IE6 to Implement W3C Privacy Standard
Arthur Phillip Dent writes: "News.com is running a story about IE6 being the first browser to implement the Platform for Privacy Preferences (P3P) standard. Bad news for Doubleclick et. al., that is unless it's just /.ers using the features! This will get real interesting if lusers' using it with sites that do not post P3P policies (and thereby blocking sites from setting cookies, for example) creates any kind of unrest/discussion about the exchange of marketing data for content and functionality." One thing no one writing about IE6 seems to note: Microsoft has carefully arranged their MSN cookie setting technique to avoid being blocked by their own browser - they bounce people through msn.com to log in to any Microsoft property, so it's always a "first-party" cookie being sent/placed.
I want the ability to filter cookies based on the domain they came from. /. cookies - Yes. Doubleclick - No.
I want the ability to filter images based on the domain and/or size (no more 1x1 web bugs).
I want the ability to filter JavaScript based on the domain.
I want the ability to set up my browser so that sites cannot open new browser windows.
Most of all, I want these features built into the borwser. I should not have to download a third party application to control fundamental parts of my web browsing activities.
I normally use iCab on the Mac http://wwwicab.de/but for the past few weeks have had to use IE 5.0/Windows. iCab normally offers all of these filters (and more), and I find the features sorely lacking in IE.
- (c) 2018 Hank Zimmerman
Anytime you have multiple websites owned by the same company, then you immediately have a condition where that information is assumed to be shared between sites. This is a backend issue unrelated to how browsers or privacy policies work.
I'm mildly amused that the poster seems to regard this as some kind of 'sneaky trick' by microsoft. As if it is 'wrong' to maintain a single login location, as if you 'should' create a separate login for every single website. I've been working on database driven websites for nearly 5 years now, and I can't recall a single technical reason why I'd want to make multiple points of entry to the same database. The only reasons that are valid are design issues... specifically, did we want to have the customer see that login page A is actually affiliated with website B. Microsoft, being such a public brand, has no need to hide the association.
The way I look at it, by having a single login location Microsoft is actually being open and honest. They COULD have multiple points of entry into the login database, one for each site, and thus hide the fact that they are pooling user information between domain names. With a single point of entry, they are revealing their practice of data sharing... something that would be obvious to anyone with technical understanding of database driven sites.
People get all up in arms about privacy with cookies, logins, and user information pages... completely forgetting that sites owned by the same company don't have to use ANY of that to create a profile of your activity on their multiple sites. People seem to have this idea that differing domain names create a magical 'wall' between sites, preventing anything from leaking from one domain to another. Anything they see as breaking that wall is somehow evil.
In all practicality, if Microsoft really wanted to, they could make all their sites as subdomains of microsoft.com... msn.microsoft.com, passport.microsoft.com, msnbc.microsoft.com, etc. Then, the actuality of data sharing would be more concrete for the less technically inclined.
Raven
And my soul from out that shadow that lies floating on the floor
"I will trust Google to 'do no evil' until the founders no longer run it." Hello Alphabet.
Slashdot didn't give P3P such a warm reception the first time around.
It's 10 PM. Do you know if you're un-American?
You know...basic browser stuff.
Got Rhinos?
Yep, this really sucks for third party ad serving companies (like mine). The shitty thing is, it doesn't matter if we implement p3p on our systems or not, we will still get blocked from our cookies, because the default setting doesn't allow 3rd party cookies. (and who in the world is going to relax that?) We (as a industry segment, not just individual companies) have complained to MS about this and their response has been pretty lame. It is really easy for them to redirect their people to their website, but that isn't feasable to everyone else.
I know what some will say, that finially these advertisers are getting what they deserve, and I don't totally disagree, but keep in mind, that (I don't know about other comanines, well, yes I do, but that is totaly someone else) we don't do anything "bad" with the cookies we collect. We don't sell personally identifiable data, etc. We have one of (I don't know of a better one) the best privacy policies in the industry. If everyone just decided that they didn't want 3rd party cookies, that would be one thing, but they haven't, because most people don't mind, as it doesn't hurt anyone. We don't deserve for our business to get impacted this much because of some arbitrary decision made by those people.
Oh, well, enough of this ranting.
room101 -- how much can you stand before they break you?
(they always break you eventually)