Live data from Hacker News

Twitter abandons 'Do Not Track' privacy protection

zdnet.com

71–80 of 160 posts

Re: Twitter abandons 'Do Not Track' privacy protection

#71
post #13

Ok, honestly, was DNT ever more than a smoke grenade for muddying the privacy discussion? The standard always relied on every single shady data collector out there to act against their core interest, facing not even the risk of detection (let alone punishment) if they don't comply, all just because you asked them nicely. You might as well carry a "do not rob me" card in your wallet. Was there ever a honest belief by…

Ever seen those "here we'll be setting cookies because we're going to track you if you agree (agree/fuck off)" in Europe? A EU directive or something of the best intent mandates that when you're tracking someone beyond technical needs this boilerplate is required before setting a cookie. Guess what if you disagree there's no way to store the user's answer, so the box keeps popping up, forever nagging the privacy conscious. DNT would have solved that so nicely! Header set, no box, easy peasy. Except the difference between theory and practice is that they're the same (in theory). So boxes keep popping up even from good actors.

Re: Twitter abandons 'Do Not Track' privacy protection

#72
post #58

I always suspected Mozilla pushed Do Not Track to undermine online privacy. It was a doomed idea from the start -- all DNT does is politely ask a website not to track you. Setting their browser to DNT on did give tens of millions of Firefox users the illusion they were getting a high level of privacy (so they presumably would stick to Firefox) even though it didn't actually do very much.

> I always suspected Mozilla pushed Do Not Track to undermine online privacy.

What motivation does Mozilla have to want to "undermine online privacy?" Of all the major browser vendors, they seem the least coupled to the privacy-invading ad ecosystem.

Re: Twitter abandons 'Do Not Track' privacy protection

#73
post #66

Earlier quoted context omitted.

IDK really, but i found this article lately: https://www.salon.com/2016/12/14/fountainhead-of-bad-ideas-a... Make your own conclusions.

I'm not sure one one can make their 'own' conclusions from reading that article it was clearly biased towards reaching the conclusion that Ayn Rand was a writer for 'juveniles' which I don't think is a fair appraisal. I mean I don't agree with her conclusions on the world but I would say the world she has created in her novels are at a higher level than juvenile reading.

Why, I enjoyed this article, particularly the part about rape and the end:

I seriously doubt that Donald Trump is really a fan of Ayn Rand. Her books may be juvenile and shallow, but they’re way too deep for him.

Make your own conclusions, indeed.

Heather Digby Parton, also known as "Digby," is a contributing writer to Salon. She was the winner of the 2014 Hillman Prize for Opinion and Analysis Journalism.

Um, I only hope they don't give awards for that.

Re: Twitter abandons 'Do Not Track' privacy protection

#74

Earlier quoted context omitted.

Which is exactly how DNT should work, because client-side defeating of tracking is the only way to be sure you aren't actually being tracked.

There is pretty much no practical way to be sure you aren't actually being tracked. The amount of metadata we spew is crazy.

> The amount of metadata we spew is crazy.

Could someone build a privacy-respecting browser that "spews" super-generic metadata that doesn't vary from installation to installation? It's probably have fewer "features," but I'd honestly kinda welcome a simpler browser experience.

Re: Twitter abandons 'Do Not Track' privacy protection

#75
post #45
post #13

Ok, honestly, was DNT ever more than a smoke grenade for muddying the privacy discussion? The standard always relied on every single shady data collector out there to act against their core interest, facing not even the risk of detection (let alone punishment) if they don't comply, all just because you asked them nicely. You might as well carry a "do not rob me" card in your wallet. Was there ever a honest belief by…

I work in advertising,and we do respect dnt

So if I set the DNT flag on my browser, your advertising network will neither set any cookies nor serve me any beacons or tracking pixels nor collect any other analytics data from me whatsoever?

Can I or a neutral third party audit your internal database to verify that my browsing history is not being recorded by you? Do you provide a list of all third parties with which you share information with so I can attempt to audit them as well?

What dispute resolution procedures do you support if I have reason to believe that you do, in fact, hold some of my personal information despite my express request? How would you respond to a request to purge an individual's records from your logs?

--------------------------------------------------------

I don't mean to put you, personally, on the spot. I'm sure your firm is perfectly ethical, and that you do listen for and take some action to honor DNT requests as far as you see fit. I'm also sure that were I at an advertising firm I wouldn't have any better policies. It's not your fault this is a stupid feature.

That said, to almost anyone outside the webdev community "Do Not Track" doesn't mean, "Track, but Anonymize" or "Track, but Don't Personalize", it means "Don't Create A Record I Was Here". I've yet to run across a single company, advertising or otherwise, that interprets it that way, though.

Re: Twitter abandons 'Do Not Track' privacy protection

#76
post #34
post #9

DNT made sense only in a world where there would be some sort of law to back it up. I actually had my adblocker turned off on websites I knew at least tried to respect DNT (reddit, medium and twitter), guess twitter's getting completely adblocked now.

I have no issue adblocking Twitter since they use deceptive ads. It used to be ads had to be clearly labelled as not to confuse with regular content. Twitter buries their "promoted" label at the bottom in light grey text, so you only know it's an ad after you've read it and asked "WTF? Why is this in here?"

Somehow my brain has figured out how to notice that and ignore them.

Scrolling through my feed I swipe past the ads faster than the other tweets.

Re: Twitter abandons 'Do Not Track' privacy protection

#77

what if instead of using ad blockers we use ad amplifiers that downloaded 10 or 100 copies of video ads to make sure we got the data correct? Serving video is pretty expensive. How big are the ad networks' margins? Let's see who blinks first.

Ironically if you make this look like "click fraud" you can probably ensure that the site doesn't get paid for serving ads - but the ad network was still paid by their clients.

Re: Twitter abandons 'Do Not Track' privacy protection

#78

(Kicking around an idea to build this:) Would anybody be interested in a local DNS server that automatically updated its list of black-holed domains through a mechanism that preserved your privacy? (Assuming, of course, a decentralized representation of the block lists.) Would anybody be willing to sell their attention by accepting payment (BTC), perhaps through a dutch auction, to re-enable a black-holed domain for…

If you don't already know about it, definitely check out https://pi-hole.net/

I'm not totally clear on where their blacklist comes from but their mainpage claims "Known ad-serving domains are pulled from third party sources and compiled into one list"

This is pretty much exactly your first suggestion and seems like it would be an excellent platform on which to launch your second suggestion.

Re: Twitter abandons 'Do Not Track' privacy protection

#79
post #31

Earlier quoted context omitted.

That assumes that all facebook ad traffic starts with a DNS request for *.facebook.com. It may be that all facebook ad traffic is served in this way _today_, but that doesn't stop them from changing it tomorrow. What about other ad networks? What about other ad networks where you like to use part of their services (eg google.com)? What about ad networks that serve their content from a cloud provider? Blocking domains…

> That assumes that all facebook ad traffic starts with a DNS request for *.facebook.com This is true, which is why you need a better list. Like one of these: https://github.com/StevenBlack/hosts (There are lots of others out there if one of those doesn't suit your fancy.) These things will never be perfectly inclusive, but they whack the vast bulk of the commercial surveillance shops, and have the great benefit of n…

Yeah, I went down this path with my router. Found some list, wrote a script to keep it up to date, and blocked it at my DNS server. I found that it was ~80% effective, and broke about ~5% of the websites I used. Its super good for targeting a specific ad network, if you dont need anything else from those domains.

Some interesting examples where it didn't work: 1. wowhead.com: this site hides the source of all of its assets behind its own proxy, so the content you want, and the ads you dont want come from the same place. A traditional ad blocker works fine here. 2. Google: it is really hard to block google's ad domain, but still use google's services if you are doing it at the DNS level.

There is an argument to be made for DNS blocking though. If you want to take the moral high ground, then it is a good method. IE, if you don't like google spying on you, why do you use their services at all?

Re: Twitter abandons 'Do Not Track' privacy protection

#80

Earlier quoted context omitted.

It certainly isn't a complete solution, but it probably did reduce the number of ad networks that tracked you. So yes, I guess you could say it works?

Anyone that would check that box would have a tracking blocker installed anyway.

I don't think anyone here is saying it is a great solution. There are plenty of people without Ad blockers that have it checked though, see Internet Explorer users.
Post reply on HN