dsriedel: testing something
17:03:46 [npdoty]
17:04:05 [Zakim]
17:04:07 [npdoty]
Zakim, who is on the phone?
17:04:08 [hefferjr]
hefferjr has joined #dnt
17:04:12 [sharvey]
sharvey has joined #dnt
17:04:13 [Zakim]
+ +1.202.263.aaii
17:04:20 [punderwood]
punderwood has joined #dnt
17:04:21 [Zakim]
+ +1.334.703.aajj
17:04:23 [Zakim]
On the phone I see aleecia, npdoty, NinjaMarnau, dsriedel (muted), PederMagee, efelten, AlexDeliyannis, Bjorn,Satish, dwainberg, [IPcaller], Joanne, jmayer, [IPcaller.a], WileyS,
17:04:24 [hwest]
hwest has joined #dnt
17:04:26 [Zakim]
... Bryan_Sullivan, Justin, [Mozilla], sharvey, +1.908.541.aaff, fielding, +1.650.485.aagg, +1.202.326.aahh, tedleung, +1.202.263.aaii, +1.334.703.aajj
17:04:27 [fielding]
fielding has joined #dnt
17:04:30 [Lia]
+1.202.263.aaii is Lia
17:04:31 [Zakim]
[Mozilla] has sidstamm
17:04:32 [enewland]
enewland has joined #dnt
17:04:33 [Zakim]
17:04:33 [aleecia]
17:04:37 [Zakim]
+ +1.813.366.aakk
17:04:50 [dsriedel]
Review Action Items
17:05:07 [Zakim]
+ +1.202.744.aall
17:05:11 [Chris]
Chris has joined #dnt
17:05:24 [vincent]
Zakim, [IPcaller] is vincent
17:05:26 [fielding]
fielding has joined #dnt
17:05:49 [npdoty]
17:05:49 [trackbot]
ACTION-34 -- Jonathan Mayer to draft Near-Consensus First Party vs. Third Party Section with Tom -- due 2011-11-25 -- OPEN
17:05:49 [trackbot]
17:05:53 [Zakim]
+vincent; got it
17:06:01 [dsriedel]
Action Item 10 open
17:06:01 [trackbot]
Sorry, couldn't find user - Item
17:06:03 [fielding]
fielding has joined #dnt
17:06:17 [dsriedel]
What is the status on Action Item 10
17:06:36 [dsinger]
dsinger has joined #dnt
17:06:38 [npdoty]
17:06:42 [Zakim]
17:06:44 [dsriedel]
jmayer: draft written, but not ready yet. back to the drawing board, something ready within 1 week
17:06:47 [enewland]
zakim, who is on the phone?
17:06:47 [dsinger]
zakim, [apple] has dsinger
17:06:51 [JC]
JC has joined #DNT
17:06:53 [Zakim]
On the phone I see aleecia, npdoty, NinjaMarnau, dsriedel (muted), PederMagee, efelten, AlexDeliyannis, Bjorn,Satish, dwainberg, vincent, Joanne, jmayer, [IPcaller.a], WileyS,
17:06:59 [Zakim]
... Bryan_Sullivan, Justin, [Mozilla], sharvey, +1.908.541.aaff, fielding, +1.650.485.aagg, +1.202.326.aahh, tedleung, +1.202.263.aaii, +1.334.703.aajj, hwest, +1.813.366.aakk,
17:07:03 [Zakim]
... +1.202.744.aall, [Apple]
17:07:06 [Zakim]
[Mozilla] has sidstamm
17:07:07 [enewland]
zakim, aajj is enewland
17:07:08 [Zakim]
+dsinger; got it
17:07:14 [Zakim]
+enewland; got it
17:07:23 [Zakim]
17:07:31 [Zakim]
17:07:38 [dsriedel]
aleecia: next action item 38 - ISSUE-19
17:07:40 [Frankie]
zakim IPcaller.a is Frankie
17:07:47 [Zakim]
17:08:21 [dsriedel]
aleecia: action 36 review on friday with assignees
17:08:27 [npdoty]
I think actions 31 and 36 are overdue
17:08:35 [JC]
3326 is JC
17:08:54 [clay_opa_cbs]
clay_opa_cbs has joined #dnt
17:08:56 [dsriedel]
WileyS: On action 31 still in progress
17:09:05 [dsriedel]
... progress made, but big issues
17:09:21 [WileyS]
Next week
17:09:29 [WileyS]
17:09:40 [Zakim]
17:09:45 [npdoty]
action-31 due next Wednesday
17:09:45 [trackbot]
ACTION-31 Write up a proposal for a user-agent-managed site-specific exception due date now next Wednesday
17:09:56 [dsriedel]
aleecia: Next item on the agenda: new business
17:10:11 [ksmith]
ksmith has joined #DNT
17:10:28 [npdoty]
Topic: New business
17:10:47 [Zakim]
+ +1.347.689.aamm
17:10:49 [Frankie]
17:11:09 [aleecia]
ack Frankie
17:11:13 [dsriedel]
aleecia: started to assign issues to people, awaiting feedback on them
17:11:33 [Zakim]
+ +385221aann
17:11:33 [dsriedel]
Frankie: First draft on item for end of next week
17:13:05 [hwest]
I'm happy to help with identity language
17:13:15 [dsriedel]
aleecia: going through the list of items
17:13:17 [chuckc]
chuckc has joined #dnt
17:13:22 [hwest]
If it's not a conflict to have an editor draft it
17:14:11 [dsriedel]
aleecia: hwest jumps in to draft on item about identity language
17:14:26 [npdoty]
hwest to draft text on ISSUE-32
17:15:26 [Chris_]
Chris_ has joined #dnt
17:17:43 [Zakim]
17:17:43 [JC]
17:17:56 [WileyS]
17:18:00 [WileyS]
No problem
17:18:12 [dsinger]
17:18:15 [Zakim]
17:18:42 [andyzei]
andyzei has joined #dnt
17:20:01 [JC]
Amy is out
17:20:13 [JC]
This week
17:21:46 [dsriedel]
aleecia: checking with people on the call about their assigned items. makes note to contact people who are not on the call
17:22:15 [Zakim]
17:22:16 [WileyS]
Jealous of Jonathan!
17:22:50 [Zakim]
17:23:09 [dsriedel]
aleecia: ISSUE-37 to discuss now on the call
17:23:21 [npdoty]
17:23:21 [trackbot]
ISSUE-37 -- Granularity based on business types and uses -- raised
17:23:21 [trackbot]
17:23:49 [dsriedel]
aleecia: how does this happen on a practical level?
17:24:44 [WileyS]
17:24:47 [dsriedel]
... Should it be company by company or on interest based levels, like in current implementations
17:25:50 [WileyS]
Too early to rely on ePrivacy Directive
17:25:57 [dsriedel]
... New cookie directive implies that a DNT:0 does not say on a global level that the user consents with tracking. - EU countries
17:26:10 [aleecia]
ack WileyS
17:26:56 [bryan]
Link to email?
17:27:07 [npdoty]
q+ to ask about more requirements/use cases for an opt-back-in
17:27:18 [bryan]
17:27:19 [npdoty]
bryan, only among a few of us at the moment
17:28:57 [dsriedel]
WileyS: difficult to disambiguate policy and technical aspects ... group around-31 discusses some use cases ... 1st-parties should ask for an exception regarding DNT for their 3rd parties ... a site asks for exception for itself and its 3rd-parties ... that is one case to look at
17:29:33 [bryan]
17:29:59 [dsriedel]
... at which time you ask for exceptions ... when the user enters a page ...
17:30:11 [dsriedel]
... these are open questions ...
17:30:24 [bryan]
is it assumed that new 3rd parties are only disclosed when the user pulls content from the site, or is there a push notification being considered?
17:30:41 [justin]
Getting permission for "any third party we might want to give approval to track you across any site" leads to absurd results.
17:30:50 [dsriedel]
ePrivacy directive in the EU is not yet fully implemented or within national laws, so it might be early to derive conclusions from that...
17:31:05 [aleecia]
17:31:11 [npdoty]
s/ePrivacy/... ePrivacy/
17:31:39 [dsriedel]
WileyS: The EU situation is complex and confused at the moment so it is not clear how much of the working group can take from the directive at the moment
17:31:46 [aleecia]
ack npdoty
17:31:46 [Zakim]
npdoty, you wanted to ask about more requirements/use cases for an opt-back-in
17:32:42 [aleecia]
ack bryan
17:32:44 [jmayer]
17:32:44 [dsriedel]
npdoty: Requirements and use cases regarding opting back in. Are there any other requirements and use cases the group has?
17:33:01 [JC]
17:33:40 [ninjamarnau]
17:33:41 [npdoty]
bryan: what happens when there's a new third party?
17:34:15 [npdoty]
... what happens when data is shared with an additional third party while the user isn't browsing the site any more?
17:34:58 [dsriedel]
bryan: When is the use informed only when pulling content from the site about the DNT status or also in other ways? For example when a new 3rd-party is acting on the site and the user gave an earlier consent. Is there only a notice on pulling conetnt from the site
17:35:12 [dsriedel]
WileyS: different options for the user, how he wants to be informed
17:35:18 [dsriedel]
... every time he enters
17:35:26 [dsriedel]
... maybe in an aggregated form
17:35:40 [bryan]
17:35:59 [dsriedel]
aleecia: there might be cases where a consent everytime might be needed, there are others who this might not be necessary.
17:36:06 [aleecia]
ack jmayer
17:36:59 [dsriedel]
jmayer: Use case. User: I like what facebook does on other sites, I trust them.
17:37:06 [WileyS]
Agreed - only in context of a 1st party relationship or everywhere
17:37:24 [aleecia]
ack JC
17:37:25 [dsriedel]
... globally flag a 3rd-party as trusted.
17:37:32 [npdoty]
I agree that that use case might be easier
17:37:35 [justin]
Doesn't the permission to third-party have to be global? Otherwise, they're basically just a service provider, and they're not covered by DNT!
17:37:45 [npdoty]
and we might not need it in the protocol
17:38:04 [dsriedel]
JC: as having a trusted relationship with a 1st-party site, you might also trust them as 3rd-parties
17:38:10 [justin]
There's no need to get a permission to let Yahoo! track me just on the NYT . . .
17:38:24 [dsinger]
17:38:32 [aleecia]
ack ninjamarnau
17:39:03 [Job]
Job has joined #dnt
17:39:22 [npdoty]
jc: better to have the capability to sign up with whole groups of third parties (nai, etc.)
17:39:23 [dsriedel]
ninjamarnau: user should not allow blindly a group of 3rd-parties tracking. User should have site, party specific excemptions. EU needs granularity.
17:39:31 [Frankie]
17:39:41 [Job]
Just joined IRC. No phone...
17:39:53 [aleecia]
17:40:00 [aleecia]
ack bryan
17:40:10 [aleecia]
ack dsinger
17:40:10 [dsriedel]
... example: he can allow facebook social plugin and therefore allows it as plugin on diferent sites.
17:40:15 [dsinger]
I think it is debatable whether people are happy with sites they know as 1st parties, being 3rd parties. In specific, many people I know are not happy with the sense that social network buttons on other sites can watch/track their other browsing etc.
17:40:20 [jmayer]
17:40:35 [JC]
I'm only saying people have a choice
17:40:43 [npdoty]
ninjamarnau, just to make sure I got your point there, you're saying that a user might opt in to a third party across sites, but only for certain types of resources from that third party
17:40:45 [jmayer]
17:40:45 [justin]
jmayer, sure, but the value of behavioral tracking (which is for the most part what we're talking about) comes from cross-site data. I don't see much of a use case for getting a permission for incrementally better tracking on just one site
17:40:58 [dsriedel]
dsinger: user might disagree with a 1st-party having a plugin tracking them on other sites being a 3rd-party
17:41:00 [WileyS]
Agreed - Internet-wide Exceptions should be consent driven, as well as, site-specific exceptions
17:41:39 [WileyS]
Internet-wide vs. site-specific - feels like a fair distinction
17:41:44 [WileyS]
I didn't say that Ninja
17:42:01 [dsriedel]
ninjamarnau: disagree with neglecting the ePrivdacy directive in this WG
17:42:13 [npdoty]
is anyone interested in the use case of "you can track me, but only for analytics" or similar?
17:42:23 [dsriedel]
aleecia: not sure WileyS neglects it, but sees that it is work in progress
17:42:29 [Zakim]
+ +1.650.862.aaoo
17:42:34 [npdoty]
per issue-37
17:42:34 [Johnsimpson]
Johnsimpson has joined #dnt
17:42:36 [Zakim]
- +1.650.485.aagg
17:42:44 [aleecia]
17:42:52 [dsriedel]
... so we will have places where we pay attention to it and some where we dont
17:42:53 [aleecia]
ack Frankie
17:42:56 [justin]
jmayer, Definitely, but I think most of that can be done outside of the scope of DNT.
17:42:59 [Johnsimpson]
Have joined irc. No telephone, though.
17:43:53 [dsriedel]
Frankie: Facebook and their plugin is a very simple example. there are scenarios with advertising networks and advertisers behind which draw more complex scenarios.
17:44:19 [dsriedel]
... have to consider this and work and more use cases
17:44:31 [ninjamarnau]
this is the difference between any consent and informed consent
17:45:03 [dsriedel]
speaker: another use case - consent for analytics and not trakcing
17:45:12 [ninjamarnau]
ndoty, i would be very interested
17:45:15 [Lia]
I would find that useful
17:45:16 [fielding]
17:45:18 [jmayer]
17:45:19 [fielding]
17:45:20 [JC]
I felt that was the premise of DNT
17:45:21 [npdoty]
17:45:32 [dsriedel]
... interest in looking into the option that the user can define what technique he allows and which not
17:45:39 [aleecia]
ack jmayer
17:45:44 [dsriedel]
aleecia: there are ppl who want to consider this
17:45:58 [WileyS]
Internet-Wide vs. Site-Specific vs. Use-Specific Exceptions (all driven by user consent)
17:46:08 [aleecia]
ack fielding
17:46:14 [dsriedel]
jmayer: yes, there is use for this in form of allow rules for example
17:46:36 [justin]
I would prefer to see outsourced analytics and first-party behavioral tracking to be out of scope (as commonly-accepted exceptions to DNT), and the permission to third-parties would allow them to track you across the web.
17:46:51 [dsriedel]
fielding: once dnt is expressed it is the responsibility of the sites to know how to reply/work with this
17:47:03 [WileyS]
Agree with Justin
17:47:06 [bryan]
17:47:06 [aleecia]
17:47:25 [dsriedel]
aleecia: back to ISSUE-37
17:47:37 [vincent]
17:47:47 [justin]
Close it!
17:47:48 [bryan]
(+1) Agree with both Justin and Roy
17:47:51 [aleecia]
ack vincent
17:47:53 [dsriedel]
... no support for the idea on interest categories - or anyone?
17:48:04 [dsriedel]
vincent: started prototype on this interested based DNT
17:48:22 [npdoty]
I thought ninja, lia, JC were supportive of use-based granularity for opt-back-in, when I brought it up earlier
17:48:59 [JC]
and Microsoft
17:49:10 [dsriedel]
aleecia: business type == interest groups
17:49:24 [ninjamarnau]
ndoty, no not use based - more based on a specific third party
17:49:54 [dsriedel]
aleecia: should we have the google, yahoo interest group style for DNT?
17:49:55 [npdoty]
Lia, can you explain your interest in this granularity?
17:49:56 [vincent]
I do :)
17:50:17 [npdoty]
JC, can you give more detail on Microsoft's interest in this type of granularity?
17:50:44 [JC]
We provide an interest manager similar to Yahoo & Google
17:51:00 [JC]
Not that we are intersted in this type of DNT approach
17:51:14 [Lia]
I was referring to granularity for specific uses of tracking like analytics
17:51:17 [dsriedel]
WileyS: we have 3 levels of exception. Internet-wide, site specific and use specific exceptions. Down the use specific path it could include the interest based approach. User could give a list of interests to allow tracking for.
17:51:24 [JC]
I don't think that would work
17:52:02 [vincent]
17:52:26 [dsriedel]
aleecia: the granularity regarding an interest area for the user for a 3rd-party on a 1st-party site could be tricky and not very useful
17:52:47 [JC]
Agree with Google
17:52:50 [npdoty]
jmayer, were you assuming that exceptions would be blanket allow rules? or prefer that the exceptions would be for specific collections/uses?
17:52:58 [vincent]
17:53:03 [jmayer]
One reason using existing web tech has some promise for opt-in consent: can create arbitrary types of opt-in.
17:53:03 [dsriedel]
speaker: the standard should not include any granularity like interest based filters
17:53:12 [npdoty]
17:53:12 [fielding]
I meant that, once DNT is expressed, the myriad details of how 1st and 3rd parties are implemented are not really our concern -- we should express the requirements in terms of when and what data can be collected and shared given the presence of DNT since that subject is less site-unique than implementation.
17:53:19 [vincent]
17:53:28 [aleecia]
ack vincent
17:53:46 [dsriedel]
aleecia: We close the discussion on ISSUE-37 for now and make a note about that it is category based/user interests
17:53:48 [aleecia]
going to close issue-37 as no, we won't do interest-based categories
17:54:24 [jmayer]
npdoty, I don't think there should be any blanket allow rules. Every exception should be for specific collection/retention/use.
17:54:49 [jmayer]
npdoty, It's not a great approach, but privacy policies are a starting point.
17:54:52 [dsinger]
17:54:52 [trackbot]
ISSUE-37 -- Granularity based on business types and uses -- raised
17:54:52 [trackbot]
17:54:59 [dsriedel]
vincent: have more look on this issue-37 and use cases
17:55:10 [dsriedel]
aleecia: issue-37 closed for now
17:55:14 [dsinger]
17:55:14 [trackbot]
ISSUE-57 -- What if an opt-out cookie exists but an "opt back in" out-of-band is present? -- raised
17:55:14 [trackbot]
17:55:38 [jmayer]
17:55:47 [WileyS]
17:56:02 [jmayer]
17:56:07 [dsriedel]
aleecia: ISSUE-57. Conflict between opt-out cookie and an excemption for the same company
17:56:13 [Zakim]
- +1.202.263.aaii
17:56:13 [aleecia]
ack WileyS
17:56:54 [dsinger]
17:57:05 [jmayer]
17:57:12 [aleecia]
ack dsinger
17:57:23 [dsriedel]
WileyS: Idea. Remove the opt-out cookie when there is a DNT:0, but when there is DNT:1 or now info, respect the cookie.
17:58:02 [npdoty]
17:58:08 [dsriedel]
dsinger: the more granular decision is the one that controls
17:58:17 [aleecia]
ack jmayer
17:58:52 [WileyS]
We should document these use cases
17:59:20 [aleecia]
I'd like use cases and examples in the spec
17:59:29 [sidstamm]
+1 to jmayer
17:59:33 [dsriedel]
jmayer: we have to look in the sequences when users opt- in or -out and when they do so and in which order, there might be ambiguity
17:59:41 [aleecia]
ack npdoty
17:59:44 [punderwood]
punderwood has joined #dnt
17:59:49 [fielding]
18:00:11 [hwest]
Have to drop early - sorry!
18:00:13 [Zakim]
18:00:20 [aleecia]
thanks, Heather
18:00:23 [Zakim]
18:00:45 [jmayer]
s/ambiguity/ambiguity; would propose instead a principle of taking the min of all choice mechanisms/
18:00:54 [aleecia]
ack fielding
18:01:25 [aleecia]
min would mean no override for DNT:1
18:01:44 [aleecia]
most recent is tempting but crazy to figure out unless we want to timestamp DNT
18:01:49 [ileana]
ileana has joined #dnt
18:01:50 [dsriedel]
fielding: cookie based mechanisms to opt-back-in should be respected, another area of conflict
18:02:15 [aleecia]
18:02:15 [jmayer]
18:02:22 [aleecia]
ack jmayer
18:02:32 [Zakim]
18:02:58 [punderwood]
punderwood has left #dnt
18:03:01 [dsriedel]
jmayer: agree if there are opt-in signals in the mix, regarding cookie based op-in and -outs, especially regarding browsers who (still) do not support DNT
18:03:10 [sidstamm]
18:03:26 [aleecia]
ack sidstamm
18:04:06 [WileyS]
User-Agent + Cookie State
18:04:15 [WileyS]
Interesting new dimension to consider
18:04:29 [dsriedel]
sidstamm: if the browser does not have a possibility to give more granularity than telling the whole internet: do not track, a cookie based opt-in and -out should be respected for the sake of granularity
18:05:01 [karl]
karl has joined #dnt
18:05:02 [aleecia]
18:05:15 [dsriedel]
speaker: asking for more use cases
18:05:25 [npdoty]
18:06:00 [jmayer]
s/support DNT/support DNT; would propose starting with a min rule and then carving out exceptions as necessary; we just need to agree to a clear order of precedence/
18:06:21 [dsriedel]
aleecia: we will get more cases or details on this as ppl are writing up on this issue in the next weeks
18:06:42 [Zakim]
18:06:59 [dsriedel]
aleecia: ISSUE-27. Anyone wants to add something to this?
18:06:59 [sidstamm]
apologies to all, as usuall I have to drop off early
18:07:07 [Zakim]
18:07:09 [WileyS]
Meeting schedule through the holidays?
18:07:27 [WileyS]
I'm out the last 2 weeks of the year - hence my question.
18:07:30 [JC]
Any updates on f2f in Belgium?
18:07:40 [JC]
I'm out as well
18:07:49 [fielding]
me too
18:07:54 [dsriedel]
aleecia: not talked about this too much yet. 14th of december another call. how about 21st?
18:07:56 [WileyS]
My vote is no on 21st and 28th.
18:08:03 [JC]
18:08:16 [npdoty]
I can do 21st and 28th.
18:08:23 [ninjamarnau]
yes for 21st no for 28th
18:08:24 [dsriedel]
aleecia: 28th not clear who will chair it yet
18:08:31 [efelten_]
18:08:31 [npdoty]
can you make the 21st?
18:08:31 [vincent]
18:08:33 [npdoty]
18:08:33 [enewland]
18:08:33 [Frankie]
no preferences on this - already in the office :-(
18:08:34 [tedleung]
I can make the 21st
18:08:34 [ninjamarnau]
18:08:35 [jmayer]
18:08:36 [dsriedel]
18:08:37 [dsinger]
ok 21st
18:08:37 [jmayer]
18:08:37 [andyzei_]
andyzei_ has joined #dnt
18:08:38 [jmayer]
18:08:38 [fielding]
18:08:43 [Chris_]
18:08:51 [bryan]
18:08:51 [Joanne]
18:08:52 [clay_opa_cbs]
18:08:52 [JC]
18:08:53 [WileyS]
18:08:54 [andyzei_]
18:08:55 [Frankie]
18:08:56 [Lia]
18:08:58 [andyzei_]
err -1
18:08:59 [npdoty]
who can't make the 21st? (-1s)
18:09:11 [Lia]
can make
18:09:12 [punderwood]
punderwood has joined #dnt
18:09:16 [JC]
18:09:16 [andyzei_]
18:09:16 [punderwood]
18:09:18 [aleecia]
-1 for cannot make
18:09:21 [WileyS]
18:09:39 [Zakim]
- +385221aann
18:09:48 [npdoty]
who can make the 28th?
18:09:48 [dsriedel]
aleecia: how about the 28th
18:09:50 [fielding]
-1 28th
18:09:52 [JC]
18:09:52 [dsinger]
-1 28th
18:09:52 [andyzei_]
18:09:52 [clay_opa_cbs]
18:09:53 [npdoty]
18:09:53 [justin]
18:09:53 [Frankie]
18:09:53 [WileyS]
18:09:53 [tedleung]
18:09:54 [ninjamarnau]
18:09:54 [Joanne]
18:09:54 [enewland]
18:09:54 [vincent]
18:09:54 [Chris_]
18:09:55 [jmayer]
18:09:57 [dsriedel]
18:09:57 [bryan]
18:09:58 [jmayer]
18:09:59 [jmayer]
18:10:00 [punderwood]
18:10:18 [aleecia]
18:10:29 [aleecia]
21st: call goes on
18:10:30 [dsriedel]
aleecia: looks like we have a call on the 21st and none on the 28th
18:10:33 [aleecia]
28th: no call
18:10:47 [dsriedel]
aleecia: any disagree?
18:11:21 [dsriedel]
aleecia: anyone wants to get some feedback now regarding their action items they are working on right now? Please go ahead...
18:11:43 [JC]
18:11:50 [dsriedel]
... otherwise we asume you are good to go.
18:11:56 [dsriedel]
... no updates on F2F
18:12:13 [WileyS]
Great call Aleecia - Thank you.
18:12:14 [dsriedel]
aleecia: end call early as we do not see any further commetns
18:12:16 [Zakim]
- +1.202.744.aall
18:12:32 [dsriedel]
... expecting drafts of texts in the next week
