Coalition Announces New ‘Do Not Track’ Standard for Web Browsing (2015)
eff.org
eff.org
Without any user input, one must believe consent is imputed upon all users absent a statement to the contrary to justify a 'please track me' default.
It was the refusal of ad networks to justify why people should consent to their surveillance which torpedoed the initiative. They could have. They didn't. If they believed users wouldn't like their argument, all they had to do was sweeten the pot until people jumped on board.
It remains to be seen whether or not avoiding the discussion was ultimately in their best interest - the political power-play has already started to bear poisonous fruit for the industry.
On a long enough time scale, promises from online advertisers are always lies. Remember when Google said they weren't going to tie anonymous browsing activity to your real identity, and then did? Remember when Facebook totally promised that they wouldn't tie WhatsApp data to Facebook data, and then did? "We'll totally obey DNT, honest" was an equally worthless promise.
And it was a promise made in bad faith too. The only reason DNT gained traction was as an attempt to "self-regulate" and avoid the (desperately needed) government regulation of the advertising industry - and there is quite a bit of history showing that self regulation is no regulation.
DNT was only ever going to last until turning it on became widespread. Don't blame Microsoft for being the kid who pointed out that the emperor had no clothes.
I think this just highlights the cynism of the ad industry and the whole compromise that was DNT.
If they were genuinely concerned about user preferences, opt-in vs opt-out shouldn't make a difference. But opt-out being so important is a hint to me that the ad industry was mostly agreeing because they assumed that most users wouldn't activate DNT because they didn't even know about it. (Which was probably correct)
In this situation you should either go with opt in or perhaps try to proxy for user desire. Every single person I talked with who wasn’t in the add industry prefers do not track.
It seems strange to argue that a standard that protects users should require informed consent to turn on do not track. But use the same logic to say it’s ok to track users without their explicit consent.
Do people really hate irrelevant ads?
I'd much rather avoid being in an abusive relationship to begin with: Hence, installing browsers like Brave and using search engines like DuckDuckGo -- where you can opt into breaches of privacy and advertising, rather than hoping for the slim chance of an opt-out at the benevolence of the site/ad company.
Consider that without any sort of tracking, ads are almost necessarily ones that appeal to the lowest common denominator of the audience, because there's nothing else to go on.
doubt it.
There’s this funny PR line like I like relevant ads. I don’t like ads. I don’t like the same add 10 times in one hour.
Also it’s possible to hate all three at the same time.
If Microsoft does something in the interest of their users it is suddenly "for marketing purposes"?
> While I applaud the goal of assuming people don't want tracking
Of course people don't want tracking. I'm not going to argue everyone agrees with GDPR, but that sets the trend further.
> Because many users showing DNT settings had not explicitly meant to do so.
Just because someone doesn't explicitly agree with something, doesn't mean they disagree with that.
Unilaterally choosing for them (either pro or con) by any large company is almost always worse.
Not everyone is informed well enough to make an informed choice, and tracking is not in the interest of the user anyway, so the default being blocking (DNT) is sane. Obviously it isn't in the interest of Google, and Chrome serves Google first, and its users secondary. Education is the long term solution to just about anything and I'm all for that (I can recommend a visit to Berlin-Hohenschoenhausen Memorial [1]) but the truth is that some people are just not going to be interested in certain topics.
Case in point: back in the days, everyone received snail mail spam. At some point, civilians were able to put a standardized sticker on their postbox saying yes/no or no/no (one being more strict than the other). They'd need to pick such sticker up at the city council.
Just now in start of 2018, if you live in Amsterdam, you need a yes/yes sticker to receive spam. Is that wrong as well? Even though the spam is bad for the environment (goes to bin right away), we're living in a digital age, and postboxes in flats and such pile up gigantically? Should we've educated people better instead of making this the default?
[1] https://en.wikipedia.org/wiki/Berlin-Hohensch%C3%B6nhausen_M...
Sane defaults should be used because they enhance the user experience tremendously. Nobody buys a gadget for its setup, they buy it to use it, and delaying the user from that end goal is not going to do anything but annoy the end user and ultimately harm the manufacturer's bottom lines.
Even if we limit our self to just security defaults, what linux system don't have default ulimits? There is tradeoffs naturally in every number, but I would assume even linux from scratch users don't need to explicitly set each and every number. If a user prefer making different tradeoffs they can opt-in to make changes, but even a operative system that is designed to be built by hand by the user carries with it some defaults.
So I don't disagree that the decision might have come from a good place, but the end-result was not hard to predict and was ultimately not in the interest of users. It was incredibly dumb.
The end result of DNT was never going to be "advertisers were going to less ruthlessly track you" - that's a fantasy.
If Microsoft had not made this choice then the advertisers could still have made the same decision. We will never know, and it doesn't really matter. Its a "what if" situation, and like many such "what if"s we are simply speculating about motives while not looking at the billions of dollar worth of obvious reasons why the advertisers wanted to ignore DNT.
The correct approach is to aggressively fight back with technology to prevent tracking.
Fuck advertisers! I want users to have to make an explicit choice to opt in to tracking instead of being opted in by default.
I would agree that Microsoft is much better at respecting privacy than Google, though this change was poorly considered and led to a bad result (i.e. DNT failing as a marker of explicit user intent).
I probably have a much more favorable view of Microsoft than the average here, and my comment history contains a storied history of me pointing out how Google has cast anticompetitive and profit-motivated decisions as "good for users". ;)
Yes, it's for marketing purposes, because if there were any sincerity about it then they would not also be tacking their users at the same time they enabled DNT. They don't like competition.
If Microsoft gave a shit about its users it wouldn't put key loggers in its products, explicitly state that spell check in your word documents is being done in the "cloud" and we are reading it, let you disable stupid cortona who is slurping up hell knows what, etc.
They are so obsessed with tracking you that if you surf their sites long enough you end up with a HTTP 400 - Bad Request (Request header too long) error message. I just pulled up MSDN look at the scroll bar on the right https://i.imgur.com/wlYqVIo.png.
No they don't care about users.
While I like that you're mentioning examples and welcome such, it is never this black-and-white.
All these big corps do things which aren't in the best interest of the general public, or in the best interest of their users. Microsoft is no exception to that (I am well aware of the Halloween documents and hated that company to no ends), but 1) neither are Google and Facebook 2) they've broadened from a proprietary software company.
The open source community seemed to be pretty happy with pro-FOSS companies such as Google and Facebook getting more popular and powerful. Free as in beer seems like a great deal, but you're always paying somehow. In this case you pay with your privacy.
Companies like Google and Facebook do a lot of Good Things (tm) for the FOSS community, but in this specific case they're on the bad side of the moral compass because it hurts a major source of their income.
https://www.cnet.com/news/apache-web-software-overrides-ie10...
Don't you dare give the ad companies shit for ignoring DNT though.
Faking it like Microsoft does makes DNT loses its meaning entirely.
Note that there are 3 values to DNT: null (no explicit decision), 1 (do not track), 0 (track).
When it came to the cookie law those companies had one view in regard to defaults. With the DNT header, the opposite view.
Here's an article from the time: https://arstechnica.com/information-technology/2012/08/micro...
For example, do users explicitly consent to myriad shady practices by advertisers and others when using the www simply because they use the www?
Do they "explicitly consent" to all these practices by not objecting?
Can a user "consent" to some practice without knowing it exists? How can she object to it without knowing what "it" is?
Terms of Use only covers the actions of one party. It does not provide assurances that those terms will be upheld by all the third parties that the website is profiting from when it gives those third parties access to the websites visitors.
Opinion: To be adequately informed in order to give "explicit consent", the user would need to see the terms of all the third party ad networks and others who are contracting with the website. Those companies are largely hidden from users. The easiest thing for the user is to just ask not to be subjected to the actions of these third parties.
Every website that opens its users up to an astounding number of third party servers1 can and likely will disclaim any liability from the actions of third parties.2
As others have stated, dealing with this problem on the client side is the viable alternative.3
1 Others have posted casual studies to HN of developers/users observing how many DNS requests or connections are made to third party servers for the "average" website by users with the popular browsers that automatically request resources. I leave it to the astute HN reader to find the web citations.
2 Random example of website terms: "FACEBOOK IS NOT RESPONSIBLE FOR THE ACTIONS, CONTENT, INFORMATION, OR DATA OF THIRD PARTIES, AND YOU RELEASE US, OUR DIRECTORS, OFFICERS, EMPLOYEES, AND AGENTS FROM ANY CLAIMS AND DAMAGES, KNOWN AND UNKNOWN, ARISING OUT OF OR IN ANY WAY CONNECTED WITH ANY CLAIM YOU HAVE AGAINST ANY SUCH THIRD PARTIES."
3 Block access of third parties via client software. The counteraction by the advertisers will be to try to control the client software. Choice of software is important. If the authors of the software earn their quid from advertisers, then what happens? Users may succeed in stopping websites from selling them out, but they also muct succeed in stopping the software they use from selling them out in less obvious ways.
However, from what I understand Microsoft is also the absolute worst in terms of lowering ads to the window manager level, which is beyond disgusting for a company selling a tool.
Furthermore, this sheep just highlighted the fact that it's a troublesome sheep, that requires special attention (i.e. if the DNT flag is in the header of the first request to my site, I know I can bust out my adblock-bypassing scripts, and start serving ads differently).
When I worked for [name of major ad-supported company redacted], I specifically asked a senior PM one day why are we ignoring the DNT flag in our products. He said "because that's how we make our money", thought for another second and added "also, everyone else ignores it".
The "policy" doesn't seem to be legally binding in any way, there is no way to even detect violations and the EFF itself writes that it can't enforce it:
> Posting the dnt-policy.txt file makes a promise to the users who interact with their domain. We believe it would be a false and misleading trade practice to post the policy without the intent to comply in good faith. However, EFF is not in a position to enforce this promise or monitor compliance. [1]
So what's the point?
[1] https://www.eff.org/dnt-policy#faq-What-does-the-dnt-policy....?
DNT was actually pretty widely implemented in browsers for a while, but it ultimately failed because there wasn't anything actually enforcing the standard. It was essentially just a way to politely ask servers not to track you.
I mean, just look at the current state of advertising on mobile. One constantly gets ads hijacking the browser to show ads ostensibly from Amazon or Walmart (I doubt either Amazon or Walmart would actually prevent you from getting to the content you're looking at). The "well-done" ads prevent you from even hitting the back-button on your browser to return to the content. Being an Android user, I've effectively taken to using MS Edge on Android, because at least in Edge, I can disable javascript, which has gone a long way to crippling such ads. (Before anyone asks: I'm normally a Chrome user + UBlock, etc etc, but Chrome doesn't support extensions on Android, and I've never had good luck with FireFox for anything other than draining battery).
When Ad companies learn to play nice and not hijack my browser and occasionally serve up out right malware, maybe, just MAYBE, will I reconsider playing nice with them.
Note that you can also do this in Chrome: Settings/Site settings/JavaScript.
If you're looking for another way to block ads on mobile, DNS66 works pretty well for me, and it's FOSS IIRC (obviously it doesn't get everything, there's only so much a DNS-based blocker can do, but it catches most ads except YouTube's in my experience).
I do use DNS blocking on my home PC, and yes, it works great, but obviously that is a moving target, especially if you don't actively maintain it.
I'm not familiar with DNS66 - I'll give it a closer look later tonight.
The top result: http://ccm.net/faq/39964-google-chrome-for-android-turn-off-...
Credible Wireshark log dumps would be a good start.
I'm sorry, but if you expect anyone to believe you, you're going to have to produce actual evidence.
I recently learned of GDPR. Although I'm uncertain of the exact law's implementation details, I think it's a step in the right direction. It's strictly opt-in and requires providing a clear explanation of what data gets collected.
Not to mention that AdBlock has lost all the good faith from the users, so including it in the coalition only does damage to the public image.
I know which one works best.
Yes I know this was in good faith, but when you are trying to get good faith agreement against the business model of an industry, it's no surprise it was a failure.
I know this is off-topic, but what is so innovative about Medium? Does it break any significant ground beyond what LiveJournal was doing almost two decades ago?