3 ms·
> Or the risk of offending the biggest source of funding? I (a Mozilla employee) can understand why people worry about this, because there does seem to be a co
by briansmith 14y ago
> Or the risk of offending the biggest source of funding?
I (a Mozilla employee) can understand why people worry about this, because there does seem to be a conflict of interest here. But, I've never seen anything to indicate that we consider Google's payments to us in any security/privacy decision.
DNT is not the ultimate solution to tracking on its own. It is part of a solution.
Consider this:
Let's say you go buy a box of doughnuts and take it to work, open it, and leave it open on a table next to your desk. Some people will think "Hmm, I want one of those doughnuts but I'm not sure if it is OK to take one, so I won't" and other people will just assume that it is OK to take one. (Why else would there be an open box of doughnuts? And/or isn't it better to ask forgiveness than permission?)
Let's say you write "Do NOT take these doughnuts! They are mine!" on the box with a big fat marker. If somebody were to take a doughnut, they would be clearly in the wrong in that situation, according to any kind of mainstream social convention.
Lots of people will say that it is wrong to take a doughnut without explicit permission. But, many, many people see the situation as being open to interpretation.
Now, let's say the doughnut shop pre-printed "Do NOT take these doughnuts! They are mine!" on every box. You might argue that that is the same thing as the hand-written sign. But, I would bet that the pre-printed message would get drowned out as people would normally share doughnuts out of these pre-printed boxes: "Just ignore the box, they all say that; it doesn't mean anything." The pre-printed message becomes less and less meaningful, even though the words are clear, unambiguous, and explicit. And, worse, you may be discouraged from writing your handwritten ""Do NOT take these doughnuts! They are mine!" message on the box because, well, the box already says that. Effectively, that message pre-printed on the box is harmful, as its meaning is in the eye of the beholder--just like the open box sitting on the table with no message written on it at all.
Do you see how that could possibly be problematic? This is the problem that Sid and others at Mozilla are trying to solve. "DNT: 1" means it is clearly wrong to track this user because they've gone through special effort to tell you they don't want to be tracked.
It has nothing to do with Google's money.
- cremnob 14y agoWhy not have the user decide the first time they launch the browser? They either choose to enable DNT or not.
- chii 14y agothe user don't care at that time - they probably have something more urgent to look at the first time they run their browser, and if you bombard them with questions, it gets annoying. I agree with the default being ON (that is, DNT is turned on). The analogy with the doughnuts and pre-printed message isn't quite accurate in this case, because it is _clearly_ a better choice to not have tracking done on the user, whilst with a box of donuts, its not always clear cut whether sharing it or not is the right thing to do.
- anonymous 14y agoEvery OS comes with a browser other than firefox by default (except certain flavours of Linux, but they could make the choice part of the install process). If the user needs to look at something on the internet right now, they won't go searching for firefox, downloading and installing it. Having one simple checkbox that takes half a minute to decide on won't make installs take all that longer. Or just display a configuration page the first time the browser starts up with a "you can set all these later too from <here>, btw" message.
- briansmith 14y agoThat is a very good question/suggestion. It is a good idea to make the option easier to find. I definitely think it is important to educate more people about the issue. There may some validity to the idea that "the journey is part of the gift"--that is, the harder the option is to find, the stronger the signal of user intent. But, I don't think the current balance in Firefox is correct. I'm not sure that a checkbox at startup is the right answer either. if you ask on Mozilla's dev-privacy mailing list [1], you might get a response from some somebody that has thought about it more than me. Then I'll get to learn about it too. [1] https://lists.mozilla.org/listinfo/dev-privacy https://lists.mozilla.org/listinfo/dev-privacy
- just2n 14y agoLet's make this a bit more accurate. Consider a world where your box of donuts WILL have donuts taken out of it, even if the box is closed, as soon as you walk away from the donut shop. As soon as you hit just about any website on the internet today, YOU WILL BE TRACKED. There's no maybe here, it's a virtual certainty. So this makes it accurate in your analogy. In this world (call it Doughnet?), it makes sense to have the donut shop print a sign on the box in the event that the sign is sufficient to prevent people from ambushing you and taking your donuts. You could simply ask the donut shop to give you a blank box if you wish to have your donuts taken (opt-in donut sharing) rather than asking them to give you a box with the sign (opt-out donut sharing). Nobody expects to have their privacy maliciously and constantly invaded. This is emphatically WRONG behavior. And so broadcasting to all parties that the user of your browser is willing to be tracked by default is precisely the wrong thing to do. I don't care what your motivations are, it's just wrong, period.
- briansmith 14y ago> Nobody expects to have their privacy maliciously and constantly invaded. This is emphatically WRONG behavior. Nobody is disagreeing with either of those two statements. Like I said, DNT isn't Mozilla's final or only answer to the tracking problem. > And so broadcasting to all parties that the user of your browser is willing to be tracked by default is precisely the wrong thing to do. No browser does such a thing. Anybody that infers that the lack of a "DNT: 1" header implies that it is OK to track the user is using faulty logic. See http://en.wikipedia.org/wiki/Argument_from_ignorance#Absence_of_evidence http://en.wikipedia.org/wiki/Argument_from_ignorance#Absence.... Back to my analogy: I never said it was OK to take a doughnut without explicit permission. I just said it was obviously bad to take one when there is an explicit message saying it is bad to take one.