Live data from Hacker News

IE10's 'Do-Not-Track' Default Dies Quick Death

wired.com

31–40 of 67 posts

Re: IE10's 'Do-Not-Track' Default Dies Quick Death

#31
post #22
post #5

Earlier quoted context omitted.

So don't forge your headers. I don't see how this would be slippery at all.

The parent's point is that some of those IE10 users aren't just stuck with a default, they really did intend to turn DNT on.

Which is why DNT makes zero sense to be on by default.

Re: IE10's 'Do-Not-Track' Default Dies Quick Death

#32

An issue sidestepped by this article is whether the statement in the second paragraph is correct: > ... tech and ad companies who say they comply with Do Not Track could simply ignore the flag set by IE 10 and track those who use that browser. That doesn't quite work. Web servers don't know what browser is on the other end of a connection. Yes, they know the "User-Agent:" line, but that is not the same thing. Claimin…

Yea, the whole idea of "They are not following part of the spec so we can treat them differently" seems like a sketchy argument.

Is there a clearing house for certifying browsers as DNT compliant? Or can the websites just say "Oh, THAT browser? Well I don't think it is DNT compliant so I am going to ignore the DNT headers even though they are perfectly to spec"

Re: IE10's 'Do-Not-Track' Default Dies Quick Death

#33
post #7
post #3

The whole concept of DNT is just stupid. It's misleading users and won't work. By telling users you have better privacy simply because your browser adds a random header tag onto requests you're misleading them. Sites have no obligation to obey it and it will give users a false sense of security. We already have proven, well defined method of DNT already: private browsing. This works by simply removing resources after…

> Sites have no obligation to obey it and it will give users a false sense of security. Until appropriate legislation comes into play. It worked reasonably well with the Do Not Call lists.

As if that would be appropriate or necessary to solve whatever privacy problems we have.

It's the U.S. government trying to take anonymity and privacy away from the Internet; do we want them making weak, unenforceable, irremovable laws on how to implement an HTTP header?

Re: IE10's 'Do-Not-Track' Default Dies Quick Death

#34
post #27
post #12

What is the situation if a user agent, on installation/upgrade, asks a user to update their DNT status but in doing so defaults to on? The user has to explicitly agree to turning this setting on (as they have to accept the configuration before proceeding), and is able to turn it off, but most people will just click through anyway.

If too many people turn on DNT websites will start ignoring it.

Most websites will just ignore it from day 1 anyway.

Re: IE10's 'Do-Not-Track' Default Dies Quick Death

#35
This is sad. DNT is may be a good thing.

Whenever you visit a website with an ad, DoubleClick knows you looked at that article, and uses that to build a profile about your preferences. I don't think when your average joe reads an article that it is fair that their preferences are being tracked in this way.

We should survey the public and ask: "Do you think it is okay that internet ad companies use the type of article you read to target ads that are more likely relevant to you?"

That is a reasonable question that gets to the crux of the issue. Retargeting and profile targeting may be borderline unethical, but Google and I both make good money doing it. I am not sure it is right, but we both have a vested interest in making sure we can continue.

Re: IE10's 'Do-Not-Track' Default Dies Quick Death

#36
post #9

Turning on DNT by default is a great way to ensure it will be utterly ignored. So I quite support the requirement that people explicitly enable it. Remember the DNT is voluntary - but if everyone does it by default, then there is nothing left to track, so websites will have no interest in paying attention to the flag.

> then there is nothing left to track Isn't that the whole point? Websites may not have interest in tracking disabling policies, but a lot of people do. Maybe these advertising companies ought to incentivize users to opt-in to sell their data instead of the other way around.

The users already are getting tons of free content, and on the android platform, free apps.

Re: IE10's 'Do-Not-Track' Default Dies Quick Death

#37
post #5

An issue sidestepped by this article is whether the statement in the second paragraph is correct: > ... tech and ad companies who say they comply with Do Not Track could simply ignore the flag set by IE 10 and track those who use that browser. That doesn't quite work. Web servers don't know what browser is on the other end of a connection. Yes, they know the "User-Agent:" line, but that is not the same thing. Claimin…

So don't forge your headers. I don't see how this would be slippery at all.

Does the DNT standard require that User-Agent strings correctly reflect the browser? [1] Guaranteeing a site follows DNT means that it will follow it, not that it will follow it only if headers are not forged.

Also, is "forging" really a dishonest thing in this instance? Browsers have been making themselves look like other browsers for years, in order to deal with stupid servers that make incorrect assumptions about the User-Agent string.

[1] Not a rhetorical question. I don't know the answer.

Re: IE10's 'Do-Not-Track' Default Dies Quick Death

#38
post #7
post #3

The whole concept of DNT is just stupid. It's misleading users and won't work. By telling users you have better privacy simply because your browser adds a random header tag onto requests you're misleading them. Sites have no obligation to obey it and it will give users a false sense of security. We already have proven, well defined method of DNT already: private browsing. This works by simply removing resources after…

> Sites have no obligation to obey it and it will give users a false sense of security. Until appropriate legislation comes into play. It worked reasonably well with the Do Not Call lists.

Yeah, because the Internet is american. In fact, all the servers are in Kentucky.

Re: IE10's 'Do-Not-Track' Default Dies Quick Death

#39
post #19

Earlier quoted context omitted.

> then there is nothing left to track Isn't that the whole point? Websites may not have interest in tracking disabling policies, but a lot of people do. Maybe these advertising companies ought to incentivize users to opt-in to sell their data instead of the other way around.

Yes, that is the whole point. Those people who are interested can send the Do Not Track header to indicate the preference. By sending it even when the user didn't indicate that preference, IE would have been the Boy Who Cried Wolf. Network owners wouldn't has been able to trust the header to indicate actual user preference.

I think you are conflating two problems - setting to off by default is also setting a default user preference - that the user wants to be tracked. This may or may not be the case - whether the default is on or off that will be the majority setting since most people don't know / dont't care enough to change it.

I think a couple other posters here have pointed out the larger problem - without ads like this, the free internet dries up and suddenly you need to start paying for everything from gmail to facebook (or whatever other tools/blogs/webcomics any of us visit).

Re: IE10's 'Do-Not-Track' Default Dies Quick Death

#40
post #26
post #16

Earlier quoted context omitted.

The whole business model is that users don't care if they're tracked, so let's track them (and others) and do things for them that we couldn't before I can see Google fully implementing DNT on the basis that users don't care, and for the few that do they're happy to comply But making it default to on, especially if no one gives a damn is the death knell to the whole business model Suddenly you have to pay for everyth…

> Suddenly you have to pay for everything. I wonder if we'll see sites who honor the header, but require that it be off in order to access content.

Na.. that will be too much work for the user, plus disabling DNT will mean it's disabled for everyone, not just the said website. It also does not make alot of sense, disabling DNT does not make site any money directly. So it will only raise suspicion in a casual user's minds, that why would the site need to track him/her when there is no apparent monetary profit to the site.

Instead they can show a banner that DNT is enabled and when it is disabled, the banner is gone.

Post reply on HN