Risk
12/1/2010
06:56 PM
50%
50%

FTC Proposes 'Do Not Track' Option For Internet

Web users could use a browser button to stop organizations from tracking their viewing habits, under the Federal Trade Commission proposal.

The Federal Trade Commission has made a potentially far-reaching proposal that would give web users the option of shielding personal information from advertisers, retailers and other companies while browsing the Internet.

The FTC gave its blessing to the so-called "Do Not Track" approach in a proposed framework for consumer privacy released Wednesday. The proposal would apply to all commercial organizations that collect or use data that can be linked to a specific consumer, computer or other device.

The commission favored giving consumers a simple mechanism for disallowing data gathering. To do that, the FTC recommended adding a button to browsers that would activate technology to prevent people from being tracked or receiving targeted advertising. The proposal would be an alternative to current browser privacy settings, which a recent study by Stanford University and Carnegie Mellon found inadequate to shield people's viewing habits.

The need for such simplicity stems from the fact that the voluntary approach -- in which organizations set their own privacy policies and notify consumers of the rules in advance of collecting information -- has failed. "Specifically, the notice-and-choice model, as implemented, has led to long, incomprehensible privacy policies that consumers typically do not read, let alone understand," the FTC report said.

The Future of Privacy Forum, a Washington, D.C.-based think tank, agreed with the FTC and praised the report. "Today's FTC report identifies the most pressing privacy issues facing consumers today," the group said in a statement. "They correctly recognize that the current framework needs to be updated to reflect consumers' ongoing concerns about how their data is being collected and used."

The commission's proposed privacy framework would have companies build consumer privacy protection into every stage of development of products and services. In addition, organizations would offer a clearly defined no-tracking option at the time a consumer is making a decision that would set data gathering in motion. Finally, companies would increase transparency of their data practices through clearer, shorter and more standardized privacy notices and by providing access to consumer data they maintain. If a company planned to use data for something other than its originally stated purpose, then consumers would have to agree to the new use in advance.

Advertisers have been adamantly against government-imposed privacy regulations, preferring a self-regulatory approach instead. In an appearance this year before the House Subcommittee on Commerce, Trade and Consumer Protection, Mike Zaneis, VP of public policy for the Interactive Advertising Bureau, argued that the industry "has a long and successful history of protecting consumers' privacy rights through effective self-regulation."

"Given the free content and services that consumers enjoy because of advertising revenue, it is imperative that any new laws be carefully tailored," Zaneis said.

Shar VanBoskirk, analyst for Forrester Research, said the firm's studies have shown that consumers are generally willing to share information with marketers if there's a valuable payback for doing so. Consumers are more concerned about the lack of control they have over their data, and VanBoskirk said she doesn't have a lot of faith that legislation would effectively address those concerns.

"Consumers need education to understand how their data is used, when data sharing has a benefit for them, where their data goes, who knows what about them, and then how to elect out of data sharing if they choose," VanBoskirk said in an e-mail sent to InformationWeek.

The FTC does not have the authority to require companies to follow its framework, much of which would require an act of Congress. The House Subcommittee on Commerce, Trade and Consumer Protection is scheduled to consider on Thursday the feasibility of a universal method for opting out of being tracked online, according to The New York Times.

SEE ALSO:

Web Browser Privacy Settings Flawed

The Massachusetts Data Privacy Law Debacle

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1449
Published: 2014-12-25
The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses the history API.

CVE-2014-2217
Published: 2014-12-25
Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata value.

CVE-2014-3971
Published: 2014-12-25
The CmdAuthenticate::_authenticateX509 function in db/commands/authentication_commands.cpp in mongod in MongoDB 2.6.x before 2.6.2 allows remote attackers to cause a denial of service (daemon crash) by attempting authentication with an invalid X.509 client certificate.

CVE-2014-7193
Published: 2014-12-25
The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler has CORS enabled, which allows remote attackers to obtain sensitive information, and potentially obtain the ability to spoof requests to non-CORS routes, via a crafted web site ...

CVE-2014-7300
Published: 2014-12-25
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.