Live data from Hacker News

Do Not Track is not respected on mozilla.org

bugzilla.mozilla.org

81–90 of 113 posts

Re: Do Not Track is not respected on mozilla.org

#81
post #75
post #4

Earlier quoted context omitted.

>> I have a right to track how people use my site. But you don't have a right to say what runs on my computer, or make it tell you what I'm doing. This is where our perceived rights collide. >> once you've made that choice you are within my domain, under my roof, living by my rules. No, my computer, my browser, my roof, my rules. >> People get way too offended by analytics tracking when it's there for their benefit.…

Client and server, guys. A web browsing experience is a cooperative endeavor that occurs on property controlled by both the host (web server) and the visitor (user agent). At a fine-grained level, different aspects of that experience can be said to occur specifically on client or server. Each of those aspects can be constrained or manipulated by the respective property owner. When it comes to preferences of the visit…

>> When it comes to preferences of the visitor for certain server actions (or inactions), one can only make a request.

Absolutely. But the OP seemed to be saying that it was his right as the server owner to make me run his tracking scripts on my end.

If I have the wrong end of the stick then great, I'll shut up, but he seemed to be saying that clients don't get to go to his site and then reject his use of analytics by (for instance) refusing to load the scripts. I find that attitude quite objectionable.

I think it's his right not to provide site content for people who refuse to run his scripts, that seems perfectly reasonable, it's his site and his copyright material. I'd be perfectly happy for my initial request to have a header that says "By the way, I don't run analytics, social network widgets or graphical advertising". Then everyone is informed and everyone has a choice.

Re: Do Not Track is not respected on mozilla.org

#82
post #10

Earlier quoted context omitted.

That's really not how I think, nor does it really reflect reality, IMHO. They are on my property, it's all rendered and running in my browser on my device. All that's happened is I've requested some data from the server and they've given it to me, from then on how I display it and what gets run is entirely up to me. If we want to attach terms and conditions to it (i.e. to use this site you must accept analytics/track…

Look, let's try an analogy. I run a shop, you want to come into my shop, you want to physically bring yourself into my shop, with your personal items, including your wallet and let's say a bag to help you purchasing items, or perhaps just to browse. I'm going to keep an eye on you as I see fit whilst you are in my shop. Surely you can see that as fair? You are an agent entering my property. This is what your computer…

>> You are an agent entering my property. This is what your computer does when you access my site.

No, no it does not. I'm not in your shop. I'm in my house. I requested some data from you, your server provided it. I'm under no obligation to do anything with that data at all, let alone allow you to execute arbitrary code on my computer because you feel like it's your right to.

It's closer to mail order, both in fact and in statute (remote selling regulations etc). You know I've ordered the catalog, you don't get to know it lay open at page 23 for half an hour or that I spent 15 minutes staring at the underwear models.

>> You want something from my 'shop'? I want to know how you interact with my 'shop' It's really as simple as that.

Cool, turns out I don't want it that badly that I'll allow my machine to tell you everything about what I'm doing, so if purchasing from your shop is conditional on you getting to run this code, do us both a favour and block my access.

>> Your logic damages good, honest people, instead of cutting to the actual problems. Things like Do Not Track and whining about tracking being invasive is simply attacking the symptom and not the root cause. It's like demanding a ban on horses because the cowboys harassing your town all ride them. It does bugger all but damage everyone else whilst the cowboys/evil people just ignore your ban or find another way. Please see logic.

You make the sweeping assumption here that it's ok to collect as much data as you like for purposes you think are good.

I disagree.

--edit-- let me make this very clear: I don't care in the slightest why you want to collect analytics data, I'm not interested in taking part and I won't allow my computer to leak information constantly.

Re: Do Not Track is not respected on mozilla.org

#83
post #42

Earlier quoted context omitted.

>> You already have control over this. That doesn't contradict someones right to track how people use the site. >> And again, you already have control over this. However, if you give data to a remote server, they have the right to use that data. You are, in fact, giving them that data. I think we may be talking at cross-purposes. The post I replied to says that they have a right to run tracking scripts and I don't ha…

> I think we may be talking at cross-purposes. The post I replied to says that they have a right to run tracking scripts and I don't have the right to reject them. This is what I disagree with. Yep, I saw that. Maybe it's just my interpretation. I thought of that as saying "I have the right to have scripts that track you." Not "I have the right to require that you run those scripts." So, they can provide the scripts,…

>> Not "I have the right to require that you run those scripts."

Unfortunately the OP has just popped up again to say exactly that.

Re: Do Not Track is not respected on mozilla.org

#84

"Do not track" in its present (non-)state is a farce. It should be implemented at the browser level. My ideas on DNT: If a user specifies "do not track" in their browser-global or site-specific settings then ALL requests to third party domains should simply be blocked. This could be backed up by a site-provided manifest (potentially containing a comment for each ones justification, or a flag to say if its required or…

Yeah, DNT is kind of silly. It's like someone read the evil bit RFC (http://www.ietf.org/rfc/rfc3514.txt), thought it was a good idea, and implemented it at the level of HTTP.

Re: Do Not Track is not respected on mozilla.org

#85
post #15

Earlier quoted context omitted.

>> His website. Running in my browser. >> On the other hand demanding of publishers to not track you while you're on their property is unreasonable. I'm not on their property. I'm fairly happy for them to record what they can see at their end in terms of what pages I go to, but I find it very unreasonable to demand that I run whatever code the website operator asks me to run, to turn my computer into a machine that r…

If you don't like it, don't use it - simple as that. The only thing I find reasonable is for users to be warned that they are tracked, precisely for enabling them to move to alternatives that better respect their wishes. His website is running in your browser by your choice, not his ;-)

Then return an error when requests with the DNT header are made. You can't expect people to magically know ahead of time that your website is being used to spy on them.

Re: Do Not Track is not respected on mozilla.org

#86
post #83

Earlier quoted context omitted.

> I think we may be talking at cross-purposes. The post I replied to says that they have a right to run tracking scripts and I don't have the right to reject them. This is what I disagree with. Yep, I saw that. Maybe it's just my interpretation. I thought of that as saying "I have the right to have scripts that track you." Not "I have the right to require that you run those scripts." So, they can provide the scripts,…

>> Not "I have the right to require that you run those scripts." Unfortunately the OP has just popped up again to say exactly that.

Well, that's not something the OP can expect. After all, that's not the way HTTP and associated technologies work. Regardless, it's a shame. Not that it changes what I said (at least, within the context of my understanding).

Anyways, I'm preaching to the choir.

Re: Do Not Track is not respected on mozilla.org

#87
post #51

Earlier quoted context omitted.

Something to consider. In Firefox, the DNT options have a Learn More link that answers the question: "Do Not Track is a feature in Firefox that allows you to let a website know you would like to opt-out of third-party tracking for purposes including behavioral advertising. It does this by transmitting a Do Not Track HTTP header every time your data is requested from the Web." While you can debate whether that's the a…

Then rather than call it "Do not track," it should be called something like "Do not allow third party tracking." When in doubt about naming something, name it what it is.

The problem is, DNT isn't just a Firefox thing, but something that the industry is attempting to adopt. So, DNT as a whole means something specific. It's a shame that there is that disconnect, but it's not a Mozilla specific problem.

Safari says even less about DNT (Ask websites not to track me) and the help isn't much better, though they have a separate section for blocking 3rd party cookies. But that's different from DNT.

This is a case where DNT as an industry standard means one thing to the industry, and one thing to the uneducated public. Damned if they do, damned if they don't.

Re: Do Not Track is not respected on mozilla.org

#88
post #81
post #75

Earlier quoted context omitted.

Client and server, guys. A web browsing experience is a cooperative endeavor that occurs on property controlled by both the host (web server) and the visitor (user agent). At a fine-grained level, different aspects of that experience can be said to occur specifically on client or server. Each of those aspects can be constrained or manipulated by the respective property owner. When it comes to preferences of the visit…

>> When it comes to preferences of the visitor for certain server actions (or inactions), one can only make a request. Absolutely. But the OP seemed to be saying that it was his right as the server owner to make me run his tracking scripts on my end. If I have the wrong end of the stick then great, I'll shut up, but he seemed to be saying that clients don't get to go to his site and then reject his use of analytics b…

> he seemed to be saying that clients don't get to go to his site and then reject his use of analytics by (for instance) refusing to load the scripts. I find that attitude quite objectionable.

Yeah, it's perfectly fair and reasonable to have that attitude.

Practically speaking, something like the Collusion extension/add-on or Disconnect extension/add-on allow you to forcefully constrain a wide range of "tracking" activities preferred/requested by the server.

Re: Do Not Track is not respected on mozilla.org

#90

Earlier quoted context omitted.

> No, my computer, my browser, my roof, my rules His website. Seriously, people should be warned that they are tracked, the purpose for which they are tracked and what exactly is tracked. Google Search for example is giving warnings lately, that you have to manually dismiss (probably because of EU laws) and I view that as being progress. On the other hand demanding of publishers to not track you while you're on their…

Actually, I can use your site and benefit from it, while simultaneously blocking your ability to track me. It's called Ghostery (and similar browser extensions). I use Ad-Block Plus and Ghostery for all my web browsing, and have both Ad-Block Plus set to block _all_ ads and Ghostery set to block _all_ tracking scripts. These extensions do not make 'polite requests'; they directly control the browsing experience to my…

You do know that sites will track you without javascript or ads? As well, do you browse without cookies and images, as those extensions will not help you there? And without session IDs in URIs, since you seem to want the web to return to byzantine times?

> I believe the outcome will be a better business model for sites to make money

Sites will make less money without use of cookies, images, and support of encoding sessions into URIs. You ARE welcome to use the web without these things, but it is going to mean you are not a customer of many entities, because your kind are vanishingly small in number.

You might be interested in the Firefox section of http://crunchbang.org/forums/viewtopic.php?id=24722, if your serious about your privacy and security.

Post reply on HN