The current charges involve Google's use of special
computer code to trick Apple's Safari Web-browsing
software into letting it monitor users that had blocked
such tracking.
https://money.cnn.com/2012/02/17/technology/google_tracking_...This is such a non-issue. It was widely regarded as a bug in Safari.
No browser ever expected it to do anything other than provide additional tracking metadata.
That said, I think the DNT flag being formalized is important to web development.
Previously, one of the core arguments of advertisers was "people do not care about being tracked". Individuals choosing to turn on DNT demolishes that.
Unfortunately, browsers turning it on by default muddles that indicator or intent, even if it's good for individuals.
When Google recently silently made Chrome log you in whether you logged yourself in or not, I switched to a different (previously unused, non-Chrome) browser on a new computer, and without logging in to anything Google (but from the same house), I went to YouTube. It asked me to log in, but I didn't. It proceeded to suggest mainly links to very niche-interest, low-view-count videos I had previously in the past few days, making it clear that it had at least a very good guess who I was anyway.
Apparently, asking me to log in was mostly just asking for my permission for what they were going to do whether I agreed or not.
Their methodology was pretty flawed and to top it all they also results "positive" to this kind of analysis.
This does not implies that google does not track incognito users either.
You're making the assertion. Do you have evidence to dispute the DDG study? The onus is on you.
In other words, the study proves that different people get different results. It doesn't prove, as they claim in some press, that this is because Google tracks you while you aren't logged in. It's misleading on DDGs part to claim such of that's the case.
(I work at Google, but have nothing to do with ads).
As a broader point, just because you have a null hypithesis does not mean the study is biased. That's completely not how academia works.
Bias as the gp used it doesn't mean statistical bias which also isn't what you mean, but more like "even if these results are technically accurate, they may be misleading", a common example would be p-hacked results. This, contrary to what you say, often involves inventing a hypothesis after the fact, such that it is easily disproven with your data.
However, there isn't evidence that this was what was happening, and Google hasn't exactly covered itself in glory on the privacy front so I tend not to give them the benefit of the doubt on this front. I'd love to see a response from them addressing some of the points from the DDG study.
I don't believe that Google tracks you in incognito mode. My understanding that the DDG study showed that they continue to track you when not logged in, which is consistent with Google's public statements on the matter.
Before DNT, the way consent basically worked was that companies just assumed you consented, and only if you specifically denied consent, they would have no chance to defend that in court.
With DNT, if the user turned that on themselves, they would have clearly signalled that they want this the other way around. Do Not Track me, unless I specifically give you my consent. This would have made it hard for companies to defend their behaviour in court.
With Microsoft turning it on by default, there was no way for companies to know, if the user actually wanted privacy, or if they supposedly wanted to be tracked, for whatever reason.
With the GDPR in place, you theoretically now need to get consent every time (including implicit consent, e.g. when the user asks for something to be shipped to their address, that means you can process their address). Most companies don't yet keep to it, though.
You cannot just assume the user did not actually want the default setting in their browser.
With most webpages shipping code from Google/Facebook, that was also already pretty bad for DNT.
This is false. There are multiple ways to justify processing of personal data, and your example would fall under data processing necessary to perform a contract at the customer's request. Depending on your location, there might also be legal requirements to record and keep user data, which is also a valid reason that doesn't require consent of the user.
I've checked the setting in MS Edge on 2 PCs and it was off on both.
How would that happen?
> Before DNT, the way consent basically worked was that companies just assumed you consented, and only if you specifically denied consent, they would have no chance to defend that in court. (...) With Microsoft turning it on by default, there was no way for companies to know, if the user actually wanted privacy, or if they supposedly wanted to be tracked, for whatever reason.
Herein lies the problem. Companies assumed consent. Which is a nice assumption if you want to abuse users and sell their data - though how can users consent if they typically don't even know what's being done to them? In reality, what companies should assume is lack of consent, and I'm very, very happy that at least for some of us, GDPR is fixing that.
> With the GDPR in place, you theoretically now need to get consent every time (including implicit consent, e.g. when the user asks for something to be shipped to their address, that means you can process their address). Most companies don't yet keep to it, though.
No you don't; you only need it for using user's data for things other than fulfilling user's request. It's kind of like with Cookie law - you don't really need a cookie banner, unless you're tracking people.
(Or in other words, amount of UX problems GDPR/cookie law cause are directly proportional to how abusive a website is towards its visitors. It's a useful signal.)
They of course blew that opportunity and will have to pay the price. We're already seeing apple and mozilla becoming very aggressive to prevent tracking and ads.
It's nice that they've recently taken a stand, but they're still not taking it very seriously (only blocking "abusive" trackers, IIRC) and it's 5-10 years later than they should have done it.
Why aren't they sponsoring uBlock Origin or Privacy Badger?
We have pretty strict laws about what can be in ToS and what cannot. For example, pretty much anything that's "surprising" is out.
This used to be the AGB-Gesetz (ToS-Law), but it was transformed into a more general framework but largely identical rules:
After all, the industry always claims it doesn't need regulation, because it can self-regulate.
So let's see if this is true. Shock, horror, surprise! It's not true! Mon dieu!
Next up: some regulation.
The idea of asking sites not to track is just so pathetic. If you don't want to be tracked, you do whatever it takes to not be tracked. For example, I'm fine with everything about Mirimir being tracked, correlated, etc. But Mirimir is thoroughly compartmentalized from my meatspace stuff, and from other personas. And it's not really that hard. For most people, it would just mean running multiple VMs that connect via different VPNs.
That includes asking and voting for regulations that help end this shitshow wholesale.
Give me a break.
Seriously, running VirtualBox VMs is easier than editing Word documents.
[1] https://www.w3.org/TR/tracking-dnt/ [2] https://arstechnica.com/information-technology/2012/09/apach...
1) Why should "off by default" be the standard and "on by default" a standard violation? Any sane person, especially after consulting with users, would conclude that it should be the other way around. There's no a priori reason to say that "no explicitly-expressed desire not to be tracked" is less valid than "no explicitly-expressed dire to be tracked", since we all know most people just stick with default settings.
The reason is that no one ever intended to actually honor DNT unless it was only used by a tiny fraction of people (and probably not even then), so that's the way the standard was written. Complaining that IE "violated the standard" was a useful way to try and distract from this fact.
2) IE10 violated standards left and right, and most of the time web servers and developers just grumbled and dealt with it. In no other case did anyone commit code to Apache to ignore headers sent by IE. Why different for DNT? Because unlike most settings, DNT actually cost them money. So once again "it violates the spec!" was a figleaf for the real problem.
I agree with your sentiment that on by default should be the standard. However, it isn't. The standard is specific and it says it should be off by default.
The standard was designed to be completely toothless and the advertising industry still tried to water it down. There's no enforcement mechanism and nothing that says what it means to comply.
If you want something with teeth, try the EFF's pseudo-standard for DNT: https://github.com/EFForg/dnt-guide
You're completely right, and I think this gets to the root of what DNT proves -- that it was self-regulation under the assumption that it would not hurt advertisers or force them to change their processes for most people.
One can imagine an (admittedly unrealistic) alternate universe where DNT was off by default, but some kind of significant event caused a huge percentage of users to voluntarily turn it on. In that world, advertisers would probably still stop honoring the header. Because what they were implicitly agreeing to was, "we will stop tracking a tiny minority of users who might otherwise just block us anyway."
And to be fair, you can't really blame the advertising industry for not being on board with self-regulation that would force it to radically change its approach to business. I think that's why DNT still matters for illustrative purposes. It shows why consumer adblocking and anti-tracking tools need to exist outside of the control of the advertising industry. It can't be a partnership, because it's unrealistic and, frankly, unreasonable for users to ask advertisers to voluntarily kill their own businesses.
No tool that has an actual real impact on privacy to anyone other than a tiny percentage of already irrelevant users is ever going to come out of the advertising industry being "responsible". Any kind of voluntary standard that advertisers are respecting (using easily blocked cookies, creating well-labeled ads, etc...) only exists because most consumers aren't using it to protect their privacy or because advertisers don't have the legal power to get rid of it.
This is why my country was one of the last in Europe to abolish slavery. The government had to find money to compensate the industry. A sound argument on paper but considered an embarrassment now.
I just don't think it's fair to ask advertisers to voluntarily help me with that.
Basically, Microsoft sacrificed consumer privacy as part of its petty feud with Google (and after their own attempts in ad tech went up in flames—taking a $6B write-down on their acquisition of AQuantive).
Why didn't your company disable it for just IE? It wasn't hard at the time to detect which browser people were using based on headers.
You could have checked to see which browsers turned it on by default and ignored them specifically. If IE went the route of trying to make IE's headers imitate Firefox's or something, fine, then disable it for IE and Firefox, but keep it on for Chrome.
But the idea that one browser misbehaving meant that suddenly no browsers could be trusted sounds to me like an excuse. Across the industry we build browser-specific behaviors for all kinds of things. What's so special about user tracking that nobody in the industry could do that?
Like if adtech companies weren't literally the best players at figuring out which browser a visitor uses.