Live data from Hacker News

Twitter abandons 'Do Not Track' privacy protection

zdnet.com

31–40 of 160 posts

Re: Twitter abandons 'Do Not Track' privacy protection

#31
post #15

Earlier quoted context omitted.

My solution is to change the DNS settings in my router to set all domains for Facebook to 0.0.0.0. So, *.facebook.com 0.0.0.0 I'm sure the same could be done with Twitter. This ensures that they cannot track you on e.g. a news site or any other site with a "share" feature. But... This only works if you're willing to entirely live without Facebook/Twitter. Probably not the best choice for the majority of people.

That assumes that all facebook ad traffic starts with a DNS request for *.facebook.com. It may be that all facebook ad traffic is served in this way _today_, but that doesn't stop them from changing it tomorrow. What about other ad networks? What about other ad networks where you like to use part of their services (eg google.com)? What about ad networks that serve their content from a cloud provider? Blocking domains…

> That assumes that all facebook ad traffic starts with a DNS request for *.facebook.com

This is true, which is why you need a better list. Like one of these:

https://github.com/StevenBlack/hosts

(There are lots of others out there if one of those doesn't suit your fancy.)

These things will never be perfectly inclusive, but they whack the vast bulk of the commercial surveillance shops, and have the great benefit of not being prone to bypass from browser/extension exploits.

They also cut the flood of garbage down to a point where it is possible to individually see what bugs are getting through and do something about them.

You're right that they're a partial solution, but they are a massively helpful one.

If you're going to use one, do glance over the list to make sure you understand what you're blocking.

Re: Twitter abandons 'Do Not Track' privacy protection

#32
post #16

It's interesting how Microsoft killed DNT - by supporting it. Once they made it the default, it was all over. It was so obvious that doing so would kill DNT that I have to wonder if they did that on purpose. It's definitely an interesting way of stopping something you don't like - support it to such a degree that those who asked for it don't want it anymore.

[deleted]

Re: Twitter abandons 'Do Not Track' privacy protection

#34
post #9

DNT made sense only in a world where there would be some sort of law to back it up. I actually had my adblocker turned off on websites I knew at least tried to respect DNT (reddit, medium and twitter), guess twitter's getting completely adblocked now.

I have no issue adblocking Twitter since they use deceptive ads.

It used to be ads had to be clearly labelled as not to confuse with regular content. Twitter buries their "promoted" label at the bottom in light grey text, so you only know it's an ad after you've read it and asked "WTF? Why is this in here?"

Re: Twitter abandons 'Do Not Track' privacy protection

#36
post #15
post #8

Earlier quoted context omitted.

You may be blocking ads, but your ad blocker can't prevent the site from tracking you.

My solution is to change the DNS settings in my router to set all domains for Facebook to 0.0.0.0. So, *.facebook.com 0.0.0.0 I'm sure the same could be done with Twitter. This ensures that they cannot track you on e.g. a news site or any other site with a "share" feature. But... This only works if you're willing to entirely live without Facebook/Twitter. Probably not the best choice for the majority of people.

In case you genuinely want to block Facebook via DNS, check this discussion nearly a year ago:

https://news.ycombinator.com/item?id=11791052

Re: Twitter abandons 'Do Not Track' privacy protection

#37
post #9

DNT made sense only in a world where there would be some sort of law to back it up. I actually had my adblocker turned off on websites I knew at least tried to respect DNT (reddit, medium and twitter), guess twitter's getting completely adblocked now.

I wonder if the major adblockers should have whitelisted the DNT-respecting sites by default.

They haven't for most cases but to be fair, even if the publisher would respect DNT, it doesn't mean that the ad-server at the end of the line or any of the other partners will.

Re: Twitter abandons 'Do Not Track' privacy protection

#38
post #28
post #16

It's interesting how Microsoft killed DNT - by supporting it. Once they made it the default, it was all over. It was so obvious that doing so would kill DNT that I have to wonder if they did that on purpose. It's definitely an interesting way of stopping something you don't like - support it to such a degree that those who asked for it don't want it anymore.

This. If any Good citizen site ever thought about honoring DNT they got their plans crushed when Microsoft did this. It was a silly proposal from the start but a hopeful one. Hopeful that people would do the right thing. The web was always built on assumptions that the other side would do the right thing in that context DNT was not so silly. This one failed. Because Microsoft didn't do the right thing. They decided t…

I think you're putting too much blame on Microsoft here. DNT was always garbage, the fact that as soon as anyone used it (it becoming default for IE being the push in this case) it would fall apart just shows that it was always doomed.

Shouldn't not being tracked be the default? Shouldn't we be opting into targeted ads, not out of them? Seems reasonable, if DNT weren't garbage, to have it be on by default. But it was garbage and so it was never really any help to anyone anyway.

Really, everyone should just install an adblocker, and whitelist sites that are non-invasive, don't track, and that you want to support. Then the responsibility isn't on advertisers not to track us, it's on citizens to whitelist sites that they genuinely should be supporting.

Re: Twitter abandons 'Do Not Track' privacy protection

#39
Commenters are confusing ads versus tracking.

Remember that it is possible to track users without the use of ads.

A browser written by an organization that profits from ad revenue or collecting user information (hereafter "well-known browser") will load elements, e.g., images, in a web page automatically.

No user interactivity is required. The user need not "click" anything. The user may not even be able to see the element loaded.

Email clients supporting HTML email can do the same thing, loading images automatically, hence suporting a method of tracking.

This is a very old method but still widely used.

What if the user is not using a "well-known browser"? What if those elements will not be loaded automatically? Will these methods of tracking still work?

All methods of tracking, other than IP addresses in access logs, rely on assumptions. Many rely on assumptions about usage of a "well-known browser".

The assumption re: automatically loaded elements, "beacons" or whatever one wants to call them, is that the user is using a "well-known browser" that will load elements automatically. If the user is not using a "well-known browser", all bets are off?

Another example is the HTTP header "fingerprint". HTTP headers are tied to "well-known browsers". What if suddenly all users decided to only send the same minimal headers? In the way that some server software might try to hide its version (e.g., BIND) imagine that users decided to hide their client software version.

Aside from IP addresses, many methods of web tracking are heavily reliant on assumptions about use of "well-known browsers" and the behavior of those browsers. Could these assumptions ever fail to be true? Can users think for themselves?

The www as a medium for exchanging information or even doing commerce does not necessarily require the use of any particular browser. That "requirement" is only imposed by certain sites on the www, for reasons that may ultimatley benefit the site owner more than its users. No such "requirement" is imposed by the www itself.

Thinking of this in terms of "a carrot and a stick", as far as I have seen using the www since 1993 there is only a carrot in the form of a "well-known browser". There is no stick. Users are free to make HTTP requests using any client they choose, including ones that do not expose them to advertising or tracking. Such clients may not require an "adblocker" because they do not requests elements automatically.

There used to be and perhaps there still is a never-ending battle between commercial entities over which is the "default browser" in a graphical OS. Certain companies tried to coax users into using certain "well-known browsers". There was even a large antitrust case in the US over this issue.

The implication seemed to be that if not set by default users might otherwise choose some other HTTP client to interact with the www. In those days one company wanted to sell a browser as enterprise software. Today that browser is owned by a "non-profit" organization of salaried employees. Other well-known browsers are owned by "for profit" (subject to taxation) commercial entities with thousands of employees.

Today, these well-known browsers are "free". And yet these browsers are written by salaried employees, not open-source project volunteers. These entities continue to market their "free" browsers aggressively to users.

As a user, ask yourself why.

Ads? Tracking?

Re: Twitter abandons 'Do Not Track' privacy protection

#40
post #28
post #16

It's interesting how Microsoft killed DNT - by supporting it. Once they made it the default, it was all over. It was so obvious that doing so would kill DNT that I have to wonder if they did that on purpose. It's definitely an interesting way of stopping something you don't like - support it to such a degree that those who asked for it don't want it anymore.

This. If any Good citizen site ever thought about honoring DNT they got their plans crushed when Microsoft did this. It was a silly proposal from the start but a hopeful one. Hopeful that people would do the right thing. The web was always built on assumptions that the other side would do the right thing in that context DNT was not so silly. This one failed. Because Microsoft didn't do the right thing. They decided t…

What a nonsense apologetic approach. Define "the right thing"? Blocking tracking by default sounds like the "right thing" to me. I'm not sure how "being a good citizen on the internet" became synonymous with "bending over to advertising moguls" or "thinking about the poor starving blogger who must partake in that advertisement tracking ad tech nonsense and blocking that is taking food from his kids". Advertising and tracking blocking has become a gatekeeper of democracy on the internet these days. Unfortunately, with the idiotic political direction in USA (and USSC), I wouldn't be surprised if politicians are not bribed to introduce legislation against blocking advertisement ("it infringes on first amendment of Coca Cola!"), followed swiftly by "America's interests" - much of Europe.
Post reply on HN