{"id":14724,"date":"2019-02-28T10:45:45","date_gmt":"2019-02-28T18:45:45","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2019\/02\/28\/news-8473\/"},"modified":"2019-02-28T10:45:45","modified_gmt":"2019-02-28T18:45:45","slug":"news-8473","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/02\/28\/news-8473\/","title":{"rendered":"A Second Life for the &#8216;Do Not Track&#8217; Setting\u2014With Teeth"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5c76eed4b235600ed92391c5\/master\/pass\/Do%20Not%20Track%20v2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lukasz Olejnik| Date: Thu, 28 Feb 2019 13:00:00 +0000<\/strong><\/p>\n<p><span class=\"lede\">In 2009, as <\/span>people grew concerned about the pervasiveness of web tracking, the idea of adding a Do Not Track (DNT) setting to browsers gained traction across the web. By enabling it, the browser attaches \u201cDNT: 1\u201d to a web request, effectively telling websites that the user does not wish to be tracked.<\/p>\n<p>Initially, the concept was applauded for solving the pernicious problem of invisible online tracking. All the major web browsers added the DNT setting to their configuration. It was on the radar of the <a href=\"https:\/\/www.ftc.gov\/news-events\/press-releases\/2010\/12\/ftc-staff-issues-privacy-report-offers-framework-consumers\" target=\"_blank\">Federal Trade Commission<\/a>, and the Electronic Frontier Foundation <a href=\"https:\/\/github.com\/EFForg\/dnt-guide\" target=\"_blank\">created a semi-standardized approach<\/a>.<\/p>\n<p name=\"inset-left\" class=\"inset-left-component__el\">Lukasz Olejnik is an independent security and privacy researcher and advisor, W3C TAG member, and research associate at the Center for Technology and Global Affairs at Oxford University.<\/p>\n<p class=\"paywall\">But there was a catch: DNT is a voluntary agreement. Users need to trust that the sites they visit <em>honor<\/em> the setting. And at first some sites, like Twitter, did. But if a site chooses not to honor the setting, there is no punishment and no regulatory backing to enforce the standard.<\/p>\n<p class=\"paywall\">In the 10 years since DNT was initially proposed, it&#x27;s been heading toward the history book of failed technical ideals. In 2019 the World Wide Web Consortium (W3C) discontinued work of <a href=\"https:\/\/www.w3.org\/TR\/tracking-dnt\/\" target=\"_blank\">Tracking Preferences Expression<\/a>, the successor of DNT. Sites, including Twitter, reversed their stance. DNT was rightly criticized for doing essentially nothing, gradually losing the favor of public opinion.<\/p>\n<p class=\"paywall\">But now DNT is having a renaissance of sorts, after it caught the interest of regulators in Europe. In January 2017 the European Commission announced an initiative to update the <a href=\"https:\/\/blog.lukaszolejnik.com\/eprivacy-proposal\/\" target=\"_blank\">ePrivacy Regulation<\/a>, a proposal that would revisit a 15-year-old directive dealing with privacy protections and how users consent to being tracked by cookies (websites served to citizens of the European Union are required to ask for consent for the use of cookies).<\/p>\n<p class=\"paywall\">The process of creating EU regulations is complex, involving the European Parliament and the Council of European Union, and the 2017 proposal had its issues. It did not, for example, include any form of automatic or universally standardized mechanisms for users to consent to being tracked. Without a universal standard, the patchwork of varying pop-ups that polluted a user\u2019s web browsing experience would remain in effect. (In May 2018, when the EU enacted the General Data Protection Regulation, the problem with pop-ups was reinforced, which in retrospect was <a href=\"https:\/\/blog.lukaszolejnik.com\/is-gdpr-recharging-cookie-notice-popups\" target=\"_blank\">easy to predict<\/a>.) Among the goals of the new ePrivacy Regulation was cleaning up this exact mess by requiring some sort of standardized and automatic process that is transparent to users. So in 2017, the European Parliament pushed hard toward making the browser mechanisms for user privacy preferences and consent expressions legally binding, and it issued a <a href=\"http:\/\/www.europarl.europa.eu\/sides\/getDoc.do?pubRef=-\/\/EP\/\/NONSGML+REPORT+A8-2017-0324+0+DOC+PDF+V0\/\/EN\" target=\"_blank\">report<\/a> that <a href=\"https:\/\/blog.lukaszolejnik.com\/proposed-amendments-to-eprivacy-regulation-are-great\/\" target=\"_blank\">explicitly endorsed<\/a> Do Not Track settings as a way of expressing consent. Ten years after the original proposal, DNT suddenly became integral in the debate over regulating privacy protection in the biggest economy in the world.<\/p>\n<p class=\"paywall\">From a purely technical standpoint, DNT is somewhat redundant. The default settings of major web browser vendors like <a href=\"https:\/\/support.apple.com\/en-gb\/guide\/safari\/prevent-websites-from-tracking-you-sfri40732\/mac\" target=\"_blank\">Apple Safari<\/a> and <a href=\"https:\/\/wiki.mozilla.org\/Security\/Anti_tracking_policy\" target=\"_blank\">Mozilla Firefox<\/a> actively fight tracking. And, in a further twist, Apple decided to <a href=\"https:\/\/developer.apple.com\/documentation\/safari_release_notes\/safari_12_1_release_notes\" target=\"_blank\">remove<\/a> the DNT function from Safari 12.1, citing \u201cfingerprinting risk.\u201d Fingerprinting allows a site to identify a user based on traits specific to their devices or browser, and as Apple tried to argue, DNT could be one more setting used to track you. While the particular fingerprinting risk cited by Apple is extremely low (as Firefox\u2019s <a href=\"https:\/\/telemetry.mozilla.org\/new-pipeline\/dist.html#!cumulative=0&amp;end_date=2018-12-06&amp;include_spill=0&amp;keys=__none__!__none__!__none__&amp;max_channel_version=beta%252F64&amp;measure=DNT_USAGE&amp;min_channel_version=null&amp;processType=*&amp;product=Firefox!Fennec&amp;sanitize=1&amp;sort_by_value=0&amp;sort_keys=submissions&amp;start_date=2018-11-01&amp;table=1&amp;trim=1&amp;use_submission_date=0\" target=\"_blank\">telemetry<\/a> data suggest), the message risks demonizing DNT.<\/p>\n<p class=\"paywall\">DNT has suffered from users&#x27; misunderstanding of how it works. People don\u2019t seem to know that DNT doesn\u2019t make you invisible; it merely informs websites that you would prefer not to be tracked. But just because its purpose might be misunderstood doesn\u2019t mean DNT should go away. (<a href=\"https:\/\/www.usenix.org\/system\/files\/conference\/soups2018\/soups2018-habib-prying.pdf\" target=\"_blank\">Research<\/a> <a href=\"https:\/\/saschafahl.de\/static\/paper\/privatebrowsing2018.pdf\" target=\"_blank\">indicates<\/a> that people don\u2019t fully comprehend what \u201cprivate browsing modes\u201d do either; for example, they don\u2019t mask your location or IP address.) DNT could have great value if it has regulatory backing.<\/p>\n<p class=\"paywall\">Admittedly, crafting policy and enforcing regulatory action are long processes, and can be influenced in favor of or against some particular views. But there is a growing appetite for this kind of regulation. Just look at the European Union: It adopted the world\u2019s most comprehensive and strongest privacy regulation framework, the General Data Protection Regulation, and now the EU is considering a regulatory solution that could rely on Do Not Track. And even though, in 2018 and 2019, the Council of the European Union is moving against the positive privacy changes in ePrivacy, and the much needed update to the regulation is postponed, when conversations around the proposal resume they will take place in a reality where aggressive tracker blocking is already the de facto technically enforced default. It seems that consent will remain an important regulatory concept in the months and years to come.<\/p>\n<p class=\"paywall\">Which is why giving up on DNT at this particular moment\u2014especially by actors as influential and decisive in the privacy debate as Apple\u2014is not the signal we now need. Regulatory changes are finally on the table, and DNT could be a much needed solution for how to enforce these rules.<\/p>\n<p class=\"paywall\">Technologists often complain about the relative slowness of the regulatory process, especially as compared to how fast technology develops. So it\u2019s especially perplexing that tech companies and enthusiasts would rescind a technical proposal that could finally function the way it was supposed to all along. It doesn\u2019t seem like the time to turn the setting off completely.<\/p>\n<p class=\"paywall\">WIRED Opinion <em>publishes pieces written by outside contributors and represents a wide range of viewpoints. Read more opinions <a href=\"https:\/\/www.wired.com\/opinion\">here<\/a>. Submit an op-ed at\u00a0opinion@wired.com<\/em><\/p>\n<p class=\"related-cne-video-component__dek\">America has a new president who is, how should we say, unpredictable. There\u2019s no telling how the NSA and the surveillance state will evolve in the next four years. So, if you\u2019re worried about keeping your private communications private, here\u2019s what to do.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/a-second-life-for-the-do-not-track-setting\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5c76eed4b235600ed92391c5\/master\/pass\/Do%20Not%20Track%20v2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lukasz Olejnik| Date: Thu, 28 Feb 2019 13:00:00 +0000<\/strong><\/p>\n<p>In recent years, the setting has been criticized as being essentially meaningless. But it might have a crucial role to play in enforcing privacy regulations.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[234,714],"class_list":["post-14724","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-opinion","tag-security"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14724"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14724\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}