Apple WebKit Team Publishes Website Tracking Prevention Policy - MacRumors
Skip to Content

Apple WebKit Team Publishes Website Tracking Prevention Policy

by

Apple's WebKit team has published a "WebKit Tracking Prevention Policy" that details a range of anti-tracking measures it has developed and the types of tracking practices it believes are harmful to users.

webkit logo
Inspired by Mozilla's anti-tracking policy, the document posted to the WebKit blog provides an insight into the anti-tracking features built into Apple's Safari browser that the team hopes to see in all browsers one day.

This document describes the web tracking practices that WebKit believes, as a matter of policy, should be prevented by default by web browsers. These practices are harmful to users because they infringe on a user's privacy without giving users the ability to identify, understand, consent to, or control them.

Apple introduced Intelligent Tracking Prevention in iOS 11 and in Safari 11 in macOS High Sierra 10.13 and has been working to develop ITP ever since. For example, in February Apple released iOS 12.2 and Safari 12.1 for macOS, both of which included ITP 2.1 featuring enhancements that block cross-site tracking.

The new WebKit policy highlights Apple's continuing efforts to target all forms of cross-site tracking behavior, even if it's in plain view.

WebKit will do its best to prevent all covert tracking, and all cross-site tracking (even when it’s not covert). These goals apply to all types of tracking listed above, as well as tracking techniques currently unknown to us.

If a particular tracking technique cannot be completely prevented without undue user harm, WebKit will limit the capability of using the technique. For example, limiting the time window for tracking or reducing the available bits of entropy — unique data points that may be used to identify a user or a user’s behavior.

In addition to cross-site tracking, the document outlines several other tracking practices it deems harmful to users, and says WebKit will treat circumvention of its anti-tracking measures "with the same seriousness as exploitation of security vulnerabilities."

If a party attempts to circumvent our tracking prevention methods, we may add additional restrictions without prior notice. These restrictions may apply universally; to algorithmically classified targets; or to specific parties engaging in circumvention.

For more on tracking definitions, the unintended impact of anti-tracking measures, and exceptions to the rules, check out the full WebKit Tracking Prevention Policy on the WebKit blog.

Top Rated Comments

88 months ago
The logical way to thwart tracking/spying is to cut off network communication to the servers that collect data. I've been using Little Snitch on MacOS for years to do so. It's amazing how many servers and domains a typical app or website connect to. Some are necessary for core functions but a large number are for activities by undisclosed associates with covert motives. Little Snitch lets me deny network connections selectively to background requests. I've amassed a blacklist that is in the hundreds.

I don't mind ads. They're a necessary nuisance to fund the web services and content that we won't directly compensate. Therefore, I allow those entities whose known purpose is ad serving. It's the unknown purpose(s) and reputations of other tracking entities that I choose to undermine.

I mention this tool because it—or anything like it—are sorely needed on iOS devices.

Disclaimer: I am not an employee or spokesperson for Little Snitch. My endorsement is my own.
Score: 3 Votes (Like | Disagree)
thisisnotmyname Avatar
88 months ago
Keep fighting the good fight Apple
Score: 3 Votes (Like | Disagree)
decafjava Avatar
88 months ago
I will forever think Facebook is listening.
The other day I was TALKING to my friend on the couch how I want to wait with buying plane tickets until my boss approves the holidays so I don’t end up spending money on a ticket I won’t be able to use and literally 30 minutes later I open Instagram I get an ad about „how do I get my money back for an unused plane ticket? Find out more“
Press icon til wobbly - delete.
Score: 3 Votes (Like | Disagree)
88 months ago
There's a content-blocker interface in iOS Safari, and a bunch of content blocker apps that use this, including some that will let you add arbitrary sites/IPs. You could port your blacklist into one of these, but it wouldn't be simple.
To be clear, I'm not seeking to block content. Ad blockers do that. I'm more interested in blocking covert background activities that hog resources and don't reveal their purpose.
Score: 1 Votes (Like | Disagree)
88 months ago

I mention this tool because it—or anything like it—are sorely needed on iOS devices.
https://www.macrumors.com/2019/07/24/lockdown-firewall-app-privacy-protection/
Score: 1 Votes (Like | Disagree)
Populus Avatar
88 months ago
Hey, I like that Safari icon better than the actual one.
Score: 1 Votes (Like | Disagree)

Popular Stories

MacBook Pro Low Angle Wide Lens

macOS 27: Two More Changes Leaked Ahead of WWDC Next Month

Sunday May 10, 2026 9:45 am PDT by
macOS 27 will have a "slight redesign" compared to macOS Tahoe, according to the latest word from Bloomberg's Mark Gurman. In his Power On newsletter today, Gurman said the design changes will help to improve the readability of macOS Tahoe's Liquid Glass interface:If you've used Tahoe, you're likely familiar with some of the quirks — particularly the transparency effects and shadows that...
apple lock security bug vulnerability fix privacy

Apple Warns Canada's Bill C-22 Could Force Encryption Backdoors

Friday May 8, 2026 4:22 am PDT by
Apple and Meta have opposed a Canadian bill that the companies say could force them to create backdoor access to encrypted user data, should it pass through the country's parliament. Proposed by Canada's ruling Liberal Party, Bill C-22 contains provisions that could be similar ​to a UK data access provision order sent to Apple last year, depending on how they are implemented. Back in Feb...
Aston Martin CarPlay Ultra Screen

Apple Says CarPlay Ultra is Coming to These Vehicle Brands

Thursday May 21, 2026 11:53 am PDT by
Last year, Apple launched CarPlay Ultra, the long-awaited next-generation version of its CarPlay software system for vehicles. Nearly a year later, CarPlay Ultra is still limited to Aston Martin's latest luxury vehicles, but that should change fairly soon. In May 2025, Apple said many other vehicle brands planned to offer CarPlay Ultra, including Hyundai, Kia, and Genesis. CarPlay Ultra...