"Do Not Track" HTTP header supported by IE, Opera, FF, Safari but not Chrome
en.wikipedia.org
en.wikipedia.org
"Do Not Track" sounds nice, but seems no easier to scope than the initial problem of excessive information collection. I think it's safe to say that I want companies to 'track' me in order to keep me logged in for a session. Likewise, I hope that my bank keeps logs of visitors, so that it can respond to abuse / hacking attempts. Is this aimed only at behavioral advertising, or is it meant to have a broader scope?
It seems like the technical execution is almost misguided without having the policy discussion first and figuring out what it is we disagree with. Without that, I don't feel like this is going to draw a strong enough line to separate people abusing tracking from the legitimate uses.
Emphasis on "websites they do not visit" directly, meaning that it only applies to iframes, popups, etc. If you typed it in the address bar, or clicked on a link to get there, the site isn't limited by DNT.
This is not legal advice.
As part of its functionality it relies on the ability to uniquely identify a user across sites (to provide user authentication).
There are quite a few other services that work in a similar way.
On the other hand, if I'm not logged in, I don't want them tracking me across all the Disqus-enabled sites I visit.
As a user, I want to be stay logged in to Facebook when posting a TC comment. But I don't want Facebook to track me when I visit some random site with a like button. How do we draw the line here?
This is made easier for me by the fact that I don't use Facebook.
So Facebook & Google are fine, too then. You authenticate with them, then they add features based on that.
In the case of facebook they can show the "like" button, but they cant use the information that it has been shown for you on a particular site, on a particular date/time.
Facebook's entire purpose is to show you things you are interested in. The fact you didn't like something on a given site is nearly as useful as if you did.
Facebook show's me updates from my friends activity. It can better match those to my interests if it knows what I am interested in.
Seems that it's like P3P[0], in that it causes problems for developers but in no way keeps a company from asserting things that they don't actually follow, and there's no way to verify that they are.
WTF? So analytics packages will somehow have to exclude these browsers from all reports? Some reports? Can you count impressions from these users?
A hypothetical and largely incorrect real-life analogy: you can use cameras to recognize regular clients and keep statistics on them, but you cannot send the camera images to another company to have them processed, because your clients are visiting your store, and not that other company. (This analogy is largely incorrect because camera images are more privacy-sensitive than cookies, and different legal and moral issues are involved, but there's still a similarity.)
Now then again DNT is an intent, the vendor does whatever he likes, and can support DNT for other features and still have statistics. There's no list of things you can do or not do. There's no agreement either. It's just the user indicating that they don't want to be tracked in any way.
Consider a real world equivalent. Suppose you walk into a bookstore and buy a book with cash. The store might not be able to track you individually but they can track how many people visited, how many books they sold, etc. You can't say that's not legitimate.
So I could see an argument that the line that should be drawn is one that involved tracking cookies, but that is quite a narrow exclusion regarding statistics of individual users. You can still get pretty good stuff from the access log and there's no case to be made that DNT means Do Not Log.
Then again anyone is free to track/not track, stat/not stat (so far at least) and only "not track" subset of their data (as long as they don't lie)
Then again there's a few privacy-aware websites who do logging and some stats but on pseudonymized IPs which is also a pretty decent compromise.
I am confused as to how this works for statistics purposes.
Deleted comment
advertising existed before every move you made was tracked, and it was quite profitable. There is zero reason that such invasive bullshit is a requirement.
HN user fauigerzigerk put it best:
I would like to agree with your idea of tracking
as payment, but I really can't, because:
a) Most of the time I don't have a choice. There's
no option to pay them money and even if I pay them
directly, they may still keep collecting tons of
personal information about me on top of it.
b) It's sneaky. I don't really know what
information they have and how they use it. I just
have a couple of completely meaningless words
from their privacy policy.
c) I don't know the price I'm paying.
The last point is the most important one.
The value and the risk associated with a
particular piece of information greatly depends
on what other information it is combined with,
but I can't control that. The company could get
acquired tomorrow by some ad behemoth that knows
a lot of other things about me, so the price I'm
paying could change after the fact. That's not
the way payment works. I have to know the price
I'm agreeing to pay before I enter that contract.
https://news.ycombinator.com/item?id=3751905If your point is strong you should have no need to throw your hands up in the air and say "end of discussion" which is what period pretty much means. Your making the call that this discussion is over because you know best.
I had to post this, your 'period' distracted your entire argument for me.
Deleted comment
The thing is, in the offline world, you can control much better who's tracking you. And this is why people get upset at CCTV cameras too; while you can see the people around you who are observing you, and choose to modify you're behavior by whether someone's around or who is around, CCTV means that you may be observed, recorded, and tracked at any time without consent.
Deleted comment
"If we don't alllow web advertising to be unregulated, all good content will be paywalled."
You mean that kind of irrational fearmongering?
Because there is ample evidence that good content was available through the internet and later the web, before it was permitted to be used as a commercial vehicle and long before the web became laden with cheap advertising.
Deleted comment
OK, thanks.
If you want to get pedantic about it just being text, all law is just text, books upon books, but its the enforcement that counts. This opens the door for enforcement of other laws.
I'm fairy sure a mix privacy & contract laws in my country would hold companies subject to this as its stands if you didn't agree to allow them to do it in a EULA.
Because if I'm not mistaken by accepting the request you are agreeing to contractual obligations... so the server has to accept your contract to engage in transactions... the server can choose to accept or deny this transaction... by default accepting the contract.
Of course you would have a good defence against this a well, so agreed you'd need it standardised to make it a real threat against a company in court. Would be interesting to see played out in court TBH.
Also if stances are made like this then changes will never manifest, because its close to useless now doesn't mean it won't become a foundation for something later.
I think from a legal point of view though , you are expressing your desire to not be tracked.
This would be preferable to legislation dictating that the user must manually approve all cookies etc.
Yes. And I think this is important. For example, for cases brought by the FTC, class actions, and other litigation it might be useful.
If a company ignores the Header sent by the user and tracks her anyway, then one could argue the company too has expressed an intent.
The Header is machine readable like any other. A server can parse it and take a specific action based on its presence or absence. Arguably it does have technical merit.
Unless you have Chrome.
It should be pretty obvious why Chrome doesn't implement it. It's against the core business of Google (tracking). They will only implement if it causes a PR issue (and this very post is a PR issue btw, even thus a small one)
I don't know if they've made any promises to honor DNT requests, but their browser will be able to send them.
Also note that almost no other browser are supporting such a feature out-of-box, at least not when this feature was added to Chrome.
So while I'm not a big fan of Google, either, I find it hard to argue that Google doesn't care about privacy features in Chrome.
Once it exists, sites can be forced to explain why they don't obey the users' express wishes.
Wikipedia says Chrome is set to support the header by the end of this year (2012).
Wikipedia's source: http://online.wsj.com/article/SB1000142405297020396080457723...
I guess we'll see if they honour their promise by the end of the year.
So what, if any, websites support the "Do Not Track" header?
For those, quoting from http://donottrack.us/implementations :
3PMobile, AdInsight, AdOcean, AdTruth, AP News Registry, Blue Cava, BlueKai, BrightTag, Chitika, Effective Measure, eXelate, Jumptap, m6d, Mochi Media, TagMan, Tealium, TruEffect, Ensighten, Twitter.
Note absence of Google with their advertiser hat on, as well as Facebook.
Also, way too little way too late.
Ten years ago this might have been seen as constructive contribution towards industry self-regulation. Now it's just a sick joke that won't do anything to change the fact that tracking without explicit permission will be illegal in many parts of the world.
(the tl;dr of the spec is that it adds this HTTP header to all requests:
DNT: 1
it can be set to 1 or 0).There is also a large risk here of creating a false sense of security amongst less knowledgable users. We should be teaching users cookie control, plugin and request blocking as part of using the web, not an 'install once, forget forever' solution that doesn't work.
DNT is also adding more entropy to HTTP requests, making you easier to identify or profile. You get less privacy. Think about how much an advertiser would love to know that you are privacy conscious, that puts you in a certain socio-economic group.
I am a huge privacy nut and advocate but DNT will not work. The only way to fix this is better third party blocking and controls in browsers.
I have been meaning to flesh out a blog post against DNT for a while, since I keep getting emails asking to comment on media stories about it being adopted.
Doomed to failure. Users shouldn't need to know this stuff, and the vast majority never will. Even if it is taught and tested at school. There are plenty of things we could do to improve privacy, but much of it will cause the major browser vendors to make less money, so is unlikely to happen.
1.) Tie all cookies to the domain in the address bar. No more third party cookie tracking.
2.) Tie all cache entries to the domain in the address bar. Gets rid of numerous tracking tricks at the cost of increasing bandwidth usage a little.
3.) Get rid of HTTP referrers. Completely. It's none of your business which site I was on before yours.
These three things alone would make a huge difference. It's the low hanging fruit that we need to get before we tackle the more difficult problems.
I think there's too much money involved though. The above improvements would definitely hit Microsofts and Googles bottom lines. But hey, there's no problem with insanely rich advertisers controlling the major browsers right. No conflict of interests there.
EDIT: I agree with all of your other points regarding DNT. Just not the user education one.
EDIT2: Another one:
4.) Make all cookies, session cookies. I configured my browser to delete all cookies on exit ages ago, and the web still works fine. I might have to type in my username each time I go to login to sites instead of having it auto-filled, but that's a good trade off. Besides, browser plugins like LastPass solve that problem better.
I totally agree that users shouldn't need to know the details, but there are some things, like third-party cookies, that needs to be explained and simplified. A bit like not clicking on an exe email attachment.
I think the equivalent could be that users white-list websites, or 'install' them, if they trust them, which allows those sites to execute third-party cookies. Everything else would be 'incognito' by default.
But I am not entirely sure what would work, hence my experimentation at the moment. I know that the answer definitely isn't DNT.
[1]http://www.whitehouse.gov/sites/default/files/privacy-final....
[2]http://ec.europa.eu/justice/data-protection/article-29/docum...
You are asking Schneier to implement security by obscurity with emphasis on the obscurity part. Hell, you are asking the same people that sent a "This is not a P3P policy" P3P policy.
Now I don't know if they think, as do I, that all of this is just meaningless extra traffic on the wire, or that they are evil and don't want to commit to privacy guarantees. No way to tell.
Did Google web properties use WebGL, NaCl etc. before Chrome supported them?
its just a request to not track me but i don't can see if its really not tracking me.
"If a house be divided against itself, that house cannot stand."