Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>The vulnerability is already being exploited by at least two display ad analytics companies across billions of page impressions per month.

Who are these companies?



So much for Microsoft's automatic Do Not Track. It seems users are less safe, not more with IE, from ad companies.


Do Not Track was always a sham.

It's a symbolic flag to respect users preferences or browser vendors are going to make ad-block standard by default just like pop-up blockers.

If ad companies ignore DNT they are digging their own graves.

It's not about protecting users. It's about heading off an arms race to help protect the ad industry.


How was DNT a sham until IE screwed it up by making it opt-out?


I think it was a sham either way (without legislation, there's really no reason for anyone to adhere to the requests, and as users we have little to no way of knowing if our requests are being fulfilled), but MS screwed the pooch here by completely violating the intent and implementation of the spec.

Sending "DNT: 1" in your request header means "please do not track me". Sending "DNT: 0" means "I don't care if you track me". Sending no DNT header (every request on a browser where the header is unsupported or a browser has not received a preference from a user) means "I have not expressed a tracking preference or do not have the ability to do so".

By having a default sent either way as MS did, it violates the semantic meaning of the header, meaning that the receiving server can't distinguish between "no preference" and "don't track"/"go ahead". It's like a pair of radio buttons: selecting neither is valid, but once you've made a selection you can't get it back to an unselected state.


I've seen this repeated a couple times and I'd like to know the reasoning on this argument. Is making DNT opt-out bad? Seems like MS would catch more flak had they made it opt-in, though I may just be misunderstanding the situation


> Is making DNT opt-out bad?

The common argument is that it is:

1) Advertisers won't give up tracking across the board. It's too lucrative for them.

2) Most users don't care about the setting that much.

3) Enabling it for default for the majority of users will cause present advertisers with a majority of users who they cannot track.

4) Per (1), the advertisers will then elect to ignore DNT.

5) DNT becomes a useless ignored flag and a waste of time.

Instead, if it's opt-in:

1) Most people don't bother turning it on.

2) The advertisers face pressure to comply with the ones who do.

3) People who do turn it on then enjoy the benefits.

Also, the DNT specification explicitly says that DNT should not be turned on by default, for these very reasons.


The spec does not say DNT should be turned on by default. The spec says it has to give the users full knowledge of what turning on DNT means which IE 10 does on first run.


How is that not blackmail? You might as well say if everybody started reading the list of ingredients of food they buy and take them seriously, corporations would just start to lie and put whatever they want in there. Sure, maybe some would, but that's what jail is for.


People intentionally and knowingly reading the ingredients / turning on DNT is the correct method.

I'm struggling to find a valid food-ingredient-analogy but it would be very different from your scenario. It would have to involve Microsoft auto-scanning the ingredients without the user ever turning this feature on. Then Microsoft would have to do something with the results that hurts/disparages certain food producers. And then the food producers would stop listing ingredients in a form that Microsoft can OCR, not lie about them.


If you are an ad company or a company that relies on ads in some way for revenue, what possible reason would you have for respecting it?


Generally because anyone tech savvy enough to opt out of it would be worth less to advertisers anyway.


I have no idea why that would be true? I assume pretty much anyone with enough money for an internet connection has some value to advertisers.


You still get advertisements, but with DNT they wouldn't be targeted to your profile.


I'm not sure, but let's assume they are. Doesn't respecting do not track reduce their value even further? I'm not arguing that ad companies shouldn't respect so not track, just considering the incentives and disincentives in front of them.


The main motivation is to have some standing ground to prevent legislation.


Name no names please. Don't want a witch hunt when we are in a glass house.


Honestly, I don't understand this reluctance to name wrongdoers, especially for something like this where verifying the wrong is trivial (e.g. load up a client site and find the offending code in source).

It seems to me that the harm is greater not naming names - reputation is important and if you take steps to invade user's privacy then your reputation can and should suffer for it.


"Witch hunt" generally refers to persecution of someone without any regard to whether they're innocent or guilty, so I presume the comment was intended to admonish against guessing which ad companies may be using this technique.


Yes. I am sorry I was not clearer.


My first thought on reading this was, "Ah. 3825 works for one of them."


Who are these ad companies is a question that addresses the wrong topic. VP for Internet Explorer effectively said[1] that the vulnerability in Internet Explorer would not be an issue if nobody exploited it.

[1]: http://blogs.msdn.com/b/ie/archive/2012/12/13/update-to-alle...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: