Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Personally, I don't set the DNT header.

You have no way of knowing if any sites are actually going to comply, and it actually provides an extra datapoint to fingerprint you with.



There are 100s of ways to fingerprint the browser and more exactly. I think is better to set it for the few that comply.


That's true, but they usually require running javascript etc.

Looking at the request headers is the simplest way of fingerprinting.


But isn't it better to at least ask instead of not asking at all?


As I said, simply asking for it will actually reduce your privacy for any service that doesn't comply, by making you more fingerprintable.


But there is some pressure on companies to comply. Plus they can't use the defense that you could have enabled it and chose not to.


Its pretty obvious the default should be the opposite to avoid a race condition like that.


It was proposed that DNT be the default, but then ad companies said if that were the case, then they would just ignore the header. They want users to explicitly opt out of tracking otherwise they will assume they agree to being tracked.


Are you suggesting a "please track me" header? Nobody would ever use it...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: