August 14, 2026

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

A Decryptads summary of the advertising partnerships declared by espn.com.

The newly launched decryptads.com says it is constantly scraping the files that websites and apps make publicly available to disclose the companies that are permitted to run ads or collect user data. These files include:

ads.txt: all of the adtech companies and data brokers that may run ads or harvest data from the site;
app-ads.txt: entities that can harvest data from or display ads on mobile and smart TV apps;
buyers.json/sellers.json: the entities buying, selling or reselling ad inventory for a given site or app.

Zach Edwards is chief research officer for DecryptAds and a threat researcher at the security company Infoblox. Edwards said he and two other founders decided the service was needed because the adtech data in these files is generally only useful when it can be cross-referenced to build a more complete picture of the advertising ecosystem for each website or app.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said. “It’s really built for a lot of privacy and security use cases that have been dramatically underserved.”

Those use cases, he said, include tracking down the source of malicious ads that try to foist malware on targeted users, identifying ad networks located in adversarial nations, and detecting the fast growing swarms of AI-generated slop websites and apps. And as decryptads.com demonstrates, these potential security and privacy threats are near impossible to detect just by viewing a single apps.txt or app-ads.txt file.

“Supply-chain integrity issues rarely live in a single file,” the site explains. “They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list.”

A search in DecryptAds for the hugely popular sports network espn.com reveals 143 ad partners and 19 registered data broker domains are listed within its ads.txt and app-ads.txt files. That data broker information is gradually becoming available because four states — California, Oregon, Texas and Vermont — have recently passed laws requiring data brokers to register if they buy or sell data on consumers from those states. DecryptAds reports that almost half of those data brokers are collecting geolocation data from espn.com visitors who aren’t blocking ads, while another three disclose that they collect device fingerprints and sensitive personal information.

A visual representation of the complex ad supply chain declared by espn.com. Image: decryptads.com.

HIGH-RISK AD PARTNERS

DecryptAds also makes it easy to learn the beneficiaries and national origins of the advertising firms lurking in apps and websites, displaying a conspicuous warning when adtech partners of an app or website are based in “geo-risk” areas like China and Russia, or in countries with strong financial and political ties to both — such as Cyprus and the United Arab Emirates (UAE).

According to DecryptAds, espn.com works with four different advertising entities that are based in either Russia, China or the UAE, including the adtech firm Between Digital, which lists a New York address. However, the dossier on Between Digital flags them as a Russian firm, showing that their publisher offers (PDF) are processed through Alfa Bank, Russia’s largest private commercial bank and one of several financial institutions placed under U.S. sanctions in 2022 after Russia invaded Ukraine. KrebsOnSecurity sought comment from both Between Digital and the company’s founder, and will update this story in the event that either replies.

A search for several top U.S. military news websites — including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com and federaltimes.com — shows they all allow Between Digital to serve ads and track users, as well as two entities in the UAE and another in the ownership secrecy haven of Panama. DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

The “Geo Risk” section of decryptads.com.

Pivoting on Between Digital’s app-ads.txt file reveals hundreds of domains featuring simple web-based games that are frequently interrupted by ads. Edwards said Between Digital’s own declarations show the company is listed as both a publisher and a reseller on approximately two-thirds of their portfolio.

“It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest,” Edwards told KrebsOnSecurity. “The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files.”

The Opera Web browser remains quite popular, and probably many users are unaware that since 2016 it has been majority owned and controlled by the Chinese company Kunlun Tech (the operational headquarters of Opera remain in Oslo, Norway).

Opera.com’s profile at DecryptAds identifies 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia and one each in Hong Kong and Ukraine. DecryptAds makes clear, however, that these companies represent just seven percent of the adtech partners specified in Opera.com’s ads.txt and app-ads.txt files.

LEGAL DOSSIERS

One feature of DecryptAds that sent this author down multiple hours-long research rabbit holes is its Legal Dossier lookup, which takes several minutes for each search but eventually churns out oodles of useful information about who owns a particular domain or app, when it was registered, and any aliases or relationships it may have to adtech companies and other websites or apps.

For example, last month KrebsOnSecurity wrote about researchers from Bitsight who found that an extremely popular line of TV streaming sticks called H96 quietly rent out each user’s Internet connection to strangers. Bitsight also discovered that when these devices aren’t being used to stream pirated video content, they are spoofing themselves as mobile phones clicking ads on AI-generated slop websites.

Bitsight concluded that the same Chinese company that made several of the malicious apps common to all of these H96 streaming sticks — the Fengwo Group — also also ran the network of ads and AI slop websites being clicked on by tens of thousands of these devices that are pretending to be mobile phones.

Examples of ad landing pages linked to the Fengwo Group. These sites were designed to show ads only to H96 devices that were spoofing their device type as mobile phones. Image: Bitsight.

A DecryptAds legal dossier on the (now dormant) Fengwo Group domain name for the AI slop website pictured on the left in the screenshot above (medicalbeautyhub dot com) shows it shares a seller ID (1674071) with a gaming website — giacoloredstones[.]com — which features yet another seller ID (103488000).

Pivoting on that latter seller ID reveals hundreds of active websites within Russia’s Yandex ad system featuring extremely low-quality games or simple utilities that pepper visitors with ads.

QUIET REMOVALS

Edwards said that when advertising networks suspect a given advertiser is engaged in unauthentic clicks or displaying malicious ads, very often those networks will quietly remove the offender from their list of approved partners without letting anyone else know about their suspicions.

This practice, he said, makes it easier for dodgy adtech firms to avoid accountability and continue victimizing others. To address that visibility gap, DecryptAds features a quiet removals feed that records and correlates all of the sellers.json removals across ad exchanges for the same seller domain or name.

A screenshot of the Quiet Removals Feed at decryptads.com.

“The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public,” Edwards said. “The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once.”

MALVERTISING AND AI SLOP

Malvertising, the term given to the practice of inserting malicious ads that foist malware or redirect visitors to phishing pages, remains an all-too-frequent occurrence in the modern adtech industry. But Edwards said these malicious ads are far more commonly found now on newly generated AI slop websites than on high traffic destinations that typically employ a variety of technologies and third party tools to quickly flag bad ads.

“None of these slop AI content farms are paying for that kind of protection,” he said. “They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search.”

Edwards said the AI slop websites are populated with machine-generated blog posts and images, and cover a wide array of themes from home improvement and decorating to food recipes, hunting, cars and consumer technology. He said organizations that get hit with malicious ads are often at a loss for what to do next, unaware that in most cases the answer is one of the entities listed inside the website’s ads.txt or app-ads.txt file.

“A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis,” he said.

Edwards maintains that truly getting a handle on the malvertising and AI slop problems will require more data-sharing by the major ad networks. Specifically, he says those platforms do not broadly share what’s known as the “supply chain object” or SCO, structured data attached to each advertising bid request that lets buyers see every seller, reseller and intermediary involved in passing an ad impression from the publisher to the final buyer.

“That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload,” Edwards explained. “You may see the malicious zero-click redirection, but without the supply chain object — which is only served server side — you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad.”

DecryptAds also offers an application programming interface (API) that allows researchers to automate queries and integrate the site’s functionality into popular AI platforms.

WHAT CAN YOU DO?

The only sane reaction to the examples described above is to block all online ads outright. This approach is broadly endorsed by security experts because it also makes it more difficult for adtech firms and data brokers to build detailed profiles on you and track your movements around the web and in the real world.

However, much depends on how you normally prefer to browse the Internet, and how much trust you place in third party browser plugins and extensions. For those primarily surfing via a regular desktop or laptop Web browser, uBlock Origin Lite is an excellent free and well-maintained open source option. uBlock Origin also should work with mobile browsers like Firefox, but apparently only on Android-based devices.

Adblock Plus is a decent option for iPhone and iPad users. For power users, Adblock and uBlock Origin both support custom blocking rules from easylist.to, which publishes a frequently updated list that removes most advertisements from webpages.

The well established browser extension NoScript blocks all non-approved Javascript code, and it generally does a fine job blocking most ads from loading. However, script blockers like NoScript may not be suitable for average users who don’t enjoy constantly having to referee which scripts should be allowed to load so that each site displays properly.

More technically inclined/adventuresome readers should strongly consider a hardware approach to blocking ads at the local network level, because that is easily the cheapest, most secure and scalable way to do it. A tiny, low-cost and broadly available computer known as a Raspberry Pi can be turned into a powerful ad blocker for all devices on a local network when fitted with a microSD memory card and a free program called Pi-hole. Once you’ve set it up properly and changed your router’s network settings to use the Pi-hole’s DNS sinkhole and DHCP servers, it should prevent ads from displaying on any devices connected to that network.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to install on their devices. Many websites now push users to install a mobile app, supposedly in order to more fully access and enjoy the site’s services and content. But in my experience, they’re not doing this because the user experience is somehow way better on the app (as LinkedIn tries to convince us non-app users several times a week via email). On the contrary, I find most mobile apps to be horribly designed, annoying, and/or completely unnecessary, and when given the option I will almost always choose to interact with a website or service directly in a Web browser.

No, the cold truth is that big web destinations tend to get pushy with their apps because they make it easier for these companies to keep you on their platforms longer and to collect (and in many cases resell) far more precise data about who, what and where their users are. Also, companies pushing customers the hardest to install mobile apps always seem to liberally opt everyone in to having their data used to train large language models these days. So be cautious about the apps you install on your mobile devices (including any smart TVs!), and poke around their listings at DecryptAds if you want to learn more about their privacy practices and any relationships they may have to adtech firms.


50 thoughts on “Who’s Tracking You? Use This New Service to Find Out

  1. Some guy on the Internet

    Perhaps in an excess of caution, I avoid installing extensions in my browsers. After all, the extensions require access to my browsing data, and they are owned and operated by developers… who are they, by the way?

    So, I use Safari on my Apple devices, setting up DuckDuckGo (a privacy-aware search engine) instead of using Google as my default browser search engine. On Windows, which I use rarely, I use Brave, a browser based on Chrome, which works fairly well. I access no online services that require passwords from Windows.

    So, perforce I trust Apple’s privacy practices. ‘cuz I gotta, ya know?

    I’ve tried switching my default browser to a privacy-aware browser like DuckDuckGo or Mullvad or Brave, but sometimes web pages don’t work well, and I lose access to passwords.

    Any thoughts? I’ve been slipping my gears on this issue for several months.

    1. Foodandart

      Am not a big mobile user for accessing the internet. It’s and age and eyes thing, so I stick to computers 99% of the time. I just bit the bullet years ago and use Firefox and uBlock Origin, and the Electronic Freedom Foundations’ fantastic Privacy Badger add-on, and NoScript which has been on every browser I’ve used since day one. I only use Safari for accessing the apple site directly, since it handles the forums there better than anything else. No Chrome since it’s keystoneupdate agent eats CPU cycles mercilessly and of course the whole manifest v3 rollout making the ad-blockers not as adaptable. Firefox only. Outside of that, I seldom encounter ads, and with uBO, I can whitelist sites that crab about having an ad-blocker.. Which is interesting, as when I DO whitelist sites, the ads still do not show so one of the other add-ons is stepping up in the background to maintain the restrictions on the ads? Hmm. I do also use Dan Pollocks’ Hosts file (which can be found at someonewhocares-dot-org/ hosts/ – I’ve used it for over 2 decades – started with my beigh G3 PowerMac running MacOS 8.6 and it’s been faithfully updated weekly -seriously, Dan’s an absolute God…) so maybe that is why I seldom get ads even on whitelisted sites.

      1. Matt C.

        I haven’t gone near EFF since autumn 2012. Evil people. Worse even than FISA in a way.

        1. Wannabe Techguy

          Can you please explain that? While I usually disagree with their “politics”, I do use “Privacy Badger” and run “Cover your Tracks” sometimes.

    2. S

      Safari is decent if you go through the settings and customize it for more privacy. I have Mullvad browser but sometimes websites are broken, so I use Vivaldi on a daily basis instead – never had any issues there. If you want to switch, you should be able to easily export your passwords, then import them into a new browser. No extension required.

      I don’t like DuckDuckGo so for searching I use Searx, which requires some setup. Startpage was my default before that, though its results got worse over time. Kagi is really nice because it has high quality results and you can filter out AI slop, but it’s paid and you have to trust that they’re adhering to their no-tracking policy.

  2. Guillaume

    @Some guy on the Internet

    You are correct to be careful with extensions, after all even a legitimate one could eventually be compromised, and depending on your browser and the permissions you grant the extensions, this could lead to full page content being exposed for everything you browse, including credential cookies.

    However, since you use Safari, this is different for Safari content blockers. They are somewhat less powerful by design as they are essentially a static list of patterns to block that gets built and added to Safari. This is closer to Chrome’s Manifest V3 than V2 which was more powerful. So, privacy upside, with a downside being features.

    So if you use a basic content blocker on Safari, that only has a content blocker extension, it will not see your browsing activity, but it will not be as good at reformatting pages after ads are removed, or at removing ads from more complex websites etc.

  3. Sacha

    This is an excellent (and eye-opening!) article. I’m glad to see that as time goes on, dodgy internet entities that used to be able to hide in the shadows are now able to be unmasked. Our details aren’t just being used to target advertising. People search sites often list relatives associated with the searched name. I currently have stupid scammers sending me emails from several of my relatives in hopes that I will be enticed to open the messages to view all of the great family photos I’m missing. But given that data on those sites is not always correct, they don’t realize that it’s not possible for someone who’s been dead for twenty years to be sending emails about family reunions.

    My hope is that we are able to continue to “reverse engineer” these crappy sites and eventually develop the technology that allows us to trace and unmask all of these leeches. Keep up the great work, Brian!

  4. Wannabe Techguy

    I love that phrase “AI slop”!
    @Some guy on the Internet:
    How about using a stand alone password manager? I use Bitwarden and there are others as well.

  5. Jay

    As this article illustrates, Decrypt’s web pages are annoyingly formatted as white on black, which is very difficult to read. If Decrypt wants its pages to be more easy to red, change them to the normal black on white.

      1. Matt C.

        Should we really care about how and data scraping site has “themes”?

    1. Kasey Best (DecryptAds CEO)

      As Brian Krebs himself mentioned, we have a light mode available! Just go to your Account dropdown in the top-right, go to Appearance, and you can swap between Dark / Light.

      If anyone else has questions/feedback, happy to help!

    2. Sunman42

      Just as an aside for purposes of “representation,” I use dark mode on everything I can. With my eyes, I’m able to read much longer in dark mode than I am in black on white.

      I’m glad we livein an age when we get to choose.

  6. Michael

    One suggestion: always use incognito mode in your web browser. Unless a site is doing fingerprinting, it should help avoid long term spying on you. And, some browsers have defenses against fingerprinting.

    The suggestion to use two browsers is excellent. Have one with no extensions, other than ad blocking, for sensitive websites (however you define that) and a browser with extensions for normal day to day browsing.

    1. mealy

      I don’t think incognito mode actually does quite what you think it does.

      1. Boo boo witch

        I think it is totally fair to assume a strange looking shadowed figure is following you around wearing either a masquerade mask, opera glasses, or some form of sunglasses resembling the Nazi officer’s in Raiders of the Lost Ark (but updated to at least a half century later, and with the man’s self tinted a dark grey). This figure then physically locates the bits and bytes in question, whisks them away to a safe place, modifies the date to one in a different dimension, unique only to you, then returns the results, scrubbed of all identifying marks, to your extra dimensional browser. It is further incognitoed by the fact that anyone witnessing you viewing the results will see neither hide nor hair of the actual results without the special invisible decoder ring that only your specifical browser’s session cookies bestows.

    2. Nathan

      Fingerprinting is a lot more than whether your search history/cache is turned on. It involved your networking fingerprint (TLS Hello) which is unique to your browser and it’s configuration (doesn’t change with/without incognito), your IP address, geolocation, the advertising IDs associated with your IP address, time of day, and so many other things. All incognito does it makes it to where the advertisers have to look up your advertising ID rather than you sending it attached to the web request (super trivial)

      1. Boo boo witch

        We all like to make every real life event a scene here in the world of Macromedia Director in the 90s. Not sure that would be worth much either almost thirty years after becoming heirless.

  7. Ulf Lindroth

    I read this looking for a reference to email spam as I assume this is part of the same effort by these ad groups, but I didn’t see any. I’m curious why.
    For context I ask because I receive several dozen email spam daily, of which a good portion are phishing (your photo storage will be deleted etc.) and others are the usual medical “trick” garbage. However the most puzzling aspect is that 95% of all spam are sent from Microsoft Outlook or an Amazon hosted domain. Neither Microsoft nor Amazon do anything about the hundreds of abuse reports they have been sent. Why?

  8. Michael

    Using DNS to avoid ads/trackers is very useful. However, DNS is complicated and modifying your router, either with Pi-Hole, or NextDNS or any DNS service that offers blocking of ads/trackers/malware is far from the whole story. The DNS configuration can also be set by your Operating System, your browser, or a VPN. Which one over-rides the others? There are assorted testers of your live DNS configuration here

    https://routersecurity.org/testdns.php

  9. edd

    “too many emails created with this domain today” [gmail[.]com]. hooray

    1. Kasey Best

      Please try again, we had some initial security restrictions that have been raised due to the flood of interest.

  10. Quid

    There are national security concerns if the Chinese and less than friendly nations are tracking our military via ads.
    Whether or not DecryptAds is black on white or white on black is a 1st world complaint.
    One would think the DOD/DOW, DIA, CIA, NSA, etc. will be contacting Mr. Best real soon now for assistance, if they haven’t already.

  11. Brian

    Why do I need to register a ‘free’ account to simply change from Dark mode to Light ????

    Nothing is ‘free’ in this world….

    Note to ‘Kasey Best (DecryptAds CEO) ‘ ……a show of good faith and best of intentions, would be to make the page light without the need to make an account.

  12. Unsure and Suspicious

    Why do I need to register to run any search? By registering we are freely giving an email address to DecryptAds and DecryptAds is collecting and storing that information for subsequent logins. If DecryptAds is concerned about privacy and revealing who’s tracking me, why should I allow them to track me?

  13. Ronald Rossi

    Just browse through Yahoo.com news articles if you want to find some malvertsing
    You can literally use that page to test your Malwarebytes or similar software
    Unless they have cleaned it up in the past few years, have not tried it lately?

  14. Jojo

    “Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to install on their devices. Many websites now push users to install a mobile app, supposedly in order to more fully access and enjoy the site’s services and content.”
    —-
    Get Blokada. Works great! It’s showing it has so far blocked 2,635,424 ads and trackers on my Android phone. Works against all apps, although there are a few apps that refuse to show content when they sense an ad blocker. I just ignore them. Most content is always available somewhere else.

  15. Non mi piace

    Kind of ironic when companies acting like they want to add privacy link lookups like these to users’ identities. What is THEIR profit model?

  16. Inan

    Annoyingly, this service uses some dark-patterns. I wanted to re-scan a URL, but the button was disabled. I inspected and found a title attribute that indicates this feature requires you to sign-in. After creating a free account, I navigated to the same results to see that the button is still disabled. Another inspection revealed that the title reads “Enterprise account required — sign in to use this feature”. This is never mentioned clearly on the homepage, and even on the pricing page. I decided to delete my account, and guess what, they do not have a delete account feature. I am guessing you have to email them to delete your account. I suggest you don’t create an account with this company.

    1. mealy

      It does say straight up that some features are only for enterprise/researchers and basic free trial account is “limited.”

      I don’t think “having an account” does anything except allow you to use the service, hence deleting it is not real necessary, assuming they’re not going to bombard you with spam – which given the nature of their service would be pretty ironic.

  17. Gareth Pye

    I recently upped my add blocking to include running my phone through tailscale to use my home server as an exit node, making my phone use the home technitium DNS (fancy man’s pihole) and it’s really nice. Getting DNS ad blocking for all my mobile browsing and apps is very pleasing.
    I’m not suggesting that as a solution for everyone, but it is very nice

  18. Neurone

    Tried to register several times with my proton account, nothing ever received.

    1. Boo boo witch

      Most places poopoo on protonmail. I have attempted to use protonmail, tutanota, and a couple of other email services for things in the past and not only never got email verifications but got locked out of email addresses for some places that feel merely the idea of a non-top-five email provider was criminal; not sure how they pull that off, but it is no fun. Be warned. note, I am not a Nixon fan (especially the one who ran for Office in 2018), but that doesn’t make me also not a crook; I am pretty damn clean.

  19. Lucas S.

    One additional use for this kind of mapping is evidence preservation. Files such as ads.txt and sellers.json are mutable, so a present-day lookup may not show the supply path that existed when a malicious ad or unexpected data transfer occurred. A useful workflow would save timestamped copies of the relevant declarations, record redirects and ownership identifiers, and compare changes over time. That would help distinguish a partner that was never authorized from one that was listed briefly and later removed. It could also make incident reviews more reproducible for publishers, exchanges, and researchers without treating every current declaration as proof of past behavior.

    1. Hunny

      In the land of dead ptah’s every dead bird we killed urself is speech taking day for the innocent

      Hey SIM nearest you, turn.

      1. Your EULA

        Great antennas. Almost as good as due process and lawyers.

  20. Jason

    This is why I switched completely to the Brave browser recently. They have recently introduced native Containers in which you can lock websites you visit to certain containers so that cross cookie contamination/tracking between sites can somewhat be managed or controlled. Another feature I enable is whenever I close a tab, all cookies for those domains I visited get deleted after 30 seconds or so. Even with Private Browsing, the cookies are still stored in that session until you close it. The three ad-blocking extension I use include ublock origin, adguard, disconnect and the prebuilt Brave Shields.

    Finally, I use a VPN.

  21. Dan

    Thank you for the article, Brian.

    I recommend using an alternate DNS system to protect against all ads and censorship, such as NextDNS. It requires 30 min of setup to create your profile, add blocking lists, and configure your devices. But once it’s done, you’ll never have to do it again.

    From my point of view, it’s simpler than setting up a Pi-hole, and it works outside your home, for your movile connection too. It does require trusting the DNS provider, but since everybody has been using Google for decades, and they have not been the most respectful actor regarding privacy, I guess it can’t be any worse! Just choose a well-established alternate DNS provider that allows adding block lists, and you’re good to go.

    1. Jerolomo G

      I used a flat hosts file on my old macbook for my most often visited sites, then sent certain IP ranges to certain DNS servers through a simple shell script for privacy purposes.

      I had more than one of these host files and setups, depending on my usage and whether or not my VPN(s) were on.

  22. Tom

    Carry a smart phone, you can be tracked.
    Drive a late model car, you can be tracked.
    Use Google with an account, you’re being tracked.
    AI does a great job of figuring out who/where you are.
    I mostly use Duckduckgo for most searches, and before you…
    it’s safer than Google.

  23. XORZ

    Krebs must have hated hackers since he was a child.. or anyone who uses hacked logs..

  24. RW

    Had a family member install Pihole. It was mindboggling the amount of tracking going on.

  25. Hame G

    I think this is really interesting because most people don’t know how much information websites and apps collect about them. Tools like DecryptAds can help people understand where their data is going and protect their privacy.

  26. Mike H.

    I became very concerned by the fact it seemed not only Google was tracking my packages even a decade and a half ago when I used it. Can we talk about that? This seems benign by comparison.

  27. Reham

    I thought this article was really interesting, especially seeing how many different companies can be involved in tracking people online. I don’t think most people realize how much information can be collected just from visiting a website or using an app. The part about advertising networks being used for malicious ads also stood out to me. It shows that privacy and cybersecurity are connected in ways that people might not think about. This was a good reminder of why it’s important to pay attention to what is happening online and keep up with new security threats.

  28. Jimmy

    pipeline patterns across ads.txt, app-ads.txt, sellers.json and buyers.json is exactly where adtech meets supply-chain security – the kinds of cross-reference failures Edwards describes (cloned declaration sets, suspicious seller removals) are usually invisible from any single file. Worth noting that the same logic maps onto other corners of the same problem: cross-referencing reseller inventory against the original seller registry has long been a useful signal in pharma-safety and counterfeit-goods work, where the differences between declared and actual supply show up only when you walk the chain. In a different field I keep a small independent reference for AI coding agents (usage-limit resets and reset-failure cases, not affiliated with OpenAI), and the hardest job is the same – making the difference between a stated claim, a verified event, and an inferred pattern visible without confusing them. Tools like decryptads lower the bar for everyone trying to do that kind of cross-file verification.

Comments are closed.