Re: ACTION-252: Propose defining formerly-known-as absolutely-not-tracking via permitted uses

Clarifying question: how would this apply to a first party? 

	Aleecia

On Sep 11, 2012, at 11:39 PM, Roy T. Fielding <fielding@gbiv.com> wrote:

> Hi Nick,
> 
> This seems reasonable.  I prefer (2) -- "n" as a qualifier, since
> it could be orthogonal to the status value and it would provide
> a believable use case for having optional qualifiers.  It would
> also mean the TSV of "N" goes away.
> 
> ....Roy
> 
> On Sep 10, 2012, at 12:30 AM, Nicholas Doty wrote:
> 
>> I volunteered to take an action to avoid defining "absolutely-not-tracking" (or some similar term, none of which the group has taken to) and instead just rely on permitted uses. The idea is that we don't need any additional level like "anonymous" or "not tracking" (what conditions would such a level have to meet, anyway? would they be a subset of or distinct from our list of permitted uses?); we already have the functionality to say which permitted uses are claimed and can include the ability to claim none.
>> 
>> The current editor's draft contains a Tracking Status Value (in 5.2) of N:
>>> None: The designated resource does not perform tracking of any kind, not even for a permitted use, and does not make use of any data collected from tracking.
>> 
>> And also has optional Tracking Status Qualifier Values for enumerating permitted uses if the server so desires.
>> 
>> I think there are two plausible options for enabling services to note which permitted uses they take advantage of, or none altogether, without debating "absolutely not tracking", both of which would be optional (and likely infrequently used) and straightforward.
>> 
>> 1) Change TSV of "N" to signify:
>>> No Permitted Uses: The designated resource does not perform tracking, even for the defined list of permitted uses.
>> If the Compliance draft ends up with different terminology, this could be changed slightly to, for example:
>>> No Permitted Uses: The designated resource does not retain or use data, even for the defined list of permitted uses.
>> 
>> 2) Add a TSQV of "n" to signify:
>>> No Permitted Uses: No tracking is performed, including for any of the permitted uses.
>> And then note that "n" must not be used with any of the other qualifiers.
>> 
>> In either case, I think we would actually want to add the following requirements (which I believe just clarifies our existing understanding) to the TSQV:
>>> Servers MAY indicate which permitted uses are being used with the tracking status qualifier member. If no qualifier is present, the server might be tracking for any or all of the permitted uses. 
>> And add a clause to an existing sentence:
>>> An origin server indicating one or more of those permitted uses also indicates that it conforms to the requirements associated with those permitted uses _and does not perform tracking for any other permitted uses not listed_.
>> 
>> Thanks,
>> Nick
> 
> 
> 

Received on Wednesday, 12 September 2012 15:33:20 UTC