Identity

What 1,500 Emails Reveal About Tracking

The earlier posts on this blog – The Cookie That Never Expires and UID2: The Standard That Replaced the Cookie – made an argument about how the ad industry replaced the cookie with your email address. This post is not an argument. It is what happened when that argument got pointed at one person’s actual mail.

The corpus is two personal mailboxes, a handful of single-service aliases, and a script that never once touches the network – it only reads what senders already embedded in the message. What came back is a specific, traceable answer to the industry’s favorite defense, that tracking pixels are harmless aggregate telemetry counting opens. The mail says otherwise, and it says something stranger besides.

Continue reading

You Run the List. You Own the Risk.

If you run a group email list, you own the risk for everyone on it. Every address your members handed you, every message that flows through, every threat that rides in with it – that is yours to protect now, whether you signed up for the job or not.

I learned this the hard way. For about twenty-five years I have run the email list for my extended family, and it has taught me more about email privacy than any specification ever did. Eventually it made me write my own email system.

Continue reading

UID2: The Standard That Replaced the Cookie

The earlier post – The Cookie That Never Expires – showed how hashed email addresses became the ad industry’s replacement for the tracking cookie. Companies hash your address when you hand it over, and the hash becomes the identifier that follows you across sites and devices. That practice did not stay informal for long. In 2019, The Trade Desk gave it a name, a spec, and an open-source implementation. The result is called Unified ID 2.0, UID2 for short, and it is now the infrastructure underneath a significant share of the open web’s advertising.

Continue reading

The Cookie That Never Expires

You probably remember when the tracking cookie died. Browsers blocked them, regulators demanded banners for them, and the advertising industry spent years announcing its move to a “post-cookie world.” It felt like a win for privacy.

It wasn’t a win. It was a substitution. The identifier that replaced the cookie is your email address.


A cookie lived in one browser on one device, and you could clear it whenever you wanted. Your email address follows you everywhere. You type it into every store, newsletter, app, loyalty program, and login screen. It is the same on your phone, your laptop, and your work computer. It survives for decades.

Continue reading