The Slow Death of ‘Do Not Track’
nytimes.com
nytimes.com
For blocking tracking, the most effective tools are browser extensions made to block ads. Ghostery provides comparisons on an non-biased website between the methods of blocking tracking through browser modifications [1]. According to the site, the Do Not Track header actually has an effect with a difference of 18% in cookie size when the header is set. AdBlock Edge and disabling third-party cookies results in a 59% and 40% decrease in cookie size respectively. It seems that the easiest thing you can do to lessen your internet footprint would be to disable third-party cookies and enable the DNT header, and the majority of tracking can be eliminated through the use of a browser extension. (But with the recent revelations [2], using a browser extension may actually reduce your browsing experience if you don't have the RAM to spare.)
[1] http://www.areweprivateyet.com/ [2] https://news.ycombinator.com/item?id=8802424
Call me a conspiracy theorist, but being a former CTO of an adserving company, I feel qualified to at least voice my opinion: this was a brilliant move by Microsoft. The DNT header as it were, was a perfect middle-ground for advertising companies: people that cared enough were able to opt-out, and people that did not care would still be able to be tracked.
Google had the most to lose. I feel Microsoft made this decision in order to (accelerate the) kill of the DNT header, and thus hoping on more severe legislation.
I'm not saying it's necessarily what happened with the DNT header, but they'd do well to avoid drawing too much attention to themselves in certain cases.
I would expect that a fuzzy hash of your ip,location,language settings,resolution, browsertype, average mousespeed, your computers speed to draw a circle, calc a prime etc etc etc will always identify you.
It used to be that sites could inspect the clipboard until we realised how bad for security that was. Perhaps mouse movement and/or timing information should be something that isn't allowed by default without granting the site additional permissions. Perhaps browsers could be set to stop sending many of the headers they currently send by default, or send approximations to reduce the uniqueness of the headers.
Regarding plugins, the best solution I have found is to have none enabled. Firefox still sends them in the list when using click-to-play, so it is necessary to disable them completely.
As to the plugin list, you could make it non-enumerable, but then one could just probe for the X most common ones, like can be done for fonts.
You are right that this gives more information to a determined person, but anyone who pushes fingerprinting to the point of detecting a user’s browser version and other characteristics through JavaScript will certainly be able to identify you uniquely anyway. In such a case, it doesn’t matter than this person has more or less information, since he can already identify you; and having a generic user agent makes people who only look at it know less about you.
p0f, for example, can do this.
If you trust javascript that little, just turn it off entirely in your browser and let the rest of the web be. You're far, far more at risk from the browser itself, plugins and apps than from javascript.
>The idea that any junk website is allowed to execute code on your machine without asking or even the user being aware is a fundamental security flaw.
That's not a bug, it's a feature.
Most of the web works fine, it does not break most sites the internet.
JS can be used to just do annoying crap, play sounds or videos, etc. I can choose to mute my entire browser or I can choose to not run JS on new sites until I approve of them. (This used to be more important before patches for js moving browser windows and the like)
While most JS wont break out of the browser in most cases, what you can do within the browser to determine where you have been, who you are, and (if you visit samy.pl) things like enumerating your local network or running a bitcoin miner with JS are possible.
While I agree with you in spirit, this doesn't seem to be true in practice. I also browse with JS turned off by default, and, in general, whenever I visit a new site, I often find it blank, or completely illegible. After allowing JavaScript for that site, I then often have to play a guessing game of what CDNs or other external resources I have to allow before anything will display. (For example, I was able to see weather on weather.com—hardly anyone's idea of a good Internet citizen, but the first one that springs to mind—simply by allowing JavaScript from their domain; but had to guess around quite a bit before I could get the settings icon to display.)
There were a time when the internet was about reading text, but that has long since passed. Without javascript you can't have a presentation overlayed with video (say of the presenter), you can't have real time anything, you can't comment without having to reload the page, etc. Look at how horrible the UX of HN is compared to reddit.
If plain HTML isn't good enough, it just means we need a better HTML.
Why is it arrogant? Surely "my site won't work with your browser settings" is not inherently an argument that I have to change my browser settings!
I mean, you can say "by browsing with JavaScript off, you kill the rich web", but I can also say "by refusing to make available a plain-text version of your site, you kill the information web" (with whatever appropriate buzzwords substituted for my ungainly ones). Many of the same arguments here could, I think, have explained why Flash is absolutely necessary for the modern web—until Apple's weight showed that it isn't.
E.g., even if you wear a burqa, you can still be tracked by the color of your sandals, the speed by which you move, the perfume that you use, etc.
Hence, the problem is probably best attacked by making appropriate laws that prohibit use of tracking information.
If we are goign to get something like Do Not Track, then it should have been drafted out of the public eye, had a nice short period for public comment and then recieved some sort of backing in law. Speculative implementations didn't really help.
I'm not too familiar with the laws surrounding things like 'do not call' lists and anti-spam measures, but some sort of system from that area of law could surely have been a part of DNT.
Cookie popups were stupid - cookies aren't really an opt-in system. DNT should have been an opt-out system for off-site tracking. If Facebook tracks you through a like button or Google tracks you through an ad/analytics after you sent then a DNT header, they get into trouble.
Maybe the header size effect DNT could have been mitigated by not sending it to sites with the same origin as the current page (or another origin policy that the website specifies).
I'm confused by this—how would drafting the law / specification / whatever out of the public eye have helped the process?
Sure, but so doing might carry its own risk—namely, no community investment once the proposal was released. A very consistent proposal by which no-one feels represented isn't necessarily an improvement!
The only real solution is client-side, and we have that technology now: hosts-blocking, Ghostery, AdBlock, etc. If enough people cared, it could be enabled by default on new browser installs.
Now, granted, it's technically far inferior to a DNT header (it sets a cookie on each ad network domain) but as far as I can tell it works and has worked for years.
Rather what I do is to blackhole the analytics servers with my /etc/hosts:
127.0.0.1 www.googleanalytics.com
127.0.0.1 www.heapanalytics.com
Unfortunately one must jailbreak mobile devices to get at their hosts files. I understand that Windows no longer uses it at all.Better would be to block the analytics services at the router, or preload a caching DNS server with them.
I also avoid "Log In With Facebook" &c. I don't register at a site unless it offers its own login facility.
Strictly speaking DNS is a protocol and not an API. Applications aren't required to perform name lookups by using any particular software, it's just common to use what the OS supplies.