3 ms·
Pardon me, your first couple of paragraphs are confusing -- are you sure you're not mixing up opt-in an opt-out? "Opt-in" would mean that by default -- with no
by randomwalker 16y ago
Pardon me, your first couple of paragraphs are confusing -- are you sure you're not mixing up opt-in an opt-out?
"Opt-in" would mean that by default -- with no action on the user's part -- tracking would be prohibited. Clearly that is infeasible (for precisely the reasons you describe; it would kill the industry.)
While the proposal is about opting out of "third party web tracking", it is not obvious what a third party is. Is a YUI, Google Analytics, or Facebook Connect plugin which I chose to integrate into my site "third party code"? What if I have a business account with something like Crazyegg.com -- can I put their JS heatmap tracking in my webpage to figure out what buttons my users are getting confused by?
Yes, these are exactly the questions that me and my colleagues are working out. The goal is to avoid breaking the web as much as possible. For example, one way in which an exception to Do Not Track is triggered is if the user logs in to the 3rd party provider, so FB Connect will work smoothly regardless of DNT.
If this is complex for hackers, do you trust the government that thinks the internet is a series of tubes to get this right?
Great point, which is why things are structured the way they are -- the idea is for Congress to delegate authority to the FTC, which is a highly tech savvy organization (they just tapped Ed Felten, for example). They're also great at getting input from the technical community (I was myself on an FTC privacy panel earlier this year.) In short, hackers are quite involved with the process.