AP Adopts Firefox's 'Do Not Track'; Others On the Way 80
theweatherelectric writes "As noted by the Mozilla Blog, the AP News Registry is the first large scale service to support the Do Not Track (DNT) feature of Firefox 4 and Internet Explorer 9. They write, 'The Associated Press (AP) is the first company to deploy DNT on a large scale, and it only took a few hours for one engineer to implement. The AP News Registry tracks 1 billion impressions of news content, with 175 million unique visitors per month, and has membership with more than 800 sites. When consumers send a DNT preference via the browser while viewing a story at one of its publisher's sites, the AP News Registry no longer sets any cookies. The previous solution was for users to opt-out via a link to a central opt-out page referenced in each participating news site's privacy policy. They still count the total number of impressions for each news story, but aggregate consumer data for those with DNT in a non-identifiable way.'"
Alert! Site malfunction! (Score:2, Funny)
My karma status allows me to disable ads, but this one just got through anyway.
I hope someone in charge can fix this for us l33t guys....
Re: (Score:2)
Non-identifiable? (Score:5, Insightful)
"but aggregate consumer data for those with DNT in a non-identifiable way.'"
hmm. Haven't we had many stories about how "non-identifiable" is still identifiable in some cases? It sounds like "Do Not Track" may mean actually "Might track less". As with all voluntary things though, the implementation is completely up to the company implementing it. There's no reason for them to do anything different. I might think it would even allow another layer of tracking since if you have "DNT" on then all that means is yet another flag could be used as a unique identifier, and now they can infer that you're tech savvy and paranoid enough to flip that flag.. What is the point of this again?
Re:Non-identifiable? (Score:4, Funny)
Yeah Do Not Track is a great big joke. It's like going through a bad neighborhood at night, loaded with jewellery like a Hollywood diva with a Do Not Rob sign stuck to your back.
Re:Non-identifiable? (Score:5, Interesting)
Well, how does it work?
You visit site, the server checks your DNT flag before sending a cookie...and then what?
I'm guess the server records GameBoyRMH visited site xyz.com, but no cookie was set. And whenever you visit one of those 800 sites, they know it's you, because they have to check for your DNT flag.
So you've preserved the 100-or-so bytes the cookie would take on your drive, but how is that not tracking?
It seems to me a real DNT track system would be client-side only, and the setting would instruct the browser to accept and instantly (or after the session) delete the cookie, without giving any indication of the activity to the server.
Re: (Score:2)
Bingo, you hit the nail on the head.
Re:Non-identifiable? (Score:4, Informative)
A cookie allows them to give you a unique identifier, which works for differentiation down to individual browsers on the same machine, and that allows them to get a good picture of your travel around their site (and their affiliate sites etc) - the DNT flag would remove that, only allowing them to track the number of hits on a page and where the visitor came from.
They don't know its "you" each time, because the DNT flag contains no identifiable information - to them, this is the equivilent of you clearing out your cookies after each individual page visit. No cookie, no ID, no tracking beyond the current page. Same deal.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Go to your Firefox preferences.
Switch to the privacy tab.
Firefox Will => Set to "Use custom settings for history"
Uncheck "accept third-party cookies"
Congratulations, almost all tracking is now disabled (since most sites don't track you themselves, they set a third party cookie to track you).
Re: (Score:2)
Sorry sir, you may cease guessing now, because it is a total lie and doesn't work.
Setup:
1. Tools/Options/Advanced/Tell web sites I do not want to be tracked
2. Tools/Clear Recent History/Everything
3. Tools/Options/Privacy/Show Cookies/Remove All Cookies
4. Then go for example to http://marketing.apnewsregistry.com/ [apnewsregistry.com] [apnewsregistry.com]
5. Go look at Tools.Options/Privacy/Show Cookies
Voila!
__utmz
211664137.1301603676.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)
__utma
211664137.1337932741.1301603676.130160367
Re: (Score:2)
__utmb is a session cookie. You do understand what session cookies are and why we need them, right?
Re: (Score:2)
In the context of Non-Tracking, the normal logic behind session cookies is not good enough. I'll leave it to my betters to show the proof, but "tracking" is a data-inbound event, so even if that session cookie becomes invalid later, a company sufficiently motivated to make a big show of "Do Not Track" while simultaneously getting trackable inbound info can do it, but it wouldn't all be stored in the cookie, it would be the cookie + other steps.
Basically, it's impossible to prove a company "isn't tracking yo
Re: (Score:3)
All those cookies you listed have already expired. Just look at the timestamps, it's right there.
If someone wanted to track you badly enough to do the things you're suggesting, they would simply ignore the DNT flag.
Something I suspect a lot of the folks on /. struggle with, as I do myself, is accepting the axiom that perfect is the enemy of good. DNT isn't remotely perfect, but that isn't the same as not being a good thing.
Re: (Score:2)
If you're concerned about being tracked by a site you probably shouldn't be logging into it.
Re: (Score:2)
Re: (Score:2)
You mean this site? https://panopticlick.eff.org/ [eff.org]
Re: (Score:2)
Nice post.
Elsewhere I took a strongly worded stand vs a well meaning AC about session cookies, and "left it to my betters to work out the details". You provided one - the mere (rare) existence of the bit set to on itself.
I know about the Panopticlick method, but that felt "too easy" - so let's work on sneakier tricks. Using the principle of the 20-Questions Narrowing Down theme, can they narrow it down to "you" say within four page clicks? Sure, the homepage might not be enough, but there could be 10 ways o
Re: (Score:2)
Re: (Score:1)
Well, I get the exact opposite, more in line with what GP says.
I am running FF 4 in MacOS X (madness, I know) and with Adblock and NoScript activated I have the same fingerprint as 1 in 53,152 browsers. If I use it with NoScript deactivated my browser finger print makes it unique, so I can be identified among all 1.4 million people that used Panopticlick. It's true MacOS X is not as common as Windows XP, but for me activating NoScript helps my privacy (I become 1 out of 30 instead of a specific one).
Re: (Score:2)
That's basically what Cookiesafe [mozilla.org] and Cookie Monster" [mozilla.org] do. Firefox's default cookie manager does it a bit more clumsily, and is missing the option to allow a site to leave cookies for just the current session, not future sessions. Your only choices are always deny, allow pers
Re: (Score:1)
I already have a do-not-track. It's called adblock. It's not perfect and it isn't a certainty that I can't be tracked by advertisers and others (in fact, it's a certainty that I can be, I'm sure). At least I can avoid ads and a significant portion of tracking, though.
Re: (Score:2)
Way ahead of you. I use NoScript, Flashblock and Betterprivacy (ads that don't use Flash or JS still work fine, so I support the sites I browse). But unlike us, the Average Joe doesn't know how to defend himself, and it's sort of unreasonable to expect someone to know which scripts should be allowed and which shouldn't.
Re: (Score:2)
I also recommend adding Cookie Monster to that list. I don't use Flashblock as NoScript pretty much takes care of it; I do allow scripts from the same domain by default.
Re: (Score:2)
I've actually been meaning to try Cookie Monster 1 or CookieSafe.
Re: (Score:2)
I already have a do-not-track. It's called adblock. It's not perfect and it isn't a certainty that I can't be tracked by advertisers and others (in fact, it's a certainty that I can be, I'm sure). At least I can avoid ads and a significant portion of tracking, though.
Adblock is a really good partial solution. Not only does it make you more difficult to track (since much of that is done by ad networks) but it also speeds up browsing and removes the more obnoxious ads. What you said makes me think of this line from the summary:
That's the previous non-solution. Implicit in this idea is the notion that we're completely at the mer
Aimed at Google? (Score:1)
Am I the only one to suspect that DNT is mainly aimed at the market participant which does the most tracking and which has the highest online ad revenue: Google/DoubleClick?
Can't Wait for the NSA to Follow Suit! (Score:4, Funny)
This is nice but the obvious remains... (Score:4, Insightful)
Re: (Score:2)
This isn't a security feature, its a standardized opt-out.
Seems like a good thing. Better security to prevent malicious tracking is still important, but its complimentary to this.
Re: (Score:2)
And whether or not it gets wildly honored, if more people set the flag, it certainly sends a message and makes people aware that privacy is important.
Re: (Score:2)
Except it doesn't even seem to work for me - see my post above for the apregistry. What good is a method that's so buggy you can't rely on it? What fallacy is that, that they promote a feature yet for ____ % of the population it "just happens" not to work?
Re: (Score:2)
I don't get your post. It's not a client thing. The browser simply says to the remote server, "this person does not want to be tracked". It's not buggy or broken. It's up to the remote server to honor it. That's all. Now.. the "idea" may be buggy or broken. Sure. But that's a different thing.
This doesn't claim to delete cookies or anything of the sort.
Re:This is nice but the obvious remains... (Score:4, Insightful)
I'm scratching my head a bit as to why Mozilla went down this road at all.
Well it seems like a bit of a publicity ploy for Mozilla to me, albeit, a good one. Mozilla has had issues with FF in recent versions (I'm looking at you FF3 bloat), but it still remains the poster child browser for a private/independent/free browser. I think the devs at Mozilla know full well that the Do Not Track flag requires the unlikely compliance from other entities. However, by making the feature easy to use and by publicizing it, it has brought the problem of, "Random data mining companies are harvesting everything about you," right into the main view of every user that configures their own Option settings in FF.
Furthermore, if users start checking the option because it sounds like a good idea, but there is still a big fuss about companies tracking users anyway, the users will start to ask what the hell is going on. If Mozilla takes the time to explain that, for true non-tracking web-browsing, those data mining companies have to take it down a notch, it could very well increase public criticism of data mining in general.
So all in all, I think adding the "Do Not Track" option was much more of a political move by Mozilla than an actual technical one. It's nice to see someone with money and clout sticking up for such things for once.
Re: (Score:2)
Why not make it so if you have DNT set and a site ignores it, a big notice pops up saying "This site does not honor your Do Not Track setting. If you proceed, information about your behavior while visiting this site will be tracked and collected, and may be used in a manner you find objectionable. Are you sure you wish to continue?" No, Always Allow, Allow this one time.
Personally, I ju
Re: (Score:2)
What good is a privacy feature when it rests on the compliance of those who have conflicted interests in the matter?
I think this may be setting technical foundation for a legal privacy framework with teeth. If there is a de-facto, widely implemented industry standard (even more so if they get it through say W3C) to say "I don't want you to gather my private information", and a company ignores it, can they be held liable? Maybe not today, but a law could be made to that effect tomorrow.
OK, I'll admit (Score:2)
Re: (Score:2)
Re: (Score:2)
The particular problem that the OP suggests would be solved by privacy mode. I'm assuming his problem is that he's logged on to Facebook and when he visits sites with a "Like" button, Facebook "helpfully" posts it for him (actually I don't think you even need to be logged into Facebook, it can track you anyway if you have a Facebook cookie). If you turn on privacy mode you won't be logged onto Facebook (unless you then, stupidly, go ahead and log on to Facebook), so those like buttons won't connect you back
Re: (Score:3)
What's worse about this, is that it is implemented by an iframe. The "like" button is actually at facebook. bigfatsluts.com doesn't know anything about your facebook info, but, because you are logged in, and the facebook content knows what page it is being loaded into (the iframe source looks likes this: facebook.com/plugins/like.php?http://bigfatsluts.com/thehairiest.movie), facebook knows that you have visited the page.
The more sites that implement this, the more facebook is able to track your web brows
Re: (Score:2)
RefControl [mozilla.org] might help you here. Additionally the HTTPSEverywhere extension; then all the iframes over regular http would get converted to https and hopefully fail.
You almost need to: allow cookies for facebook.com, login to facebook, ...., logout, block cookies for facebook.com, continue normal browsing.
Try Cookie Monster [mozilla.org] for help with that.
A pain in the ass, but I wouldn't trust facebook either, even if they did claim to honor DNT.
Re: (Score:1)
What's worse about this, is that it is implemented by an iframe.
NoScript can be used to block IFRAMEs.
Re: (Score:1)
Log out of facebook. Wouldn't that solve the problem?
Re: (Score:3)
Not if you're still accepting cookies from facebook.com / fbcdn.net
I wasn't worried about the good actors... (Score:3)
This is a nice thing for everyone to be doing, but it's still a trust relationship with no transparency. Bad actors won't respect my wishes. That's the definition of a bad actor.
The solution has to be on client side. Otherwise it's just more trust, which is what we've been using all along. I'd much rather trust the Ghostery extension to just block the tracker scripts to begin with.
Re: (Score:1)
Ghostery is marketeer self-regulation as well, blocking only scripts from companies who opted in to the program.
Re: (Score:2)
Bad actors won't respect my wishes.
Tell me about it. Keanu Reeves keeps appearing in movies, despite my repeated requests. Brah.
Re: (Score:2)
Stop letting them have an IP even.
Okay, I'm mostly agree with the sentiment, but without an IP address how do you expect them to serve you any webpages?
Re: (Score:2)
Okay, I'm mostly agree with the sentiment, but without an IP address how do you expect them to serve you any webpages?
Unicorn sparkles. It's pretty obvious that it's the only way to be sure. THE ONLY WAY.
Re: (Score:2)
Stupid Idea (Score:3, Interesting)
To start with, they should rather strip all the unnecessary, incredibly detailed version information [eff.org] off the default user-agent string. Relying on the "goodwill" of ad companies is just absurd.
Oh and, as soon as this Do-Not-Track header becomes a default setting it will be ignored anyway...
Do Not Track (Score:1)
Sounds like somebody put the bridge up for sale again. How many owners does the damn thing have by now?
"privacy policy" ha ha ha ha ha ha BWAAAA HAHAHA!!!
ok, that's enough
Sorry, too late. (Score:3)
Those of us who care, already whitelist cookies. Those who don't, are not going to bother setting the DNT flag in the first place.
Re:Sorry, too late. (Score:4, Insightful)
I can convince my family to enable do not track, no way am I going to try to walk them through cookie white listing.
Re: (Score:3)
With Cookie Monster [mozilla.org] it's not too painful. Set it to apply to the entire domain and not deal with subdomains, and have it block by default. Any time they need to login, just click the icon and permanently allow. Any time some crappy website that requires cookies denies them, then temporarily-allow.
I'm not saying most people will do this, but a fair amount can do this if they care. I doubt there is anything we can say to show them they should care, however.
Re: (Score:1)
Yeah, that's what I use.
It isn't so much that it is complicated, it is that it is an extra step or two, and they don't care.
Re: (Score:1)
It isn't so much that it is complicated, it is that it is an extra step or two, and they don't care.
This sounds like an iron-deficient fist problem.
That reminds me... (Score:2)
I'm flying to NYC in the morning and need to pack my "Do Not Mug Me" shirt. :-)
uhh.... Firefox AND IE9 (Score:2)
They use the exact same Do Not Track header.
Re: (Score:1)
I bet they connect to the same ports too!
Re: (Score:2)
With a username like that, you're surprised?