Skip Links

Privacy experts criticize moves to sidestep IE10's default Do Not Track settings

Apache, Yahoo overriding tracking settings -- off by default -- in Microsoft's new Internet Explorer browser

By Taylor Armerding, CSO
November 01, 2012 07:25 AM ET

CSO - When it comes to consumers' rights to control their own browsers, everybody wants to sound like they're pro-choice. But with many millions of advertising dollars on the line, the definition of pro-choice tends to align with the financial interests of those doing the defining.

Apache fires at Microsoft over do not track setting

That probably goes a long way toward explaining why software giant Microsoft and web services including Adobe, the Apache Foundation and Yahoo are at odds regarding the Do Not Track (DNT) feature of Microsoft's Internet Explorer 10 (IE10), which comes with the release of Windows 8.

They all say consumers should have a say over the level of privacy they want, in the form of choice about whether or not they want their browsing activities tracked, which allows ad networks to display targeted advertising on websites they visit.

But so far, there haven't been any loud complaints from advertising advocates about a lack of choice in systems (including Apple's iO6) that have tracking enabled by default. It is when it is disabled by default -- as is the case with IE10 -- that "choice" becomes a very hot button.

Not only are Apache, the Internet's most widely used webserver application, and others complaining, some are deploying patches to override DNT signals from IE10.

Microsoft prominently presents the option for users to enable tracking during the Windows 8 setup. But that is not enough for Roy T. Fielding, principal scientist at Adobe and co-founder of the Apache HTTP Server Project.

Fielding submitted a patch that instructs Apache to ignore the DNT setting, arguing on Github that it amounts to a "false signal" because there is no way to tell if DNT is the choice of the consumer or Microsoft.

[See also: 6 ways we gave up our privacy]

Microsoft's response has been to say that since consumers are offered the option to turn tracking on, a consumer who leaves that and other defaults as they are (off) is assenting to them.

Fielding countered in his post: "The only reason DNT exists is to express a non-default option. It does not protect anyone's privacy unless the recipients believe it was set by a real human being, with a real preference for privacy over personalization."

He added that Microsoft is deliberately violating the standard set by the Tracking Protection Working Group of the W3C (World Wide Web Consortium) and, "knows full well that the false signal will be ignored, and thus prevent their own users from having an effective option for DNT even if their users want one."

Fielding is not alone. Yahoo issued a policy in a blog post last week, saying it would also ignore Microsoft's "unilateral" decision to have DNT on by default, because it "degrades the experience for the majority of users and makes it hard to deliver on our value proposition to them. It basically means that the DNT signal from IE10 doesn't express user intent."

Those arguments don't convince privacy experts. Lee Tien, a senior staff attorney for the Electronic Frontier Foundation, notes that contrary to Fielding's assertion about Microsoft violating the W3C standard, "there is no standard yet," since it is still under development.

Our Commenting Policies
Latest News
rssRss Feed
View more Latest News