Live data from Hacker News

Do Not Track is not respected on mozilla.org

bugzilla.mozilla.org

71–80 of 113 posts

Re: Do Not Track is not respected on mozilla.org

#71

There's a large effective difference between "do not track" as it is outlined in the bug, and how many people see it (see, for example, comment 16 in the report, and then comment 25) Specifically, it's to do with third party cookies, not any particular site. If I visit someone's website, I'm usually perfectly happy for them to record my visit and my actions. If, on the other hand, I visit their website and some invis…

I usually use an analogy to explain this. Tracking via first party cookies is like walking into a store that uses security cameras. I have even seen boards that inform the visitors that the store is under surveillance. Generally, the security camera is only monitored/used by the folks running the store.

Third party cookies are like as if the security camera is monitored and used by a random third party company who you are not even aware of. This is why it is bad.

Perhaps we should have a standard badge/button to indicate first party and third party tracking - something like https://www.safetysignsupplies.co.uk/images/product_imgs/ful... for first party cookies and a more "evil" version for third party cookies.

Re: Do Not Track is not respected on mozilla.org

#72
post #4

Earlier quoted context omitted.

>> I have a right to track how people use my site. But you don't have a right to say what runs on my computer, or make it tell you what I'm doing. This is where our perceived rights collide. >> once you've made that choice you are within my domain, under my roof, living by my rules. No, my computer, my browser, my roof, my rules. >> People get way too offended by analytics tracking when it's there for their benefit.…

>> I have a right to track how people use my site. > But you don't have a right to say what runs on my computer, or make it tell you what I'm doing. This is where our perceived rights collide. Exactly! But you also don't have the right to tell him not to send tracking info either. You do, however, have the right not to execute it. For instance NoScript, Ghostery,and AdBlock+ will prevent the requests for this content…

>> I think OP meant that once you make a request to his server, his server is free to do what it wants with that request.

I don't think they did mean that -

"But you've politely requested that I don't track you. For starters this should only ever be a polite request, not a forced rejection of any tracking scripts. I have a right to track how people use my site."

"People get way too offended by analytics tracking when it's there for their benefit."

It looks to me like they're saying that if you go to their site you have to run their scripts regardless of your own wishes, and that you're 'under his roof' and will therefore do what he says.

>> You can't possibly believe that his storing access logs is wrong.

No, I don't, that would indeed be silly! I believe that it's rude to try to demand people run your code, and if you do demand it then we need to find a way for me to tell him up front that I'm not going to, so he can decide if he still wants to send me the page data.

Re: Do Not Track is not respected on mozilla.org

#73
post #4

Earlier quoted context omitted.

>> I have a right to track how people use my site. But you don't have a right to say what runs on my computer, or make it tell you what I'm doing. This is where our perceived rights collide. >> once you've made that choice you are within my domain, under my roof, living by my rules. No, my computer, my browser, my roof, my rules. >> People get way too offended by analytics tracking when it's there for their benefit.…

>> I have a right to track how people use my site. > But you don't have a right to say what runs on my computer, or make it tell you what I'm doing. This is where our perceived rights collide. Exactly! But you also don't have the right to tell him not to send tracking info either. You do, however, have the right not to execute it. For instance NoScript, Ghostery,and AdBlock+ will prevent the requests for this content…

> Exactly! But you also don't have the right to tell him not to send tracking info either. You do, however, have the right not to execute it. [...]

You're right about both parties' rights. However, dealing with the "Most Trusted Internet Company in Privacy" [1], I expect them to do better than to insist each their rights to the letter. With regard to this discussion, as a novice user, I'd expect Mozilla /not to track me/. No ifs, no buts -- Do Not Track ought to skip all third-party tracking and remove any of my identifying data from their logs as soon as reasonably possible.

[1] http://blog.mozilla.org/theden/2013/02/06/mozilla-is-most-tr...

Re: Do Not Track is not respected on mozilla.org

#74
post #60

Earlier quoted context omitted.

None: the website requires explicit opt-in permission to collect personal data in the first place, making opt-out DNT largely irrelevant. e.g. from http://www.theregister.co.uk/2012/01/27/time_running_out_for... [Peter Hustinx, the European Data Protection Supervisor] said that the DNT system "although valuable" seemed to "fall short of the" of the requirements for obtaining lawful consent set out in the EU's Privacy…

None: the website requires explicit opt-in permission to collect personal data in the first place, making opt-out DNT largely irrelevant. It's nowhere near as simple as that, either in theory or in practice.

Can you be more specific?

In practice, I agree there are several problems: it is common industry practice to ignore data protection concerns (led by example of large US corporations) and EU member states have neither the intent nor the means to enforce the law. What's more, the recent cookie directive debacle makes the EU seem confused and toothless.

In theory, however, data protection seems pretty clear to me: http://europa.eu/legislation_summaries/information_society/d...

Intended reform makes the situation even more clear: http://ec.europa.eu/justice/newsroom/data-protection/news/12... I particularly recommend "How will the data protection reform affect social networks?", which discusses the requirements of 'privacy by default' and 'privacy by design'.

Re: Do Not Track is not respected on mozilla.org

#75
post #4
post #3

Do Not Track is silly. For example: You come on to my site, I want to know how you're using it, I don't want your personal details, I just want to see how you're interacting with the site I've made for you. Why do I want to know? Well it depends on the purpose of the site, but for the most part it is so that I can optimise and improve what my site offers to you and others. But you've politely requested that I don't t…

>> I have a right to track how people use my site. But you don't have a right to say what runs on my computer, or make it tell you what I'm doing. This is where our perceived rights collide. >> once you've made that choice you are within my domain, under my roof, living by my rules. No, my computer, my browser, my roof, my rules. >> People get way too offended by analytics tracking when it's there for their benefit.…

Client and server, guys. A web browsing experience is a cooperative endeavor that occurs on property controlled by both the host (web server) and the visitor (user agent).

At a fine-grained level, different aspects of that experience can be said to occur specifically on client or server. Each of those aspects can be constrained or manipulated by the respective property owner.

When it comes to preferences of the visitor for certain server actions (or inactions), one can only make a request. This isn't a grand moral point, or a technical one, but one of basic property rights and personal freedom. And such a request is what the DNT header signifies.

Likewise, when the server has preferences for certain user agent actions (such as running JavaScript or storing cookies) again it can only request that this occur since the user agent can typically disable JavaScript or cookies. This is what certain HTML metadata elements and the Set-Cookie header signify.

If visitors are unhappy with the behavior of a server, they can avoid it. In aggregate, such avoidance can become a significant market force. At the same time, a website that does no analytics for DNT visitors and has a high ratio of DNT visitors may also become less competitive and valuable over time. Both can feedback into respective preference consideration. This is ultimately the meager value of DNT. It (combined with adequate education) provides extra context data that can motivate through market forces an adjustment to web browsing norms.

Along the lines of "adequate education", the option in Firefox should read "Tell websites to restrict their tracking of me. __(Learn more.)__"

Practically, how would you know in advance if a server will respect your DNT preference without first visiting the site? Well, in real life, how do you know whether someone who invites you over for dinner won't serve you poison? One way is through trusted third-parties, but the market hasn't yet demanded such a service (and may never).

Re: Do Not Track is not respected on mozilla.org

#76
post #74

Earlier quoted context omitted.

None: the website requires explicit opt-in permission to collect personal data in the first place, making opt-out DNT largely irrelevant. It's nowhere near as simple as that, either in theory or in practice.

Can you be more specific? In practice, I agree there are several problems: it is common industry practice to ignore data protection concerns (led by example of large US corporations) and EU member states have neither the intent nor the means to enforce the law. What's more, the recent cookie directive debacle makes the EU seem confused and toothless. In theory, however, data protection seems pretty clear to me: http:…

Businesses collect personal data without explicit consent all the time. Think of records when you buy something by card, for example. Not only is the subject of the data not required to give explicit consent for keeping a record of this transaction, but they also have no right in law to have such data deleted, and indeed businesses may not be able to delete it within the law given their obligations to maintain adequate tax records. If you pay for something by card, it's implicit that you agree to this.

For something closer to the tracking we're talking about, it is normal to maintain server logs that show visits to your site, and to record various information that is voluntarily sent by browsers as part of HTTP requests. There's obviously some debate about how much IP addresses represent personal identification, but clearly in practice they can identify individuals under some circumstances. That doesn't mean someone has to ask you for permission to see your IP address when you visit their site, because obviously that would make no sense technically.

Obviously there are implications to keeping some of this data or using it for other purposes, but as I said, this is where things aren't always clear even in theory. Some issues really are black and white, but you quickly get into what is fair or reasonable or implicitly permitted by data subjects and what is crossing that line and should require explicit consent.

In practice, it's even worse, because we have silly things like the infamous EU cookie rules that are almost universally disliked by users (they make the experience of using web sites worse), almost universally ignored by business (who don't want the overheads of implementation and don't want their users' experience to be worse), and as far as I know universally unenforced by regulators (who would in many cases have to start by going after their own governments for flagrant violation). While possibly well-intentioned, such poorly conceived rules just bring data protection law into disrepute while alienating almost everyone. They also demonstrate that realistically there are few risks to flagrantly ignoring the rules as a business, which is hardly going to help with promoting good practice.

Re: Do Not Track is not respected on mozilla.org

#77
post #3

Do Not Track is silly. For example: You come on to my site, I want to know how you're using it, I don't want your personal details, I just want to see how you're interacting with the site I've made for you. Why do I want to know? Well it depends on the purpose of the site, but for the most part it is so that I can optimise and improve what my site offers to you and others. But you've politely requested that I don't t…

> I have the right to track how people use my site.

lol no you don't. You're choosing to respond to HTTP requests to your site, you put it out in public. I'll make whatever requests I want to your site and do whatever I want with what you give me, which may include rendering some or all parts of a "web page" as I see fit. If I give you some data in turn, sure, do what you want with it.

Do Not Track is silly because it's based on trust. I don't trust you to not track me even if I ask you not to. The only privacy is when I choose not to send you data (and I shouldn't, and browsers are horrible in this regard, they have failed their users).

Re: Do Not Track is not respected on mozilla.org

#78
So maybe the text in the UI jut needs to be changed to be more accurate. Instead of "Do Not Track", something along the lines of "Request No Tracking Across Sites" or "Request No Cross-Site Tracking". This clarifies that it isn't the browser stopping tracking, it is the browser asking the sites not to, which they may or may not implement. It also clarifies that what is being requested not to happen is using the same identifier across sites and between different parties.

On an unrelated note, I'm really impressed with the Persona login on that site. When I first saw it I thought, oh no, not another username and password. Why can't they just use social login where I already have accounts? But all I had to enter was my gmail address, approve the usage, and I was done. No extra username and password even though I've never used Persona before. No need to confirm an email. It worked out really well.

Re: Do Not Track is not respected on mozilla.org

#79
post #10
post #8

Earlier quoted context omitted.

> No, my computer, my browser, my roof, my rules. I think of websites like private properties. You are given conditional access on the assumption that you can behave (T&C / AUP), otherwise it's like trespassing. So, I don't think that people should expect excessive rights of freedom that they might have on their own property or even in public. It's a balancing act.

That's really not how I think, nor does it really reflect reality, IMHO. They are on my property, it's all rendered and running in my browser on my device. All that's happened is I've requested some data from the server and they've given it to me, from then on how I display it and what gets run is entirely up to me. If we want to attach terms and conditions to it (i.e. to use this site you must accept analytics/track…

Look, let's try an analogy. I run a shop, you want to come into my shop, you want to physically bring yourself into my shop, with your personal items, including your wallet and let's say a bag to help you purchasing items, or perhaps just to browse.

I'm going to keep an eye on you as I see fit whilst you are in my shop. Surely you can see that as fair?

You are an agent entering my property. This is what your computer does when you access my site.

I can extend this further. You have your wallet, you make a purchase, I have a till I record the purchase and even give you a receipt of the purchase, so that you can come back and we can both agree that you've been here before. So you come on to my site and you click on a download, I record the event through Google Tag Manager, which shoots it across to Google Analytics, and I even give you a cookie, useful for both of us. Next time you come to the site perhaps that cookie will mean I hide the download button from you, or it shows another related download to you.

Feel free to rip up the receipt, or delete the cookie, you're messing with the accepted way of doing things and harming yourself as well as me, but please go ahead you're free to. But please try to understand that not everyone is out to get you, I'm not trying to 'spy' on you, I couldn't care less about you as an individual. I'm trying to optimise for the whole, for my business, for my clients. I have no evil agenda, and if I did you wouldn't be able to stop me because evil finds a way.

The social contract exists, it is established, and it is incredibly close to how physical suppliers of products and services work. You live your life allowing businesses to track your movements within their physical domains, so why have a double standard for virtual domains?

Don't pretend for a moment that because my 'shop' is rendering at your physical location that you aren't in fact virtually visiting me. You want something from my 'shop'? I want to know how you interact with my 'shop' It's really as simple as that.

Your logic damages good, honest people, instead of cutting to the actual problems. Things like Do Not Track and whining about tracking being invasive is simply attacking the symptom and not the root cause. It's like demanding a ban on horses because the cowboys harassing your town all ride them. It does bugger all but damage everyone else whilst the cowboys/evil people just ignore your ban or find another way. Please see logic.

Post reply on HN