The Digital Panopticon: DecryptAds Sheds Light on the Opaque World of Adtech Surveillance

the-digital-panopticon-decryptads-sheds-light-on-the-opaque-world-of-adtech-surveillance

In the modern digital economy, the infrastructure powering the advertisements we see on websites and the tracking scripts embedded within our mobile apps has long been a "black box." While the technical mechanisms—such as ads.txt and app-ads.txt files—are technically public, they remain buried, fragmented, and intentionally difficult for the average user to interpret. Today, that barrier to entry has been dismantled by the launch of DecryptAds, a powerful, free service designed to scrape, correlate, and demystify the complex relationships between publishers, adtech platforms, and data brokers.

By providing a clear lens into the digital supply chain, DecryptAds is transforming how security researchers and privacy advocates view the internet, exposing a vast, often interconnected web of data collection that stretches from reputable media giants to obscure, AI-generated content farms.

The Architecture of Ad Transparency

The primary mission of DecryptAds is to bring clarity to the "adtech supply chain." The service continuously scrapes public-facing files that websites and apps are required to host to declare which entities are authorized to sell their inventory. These include:

  • ads.txt: A standard used by web publishers to list authorized adtech companies and data brokers.
  • app-ads.txt: The equivalent standard for mobile and smart TV applications, governing how data is harvested and ads are served in those environments.
  • buyers.json/sellers.json: Metadata files that disclose the identity of the entities buying, selling, or reselling ad inventory.

Zach Edwards, Chief Research Officer at DecryptAds and a veteran threat researcher at Infoblox, notes that the platform was born out of a fundamental necessity. "It’s an adtech tool, but we’re trying to approach it from a security perspective," Edwards explains. "These files are only truly useful when cross-referenced. In isolation, a single file tells you almost nothing. When you pull the threads across the entire ecosystem, you start to see the supply-chain integrity issues that have been ignored for far too long."

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Chronology of a Digital Supply Chain Crisis

The rise of "adtech opacity" has been a gradual, multi-year process. Historically, the industry operated on a "trust-but-don’t-verify" model. As the internet moved toward programmatic advertising—where ads are auctioned and served in milliseconds—the number of intermediaries grew exponentially.

In recent years, the landscape shifted further toward risk. As legislative pressure mounted—specifically through laws in California, Oregon, Texas, and Vermont requiring data brokers to register—information that was previously shielded began to trickle into public view. DecryptAds capitalizes on this new era of mandatory disclosure, creating a historical record of how ad partnerships shift.

A notable recent development in this timeline is the emergence of "AI-generated slop"—vast networks of low-quality websites created by machine learning models specifically to house ads and harvest user data. Security researchers, including those at Bitsight, recently exposed the "H96" streaming stick scandal, where compromised devices were found to be spoofing mobile browsers to click on ads hosted by these AI-slop farms. DecryptAds provides the forensic tools to trace these activities back to common ownership, proving that these networks are not accidental but orchestrated.

Supporting Data: The Case of ESPN and Beyond

To illustrate the scale of the tracking ecosystem, a search on DecryptAds for a major entity like espn.com is revealing. The service identifies 143 distinct ad partners and 19 registered data brokers within the site’s ads.txt and app-ads.txt files. Perhaps most concerning is that nearly half of these brokers are actively collecting geolocation data from visitors, while others explicitly disclose the collection of "device fingerprints"—a technique used to track users even when cookies are deleted or blocked.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

The data reveals a disturbing trend: high-traffic, trusted domains are often "greased rails" for third-party entities, some of which are based in jurisdictions known for adversarial behavior.

The "Geo-Risk" Factor

DecryptAds features a specialized "Geo-Risk" warning system. When a website or app partners with adtech firms based in nations with significant political or financial ties to Russia or China—such as the UAE or Cyprus—the platform flags the relationship.

For instance, espn.com has been shown to partner with entities like Between Digital. While the firm lists a New York address, DecryptAds’ dossier identifies it as a Russian-based entity, noting that its financial operations are processed through Alfa Bank, Russia’s largest private commercial bank, which was heavily sanctioned by the U.S. in 2022. Between Digital is not an outlier; it operates on an estimated 55,000 websites, including numerous U.S. military-focused news outlets like Army Times and Defense News.

Official Responses and Industry Accountability

When presented with findings regarding their adtech partners, many companies remain silent, while the adtech networks themselves often engage in what Edwards calls "quiet removals."

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

"The way the industry works, if an ad network suspects an advertiser is committing fraud, they simply remove the seller from their sellers.json file," Edwards explains. "They don’t tell anyone. They don’t publish a report. One day the partner is there; the next, they are gone. It makes it nearly impossible for the public to track the history of bad actors."

DecryptAds counters this by maintaining a "Quiet Removals Feed," which tracks these invisible changes across exchanges. By correlating these removals, researchers can finally see which advertisers are being blacklisted for fraud, malware distribution, or policy violations, providing a level of accountability that has never existed in the programmatic advertising space.

Implications for Security and Privacy

The implications of these findings are profound. We are no longer just dealing with "annoying ads"; we are dealing with a supply chain that can be weaponized for "malvertising"—the delivery of malware through legitimate ad networks.

The Zero-Click Threat

Edwards emphasizes that the most sophisticated attacks are no longer happening on major portals like ESPN, but on the "long tail" of the internet—the AI-generated slop sites. These sites, which lack basic security vetting, act as magnets for low-tier, malicious ad partners. "Most malvertising attacks don’t happen on high-traffic sites," Edwards says. "They happen on low-quality content farms that a user might stumble upon via search. These sites are essentially conduits for zero-click payloads."

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

To solve this, Edwards argues for the industry-wide adoption of the Supply Chain Object (SCO). The SCO is a structured data piece that tracks the entire path of an ad impression from the publisher to the final buyer. Without the SCO, security teams cannot identify which entity served the malicious payload. "If we can force the industry to expose the SCO, the era of anonymous malvertising will effectively end," he suggests.

Protecting Yourself: A Practical Guide

Given the current state of the adtech ecosystem, security experts are increasingly advocating for a "block-all" approach to advertising.

  1. Browser-Level Blocking: For desktop users, uBlock Origin Lite remains the gold standard. For mobile, users should be aware that mobile app environments are significantly more restrictive and invasive.
  2. Network-Level Protection: For the best results, hardware-based solutions like a Raspberry Pi running Pi-hole allow users to intercept ad traffic at the DNS level before it even reaches a device. This provides blanket protection for every device on a home network, including smart TVs and IoT devices.
  3. The "Web-First" Strategy: As companies push users toward mobile apps to facilitate deeper tracking and data harvesting for AI training, the most effective defense is to abandon the app. Browsing via a secure, ad-blocked web browser is consistently safer than using a proprietary app that is designed to keep you inside a closed, data-hungry garden.

As DecryptAds continues to gain traction, it serves as a wake-up call. The internet is no longer a neutral space; it is an environment where every click, scroll, and view is a commodity. By arming users with the ability to see the "hidden" participants in their digital life, DecryptAds is providing the first real tools for reclaiming privacy in an era of total surveillance.