowledgeable about the practice,
which is perhaps one reason they avoid it when they have their buy-side
hat on.</p>
</blockquote>
<p>More info in <a href="https://www.adweek.com/programmatic/the-trade-desk-publicis-fight-is-really-a-war-against-transparency/">The
Trade Desk-Publicis Fight Is Really a War Against Transparency</a> by
Jay Friedman and <a href="https://digiday.com/media-%20buying/publicis-vs-the-trade-desk-isnt-really-about-transparency-its-about-who-gets-the-margin/">Publicis
vs. The Trade Desk isn’t really about transparency – it’s about who gets
the margin</a> by Ronan Shields.</p>
<blockquote>
<p>When something isn’t easy to measure, price becomes the proxy. So,
the world’s largest agencies now essentially pitch for free and operate
on razor-thin disclosed margins.</p>
<p>To survive, they have to generate profit from hidden fees and
undisclosed arrangements.</p>
<p>Marketers, in turn, reward this by continuing to hire and rehire the
agencies that play the game most aggressively.</p>
<p>This forces increasingly complex schemes and systems, which pulls
time, energy, and talent away from the thing the agency was
theoretically hired to do in the first place: drive brand growth.</p>
</blockquote>
<p>Michael Farmer has more info on how big agencies have failed to keep
the rates up for the legit side of their businesses: <a href="https://michaelfarmer.substack.com/p/price-premiums-are-the-ultimate-measure">Price
premiums are the ultimate measure of successful professional
relationships. Holding Companies have failed to achieve them</a></p>
<p>Besides brands, the other big losers from this whole mess are the
long-suffering legit ad-supported sites, whose business model is like
selling fresh artisinal donuts to a market that makes a point of not
being able to tell a donut from a turd. More on that problem in <a href="https://pressgazette.co.uk/news/the-seo-parasites-buying-exploiting-and-ultimately-killing-online-newsbrands/">The
SEO parasites buying, exploiting and ultimately killing online
newsbrands</a> by Rob Waugh. <q>Sites typically go from being viable
outlets, still valuable enough to be bought for large sums, to being
filled with AI-written articles and casino links, before simply being
abandoned.</q></p>
<section class="level2" id="the-alternative-is-worse">
<h2>The alternative is worse</h2>
<p>Web adtech is a dirty business, but the real villainy gets started
within the Big Tech platforms, where internal ad markets run inside the
data center and not out on the web where competitors and researchers can
watch them in browser dev tools.</p>
<p>Jack Benjamin asks, <a href="https://uk.themedialeader.com/are-we-monetising-addiction-ad-industry-faces-reckoning-following-social-media-addiction-lawsuit-verdict/">‘Are
we monetising addiction?’ Ad industry faces reckoning following social
media addiction lawsuit verdict</a>. <q>Advertisers, it follows, are
complicit in funnelling spend to platforms without demanding
transparency into what specific content they are monetising against.</q>
(In the long run, this will be a problem for recruiting into marketing
as an occupation. If a lot of the work is <a href="https://blog.zgp.org/reinventing-gosplan/">feeding some kind of
central planning system</a> that we all know has negative externalities,
then qualified people will look for other career options. Related: <a href="https://www.bjanda.com/blog/relax-its-only-an-existential-threat/">Relax,
It’s Only An Existential Threat</a> by Brian Jacobs.)</p>
<p>And Karen Middleton, writes, in <a href="https://theconversation.com/why-harmful-content-keeps-reaching-children-online-and-what-advertising-has-to-do-with-it-277527">Why
harmful content keeps reaching children online – and what advertising
has to do with it</a>, <q>For people working inside advertising and
technology industries, this moment may feel particularly significant.
Greater public awareness means fewer opportunities to claim that online
systems are too complex to understand or influence.</q> The costs of
participating in surveillance advertising keep <a href="https://blog.zgp.org/triple-taxation-on-surveillance-marketing/">going
up</a>.</p>
<p>And yes, there’s an alternative. <a href="https://blog.zgp.org/internet-optimism/">Sunday Internet
optimism</a></p>
</section>
<section class="level2" id="bonus-links">
<h2>Bonus links</h2>
<p><a href="https://arstechnica.com/tech-policy/2026/03/elon-musk-loses-big-in-court-x-boycott-perfectly-legal/">Elon
Musk loses big in court; X boycott perfectly legal</a> by Ashley
Belanger. <q>In her opinion, Boyle noted that Musk also failed to show
that advertisers had worked together to boycott then-Twitter.
Advertisers argued that they made independent business decisions based
on their own brand safety concerns, and there was no evidence to suggest
they were lying.</q> <a href="https://www.mediapost.com/publications/article/413868/judge-tosses-musks-wfa-ad-boycott-suit.html">Judge
Tosses Musk’s WFA Ad Boycott Suit</a> by Wendy Davis. <q>The World
Federation of Advertisers shuttered GARM in August, days after Musk
sued.</q> (Time for a GARM re-launch with a new host org? Musk’s
politics are remarkably unpopular, so brands that get associated with
them will be worse off on every timeline except some of the extreme
dystopias where they will have a lot more to worry about anyway.)</p>
<p><a href="https://adaged.blogspot.com/2026/03/finding-voice.html">Finding a
Voice.</a> by George Tannenbaum. <q>There was a time in our business, at
least at Ogilvy, where creative people weren’t just designers and
writers. They cared about design and writing, but more than that, they
were business people who could use creativity to advance a client and
agency’s prospects, and therefore their career.</q> (Anyone else
remember the <a href="https://www.youtube.com/watch?v=AIOqOxI0K_I">Universal Business
Adapter</a>?)</p>
<p><a href="https://blog.bofh.it/debian/id_473">Marco d’Itri: systemd
has not implemented age verification</a> <q>[T]he facts are simply that
the systemd users database has gained an optional “date of birth” field,
which the desktop environments may use or not as they deem appropriate.
Of course there is no <q>identity verification</q> or requirements to
provide any data, which in any case would not be shared beyond
authorized local applications.</q></p>
<p><a href="https://cardcatalogforlife.substack.com/p/google-has-a-secret-reference-desk">Google
Has a Secret Reference Desk. Here’s How to Use It.</a> by Hana Lee
Goldin, MLIS. Good list of advanced search features that still work.
<q>The AI-generated summary at the top of many Google results is the
feature most likely to be wrong and most likely to present that
wrongness with complete confidence.</q></p>
<p><a href="https://futurism.com/robots-and-machines/staff-brain-data-center-spine-fluid">Staff
at New Data Center Powered by Human Brain Cells Need to Swap Out
Cerebrospinal Fluid Every Day</a> by Frank Landymore. <q>Though it
remains highly experimental, Cortical Labs touts one key advantage over
traditional computing: a far smaller energy draw. To Bloomberg, Chong
claimed that each CL1 unit needs less power than a handheld calculator,
further predicting that they will one day be faster than traditional
computers, too.</q></p>
</section>]]></description>
		</item>
		<item>
			<title>A Vibe CMS</title>
			<link>https://blog.zgp.org/vibe-cms/</link>
			<guid>https://blog.zgp.org/vibe-cms/</guid>
			<pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p>Spotted this over the weekend, an error message
that somehow went live.</p>
<figure>
<img alt="Article Cannot Be Produced - Source Material Does Not Exist error message, formatted as a news story" loading="lazy" src="/i/vibe-cms.png"/>
<figcaption aria-hidden="true">Article Cannot Be Produced - Source
Material Does Not Exist error message, formatted as a news
story</figcaption>
</figure>
<p>The same site refers to stories on Phoronix and others, too. At least
they link to their source material. The sad part is that even though
this site is missing an <a href="https://blog.zgp.org/ads-txt-for-a-site-with-no-ads/">ads.txt
file</a>, it does have ads showing up for at least one real consumer
electronics brand and one real business event.</p>
<p>TechCrunch does have the <a href="https://techcrunch.com/2026/03/22/delve-accused-of-misleading-customers-with-fake-compliance/">story
that the error message seems to be about</a>, so maybe either there was
an error in the crawler, or TechCrunch was able to block the crawler, or
I happened to visit while TechCrunch was in the process of catching this
site doing this.</p>
<p>I’m not going to name the site because first of all, the company that
runs it has a lot of domain names, and second, now that they have their
automatic slop CMS going, they can always get more. The point of writing
this is <em>not</em>, look, I found a slop site, everybody add it to
your blocklist. The point is that the advice to use a blocklist to keep
your ad from showing up on crap sites was always bogus—even before
widespread use of LLMs, editing a blocklist for one brand or agency was
always a losing race against all the crap site makers in the world
registering domains.</p>
<p>Looking back at advertising history, getting ads into legit contexts
is the original role of an ad agency. Back when the advertising options
were basically signs and newspapers, a manufacturer couldn’t read all
the local newspapers, so they needed a trusted set of eyes to keep up
with which newspapers really reach the people they claim to, and handle
the process of placing insertion orders and paying invoices. Agencies
only started making the actual ads later. Yes, sellers of ads space
tried to subvert agencies, and sometimes succeeded, but the expectation
was that the agency works for the advertiser. (Part of the reason for
the crisis that big agencies are in now is the shift from
<em>agency</em> agency to <a href="https://www.adexchanger.com/marketers/the-rise-of-principal-media-and-the-end-of-the-agencies-as-we-knew-them/">inventory
flipper</a>.)</p>
<p>The slop situation should be an opportunity for agencies. (Not an
opportunity to make slop—a dedicated platform tool will do it better.)
The Forum on Information and Democracy has details, in the new report <a href="https://informationdemocracy.org/2026/03/20/the-online-advertising-market-needs-urgent-structural-reform-to-support-democracy-and-journalism/">The
online advertising market needs urgent, structural reform to support
democracy and journalism</a>.</p>
<blockquote>
<p>Advertisers lack control over where their ads appear and what exactly
it funds. This leads to significant resource wastage on platforms that
promote low-quality or misleading AI-generated “made for advertising”
(MFA) websites that would otherwise reach news publishers.</p>
</blockquote>
<p><a href="https://www.adexchanger.com/data-driven-thinking/what-happens-when-the-attribution-cartel-meets-advertisings-halo-effect/">Legit
sites are more effective than slop as an advertising medium</a>, but
slop is the default.<span class="aside">ICYMI: <a href="https://taikundigital.com/blog/google-is-robbing-you/">Google is
Robbing You… and You Can’t Stop Them</a> by Collin Slattery</span> If
the default is running on slop, then a brand or agency can get attention
by doing the opposite.</p>
<p>Just announced: the new <a href="https://www.beeler.tech/navigator-award-2026/">Navigator
Award</a>. They’re looking for ad-supported sites to nominate brands and
agencies.</p>
<blockquote>
<p>The Navigator Award gives publishers a way to recognize the brands
and agencies that have made a real, intentional effort to show up in
trusted news and publisher environments, especially where blanket
approaches to brand safety and suitability would have made it easier to
stay away.</p>
</blockquote>
<p>Who is successfully avoiding the slop mongers and making a real
impact?</p>
<section class="level2" id="related">
<h2>Related</h2>
<p><a href="https://blog.zgp.org/performance-max-preserving-attribution/">Performance
Max Preserving Attribution</a>: why Google gives the “lossy copy” slop
version better ads and search treatment than the original, and what’s
their plan for next steps?</p>
</section>
<section class="level2" id="update">
<h2>Update</h2>
<p><a href="https://techcrunch.com/2026/04/04/embattled-startup-delve-has-parted-ways-with-y-combinator/">Embattled
startup Delve has ‘parted ways’ with Y Combinator</a> by Anthony Ha.
(There’s probably a vibe CMS version of this one, too, but TechCrunch
has the original story.)</p>
</section>]]></description>
		</item>
		<item>
			<title>Links for 22 March 2026</title>
			<link>https://blog.zgp.org/mlp-2026-03-22/</link>
			<guid>https://blog.zgp.org/mlp-2026-03-22/</guid>
			<pubDate>Sun, 22 Mar 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p><a href="https://techcrunch.com/2026/03/21/delve-accused-of-misleading-customers-with-fake-compliance/">Delve
Accused of Fraud</a> by Anthony Ha. <q>Delve responded to the
accusations by saying it does not issue compliance reports at all.
Instead, it’s an <q>automation platform</q> that ingests information
about compliance, then provides auditors with access to that
information.</q> (What if Silicon Valley’s hottest startup trend is
half-assing as a service (HAaaS))</p>
<p><a href="https://militarnyi.com/en/news/unknown-drones-spotted-us-base-b-52-bombers/">Groups
of Unknown Drones Spotted Over US Base Housing B-52 Bombers</a> by
Dmytro Shumlianskyi. <q>These drones did not resemble commercially
available models—they were high-tech, had a significantly greater range,
and were resistant to electronic countermeasures.</q> (Related: <a href="https://blog.zgp.org/surveillance-risks-and-the-tidalwave-report/">Surveillance
risks and the TIDALWAVE report</a>)</p>
<p><a href="https://www.fastcompany.com/91512393/pakistans-solar-boom-is-helping-it-save-billions-during-the-ongoing-energy-crisis">Pakistan’s
solar boom is helping it save billions during the ongoing energy
crisis</a> by Adele Peters. <q>Pakistan gets almost all its oil and gas
from the Middle East, where U.S. and Israeli bombing of Iran have caused
crude prices to blow past $150 a barrel and tankers can’t get through
the Strait of Hormuz. But it has one edge in the crisis: a rapid, recent
shift to solar power.</q></p>
<p><a href="https://linuxiac.com/germany-mandates-odf-for-public-administration/">Germany
Mandates ODF for Public Administration in Sovereign Digital Stack</a> by
Bobby Borisov. <q>Germany has mandated the Open Document Format (ODF) as
the standard for public administration documents within its new
sovereign digital infrastructure framework, the Deutschland-Stack.
Published by the Federal Ministry for Digital and State Modernisation,
the framework sets technical standards for a unified, interoperable
digital environment across all government levels. It explicitly requires
ODF and PDF/UA as document formats, excluding proprietary alternatives
from official use.</q></p>
<p><a href="https://www.theverge.com/report/896820/lina-khan-ftc-meta-supernatural-antitrust">Lina
Khan was right</a> by Victoria Song. <q>The FTC’s Meta lawsuit was often
framed as an abstract attempt to rein in Big Tech. But in the end, the
acquisition’s human cost was obvious—and an example of precisely why
antitrust law matters.</q></p>
<p><a href="https://www.mollywhite.net/micro/entry/202603172318">90% of
crypto’s Illinois primary spending failed to achieve its objective</a>
by Molly White. <q>The cryptocurrency industry super PACs dumped $14.2
million into the Illinois primaries. 90% of that – $12.8 million – was
wasted, in that it went to opposing Democratic candidates who won their
primaries.</q></p>
<p><a href="https://carnegieendowment.org/posts/2025/01/how-china-aligned-itself-with-saudi-arabias-vision-2030">How
China Aligned Itself with Saudi Arabia’s Vision 2030</a> by Hesham
Alghannam. <q>As for the localization of the renewable energy industry
in Saudi Arabia, in July 2024, China’s Envision Energy entered into a
joint venture with the PIF and the Saudi manufacturer Vision Industries,
a private company, to build a turbine factory in the kingdom….Saudi
Arabia also signed two other joint ventures with Chinese companies to
manufacture and assemble equipment and components for solar
power.</q></p>
<p><a href="https://www.campaignlive.com/article/ibm-ogilvy-end-32-year-creative-partnership/1952294">IBM
and Ogilvy end 32-year creative partnership</a> by Luz Corona. (All the
Linux advertising I remember from the Linux boom was for IBM.)</p>
<p><a href="https://gothamist.com/news/new-era-for-street-vendors-mamdani-names-top-advocate-as-nycs-vendor-czar">‘New
era for street vendors’: Mamdani names top advocate as NYC’s vendor
czar</a> by Arya Sundaram. <q><q>Our street vendors are not a problem to
solve — they are a community to support,</q> the mayor said in a
statement.</q></p>
<p><a href="https://www.france24.com/en/americas/20250731-how-brazil-innovative-pix-payment-system-is-angering-trump-zuckerberg">How
Brazil’s innovative ‘Pix’ payment system is angering Trump and
Zuckerberg</a> by Vitoria Barreto. <q>[Paul Krugman] emphasised that Pix
is <q>achieving what cryptocurrency boosters claimed, falsely, to be
able to deliver through the blockchain—low transaction costs and
financial inclusion</q>.</q></p>
<p><a href="https://outpost.pub/you-outpost-moved-to-the-e-u/">Outpost
Moved its Servers to the E.U.</a> by Ryan Singel. <q>Just to be clear,
Outpost has never had a data request, subpoena or National Security
Letter dropped on us for our data or any member publisher’s data. But we
still thought this was a prudent step given the current political
environment.</q></p>
<p><a href="https://theconversation.com/beavers-can-turn-streams-into-carbon-stores-we-measured-how-much-278489">Beavers
can turn streams into carbon stores – we measured how much</a> by Joshua
Larsen, Annegret Larsen and Lukas Hallberg. <q>So when beavers dam
rivers, they can also fundamentally change how carbon is stored in river
landscapes.</q></p>
<p><a href="https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government">Federal
Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They
Approved It Anyway.</a> by Renee Dudley, with research by Doris Burke.
<q>For years, reviewers said, Microsoft had tried and failed to fully
explain how it protects sensitive information in the cloud as it hops
from server to server across the digital terrain. Given that and other
unknowns, government experts couldn’t vouch for the technology’s
security.</q></p>
<p><a href="https://shkspr.mobi/blog/2026/03/how-can-governments-pay-open-source-maintainers/">How
Can Governments Pay Open Source Maintainers?</a> by Terence Eden.
<q>When I worked for the UK Government I was once asked if we could find
a way to pay for all the Open Source Software we were using. It is a
surprisingly hard problem and I want to talk about some of the issues we
faced.</q></p>
<p><a href="https://www.himthe.dev/blog/when-microsoft-could">Bogdan’s
Blog – Windows 8 Was Peak Microsoft and I will die on this hill</a> <q>I
know it’s a hot take, and some of y’all might already be reaching for
your keyboards, but I don’t care. I used Windows 8 on my desktop, used
it on a janky 2-in-1 laptop, and had a blast with both. Dare I say, it
might’ve been the snappiest, most responsive version of Windows ever
released.</q></p>]]></description>
		</item>
		<item>
			<title>So much crime, so little pay</title>
			<link>https://blog.zgp.org/so-much-crime-so-little-pay/</link>
			<guid>https://blog.zgp.org/so-much-crime-so-little-pay/</guid>
			<pubDate>Sun, 15 Mar 2026 00:00:00 +0000</pubDate>
			<description><![CDATA[<p>Augustine Fou writes, in <a href="https://www.linkedin.com/pulse/how-brands-didnt-grow-need-digital-rebalancing-dr-augustine-fou-s4xxe/">How
Brands DIDN’T Grow—The Need for Digital Rebalancing</a></p>
<blockquote>
<p>The analysis of 86 public companies across 17 sectors, using 15 years
of public revenue data from 2009-2024 reveals a striking disconnect
between modern marketing theory and actual revenue performance. Massive
digital spending has failed to drive meaningful revenue expansion for
most brands over the 15 year time span.</p>
</blockquote>
<p>Some brands that spend a lot on modern advertising are growing more
slowly than the economy as a whole. In <a href="https://michaelfarmer.substack.com/p/holding-companies-need-high-level">Holding
Companies Need High Level Strategic Plans, Not Just Announcements of New
Structures and Cost Reduction Targets. Independent Agencies Will Take
Advantage…</a>, Michael Farmer writes,</p>
<blockquote>
<p>Public data tells us that the 2009-2024 sales growth rate of
<strong>40 out of 60 major advertisers</strong> has been very depressed,
averaging (as a group) only 2% per year for 15 years.</p>
<p>By contrast, the market had <strong>real GDP growth of 2.4% per year
plus inflation of 2.3% per year</strong> — so the benchmarked
<strong>nominal GDP growth rate was 4.7% per year.</strong></p>
<p>Imagine! The group of 40 out of 60 big-spending advertisers grew at
less than half of the nominal GDP growth rate for 15 years.</p>
</blockquote>
<p>Dr. Fou suggests adfraud and under-investment in brand-building
advertising as contributing factors. Another problem may be that money
spend on surveillance advertising tends to crowd out investments in
product improvements, or require disinvestment in products and services,
much as <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4881086">sports
betting tends to crowd out investments by households</a>. Trader Joe’s
peanut butter cups have milk chocolate, no ads, and no <a href="https://www.theguardian.com/us-news/2026/mar/11/reeses-hersey-chocolate-candy-cocoa">ingredients
list drama</a>.</p>
<figure>
<img alt="Ingredients list for Trader Joe’s peanut butter cups" loading="lazy" src="/i/tjs-pbc.jpeg"/>
<figcaption aria-hidden="true">Ingredients list for Trader Joe’s peanut
butter cups</figcaption>
</figure>
<p>The <a href="https://blog.zgp.org/reinventing-gosplan/">future
timeline in which the role of marketing decision-makers is reduced to,
effectively, interacting with an “AI”-based central planning system</a>
is already partly here. In <a href="https://michaelfarmer.substack.com/p/orwellian-doublethink-and-programmatic">Orwellian
“Doublethink” and Programmatic Advertising</a>, Farmer writes,</p>
<blockquote>
<p><strong>Programmatic is successful in generating income for Big
Tech</strong>, particularly for Google, Meta, Amazon, data providers and
martech infrastructure owners. Anyone beholden to or involved with Big
Tech sees programmatic advertising as “good.” (What must be ignored is
that the publishers and agencies are being starved of revenue by Big
Tech…and agencies will be eventually squeezed out by Big Tech.)</p>
</blockquote>
<p>Eventually could be soon. According to some documents that <a href="https://www.adexchanger.com/daily-news-roundup/tuesday-24022026/">came
out in discovery</a>, at least one of the major agency holding companies
is disturbingly reliant on “proprietary media trading” as <a href="https://www.thedrum.com/opinion/rory-sutherland-ad-agencies-don-t-have-an-ai-problem-they-have-a-pricing-problem">their
pricing power declines</a>. Tom Denford writes, in <a href="https://www.idcomms.com/blog/wpp-project-claridges-cmo-advice">3
Things Marketers Must Do After the WPP Disclosures</a>,</p>
<blockquote>
<p>At the same time, the leaked “Project Claridges” presentation,
released in ongoing litigation, shines a light on $1bn of what WPP calls
a “non‑product related income” engine built on rebates, content deals
and, most significantly, proprietary media trading. That disclosure
doesn’t just affect WPP, it validates what many CMOs have long suspected
about the wider holding‑company model.</p>
</blockquote>
<p>Maybe surveillance advertising is working, and working so well that
the Big Tech companies are capturing all the value created by it?</p>
<p>But it doesn’t look that way. Meta and Google are taking the kinds of
high-profile <a href="https://blog.zgp.org/speaking-truth-to-weakness/">risks of doing
obvious crimes</a> that a legitmately growing company shouldn’t have to.
<a href="https://www.mediapost.com/publications/article/413462/iab-sweden-expels-meta-warns-advertisers-about-fr.html">IAB
Sweden just voted to expels Meta</a> over crime issues, which is not the
kind of thing that industry organizations just do to a major member. If
we were on the timeline where Big Tech were making sustainable revenue
from their advertising oligopoly, they would have been able to reverse
<a href="https://blog.zgp.org/but-i-want-to-turn-people-into-dinosaurs/">fraud-friendly
decisions</a> and smooth this kind of thing over. Instead, because the
companies are forced to juice their stock prices without enough legit
revenue to justify it, the tricks continue. For example, they’re
consolidating ownership of how ads are measured by putting <a href="https://www.adexchanger.com/data-driven-thinking/the-hidden-dangers-of-privacy-preserving-attribution-and-a-smarter-solution/">obfuscated
ad reporting into web browsers</a>.<span class="aside">The surprising
part is that Apple is still going along with that one. It seems like
they would have taken the opportuntity to squeeze Meta and Google, like
they’re squeezing the laptop business by releasing a <a href="https://daringfireball.net/2026/03/the_macbook_neo">bargain-priced
but good Mac OS laptop</a> right when everyone else is dealing with the
RAM shortage.</span></p>
<p>Surveillance advertising hasn’t been good for brands, agencies, or
the people it tracks. (Even the <a href="https://blog.zgp.org/advertising-personalization-good-for-you/">literature
that proponents cite</a> doesn’t really support it, if you read the body
copy.) It’s going to be harder and harder to justify the risks. Oh well,
see you in the comment files for the next state privacy law.</p>
<section class="level2" id="bonus-links">
<h2>Bonus links</h2>
<p><a href="https://www.tvscientific.com/insight/the-broken-state-of-mobile-marketing">The
Broken State of Mobile Marketing: How Attribution Theft Created a $100B
Fraud Scheme</a> by Jason Fairchild. <q>By awarding 100% of the credit
to the final interaction, a few key measurement providers have built a
system that incentivizes “Attribution Theft” and perpetuates the
industry’s most pervasive fraud problem.</q></p>
<p><a href="https://blog.confiant.com/p/disrupting-59m-malicious-impressions">Disrupting
59M Malicious Impressions: Inside D-Shortiez Testing Infrastructure and
Campaign Management</a> by Confiant and Michael Steele. (See screenshots
for examples of “Google-branded gift card scams” and “Amazon-branded
giveaway scams”. If the web ad business is so good at AI, why do obvious
trademark-infringing ads even run?)</p>
</section>]]></description>
		</item>
	</channel>
</rss>

