Blacklight Report - https://arstechnica.com/

Blacklight searched 2 pages on arstechnica.com at 29th September 2026 20:22 ET.
For more information on the files in this report please visit our Github Repository.

Blacklight Inspection Result

Blacklight works by visiting each website with a headless browser running custom software built by The Markup. To learn more, read our methodology.

  • 34 Ad trackers found on this site. This is more than the average of seven that we found on popular sites

    Websites containing advertising tracking technology load JavaScript code or small invisible images that are used to either build your advertising profile or to identify you for ad targeting on this site. These techniques are often used in addition to cookies to profile you.,Blacklight detected trackers on this page sending data to companies involved in online advertising. Blacklight detected scripts belonging to TripleLift, Microsoft Corporation, and twenty-two other companies.

  • 42 Third-party cookies found. This is more than the average of three that we found on popular sites

    These are commonly used by advertising tracking companies to profile you based on your internet usage.,Blacklight detected 42 third-party cookies on this site. Blacklight detected cookies set for Amazon Technologies, Inc., Conde Nast Publications Inc. and and twelve others

  • This website loads trackers on your computer that are designed to evade third-party cookie blockers.

    Canvas fingerprinting was detected on this website. This technique is designed to identify users even if they block third-party cookies. It can be used to track users' behavior across sites. This technique was used by six percent of popular sites when we scanned them in September 2020., Blacklight detected a script belonging to the company Teads ( Luxenbourg ) SA doing this on this site.,It secretly draws the following image on your browser when you visit this website for the purpose of identifying your device.

    However...

    While Blacklight accurately detects the presence of canvas fingerprinting on a website, it cannot determine if the purpose is user behavior monitoring or for fraud prevention or bot detection.

  • This website could be monitoring your keystrokes and mouse clicks.

    Blacklight detected the use of a session recorder, which tracks user mouse movement, clicks, taps, scrolls, or even network activity. This data is compiled into videos and heat maps that website owners can watch to see how users interact with the site. Research has shown these practices can be insecure and make sensitive user data such as passwords and credit card information more vulnerable to leaks. This technique was used by fifteen percent of popular websites when we scanned them in September 2020., Blacklight detected a script belonging to the company Hotjar Ltd doing this on this site.

    However...

    While Blacklight can detect whether a session recorder was loaded, it cannot determine exactly how the collected data is being used.

  • When you visit this site, it tells Facebook.

    The Facebook pixel is a snippet of code that sends data back to Facebook about people who visit this site and allows the site operator to later target them with ads on Facebook. A Facebook spokesperson told The Markup that the company set up this system so that a user doesn’t have to be “simultaneously logged into Facebook and viewing a third-party website for our business tools to function.” Common actions that can be tracked via pixel include viewing a page or specific content, adding payment information, or making a purchase. The Facebook pixel appeared in thirty percent of popular websites when we scanned them in September 2020.

  • When you visit this site, it tells TikTok — even if you block cookies.

    The TikTok pixel is a snippet of code that sends data back to TikTok about people who visit this site and allows the site operator to later target them with ads on TikTok. A user doesn’t have to be “simultaneously logged into TikTok and viewing a third-party website for our business tools to function.” Common actions that can be tracked via pixel include viewing a page or specific content, adding payment information, or making a purchase.,This website seems to be using TikTok pixel "advanced matching" feature, which allows the site to share data about visitors with TikTok even if users block TikTok cookies.

  • When you visit this site, it tells X.

    The X pixel is a snippet of code that sends data back to X (previously known as Twitter) about people who visit this site and allows the site operator to later target them with ads on X. A user doesn’t have to be “simultaneously logged into X and viewing a third-party website for our business tools to function.” Common actions that can be tracked via pixel include viewing a page or specific content, adding payment information, or making a purchase.

  • This site allows Google Analytics to follow you across the internet.

    This site uses Google Analytics and seems to use its ”remarketing audiences” feature that enables user tracking for targeted advertising across the internet. This feature allows a website to build custom audiences based on how a user interacts with this particular site and then follow those users across the internet and target them with advertising on other sites using Google Ads and Display & Video 360. A Google spokesperson told The Markup that site operators are supposed to inform visitors when data collected with this feature is used to connect this browsing data with someone’s real-world identity. You know when those shoes you were looking at follow you around the internet? This is one of the trackers leading to that. This feature appeared in fifty percent of popular websites when we scanned them in September 2020.

Some of the ad-tech companies this website interacted with:

The inspected website contacted some well known actors in the ad-tech industry. Not all of these loaded trackers, so they may be different from those listed in the tests section above. For more information on each company, what it does, and which of its domains Blacklight found during the inspection, click the arrow. Reading this can give you a better idea of how the ad-tech industry works.

  • Alphabet

    Blacklight detected this website sending user data to Alphabet, the technology conglomerate that encompasses Google and associated companies like Nest. The Silicon Valley giant collects data from twice the number of websites as its closest competitor, Facebook. An Alphabet spokesperson told The Markup that internet users can go here if they want to opt out of the company showing them targeted ads based on their browsing history. ,The site sent information to the following domains doubleclick.net, google.com, googleadservices.com, googlesyndication.com, googletagmanager.com, googletagservices.com.

  • Amazon

    Blacklight detected the inspected website sending user data to Amazon, which has a wide variety of business units. The most commonly appearing Amazon trackers in our scan of popular sites in September 2020 were those for CloudFront and its marketing research arm, Alexa, which helps marketers improve their search engine performance and provides site operators insights about the popularity of their websites. (This Alexa is unrelated to Amazon’s virtual assistant of the same name.) Representatives from Amazon did not respond to multiple requests for comment., The site sent information to the following domain amazon-adsystem.com.

  • Comscore

    Blacklight detected the inspected website sending user data to Comscore, a company that monitors traffic on millions of websites to create market research data on how people use the internet, which it sells to advertisers, according to The Guardian. The company’s analytics also incorporate user data collected from its dozens of corporate partners, such as Facebook, Oracle, and Salesforce, according to its own website. Representatives from Comscore did not respond to multiple requests for comment. , The site sent information to the following domain scorecardresearch.com.

  • Criteo

    Blacklight detected the inspected website sending user data to the advertising technology company Criteo, which a company spokesperson told The Markup specializes in what are called “retargeting campaigns,” targeting advertisements across the internet at people who have already visited the advertiser's digital properties. Decisions about which previous site visitors to target are made with profiles compiled by the company about consumers’ interests and previous shopping behavior. Speaking in July 2020, CEO Megan Clarken said that the company had data on “2.5 billion unique users globally, of which 98 percent had persistent identifiers beyond cookies.” , The site sent information to the following domain criteo.com.

  • DoubleVerify

    Blacklight detected the inspected website sending user data to DoubleVerify, an ad tech company that says it helps advertisers, online advertising exchanges, and site operators track ad performance, prevent fraud, and ensure ads are only running next to content with which advertisers are comfortable. Representatives from DoubleVerify did not respond to multiple requests for comment., The site sent information to the following domain doubleverify.com.

  • HotJar

    Blacklight detected the inspected website sending user data to the behavioral analytics company HotJar. A HotJar spokesperson told The Markup that the company helps website operators better understand how users interact with their websites. HotJar offers things like heatmaps (showing where on a page users have clicked or moved their mouse cursor), session recordings (that play back videos of a user’s actions while on the website), as well as polls and surveys (querying users directly about their experiences on a site)., The site sent information to the following domain hotjar.com.

  • LinkedIn

    Blacklight detected the inspected website sending user data to LinkedIn, which is owned by Microsoft. Primarily known as a career-focused social network, the company has branched out more broadly into advertising. In 2019, it purchased Drawbridge, which a company spokesperson told The Markup allows LinkedIn to “infer a member’s association to their devices” in what’s called an “identity graph.” At the time of the acquisition, a LinkedIn executive told Ad Exchanger the company hoped Drawbridge will fill in some of the blind spots LinkedIn has on its users.,The site sent information to the following domains licdn.com, linkedin.com.

  • LiveRamp

    Blacklight detected the inspected website sending user data to LiveRamp. Using its own, unique identifier for each individual, LiveRamp verifies that data held by Company A is about the same person as the data held by Company B. LiveRamp also operates a Data Store, where advertisers can purchase datasets, like this one, about consumers from LiveRamp’s corporate partners. , The site sent information to the following domain pippio.com.

  • OpenX

    Blacklight detected the inspected website sending user data to OpenX, an online advertising exchange. Ad exchanges are online marketplaces where advertisers can bid against each other to place ads on various websites. OpenX specializes in real-time bidding, according to its website, which is when ads are targeted at individual web users based on profiles assembled about their demographics and prior behavior. It also says on its website that ads placed by the exchange reach more than 240 million U.S. consumers each month. Representatives from OpenX did not respond to multiple requests for comment., The site sent information to the following domain openx.net.

  • PubMatic

    Blacklight detected the inspected website sending user data to the online advertising company Pubmatic. Pubmatic is a portal for site operators to offer space on their website for sale to advertisers. The company also runs an “identity hub” that, a PubMatic spokesperson told The Markup, helps advertisers use the data they’ve acquired from a third party— a data broker, for example—to target ads to the specific interests of someone visiting a website. , The site sent information to the following domain pubmatic.com.

  • Magnite

    Blacklight detected the inspected website sending user data to Magnite. Created by the 2020 merger of ad tech companies Rubicon Project and Telaria, Magnite places advertisements on more than million websites and apps. The company claims to have reached more than a billion consumers with ads placed on websites, mobile apps, and streaming videos. Representatives from Magnite did not respond to multiple requests for comment., The site sent information to the following domain rubiconproject.com.

  • TowerData

    Blacklight detected the inspected website sending user data to Tower Data, an ad tech company that creates profiles of web users anchored to their email address, according to its website. It also sells data about voters to political campaigns. Representatives from Tower Data did not respond to multiple requests for comment., The site sent information to the following domain rlcdn.com.

  • Verizon

    Blacklight detected the inspected website sending user data to Verizon. While best known for providing cellphone and broadband service, Verizon has gained a significant presence in online advertising through acquisitions of ad-focused companies like AOL and Yahoo!, which offer advertising services in addition to content. Domains associated with Yahoo! and AOL (specifically, advertising.com, which was part of AOL before Verizon’s purchase of the company) appeared the most frequently among the many Verizon-controlled trackers appearing in our scan of popular websites in September 2020. Representatives from Verizon did not respond to multiple requests for comment., The site sent information to the following domain yahoo.com.

Blacklight results should not be taken as the final word on potential privacy violations by a given website. Rather, they should be treated as an initial automated inspection that requires further investigation before a definitive claim can be made.