12:11 PM

W3C Proposes Do Not Track Privacy Standard

Microsoft, Mozilla, Google, Apple, privacy groups, and online advertising associations work to balance consumers' interests with Web companies' requirements for user data.

Firefox 8 Beta: Visual Tour
Firefox 8 Beta: Visual Tour
(click image for larger view and for slideshow)
The World Wide Web Consortium (W3C), the standards body that develops the protocols and guidelines for the Web, Monday released the first draft of its proposed standard for implementing "Do Not Track" online.

Do Not Track refers to giving consumers the ability to opt out of having their personal information and online browsing habits tracked by advertisers, marketers, and websites in general. The final W3C Do Not Track standard--due out by the summer of 2012--will detail both how consumers can express their tracking preferences, as well as how websites and their affiliates will acknowledge those preferences.

"We know there are many types of users. Some eagerly welcome the benefits of personalized Web services, while others value their privacy above all else," said Aleecia M. McDonald, a privacy researcher for the Mozilla Foundation, and co-chair of the Tracking Protection working group developing the standard, in a statement. "Do Not Track puts users in control, so they can choose the tradeoffs that are right for them.

[Privacy experts worry that Amazon's Kindle Fire tablet will stockpile your browsing habits. See Amazon Addresses Silk Tablet 'Optimized Browsing' Privacy Concerns.]

How will the W3C working group balance the needs of privacy-conscious consumers with the data-collection demands of online advertising, which provides the revenue that many websites require to stay in business? "The overall goal is to match the expectations of the users. On average, users have expectations for if they turn tracking off, and what this means, and we try to get as close as possible to these expectations," said Matthias Schunter, who's part of IBM Research and a co-chair of the W3C Tracking Protection working group.

But adding more anonymity to the Web creates challenges. "From a technology perspective, I think a big challenge will be research and statistics," said Schunter. "Advertisers, even if they don't show targeted ads, it's important for them to know how many people viewed and clicked, what your conversion rate is. Currently, many mechanisms used for these statistics are not so privacy-friendly."

The working group's mission will be to find the right checks and balances among these various requirements. "I wouldn't want to come up with a lame compromise that falls apart in a year," he said.

Accordingly, the group includes representatives from many organizations with a stake in both sides of the online advertising and tracking debate. "The working group has just started, but the big achievement at this point isn't the documents that we've put out, but that we've gathered all of the big players in the space together--Google, Facebook, IBM, Mozilla, Microsoft, Mozilla--as well as the big privacy organizations--the Center for Democracy and Technology, the Electronic Frontier Foundation--and also the interactive advertising organizations, which are usually umbrella organizations for advertising agencies," he said. The Federal Trade Commission and German Independent Center for Privacy Protection are also advising the group.

The working group is crafting two standards. The first is Tracking Preference Expression, "to define a standard for a how a browser can tell a website that a user wants more privacy," said Schunter, so browser makers can implement Do Not Track consistently. "So you send a signal, and you get a response from the website which tells you that the request has been honored." The second standard, meanwhile, is the Tracking Compliance and Scope Specification, which details how websites should comply with Do Not Track preferences.

Once finalized, these standards won't be enforced by the W3C. Rather, enforcement would likely involve advertising industry associations, who could require their members to comply with Do Not Track. In addition, any U.S. advertiser that said it complied would be held to account by the FTC, as well as by privacy monitoring organizations, such as TRUSTe--also part of the Tracking Protection working group--and the Better Business Bureau.

Do Not Track will likely not be active by default. "Simply speaking, if all browsers would ship with Do Not Track on, then you'd offer too much privacy to the people who don't care. So the agreement that I do see happening is that the browser should only transmit preferences that the user has expressed," said Schunter.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Ninja
11/17/2011 | 4:01:15 AM
re: W3C Proposes Do Not Track Privacy Standard
I agree Jim. Also, the second to last paragraph I think spotlights the question of enforcement, and whether or not that will be sufficient.
Brian Prince, InformationWeek/Dark Reading Comment Moderator
User Rank: Apprentice
11/15/2011 | 6:22:39 PM
re: W3C Proposes Do Not Track Privacy Standard
How this is implemented will be key. If it's easy for sites to ignore user preferences, then it is essentially toothless.

Jim Rapoza is an InformationWeek Contributing Editor
Register for Dark Reading Newsletters
White Papers
Current Issue
Dark Reading Tech Digest September 7, 2015
Some security flaws go beyond simple app vulnerabilities. Have you checked for these?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-12
vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.

Published: 2015-10-12
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.

Published: 2015-10-12
Cisco Unified Computing System (UCS) B Blade Server Software 2.2.x before 2.2.6 allows local users to cause a denial of service (host OS or BMC hang) by sending crafted packets over the Inter-IC (I2C) bus, aka Bug ID CSCuq77241.

Published: 2015-10-12
The process-management implementation in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges by terminating a firestarter.py supervised process and then triggering the restart of a process by the root account, aka Bug ID CSCuv12272.

Published: 2015-10-12
HP 3PAR Service Processor SP 4.2.0.GA-29 (GA) SPOCC, SP 4.3.0.GA-17 (GA) SPOCC, and SP 4.3.0-GA-24 (MU1) SPOCC allows remote authenticated users to obtain sensitive information via unspecified vectors.

Dark Reading Radio
Archived Dark Reading Radio
What can the information security industry do to solve the IoT security problem? Learn more and join the conversation on the next episode of Dark Reading Radio.