Live data from Hacker News

Console Do Not Track – Proposal for a standard environment variable

consoledonottrack.com

71–80 of 352 posts

Re: Console Do Not Track – Proposal for a standard environment variable

#72
post #57

Earlier quoted context omitted.

> It's a doomed concept. Indeed, because it assumes developers who are doing opt-out tracking will respect this voluntarily. I disagree with the poster above about Debian adopting this. They shouldn't adopt DO_NOT_TRACK, they should ban any package that does tracking by default from their repo; in distros that already keep non-free software out of the standard repository this wouldn't be that much of a leap. This see…

> They shouldn't adopt DO_NOT_TRACK, they should ban any package that does tracking by default from their repo Debian maintainers are amazing and they go one step further: they patch it out when they distribute it. They also patch out old version time bombs and all manner of other phone-home.

> They also patch out old version time bombs

As an open source software developer, I do have some sympathy for the upstream devs here, and some frustration with distro maintainer policies. I'm not interested in getting a bunch of bug reports for issues that were fixed 4 years ago, or introduced because Debian maintainers "patched out" something they shouldn't have.

Re: Console Do Not Track – Proposal for a standard environment variable

#73

Of course, developers could say "Actually it's crash reporting, not tracking" or "Actually it's version checking, not tracking", so idk.

I'm hoping some of those developers will have to explain this in more detail to a DPA processing a GDPR complaint against them.

Re: Console Do Not Track – Proposal for a standard environment variable

#74
post #52
post #32

Bad-actors would ignore it wholesale anyway, so this at best gives one a false sense of privacy. It would probably be better _not_ to have it, since people won't be misguided into thinking they're not being tracked. An actual effective approach to privacy is to use a firewall to block all unwanted connections (allowlist only), and a DNS sinkhole like pi-hole. IMO we should get more on the more aggressive side when it…

I don't see why both solutions can't co-exist. If DO_NOT_TRACK suppresses the honest software (of which should be the majority you have installed anyway) then you have fewer applications left to manage manually / less network noise to identify and black. Saying an imperfect solution is worthless is a little like throwing the baby out with the bath water.

I seriously doubt marketing and advertising departments will care about standards, if they would even notice. The industry can't even manage with web standards, imagine trying to get scummy tracking companies to comply.

IMO it's not even an imperfect solution. I'd say performative, and past DNT efforts have failed, so why are trying this again?

Maybe a tool that lets one easily report software for GDPR violations? That would have more teeth.

Re: Console Do Not Track – Proposal for a standard environment variable

#76
post #64

Earlier quoted context omitted.

Can’t say I’m surprised that putting one day’s of work into getting the industry to adopt a proposed standard you came up with yourself didn’t really work out. Based on your other comments you also seem to have some level of contempt for some of the projects that you were trying to influence. Those probably didn’t help your cause.

Yes, contempt is an accurate assessment. Shipping nonconsensual spyware is unethical, and there are too many devs in our industry who are happy to behave unethically so long as their boss tells them to. Creating more social and reputational consequences for individual worker bees who make such commits on the job is also on my to-do list. Ultimately the opt out vars are token efforts by developers anyway. These projec…

What? You want to single out developers and public shame them? Yeah, that would totally work out. /s

Re: Console Do Not Track – Proposal for a standard environment variable

#77
post #64

Earlier quoted context omitted.

Can’t say I’m surprised that putting one day’s of work into getting the industry to adopt a proposed standard you came up with yourself didn’t really work out. Based on your other comments you also seem to have some level of contempt for some of the projects that you were trying to influence. Those probably didn’t help your cause.

Yes, contempt is an accurate assessment. Shipping nonconsensual spyware is unethical, and there are too many devs in our industry who are happy to behave unethically so long as their boss tells them to. Creating more social and reputational consequences for individual worker bees who make such commits on the job is also on my to-do list. Ultimately the opt out vars are token efforts by developers anyway. These projec…

> so long as their boss tells them to

What do you mean? The closed PRs are all for free and open source software. You seem to misunderstand their intentions and have a lot of entitlement.

Re: Console Do Not Track – Proposal for a standard environment variable

#78
post #27

"PRs and Status" is a very optimistic headline for a list of rejected pull requests. I like the idea, but the execution leaves a lot to be desired. I can understand why some Homebrew devs think it's just an attempt from someone to pad their resume. It's essentially a single person setting up a website, then submitting a bunch of untested pull requests to a bunch of projects. I imagine this would work much better if a…

Chicken and egg problem, naturally. I'd love it to gain more traction. It was an idea and I thought it would be better an idea and a website than just an idea. It was strange to see it get labeled as a marketing attempt during my attempts to gain some traction, considering I'm not selling a damn thing. I have severe focus issues, so it had to be a one-day project unfortunately, which is why a couple of the patches we…

[deleted]

Re: Console Do Not Track – Proposal for a standard environment variable

#79
post #33
post #32

Bad-actors would ignore it wholesale anyway, so this at best gives one a false sense of privacy. It would probably be better _not_ to have it, since people won't be misguided into thinking they're not being tracked. An actual effective approach to privacy is to use a firewall to block all unwanted connections (allowlist only), and a DNS sinkhole like pi-hole. IMO we should get more on the more aggressive side when it…

The approach I use is Little Snitch. It's how I discovered most of these telemetry misfeatures in the first place.

How do you trust Little Snitch?
Post reply on HN