IE10's 'Do-Not-Track' Default Dies Quick Death
wired.com
wired.com
By telling users you have better privacy simply because your browser adds a random header tag onto requests you're misleading them. Sites have no obligation to obey it and it will give users a false sense of security.
We already have proven, well defined method of DNT already: private browsing. This works by simply removing resources after the session ends. There's no reliance on servers, so it will always work.
Until appropriate legislation comes into play. It worked reasonably well with the Do Not Call lists.
Catching up is a matter of when, not if.
A number of large ad networks have already announced support for DNT. Sure, there will always be sites that ignore the header, but there's also a realistic chance that it will give users a meaningful choice about how their behavioral data is used by many of the biggest sites they use most often.
It's a lot harder to detect, and probably harder yet to prove, when they're engaging in illicit tracking.
It's the U.S. government trying to take anonymity and privacy away from the Internet; do we want them making weak, unenforceable, irremovable laws on how to implement an HTTP header?
And by session, this wouldn't just be the cookie store, it would also be the cache store and everything else which can be manipulated for tracking purposes.
EDIT: I'd also want it clearing between browser restarts too.
If this became (over night) the default standard way for browsers to behave, the vast vast majority of websites (at least 99.9% I'd guess) would continue to work without issue and it would pretty much annihilate nearly all privacy/tracking issues on the web.
Stuff like Google Analytics would continue to be able to work, but wouldn't be able to gather as many different types of information. Advertisers would be able to continue to advertise, but they would lose the ability to track you across sites, which potentially might hit their revenue a bit.
You are still being tracked with private browsing. You IP, user agent, OS, screen resolution, etc. are enough to connect the dots in most situations.
This is a decent idea that will need to be implemented to some degree if sites are eventually going to support under-13s, since it is illegal to track their behavior under current law. But you are right, I don't see a lot of places voluntarily signing up to make less money.
I'm sorry, but what is the deal with web-based tracking? I see comments like
> Whenever you visit a website with an ad, DoubleClick knows you looked at that article, and uses that to build a profile about your preferences. I don't think when your average joe reads an article that it is fair that their preferences are being tracked in this way.
and I honestly wonder how this sentiment can be so common, given the realities of our current society (note: this comment is not meant to say anything bad about that comment's author, it's just a convenient example of a trend in the discourse on this topic).
First, we give up many "rights" as tradeoffs for other things that we want. We have the right to the pay from our jobs, but that doesn't mean that we are entitled to get things from the store for free. We have to give up ownership rights of our money in order to trade it for goods and services. We have the right to free speech, but that doesn't mean that someone can't ask us to leave their home or other property if we say something that upsets them. We give up our right to say whatever we want by going onto someone else's property. This sort of situation is so common that it would be impossible for me to list all of the times in which we are faced with it here. However, this argument would not be complete unless I also stated that web-based tracking is in exactly this category: someone has set up a situation where your computer can exchange data with their server. However, in doing so, it is possible that they will notice that you have done so and keep a record of this fact. In other words, if you, through your computer, communicate with a company or individual, that company or individual may know that you communicated with them and what the contents of those communications were. You are giving up your right not to be known to have performed a behavior by a set of potential witnesses in exchange for performing that behavior in front of those witnesses. It's unreasonable to say that, just because you are communicating through computerized agents the other party should not be able to keep a record of your exchange.
Second, it is unfathomable (edit: To me. Please, tell me how your opinion differs) that this could be an issue for people because this is the state in which we constantly live. Every time you leave your house, your neighbors may take notice. Every time you go to the store, your actions are recorded (tracked!) by security cameras. The clerk knows what you bought and may recognize you as a regular customer. If you use a credit or loyalty card, the store keeps keeps a log (tracks) your purchases and builds a demographic profile. At a casino, the floor manager watches you gamble over security cameras. If they notice you winning a lot, they may ask you to leave for the day. I could go on like this all day. The point is that there are all kinds of times where we are tracked and where the only way to opt out is not to have dealings with the tracking entity or to not go out in public. There are all kinds of businesses built around or supplemented by tracking people. It seems to me that the tracking-things-you-witness ship has already sailed and if people wish to bring it back into harbor, they will first need to establish a reasonable test that makes it clear when tracking is actually abusive. It seems very unlikely to me that any test that wasn't specifically designed to do so would label all internet-based tracking as abusive, as some people seem to do, while calling these other behaviors OK.
Am I wrong? Am I just an asshole?
Tracking does not mean looking at server logs (or by analogy, reviewing security camera footage), it means things like cookies, Flash cookies, beacons and KISSmetrics.
Chances are DNT idea will have little effect. People raised issues with cookies back in the 1990's and in rerospect it hasn't impeded websites from tracking. People were forced to opt-in to cookies and everyone became desensitised to them over time. Now people don't even think about not accepting cookies. Tracking has gotten very aggressive though. Some of the behavioral tracking ideas are really pushing the limits.
DNT is hardly a draconian measure. Be glad that the web is still very much unregulated in comparison to meatspace.
Some people still build sites that have basic functionality with JS off. Nobody bothers to do the same for cookies.
It's true a good portion of the web still works well without Javascript. This seems like a good thing as Javascript can be a mixed blessing. Enabling it comes with both benefits and risks. Like cookies, a user could selectively choose which scripts to allow, one at a time (remember the embedded Java applet days?), but this can quickly become more trouble than it's worth.
Perhaps a difference of JS from cookies is that with Javascript the user might sometimes see what the actual benefits are and they might be more enticing than those of cookies, e.g., "To see this cool doodad, you need to enable Javascript." It is very clear what the benefit will be: the doodad.
Contrast this with "To use this site you must have cookies enabled." Terms like "provide a better user experience" might be used to describe the need to enable cookies. But the specifics are usually absent.
If all websites were reasonable, and no one abused their ability to manipulate and track end users, things like DNT would probably not be necessary. But we know that's not the case.
So I quite support the requirement that people explicitly enable it.
Remember the DNT is voluntary - but if everyone does it by default, then there is nothing left to track, so websites will have no interest in paying attention to the flag.
Isn't that the whole point? Websites may not have interest in tracking disabling policies, but a lot of people do. Maybe these advertising companies ought to incentivize users to opt-in to sell their data instead of the other way around.
I can see Google fully implementing DNT on the basis that users don't care, and for the few that do they're happy to comply
But making it default to on, especially if no one gives a damn is the death knell to the whole business model
Suddenly you have to pay for everything.
Although I would be interested in using DNT if out had more granular control to block certain entities
I wonder if we'll see sites who honor the header, but require that it be off in order to access content.
Instead they can show a banner that DNT is enabled and when it is disabled, the banner is gone.
False dichotomy. It's not "targeted ads vs no content on the internet". People will just have to use generic ads, not targeted ones. I don't think there will be any meaningful difference in profit, and even if there is, then so be it.
I think a couple other posters here have pointed out the larger problem - without ads like this, the free internet dries up and suddenly you need to start paying for everything from gmail to facebook (or whatever other tools/blogs/webcomics any of us visit).
Web developers might hate it, but DNT could be potentially good for end-users who want to make privacy claims. It's just one extra header. A few extra bytes. Meanwhile things like XML and JSON, which add considerable bloat to web responses, are accepted without any complaint.
Tracking can be done by servers, using a workstation signature (ip/port, installed software versions etc, been discussed in other posts), it doesn't require your client station's consent (cookies).
It is not default, the user has to choose.
> ... tech and ad companies who say they comply with Do Not Track could simply ignore the flag set by IE 10 and track those who use that browser.
That doesn't quite work. Web servers don't know what browser is on the other end of a connection. Yes, they know the "User-Agent:" line, but that is not the same thing.
Claiming to follow a privacy standard, but then ignoring it based on a conclusion reached via fallible means, is a bit scary. It strikes me as the beginning of a slippery slope, regardless of what position Microsoft ultimately takes with IE 10.
I don't see how this would be slippery at all.
Also, is "forging" really a dishonest thing in this instance? Browsers have been making themselves look like other browsers for years, in order to deal with stupid servers that make incorrect assumptions about the User-Agent string.
[1] Not a rhetorical question. I don't know the answer.
Is there a clearing house for certifying browsers as DNT compliant? Or can the websites just say "Oh, THAT browser? Well I don't think it is DNT compliant so I am going to ignore the DNT headers even though they are perfectly to spec"
Whenever you visit a website with an ad, DoubleClick knows you looked at that article, and uses that to build a profile about your preferences. I don't think when your average joe reads an article that it is fair that their preferences are being tracked in this way.
We should survey the public and ask: "Do you think it is okay that internet ad companies use the type of article you read to target ads that are more likely relevant to you?"
That is a reasonable question that gets to the crux of the issue. Retargeting and profile targeting may be borderline unethical, but Google and I both make good money doing it. I am not sure it is right, but we both have a vested interest in making sure we can continue.