02:33 PM
Connect Directly

Mozilla, Google Propose Defenses Against Ad Tracking

Will self-regulation will be any more effective in the future than it has been in the past?

In the wake of a Federal Trade Commission threat last month to take action against companies that violate consumers’ privacy though behavioral ad tracking, Google and Mozilla this week proposed new tools to help consumers gain more control over ad tracking cookies.

The FTC's December report, "Protecting Consumer Privacy in an Era of Rapid Change: A Proposed Framework for Businesses and Policymakers," calls for the implementation of a “Do Not Track” mechanism," similar in concept to the National Do Not Call Registry.

Yet even as the report suggests that industry self-regulation hasn't worked, it continues to recommend self-regulation, without imposing any substantive penalties for lack of compliance.

Google on Monday acknowledged the shortcomings of existing self-regulatory measures, such as the Network Advertising Initiative and the Self-Regulatory Principles for Online Behavioral Advertising. The principal problem with such programs in Google's eyes is that users who have chosen to opt-out of ad tracking have that decision erased if they ever clear their browser cookies. Also, past settings may not cover ad tracking cookies placed by companies that launched after the user set his or her ad tracking preferences.

So Google is offering a browser extension called Keep My Opt-Outs, which will store a user's opt-out preferences even if he or she subsequently deletes his or her browser cookies. This extension is intended to serve as a complement to Google's existing Advertising Cookie Opt-out Plugin.

"[W]e’ve designed the extension so that it should not otherwise interfere with your Web browsing experience or Web site functionality," explain Google product managers Sean Harvey and Rajas Moonka in a blog post. "This new feature gives you significant control without compromising the revenue that fuels the Web content that we all consume every day."

Mozilla meanwhile is proposing a Do Not Track HTTP header that will allow browser users to transmit their desire to opt-out of behavioral ad targeting to Web servers.

"When the feature is enabled and users turn it on, Web sites will be told by Firefox that a user would like to opt-out of [online behavioral advertising]," said Alex Fowler, Mozilla's head of global privacy and public policy, in a blog post. "We believe the header-based approach has the potential to be better for the Web in the long run because it is a clearer and more universal opt-out mechanism than cookies or blacklists."

Anup Ghosh, founder and chief scientist of Invincea, a browser security company, finds both approaches lacking. Mozilla's proposal, he says, is a "paper tiger."

"It's basically up to Web sites to do something or nothing with [users' preference information]," he said in a phone interview. "It's not enforceable."

Microsoft recently discussed a similar privacy feature in Internet Explorer 9. Ghosh says that while he was initially critical of what Microsoft was doing, the Mozilla proposal makes him think better of what's coming in IE9, even though Microsoft's privacy plan puts the onus on the user to identify the cookies to be blocked.

Without any penalties for lack of compliance, Mozilla's proposal, he suggests, ends up harming those companies that choose to comply rather than those that do not.

Google's approach, he observes, requires users to download and install software. "Most users aren't going to be doing that," he said.

Faced with solutions of dubious efficacy, users may resort to technology that already works: ad blocking extensions. Ghosh concedes that ad blocking extensions will prevent cookies from being placed. "But the industry doesn't want to go that way," he said. "Advertising pays for free content."

That leaves open the question of how much the ad industry really wants to pay for privacy.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Why else would HR ask me if I have a handicap?"
Current Issue
The Changing Face of Identity Management
Mobility and cloud services are altering the concept of user identity. Here are some ways to keep up.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio

The cybersecurity profession struggles to retain women (figures range from 10 to 20 percent). It's particularly worrisome for an industry with a rapidly growing number of vacant positions.

So why does the shortage of women continue to be worse in security than in other IT sectors? How can men in infosec be better allies for women; and how can women be better allies for one another? What is the industry doing to fix the problem -- what's working, and what isn't?

Is this really a problem at all? Are the low numbers simply an indication that women do not want to be in cybersecurity, and is it possible that more women will never want to be in cybersecurity? How many women would we need to see in the industry to declare success?

Join Dark Reading senior editor Sara Peters and guests Angela Knox of Cloudmark, Barrett Sellers of Arbor Networks, Regina Wallace-Jones of Facebook, Steve Christey Coley of MITRE, and Chris Roosenraad of M3AAWG on Wednesday, July 13 at 1 p.m. Eastern Time to discuss all this and more.