In Part 1 of my blog on the Microsoft Internet Explorer 9 (IE9) Tracking Protection List (TPL) feature I discussed why it was important to do something about tracking. Now lets talk just a little bit about how tracking and the TPLs work and then spend most of the article on which TPLs you should use with IE9.
Tracking Protection Lists are simply lists of web addresses that Internet Explorer should NOT communicate with unless the user directly goes to the site. In other words, they tell Internet Explorer not to engage in third-party communications with that web address. TPLs can also include instructions to explicitly allow third-party communications with a web address. I’ll explain why that is important in a minute. You could actually use TPLs in a number of ways beyond what Microsoft has explicitly designed them for. For example, beyond limiting tracking you can also use them to actually block the display of third-party ads. But we’ll focus on tracking protection.
What Microsoft hasn’t done is create an actual Tracking Protection List for users, it is relying on third parties to do that. You can find a set of TPLs by clicking on the tools (gear box) icon in IE9, then Safety->Tracking Protection. There you will find a link to get “Tracking Protection Lists Online”. Clicking it will show you a set of lists, with very poor descriptions of what they do. Ed Bott did some analysis of the lists as of last February and I’m using his data in my analysis. You can use more than one list, and which one(s) you choose is based on what your goal is.
In Part 1 of this series I broke the actors who are tracking down into three categories which I’ll recast here. “Good Guys” are those who are tracking you so they can provide a better web experience and have strong privacy protection policies in place. “Careless Guys” are those whose motives may be good, but whose privacy protection policies and/or operations are suspect. “Bad Guys” are everybody else. The question you have to ask yourself is, are you willing to let some of these actors (e.g., the Good Guys) track you while blocking the others or do you just not want to be tracked at all? As a reminder, letting yourself be tracked results in more appropriate ads (e.g., diaper ads for a new mother and sports car ads for an empty nest guy going through a mid-life crisis). And in the future you might find websites that block your access to content unless you allow them to track you and display appropriate ads. So you need to make a decision just how much you want to give in to tracking paranoia.
The most important list you need to know about, and the one I recommend, is the EasyPrivacy Tracking Protection List. This list is the most aggressive at blocking tracking. The EasyPrivacy list is taken directly from the popular Adblock Plus add-in for Firefox, so it has a long history and a very active volunteer community dedicated to eliminating third-party tracking. But of course, it is going to block the “Good Guys”. Fortunately for all of us, if you want to re-enable the “Good Guys” then you can simply add another list. TRUSTe’s TRUSTed Tracking Protection List is a list of what are supposed to be the “Good Guys” as determined by TRUSTe.
That sounds easy doesn’t it? Add one list if you are “paranoid” about tracking, then add a second if you want some tracking protection but don’t want to interfere too much with the web experience. There is a caveat there of course, you have to trust TRUSTe to only have the “Good Guys” on its list. I think for most users this is an ok assumption, though the TRUSTe “Good Guy” list is long enough that it makes me wonder if some “Carless Guys” are actually on it. Still, nothing is perfect.
There are other choices in Tracking Protection Lists. For example, instead of the two lists I mention above you could use the lists from PrivacyChoice. There are two, one that blocks all third-party tracking that PrivacyChoice knows about. This would be the list for the “paranoid”. The other is a PrivacyChoice that only blocks tracking sites that are not part of the Network Advertising Initiative (NAI). The NAI is another attempt at identifying the “Good Guys”. So if you believe NAI has a better program than TRUSTe then the PrivacyChoice TPL blocking companies without NAI oversight is for you.
There are other lists such as Albine (which has one list specifically designed to block tracking on kid-oriented web sites), and then FanBoy which seems similar to EasyPrivacy. These might be of interest, but require more investigation.
There you have it. If I were you I’d go turn on IE9’s Tracking Protection List feature immediately. Either EasyPrivacy + TRUSTe or EasyPrivacy alone.
Thanks for the article Hal. I will have to enable the TPL on my machine. So I was wondering if IE9 blocks 3rd party cookies by default? I know IE8 does, however cannot see if IE9 automatically does so.