I was about to click a link last week when it hit me — the sidebar ad had just shifted from hiking boots to the exact brand of hiking boots I’d been looking at on a totally different site an hour earlier. My first instinct, same as everyone’s, was “it’s listening to my mic.” It’s not. I wish it were that simple, honestly, because a phone quietly recording you is at least a story you can wrap your head around. What’s actually happening is worse, and it doesn’t need your microphone at all — it just needs you to click something, because clicking is enough to kick off an auction you were never invited to.
The 100-Millisecond Auction #
That auction runs in the time it takes a page to think about loading. By the time your spinner finishes spinning, a company you’ve never heard of has already bought the right to show you an ad based on a packet of information about you that got broadcast to hundreds of strangers a few hundred milliseconds earlier. This is Real-Time Bidding, RTB if you want the acronym, and it’s not a metaphor for surveillance — it’s just straightforwardly surveillance with a billing department attached.
Here’s the mechanics, because the mechanics are the part nobody explains. You click a link. The site you landed on pings an Ad Exchange — think of it as a trading floor, except the thing being traded is a profile of you. The Exchange fires that profile out to hundreds of Demand-Side Platforms simultaneously, and those DSPs run their own math in real time to decide what you’re worth to them right now, this second, based on who you are and what you’re probably about to buy. Highest bidder wins, their ad renders, and the whole auction — discovery, bidding, settlement — is done before your page finishes painting. I’ve had slower text messages.
Inside the Bidstream #
What actually goes out in that packet is the part that should bother you more than it does. It’s not some anonymized blob. It’s your GPS coordinates, accurate down to the meter in a lot of cases — not “which city,” which exact spot you’re standing in. It’s device behavior data: battery level, screen brightness, what kind of phone you’re holding, because apparently your battery percentage is also for sale now. And underneath that is what I’d call the dossier layer — inferred stuff nobody told them directly, built from your reading habits, your search history, traits some model decided you probably have based on patterns you never consented to being scored on. And this isn’t a once-a-day thing. The Irish Council for Civil Liberties put actual numbers on it — the average American gets this packet broadcast out about 747 times a day, and the average European about 376 times a day. Multiply that out and you’re at 178 trillion broadcasts a year across the US and Europe combined. That’s not a leak. That’s the business model running exactly as designed, every single day, at a scale that makes most actual data breaches look quaint. (ICCL report on the scale of Real-Time Bidding data broadcasts in the U.S. and Europe - Irish Council for Civil Liberties +2)
The Losing Bidder Data Scam #
Now here’s the part that made me genuinely angry when I first read it, because I assumed — stupidly, in hindsight — that losing an auction meant your data just evaporated. It doesn’t. Only one company wins the right to show you the ad, sure, but every single company that bid and lost still received your full profile before the auction even closed. That’s not a side effect, that’s how the auction has to work — you can’t bid on something without seeing it first. And there is no technical mechanism forcing any of those losers to delete what they just saw. None. So hundreds of companies a day are getting a free look at your location, your habits, your inferred traits, and the only thing stopping them from keeping it forever and building their own shadow profile on you is their own self-restraint. I don’t need to tell you how that’s going.
The National Security Loophole #
And if you think “well, at least it’s just advertisers,” that’s where it gets worse. Government agencies figured out a while back that buying this data from brokers is a lot less paperwork than getting a warrant. Why go through a judge when Bidstream data is sitting there, for sale, already packaged, already granular enough to reconstruct somebody’s patterns of life — where they go, when, how often — with zero judicial oversight involved at any point. It’s not hacking. It’s not even illegal. It’s a receipt. The EFF and the ICCL are both actively in court over exactly this, going after the ad tech giants and the IAB directly, because right now the oversight gap here isn’t a loophole so much as a loading dock nobody bothered to lock.
How You Starve It #
So what do you actually do with this. Not panic — starve it.
Start at the network level. Run DNS-level blocking before any of this traffic leaves your house — NextDNS if you want something that just works, a Pi-hole if you want to run it yourself. Kill the ad-tech domains at the door and a huge chunk of this never even gets the chance to fire.
Then the browser. If you’re still on something leaky, stop. Move to Brave or a hardened Firefox build and run uBlock Origin on top of it — not the lightweight version, the real one, with the harder filter lists turned on.
Phone’s next, and this is the one people skip. Go through your app permissions and ruthlessly revoke background location access from anything that doesn’t need it to function — your weather app does not need to know where you are at 3am. Reset your mobile ad ID, the AAID or IDFA depending on your platform, on a regular cadence, because that ID is the thread that ties all these broadcasts back into one profile over time.
And last — just delete the apps that bundle aggressive third-party analytics and ad SDKs. If an app’s business model depends on knowing more about you than it needs to function, it doesn’t get a spot on your phone. That’s not paranoia. That’s just not feeding the auction.