Live data from Hacker News

Facebook and many other sites also bypass Internet Explorer privacy controls

nikcub.appspot.com

31–40 of 63 posts

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#31
post #26

Earlier quoted context omitted.

IE's implementation of privacy controls is flawed. It really doesn't matter what MS does; they get bashed either way. In this case, their implementation is perfect: afaik, they're the only browser that actually follows the spec. FF, Chrome, etc., are just ignoring the standard. The problem here is that it's a really stupid standard, so that implementing it correctly results in brain-dead "protection". But Microsoft p…

They played by nonsensical rules and got grief for it. It's kind of fair, actually. Yet, I refrain from criticizing them - P3P is a broken standard, but Microsoft followed it. I'm criticizing them for singling out Google when, in fact, ignoring P3P or actively disabling it is widespread practice. I'm surprised live.com doesn't do it.

I think live.com does (or did) do it. See page 8, second column of the CMU paper in this reddit comment: http://www.reddit.com/r/technology/comments/py9h5/now_google...

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#32
post #10

Sorry but this is insane. The real question is why is IE allowing Facebook, Google and others to bypass its privacy controls? Maybe beacause IE is not that secure. If your software have security problems, please fix those problems instead of complaining that others are exploiting them.

P3P is based on trust. If Facebook and Google don't want to support it then they should ignore it rather than subvert it.

Where does P3P allow me to manage this trust relationship you say it's based on?

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#33
post #12

The article makes it sound a bit like the big companies are doing something very evil to the users data just because they are evil and greedy. I encountered this problem in my development work, and in reality it's much more complicated, while some companies might well be evil and greedy, the real problem is that the means available in the browser for doing cross-domain integration of web services while controlling pr…

Google could display a message in page, like they do when first party cookies are disabled or when firebug is running. Instead, they chose to "jailbreak" themselves and not even tell the user what they are doing. Google makes a tickertape parade of yellow see sticky notes every time they change the shade of grey in a form button, it is quite telling that they are ashamed of admitting "

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#35

> Microsoft explicitly called out Google for their behaviour but either neglected to mention or didn't investigate Facebook (skeptics may believe that this is because of Microsoft's shareholding in Facebook and their partnerships in search and advertising) I have trouble believing that they didn't check any other websites when they were preparing that blog post (and facebook would be the obvious next choice to test),…

[deleted]

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#36

So Facebook uses the exact same trick. They could have just omitted the P3P header completely, but no they must and shall have 3rd party cookies so they respond with an invalid P3P header, just like Google. The fact that the invalid P3P header contains the string "We don't support P3P and here's why" is a red herring: The only reason why they would place a statement regarding their non-support in the very header that…

If it's broken to begin with, it's not really "breaking the users security settings". Specifically if it can be broken just by saying "break it", then it's broken from the start.

In that sense NO ENTRY signs are also broken. And so is the robots.txt protocol.

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#37

So Facebook uses the exact same trick. They could have just omitted the P3P header completely, but no they must and shall have 3rd party cookies so they respond with an invalid P3P header, just like Google. The fact that the invalid P3P header contains the string "We don't support P3P and here's why" is a red herring: The only reason why they would place a statement regarding their non-support in the very header that…

No, they couldn't omit the P3P header.

Why, did someone tattoo it onto their servers?

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#38

So Facebook uses the exact same trick. They could have just omitted the P3P header completely, but no they must and shall have 3rd party cookies so they respond with an invalid P3P header, just like Google. The fact that the invalid P3P header contains the string "We don't support P3P and here's why" is a red herring: The only reason why they would place a statement regarding their non-support in the very header that…

Even from your description, P3P does not work; IE is equally dishonest imho for claiming that P3P provides any kind of privacy.

It's a crappy protocol, I agree. I don't see how that's relevant though.

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#39

Sorry but this is insane. The real question is why is IE allowing Facebook, Google and others to bypass its privacy controls? Maybe beacause IE is not that secure. If your software have security problems, please fix those problems instead of complaining that others are exploiting them.

> The real question is why is IE allowing

Because the standard says that it should. In this circumstance they can legitimately claim "in all good faith". We can't lambaste MS for running roughshod over standards when ever it suits them (and believe me, I do) then turn around and moan because we don't a like the side-effect of them implementing a standard correctly (correctness here being defined by the standard, not any other measure of desirability) - that would be somewhat hypercritical.

MS are (by my interpretation at any rate) being catty about this and using it as an excuse to get a petty shot out against Google, but that doesn't alter the three facts:

1. The standard has flaws

2. MS has implemented the standard (flaws and all, but that isn't the point)

3. Google (and others, though Google is the one MS are calling out) appear to be using a loophole in the standard to go against the spirit of the standard. If they don't agree with using that header for its intended purpose then they should just not include it. Including a header that is intended to be machine readable but giving it human readable content is not something that can be easily defended: they could easily include it as "x-P3P" instead which is perfectly valid. Any human that does looking for the P3P header will find a message in a x-P3P header just as readily and it wouldn't confuse the client application into opening greater access because it doesn't understand the "for humans" message

Perhaps, considering the "assume human fallibility over malicious intent unless there is evidence otherwise" maxim, Google (and facebook, and everyone else that does this but isn't being fingered for it right now) did this in all good faith rather than to deliberately make use of a loophole, in which case the right course of action is to encourage them to correct this oversight instead of telling MS to ignore part of the standard.

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#40

I wonder why it is necessary for you riff of every high ranking HN article. Are we to be exposed to your "HN is just another Social Network" article? Or will it be "How my high HN karma bootstrapped my socio-locale-mobile start-up to 28k in the first weekend?" As if ANYONE (over the age of 16) EVER was impressed by the ability to earn a few thousand dollars in a weekend.

Wow. I wish I could down vote this a thousand times. Here we have someone actually contributing useful information in an unbiased way and you create a throwaway account to complain? Shame on you.
Post reply on HN