Firefox removes "do not track" feature support
windowsreport.com
windowsreport.com
It was completely optional for websites to support this. A few did at first.
A lot of people internally wanted it to be on-by-default, but the argument was that if it was, nobody would respect it – after all, what tracking platform would willingly only track the 0.1% of people who went into the settings to enable it? (Internet Explorer did eventually enable it by default, which got them good press but ultimately killed the feature since everyone stopped respecting it.)
Overall, I'm happy to see this sunsetted. I don't think it actually did anything – in fact, I think it implies that it did way more than it did, so it was just a faux feeling of security.
(All that being said, I would love if the cookie modals on each site became browser-level, but I'm sure there's many reasons that hasn't happened yet. And I suspect a bit reason starts with a G and ends with an Oogle.)
Well, it is not singled out by regulation. The GDPR doesn’t even mention cookies at all. They mention any way to track users. Fingerprinting is also banned, for example.
many of it's predecessor sadly are not and are still around
leading to absurdities of there being _both_ a GDPR dialog for tracking and a "cookie dialog" (which depending of the law might also apply to local storage and co) to get permission to "store" something on you computer. Like a hint to not track you :facepalm:
(And yes legally from GDPR storing a same origin cookie only accessible to the browser and you to remember the user doesn't want to be tracked is legal _iff_ you don't use it for tracking users which don't want to be tracked server side. It's one of the many examples where "what legally is good enough" and "what security wise is good enough" can diverge quite a bit.)
[0] https://blog.privacyguides.org/2024/07/14/mozilla-disappoint...
[1] https://cybershow.uk/blog/posts/you-are-too-dumb-for-tech
Microsoft is the main culprit of DNT failures.
But advertisers exist and will continue to exist, and have no incentive to follow this. I don't think either are at fault necessarily; I think it was a weak attempt all around.
The only thing that will get companies to comply are a/ laws (and so far all laws have done is annoy end users) b/ browsers doing more to block tracking (which is almost impossible; this will forever be a game of cat-and-mouse).
You probably can build a case around DNT clearly communicating that a user doesn't want to be tracked and as such it should be treated like an if the user manually opt out of all tracking.
But as long as lawmakers or court don't pin it down legally to make it a clear cut case instead of some gray area thing with a lot of wiggle room.
There is very little you can do against modern tracking tech without crippling browser functionality, as such solutions have to be law based foremost and supplemented with technology and actually painful penalties if companies try to sneak by this.
How can I, as an end user, check if a site is ignoring it and therefore report it to the proper authorities?
Flipping that bit increased your browser fingerprint a smidge, ironically :-)
https://www.macworld.com/article/232426/apple-safari-removin...
They are, in a roundabout way. Hop into your uBlock Origin settings and enable the Cookie Banners and Annoyances filters. The modal gets silently nuked in the background and you can carry on with your browsing. Since you never consented, this ought to be functionally the same as Declining the banner.
The Kill Sticky bookmark works similarly, for crappy browsers that don't support uBlock Origin (eg iOS, Chrome for Android): https://www.smokingonabike.com/2024/01/20/take-back-your-web...
(Remember when web browsers used to treat their users first and implemented things like Popup Blocking, enabled by default? I miss those days.)
Sure, sounds good. When you win that fight, let me know and I'll reconsider the ad blocker.
The average user doesn't even recognize that running a website literally cost electricity that must be paid for. Who pays for it? Who will carry the boats?
Now there may be some upsides to this. Shock content, designed to garner page views, may become less common. Perhaps content will get longer.
But I do not relish the annoyance of having to pay for every site. I despise that tech help on medium, for example, is often behind a paywall. I'd rather watch an ad.
Subscriptions suck because it is another thing to keep track off and many business models rely on you forgetting about them.
I think micropayments would be great but the problem is that you need to consume the content before knowing if it was really worth paying for.
My dream would be some kind of general internet subscription network set up as a non-profit public service where I pay a fixed sum every month and where all kinds of content creators, news sites, basically anyone could be in. The network would pay their members a split of my monthly fee based on the sites I visited by default but offer me up and downvote buttons on every page. Downvotes means the site is excluded from getting payments from me, upvote means double payment. (Of course I can't downvote all of them, the sum I pay is always fixed.)
So I have only one single monthly payment, I don't have to think about it much while still having a way to encourage high-quality content.
That's it. That's not entitlement. I just want to actually read the stuff on a website. If websites could do ads that weren't trying to monopolize attention and/or trick me in to downloading malware, I'd definitely think twice about my use of a blocker on that website.
Sure there are some that feel like because its on the internet that's its free and they are entitled to it. But I'd wager most ad block users fall in to a similar camp as me.
Plus most adblocking extensions these days are also tracker blockers as well, so there's some element of privacy protection in play there as well.
Also, ads got ridiculous real fast, and started doing a lot more than just show a picture. This was really the breaking point for me. I happily pay for the couple mentuomed earlier, and donate to OSS projects even but more than that is unfeasible.
There are lists one can use for filtering out only the "bad" ads, mostly community driven. What we really need is a standard way of doing this, one that is enforced. But no ad company wants this, at least from what I gather.
Blaming ad blockers is the same as blaming video game piracy, you aren't tackling the real issue. The issue is that ad blockers provide a better service than not having one (i.e. not filling your screen and preventing you from seeing the content, not being a security nightmare, etc...), even if you need to go through the trouble of getting one. Alas, in this case it generates a perpetual cycle, which further puts people over their breaking point.
I guess what I'm really saying is that ad companies, and websites filling their pages with them, did this to themselves. The public tolerates it to a certain point, but I wouldn't see it it's their fault if normal web usage continues to deteriorate.
Running a retail store also has costs associated with it, including, yes, electricity.
Yet if I walk into a store and leave without buying anything, do I feel like I owe the store owner anything?
No. That's not how that works, nor is that how it should work.
You can imagine why Amazon never decided to go with this business model.
Not my problem. The web existed as a medium before advertising and it will continue just fine without it.
Get a better business model and stop crying like a spoiled child.
I don’t want to dedicate 4.5 inches of screen space to ads including videos, banners, and often time inappropriate ads. If you want to do 3rd party banner ads, be my guest, but the minute there’s more of them then content I’m going to turn them off.
It blows my mind how people are so accepting of the status quo, especially on mobile, where many news sites will put a sticky ad banner on the top, throw a video ad on the corner (with a close button that's only 1/8" across, of course), and then every paragraph (which is only like 2-3 sentences) is separated by an ad. At any given moment, well over half my screen is ads, even after managing to close the video ad in the corner.
Browsing the web on a phone, I wonder how many bandwidth and battery is being used just to show ads.
I dunno, the website chose to monetize that way. Arguably we don't need so many low quality adspam sites on the web anyway and if most of them died, the signal to noise ratio would get better. Advertising and SEO is a scourge that doesn't need to be protected, IMO. Let them die...
I would happily pay a subscription that gets divided among whatever sites I visit. In the absence of that option, I pay for a subset of sites and freeload the rest. My solution seems ethical to me since if everybody picked a random subset, most sites would get their revenue.
So I think the experience would be like you add $5 to your browser, then as you visit sites it asks you either to pay a one time access fee or subscribe for continued access.
But this would be the case for every site, right, because they all cost money. I wonder how many distinct websites the average user visits and if they're willing to pay that many parties that much money.
I guess my conclusion here is that bad ads should be punished by some mechanism. Unfortunately making the most targeted, helpful (and they are helpful, by the way, when done right they show you something you like) ads often incentivizes bad ad production practices like data farming and data marketplaces. I think that has to be attacked legislatively or, in your example, by direct payment.
But I think the reality of an internet gated by payments is a bigger deal than people appreciate.
(PS Not that this is usually my line of argument, but it also has the unfortunate effect of tying someone's economic status to what they can access, leading to greater isolated groups and class hierarchies in content)
it seems more reasonable to me to only advertise like that when a user signals they're interested in a particular type of product, not passively all the time.
Most businesses don't really get to do that. They set their price based on what customers are willing to pay. Then they try to keep their variable costs low enough to be profitable, and get enough sales to cover their fixed costs.
> tying someone's economic status to what they can access
An option there is subscriptions for those willing to pay, ads for the rest. Youtube does that, for example (and it's one of the sites I pay).
I don't really want "helpful" ads. I just want to be left alone. I don't want corporations trying to manipulate me, and I don't want distractions from whatever I'm trying to read, because I'm distractible enough as it is. If I want to buy something, I can search for it, and when I do, I don't want to see it everywhere I go for the next month.
That's what it is. A request to get sent some bytes. It's up to the web server whether or not to send the bytes.
Once it decides to do so, what I choose to do with those bytes is, broadly speaking, up to me. Copyright sets some legal restrictions there, but none of those restrictions apply to deleting some of the bytes.
Perhaps the webmaster had some ambition to make some money by sticking some bytes on my computer and using them to track me without my consent. That's for them to decide, me? I'm deleting those bytes. That monetization plan is not in my interest. Perhaps they can come up with something which I'm willing to play along with, perhaps they can't.
Generally I've found that the websites which place onerous limits such as paywalls on byte access, are not worth spending my time on. Yet somehow, the Internet remains full of useful bytes and I spend many an hour productively browsing them. It's a magical place.
Advertisers are welcome to treat me like a magazine from days gone by with lots of static images of their products and no code involved. If they don't like that, then I'm okay with going back to the pre-commercial web where people with passion built websites without trying to be the next big thing.
And the idea that the alternative to ads is 40 different subscriptions is laughable to me because there are not even 4 sites on the entire internet that I'd pay (even a small) subscription fee to use regularly, let alone 40.
The vast majority of sites I use on the internet are basically distractions of one form or another and I only ever use them because I can do so for free with a limited amount of annoyance. Any cost at all to them whether that's a subscription fee or obtrusive ads means I just stop using that site.
I've got not problem paying 1/10th of a 1 cent as a microtransaction to read the page and I'll happily do so when that sort of system is available.
> I am unwilling to have 40 different subscriptions to 40 different websites all because every user disabled targeting.
And that's a false dichotomy. The natural alternative to a system where publishers are paid per view by advertisers is a system where publishers are paid per view by users (either directly or via some intermediary), in the same amount as before.
Avoiding said tracking is not in the least bit "unethical" and digital media sources can find other ways to make money, or just disappear if they don't like being circumvented in their ad tracking efforts. Only a badly distorted SEO/ad bro mind would consider users avoiding tracking to be somehow immoral by the users. Should then it also be unethical to not view ads on video media too?
I feel for those businesses who try to build a revenue stream off of advertising, but that well has been permanently poisoned for me. If I cannot sanitize a website of its maliciously user-hostile behaviour, I will simply refuse to make use of it.
And I encourage everyone to join me. The sooner advertising of all kinds die, the better.
That's why RFC 35140 "Do-Not-Stab" specifies that the user agent MUST NOT enable it by default.
> The header has only one form, Do-Not-Stab: 1. This is because the lack of a header indicates a clear preference that the user wants to be stabbed.
> Exceptions to the Do-Not-Stab header are accepted when commercial interests outweigh safety concerns. These include: Stabbings requested by a government. Websites SHOULD NOT try to challenge the legality of any stabbings requested, the user probably deserved it.
Happily, our local police department is sunsetting it, since it gives people a false impression of whether or not they’re currently being stabbed.
I genuinely doubt that anything could have caused them to respect it. Tracking without consent is the source of their money; they're not going to give that up just because you give a positive signal that you do not consent, rather than simply never asking you in the first place.
Removing this feature now is completely the wrong move. Instead Mozilla should have invested money to use the courts to make the signal be respected, where it isn't already.
For me, this signals that finally, Mozilla has completely crossed the line. I will look into forks now that retain the signal.
But then Microsoft broke the agreement by enabling it by default, as part of their war with Google (and after their own adtech ambitions ended in a 6 billion dollar write down on their acquisition of aQuantive). This killed it for everyone.
The ad industry was never going to go for an opt-out version of DNT. It worked while only a minority that cared about it opted-in, but not when the (then) dominant web browser made that choice for all of its users.
I fully understand why people hate tracking and targeted advertising (which has if anything gotten more invasive in the past decade), but at least at the time it was essential to the commercial web.
https://www.theverge.com/2012/9/11/3314211/ie10-dnt-header-m...
The same could be said about slavery.
https://calmatters.org/politics/elections/2024/11/california...
It doesn’t mean either statement is true though.
What also would be legal is to offer the user a choice at the first startup.
Google will never touch it with a hundred-foot pole due to antitrust concerns, they're effectively banned from making any significant, user-experience-affecting changes to Chrome at this point.
Many people would immediately switch to a browser with 1) reliable Youtube ad blocking, 2) no cookie modals, and possibly 3) no other "distractors", like subscription pop-ups or "related articles" widgets.
Yes, ad blockers and reader mode can sort-of do all three, mostly, ish, but they're not easy to set up for non-techies, particularly on smartphones, even more particularly on iPhones, so a simple marketing pitch of "get this app, have these features" would probably work.
One would have to default to accepting cookies, though. Most users don't care either way, while website owners do. If you defaulted to refusing, they'd try to fight you and make their popups harder to auto dismiss, while auto-accepting would do the opposite.
Personally I use FF with lots of blockers and settings on my laptop/desktop, and DDG browser on my mobile.
There's been a few attempts (Brave wants to monetize via crypto, Arc is pivoting away), but it's really hard. People don't want to pray for a browser – 99% of people are apathetic, and the 1% that cares aren't known for paying for things.
It’s just weird that a few hobbyists can generally throw together a database in a weekend, fork kubernetes and probably run with it forever if they really wanted to, create a free operating system that takes over the world, etc. And yet for browsers, we’re shaking our heads and saying the situation is impossible, we kind of always have done this, and it looks like we always will.
Does the reliance on Firefox ESL or based on Gecko rule this one out?
Based on Chromium
I'm sad to see this, as many sites actually used it.
Geizhals.de, a major european price comparison site, uses DNT as cookie opt out.
My personal sites, but also the official websites from a few companies I worked at used umami or plausible metrics, configured to obey the DNT header for opt out handling.
And only recently German courts have ruled that the DNT header is legally considered rejection of tracking (Az.: 16 O 420/19)
It's actively used across the web, and Mozilla just decides to kill it? What the heck?
The only way to stop tracking is via laws or regulations. Technical solutions are, arguably, a never-ending arms race - probably a losing one for end users.
DNT was a way to demonstrate consumer interest in not being tracked, and it put businesses in the position of ignoring explicit requests from consumers for privacy.
Unfortunately, nobody effectively capitalized on that.
if the EU regulators who wrote the cookie law had any competence, this is how it would have been implemented. browsers should have a cookie prompt in the UI, not websites.
A browser level opt-in would be even more useless than a website prompt. Demonstrably almost no end users understand what they opt in to, and that type of contract should therefore carry close to zero weight.
A browser feature to control cookies wouldn't cover everything the law does.
Getting rid of it for being "ignored" is ignoring that it is a means for the User to signal to the rest of us they do not wish to take part in tracking. Which in our world, is the important bit. A provider not being challenged with this bit can argue that the user doesn't mind being tracked because they didn't explicitly say so.
Mozilla is being a complete moron.
Firefox has implemented the replacement, Global Privacy Control. It has the exact same problems and isn't respected either, except even fewer websites have implementations that respect GPC.
It's not a real solution to the normalised cyberstalking websites practice today, but it's also not entirely useless.
DNT has legal standing in the EU, GPC has theoretical legal standing in the USA, where laws are more geared towards protecting data brokers. Removing a protocol because it doesn't work in the USA despite it being a legal opt-out in the EU is foolish; just send both headers, let local jurisdiction pick the which one is legally binding and which one can be ignored.
GPC has been standardised to never make it extendable beyond "Sec-GPC: 1" so there is no way for it to imply a set of choices in the future, without breaking backwards compatibility. The choices are limited by design.
1. assume the user by default does not want to be tracked and make do-not-track opt-out.
2. have it running for a few years and gradually increase the heat on the discussion that nobody respects it.
If it would've been done this way it would've been newsworthy and maybe would've been considered as something to enforce via regulation (at least in EU).But as it stands do-not-track never had a chance to succeed - I believe that was by intention.
proof is that musk first and only feature added to shitter post purchase fiasco was to detect firefox anti tracking feature and block the user! the fact the most shrewd person in the world acted on it is perfect proof it worked againt his goals (which now we know was to influence elections)
I would say this needs to start with a law, more or less.
In that light removing it might push a few people to apply more protections to their browser and be an overall (if extremely minor) win for privacy.
Although, anti-tracking in general is basically fighting a losing battle. Go to https://amiunique.org/ and you'll see why. I use Firefox with all possible protection mechanics -- "strict" tracking protection mode, uBlock origin, yet I cannot escape first-party tracking.
One striking example: These days browsers may expose how many cores your device's CPU has to websites. That alone could eliminate 80%-90% of users. Combined with user agent, IP, language etc you are pretty much uniquely identified.
https://developer.mozilla.org/en-US/docs/Web/API/Navigator/h...
Low script rather than no script, if you will.
The goal shouldn't be to appear non-unique. There are too many little things that will out you. Even if you somehow account for every single one of them today your next browser update could enable more and you can't trust that amiunique.org is looking at every identifying data point either. It's an arms race you're going to lose.
What you want is to be differently unique for each website you visit. Even better if you have JS disabled by default and sites can't collect 90% of the data points your browser exposes at all. The best protection you could get would be to change up IP addresses via VPN and randomize your user-agent and other tells.
There's two gigantic issues with that:
1. Most websites won't work
2. Most people like websites to work, and so they have JS turned on. If you don't, you'll stick out like a sore thumb.
Sticking out like a sore thumb isn't a problem as long as you look like a different person's sore thumb to the next website.
Being consistently unique is okay as long as the tracking party is simply generating programmatic hashes. But if you're always unique, but in a specific way, it doesn't matter. The total amount of entropy matters.
> I wouldn't even attempt online shopping without JS,
So, a nonstarter for basically all normal internet users.
I feel like DNT was a "rushed" (i.e. with no legal backing) attempt to achieve the latter.
This information could be determined prior to the introduction of navigator.hardwareConcurrency.
I published a timing attack polyfill that derives this information and initially proposed the navigator.hardwareConcurrency API as a replacement for this timing attack polyfill.
In addition to the fundamental utility of this API, browser vendors also saw implementing this as a way to save battery life by making it no longer necessary for websites to benchmark user devices to determine this value.
Transcend Consent Management's default configuration opts users out of every unessential tracking purpose (and suppresses automatic consent prompts) whenever DNT is enabled, but only opts users out of "Sale/sharing of info" when only GPC is enabled.
Removing this centralized privacy signal means some users cannot express full opt outs to Transcend Consent Management by default without having to interact with annoying banners.
I believe this change was steamrolled without taking in proper consideration and feedback from the web community. Mozilla made this change so fast that barely anyone noticed the issue before it got closed[1]. To add insult to injury, they've configured their Bugzilla to disallow further comments from non-Mozilla employees after issues are closed.
I shared similar feedback with the Chrome team in 2023 when they were proposing to remove DNT[2]. They considered my feedback and currently DNT is still in Chrome, with its removal indefinitely postponed.
It doesn't, because nobody respects it.
It is actually harmful to have a feature that misrepresents its efficiency to users, especially when it comes to privacy and security.
Nobody should ever feel that they will not be tracked because they enabled do-not-track, because it's wrong.
Removing it is the right thing to do because of this.
Edit: I just saw that Firefox supports GPC, which seems a better alternative to DNT.
GPC is also not intended to limit a first party’s use of personal information within the first-party context (such as a publisher targeting ads to a user on its website based on that user’s previous activity on that same site).
GPC also appears to use the same tracking signals as DNT, so it has the exact same potential for abuse, as far as I can tell. Maybe I'm missing something, but unless there's legal power behind this, I'm not sure if it's better.
The other option, Mozilla should have done, is shame companies that did not respect it. A continually updated list, a notification when browsing a site that did not, etc, but the problem comes from this being a vendor issue and that it would not be 100% accurate.
Shaming is the only way this would have worked out, but they didn't, but for the ones who did this out of being a decent organization, they now no longer have a standard to base it on.
~ genuinely curious about statics on the subject.
They could have stood up a regulatory-ish body, or group, that organizations could sign onto, and/or an accreditation organization that does audits to ensure they are following DNT.
Could have also done the simplest thing, the most error-prone, but still something tangible, and said "If you support DNT, add it a DNT-HEADER tag, and if it comes out that an org as using it and didn't follow it, then we will name and shame you". Just like we did with forcing HTTPS, the red icon did the heavy lifting there.
The decision to /not/ do so, seems to be a choice they willingly made, because all three of those options are potentially obvious security and methods of 'protecting the \'net' or 're-wilding the \'net' while also adding another revenue stream to ensure they have the financial bandwidth and personel to make This A Thing, as it should be.
There's better ways to protect your privacy that don't rely on a best effort voluntary flag that you send to advertisers and hope they accept it.
Separately, privacy signals are being required by law in some regions. If we're going to have browser level privacy signals in the first place, we might as well support and use them as intended.
Major sites like Geizhals.de actively use it.
It's been ruled to legally be considered rejection of tracking by German courts (Az.: 16 O 420/19)
Does every feature need 100% market share to be viable?
- Legal backing: Unlike DNT, GPC is supported by more laws, like the CCPA, which requires businesses to honor these signals.
- Targeted approach: While DNT broadly addressed tracking, GPC focuses specifically on stopping data from being sold or shared, making it more relevant to today’s privacy needs.
- Better adoption potential: GPC was created with input from regulators, privacy advocates, and industry leaders, to align it with existing laws and address previous gaps in functionality.
But essentially, it's more or less the same.
So it seems it's less "Firefox removes DNT" and more "Firefox deprecates earlier ineffective version of GPC".
Because it's off by default? It's the exact same thing, a header with a preset value.
> While DNT broadly addressed tracking, GPC focuses specifically on stopping data from being sold or shared, making it more relevant to today’s privacy needs.
My needs are not being tracked. The tracking is what comes before the selling. I don't want to opt out of selling, I want to opt out of tracking.
> Better adoption potential: GPC was created with input from regulators, privacy advocates, and industry leaders, to align it with existing laws and address previous gaps in functionality.
"Gaps in functionality"? The difference between GPC and DNT is that DNT sends "DNT: 1" and GPC sends "Sec-GPC: 1".
Companies that never respected DNT aren't going to respect GPC. The only difference here is that IE doesn't have GPC enabled by default, but it does have DNT enabled by default.
It depends. While I agree that GPC is technically just a more complicated form of DNT, the major difference is that DNT is 100% optional for websites to honor, which is why they don't, but GPC becomes mandatory for nations that have reasonable laws around tracking. Companies operating in those nations will honor it because there are legal penalties if they don't.
The California Attorney General ruled that if a user presents a GPC signal, the company should update all of their backend systems to opt out of tracking in the same way as if the user clicked a "Do Not Sell My Personal Information" button.
Legal backing obviously isn't reason enough for Mozilla to support a feature.
And GPC isn't even compatible with GDPR.
So instead of sending the header:
DNT: 1
Firefox will now optionally (via a different setting than was used for DNT) send:
Sec-GPC: 1
I'm unclear on why anyone thinks this is a useful change. As a website owner who previously implemented anonymization code activated in the presence of a DNT header, I guess I can add code to also look for Sec-GPC, but this feels like churn for the sake of churn.
It also feels ridiculous that Mozilla can't just send both headers if the same browser preference is checked, rather than requiring websites to look for both. I get that they want stronger promises around "Sec-GPC" than around "DNT", but the latter is a subset of the former, so why not update the client-side checkbox description, and then send both?
Perhaps now we can get something more robust in the works.
Contrary to popular believe the EU has somewhat defined what that means (just read the law) and surprise: The way many datahogs wish it to be, isn't how the law was written.
E.g. if you trick or extort users into agreeing, consent was neither given informed nor freely. In front of the law it is as if you haven't asked for consent at all and GDPR fines can be up to 4% of the global turnover of the previous fiscal year. But yeah.
When (major advertiser/website detected): Prompt user, "Warning: (Advertiser/website) insists on tracking you, and have made public statements affirming this position. Your privacy is not enforceable on this website."
It's a tough position to be in because the thing that really gets heads turning is regulation, licensing, and fines, but...when it comes to website design (assuming we're not talking about illicit material) I get queasy at the idea of (the/any) government saying, "You're not running your website the right way! Pay us money!" Perhaps the few exceptions being something like: PII storage, or payment processing.
I dread the idea of anyone saying you have to, say, use a specific font type or whatever, you know? I don't want to put that burden on website owners, or complicate my own life.
I'd rather inform the end user, point out the biggest offenders, and leave them be. "Detect, inform, and move on." Big scary message[2] then leave it to the user to decide what they want to do. "Oh, they're going to track me? Let me look up that VPN-thingy I keep hearing my nephew talk about."
[1] https://news.ycombinator.com/threads?id=registeredcorn#42380...
That wouldn't fly in the EU though because tracking is supposed to be opt in so enabling by default is fine.
The only way that anything like this can possibly succeed is through legislation.
So rather than eliminate it with another thing that is nothing more than a name changes, it should just become useful
It would be nice to have a feature for enable/disable javascript per site also.
The conflation of semantics isn’t worth it, and may even be harmful. I totally disagree with the proposal.
https://cybernews.com/tech/germany-court-bans-linkedin-from-...
They support GPC because it has legal backing by the california attorney general, but remove DNT because it's only supported by German courts?
Want to stay logged in? Press the "keep the cookies for this domain" button by the url bar, and a separate cookie jar will be made just for example.org and persist there.
The EU does not require the use of "cookie prompts".
User consent is required to process a user's data for certain purposes+.
That may involve the use of a cookie, or it may not.
Whatever technological methods you use to process the user's data, and regardless of whether it happens on the client or server, you must ask for consent.
Having a system where cookies are not remembered between sessions would be no use, as the user's consent would still be needed while those cookies were set.
+Not everything needs consent, but things like tracking for advertising or analytics typically does. Even if you do it via IP address or local storage, you need to ask for consent - nothing to do with cookies.
I have never noticed any kind of acknowledgement from any website I've visited in years with Firefox and this option on.
I want to do something to help signal "No thank you, I don't want this" messaging so the "harms user agency" feels relevant but if its not respected on the other end whats the point.
By consequences I mean a percentage of their revenue vs profit which can be waved away by accountants is seized, donated to people affected by shady companies and all the leaders of the company must be marched through cities by shame nuns whilst citizens are permitted to throw rotten food and excrement at them. Anything short of this would just be the cost of doing business.
As Mozilla likes to tell everyone, Firefox is open source. Wonderful. But making it easy for more users to edit the source code and compile it is not on their list of important things to do.
Removing or adding an HTTP header is a trivial change anyone can make in the source code of any browser. Perhaps all the Firefox forks will keep the DNT header. They certainly could if they wanted to.
NB. I am not suggesting whether anyone should or should not use DNT. I have no comment about DNT. Rather, I am making a point about the lack of user control over inclusion or exclusion of (open source) browser "features", specifically HTTP headers.
You can't expect people to willingly support a feature that diminish their revenue, it was doomed from the start.
I think everyone with a brain cell could predict that, in my opinion mozilla would have better allocated resources on feature that are client side, not server side.
For instance the containerization of cookies, the support of mv2, integrating ublock origin by default, and so on.
Any other Brave users? Brave definitely causes issues on sites and shields have to be turned off. And, it's painful if not impossible to whitelist a whole domain, it's by host, which is completely annoying. But Brave does its job well.
Any other Brave users?
How do you compare Firefox+ ublock origin on mobile?
I'm an android user FWIW
One of the basic tenants of contract law is “last writer wins”. If I say “here’s a contract”, and then you make amendments to it, sign it, and then I sign it, the amendments are part of the contract.
It is legally obvious that “Do Not Track” should be incorporated into the user agreement for the web site.
https://wideangle.co/blog/do-not-track-gdpr-opt-out
While highly uncommon, there were legal grounds to treat it as strong opt-out signal.
Like it might make all their tries of cookie/tracking alternatives meaningless.
https://consentomatic.au.dk/ - automagically denies consent to GDPR banners https://ublockorigin.com/ - the one and only https://decentraleyes.org/ - skip tracking CDNs
Since you are said a lot of websites do you have any examples? I have actually encounter more problems with Safari than Firefox.
This is spurious reasoning. "Many" is neither a percentage, or a basis for justification. Many people ignore speed limits - so what?
>The company recommends using the Global Privacy Control setting as an alternative to prevent websites from tracking user data.
>If you wish to ask websites to respect your privacy, [...] [t]his option is built on top of the Global Privacy Control (GPC). GPC is respected by increasing numbers of sites and enforced with legislation in some regions.
Increasing numbers? But then that means that "'Many' websites ignore it", right?
This reeks of early movements towards monetization of their shrinking userbase. It's genuinely disappointing. I used to like Firefox, and continue to use Thunderbird today. Good luck to the stragglers who decide to stick it out.
From a product perspective, this is an additional option in their settings page that is confusing and marginally useless. I work on creating user facing products as my job, and I 100% support this decision.
I'll be honest: nobody is going to stop Firefox because of this, because it does not affect their life in any way or manner.
I do agree with your point on people continuing to use Firefox in spite of this. Most people are not invested in the details, or don't care about security/privacy, or can't be bothered to figure out which other browser option is best for their use case.
My annoyance is more so on their behalf - that average people will probably be unaware of what security feature is being taken away from them. Do they care? Probably not. Will it change much for them? No. It irks me, however, that they no longer even have the option.
I think the major point is that they don't have the option right now. The percentage of websites that honor DNT is a rounding error, so the existence of it -- at best -- gives the illusion of privacy protection. In my opinion, the illusion of security is worse than not having security but knowing it.
Referring to my previous comment: "This is spurious reasoning. 'Many' is neither a percentage, or a basis for justification. Many people ignore speed limits - so what?" Privacy configurations are not a popularity vote. Instead, they are an implementation of software design. E.g. "No one" bothers with PGP, therefore it should be supported.
A more charitable description of DNT, instead of saying it is "not an option" would be that it is a privacy option that is poorly enforced - exceedingly so!
I will of course agree wholeheartedly that the effectiveness of that privacy option, which is independent of its implementation and design, is ineffective. I also agree that it has a theoretical potential to give a user "false optimism", because of its failure of enforcement, but I don't see that second point as being inherently harmful.
I suppose it comes down to whether you want to take a pill that has "reduced effectiveness" at fighting pancreatic cancer, or if you prefer the several seconds saved in not needing to swallow. In my mind, even if the pill sucks and has a failure rate of 99.7/100, it seems bizarre to snatch it away from someone who would like to take it anyway.
DNT is not shilled by some privately-owned company that claims it will somehow, "Make users invisible online for the low, low price of (money)!" Instead, it is simply an HTTP header that some (many) websites ignore, or outright maliciously exploit for personal gain.
Computer Operating systems are not "false advertising" simply because certain programmers ignore standard practices outlined by the maintainers. It is not the fault of an Operating System if programmers refuse to adhere to the documentation on how something should be implemented. It's certainly not a sensible justification for Operating Systems "needing to go", just because people write bad or malicious software to abuse an OS's weaknesses.
To be clear, I am hardly saying DNT is a good option, precisely because so many websites have ignored or abused it in the past. I am simply saying DNT should be an option, and that it should be one that is enabled by default.
>If you can find someone and successfuly sue them for not honoring it great - but you still need to do a lot more (sue many others in many countries).
If DNT is removed as being an option, what need would there be for such a law to be created in the first place? You said you support the idea of a law being made - shouldn't you be for DNT remaining, then? I hope that doesn't mischaracterize your point but it's a little confusing, it sounds like you're saying you: support the premise of DNT, want a law to enforce DNT...and you don't want DNT as a configuration option in Firefox.
The problem is that there is no, and can be no enforcement mechanism. Unless you live behind a great firewall of [country] or are only accessing the web through your employer's corporate network.
Operating a motor vehicle on public roads requires a license and vehicle registration in most jurisdictions. These rules are not always observed, but there are enforcement mechanisms in place.
There is no website licensing body, and kind of can't be without making everything worse.
Returning to the point, I suppose the question might be what enforcement would even look like, as you mentioned. Some governmental organization ala DMV? Seems excessive. A professional organization of some sort, similar to IEEE? Probably not. Perhaps just a "watch dog" organization like a sister organization to the EFF, specifically focused on reporting which sites honor, and dishonor DNT.
Personally, I would prefer the last, with some kind of check that could help indicate in the browser visually to the user whether the site honors DNT. Similar to (or tied into) the lock symbol for HTTPS would be nice. Outside of that, it seems like such a niche and fringe thing that, unless enabled by default, would fall on deaf ears. I don't see myself endorsing some kind of financial penalty, simply because I think it would hurt small websites. And also because website stuff is confusing and stressful enough already. I personally think a kind of visual "name and shame" to the end user, along side improved support to support DNT would be optimal.
I.e. Hot dog on a stick in one hand, dog poop on a stick in the other hand.
Reading through the Wikipedia article, it sounds this is largely what was already done with DNT, and failed. https://en.wikipedia.org/wiki/Do_Not_Track#History
...And subsequently, GPC began to act in a way that I'm not thrilled about. https://en.wikipedia.org/wiki/Do_Not_Track#Global_Privacy_Co... It comes off reeking of a pretext to confine the nature of how websites, and the internet at large, are allowed to operate.
You can use an extension to set the header if you really want it. I think that's an okay level of difficulty for something so misleading and ineffective.
I will stop using Firefox because of this.
Many German sites actually follow DNT, because German courts only recently ruled DNT to be legally binding.
Mozilla removing a feature that has even gotten legal support has to be an absolute clown take.
start with uBlockOrigin and i-don't-care-about-cookies and you have the world most privacy respecting browser with zero downside.
Mozilla buying out an adtech company: https://blog.mozilla.org/en/mozilla/mozilla-anonym-raising-t...
Mozilla has also been lending its credibility and whitewashing Meta's "PET" measuring standards at W3C. More on this, from Mozilla: https://blog.mozilla.org/en/mozilla/privacy-preserving-attri...
iykyk