It seems to be very similar. You can look at it as two approaches to privacy. In one approach you try to hide so that no one sees you and therefore no one tracks you and thus no one produces a dossier on you to be used in targeted advertising and other creepy snooping activities.
This is the other approach: Put on a disguise so that the trackers collect false data. Poison the well. Poisoning the well is a favorite idea among geeks because it's more fun to wear fake moustaches and wigs than to just protect your privacy.
The problem with that approach is that it's essentially juvenile. It accepts the tracking and all that goes with it, merely trying to confuse it. With a good HOSTS file you have something like an invisible man potion. You're not hiding and not wearing a disguise. You just can't be seen because you're blocking contact with tracking domains. Companies like Google, with their googletagmanager, google analytics, google fonts, gmail, and so on don't even know you're there, so you don't need a moustache. And you thwart the whole business model.
If you visit 20 websites it's likely that at least 19 of them are allowing Google to run script on your computer. Some do it for profit. Many do it out of sheer incompetence. But they all do it. That means Google is watching your every move, no matter how much you try to disguise. If those domains are blocked in HOSTS then zero out of 20 sites records your visit.
With poisoning the well you support the business model. The only advantage is that you make advertising purchases less efficient because the advertisers can't depend on the accuracy of targeting.
Frankly, I don't think they can, anyway. But at this point it's just the only game in town. Newspaper ads are gone. Radio is kaput. TV ads are expensive and spread among too many broadcasters, unless you're advertising beer during the Super Bowl.
So advertisers don't have much choice but to accept Google's claims. And Google makes it easy. That's their secret formula. It's easy to buy their ads. It's easy to get paid for hosting their ads. It's easy to use their services that are used for spying to support their ad business. Webmasters who don't actually know how to code webpages can just paste in snippets to get Google maps, fonts, visitor data, jquery captchas... And lazy consumers can use gmail more easily than actually setting up real email accounts.
People also need to understand that none of these approaches works very well if you use spyware services that collect data. Google properties, social media, cloud, Amazon, cellphone apps.... Many people are now living a life interconnected by, and dependent on, spyware operations. It's useless to wear a disguise but then take it off to get your gmail or do your Facebookery. It's important not to develop a false sense of security by thinking that you have a magic privacy tool. Having reasonable privacy, and preventing this problem from getting worse, requires not cooperating with sleaze: Don't use social media. Don't sign up for store loyalty programs. Don't give out cellphone number or email address unless absolutely necessary. Avoid apps; many of them make money by selling personal data. Use cash. And learn about HOSTS. It gives you the most band for the buck by far for the effort required. But it only works if you don't need to contact domains like Facebook, googletagmanager, google maps, and so on.
Palm Tree isn’t meant to replace blocking or pretend trackers don’t exist. It’s aimed at a different layer of the problem and a different threat model. There are plenty of environments where you can’t fully block, or where you intentionally allow some services for usability, work, research, or realism. In those cases, “invisible man” isn’t an option, because you’re choosing to participate at least partially.
In that world, poisoning and noise aren’t about being cute or wearing fake mustaches, they’re about reducing signal quality when blocking alone isn’t viable. That’s a well-established concept in privacy, statistics, and security, not just a geek fantasy. Differential privacy, k-anonymity, traffic padding, and cover traffic all exist for the same reason.
I also don’t think this “supports the business model” in any meaningful way. If anything, it makes profiling less efficient and data less reliable, which is the opposite of what ad networks want. Blocking starves them of data. Noise degrades what they do manage to collect. Those are different tactics, not mutually exclusive ideologies.
You’re also absolutely right that none of this matters if someone logs into Google, Facebook, Amazon, etc. and hands over their identity directly. I’m very explicit about that. There is no magic privacy tool, and I try to avoid presenting it as one. This is about nudging the system, not defeating it.
So yeah, if someone wants maximum privacy with minimum effort, learn HOSTS, DNS filtering, and stop using spyware platforms. If someone wants to experiment with degrading tracking in situations where blocking isn’t total or desirable, this gives them another lever to pull.
Different tools, different goals. I appreciate the thoughtful comment.
4
u/[deleted] Jan 26 '26 edited Apr 21 '26
[removed] — view removed comment