[1] https://www.w3.org/TR/tracking-dnt/ [2] https://arstechnica.com/information-technology/2012/09/apach...
[1] https://www.w3.org/TR/tracking-dnt/ [2] https://arstechnica.com/information-technology/2012/09/apach...
1) Why should "off by default" be the standard and "on by default" a standard violation? Any sane person, especially after consulting with users, would conclude that it should be the other way around. There's no a priori reason to say that "no explicitly-expressed desire not to be tracked" is less valid than "no explicitly-expressed dire to be tracked", since we all know most people just stick with default settings.
The reason is that no one ever intended to actually honor DNT unless it was only used by a tiny fraction of people (and probably not even then), so that's the way the standard was written. Complaining that IE "violated the standard" was a useful way to try and distract from this fact.
2) IE10 violated standards left and right, and most of the time web servers and developers just grumbled and dealt with it. In no other case did anyone commit code to Apache to ignore headers sent by IE. Why different for DNT? Because unlike most settings, DNT actually cost them money. So once again "it violates the spec!" was a figleaf for the real problem.
I agree with your sentiment that on by default should be the standard. However, it isn't. The standard is specific and it says it should be off by default.
The standard was designed to be completely toothless and the advertising industry still tried to water it down. There's no enforcement mechanism and nothing that says what it means to comply.
If you want something with teeth, try the EFF's pseudo-standard for DNT: https://github.com/EFForg/dnt-guide
You're completely right, and I think this gets to the root of what DNT proves -- that it was self-regulation under the assumption that it would not hurt advertisers or force them to change their processes for most people.
One can imagine an (admittedly unrealistic) alternate universe where DNT was off by default, but some kind of significant event caused a huge percentage of users to voluntarily turn it on. In that world, advertisers would probably still stop honoring the header. Because what they were implicitly agreeing to was, "we will stop tracking a tiny minority of users who might otherwise just block us anyway."
And to be fair, you can't really blame the advertising industry for not being on board with self-regulation that would force it to radically change its approach to business. I think that's why DNT still matters for illustrative purposes. It shows why consumer adblocking and anti-tracking tools need to exist outside of the control of the advertising industry. It can't be a partnership, because it's unrealistic and, frankly, unreasonable for users to ask advertisers to voluntarily kill their own businesses.
No tool that has an actual real impact on privacy to anyone other than a tiny percentage of already irrelevant users is ever going to come out of the advertising industry being "responsible". Any kind of voluntary standard that advertisers are respecting (using easily blocked cookies, creating well-labeled ads, etc...) only exists because most consumers aren't using it to protect their privacy or because advertisers don't have the legal power to get rid of it.
This is why my country was one of the last in Europe to abolish slavery. The government had to find money to compensate the industry. A sound argument on paper but considered an embarrassment now.
I just don't think it's fair to ask advertisers to voluntarily help me with that.