8 ms·
I still haven't heard a cogent explanation of what this is supposed to do. "Do Not Track" sounds nice, but seems no easier to scope than the initial problem of
by willscott 14y ago
I still haven't heard a cogent explanation of what this is supposed to do.
"Do Not Track" sounds nice, but seems no easier to scope than the initial problem of excessive information collection. I think it's safe to say that I want companies to 'track' me in order to keep me logged in for a session. Likewise, I hope that my bank keeps logs of visitors, so that it can respond to abuse / hacking attempts. Is this aimed only at behavioral advertising, or is it meant to have a broader scope?
It seems like the technical execution is almost misguided without having the policy discussion first and figuring out what it is we disagree with. Without that, I don't feel like this is going to draw a strong enough line to separate people abusing tracking from the legitimate uses.
- zobzu 14y agoDo not track me for advertisement, statistics, etc. is the intent.
- __ted__ 14y agoEnding your list with etc. undermines your point. With this header set, can my site track what pages a user views to recommend pages to him later? Can compliant sites keep stats for engineering purposes? Grandparent is dead-on - it's bad enough that this does not affect the behavior of bad actors, but if it isn't even clear what effect it will have on good ones, the false sense of security may be worse than nothing.
- zobzu 14y agoKey word is "intent". Privacy != security. Close, but not quite.
- nl 14y agostatistics WTF? So analytics packages will somehow have to exclude these browsers from all reports? Some reports? Can you count impressions from these users?
- zobzu 14y agoHow that's "wtf"? If I don't want companies to make statistics using what I do that sounds perfectly legitimate to me. Now then again DNT is an intent, the vendor does whatever he likes, and can support DNT for other features and still have statistics. There's no list of things you can do or not do. There's no agreement either. It's just the user indicating that they don't want to be tracked in any way.
- einhverfr 14y agoIt's a wtf because you can't draw any good lines on statistics. Web server admins have legitimate reasons to track (i.e. log) all requests to some extent against their web sites. We have good tools to help analyse a lot of this. Consider a real world equivalent. Suppose you walk into a bookstore and buy a book with cash. The store might not be able to track you individually but they can track how many people visited, how many books they sold, etc. You can't say that's not legitimate. So I could see an argument that the line that should be drawn is one that involved tracking cookies, but that is quite a narrow exclusion regarding statistics of individual users. You can still get pretty good stuff from the access log and there's no case to be made that DNT means Do Not Log.
- zobzu 14y agoStatistics != "logging" Then again anyone is free to track/not track, stat/not stat (so far at least) and only "not track" subset of their data (as long as they don't lie) Then again there's a few privacy-aware websites who do logging and some stats but on pseudonymized IPs which is also a pretty decent compromise.
- einhverfr 14y agoBut what about mining statistics from logs?
- gpvos 14y agoThe intent is to enable users to "opt out of tracking by websites they do not visit, including analytics services, advertising networks, and social platforms". So you can have an analytics package on your site and do everything you mention, but you cannot offload your statistics gathering to yoursitename.statistics.net, which can track the user across websites, because the users are visiting your site, not statistics.net. A hypothetical and largely incorrect real-life analogy: you can use cameras to recognize regular clients and keep statistics on them, but you cannot send the camera images to another company to have them processed, because your clients are visiting your store, and not that other company. (This analogy is largely incorrect because camera images are more privacy-sensitive than cookies, and different legal and moral issues are involved, but there's still a similarity.)
- einhverfr 14y agoDoes that mean the access_log should omit visitors who set this header? Does this mean log analysis tools should omit such records in the logs? I am confused as to how this works for statistics purposes.
- deleted 14y ago[deleted]
- commonersense 14y agoIs there any evidence to support your worry? Because there is ample evidence that good content was available through the internet and later the web, before it was permitted to be used as a commercial vehicle and long before the web became laden with cheap advertising.
- deleted 14y ago[deleted]
- throwaway55-33 14y ago"No, there's no evidence to support my worry." OK, thanks.
- deleted 14y ago[deleted]
- deleted 14y ago[deleted]
- throwaway64 14y agothis is a load of crap that gets repeated again and again, please stop. advertising existed before every move you made was tracked, and it was quite profitable. There is zero reason that such invasive bullshit is a requirement. HN user fauigerzigerk put it best: I would like to agree with your idea of tracking as payment, but I really can't, because: a) Most of the time I don't have a choice. There's no option to pay them money and even if I pay them directly, they may still keep collecting tons of personal information about me on top of it. b) It's sneaky. I don't really know what information they have and how they use it. I just have a couple of completely meaningless words from their privacy policy. c) I don't know the price I'm paying. The last point is the most important one. The value and the risk associated with a particular piece of information greatly depends on what other information it is combined with, but I can't control that. The company could get acquired tomorrow by some ad behemoth that knows a lot of other things about me, so the price I'm paying could change after the fact. That's not the way payment works. I have to know the price I'm agreeing to pay before I enter that contract. https://news.ycombinator.com/item?id=3751905 https://news.ycombinator.com/item?id=3751905
- fizx 14y agoFrom http://donottrack.us http://donottrack.us: "Do Not Track is a technology and policy proposal that enables users to opt out of tracking by websites they do not visit, including analytics services, advertising networks, and social platforms." Emphasis on "websites they do not visit" directly, meaning that it only applies to iframes, popups, etc. If you typed it in the address bar, or clicked on a link to get there, the site isn't limited by DNT. This is not legal advice.
- smashing 14y agoI don't know what legal ramifications could follow sites which declare they support Do Not Track as a spec but in actuality do not support any of the features of the spec in a meaningful way. Other than just bad press if discovered, I don't think there is any punishment for not properly following a technical spec outside of civil lawsuits.
- thwarted 14y agosites which declare they support Do Not Track as a spec but in actuality do not support any of the features of the spec in a meaningful way Seems that it's like P3P[0], in that it causes problems for developers but in no way keeps a company from asserting things that they don't actually follow, and there's no way to verify that they are. [0] http://en.wikipedia.org/wiki/P3P http://en.wikipedia.org/wiki/P3P
- fizx 14y agoThe FTC would likely investigate, if you had a non-trivial number of users. You really don't want this.