Build1 publisher3 min readPublished Updated
Domain counts hide 90 Pinterest segment events in a captured WIRED homepage session
RuntimeWire says a captured WIRED homepage session sent Pinterest 90 audience-segment events plus fields labelled email_sha256 and fingerprint. That traffic sits in request bodies, where a tally of outside domains cannot see it.
The Engineer · Build desk

What happened
- The 90 Pinterest requests in the WIRED log covered 35 distinct audience-segment IDs.
- All ten publisher captures in RuntimeWire's sample included requests to DoubleClick and PubMatic.
- Meta page-view events appeared on The Verge, Ars Technica, TechCrunch and TechRadar, and Ars Technica and TechRadar also sent requests to TikTok's pixel API.
- The Verge's public scan summary missed Meta events that were visible in the underlying request bodies.
- RuntimeWire's own 6.6-second homepage capture reached two outside domains, Google sign-in and Google Cloud image storage, with no recognized ad trackers.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint A domain tally cannot tell a site owner whether partner calls carry a hashed-email field, so it cannot support any statement about what the site actually shares with advertisers.
- exposure Publishers carry the reader-trust risk for payloads their ad partners send from publisher pages, including payloads a scanner's summary never surfaces.
- decision Teams auditing their own sites have to budget for reading raw request bodies under each consent choice, because body inspection is how this audit found the email_sha256 field.
RuntimeWire's tally groups subdomains with the Public Suffix List and counts each domain outside the publisher's own [5]. Under that rule a domain appears once. The count is the same whether it received one request or ninety, and whatever the bodies held [3]. RuntimeWire says plainly that these are outside-domain counts, not tracker counts. They include image delivery, consent tools and publisher-owned infrastructure on other domains, as well as advertising and analytics [5].
The WIRED findings came from a second pass that read request URLs and bodies for events and identifiers [6]. The 90 Pinterest requests span three homepage loads. That is an average of 30 per load and about 2.6 per segment ID [1][2]. The identify requests carried nonempty fields labelled email_sha256 and fingerprint, next to calls to identifier-syncing endpoints [4]. The first label describes a SHA-256 hash of an email address [4]. RuntimeWire does not overstate it: the logs show data being sent, and they do not prove identity matching or how platforms used each visit [14].
The Verge result is the one I would put in front of a team that trusts its scanner's report. The events the summary dropped were in the request bodies all along [9]. The Verge and Ars Technica also contacted X advertising-tracking endpoints [8]. RuntimeWire wrote that automated summaries can miss events in request bodies, "making raw-log audits and meaningful consent controls more important than a simple tracker tally" [16].
For the 90 to mean anything beyond one log, several things would have to hold. Nine of the automated publisher scans completed. WIRED's failed twice, so its figure comes from a locally captured browser log [1][2]. That log used a different browser and three homepage loads, and RuntimeWire reports its totals separately for that reason [7]. Ryan Merket, who owns RuntimeWire, supplied it [11]. The publishers are a selected sample, not a traffic-ranked top ten [12]. The longer captures differ in length and, by RuntimeWire's own account, are not a privacy ranking. Only the first five seconds form a consistent window [13]. RuntimeWire's record says the company was not contacted before publication [15].
RuntimeWire finishing cleanest in RuntimeWire's audit is the least surprising result in it. Its homepage's only first-party traffic of note was page-view requests to its own API [10]. The audit applied the same counting and inspection rules to its own homepage and disclosed who supplied the WIRED log [11]. The method has good habits: a consistent window, a stated definition of what is counted, WIRED kept apart from the other nine, and a stated limit on what the logs prove [13][7][14].
Consent is where the evidence is thinnest. The published method covers URLs, bodies, domain grouping and a five-second window, and the findings do not compare the same page before and after a reader declines [6].
What to watch
- A response from WIRED or Pinterest on what the email_sha256 and fingerprint fields contained and when they are sent.
- A rerun of the WIRED homepage in the same browser and five-second window used for the other nine publishers.
- A capture of the same homepages after a reader declines consent, with request bodies compared against the default.