The advertising industry is simultaneously everywhere and incredibly difficult to investigate. Ads can power all sorts of surveillance, from the relatively mundane like inferring someone’s age or gender, right up to harvesting their precise location data and selling this to the government. But researching that omnipresent surveillance is, ironically, an uphill struggle because the relevant data is spread across the web, nestled in obscure files that most people never look at or even know to look for, and can’t be searched all at once.
A new research tool called DecryptAds hopes to change that by bringing together a massive corpus of data. It can show what advertising brokers are operating on a particular website, and, more importantly, many other places those same brokers are operating. The tool cuts down on work that would ordinarily take much longer, and creates entirely new ways to explore the world of advertising and surveillance.
Do you work for a data broker or advertising company selling this sort of data? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.“For years I’ve personally worked on some of the biggest data privacy problems that have impacted the world, and I’m damn sick of people trying to guess how hundreds of data brokers are selling location data on people and a wide variety of other sensitive audience segments,” Zach Edwards, chief product and research at DecryptAds, told 404 Media. “We want to make it easy for anyone to look up a website or app and quickly understand the data sharing implications to risky ad tech companies and data brokers.”
In a process called real-time bidding (RTB), advertising companies outbid one another to have their clients’ ads placed in the web browsing session or app of a particular type of person. A side effect of that process is that companies can harvest all sorts of sensitive information about peoples’ devices, in some cases including their location. 404 Media has covered this type of surveillance extensively, from an Israeli spy firm monitoring billions to uncovering thousands of specific apps that siphon location data, with middlemen then selling it to the U.S. government.
When 404 Media and other outlets have investigated this industry, it has typically been through sources, leaks and hacks, or technical analysis of certain apps. DecryptAds takes a different approach. The site brings together ads.txt and app-ads.txt files — which list the advertising systems plugged into websites or apps — and sellers.json files which advertising exchanges use to list the companies they work with. Ordinarily these files cannot be easily compared to one another or searched in aggregate. DecryptAds makes that possible.
“It’s my hope that a new generation of researchers and activists starts to step up and demand more from publishers we frequent and support. We built DecryptAds to empower people with information which is currently spread out across complex datasets and tough to parse, but we believe with the right data and tools, we can help people understand the complex web of programmatic advertising and its relationship to the global data broker ecosystem, and start to make a dent in the changes with these systems that will improve privacy, security and advertising outcomes for everyone,” Edwards said.
At the time of writing, a counter at the bottom of the site said DecryptAds’ database includes 284,250,766 ads.txt files, 183,939,277 app-ads.txt files, and 201,389,256 sellers.json files.
It’s possible to search the DecryptAds data by a specific app, advertising company, a relevant domain, IP address, and more. The tool is also monitoring for changes on the sellers.json files, which Edwards says may help “to identify suspicious publishers or app makers who could be quietly banned from multiple exchanges without any public notice or fanfare.”
DecryptAds adds context to the collected data in various ways. One of those is by giving ad systems a “geo risk” score. This includes those who are linked to sanctioned countries (such as Russia, Belarus, and Iran); determined as U.S. adversaries under Executive Order 14117 (like China and Hong Kong); and “financial-secrecy havens” (including Cyprus and the British Virgin Islands).
Having one of these flags does not necessarily mean any single exchange is harvesting data for nefarious purposes, but it can be a strong lead for journalists or researchers to look into. “If the ad tech company has ties to Russia or China, expect shenanigans. If a company is based in Cypress or another jurisdiction for shell companies, expect them to be connected to numerous other suspicious companies, probably hide their beneficial owners, and potentially be the type of company who has poor KYC [know your customer] and partner standards and is more likely to be the source of a malvertising attack,” Edwards said.
Last month, advertising company Adform discovered hackers had targeted it. It found the hackers implanted code that would replace cryptocurrency wallet addresses displayed in a web browser. In other words, these hackers attempted to use the advertising ecosystem as a way into peoples’ active browsing sessions, and then potentially use that access to steal peoples’ funds.
Using data in DecryptAds, it is possible to see nearly 20,000 websites that declare Adform in their ads.txt or app-ads.txt. That includes 404 Media; we removed Adform from our ads.txt after finding this.
“Our goal is to continue working to layer context onto the programmatic advertising ecosystem so that people can understand the data sharing implications of consenting to ads on these sites, and so that security and ad tech companies can understand the complex publisher ecosystem and opportunities to reduce the risks from working with unscrupulous publishers and their partners,” Edwards added.