3 ms·
Removing this feature harms user agency. This will result in Firefox users having to deal with more annoying consent prompts. Transcend Consent Management's de
by Sephr 2y ago
Removing this feature harms user agency. This will result in Firefox users having to deal with more annoying consent prompts.
Transcend Consent Management's default configuration opts users out of every unessential tracking purpose (and suppresses automatic consent prompts) whenever DNT is enabled, but only opts users out of "Sale/sharing of info" when only GPC is enabled.
Removing this centralized privacy signal means some users cannot express full opt outs to Transcend Consent Management by default without having to interact with annoying banners.
I believe this change was steamrolled without taking in proper consideration and feedback from the web community. Mozilla made this change so fast that barely anyone noticed the issue before it got closed[1]. To add insult to injury, they've
configured their Bugzilla to disallow further comments from non-Mozilla employees after issues are closed.
I shared similar feedback with the Chrome team in 2023 when they were proposing to remove DNT[2]. They considered my feedback and currently DNT is still in Chrome, with its removal indefinitely postponed.
1. https://bugzilla.mozilla.org/show_bug.cgi?id=1928087 https://bugzilla.mozilla.org/show_bug.cgi?id=1928087
2. https://issues.chromium.org/issues/41440843#comment12 https://issues.chromium.org/issues/41440843#comment12
- iLoveOncall 2y ago> Removing this feature harms user agency It doesn't, because nobody respects it. It is actually harmful to have a feature that misrepresents its efficiency to users, especially when it comes to privacy and security. Nobody should ever feel that they will not be tracked because they enabled do-not-track, because it's wrong. Removing it is the right thing to do because of this.
- deleted 2y ago[deleted]
- shaky-carrousel 2y agoThat nobody respects is is a false statement. Some do. Also that header permits users to signal sites if they want or not to be tracked, avoiding cookie popups. Edit: I just saw that Firefox supports GPC, which seems a better alternative to DNT.
- bluGill 2y agoBut others use it as a signal. You are easier to track by the dishonerable with it. Meanwhile the honerable were probably not tracking as much [no way to tell but a reasonable guess]
- joveian 2y agoYou might be easier to track with it, but it is not hard to end up with a unique signature anyway. I can already be uniquely identified, so sending "Do Not Track" only has potential upsides. I have seen websites that claim to honor it so it seems to be doing something and I wish they wouldn't remove it.
- mossTechnician 2y agoI looked into GPC, and I'm not sure if it's much better. From the implementation notes[0]: GPC is also not intended to limit a first party’s use of personal information within the first-party context (such as a publisher targeting ads to a user on its website based on that user’s previous activity on that same site). GPC also appears to use the same tracking signals as DNT, so it has the exact same potential for abuse, as far as I can tell. Maybe I'm missing something, but unless there's legal power behind this, I'm not sure if it's better. [0]: https://w3c.github.io/gpc/ https://w3c.github.io/gpc/
- drannex 2y agoCounter: It does, because some organizations and webmasters did respect it. The other option, Mozilla should have done, is shame companies that did not respect it. A continually updated list, a notification when browsing a site that did not, etc, but the problem comes from this being a vendor issue and that it would not be 100% accurate. Shaming is the only way this would have worked out, but they didn't, but for the ones who did this out of being a decent organization, they now no longer have a standard to base it on.
- jessyco 2y agoWhere is this information about respecting come from? What tools or metrics do we have out there to observe it was being respected or not? Is it your feeling or do you have anything to back up what you're saying? ~ genuinely curious about statics on the subject.
- drannex 2y agoNo idea, which is why I mentioned it's a vendor related issue. They could have stood up a regulatory-ish body, or group, that organizations could sign onto, and/or an accreditation organization that does audits to ensure they are following DNT. Could have also done the simplest thing, the most error-prone, but still something tangible, and said "If you support DNT, add it a DNT-HEADER tag, and if it comes out that an org as using it and didn't follow it, then we will name and shame you". Just like we did with forcing HTTPS, the red icon did the heavy lifting there. The decision to /not/ do so, seems to be a choice they willingly made, because all three of those options are potentially obvious security and methods of 'protecting the \'net' or 're-wilding the \'net' while also adding another revenue stream to ensure they have the financial bandwidth and personel to make This A Thing, as it should be.
- dewey 2y agoThat it should exist because one (and there's probably not many) consent managers actually understands and uses this flag is not a strong point in support of that feature. There's better ways to protect your privacy that don't rely on a best effort voluntary flag that you send to advertisers and hope they accept it.
- Sephr 2y agoAgreed that users need more baseline protections. Separately, privacy signals are being required by law in some regions. If we're going to have browser level privacy signals in the first place, we might as well support and use them as intended.
- kuschku 2y agoMany consent managers and analytics tools support and use it. Major sites like Geizhals.de actively use it. It's been ruled to legally be considered rejection of tracking by German courts (Az.: 16 O 420/19) Does every feature need 100% market share to be viable?