Earlier quoted context omitted.
IE's implementation of privacy controls is flawed. It really doesn't matter what MS does; they get bashed either way. In this case, their implementation is perfect: afaik, they're the only browser that actually follows the spec. FF, Chrome, etc., are just ignoring the standard. The problem here is that it's a really stupid standard, so that implementing it correctly results in brain-dead "protection". But Microsoft p…
They played by nonsensical rules and got grief for it. It's kind of fair, actually. Yet, I refrain from criticizing them - P3P is a broken standard, but Microsoft followed it. I'm criticizing them for singling out Google when, in fact, ignoring P3P or actively disabling it is widespread practice. I'm surprised live.com doesn't do it.
Facebook and many other sites also bypass Internet Explorer privacy controls
31–40 of 63 posts
Re: Facebook and many other sites also bypass Internet Explorer privacy controls
#32Sorry but this is insane. The real question is why is IE allowing Facebook, Google and others to bypass its privacy controls? Maybe beacause IE is not that secure. If your software have security problems, please fix those problems instead of complaining that others are exploiting them.
P3P is based on trust. If Facebook and Google don't want to support it then they should ignore it rather than subvert it.
Re: Facebook and many other sites also bypass Internet Explorer privacy controls
#33The article makes it sound a bit like the big companies are doing something very evil to the users data just because they are evil and greedy. I encountered this problem in my development work, and in reality it's much more complicated, while some companies might well be evil and greedy, the real problem is that the means available in the browser for doing cross-domain integration of web services while controlling pr…
Re: Facebook and many other sites also bypass Internet Explorer privacy controls
#34Re: Facebook and many other sites also bypass Internet Explorer privacy controls
#35> Microsoft explicitly called out Google for their behaviour but either neglected to mention or didn't investigate Facebook (skeptics may believe that this is because of Microsoft's shareholding in Facebook and their partnerships in search and advertising) I have trouble believing that they didn't check any other websites when they were preparing that blog post (and facebook would be the obvious next choice to test),…
Re: Facebook and many other sites also bypass Internet Explorer privacy controls
#36So Facebook uses the exact same trick. They could have just omitted the P3P header completely, but no they must and shall have 3rd party cookies so they respond with an invalid P3P header, just like Google. The fact that the invalid P3P header contains the string "We don't support P3P and here's why" is a red herring: The only reason why they would place a statement regarding their non-support in the very header that…
If it's broken to begin with, it's not really "breaking the users security settings". Specifically if it can be broken just by saying "break it", then it's broken from the start.
Re: Facebook and many other sites also bypass Internet Explorer privacy controls
#37So Facebook uses the exact same trick. They could have just omitted the P3P header completely, but no they must and shall have 3rd party cookies so they respond with an invalid P3P header, just like Google. The fact that the invalid P3P header contains the string "We don't support P3P and here's why" is a red herring: The only reason why they would place a statement regarding their non-support in the very header that…
No, they couldn't omit the P3P header.
Re: Facebook and many other sites also bypass Internet Explorer privacy controls
#38So Facebook uses the exact same trick. They could have just omitted the P3P header completely, but no they must and shall have 3rd party cookies so they respond with an invalid P3P header, just like Google. The fact that the invalid P3P header contains the string "We don't support P3P and here's why" is a red herring: The only reason why they would place a statement regarding their non-support in the very header that…
Even from your description, P3P does not work; IE is equally dishonest imho for claiming that P3P provides any kind of privacy.
Re: Facebook and many other sites also bypass Internet Explorer privacy controls
#39Sorry but this is insane. The real question is why is IE allowing Facebook, Google and others to bypass its privacy controls? Maybe beacause IE is not that secure. If your software have security problems, please fix those problems instead of complaining that others are exploiting them.
Because the standard says that it should. In this circumstance they can legitimately claim "in all good faith". We can't lambaste MS for running roughshod over standards when ever it suits them (and believe me, I do) then turn around and moan because we don't a like the side-effect of them implementing a standard correctly (correctness here being defined by the standard, not any other measure of desirability) - that would be somewhat hypercritical.
MS are (by my interpretation at any rate) being catty about this and using it as an excuse to get a petty shot out against Google, but that doesn't alter the three facts:
1. The standard has flaws
2. MS has implemented the standard (flaws and all, but that isn't the point)
3. Google (and others, though Google is the one MS are calling out) appear to be using a loophole in the standard to go against the spirit of the standard. If they don't agree with using that header for its intended purpose then they should just not include it. Including a header that is intended to be machine readable but giving it human readable content is not something that can be easily defended: they could easily include it as "x-P3P" instead which is perfectly valid. Any human that does looking for the P3P header will find a message in a x-P3P header just as readily and it wouldn't confuse the client application into opening greater access because it doesn't understand the "for humans" message
Perhaps, considering the "assume human fallibility over malicious intent unless there is evidence otherwise" maxim, Google (and facebook, and everyone else that does this but isn't being fingered for it right now) did this in all good faith rather than to deliberately make use of a loophole, in which case the right course of action is to encourage them to correct this oversight instead of telling MS to ignore part of the standard.
Re: Facebook and many other sites also bypass Internet Explorer privacy controls
#40I wonder why it is necessary for you riff of every high ranking HN article. Are we to be exposed to your "HN is just another Social Network" article? Or will it be "How my high HN karma bootstrapped my socio-locale-mobile start-up to 28k in the first weekend?" As if ANYONE (over the age of 16) EVER was impressed by the ability to earn a few thousand dollars in a weekend.