Live data from Hacker News

Facebook and many other sites also bypass Internet Explorer privacy controls

nikcub.appspot.com

61–63 of 63 posts

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#61
post #52

What is the preferred way to handle P3P for a young startup or a small (possibly academic) project? As I see it, there are seven relevant facts: 1. The intent of P3P is to make it so that you are personally, legally bound to enforce particular privacy guarantees. 2. The attempt to make a P3P standard has been abandoned for half a decade, and only one browser maker supports it, largely for historical reasons. Document…

If I read correctly, the article says that of the top 10000 sites 95% do have a valid P3P header. Does that make a decision any simpler for an aspiring startup?

No, he just said 5% had an invalid header, no claims were made about how many had valid headers. And unless he's actually audited any of the websites to see if what they're claiming in their P3P policies corresponds with how they actually use their cookies then how many sites have well formed headers is beside the point.

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#62
post #11

Earlier quoted context omitted.

I doubt Facebook shares have anything to do with it. Microsoft wanted to embarrass Google, but the alleged crime is very common because IE's implementation of privacy controls is flawed.

IE's implementation of privacy controls is flawed. It really doesn't matter what MS does; they get bashed either way. In this case, their implementation is perfect: afaik, they're the only browser that actually follows the spec. FF, Chrome, etc., are just ignoring the standard. The problem here is that it's a really stupid standard, so that implementing it correctly results in brain-dead "protection". But Microsoft p…

The stupid thing about IE's implementation is that, while it is supposed to restrict third-party cookies unless sites have an acceptable privacy policy, it treats an invalid P3P header as if it were an acceptable privacy policy, rather than treating it as if there were no privacy policy. I don't see anything in the spec which mandates that.

Re: Facebook and many other sites also bypass Internet Explorer privacy controls

#63
post #9

Earlier quoted context omitted.

Is it a joke to expect Google to honor user privacy?

It's a joke for people to expect that P3P is a good privacy model.

From the parent: "trusting third party websites to honor user privacy ? seriously"

That's what I was responding to. They seem to be suggesting that the idea of trusting Google is absurd on the face of it.

Post reply on HN