We Traced What Happens When You Open 11 Tech News Sites

WIRED sent audience-segment events to Pinterest. Four publishers sent Meta page views. RuntimeWire's homepage scan reached two outside domains.

By · Published

RUNTIMEWIRE INVESTIGATION — Original analysis

Original reporting by RuntimeWire, based on testing, data analysis.

Why it matters

The ad stack is a commercial tradeoff: publishers gain targeting and measurement infrastructure, while readers face opaque data flows and publishers carry the resulting trust risk. Domain counts alone cannot reveal that exposure, and automated summaries can miss events in request bodies, making raw-log audits and meaningful consent controls more important than a simple tracker tally. The logs show data transmission, not successful identity matching, so they establish a privacy concern without proving how platforms used each visit.

Reporting record

Finding

The audit found that WIRED’s supplied local capture recorded 90 Pinterest audience-segment events and transmitted fields labeled “email_sha256” and “fingerprint,” while RuntimeWire’s 6.6-second homepage capture reached two outside domains and showed no recognized ad trackers or tested social-pixel endpoints.

How we verified

Methods: testing, data analysis.

WIRED’s local browser network log recorded 90 Pinterest requests, 35 distinct segment IDs, and identify-request payloads with nonempty email_sha256 and fingerprint fields; RuntimeWire’s homepage capture recorded two outside domains and requests to its own page-view API.

The article reports scans of ten major English-language technology publishers plus RuntimeWire. Nine publisher automated scans completed; after WIRED’s automated scan failed twice, the audit analyzed a locally captured browser network log spanning three homepage loads. It inspected request URLs and bodies for events and identifiers, counted outside domains using the Public Suffix List, and compared a consistent first-five-seconds window. RuntimeWire’s homepage capture lasted 6.6 seconds. The article discloses that RuntimeWire’s owner supplied the WIRED capture and that the same domain-counting and request-inspection rules were applied to RuntimeWire.

Evidence

Company response

The company was not contacted before publication.

Illustration of a technology news homepage connected to a web of advertising and measurement services.

What we found

Opening a technology news homepage can connect your browser to an extensive advertising operation. Our audit found calls to ad platforms, identity services and social tracking endpoints alongside the code needed to display the news.

We examined 10 major English-language tech publishers, then included RuntimeWire. Nine publisher automated scans completed. After WIRED's automated scan failed twice, we analyzed a locally captured browser network log of its homepage.

The main findings:

  • WIRED's local capture recorded 90 Pinterest audience-segment events, covering 35 distinct segment IDs.
  • WIRED also transmitted identification fields labeled 'email_sha256' and 'fingerprint', alongside calls to identifier-syncing endpoints.
  • All ten publisher captures included requests to DoubleClick and PubMatic. WIRED used a different browser and three homepage loads, so we report its totals separately.
  • Meta page-view events appeared on The Verge, Ars Technica, TechCrunch and TechRadar. Ars Technica and TechRadar also sent requests to TikTok's pixel API. Ars Technica and The Verge contacted X advertising-tracking endpoints.
  • The Verge's public scan summary missed Meta events that were visible in the underlying request bodies.
  • RuntimeWire's homepage requested two outside domains: Google sign-in and Google Cloud image storage. We found no recognized advertising trackers or tested social-pixel endpoints in its homepage capture. It also sent page-view requests to its own API.

Disclosure: Ryan Merket owns RuntimeWire and supplied the local WIRED capture. We applied the same domain-counting and request-inspection rules to RuntimeWire. This is a selected sample of major outlets, rather than a verified traffic-ranked top ten.

The homepage comparison

We counted distinct domains outside the publisher's own domain, grouping subdomains with the Public Suffix List. These are outside-domain counts, not tracker counts. They include image delivery, consent tools, publisher-owned infrastructure on other domains, advertising and analytics.

The first-five-seconds column provides a consistent observation window. The longer capture shows what appeared before the scanner navigated to its second page.

Publisher Outside domains in first 5 seconds Outside domains during homepage capture Homepage capture length
Ars Technica 25 52 25.1 sec
CNET 13 38 23.8 sec
Engadget 12 68 32.6 sec
Gizmodo 24 43 20.2 sec
PCMag 30 43 27.2 sec
TechCrunch 23 47 30.1 sec
TechRadar 11 101 52.3 sec
The Verge 16 115 36.2 sec
WIRED Separate local capture See below Three homepage loads
ZDNET 28 39 18.9 sec
RuntimeWire 2 2 6.6 sec

The longer captures are different lengths and should not be treated as a privacy ranking. A domain appearing later has more opportunity to enter a longer capture. The five-second figures count requests initiated during the first five seconds, including redirects, rather than five seconds after a page finishes loading.

Bar chart of outside domains requested in the first five seconds of automated scans: Ars Technica 25, CNET 13, Engadget 12, Gizmodo 24, PCMag 30, TechCrunch 23, TechRadar 11, The Verge 16, ZDNET 28 and RuntimeWire 2. WIRED's separate local capture is excluded.
Outside-domain requests during the same five-second window. The count includes functional services and does not establish how many companies tracked a visitor.

WIRED sent audience-segment events to Pinterest

WIRED's local network log recorded 90 requests to 'ct.pinterest.com/v3/': 87 events named 'PermutiveSegmentEntry' and three named 'PermutiveSegmentExit'. Those requests carried 35 distinct segment IDs. All 90 returned HTTP 200.

The event names and segment fields show audience-segment information being sent to Pinterest. The log does not reveal the categories behind those numbers or establish that Pinterest matched the visitor to an account. Pinterest describes its tag as a tool for tracking website activity, measuring advertising performance and building targeting audiences. Pinterest's documentation

The capture covered three homepage document loads across roughly 65 seconds:

Measurement WIRED local capture
Homepage document loads 3
Recorded requests, including redirects and repeats 1,060
Distinct hostnames requested 153
Outside domains requested, grouping subdomains 92
Outside domains with an HTTP response 91
Pinterest audience-segment events 90

These are totals across three loads. They include images, ad creatives and other functional requests. They cannot be compared directly with another publisher's single automated visit or divided by three to produce a reliable per-load count. One outside domain, 'addthis.com', had a request with no HTTP response recorded.

Identification fields included an email-hash label

The browser made four POST requests to 'permutive.wired.com/v2.0/identify'. Their payloads included aliases labeled 'appnexus', 'ip_address', 'email_sha256', 'fingerprint' and other identifiers.

Two payloads contained nonempty 'email_sha256' values comprising 64 hexadecimal characters, consistent with SHA-256 hashes. Two also contained nonempty 'fingerprint' fields. All identifier values are withheld.

The log establishes that these labeled fields were transmitted. It does not establish the original email address, how the values were obtained, or whether the field labeled 'fingerprint' came from browser fingerprinting. Prior login, site-storage and consent state were not established, so we do not describe this as a verified first-time anonymous visit.

Permutive describes its platform as using publisher data to build audience segments and support advertising. Permutive's product overview

Advertising-related measurement can also use a publisher's own domain. Requests to 'permutive.wired.com' remain inside WIRED's domain and do not increase our outside-domain count.

Identifier-syncing endpoints also appeared

Destination Requests Evidence in the request
LiveRamp: 'idsync.rlcdn.com' 3 GIF pixel paths with nonempty 'partner_uid' parameters
Tapad: 'pixel.tapad.com/idsync/ex/receive' 3 Nonempty 'partner_device_id' parameters
'match.adsrvr.org' 7 '/track/usersync' and '/track/cmf/' paths
LinkedIn: 'px.ads.linkedin.com/setuid' 1 'partner', 'dbredirect' and nonempty 'ruxId' parameters
Google: 'cm.g.doubleclick.net' 13 Partner-pixel and pixel paths, including 'google_hm' parameters

LiveRamp documents the GIF-and-'partner_uid' pattern as cookie synchronization used to match identifiers across partners. LiveRamp's implementation guide

An HTTP response establishes that a request reached an endpoint. It does not prove that an identity match succeeded. The capture also reached Amazon's ad system, PubMatic, OpenX, Criteo, Rubicon Project, Media.net, DoubleVerify and 'adsafeprotected.com' measurement endpoints. Ad creatives and embedded scripts can trigger more requests, so this list does not establish that WIRED directly integrated every downstream service.

Redacted WIRED network evidence showing Pinterest audience-segment events and identification fields labeled email_sha256 and fingerprint.
Caption: WIRED's local capture recorded 90 Pinterest segment events and identify payloads with email-hash and fingerprint labels. Identifier values are withheld.

--

WIRED's homepage showing a large De Beers advertising placement above its news.
A De Beers advertisement occupied the top of WIRED's homepage in the supplied September 29th screenshot. The network log separately recorded ad and measurement requests; the screenshot cannot establish which services belonged to that ad.

Which homepages sent social tracking events?

A script reference tells us that a site includes an integration. A request carrying a page-view event gives us stronger evidence that it transmitted that event during the visit.

We checked URL parameters and POST bodies, rather than relying exclusively on the scanner's summary.

Publisher Meta page view TikTok pixel API X ad-tracking endpoint Pinterest segment event
Ars Technica Observed Observed Observed Not observed
CNET Not observed Not observed Not observed Not observed
Engadget Not observed Not observed Not observed Not observed
Gizmodo Not observed Not observed Not observed Not observed
PCMag Not observed Not observed Not observed Not observed
TechCrunch Observed Not observed Not observed Not observed
TechRadar Observed Observed Not observed Not observed
The Verge Observed Not observed Observed Not observed
WIRED, local capture Not observed Not observed Not observed Observed
ZDNET Not observed Not observed Not observed Not observed
RuntimeWire Not observed Not observed Not observed Not observed

“Not observed” describes this homepage visit. Other pages, later requests, signed-in visits or different consent choices may produce different results. These checks also do not establish whether a platform successfully matched the visit to a person's account.

The Verge's Meta events were missing from the scan summary

Blacklight's public result for The Verge said it had not found a Facebook Pixel. Its downloadable network log contained POST requests to 'www.facebook.com/tr/' with 'PageView' events and The Verge's homepage URL in the request body.

The same capture included events named 'PermutiveSegmentEntry_14373' and 'PermutiveSegmentEntry_242209' sent to that endpoint. Those names show audience-segment events being transmitted; they do not tell us what the segment numbers mean.

This discrepancy is why we reviewed the raw logs. A scanner's “not found” label can miss a request format that its detection logic does not recognize.

Evidence comparison showing Blacklight's negative Facebook Pixel result alongside a Meta POST request containing a PageView event for The Verge's homepage.
The public summary reported no Facebook Pixel, while the underlying homepage log recorded Meta events in POST bodies. Source: The Verge's September 29th Blacklight archive.

The advertising layer goes beyond social pixels

All ten publisher captures reached 'doubleclick.net' and 'pubmatic.com'. Other observed destinations included 'amazon-adsystem.com', 'openx.net', 'rubiconproject.com' and 'criteo.com', with different combinations across publishers.

These requests serve different purposes. Google's Publisher Tag documentation describes a library that builds ad requests and displays ads. DoubleVerify, whose domains also appeared in several captures, provides measurement for viewability, fraud and other advertising-quality checks.

Calling every outside service a data broker would obscure those differences. The logs show a layered advertising supply chain, and the presence of a domain alone does not establish every use made of the resulting data.

These selected destinations show how the mix differed. DoubleClick and PubMatic are omitted from this table because both appeared in all ten publisher captures.

Publisher Other ad-system domains observed, selected examples ID5 / LiveRamp domains observed
Ars Technica 'amazon-adsystem.com', 'openx.net', 'rubiconproject.com', 'criteo.com' LiveRamp
CNET 'amazon-adsystem.com', 'openx.net', 'rubiconproject.com', 'criteo.com' Neither observed
Engadget 'openx.net', 'rubiconproject.com', 'criteo.com' ID5 and LiveRamp
Gizmodo 'openx.net', 'rubiconproject.com' ID5
PCMag 'amazon-adsystem.com', 'rubiconproject.com', 'criteo.com' Neither observed
TechCrunch 'amazon-adsystem.com' LiveRamp
TechRadar 'amazon-adsystem.com', 'openx.net', 'rubiconproject.com', 'criteo.com' ID5 and LiveRamp
The Verge 'amazon-adsystem.com', 'openx.net', 'rubiconproject.com', 'criteo.com' ID5 and LiveRamp
WIRED, local capture Amazon, OpenX, Rubicon Project, Criteo LiveRamp; ID5 not observed
ZDNET 'amazon-adsystem.com', 'openx.net', 'rubiconproject.com', 'criteo.com' Neither observed
RuntimeWire None of these observed Neither observed

Audience-measurement destinations appeared as well: all nine completed publisher homepage captures included 'scorecardresearch.com'. Examples elsewhere in the logs included 'parsely.com' on CNET, TechCrunch, The Verge and ZDNET, and 'chartbeat.com' on PCMag.

Identity-matching endpoints also appeared

TechRadar's homepage capture included requests to ID5 endpoints, including '/api/config/prebid' and '/i/455/8.gif', and to LiveRamp's 'idsync.rlcdn.com'. The Verge and Engadget also requested ID5 and LiveRamp domains. Ars Technica and TechCrunch requested LiveRamp domains.

ID5 documents cookie synchronization as a way to improve recognition across advertising platforms. LiveRamp's implementation guide describes a cookie-sync tag using 'idsync.rlcdn.com'.

The captures establish requests to those services. They do not establish that every identity lookup succeeded: some LiveRamp identity-envelope calls in the logs returned HTTP 401.

Ars Technica loaded Hotjar scripts

Ars Technica's homepage loaded scripts from 'static.hotjar.com' and 'script.hotjar.com'. Blacklight identifies Hotjar as a session-recording provider; Hotjar's documentation describes recordings used to examine visitor interactions.

Loading those scripts establishes the integration. It does not establish that every visitor's session is recorded, or that this particular simulated session produced a recording an operator could watch.

RuntimeWire: a smaller third-party footprint, with first-party measurement

RuntimeWire's homepage capture contained requests to 'accounts.google.com' for Google sign-in and to 'storage.googleapis.com' for images. Google documents the sign-in library as part of Google Identity Services.

We did not observe DoubleClick, PubMatic, ID5, LiveRamp, Hotjar or the tested Meta, TikTok, X and Pinterest tracking endpoints on its homepage. Blacklight's broader two-page inspection also reported zero recognized ad trackers and zero third-party cookies.

RuntimeWire still measures visits. The homepage sent requests to its own '/api/public/pageview-token' and '/api/public/pageview' endpoints. The broader inspection recorded first-party cookies, including 'GAESA', 'g_state' and a RuntimeWire Google One Tap cookie. This audit cannot establish all server-side uses of first-party data.

Google Reader Revenue Manager's 'swg-basic.js' appeared on the second RuntimeWire page visited by the scanner. We excluded that request from the homepage totals.

How we checked

On September 29th, we ran Blacklight inspections using its California location and mobile setting. The downloaded configurations identify headless Chromium with iPhone 13 Mini emulation and ad blocking disabled. This emulates a mobile device in Chromium; it is not a test of Safari's tracking protections.

Blacklight visits a homepage and a second page. We downloaded its evidence archives and cut each request log at the start of the second-page navigation. We then counted outside domains, compared the first five seconds and inspected social-pixel requests. We checked Meta POST bodies as well as URL parameters. We separately fetched homepage HTML to corroborate declared integrations.

WIRED was a separate local capture. Its HAR covers approximately 5:20:48 p.m. through 5:21:53 p.m. Central Time and records three homepage document loads. The collector reported Austin, Texas, no VPN and Brave Shields down. The browser-brand header identifies Brave; the user-agent reports a Pixel 9 running Android 15. The supplied screenshot shows a desktop browser with extensions visible. Prior login, site-storage and consent state were not established.

The sanitized WIRED HAR contains no Cookie or Set-Cookie headers. Their absence cannot establish that the browser had no cookies; sanitized exports can remove those headers. Chrome's DevTools documentation

The automated scans were single snapshots, without a controlled accept-versus-reject consent experiment. Geography, consent, browser protections, advertising demand and repeat visits can change what loads. Domain counts describe request destinations, rather than distinct corporate owners or confirmed privacy violations. We inspected browser-visible traffic; server-to-server sharing is outside this audit.

Source files

The archived captures underpin the homepage counts and event findings. Blacklight's public summaries may combine both pages and can differ from our homepage-only analysis.

Reader comments

Conversation for this story loads after sign-in.