May 23, 2006

  • Some thoughts about Xanga's Footprints...


    First, Xanga's tracker - Footprints - is the ONLY tracker that cannot be defeated by simple anti-tracking counter-measures.  That's because it is a SERVER-side control and not a BROWSER (client) - based control like ALL of the rest of the 3rd party Xanga trackers.


    All client/browser -based trackers can be ever so easily circumvented by proxies, disabling browser settings, etc., and thus permit an unquantifiable amount  of stealth activity to go undetected.  Server-side controls are enforced on the server - you'd have to breach server security to to defeat them and Xanga is betting that no one will.


    Xanga's Footprints, however, currently has one 'hole' purposely left open to afford those of us who may feel restricted or spied upon by a requirement to leave footprints: you can choose not to participate in Footprints and you currently will not be trackable by your username, though you will be tracked by those employing Footprints by country/state.


    Initially, my reaction to this hole, left on Mary's post was harshly negative:


    "You should either provide the service with full integrity (and as a server-based service, it is the only tracker capable of full integrity) or junk it.  A lot of Xangans who will use your tracker will forget that Xangans can always opt to go under the radar.  If you do continue with it in this wounded form, you should put a very strong, large, and bold verbal and graphic reminder on the Footprint Page to that effect."


    John  responded to my comment in a personal email and asked me:


    "Is your sense that the Footprint optout is too stalker-friendly?"


    He also suggested a couple of compensating controls for this 'hole', one of which would be a Footprint User Lock.


    Concerning his suggestion of this Lock, I responded to him with the following:


    "OR...as you suggest, having a compensating control to close the hole.  You mention a "User Footprint Lock".  I imagine this to be a mechanism used in conjuction with Xanga Lock and Footprint to lock out anyone from one's site that decides to opt-out of Footprinting.  If you can devise such a mechanism and it is 100% reliable, then I believe that you will have a perfect blocker-tracker: some people can opt-out (of being tracked and tracking) and still visit some Xanga sites (of those not enforcing the User Footprint Lock);  other people can decide to lock down their site so only those who comply with being Footprinted can visit.  In that case:


    If I agree to Footprinting, I may or may not utilize the Footprint logs, may or may not enforce Xanga Lock and the User Footprint Lock.  If I do use Footprinting with Xanga Lock and User Footprint Lock, then essentially I am creating a "Qualified Protected Environment" with the key being a Xanga username: provide a username to be recorded and you'll be let in.


    If I opt-out of Footprinting, I realize that I won't be able to visit users who employ Xanga Lock with Footprinting and User Footprint Lock.


    Am I getting your sense of User Footprint Lock right?"


    John's response to me?   ...








    "Cool, yah that's exactly how a Footprint Lock would work."


    So my hope is that John and the Xanga Team go ahead and start to compensate for the tracker hole they are affording as an opt-out by developing this User Footprint Lock and keeping us notified of progress in this area.


    To summarize, here's how the tracker security now works, followed by a vision of how it would work with a viable Footprint Lock in place...


    Currently, if you are using Xanga Lock and Footprints and other users are...



    • Not Signed In: they cannot see your page.  
    • Signed In and Not Participating: you'll see their Country or State.
    • Signed In and Participating in Footprints: you'll see their username.

    If, in the future, you are using the Xanga Lock, Footprints, and the Footprint Lock, and other users are... 


  • Not Signed In: they cannot see your page. 
  • Signed In and Not Participating: they cannot see your page. 
  • Signed In and Participating in Footprints: you'll see their username.

    Nobody will be forced to participate in Footprints, but you will have the choice of whether or not you want a Footprint to be an entry token to your blog.


    This works for me.  


    John:  Keep us posted!

Comments (215)

Comments are closed.

Post a Comment

Recent Posts

Categories

The End of Days

May 2006
M T W T F S S
« Apr   Jun »
1234567
891011121314
15161718192021
22232425262728
293031