Hacker News new | ask | show | jobs
by jgraettinger1 961 days ago
They're not literally passing around the hash. Holders of hash(email) <=> browser cookie associations are heavily incentivized for both regulatory and also competitive reasons to not blast that information around the internet -- or even to let direct partners A & B identify overlaps without their being in the middle.

When passing identifiers, there's generally some combination of lookup tables, per-distribution salted hashes, or encryption happening to make reverse mapping as difficult as possible.

(I was in this space up until a few years ago).

2 comments

Which makes perfect sense, because why would anyone sell their golden goose, if they had any other possible way of monetizing it?
I think this is generally false in most instances. All advertising pixels use unsalted sha1 hashes over https.