Sign in

Zach Edwards

@thezedwards.bsky.social
1.5K followers 6.6K following 3.9K posts

data supply auditor | privacy & ad tech expert | internet threats Personal @ victorymedium.com Work @ Staff Threat Researcher @ Infoblox.com Co-Founder @ DecryptAds.com

PostsRepliesMedia
Zach Edwards @thezedwards.bsky.social · 06/10/2026
Massive news from Google today (futurism.com/artificial-i...) -- they are finally going to be down ranking AI slop publishers who are deceptive about their owners / authors / writers. Big congrats to @futurism.com and their pieces on the BBM network which broke the camels back!
Previously, Google’s rules for creating “helpful, reliable, people-first content” included this guidance:

“If you’re clearly indicating who created the content, you’re likely aligned with the concepts of E-E-A-T [experience, expertise, authoritativeness, and trustworthiness] and on a path to success,” it read. “We strongly encourage adding accurate authorship information, such as bylines to content where readers might expect it.”

Yesterday, though, Google added a strongly worded new paragraph under that one:

“However, avoid using deceptive authorship information,” reads the new guidance. “Fabricating creator profiles (such as by using AI-generated headshots, made-up names, or false credentials to make content appear as if it was written by human experts) is a form of deception. Any form of deception makes a page untrustworthy to both users and our automated quality systems, and is a signal of a low-quality page.”
072
Zach Edwards @thezedwards.bsky.social · 04/10/2026
I for one enjoy when 2 tech giants fight it out in the streets, especially when one is fighting for a slightly more privacy centric version of the future. So I truly do hope to one day in the future see a Safari for Android & an Apple App Store for Android. I think the market needs these options.🖖
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
Final thought: it's 'defensive' when Apple breaks something like IDFA / MAID products, or blocks ad tech domains used for various ad delivery / user tracking / fingerprinting schemes -- but the real offensive move is going to be if they use their growing privacy commitments against Google directly.
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
Best of luck to everyone in ad tech recently blocked by the Safari changes trying to back channel to Apple to get this privacy enhancement & improvement reversed. Hopefully ad tech folks have plans for "Apple MAIDageddon" - the day Apple finally stops building their data broker MAID. What's next??
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
Every time Apple evolves privacy frameworks people in the industry go through the 5 stages of ad tech grief: "Claiming it's a rumor" "Yelling about Apple self preferencing" "Attempting to back channel when comms are on a public github page" "iDepression™" "Attempting Fingerprinting Workarounds"
101
Zach Edwards @thezedwards.bsky.social · 04/10/2026
If Apple steps into the Android app store, they will then of course need to facilitate 3rd party app stores on iOS in all regions instead of largely only allowing this in Europe and a few countries, but this could be done with a flip of a switch that has likely already been built for years.
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
Only time will tell what the new Apple CEO is willing to green light, but don't think for a minute they don't have folks internally advocating to move on Google by stepping into their Android ecosystem. And for a lot of that we have Epic Games to thank for their lawsuit.
110
Zach Edwards @thezedwards.bsky.social · 04/10/2026
I continue to see opportunities for Apple to shift conversations around privacy and box Google into a bunch of tricky situations due to their reliance on ad tech revenue. There's never been a better time for Safari for Android or an Apple App Store for Android + breaking IDFA / other tracking
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
imo in a world where everyone is rightfully worried about flock cameras & ad tech big data sets tracking them, a company like Apple can step up big into the anti-tracking space by fixing their current tracking vectors (#1 IDFA MAID, #2 cross-site fingerprinting domains, #3 more IP / VPN products)
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
Many folks can appreciate the new Apple CEO likely started his job on day 1 with a series of memos about potential opportunities, and one of them likely was titled, "Safari for Android" and/or "Apple App Store for Android" - these are clear growth opportunities against Google with these.
110
Zach Edwards @thezedwards.bsky.social · 04/10/2026
Apple's new CEO needs to plant his own flag on privacy, and they have likely had teams advocating for changes to their mobile MAID products for years. It appears Safari just got the green light to break known cross-domain/app fingerprinting and tracking schemes, but where is Safari for Android?
112
Zach Edwards @thezedwards.bsky.social · 04/10/2026
We're in a place where Google has been forced to allow 3rd party App marketplaces on Android, they will now be keeping their ad tech stacks, & so for the indefinite future, Google = antiprivacy due to their reliance on ad tech revenue. This is the perfect opportunity for Apple to move into Android.
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
So am I surprised that Apple see's an opportunity in this chaotic data privacy environment to make further changes to Safari and maybe other channels/ apps / their devices? No. And when Google has just won a historic (and likely last) antitrust effort to breakup their ad tech division, what's next?
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
We still don't have a federal privacy law in the U.S., the Europeans are constantly taking one step forward and then tripping while trying to step backwards, and outside of some encouraging state laws + the new DROP data broker opt-out program in California (www.eff.org/deeplinks/20...), it's bad.
eff.org
Protect Your Privacy with California's DROP Tool
Are you a California resident? Then we've got exciting news for you: there's a tool just for you that lets you take a single, relatively easy step to protect your privacy. It's called a DROP request. ...
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
And I think Russian + Chinese + Cypress + UAE (and other) ad tech companies have been slowly growing their presence and publisher partners through aggressive SSP / sales house deals (likely 'guaranteed revenue' to add the company to their ads.txt / app-ads.txt, giving data/targeting opportunities)
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
To me some platforms & most regulators have been asleep at the wheel as ad tech companies have developed technologies to track people across websites and apps (uhh what have ya'll been doing over there Applovin eh?? www.buchodi.com/i-broke-appl...) outside the allowed frameworks.
buchodi.com
AppLovin's mediation protocol.
I broke the cipher AppLovin wraps around its ad-mediation traffic and decrypted several thousand real requests captured. The conclusion is straightforward: The encrypted bid request carries enough dev...
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
Some folks may think, "Ah I guess those dozens of ad tech shell companies based in the UAE are perfect angels & would never sell data they collect from the global bid streams" or "Why would BetweenDigital, a Russian ad tech company with a CEO based in Moscow be untrustworthy?" Those things worry me.
110
Zach Edwards @thezedwards.bsky.social · 04/10/2026
At DecryptAds we organize ad systems by geography & have categories for risky geography (available w/ account @ decryptads.com/geo_risk) and *none* of the 299 ad tech companies from our Risky Geo lists are registered as data brokers. Essentially foreign ad tech is invisible on state registries.
Screenshot of the DecryptAds (Decrtypads[.]com) interface and our Geo Risk page showing Sanctions, Adversary, Secrecy Haven and Elevated countries. Sanctions
81 ad systems flagged
OFAC comprehensive or near-comprehensive programs. Ad systems registered here may be off-limits to US-person counterparties without specific OFAC licensing.
 Russia  Belarus  Iran  North Korea  Syria  Cuba  Venezuela  Myanmar (Burma)
Adversary
89 ad systems flagged
US Executive Order 14117 countries of concern for sensitive US personal data. Non-sanctioned but subject to heightened scrutiny (CFIUS, DOJ bulk-data rules).
 China  Hong Kong  Macau
Secrecy haven
25 ad systems flagged
FATF grey list / Tax Justice Network Financial Secrecy jurisdictions frequently used as shell-company havens. A registration here is a diligence flag, not a determination.
 Cyprus  British Virgin Islands  Cayman Islands  Panama  Seychelles  Marshall Islands  Belize  Gibraltar  Isle of Man  Jersey  Liechtenstein  Malta
Elevated
104 ad systems flagged
Other enforcement-flagged jurisdictions and active conflict zones warranting heightened diligence.
 United Arab Emirates  Turkey  Pakistan  Nigeria  Ukraine
111
Zach Edwards @thezedwards.bsky.social · 04/10/2026
And when you look at the lists of ~63 ad tech orgs who have registered as a data broker in either California, Texas, Vermont or Oregon @ decryptads.com/data_broker one *shocking* reality is that literally none of the 299 ad tech companies registered in risky geographies are data brokers?.. hmm
static.klipy.com
Elf: You Sit On A Throne Of Lies
Alt: Elf: You Sit On A Throne Of Lies
111
Zach Edwards @thezedwards.bsky.social · 04/10/2026
One of the reasons that we launched DecryptAds was to make it easier to understand the ad tech companies which were registered as data brokers to understand the publisher websites & apps that are part of their data ingestion schemes. Right now there are *63* major ad tech companies on these lists.
Screenshot of the DecryptAds data broker registry page showing the ad tech companies on the California, Texas, Vermont or Oregon data broker list. Available with an account @ https://decryptads.com/data_broker
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
imo the ad tech industry has been slowly getting too comfortable with the data sharing they are facilitating, largely brought on by Chrome's decision to not depreciate 3rd party cookies. Folks saw that & took a deep breath then decided to double down on cross website / app tracking schemes.
121
Zach Edwards @thezedwards.bsky.social · 04/10/2026
If you haven't yet, please read the amazing research on Extended Identifier tracking (arxiv.org/html/2609.02... ) and then check out the changes that Apple has quietly rolled out recently which the ad tech industry is trying to roll back (www.adexchanger.com/privacy/appl...)
Chart from the "Bridging the Gap: A Longitudinal Analysis of Extended Identifiers in the Post-Cookie Era" with a list of "Identity providers" and the number of SSP / IDs per provider. The list includes ID5, Trade Desk, Audigent and numerous other providers recently blocked by Apple. Text from the AdExchanger article "Apple Has Far-Reaching Plans To Block Hundreds Of Programmatic Data Companies From iOS" - text reads "Earlier this week, AdExchanger reported that Apple’s iOS 27 update from two weeks ago quietly blocked a handful of programmatic data players – including The Trade Desk and its Unified ID 2.0 initiative, LiveRamp, ID5, Permutive and Audigent – from collecting data or serving ads on Safari. (They were also blocked on other mobile browsers, since browsers must use WebKit to launch on Apple devices.)"
120
Zach Edwards @thezedwards.bsky.social · 04/10/2026
Many of the companies impacted by Apple's recent fingerprinting restrictions are also cited in a report from some of the most serious researchers in ad tech released in September 2026 about the growth in extended identifiers as an alternative to tracking in a world without 3rd party cookies.
110
Zach Edwards @thezedwards.bsky.social · 04/10/2026
For folks trying to figure out why Apple may be suddenly changing their policies on fingerprinting, I'm shocked more folks haven't shared "Bridging the Gap: A Longitudinal Analysis of Extended Identifiers in the Post-Cookie Era" @ arxiv.org/html/2609.02... from some of the smartest folks...
arxiv.org
Bridging the Gap: A Longitudinal Analysis of Extended Identifiers in the Post-Cookie Era
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
Google even made a big deal out of the ITP privacy leaks in 2020 and how someone could leak browser data and other details via this bug (which was quickly patched by Apple) @ www.mediapost.com/publications... (research.google/pubs/informa...)
mediapost.com
Google Researchers Say Workarounds Fail To Fix Underlying Problems In Apple Safari ITP
Google Security Engineering researchers detailed several data leak issues in Apple's Intelligent Tracking Prevention (ITP) technology, which aims to restrict cookies from sharing data and browsing ha...
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
And let's be clear, Intelligent Tracking Protection, and the way it builds block lists using local ML models, has been a 'secret block list' since launch? www.apple.com/safari/docs/... That's part of what makes this tech fancy -- but Apple has been stuff like this since 2003 - always pushing ahead
121
Zach Edwards @thezedwards.bsky.social · 04/10/2026
Personally when I see something launch in Safari which aligns to their "Prevent cross website tracking" privacy commitments, I'm never surprised. They have always been far ahead of the game. They were the first on ~every major privacy change (Mozilla + Brave + a few others have done solid work too)
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
I think the one reason Apple wouldn't launch an Android app store is concern for antitrust investigations, but if they can make a definitively safer product it makes a much more convincing argument to allow something like this to launch. And right now, antitrust cases are not a real threat...
110
Zach Edwards @thezedwards.bsky.social · 04/10/2026
Imagine if you're an Android user and you've got the option from using the exact same app from the Google Play app store and the Apple app store, except the Apple version is guaranteed to have some framework which breaks MAIDs and cross-site tracking vectors and is inarguably more privacy safe.
100
Zach Edwards @thezedwards.bsky.social · 04/10/2026
If Apple broke their Apple MAID & then launched a new "Apple App Store for Android" & banned apps from making requests to the Android Ad ID (developers.google.com/android/refe...) they could effectively protect people from MAIDs & the location data broker ecosystem across both iOS & Android.
110
Zach Edwards @thezedwards.bsky.social · 04/10/2026
Prediction: We'll have an Apple App Store for Android & Safari for Android sometime in the future. Apple could announce breaking the MAID finally & all cross domain / cross-app tracking domains prior to launch. Google keeping their ad tech in the antitrust case are cement shoes. ICYMI ⤵️🌩️⚖️🧵
adexchanger.com
Apple Has Far-Reaching Plans To Block Hundreds Of Programmatic Data Companies From iOS | AdExchanger
Oh, what a tangled WebKit we weave. Earlier this week, AdExchanger reported that Apple’s iOS 27 update from two weeks ago quietly blocked a handful of programmatic data players – including The Trade D...
132
Zach Edwards @thezedwards.bsky.social · 27/09/2026
FWIW I'm also advocating for this to eventually use new ad targeting transparency data being exposed client side to help people understand this targeting ecosystem. In the meantime building my dream ad tech research tool @decryptads.bsky.social -- I've written more @ decryptads.com/blog/posts/a...
decryptads.com
The Ad Tech Industry is a Non-Transparent Mess, and DecryptAds Aims to Do Something About It
DecryptAds maps programmatic ad-tech supply chains from public files — trace hidden flows, surface invalid supply, and publish evidence-backed findings.
000
Zach Edwards @thezedwards.bsky.social · 27/09/2026
Long story short, more data privacy folks should be talking about Supply Chain Object (digiday.com/media/wtf-is...) + Demand Chain Object / buyers.json @ www.confiant.com/news/bringin... & understanding the transparency opportunities if we were to require this data to be exposed publicly. 🌩️⚖️🖖
122
Zach Edwards @thezedwards.bsky.social · 27/09/2026
Someone could in the future be viewing an ad which was targeted with OpenAI data, which promoted some external product, and unless some part of the attribution (UTM) strings doxxed the relationship, the end user could have no clue what DSP / targeting company like OpenAI could have been behind it.
110
Zach Edwards @thezedwards.bsky.social · 27/09/2026
With AI companies like OpenAI shifting into internal ads products, most folks know that this will slowly push them into more and more external ad products, that's the nature of the financial opportunities in this space. If OpenAI were to help "target ads off ChatGPT - across the web and apps!"...
100
Zach Edwards @thezedwards.bsky.social · 27/09/2026
One concern is that we're on the cusp of going through another contentious presidential U.S. election, with potentially billions of dollars spent on digital ads and other channels with user targeting, and once again people won't know how those political ads are targeted to them on the open web.
100
Zach Edwards @thezedwards.bsky.social · 27/09/2026
I'm confident that at some point in the future legislators in some corner of the world will realize that this ad tech data exists and understand why it should be transparently shown to end-users being targeted with ads, and it will kick off a slow push to expose these payloads globally.
100
Zach Edwards @thezedwards.bsky.social · 27/09/2026
imo the ad tech industry has not even gotten close to resolving data privacy concerns to give folks trust to turn off ad blockers. And until there's a serious effort by ad tech to actually make the ad targeting companies transparently visible to the people being targeted, trust will remain broken.
120
Zach Edwards @thezedwards.bsky.social · 27/09/2026
laws to require the Supply Chain Object (SCO)/buyers.json + Demand Chain Object (DCO) be exposed in a human readable label after an ad was served, suddenly people would know all of the companies involved in targeting an open programmatic banner ad / video shown on websites / apps / CTV..
110
Zach Edwards @thezedwards.bsky.social · 27/09/2026
But none of the new ad tech standards require sharing these details publicly - ad tech won't do this by default unless they are required by law. But if one enterprising legislator out there was able to push through an effort to require the ad tech industry to publicly share new data after auctions..
122
Zach Edwards @thezedwards.bsky.social · 27/09/2026
What would happen if when someone were browsing a site and an invasive ad about medical issues showed up, but they knew with one click they could click to see what company helped to target the ad? The ad tech industry is requiring sharing this data as part of new standards...
110
Zach Edwards @thezedwards.bsky.social · 27/09/2026
There are countless ad tech companies who play fast and loose with what it means to be a data broker so they don't register as a data broker, but they still collect profiles on people and help 3rd parties target ads to those ad segments. But those folks get to largely hide and never face scrutiny.
141
Zach Edwards @thezedwards.bsky.social · 27/09/2026
For states like California w/ automated data broker deletion frameworks ("California's Delete Request and Opt-out Platform (DROP)" @ privacy.ca.gov/drop/) someone can participate in that effort with their data being deleted from hundreds of data brokers automatically, but still tracked by ad tech?
100
Zach Edwards @thezedwards.bsky.social · 27/09/2026
The Demand Chain Object and Supply Chain Object aren't fully implemented by the ad tech industry, with various orgs dragging their heels, but if this was required to be exposed client side, people would see an ad and know far more about who targeted and monetized that ad.
120
Zach Edwards @thezedwards.bsky.social · 27/09/2026
There's a buyers.json standard and Demand Chain Object (iabtechlab.com/buyers-json-...) Supply Chain Object (support.google.com/admanager/an...) which could be required by legislators / regulators / laws to be exposed *client side* instead of hidden away server side only for ad tech visibility.
110
Zach Edwards @thezedwards.bsky.social · 27/09/2026
There are DSPs and highly aggressive audience companies involved in helping to target invasive creative (medical issues / gambling / family issues / etc) and yet when those ads are served, the end-user has *no idea* what company is helping with that invasive targeting. But that data *is available*
120
Zach Edwards @thezedwards.bsky.social · 27/09/2026
I really wish more data privacy folks would talk about the lack of disclosures folks have after a programmatic ad is served. You may know the entity hosting that banner frame, and some have "About this advertiser" info, but you don't know who targeted the ad or who bought/sold the impression.
120
Zach Edwards @thezedwards.bsky.social · 27/09/2026
We're a decade past Cambridge Analytica ad targeting scandals and even Facebook still doesn't expose the native FB likes/interests being used to target ads. Microtargeting is largely invisible. We've got the same problems with open web programmatic advertising - but there are standards to help!🧵
241
Zach Edwards @thezedwards.bsky.social · 18/09/2026
Researching AI slop networks can be a nightmare with how quickly they are being spun up, and if you aren't using programmatic advertising data for pivots, you literally won't be able to do this work effectively. Our MCP is @ mcp.decryptads.com (would love any feedback form others)
mcp.decryptads.com
DecryptAds MCP
DecryptAds MCP endpoint, API key setup, tool list, and client configuration.
100
Zach Edwards @thezedwards.bsky.social · 18/09/2026
smallbusinessbonfire[.]com, solardaily[.]com, space-travel[.]com, spacedaily[.]com, spacemart[.]com, spacewar[.]com, terradaily[.]com, theartfulage[.]com, thevessel[.]io, tweakyourbiz[.]com, vegoutmag[.]com, newsreports[.]com, thelawdictionary[.]org
100