User Tools

Site Tools


provenance:privacy:requests

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
provenance:privacy:requests [2026/08/12 16:50] – Provenance for privacy:requests: the two-signal population definition and every denominator, the unedited report output, both folds with their full residue, the 138-figure verification against source papers (which caught a fabricated denominator), every e karel.kubicek.claudeprovenance:privacy:requests [2026/08/12 17:25] (current) – Add section 11.5: the re-verification pass against the frozen text, three accepted findings (a fifth Duumviri passage, a Web Almanac chapter that does not exist, the MV3 wording), one rejected (a bibliography diff run against a stale local cache rather th karel.kubicek.claude
Line 16: Line 16:
 | Written | 2026-08-12, against the corpus as extended on 2026-08-11 (commit ''8a6b843'') | | Written | 2026-08-12, against the corpus as extended on 2026-08-11 (commit ''8a6b843'') |
  
-The page **extends** an existing page rather than creating or replacing one. ''privacy:requests'' already existed at 9,970 bytes with three ''<wrap todo>'' boxes (link decorators, cookie-notice classification, "Use in Publications"). All three are now filled. Everything that was already on the page was kept unless it was measurably wrong; the three sentences that were are recorded in §9.+The page **extends** an existing page rather than creating or replacing one. ''privacy:requests'' already existed at 9,970 bytes with three ''%%<wrap todo>%%'' boxes (link decorators, cookie-notice classification, "Use in Publications"). All three are now filled. Everything that was already on the page was kept unless it was measurably wrong; the three sentences that were are recorded in §9.
  
 ===== 2. Populations and denominators ===== ===== 2. Populations and denominators =====
Line 63: Line 63:
 | censorship | 3 | | censorship | 3 |
 | certificate / key revocation | 2 | | certificate / key revocation | 2 |
 +
 +**35 distinct papers**, not 36: a paper can use several kinds of blocklist, so the rows do not sum. The content page quotes the union; the report script prints both.
  
 These belong on [[design:website_classification]] and [[design:ip_classification]], not here. These belong on [[design:website_classification]] and [[design:ip_classification]], not here.
Line 87: Line 89:
  
 # stale-number guard, whole page AND windowed, AND including <file> blocks # stale-number guard, whole page AND windowed, AND including <file> blocks
-cat out/report_requests_list.txt out/requests_external.txt \ +cat out/report_requests_list.txt out/requests_external.txt out/requests_github_1626.txt \ 
-    out/requests_github_1626.txt out/requests_figures.txt > out/requests_all_evidence.txt+    out/requests_figures.txt out/filterlist_run.txt > out/requests_all_evidence.txt
 node scripts/check_page_numbers.mjs pages/privacy_requests.txt out/requests_all_evidence.txt --code node scripts/check_page_numbers.mjs pages/privacy_requests.txt out/requests_all_evidence.txt --code
 node scripts/check_page_numbers.mjs pages/privacy_requests.txt out/requests_all_evidence.txt \ node scripts/check_page_numbers.mjs pages/privacy_requests.txt out/requests_all_evidence.txt \
Line 141: Line 143:
  
 ── Off-topic blocklists caught by the same regex and excluded from S1 ── ── Off-topic blocklists caught by the same regex and excluded from S1 ──
 +  35 DISTINCT papers across these families — a paper can use several, so the rows below do not sum.
 Off-topic family                                       Papers Off-topic family                                       Papers
 -----------------------------------------------------  ------ -----------------------------------------------------  ------
Line 300: Line 303:
 5. GROUND TRUTH FOR A LEARNED REQUEST CLASSIFIER 5. GROUND TRUTH FOR A LEARNED REQUEST CLASSIFIER
 ========================================================================== ==========================================================================
-Denominator: 22 papers with a LEARNED web-request classification tuple (method in {supervised-ml, unsupervised-ml, llm}; usedOrMentioned in {used, produced}).+Denominator: 14 papers with a LEARNED web-request classification tuple (method in {supervised-ml, unsupervised-ml, llm}; usedOrMentioned in {used, produced}).
 NOTE "produced" alone gives only 14 papers, because the extractor scores a paper's own NOTE "produced" alone gives only 14 papers, because the extractor scores a paper's own
 classifier as "used" about as often as "produced" — AdGraph's random forest is tagged classifier as "used" about as often as "produced" — AdGraph's random forest is tagged
 "used". Filtering to "produced" here would drop the field's reference baselines. "used". Filtering to "produced" here would drop the field's reference baselines.
-Ground-truth source       Papers  Share of 22+Ground-truth source       Papers  Share of 14
 ------------------------  ------  ----------- ------------------------  ------  -----------
-a filter list                   31.8+a filter list                   57.1
-manual / human labelling        27.3+manual / human labelling        28.6
-other stated source             27.3% +other stated source             14.3% 
-none stated                     13.6%+none stated                     0.0%
  
 ── Validation of web-request classifications ── ── Validation of web-request classifications ──
 +  of 58 papers with a not-applicable web-request tuple, 45 (77.6%) have that tuple as method=blocklist
 +  of 60 papers with a none-reported tuple, 30 (50.0%) likewise
 classification.validation   Papers  Share of 172  Sentinel? classification.validation   Papers  Share of 172  Sentinel?
 --------------------------  ------  ------------  --------- --------------------------  ------  ------------  ---------
Line 830: Line 835:
  
 ^ Verdict ^ Count ^ ^ Verdict ^ Count ^
-| found verbatim | 136 |+| found verbatim | 141 |
 | found as a listed spelling variant | 2 | | found as a listed spelling variant | 2 |
 | **MISSING** | 0 | | **MISSING** | 0 |
Line 838: Line 843:
 **It caught one real error.** The extraction's prevalence for Rasaii et al. {[rasaii2023_thou]} reads "280 of 45,222 websites (0.6%)". **45,222 does not appear anywhere in the paper**, which says: //"Using this tool we crawled 45k websites and found cookiewalls on 280 of them"// and //"an overall cookiewall rate of 0.6%"//. The page says ~45k. A page that had trusted the tuple would have published a fabricated denominator with three significant figures. **It caught one real error.** The extraction's prevalence for Rasaii et al. {[rasaii2023_thou]} reads "280 of 45,222 websites (0.6%)". **45,222 does not appear anywhere in the paper**, which says: //"Using this tool we crawled 45k websites and found cookiewalls on 280 of them"// and //"an overall cookiewall rate of 0.6%"//. The page says ~45k. A page that had trusted the tuple would have published a fabricated denominator with three significant figures.
  
-It also corrected two presentational things: Bouhoula et al. write ''2353'' with no thousands separator (the page follows the paper), and Snyder et al. is a SIGMETRICS/POMACS paper with **no corpus record at all**, so its figures were verified directly against arXiv:1810.09160 instead (§7).+**And a second, worse one, caught by reading the paper rather than by any script.** The page as first drafted said Duumviri {[shuang2025_duumviri]} "reproduces filter-list labels at 97.44% //while needing no labels at all//" and called it "the way out of the circularity". That is wrong, and it contradicted the page's own opening box, which correctly counted Duumviri among the eight papers that take their labels from a filter list. The paper says: //"Using EasyList and EasyPrivacy as ground truth, we have 12,936 (46.66%) cases of trackers and 14,785 (53.34%) cases of non-trackers"//. What is independent in Duumviri is its **differential features** and its **breakage detector**, whose positive samples are reconstructed from exception rules and user reports — not its labels. Four passages were rewritten, and the page's open-questions section now says plainly that **nothing in this corpus trains a request classifier without a filter list in the loop.** The general lesson: a table cell that flatters a paper is the one to re-read, and an internal contradiction between two sections is the cheapest signal that one of them is wrong. 
 + 
 +Also corrected, presentationally: Bouhoula et al. write ''2353'' with no thousands separator (the page follows the paper), and Snyder et al. is a SIGMETRICS/POMACS paper with **no corpus record at all**, so its figures were verified directly against arXiv:1810.09160 instead (§7).
  
 ===== 7. External sources, and how each was verified ===== ===== 7. External sources, and how each was verified =====
  
-Every non-corpus fact on the page, its primary source, and the date. ''scripts/external_checks_requests.sh'' re-runs all of it''out/requests_external.txt'' and ''out/requests_github_1626.txt'' hold the unedited output.+Every non-corpus fact on the page, its primary source, and the date. ''out/requests_external.txt'' and ''out/requests_github_1626.txt'' hold the unedited output. 
 + 
 +''scripts/external_checks_requests.sh'' re-runs **most** of it — repository status, the EasyList scale figures, every package version, the live filter lists, Peter Lowe's list, hpHosts, the ''declarativeNetRequest'' limits, the Firefox query-stripping collection, Snyder et al.'s abstract, the two Crossref records and the AdGuard post's publication date, and which arXiv versions of the SoK exist. It does **not** cover the IEEE S&P 2026 poster PDF or the arXiv author-count glitch; those were checked by hand and are recorded only here. An earlier version of this sentence claimed the script re-runs everything, which was wrong, and the script's own EasyList-scale block silently printed blank lines when it hit the anonymous GitHub rate limit — both were found by review and fixed: the block now carries the token and prints ''FAILED'' rather than nothing.
  
 ^ Claim on the page ^ Primary source ^ Verified ^ ^ Claim on the page ^ Primary source ^ Verified ^
Line 914: Line 923:
  
 ^ Run ^ Unaccounted ^ What it found ^ ^ Run ^ Unaccounted ^ What it found ^
-| 1 | 45 | The per-paper figures were verified but **not printed** by ''verify_requests_figures.mjs'', so the guard could not see them. Fixed by printing every ''FOUND'' line. Also exposed that the verify script only covered 63 of the page's figures; extended to 138 |+| 1 | 45 | The per-paper figures were verified but **not printed** by ''verify_requests_figures.mjs'', so the guard could not see them. Fixed by printing every ''FOUND'' line. Also exposed that the verify script only covered 63 of the page's figures; extended to 143 |
 | 2 | 10 | Version-string and licence fragments (''0.13'' from ''0.13.2'', ''3.0'' from GPL-3.0), now in a ''NOT_FIGURES'' block with reasons. And two **real errors**: the page still said the verification had covered "63 of 63 figures" after the verifier had been extended well past that, and it described 410.5 days as a **median** when the paper reports it as the **mean** (median 195.5) | | 2 | 10 | Version-string and licence fragments (''0.13'' from ''0.13.2'', ''3.0'' from GPL-3.0), now in a ''NOT_FIGURES'' block with reasons. And two **real errors**: the page still said the verification had covered "63 of 63 figures" after the verifier had been extended well past that, and it described 410.5 days as a **median** when the paper reports it as the **mean** (median 195.5) |
-| 3 | 0 (''--code'': 3) | Inside the embedded ''<file>'' block: the script's docstring quoted EasyList's **total** rule count (77,736) where the page quotes its **network** rule count. Aligned both to 52,556 |+| 3 | 0 (''--code'': 3) | Inside the embedded ''%%<file>%%'' block: the script's docstring quoted EasyList's **total** rule count (77,736) where the page quotes its **network** rule count. Aligned both to 52,556 |
  
 ''check_page_numbers.mjs'' is **not** run against this provenance page: its numbers are meta (section numbers, DOIs, the size of the old page, figures quoted precisely because they were rejected), so the guard's whole premise does not apply. Running it anyway reports 13 unaccounted values, all of that kind. ''check_page_numbers.mjs'' is **not** run against this provenance page: its numbers are meta (section numbers, DOIs, the size of the old page, figures quoted precisely because they were rejected), so the guard's whole premise does not apply. Running it anyway reports 13 unaccounted values, all of that kind.
  
-The embedded ''<file python filterlist_provenance.py>'' block and the ''<code>'' output block were compared line-by-line against ''pages/filterlist_provenance.py'' and a fresh run: **122 of 122 lines identical**, output block identical.+The embedded ''%%<file python filterlist_provenance.py>%%'' block and the ''%%<code>%%'' output block were compared line-by-line against ''pages/filterlist_provenance.py'' and a fresh run: **122 of 122 lines identical**, output block identical.
  
 ===== 11. Review pass, 2026-08-12 ===== ===== 11. Review pass, 2026-08-12 =====
  
-REVIEW_SECTION+Four reviewers, each given the page text, the scripts, their output and these notes, and each told explicitly that the author's context might not be exhaustive. The three focused passes ran in parallel first; the generic pass ran after their findings were applied. Every finding is recorded below with whether it was accepted, because a rejection is the only record of whether a reviewer earned its slot. 
 + 
 +==== 11.1 Figures versus the script (Sonnet) ==== 
 + 
 +^ # ^ Finding ^ Verdict ^ 
 +| 1 | **The page paired 8,163 with the wrong denominator.** Böttger et al. report "Our dataset has a total of 122,548 rules… Only 8,163 (6.6%) distinct rules identify at least one tracking request"; the 143,654 the page used is the //combined// rule set from that paper's separate runtime and memory benchmark. | **Accepted — the most serious finding of the whole review.** Verified against ''paper.cols.txt'' directly. Corrected to 8,163 of 122,548 (6.6%), with a footnote naming the trap. **It also exposes a real limitation of ''verify_requests_figures.mjs'': it checks that a literal appears in the paper, not that a numerator and denominator printed side by side belong to the same experiment.** That limitation is now written into the script's comments. | 
 +| 2 | The embedded report output in §4 was stale: it still showed the ground-truth table computed over 22 corpus-wide papers instead of the 14 in the page population, contradicting both the current script and §9's own account of that fix. | **Accepted.** Re-embedded from a fresh run and checked byte-for-byte. | 
 +| 3 | The EasyList-scale block of ''external_checks_requests.sh'' omitted the ''GH_TOKEN'' header the neighbouring calls carry, so on the anonymous rate limit it printed **blank lines** rather than an error — a failed check that reads like a partial pass. | **Accepted.** The block now carries the token and prints ''FAILED (no Link header — rate-limited or 403, NOT a confirmation)''. | 
 +| 4 | §7 claimed the script "re-runs all of it" while having no code for the two Crossref lookups, the AdGuard post, the S&P poster or the author-count glitch. | **Accepted.** The Crossref and AdGuard checks were added to the script; §7 now says exactly what the script does and does not cover. | 
 +| 5 | §10's "both guard runs report OK" is a point-in-time fact, not a standing one: the frozen EasyPrivacy version stamp in the page's own ''%%<code>%%'' block is not in the archived evidence, because the live list has moved on. | **Accepted in substance.** ''out/filterlist_run.txt'' is now part of the evidence file, which fixes the specific failure; the general point — that a guard whose evidence includes live-fetched values expires — is recorded here. | 
 +| — | Everything else in "Use in Publications" diffed clean against a fresh run (S1 197, S2 164, both 107, POP 254; venue, year, list-family, method, validation, versioning and crawl-configuration tables), ''classify()'' in the published script was tested against the live EasyList with zero misclassifications, and all 14 ground-truth classifications were judged individually. | Noted. | 
 + 
 +==== 11.2 Citations and quotes (Sonnet) ==== 
 + 
 +^ # ^ Finding ^ Verdict ^ 
 +| 1 | **The 97.6% attributed to Bouhoula et al.'s interactive-element classifier is the wrong model's number.** The six-label element classifier trained on the 2353 annotated samples reports "an accuracy of 95.1% and an F1 score of 90.9%"; 97.6% belongs to a different BERT model in the same paper, the sentence-level AA-purpose detector trained on 1,171 sentences ("an accuracy of 97.6% and an F1 score of 95.1%"). The two are near-mirror images, which is how they got swapped. | **Accepted.** Verified against ''paper.cols.txt''. The page now says 95.1% accuracy and F1 90.9%. | 
 +| 2 | The page misdescribed Calzavara et al.'s validation procedure as "removing the identifier and checking whether the tracking behaviour disappeared". | **Accepted, though the reviewer's own correction was also wrong** — it proposed that the validation //is// the taint tracking. Reading §4.2 of the paper: they replace the identifier in client-side storage with a **canary**, revisit the page, and check whether a request matching the same template carries the canary. Confirmed / refuted / unconfirmed follows from that. The page now describes the canary. | 
 +| 3 | The opening box wrongly lists Duumviri among the papers whose labels come from a filter list, contradicting the rest of the page. | **Rejected — the reviewer had it backwards, and it was read from a stale snapshot.** Duumviri does train on filter-list labels: //"Using EasyList and EasyPrivacy as ground truth, we have 12,936 (46.66%) cases of trackers and 14,785 (53.34%) cases of non-trackers"//. The contradiction was real and had already been resolved in the other direction before this review landed — see §6. The box was right; four other passages were wrong and were rewritten. | 
 +| 4 | The Vekaria footnote's explanation of the "36 other authors" glitch was invented. | **Partly accepted.** The mechanism was measured, not invented — splitting the listing page's author block on commas yields 37 fields because the affiliation list runs into it. But the footnote asserted more than it needed to, so it now simply reports what the listing page shows and what the paper says. | 
 +| 5 | The reviewed files changed three times during the review, so the review is only valid against a snapshot. | **Accepted as a process finding.** Corrections were being applied while the reviewers ran, which is why two of them reported already-fixed items. The right order is freeze, review, apply — not review-while-editing. | 
 +| — | All ''%%{[key]}%%'' citations resolve, no key collisions, no duplicate papers under different keys, and all 20 new BibTeX entries were checked against Crossref, DBLP or the venue landing page — authors, order, titles, venues, years, volumes, issues and pages all matched. | Noted; this is the pass that most needed doing and it came back clean. | 
 + 
 +==== 11.3 External currency (Sonnet) ==== 
 + 
 +^ # ^ Finding ^ Verdict ^ 
 +| 1 | **"Firefox query stripping: no downloadable file" is falsifiable with one ''curl''.** The Remote Settings collection is a public REST endpoint. | **Accepted.** Verified: ''firefox.settings.services.mozilla.com/v1/buckets/main/collections/query-stripping/records'' returns 3 records, 23 stripped parameters and 1 allow-listed host, no auth. The table row now gives the URL and the size, and the check is in the script. | 
 +| 2 | The Khaleesi deep link anchors ''#L52'', which is the ''console.log''; the statement to remove is ''return { cancel: true }'' on line 53. | **Accepted.** Verified against the raw file. The link now points at lines 51–54 and the page says which line is which. | 
 +| 3 | The AdGuard blog post's own ''datePublished'' is 2025-11-18, not October 2025; October is when the talk was given. | **Accepted.** Footnote corrected, and the date check is now in the script. | 
 +| 4 | Firefox and Safari have their own ''declarativeNetRequest''-equivalent caps that the Chrome-only table does not mention. | **Accepted for Firefox, rejected for Safari.** MDN confirms Firefox exposes the same constants with independently-versioned values, and the page now says so and tells the reader to read the constants at runtime. The Safari figure of 150,000 rules was sourced from developer-forum threads; Apple's own content-blocker documentation did not yield it, so **no Safari number is on the page** and the footnote says why. | 
 +| 5 | Rule counts drifted a few units between the page's measurement and the review. | **No change needed**, and the page's own caveat says so. The drift is now itself a page figure: EasyList went 52,556 → 52,557 → 52,560 in half an hour. | 
 +| — | ~42 URLs all resolve; 24 repositories match the page's archived/pushed/open-issues claims exactly; the singular ''tracker-blocklist'' 404 and the two WhoTracks.me redirects are confirmed; Disconnect's LICENSE text confirms CC BY-NC-SA 4.0; every package version matches; **and the "no maintained Python engine" claim survived a deliberate falsification attempt** — the only other candidate, ''python-abp'', is staler still (PyPI 0.2.0, 2020-05-20). | Noted. The falsification attempt is the most valuable thing in this pass. | 
 + 
 +==== 11.4 Generic pass (Fable) ==== 
 + 
 +No checklist; asked only for what the other three were not looking for. It produced the largest number of accepted findings of any pass. 
 + 
 +^ # ^ Finding ^ Verdict ^ 
 +| 1 | §11.4 of this page was still the literal placeholder ''GENERIC_REVIEW'' while §11's preamble claimed in the past tense that the generic pass had run. "The provenance page claims a completed fourth review it does not contain." | **Accepted, and it is the finding this genre exists to catch.** This section is that fix. | 
 +| 2 | **The page recommends post-hoc filter-list matching twice and never says what the crawl must record for the match to be correct.** ''$third-party'', ''$domain='', resource-type options and ''@@'' exceptions all need context; a student who logs only URLs mis-evaluates a large share of rules with no error. | **Accepted — the most useful substantive addition of the whole review.** Verified against ''brave/adblock-rust'''s own ''Request::new(url, source_url, request_type, method)''. A new box lists what to record per request and says exception rules must be evaluated (758 in EasyList, 836 in EasyPrivacy). | 
 +| 3 | The venue table's submission advice is a scope confound: share-of-venue measures what a venue is //about//, not acceptance odds. | **Accepted.** The submission use is gone; the reading-list framing stays, with the confound stated. | 
 +| 4 | The 16%–19% figure is stated as settled in the opening box while being called the page's thinnest evidence 550 lines later. "The box is the part everyone will quote." | **Accepted.** The box now carries its own error bars in the same paragraph. | 
 +| 5 | AdVersa is called "the current successor" on the strength of its abstract and a Crossref record, and nobody here has read it. "The strongest endorsement on the page resting on the weakest examination." | **Accepted.** "Likeliest successor", and the page now says the figures are the paper's own and unexamined here. | 
 +| 6 | The ''ML Classification'' intro is inherited text that contradicts the page's own evidence: an unsourced "up to a billion users", "robust ML pipelines" on a page that reports AdGraph evaded 96.62% of the time, and "worth considering" filler. | **Accepted.** Rewritten; the billion is gone rather than sourced, and the paragraph now hands off to the "baselines, not tools" box. | 
 +| 7 | The Selenium ''find_element(By.CSS_SELECTOR, …)'' sentence is naive: modern cosmetic filters are a superset of CSS (procedural filters, ''##^'' HTML filtering) and finding an element is not applying a filter. | **Accepted and cut.** Replaced with the accurate advice — resolve selectors through an engine's cosmetic API first. | 
 +| 8 | The two corpus-narrowing tables appear verbatim on both pages and answer no question a fresh reader has; the content page was the longest of the three neighbours. | **Accepted.** Compressed to two sentences on the content page; the tables live here only. | 
 +| 9 | CNAME cloaking is named twice as a defeat and never as something the reader can handle — no mention that it needs DNS resolution recorded at crawl time, and no mention that a dedicated list exists. | **Accepted.** A row was added for AdGuard's CNAME disguised-trackers list (verified: 175,827 lines, ''TimeUpdated: 2026-08-03'') with the crawl-side requirement stated. | 
 +| 10 | Party determination stops at the public suffix list; entity mapping — the thing that makes ''googleapis.com'' and ''doubleclick.net'' one organisation — is absent even though both entity datasets are already cited elsewhere on the page. | **Accepted.** A new //entity/company// row in the unit table, and "What to Report" now asks which of the two you used. | 
 +| 11 | HTTP Archive is missing as an existing dataset, on a page whose own criterion is "which datasets already exist so they do not rebuild one". | **Accepted.** A box before the crawl advice, with its limits stated (landing page, no interaction, no consent state). | 
 +| 12 | A list of small wording problems: "nearly two" for 1.58×; "barely overlap" for 42%; "this page's population" used 390 lines before it is defined; five ''declarativeNetRequest'' constants reproduced where two bite; the Tang et al. row is a compliance result with half its columns empty; BannerClick and Priv-Accept unreachable from this page; and the three legacy H3 sections outweigh the systems the page calls current. | **Accepted except the last.** All fixed, the constants trimmed to the two that bite. The three H3 sections were **kept**: they are inherited content with a figure, and cutting them would lose material the site already had — instead the section intro now says explicitly to read them as historical baselines and points at the current systems. A reasonable person would trim them. | 
 + 
 +**What the generic pass changed about how the rest of the review should be read.** Its finding 5 — that the review order was freeze, review, apply and we ran review-while-applying — is the process lesson of this run, and it is why two of the three focused reviewers reported items that had already been fixed. It also means this page's own §11.1–§11.3 verdicts are recorded against a page that kept moving while they were written. 
 + 
 +===== 11.5 Re-verification pass after the fixes (Sonnet, against the frozen text) ===== 
 + 
 +^ # ^ Finding ^ Verdict ^ 
 +| 1 | "**The bibliography for this page is broken** — 20 citation keys used on the page do not exist in ''pages/literature_bibliography.txt''", including three of the five papers it had just re-verified. | **Rejected.** The reviewer diffed against a **stale local cache** of the bibliography (last written 10:01; the 20 entries were appended to the live wiki at 16:46). The live file has 160 entries, every one of the 20 keys resolves, and the rendered page shows 172 ''bibtex_citekey'' markers with zero ''bibtex_error''. The stale local copy has now been refreshed so the next run cannot repeat this. **A reminder that "the file on disk" and "the page on the wiki" are different objects, for reviewers as much as for authors.** | 
 +| 2 | **A fifth Duumviri passage survived the correction**: the reading-order sentence still said "labels without a list". | **Accepted.** Four passages were fixed; this was the one in [[privacy:requests#What to Read First]], which no grep for the claim's //numbers// would have found because it makes the claim in words only. Reworded. | 
 +| 3 | **The HTTP Archive box cited a Web Almanac chapter that does not exist** and attributed a method to the wrong one: there is no "advertising" chapter, and //Third Parties// categorises with Patrick Hulce's ''third-party-web'' dataset, not with filter lists or WhoTracks.me. The chapter that uses WhoTracks.me is //Privacy//. | **Accepted.** The box now names the Privacy chapter and warns which chapter answers which question. This claim entered via the generic pass's accepted finding 11 and **nobody read the cited chapter's methodology before publishing it** — an accepted review finding is not a verified one. | 
 +| 4 | The MV3 sentence flattened the paper's significant //increase// in anti-tracking effectiveness into "no reduction". | **Accepted.** Now states both, with the ~1.8 additional trackers per site. | 
 +| 5 | The canary description omits the third outcome ("unconfirmed") and does not say the technique was applied to the 33,584 syntactic matches rather than to every request. | **Noted, not changed.** Neither omission makes the box false and the box is already the longest paragraph on the page; the full algorithm is in §4.2 of the paper, which the page tells the reader to read. A reasonable person would add the third outcome. | 
 +| — | Part 1 confirmed four of the five earlier fixes correct against the source papers (Böttger 8,163/122,548, Bouhoula 95.1%/90.9%, the canary, Rasaii ~45k). Part 2 reproduced every script figure. **Part 3 re-checked numerator/denominator provenance across nine further "X of Y" figures** — WebGraph's two adversarial rates, WTAGRAPH's transductive vs inductive accuracies, AutoFR's 86-vs-87, CV-Inspector's "over a third", and all six of Lin et al.'s churn figures — and found every pairing correct. | Noted. The Part-3 sweep is the check the Böttger error should have had, and the page now has it. |
  
 ===== 12. Run log ===== ===== 12. Run log =====
Line 931: Line 1000:
 | Date | 2026-08-12 | | Date | 2026-08-12 |
 | Corpus at the time | 5,859 extracted papers, 7 venues (CCS, IMC, NDSS, PETS, USENIX Security, TheWebConf, IEEE S&P), 2010–2026; ''data/extract/run1'' | | Corpus at the time | 5,859 extracted papers, 7 venues (CCS, IMC, NDSS, PETS, USENIX Security, TheWebConf, IEEE S&P), 2010–2026; ''data/extract/run1'' |
-| Page before | ''privacy:requests'', 9,970 bytes, 3 ''<wrap todo>'' boxes |+| Page before | ''privacy:requests'', 9,970 bytes, 3 ''%%<wrap todo>%%'' boxes |
 | Scripts written | ''req_fold.mjs'', ''report_requests.mjs'', ''verify_requests_figures.mjs'', ''external_checks_requests.sh'', ''pages/filterlist_provenance.py'' | | Scripts written | ''req_fold.mjs'', ''report_requests.mjs'', ''verify_requests_figures.mjs'', ''external_checks_requests.sh'', ''pages/filterlist_provenance.py'' |
 | Bibliography entries added | 20, all keys checked against the live bibliography for collisions before appending | | Bibliography entries added | 20, all keys checked against the live bibliography for collisions before appending |
-| Models | Opus 5 for the page, the folds and the report scripts; two Sonnet research passes (external tooling currency; the Vekaria SoK and the post-2024 gap); the review layer as recorded in §11 |+| Models | Opus 5 for the page, the folds and the report scripts; two Sonnet research passes (external tooling currency; the Vekaria SoK and the post-2024 gap); three Sonnet review passes and one Fable generic pass, all recorded in §11 |
 | Sub-agent output that had to be corrected | The tooling pass reported ''Consent-O-Matic'''s last commit as 2025-11-07 where the API's ''pushed_at'' is 2026-02-07, and ''abp-blocklist-parser'''s as 2020-01-23 where ''pushed_at'' is 2020-11-02. Both were re-measured directly and the API values used. The SoK pass flagged that its own ''WebFetch'' summariser had fabricated a detail on one call, and re-did the work against raw text — that disclosure is why its other findings were trusted enough to check rather than discard | | Sub-agent output that had to be corrected | The tooling pass reported ''Consent-O-Matic'''s last commit as 2025-11-07 where the API's ''pushed_at'' is 2026-02-07, and ''abp-blocklist-parser'''s as 2020-01-23 where ''pushed_at'' is 2020-11-02. Both were re-measured directly and the API values used. The SoK pass flagged that its own ''WebFetch'' summariser had fabricated a detail on one call, and re-did the work against raw text — that disclosure is why its other findings were trusted enough to check rather than discard |
 +| Process mistake worth repeating out loud | Corrections were applied while the three focused reviewers were still running, so two of them reported findings that had already been fixed and one of those (Duumviri) reported the fix as the error. **Freeze the page, review, then apply.** The generic pass caught this and it is finding 5 of §11.2 and the closing note of §11.4 |
 | Accidental exposure | None. All credentials stayed in ''.env''; no authenticated request was made to any third party. The GitHub API was used unauthenticated and its 60-per-hour limit was exhausted mid-run, which is why ''out/requests_github_1626.txt'' exists as a separate record of the successful window — the later ''external_checks_requests.sh'' run shows ''ERROR API rate limit exceeded'' for those rows and **must not be read as confirming them** | | Accidental exposure | None. All credentials stayed in ''.env''; no authenticated request was made to any third party. The GitHub API was used unauthenticated and its 60-per-hour limit was exhausted mid-run, which is why ''out/requests_github_1626.txt'' exists as a separate record of the successful window — the later ''external_checks_requests.sh'' run shows ''ERROR API rate limit exceeded'' for those rows and **must not be read as confirming them** |
  
provenance/privacy/requests.1786553452.txt.gz · Last modified: by karel.kubicek.claude

Except where otherwise noted, content on this wiki is licensed under the following license: CC BY-NC-SA 4.0
CC BY-NC-SA 4.0 Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki