Live data from Hacker News

Facebook and many other sites also bypass Internet Explorer privacy controls

nikcub.appspot.com

21–30 of 63 posts

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#21

So Facebook uses the exact same trick. They could have just omitted the P3P header completely, but no they must and shall have 3rd party cookies so they respond with an invalid P3P header, just like Google. The fact that the invalid P3P header contains the string "We don't support P3P and here's why" is a red herring: The only reason why they would place a statement regarding their non-support in the very header that…

No, they couldn't omit the P3P header.

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#22
Microsoft is in a bind, now. If they fix their security hole, the Like and +1 buttons will stop working on IE9, and only IE9. The solution to fixing them will be 'use another browser'. The only solution.

So faced with losing market share, they instead chose to turn it around and say that other companies are doing unethical things. When those companies stop doing them, IE9 will stop working, but now it looks like those websites are at fault, and not IE9.

The obvious solution is simply to explain why (and G and FB have already done so) and let MS hang themselves with their own rope. MS's gambit won't pay off, and they'll lose worse for having tried it.

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#23

So Facebook uses the exact same trick. They could have just omitted the P3P header completely, but no they must and shall have 3rd party cookies so they respond with an invalid P3P header, just like Google. The fact that the invalid P3P header contains the string "We don't support P3P and here's why" is a red herring: The only reason why they would place a statement regarding their non-support in the very header that…

Even from your description, P3P does not work; IE is equally dishonest imho for claiming that P3P provides any kind of privacy.

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#24
post #19
post #11

Earlier quoted context omitted.

I doubt Facebook shares have anything to do with it. Microsoft wanted to embarrass Google, but the alleged crime is very common because IE's implementation of privacy controls is flawed.

How is it flawed? According to the original report IE's handling is correct, it's the spec that's flawed.

OK, the spec is flawed. Other browser makers have solved that problem quite neatly by not implementing it.

It's also my opinion that while the implementation is strictly speaking correct, IE's default settings are too conservative and it is not at all an easy option for the user to change.

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#25
post #11

> Microsoft explicitly called out Google for their behaviour but either neglected to mention or didn't investigate Facebook (skeptics may believe that this is because of Microsoft's shareholding in Facebook and their partnerships in search and advertising) I have trouble believing that they didn't check any other websites when they were preparing that blog post (and facebook would be the obvious next choice to test),…

I doubt Facebook shares have anything to do with it. Microsoft wanted to embarrass Google, but the alleged crime is very common because IE's implementation of privacy controls is flawed.

> but the alleged crime is very common because IE's implementation of privacy controls is flawed

By my understanding (caveat: I've not read through the standards in any detail) IE's implementation is fine by the standard and the standard itself has problems which other browsers get around by breaking the standard.

I'm not usually one to give MS the benefit of the doubt but in this case Google does look to be the one at fault so while calling them out specifically and not mentioning Facebook and others my be disingenuous, it would appear that Google (and others) are using the loophole to perform tracking against the spirit of the standard.

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#26
post #11

Earlier quoted context omitted.

I doubt Facebook shares have anything to do with it. Microsoft wanted to embarrass Google, but the alleged crime is very common because IE's implementation of privacy controls is flawed.

IE's implementation of privacy controls is flawed. It really doesn't matter what MS does; they get bashed either way. In this case, their implementation is perfect: afaik, they're the only browser that actually follows the spec. FF, Chrome, etc., are just ignoring the standard. The problem here is that it's a really stupid standard, so that implementing it correctly results in brain-dead "protection". But Microsoft p…

They played by nonsensical rules and got grief for it. It's kind of fair, actually.

Yet, I refrain from criticizing them - P3P is a broken standard, but Microsoft followed it. I'm criticizing them for singling out Google when, in fact, ignoring P3P or actively disabling it is widespread practice.

I'm surprised live.com doesn't do it.

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#27
I wonder why it is necessary for you riff of every high ranking HN article. Are we to be exposed to your "HN is just another Social Network" article? Or will it be "How my high HN karma bootstrapped my socio-locale-mobile start-up to 28k in the first weekend?"

As if ANYONE (over the age of 16) EVER was impressed by the ability to earn a few thousand dollars in a weekend.

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#28
post #24
post #19

Earlier quoted context omitted.

How is it flawed? According to the original report IE's handling is correct, it's the spec that's flawed.

OK, the spec is flawed. Other browser makers have solved that problem quite neatly by not implementing it. It's also my opinion that while the implementation is strictly speaking correct, IE's default settings are too conservative and it is not at all an easy option for the user to change.

Firefox dropped support for P3P in Firefox 3 because "p3p isn't an effective way to establish trust with a site. it's a one-way system; anyone can say they're the good guy." See item b: https://bugzilla.mozilla.org/show_bug.cgi?id=417800#c11

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#29
post #11

Earlier quoted context omitted.

I doubt Facebook shares have anything to do with it. Microsoft wanted to embarrass Google, but the alleged crime is very common because IE's implementation of privacy controls is flawed.

IE's implementation of privacy controls is flawed. It really doesn't matter what MS does; they get bashed either way. In this case, their implementation is perfect: afaik, they're the only browser that actually follows the spec. FF, Chrome, etc., are just ignoring the standard. The problem here is that it's a really stupid standard, so that implementing it correctly results in brain-dead "protection". But Microsoft p…

It really doesn't matter what MS does; they get bashed either way.

Then probably best not to draw attention to yourself by, for example, having a VP make a blog post about it.

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#30

Sorry but this is insane. The real question is why is IE allowing Facebook, Google and others to bypass its privacy controls? Maybe beacause IE is not that secure. If your software have security problems, please fix those problems instead of complaining that others are exploiting them.

Because if you don't allow people to bypass the privacy controls a significant chunk of the web stops working. For instance there's at least one well known WiFi hotspot service in the UK for which the block 3rd party cookies option in Firefox breaks the logon process for.
Post reply on HN