How Cookie Stuffing Actually Works
More specifically, a tactic as old as digital marketing called "cookie stuffing."
But let us just pause for a moment and take in the fact that 7 years before Phoebe Gates was born, Microsoft deployed the cookie spec into Internet Explorer. Her father founded and lead the company while her mother was also a senior member of management at the time. Even though cookies were invented by the team at Netscape, IE was the browser that drove explosive growth.
Then, 31 years later, the market alleges that their daughter's tech startup was involved in a large-scale media attribution scandal. This is the type of drama nerds dream of.
The honest handshake that never was
So what is the actual alleged crime? It is one of the oldest hacks in ad tech
Affiliate marketing operates on a pretty simple agreement that if you drive sales, you get paid a commission. The ways we prove who drove what sale is the tricky bit.
In overly simplified terms:
- A publisher writes about a product.
- You click their link.
- Your browser stores a tracking cookie.
- You buy the product.
- The merchant sees the cookie and pays the publisher a commission.
The entire system rests on one assumption: the cookie "proves" influence.
Cookie stuffing breaks that assumption. Someone plants an affiliate cookie in your browser without you ever clicking anything. You later buy something on your own. Direct visit, Google search, whatever. The merchant's billing attribution vendor looks up the planted cookie and pays a commission to someone who did nothing.
It is attribution theft. I call it last-click larceny.
The plumbing
Your browser is trusting by design. When a page tells it to fetch a resource, it fetches. If the responding server sends back a cookie, the browser stores it. Few questions asked.
Fraudsters exploit that trust a few ways: