How's Mozilla Doing with Do Not Track? Not So Good
readwriteweb.com
readwriteweb.com
http://en.wikipedia.org/wiki/April_Fools%27_Day_RFC
Also, RFCs are not terribly heavyweight technical documents. They're essentially memos, not ISO standards. Any (demonstrably competent) person can submit a RFC, and if it becomes popular, then the idea enters the standards track, and new, better RFCs are issued based on it.
https://www.eff.org/deeplinks/2011/03/tracking-protection-li...
I'm against bad laws.
I'm for good laws.
If a realm of human activity exists in which unregulated behavior trends toward maximum social benefit, reasonable minds will contemplate whether or not appropriate regulation (and enforcement of same) might be beneficial.
Say: putting teeth into DNT, allowing for civil penalties (a border condition in which law and private enforcement both come into play), and civil penalties for egregious flouting of the law.
That's the same problem we have in the EU right now. The correct way to deal with cookies would be for people to enable or disable them in their browser, according to their personal preferences. Instead, the EU forces their cookie legislation on everybody, because most people are too lazy to fix their preferences.
Why should this be any different with computers? The risk that you pose to others is pretty low, so there shouldn't be any requirement to have a "license". But I wouldn't call it arrogance, if I'll assume that someone using the network has a minimum knowledge about how things work.
Only to a point. I own a car and am perfectly competent to use it, but I have only the vaguest of understanding as to what things like spark plugs and catalytic converters do. I know what a manifold is in mathematics, and I suppose it's a bit similar in a car engine. I deem myself knowledgeable to open the bonnet and add windshield wiper fluid when that's low, but anything more complicated I'll take to a mechanic.
> If you're using it without learning how it works, it's your own fault, if you have an accident.
It's my fault if I drive without, say, learning how to operate the brake pedal, or learning how to turn on the turn signal. But if the accident is due to something wrong with the internals that I know very little about? I don't think any reasonable person believes that getting licensed to drive should require one to have the knowledge of an automobile mechanic.
Browsers have no way of deciding which cookies are tracking and which aren't, and disabling them all causes all kinds of problems, including with sessions. Legislation, on the other hand, is less 'blind' and lets websites using cookies for functionality the user required and/or is informed of (like sessions, preferences and such) without letting websites perform unauthorized tracking.
a better solution is to integrate tools to allow users to block third-party scripts, to fix bugs and improve cache handling headers that can be used to track users, and to not let any third-party scripts store any information on the client.
These can be pressured (by public opinion, for example) into complying with DNT even if it's not their 'first instinct' to do so.
Tracking people using DNT? This is quite ironic.
Well, robots.txt is a simple text file that politely asks robots to not spider parts of your website.
It is completely voluntary and unenforceable, but works very well.
It is completely voluntary and unenforceable, but works very well.
Ha! It works very well: for Google, and Yahoo. They use informative user-agents, and respect robots.txt directives. They have to, they're large corporations, with shareholders.Everybody else ignores it. Why would they listen?
Live example:
216.55.185.45 - - [11/Sep/2011:06:50:56 -0400] "GET / HTTP/1.0" 200 4835 "-" "Mozilla/5.0 (Windows NT 6.1; rv:5.0) Gecko/20100101 Firefox/5.0"
216.55.185.45 - - [11/Sep/2011:06:50:57 -0400] "GET / HTTP/1.0" 200 4835 "-" "Mozilla/5.0 (Windows NT 6.1; rv:5.0) Gecko/20100101 Firefox/5.0"
216.55.185.45 - - [11/Sep/2011:06:50:57 -0400] "GET /blog/ HTTP/1.0" 200 114535 "-" "Mozilla/5.0 (Windows NT 6.1; rv:5.0) Gecko/20100101 Firefox/5.0"
216.55.185.45 - - [11/Sep/2011:06:51:01 -0400] "GET /blog/archives/2010/01/12/creating_an_account_on_the_scp_wiki_is_like_pissing_glass/ HTTP/1.0" 200 10490 "-" "Mozilla/5.0 (Windows NT 6.1; rv:5.0) Gecko/20100101 Firefox/5.0"
This is all the traffic from this IP, with no lines skipped. You might notice that it doesn't request CSS, or any of the linked images, or favicon.ico. Nor does it populate the referral header fields, which of course it would be doing if it was actually Firefox, and there was actually a human clicking on these links. It doesn't even bother requesting a robots.txt, which I don't have anyway.[1] Do a whois check on the IP, and we get: Codero CODERO1999A (NET-216-55-176-0-1) 216.55.176.0 - 216.55.187.255
Codero's a dedicated server host. This is a spambot, looking for email addresses. Visit the IP in a browser, and you see a site selling fake Tiffany jewelry."Please note - This e-mail and any files transmitted with it may contain confidential or privileged information which is protected by legislation, copyright & the code of practice covering personal information. It is intended solely for the use of the individual or entity to whom it is addressed. If you have received this e-mail in error, please notify the originator. Any disclosure, copying, alteration, distribution, publication or the taking of action in reliance on the contents may be an offence."
as a random example. Bonus points for using it it in a footer, where almost by definition, you've read the email before seeing it.
I'm sure there's some legal justification for doing so, but it still strikes me as pretty stupid.