Home Online Advertising How Safari’s ITP 2.3 Update Is Cracking Down On Link Decoration ‘Abuses’

How Safari’s ITP 2.3 Update Is Cracking Down On Link Decoration ‘Abuses’

SHARE:

One more cookie workaround bites the dust, in Safari at least.

The latest iteration of Intelligent Tracking Prevention, ITP 2.3, is cracking down on localStorage and other tracking mechanisms that try and outfox ITP. The change was already in the code base, but hadn’t yet been publicized.

LocalStorage is a form of web storage that allows sites to store data directly in the browser with no expiration date. LocalStorage is sometimes lumped together with edge computing, which is a method for processing data closer to where it’s created, in this case the publisher’s domain within the browser.

The newer crop of second-generation data-management platforms, including Permutive, use a combination of localStorage and edge computing as an alternative to third-party cookies, and position the practice as privacy compliant, because the data doesn’t leave a user’s device. For this reason, Permutive claims that it’s unaffected by ITP changes.

In a blog post on Monday, WebKit security and privacy engineer John Wilander explained that the primary motivation behind ITP 2.3 is to combat what WebKit considers to be the “continued abuse” of link decoration, aka adding code to a URL in order to create cookie-less identifiers.

Previously, ITP 2.2 cut the lifespan of persistent client-side cookies from seven days to 24 hours and restricted cross-site tracking via link decoration.

But WebKit engineers noticed that some trackers had responded by moving their first-party cookies to other forms of first-party website data storage to track users.

Because ITP 2.2 outlawed decorating the link of the destination page, some trackers added code to their own referrer URL to read the tracking ID on the destination page.

Under ITP 2.3, sites that do this will see all of their non-cookie website data deleted after seven days. Combined with the capped expiration of client-side cookies, this means trackers won’t be able to use link decoration combined with long-term first-party website data storage to track users.

It’s unclear if localStorage is still kosher as long as it’s not combined with link decoration.

Over the years, publishers have deployed third-party scripts on their sites that, according to Wilander, have been “repurposed to circumvent” Safari’s protections against third-party tracking.

“ITP 2.3 makes sure that third-party scripts cannot leverage the storage powers they have gained over all these websites,” Wilander wrote.

Although ITP 2.3 is “an expected next step in the arms race” between Apple and marketers, there’s actually a silver lining in this announcement, said Andraz Tori, head of recommendations and data science at Outbrain.

Because ITP 2.3 allows first-party tracking capabilities for conversions up to seven days after the click, it’s actually “much more generous” in detailing the data available to marketers, compared to Safari’s ad click attribution API proposal from a few months ago. The experimental feature, for example, proposes only reporting that a conversion happened for a user who clicked on an ad and nothing more specific than that.

“Seven days for granular conversion attribution is probably something most marketers will be able to live with,” Tori said.

Even so, the real takeaway from ITP 2.3 is that WebKit will systematically root out cookie tracking workarounds.

Also included in ITP 2.3 are updates to the storage access API, a debug mode for Safari on macOS Catalina and a note at the end encouraging the use of secure and HttpOnly cookies, which are cookies that can only be accessed via a server and not via a client script.

Intelligent Tracking Prevention (ITP) version 2.3 is included in Safari on iOS 13, the iPadOS beta and Safari 13 on macOS for Catalina, Mojave and High Sierra.

Updated 9/25 to reflect changes to the definitions of localStorage and edge computing and to the reference to Permutive.

Must Read

Fox Announces Plans To Acquire Roku For $22 Billion

It’s long felt like a foregone conclusion that Roku would eventually get gobbled up by a much bigger fish. Now, the day has finally arrived.

What Platforms Say Will Bring Bigger Ad Budgets To Digital Audio

To close the gap between digital audio ad spend and audience engagement, audio platforms want to get more deeply embedded in omnichannel campaign planning tools.

AdExchanger's Big Story podcast with journalistic insights on advertising, marketing and ad tech

Programmatic TV Home Screens And Gaming Ads For Kids

How can companies put ads in new places without hurting the user experience? Smart TV makers, like Samsung, are adding programmatic ads to the home screen, and Roblox will now show ads to users under 13. We examine the trade-offs as platforms expand their ad footprint.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

This AI 'Brain' Wants To Get Rid Of The Grunt Work In Creative Campaigns

Innovid’s latest offering serves as the “brain” behind a company’s orchestration layer. Optimum says it reduces manual work and cuts down on execution time.

multiple sets of eyes

Amazon DSP Adds Adelaide’s Pre-Bid Attention Targeting

Advertisers can target high- and medium-attention ad inventory in Amazon DSP while filtering out low-attention placements and made-for-advertising sites.

Marketers Are Getting Used To AI In The Ad Stack

Marketers and media buyers are gradually getting more comfortable talking about ad campaigns they’re testing on large-language models like OpenAI’s ChatGPT.