The depths that marketers will plummet to - 4dw@r3

Adwear

DEF CON 33 · Day 1 · Main Stage

Overview

In this DEF CON talk, "The depths that marketers will plummet to," speaker Adwear exposes the increasingly invasive and legally ambiguous data collection practices employed by the digital marketing industry. The presentation delves into how a major shift in data privacy regulations and Google's initial (and ultimately abandoned) attempt to phase out third-party cookies inadvertently pushed marketers towards more aggressive and less transparent tracking methods. Adwear, drawing on their background working for a large digital marketing firm, reveals the industry's rapid adoption of Server-to-Server (S2S) tracking and the creation of "first-party partnerships" as a means to circumvent privacy legislation like GDPR.

Watch on YouTube

Visual summary for The depths that marketers will plummet to - 4dw@r3 by Adwear
Visual summary for The depths that marketers will plummet to - 4dw@r3 by Adwear

Key moments

  1. 0:00 Introduction and speaker's background
  2. 2:40 Google's "Privacy Sandbox" and cookie elimination
  3. 4:00 Marketing firms' panic and nation-state actor use
  4. 5:00 Introduction of server-to-server (S2S) data transfer
  5. 6:20 S2S collects more data; bypassing gatekeepers
  6. 8:00 SSID tracking maps personal networks for influence
  7. 9:00 Insecure data lakes for collected personal networks

The depths that marketers will plummet to - 4dw@r3

Speakers: Adwear

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=arvFqkI4770

Overview

In this DEF CON talk, "The depths that marketers will plummet to," speaker Adwear exposes the increasingly invasive and legally ambiguous data collection practices employed by the digital marketing industry. The presentation delves into how a major shift in data privacy regulations and Google's initial (and ultimately abandoned) attempt to phase out third-party cookies inadvertently pushed marketers towards more aggressive and less transparent tracking methods. Adwear, drawing on their background working for a large digital marketing firm, reveals the industry's rapid adoption of Server-to-Server (S2S) tracking and the creation of "first-party partnerships" as a means to circumvent privacy legislation like GDPR.

This talk is critical for anyone concerned about digital privacy, data security, and the unchecked power of advertising technology. It highlights not only the technical mechanisms marketers use to track individuals but also the profound societal and geopolitical implications, including the potential for foreign influence through ad spend and the weaponization of personal data for political purposes. Adwear emphasizes the urgent need for stronger regulatory oversight and individual action to reclaim digital autonomy, underscoring that the current landscape represents a significant erosion of personal privacy, often under the guise of "legitimate business interests."

Background

▶ Watch: Introduction and speaker's background (0:00)

The evolution of digital marketing has been inextricably linked to the collection and analysis of user data. Historically, this data was primarily gathered through cookies, small pieces of encrypted text stored in web browsers. These come in two main types: first-party cookies, issued by the website a user is directly visiting, and third-party cookies, issued by external entities (like ad networks or analytics providers) that a website integrates. Third-party cookies became the backbone of cross-site tracking, enabling marketers to build comprehensive profiles of user behavior across the internet.

However, the landscape began to shift dramatically due to increasing public awareness of privacy concerns and the introduction of stringent regulations. Apple's privacy enhancements and the European Union's General Data Protection Regulation (GDPR) imposed significant pressure on the industry, particularly on tech giants like Google. In response, Google announced its intention to deprecate third-party cookies, proposing an alternative called Privacy Sandbox and pushing its new analytics platform, Google Analytics 4. The stated goal was to enhance user privacy by eliminating third-party tracking while still allowing advertisers to target aggregated demographic groups.

This move, however, created a significant crisis for the marketing industry. Marketing firms, with an estimated 70% of their revenue generated from third-party analytics, panicked at the prospect of losing their primary data source. Privacy advocates also raised concerns, viewing Google's Privacy Sandbox as a monopolistic move that would consolidate power and data within Google's first-party ecosystem. Beyond commercial interests, nation-state actors and Super PACs also heavily relied on third-party analytics to track the spread of information, gauge public reaction, and refine their messaging for misinformation campaigns. Facing this multi-faceted pressure and the impending deadline for Google's cookie deprecation, the marketing industry hastily developed new technologies to maintain their data collection capabilities, leading directly to the rise of Server-to-Server tracking.

Key Findings

▶ Watch: Marketing firms' panic and nation-state actor use (4:00)

Adwear's talk unveils several critical findings that illustrate the lengths to which the marketing industry will go to bypass privacy protections:

  • Emergence of Server-to-Server (S2S) Tracking: In direct response to the anticipated deprecation of third-party cookies, marketing firms rapidly developed and deployed S2S technology. This involves direct API connections between websites (e.g., an e-commerce platform like Etsy) and marketing firms' data lakes and analytics engines, bypassing traditional cookie-based tracking and the gatekeeping role previously played by Google or Facebook.
  • "First-Party Partnerships" as a Legal Loophole: To circumvent GDPR's restrictions on third-party data transfers, marketing firms created a legal fiction dubbed "first-party partnerships." By contractually defining these direct S2S connections as a partnership, they attempt to reclassify what would otherwise be a third-party data transfer as a first-party interaction, thereby claiming exemption from strict GDPR provisions.
  • Significantly Increased Data Granularity and Scope: Unlike the previous model where Google or Facebook would anonymize and group user data before providing it to marketers, S2S allows firms to ingest raw, individual user information directly. This includes highly sensitive data points that were previously protected, leading to a much more detailed and invasive profile of each user.
  • Advanced Device Fingerprinting and Network Mapping: Marketers are leveraging S2S to implement sophisticated fingerprinting techniques, including SSID tracking. By monitoring which Wi-Fi networks a device connects to over time, they can infer personal relationships (family at home, co-workers at work, social groups at recurring locations like a bowling alley) and construct detailed maps of an individual's social network. This data is then used for highly targeted and manipulative advertising.
  • Minimal Security for Massive Data Lakes: The rapid implementation of S2S led to the creation of vast data lakes by marketing firms. Adwear observed that these systems were often built in a hurry "with no security essentially or minimal amounts of security," creating enormous liabilities and ripe targets for data breaches.
  • Google's U-Turn and Integration with S2S: After multiple delays and public backlash from marketing firms, Google completely reversed its decision to eliminate third-party cookies in January 2024, declaring them "perfectly fine" and "super safe and private." Furthermore, Google is now actively partnering with marketing firms and integrating S2S into its own services, such as Recapture. This means any website utilizing Recapture can potentially send extensive user statistics directly to Google and partner marketing firms.
  • Exploitation of Regulatory Ambiguity: The talk highlights how the "legitimate interests" clause in GDPR, intended to cover state or public health interests, is being broadly reinterpreted by businesses to justify any data collection that generates revenue. This self-serving definition renders a crucial privacy safeguard ineffective.
  • Profound Societal and Geopolitical Risks: The unchecked data collection has serious implications, including:
  • Foreign Influence: Russia's reported $14.9 billion annual budget for advertising (mostly external) demonstrates the scale of potential foreign influence operations.
  • Dark Money in Elections: $1.9 billion in unaccounted-for "dark money" ad spend was observed in a recent election year, indicating a significant avenue for opaque political manipulation.
  • Weaponization of Sensitive Data: The storage of highly personal data, such as searches for medical services unavailable in one's home region, poses a severe risk. In the event of a warrant, these marketing firms, prioritizing revenue, are likely to turn over such sensitive information, potentially endangering individuals.

Technical Deep Dive

▶ Watch: Introduction of server-to-server (S2S) data transfer (5:00)

The technical core of Adwear's presentation revolves around the shift from traditional cookie-based tracking to the more insidious Server-to-Server (S2S) data exchange.

Initially, web tracking relied on cookies, which are small pieces of data sent from a website and stored in a user's web browser. First-party cookies are set by the domain the user is visiting, often used for session management (e.g., keeping a user logged in) or basic site analytics. Third-party cookies, however, are set by domains other than the one shown in the browser's address bar. These are typically deployed by ad networks, analytics providers, or social media widgets embedded on a site. When a user visits a site with a third-party cookie, that external entity can track the user's activity across multiple websites that also embed its cookies, creating a comprehensive profile for targeted advertising.

Google's proposed solution, Privacy Sandbox, aimed to phase out third-party cookies. Instead of individual tracking, it proposed aggregating user data into broader interest groups within the browser itself, with only these aggregated signals shared with advertisers. This was to be complemented by Google Analytics 4, its next-generation analytics platform. However, this initiative faced immense pressure from both privacy advocates (who saw it as consolidating Google's power over first-party data) and the marketing industry (who feared losing granular tracking capabilities and significant revenue).

The marketing industry's countermeasure was the rapid development of Server-to-Server (S2S) tracking. Instead of relying on client-side browser cookies, S2S establishes direct API connections between a website's server and a marketing firm's backend systems. When a user interacts with a website (e.g., makes a purchase on Etsy), the website's server directly sends data about that interaction to the marketing firm via a secure API endpoint. This completely bypasses the user's browser, making traditional browser-based privacy controls (like blocking third-party cookies) irrelevant.

The data transferred via S2S can be far more extensive and granular than what was typically available through third-party cookies. While Google and Facebook previously acted as intermediaries, often anonymizing or aggregating data before sharing it, S2S allows the originating website to send raw user data directly. This includes:

  • User actions: Clicks, page views, purchases, cart abandonments, search queries.
  • Device information: Device type, operating system, browser, IP address.
  • Personal identifiers: Potentially hashed email addresses, phone numbers, or other unique IDs.
  • Advanced Fingerprinting: A particularly concerning aspect is the use of SSID tracking. By recording the SSIDs (Wi-Fi network names) a user's device connects to, marketing firms can infer the physical locations a user frequents and, crucially, the relationships they have. For example, consistent connection to the same home SSID suggests family members, while regular connections to a workplace SSID suggest colleagues. Visiting a specific bowling alley's SSID once a month could indicate a social group. This allows marketers to construct detailed "maps of all of our personal networks," enabling highly targeted and socially influenced advertising.

All this collected data is then ingested into "massive data lakes" maintained by marketing firms. Adwear highlights that these systems were hastily built, often with "minimal amounts of security," posing a severe risk of data breaches for highly sensitive personal information.

The talk further reveals Google's complete reversal on third-party cookies and its subsequent embrace of S2S. Google is now reportedly running Proofs of Concept (POCs) where it integrates S2S into its own services, specifically Recapture. Recapture is a widely used service designed to protect websites from bots. By integrating S2S into Recapture, Google can potentially leverage its widespread adoption to collect comprehensive user statistics from any website using Recapture, funneling this data back to marketing firms and Google's own analytics. This move signifies a consolidation of tracking power and a blurring of lines between "privacy-enhancing" initiatives and continued, if not expanded, data collection.

Demo / Proof of Concept

▶ Watch: SSID tracking maps personal networks for influence (8:00)

The talk by Adwear does not include a live demonstration or a proof of concept of the described tracking technologies. Instead, the speaker relies on their professional experience working within a large digital marketing firm, detailing the observed practices, internal discussions, and the rapid technological shifts they witnessed firsthand. The insights provided are based on this direct industry exposure and analysis of current trends rather than an interactive technical demonstration.

Defensive Implications

▶ Watch: Insecure data lakes for collected personal networks (9:00)

The revelations in Adwear's talk underscore a critical need for both systemic and individual defensive strategies against pervasive digital tracking.

1. Systemic Advocacy and Regulatory Reform:

The most impactful defense lies in strengthening privacy regulations and ensuring their robust enforcement. Adwear explicitly states that GDPR is effective, citing the billions spent by marketers to circumvent it as proof of its impact. The challenge, however, lies in its broad language. Regulators must step in to:

  • Clarify Ambiguous Terms: Specifically, the definition of "legitimate interests" needs to be narrowed down to its original intent (e.g., state interests, public health) and explicitly exclude revenue generation for businesses. The speaker's anecdote about a company defining "legitimate interests" as their "business to continue generating revenue" highlights this critical loophole.
  • Impose Revenue-Based Fines: The effectiveness of GDPR's revenue-based fines is a powerful deterrent. Legislators in other regions should adopt similar models to ensure compliance.
  • Increase Oversight: Regulators need to actively monitor new technologies like S2S and "first-party partnerships" to ensure they do not become de facto circumventions of existing privacy laws. Advocacy groups and individuals should actively report dubious practices to Data Protection Officers (DPOs), especially in EU-based entities.

2. Individual Actions for Enhanced Privacy:

While systemic change is crucial, individuals can also take significant steps to protect their own data:

  • Utilize Multi-Account Containers: Browser extensions like Firefox's Multi-Account Containers allow users to isolate different online identities (e.g., work, personal, shopping) into separate, sandboxed browser profiles. This prevents cross-site tracking by segmenting cookies and other identifiers, making it much harder for marketers to correlate activities across different contexts.
  • Employ a VPN (Virtual Private Network): A VPN can help anonymize a user's IP address and obscure their geographic location. Crucially, in the context of SSID tracking, a VPN can help mask the specific Wi-Fi networks a device connects to, making it more difficult for marketers to build personal network maps. However, Adwear cautions that VPNs are not a perfect solution, as VPN metadata itself is not always encrypted, and the VPN provider could potentially log connections. Users should choose reputable, privacy-focused VPN providers.
  • Choose Privacy-Focused Browsers: Opting for browsers designed with privacy in mind can offer better default protections against tracking scripts and cookies. Adwear specifically does not recommend Brave, citing concerns about its founder's history and its initial backer, Peter Thiel (founder of Palantir), suggesting a potential conflict with privacy principles. Users should research and select browsers with strong privacy policies and open-source foundations.
  • Isolate and Secure IoT Devices: The talk touches upon device fingerprinting and the pervasive nature of data collection. Users should isolate their Internet of Things (IoT) devices on a separate network segment (e.g., a guest Wi-Fi network or a dedicated VLAN) to prevent them from interacting with or exposing data from other devices on the main network. Furthermore, exploring open-source IoT solutions is recommended, as they often offer greater transparency and user control over data.

By combining robust legislative action with proactive individual privacy hygiene, the adverse effects of the marketing industry's "plummet to the depths" can be mitigated, and a healthier, more private digital ecosystem can be fostered.

Key Takeaways

  • Server-to-Server (S2S) tracking is the new frontier for data collection, enabling marketers to bypass traditional browser-based privacy controls and collect more granular user data directly via API connections.
  • "First-party partnerships" are a legal maneuver designed to circumvent GDPR's third-party data transfer restrictions, highlighting the industry's creative interpretations of privacy regulations.
  • Marketers are actively mapping personal networks using SSID tracking, inferring relationships (family, friends, co-workers) from Wi-Fi connections to influence behavior through highly targeted advertising.
  • Rapidly built S2S data lakes often have minimal security, creating massive liabilities and making sensitive personal data vulnerable to breaches.
  • Google's reversal on deprecating third-party cookies, coupled with its integration of S2S into services like Recapture, signifies a complex and potentially more intrusive tracking landscape.
  • Weaknesses in privacy legislation, particularly the ambiguous "legitimate interests" clause, are being exploited to justify broad data collection for revenue generation, necessitating stronger regulatory clarification and enforcement, especially with revenue-based fines.
  • Individuals must take proactive steps such as using multi-account containers, VPNs, privacy-focused browsers, and isolating IoT devices to protect themselves from pervasive tracking.

About the Speaker(s)

The speaker, known as Adwear, is a dedicated community organizer and cybersecurity professional with a unique perspective shaped by their past experience in the digital marketing industry. Adwear is a key figure in Burps, an "amazing community" in Chicago that hosts seven monthly cybersecurity meetups in the Chicagoland area, with additional chapters in Galway and Las Vegas. Burps boasts a vibrant Discord community of 1,300 members, operating without dues and focused purely on community support and growth. Adwear credits this community as a primary inspiration for their speaking engagements and career development.

Professionally, Adwear previously worked for the largest digital marketing firm in North America. In this role, they gained firsthand insight into the industry's practices, particularly regarding technology reviews post-mergers and acquisitions, and the security (or lack thereof) of these systems. It was during this period that Adwear observed the disturbing data collection tactics that form the core of this talk. Adwear is passionate about privacy advocacy and is scheduled to deliver an hour-long version of this presentation at SECTI in Stockholm.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Adwear brings a genuinely useful insider angle on adtech's pivot from cookies to S2S tracking, and the 'first-party partnership' legal laundering angle is worth hearing from someone who watched it happen from inside the industry. The problem is the talk stays at the surface of most of its technical claims and leans heavily on anecdote where it needs precision — it's more informed journalism than security research.

Heather Calloway (CISO) — SOLID

Adwear brings genuine insider knowledge of adtech's post-cookie pivot and names real risks — insecure data lakes, GDPR loophole abuse, S2S as regulatory arbitrage — that deserve more attention than they get at security conferences. But the talk stays at the awareness layer: it identifies the problem with credibility, then lands on individual privacy tips that don't match the institutional scale of what was just described.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33