SlideShare ist ein Scribd-Unternehmen logo
1 von 15
Downloaden Sie, um offline zu lesen
Tracking Protection
    Working Group
    Aleecia M. McDonald

    3 May, 2012
                          1

Friday, May 4, 12
Introduction of the W3C

    ✤    World Wide Web Consortium
         creates international standards
         for the Internet

    ✤    Sir Tim Berners-Lee

          ✤     Created the World Wide Web,
                1989

          ✤     Created the W3C, 1994

    ✤    Successful track record with standards for HTML, XML, CSS, etc.

    ✤    Hundreds of billions of dollars of commerce runs on W3C standards   2

Friday, May 4, 12
Introduction of co-chairs

    ✤    Aleecia M. McDonald                   ✤   Matthias Schunter

          ✤     Half-time Mozilla Senior           ✤   IBM Research in Switzerland
                Privacy Researcher
                                                   ✤   Focus on cloud computing,
          ✤     Half-time Stanford                     security, and privacy
                Resident Fellow
                                                   ✤   P3P standards experience
          ✤     Prior: PhD privacy; software
                start ups



                                                                                   3

Friday, May 4, 12
Approach for Do Not Track

    ✤    User agent expresses a preference not to be tracked


                                                         HTTP header of
                                                            DNT:1



    ✤    Shipping today; standards work answers “what does tracking mean?”

    ✤    Websites / applications choose to honor DNT, confirm with response

    ✤    Adoption is entirely voluntary; W3C cannot compel members to act
                                                                             4

Friday, May 4, 12
Diverse TPWG Membership

    ✤    70+ group participants, plus observers

    ✤    Browser companies: Apple, Google, Opera, Microsoft, Mozilla

    ✤    Wide membership range including Alcatel-Lucent; Adobe; AdTruth;
         Article 29 Working Party; AT&T; CDD; CDT; Chapell & Associates;
         Deutsche Telekom; EFF; ESOMAR; Facebook; IAB Europe; Nielsen;
         Nokia; Online Publishers Association; TRUSTe; Yahoo!; The Walt
         Disney Company




                                                                           5

Friday, May 4, 12
Writing Standards Documents

    1. Definitions & Compliance                     2. Tracking Preference Expression

          ✤     Chair: Aleecia M. McDonald           ✤   Chair: Matthias Schunter (IBM)
                (Mozilla)
                                                     ✤   Editors: Roy Fielding (Adobe),
          ✤     Editors: Justin Brookman & Erica         David Singer (Apple)
                Newland (CDT); Sean Harvey &
                Heather West (Google)              3. Tracking Selection Lists

                                                     ✤   Chair: Matthias Schunter

                                                     ✤   Editors: Karl Dubost (Opera);
                                                         Andy Zeigler (Microsoft)

                                                                                          6

Friday, May 4, 12
Three Types of Parties

    1. First party                                2. Service provider

          ✤     Not directly liable for others’     ✤   Agents of first parties,
                actions                                 contractual relationship

          ✤     Very few restrictions               ✤   Cannot share data across
                                                        multiple first parties or use
          ✤     Cannot share data with                  for their own purposes
                others, or else must act as a
                third party                         ✤   Debating exceptions

          ✤     Can be multiple 1st; depends      3. Third parties with strong
                upon meaningful interaction          restrictions, plus exceptions
                                                                                       7

Friday, May 4, 12
Uniform Signals, Different Results

                    Eleven Point One



                    Onze Comma Un



                        Punt Elf



                    Elf Komma Eins

                                       8

Friday, May 4, 12
Tri-part DNT Signal

    ✤    Three options
           DNT: 1 - enable DNT, user saying “do not track me”
           DNT: 0 - do not enable DNT
           Nothing - users have not made a selection

    ✤    US, Nothing:                     ✤   EU, Nothing:

          ✤     Users did not choose to       ✤   Users did not consent to
                enable DNT                        tracking

          ✤     Similar to DNT: 0             ✤   Similar to DNT: 1


                                                                             9

Friday, May 4, 12
Site-specific Exemptions

    ✤    Many countries can have a            ✤   Some countries may not allow a
         global DNT: 1 value                      global DNT: 1

          ✤     Companies want to ask to          ✤   Consent may be site-by-site
                track anyway

    ✤    Use same technical mechanism in both cases

    ✤    Exception specific to advertiser on that particular first party, not
         global for the advertiser across the whole Internet and/or

    ✤    Exception global for a specific third party, Internet wide

                                                                                    10

Friday, May 4, 12
Current Big Unresolved Issues

    1. Edges of a party                   2. Permitted uses for third parties,
                                             perhaps with retention limits,
          ✤     User expectations and        e.g.
                branding
                                            ✤   Frequency capping
          ✤     “Discoverable” based on
                corporate ownership         ✤   Billing and financial logging

                                            ✤   3rd party auditing

                                            ✤   Security and fraud
                                                prevention

                                                                               11

Friday, May 4, 12
Opportunities

    ✤    For feedback:                        ✤   For media:

          ✤     Speaking with WG on call          ✤   Internet week, May 17th

          ✤     Joining the WG                    ✤   Mozilla blog

          ✤     Community Group                   ✤   Jonathan’s list of DNT
                                                      implementations
          ✤     Individual comments on Last
                Call draft



                                                                                12

Friday, May 4, 12
Interested in Learning Thoughts...

    ✤    Response mechanism                 ✤   Hard to get user consent
                                                when brand unknown
          ✤     HTTP header
                                        ✤   Does 3rd party acting as 3rd
          ✤     Well-known URL              party help?

    ✤    How do you propagate opt-out       ✤   Auditing, billing
         status now?
                                            ✤   Silo data
    ✤    Consent for specific sites
                                        ✤   Biggest technical challenge to
          ✤     EU consent issues           implement?

                                                                             13

Friday, May 4, 12
Tracking Protection
    Working Group
    Aleecia M. McDonald

    3 February, 2012
                          14

Friday, May 4, 12
Photo credits

    ✤    Tim: http://i.telegraph.co.uk/multimedia/archive/00682/
         bernerslee-404_682192c.jpg

    ✤    Elephant: http://www.flickr.com/photos/paperpariah/2446224424/
         sizes/o/in/photostream/

          ✤     Adam Foster | Codefor

          ✤     “! danger elephants at Knowsley Safari Park?”

    ✤    Cash register: http://www.flickr.com/photos/teflon/4995681266/

          ✤     Martin Deutsch
                                                                        15

Friday, May 4, 12

Weitere ähnliche Inhalte

Ähnlich wie W3C DNT Presentation for AdMonsters

Online Collaboration — Delivering Benefits for Organisations and Participants
Online Collaboration — Delivering Benefits for Organisations and ParticipantsOnline Collaboration — Delivering Benefits for Organisations and Participants
Online Collaboration — Delivering Benefits for Organisations and Participants
danrandow
 
ISYS 363 Group Task 1
ISYS 363 Group Task 1ISYS 363 Group Task 1
ISYS 363 Group Task 1
schaudhary13
 

Ähnlich wie W3C DNT Presentation for AdMonsters (20)

Tech For Good Meetup 10.11.14 The Good Data
Tech For Good Meetup 10.11.14 The Good DataTech For Good Meetup 10.11.14 The Good Data
Tech For Good Meetup 10.11.14 The Good Data
 
Privacy and social media for Australian governments
Privacy and social media for Australian governmentsPrivacy and social media for Australian governments
Privacy and social media for Australian governments
 
GDPR within Google Tag Manager - Measurecamp 2018
GDPR within Google Tag Manager - Measurecamp 2018GDPR within Google Tag Manager - Measurecamp 2018
GDPR within Google Tag Manager - Measurecamp 2018
 
Grant 2011.0918
Grant 2011.0918Grant 2011.0918
Grant 2011.0918
 
Privacy, Encryption, and Anonymity in the Civil Legal Aid Context
Privacy, Encryption, and Anonymity in the Civil Legal Aid ContextPrivacy, Encryption, and Anonymity in the Civil Legal Aid Context
Privacy, Encryption, and Anonymity in the Civil Legal Aid Context
 
Web analytics: Practical steps to GDPR compliance
Web analytics: Practical steps to GDPR complianceWeb analytics: Practical steps to GDPR compliance
Web analytics: Practical steps to GDPR compliance
 
5 tactics for practical privacy protection
5 tactics for practical privacy protection5 tactics for practical privacy protection
5 tactics for practical privacy protection
 
Online Focus Groups Privacy and Security Considerations
Online Focus Groups Privacy and Security ConsiderationsOnline Focus Groups Privacy and Security Considerations
Online Focus Groups Privacy and Security Considerations
 
Trendstechnology
TrendstechnologyTrendstechnology
Trendstechnology
 
Online privacy & security
Online privacy & securityOnline privacy & security
Online privacy & security
 
Info leakage 200510
Info leakage 200510Info leakage 200510
Info leakage 200510
 
Service goes accessible_2013_sh
Service goes accessible_2013_shService goes accessible_2013_sh
Service goes accessible_2013_sh
 
Free your metadata
Free your metadataFree your metadata
Free your metadata
 
Cip Multichannel Retail Webcast 091112 (2)
Cip Multichannel Retail Webcast 091112 (2)Cip Multichannel Retail Webcast 091112 (2)
Cip Multichannel Retail Webcast 091112 (2)
 
International Cooperative: APT Hunting
International Cooperative: APT HuntingInternational Cooperative: APT Hunting
International Cooperative: APT Hunting
 
Online Collaboration — Delivering Benefits for Organisations and Participants
Online Collaboration — Delivering Benefits for Organisations and ParticipantsOnline Collaboration — Delivering Benefits for Organisations and Participants
Online Collaboration — Delivering Benefits for Organisations and Participants
 
Letter to Google CEO Larry Page from privacy advocates
Letter to Google CEO Larry Page from privacy advocatesLetter to Google CEO Larry Page from privacy advocates
Letter to Google CEO Larry Page from privacy advocates
 
Online Privacy & Computer Security Basics (September 2017)
Online Privacy & Computer Security Basics (September 2017)Online Privacy & Computer Security Basics (September 2017)
Online Privacy & Computer Security Basics (September 2017)
 
ISYS 363 Group Task 1
ISYS 363 Group Task 1ISYS 363 Group Task 1
ISYS 363 Group Task 1
 
Exploring Data Privacy - SQL Saturday Louisville 2011
Exploring Data Privacy - SQL Saturday Louisville 2011Exploring Data Privacy - SQL Saturday Louisville 2011
Exploring Data Privacy - SQL Saturday Louisville 2011
 

Kürzlich hochgeladen

Kürzlich hochgeladen (20)

Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdf
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 

W3C DNT Presentation for AdMonsters

  • 1. Tracking Protection Working Group Aleecia M. McDonald 3 May, 2012 1 Friday, May 4, 12
  • 2. Introduction of the W3C ✤ World Wide Web Consortium creates international standards for the Internet ✤ Sir Tim Berners-Lee ✤ Created the World Wide Web, 1989 ✤ Created the W3C, 1994 ✤ Successful track record with standards for HTML, XML, CSS, etc. ✤ Hundreds of billions of dollars of commerce runs on W3C standards 2 Friday, May 4, 12
  • 3. Introduction of co-chairs ✤ Aleecia M. McDonald ✤ Matthias Schunter ✤ Half-time Mozilla Senior ✤ IBM Research in Switzerland Privacy Researcher ✤ Focus on cloud computing, ✤ Half-time Stanford security, and privacy Resident Fellow ✤ P3P standards experience ✤ Prior: PhD privacy; software start ups 3 Friday, May 4, 12
  • 4. Approach for Do Not Track ✤ User agent expresses a preference not to be tracked HTTP header of DNT:1 ✤ Shipping today; standards work answers “what does tracking mean?” ✤ Websites / applications choose to honor DNT, confirm with response ✤ Adoption is entirely voluntary; W3C cannot compel members to act 4 Friday, May 4, 12
  • 5. Diverse TPWG Membership ✤ 70+ group participants, plus observers ✤ Browser companies: Apple, Google, Opera, Microsoft, Mozilla ✤ Wide membership range including Alcatel-Lucent; Adobe; AdTruth; Article 29 Working Party; AT&T; CDD; CDT; Chapell & Associates; Deutsche Telekom; EFF; ESOMAR; Facebook; IAB Europe; Nielsen; Nokia; Online Publishers Association; TRUSTe; Yahoo!; The Walt Disney Company 5 Friday, May 4, 12
  • 6. Writing Standards Documents 1. Definitions & Compliance 2. Tracking Preference Expression ✤ Chair: Aleecia M. McDonald ✤ Chair: Matthias Schunter (IBM) (Mozilla) ✤ Editors: Roy Fielding (Adobe), ✤ Editors: Justin Brookman & Erica David Singer (Apple) Newland (CDT); Sean Harvey & Heather West (Google) 3. Tracking Selection Lists ✤ Chair: Matthias Schunter ✤ Editors: Karl Dubost (Opera); Andy Zeigler (Microsoft) 6 Friday, May 4, 12
  • 7. Three Types of Parties 1. First party 2. Service provider ✤ Not directly liable for others’ ✤ Agents of first parties, actions contractual relationship ✤ Very few restrictions ✤ Cannot share data across multiple first parties or use ✤ Cannot share data with for their own purposes others, or else must act as a third party ✤ Debating exceptions ✤ Can be multiple 1st; depends 3. Third parties with strong upon meaningful interaction restrictions, plus exceptions 7 Friday, May 4, 12
  • 8. Uniform Signals, Different Results Eleven Point One Onze Comma Un Punt Elf Elf Komma Eins 8 Friday, May 4, 12
  • 9. Tri-part DNT Signal ✤ Three options DNT: 1 - enable DNT, user saying “do not track me” DNT: 0 - do not enable DNT Nothing - users have not made a selection ✤ US, Nothing: ✤ EU, Nothing: ✤ Users did not choose to ✤ Users did not consent to enable DNT tracking ✤ Similar to DNT: 0 ✤ Similar to DNT: 1 9 Friday, May 4, 12
  • 10. Site-specific Exemptions ✤ Many countries can have a ✤ Some countries may not allow a global DNT: 1 value global DNT: 1 ✤ Companies want to ask to ✤ Consent may be site-by-site track anyway ✤ Use same technical mechanism in both cases ✤ Exception specific to advertiser on that particular first party, not global for the advertiser across the whole Internet and/or ✤ Exception global for a specific third party, Internet wide 10 Friday, May 4, 12
  • 11. Current Big Unresolved Issues 1. Edges of a party 2. Permitted uses for third parties, perhaps with retention limits, ✤ User expectations and e.g. branding ✤ Frequency capping ✤ “Discoverable” based on corporate ownership ✤ Billing and financial logging ✤ 3rd party auditing ✤ Security and fraud prevention 11 Friday, May 4, 12
  • 12. Opportunities ✤ For feedback: ✤ For media: ✤ Speaking with WG on call ✤ Internet week, May 17th ✤ Joining the WG ✤ Mozilla blog ✤ Community Group ✤ Jonathan’s list of DNT implementations ✤ Individual comments on Last Call draft 12 Friday, May 4, 12
  • 13. Interested in Learning Thoughts... ✤ Response mechanism ✤ Hard to get user consent when brand unknown ✤ HTTP header ✤ Does 3rd party acting as 3rd ✤ Well-known URL party help? ✤ How do you propagate opt-out ✤ Auditing, billing status now? ✤ Silo data ✤ Consent for specific sites ✤ Biggest technical challenge to ✤ EU consent issues implement? 13 Friday, May 4, 12
  • 14. Tracking Protection Working Group Aleecia M. McDonald 3 February, 2012 14 Friday, May 4, 12
  • 15. Photo credits ✤ Tim: http://i.telegraph.co.uk/multimedia/archive/00682/ bernerslee-404_682192c.jpg ✤ Elephant: http://www.flickr.com/photos/paperpariah/2446224424/ sizes/o/in/photostream/ ✤ Adam Foster | Codefor ✤ “! danger elephants at Knowsley Safari Park?” ✤ Cash register: http://www.flickr.com/photos/teflon/4995681266/ ✤ Martin Deutsch 15 Friday, May 4, 12