Slashdot Mirror


Is W3C's P3P Good Privacy?

nileshch asks: "A very important development in recent times with regards to website users' privacy has happened with the W3C introducing the Platform for Privacy Preferences(P3P). P3P allows websites to create and maintain XML-based privacy policies for the entire website or sub sections of the site. These machine readable policies document what information is collected from users and how it is going to be used. Today, a few browsers like Mozilla/Netscape & Internet Explorer are committed to giving support for P3P (Mozilla here, IE here) . Although that support seems only skin-deep. I also find very few big sites adopting P3P seriously. Isn't it like the classic chicken-and-egg situation? Websites wait for full P3P support on browsers, browsers go slow on development because there isn't much feature demand happening on this front. Do you have P3P policies for your website? If not, what stops you from creating one? We all create hoopla over tiny privacy issues, user profiling and doubleclick.net . Then why isn't there much enthusiasm for P3P support in browsers?"

118 comments

  1. porn by Brian+Boitano · · Score: 0, Offtopic

    this way people will never know I'm downloading porn!

    --
    What would Brian Boitano do?
  2. Ghostzilla by Anonymous Coward · · Score: 0

    pop-up blocking
    tabbed browsing
    privacy
    black and white porn
    all in your favourite text editor.
    Thats enough privacy for me.

  3. Why? by NineNine · · Score: 5, Insightful

    We all create hoopla over tiny privacy issues, user profiling and doubleclick.net . Then why isn't there much enthusiasm for P3P support in browsers?"

    Why? It's simple. Users don't care. Geeks do, but geeks don't make up a large percentage of the general population. The general population of Web users aren't nearly as paranoid.

    1. Re:Why? by Angry+White+Guy · · Score: 3, Insightful

      You mean nearly as informed.
      A lot of people don't understand the tracking that goes on. They still see the internet as everyone being anonymous, just because they don't understand the technology.

      --
      You think that I'm crazy, you should see this guy!
    2. Re:Why? by dolo666 · · Score: 2, Insightful

      Agreed. Most un-geek people know there are dangers that go with the internet, and most of those people have a very superstition-based understanding of computers.

      You should see how superstitious the people I know are when it comes to computers. I can't count the number of times someone has donned a panic-stricken look on their face when I told them something was wrong with their computer, the network or servers. They don't understand that it's my job to FIX the problem. Instead they panic, thinking the sky is falling.

      You have to be soooo careful when you talk about computer problems with some people.

    3. Re:Why? by md17 · · Score: 4, Insightful

      Users may not care, but businesses care when people can not use their web site, because someone has their browser privacy setting high and they are not accepting cookies without P3P. The first time I implemented P3P it increased online ordering by about 5%. Most end users don't realize that a shopping cart doesn't work correctly because their browser is denying cookies. They simply get frustrated and go to another site. But when businesses realize that P3P is an easy fix, there is really no question about whether or not to use P3P.

      <rant>
      It really bugs me when people start bagging on P3P and saying how crappy it is. Why don't you do something about it? Right now P3P is the best privacy standard out there. Until someone comes up with something better, lets use it!
      </rant>

    4. Re:Why? by fforw · · Score: 1
      Most end users don't realize that a shopping cart doesn't work correctly because their browser is denying cookies.
      so.. why do you use cookie?
      --
      while (!asleep()) sheep++
    5. Re:Why? by Dion · · Score: 1

      Well, if you add:
      P3P: CP="IE You suck ass and so do your users!"
      or something similarly content-free, then you are not really using P3P, you are only working around a misfeature in IE.

      Personally I find it annoying that IE has started to demand a P3P header just to work normally.

      --
      -- To dream a dream is grand, but to live it is divine. -- Leto ][
    6. Re:Why? by koreth · · Score: 5, Insightful
      No, they just don't care. I'm a geek who understands the tracking that goes on (I've written Web tracking software in the past) and for the most part, I don't care. If Joe's Bait & Tackle Shop can make an extra buck with the knowledge that I visit the Psychology Today website, more power to 'em. I see that as a slippery slope leading nowhere. I don't see it as worth my energy to object to data collection just for the sake of objecting to data collection, if no harm can come to me as a result.

      I suppose I see the Internet as being inherently non-anonymous (a sufficiently interested party could be tapping my cable modem, either by court order or surreptitiously) because I do understand the technology, so the fact that it's not anonymous isn't an issue I feel it's really fruitful to worry about. I'd far rather get worked up about things I have a nonzero probability of actually changing, or at least that do me harm. Mind you, my definition of "harm" includes things like sending me spam, but I see little evidence that web site information sharing will ever be responsible for more than a fraction of a percent of the mountains of spam that already hit my filters.

      In the instances when I really do want to resist observation by a third party, e.g. working from home which means I'm dealing with my company's trade secrets, I take care to encrypt everything I send. Even then, though, a sufficiently interested corporate spy or government agent could break into my house and install keyboard-monitoring software without my knowledge, or could be watching my monitor using a spy cam from the neighbor's roof. At some point you either have to go completely off the deep end with privacy paranoia or conclude that as an individual there's a point beyond which it's impossible to keep secrets from the world. From there it's a matter of figuring out where you think it's reasonable for that point to be, and it's on that score that well-informed people can disagree.

      Sun's Scott McNealy summed it up pretty well, I think ("You have zero privacy anyway. Get over it.") Obviously I'm in the minority here on Slashdot, but I think he's pretty much right.

    7. Re:Why? by Angry+White+Guy · · Score: 3, Interesting

      That is a very depressive outlook on the internet. Why, because it's true. I guess that our ideals of what the internet could be often blinds us to what the internet is. I don't subscribe to any sites, and do nothing for them aside from suck up their bandwidth. And then I am shocked when they dissappear from cyberspace.

      Let them sell off my information. Let them spam me, let these sites *gasp* make money to survive. There is no such thing as a free lunch. I've told the users which I support that same statement over and over again when they download all those seemingly free programs like hotbar and bonzai buddy. And yet I can't get it through my thick skull that even though I pay to access the internet, my responsiblity doesn't stop there. If I am to continue to use these sites, should they not get paid?

      Remeber, information is free, but you have to pay the tarriffs and transportation costs.

      --
      You think that I'm crazy, you should see this guy!
    8. Re:Why? by NineNine · · Score: 1

      Well heck, with most cookies, they dont' even directly benefit a site more than, say, helping them figure out what users go where... their site's flowthrough... Or where they come from or go to afterwards. Most cookies don't actually *do* anything other than help the websites with their marketing.

      I use cookies on my sites to help the users' experience. There's no other way to do it. If they don't want to accept cookies, that's fine. But they're losing out. It doesn't effect me as a web site owner either way.

    9. Re:Why? by Monkelectric · · Score: 2
      I've written Web tracking software in the past and for the most part, I don't care ...

      Someone profiting by violating privacy, dosent care about privacy. Yep thats pretty much the problem with things right now

      --

      Religion is a gateway psychosis. -- Dave Foley

    10. Re:Why? by Zaiff+Urgulbunger · · Score: 1

      There's no other way to do it.

      I don't know what you're trying to do but about the only problem with a user not accepting cookies is that they have to "login" to the site on each visit. You can track a user on a site by query-string/form.

      I'm only pointing this out as many sites don't work without cookies and I feel this is a poor state of affairs, mostly 'cos its due to lazy site building that depends on the session management features of the web server.

      I'd urge any slightly clue'd-up web developer who cares, to try build sites that operate without cookies. The reason is that, okay, it is slightly more hassle to build the first one, but once you've got the hang of building stateless applications, you get the benefit of vastly improved scalability! This is a good thing.

      So thats nice.

    11. Re:Why? by NineNine · · Score: 2

      Well, first off the querystring is a very, very messy way of doing things, and introduce the potential for many, many more bugs in a web app.

      And actually, the reason that I decided to go with cookies instead of the querystring/form method is because Netscape 4.7 had a very tough time with querystrings. There was a length limit, and it munged up lots of special characters, so extra formatting was required on every single page, and if your querystring got to be a certain length, it simply didn't work.

    12. Re:Why? by koreth · · Score: 2
      Well, actually, I felt the same way before I had that particular job (or I wouldn't have taken it; this was during the boom when tech jobs were growing on trees.) Maybe there's a causal relationship but it goes the other way.

      And it's not that I don't care about privacy. I close the bathroom door same as anyone else. I just don't have an expectation of perfect privacy in certain contexts, and Web surfing is one of them.

      "Information wants to be free" is a double-edged sword -- every one of us is an information source as well as a consumer.

      David Brin's "The Transparent Society" has a good treatment of the issues, and I agree with most of what he has to say. Unless we put a stop to the development of information technology, the trend will be toward easier and more frequent gathering and wide dispersal of information, be it music, your surfing habits, the campaign donors of your favorite congressman, or next week's weather forecast. With the arguable exception of cryptography, just about every segment of the computer industry is devoted to increasing information flow. I believe that's a trend that ultimately results in far more good than harm. Which isn't to say there's no harm, but I don't think it's ever been possible to pick and choose the side effects of technological advancement.

    13. Re:Why? by Zaiff+Urgulbunger · · Score: 1

      the querystring is a very, very messy way of doing things

      Elegant it ain't. I think the querystring should really just be used for resource identification and *something else* used to maintain transient state information, but we're stuck with what we got!

      introduce the potential for many, many more bugs in a web app.

      How so?
      Obviously you do have to organise you app such that you know that you've validated every bit of UA supplied information, but then thats a given in anycase. I guess if you've had agro from NS4.x then that'd be enough to put anyone off!

      All that said, re-thinking about my points on "vastly improved" scalability, I was talking out of my arse, since using the querystring forces you to dynamically generate each page! I'll try to remember to think before I post in future!! :)

    14. Re:Why? by NineNine · · Score: 1

      Well, if you're talking about sessions, you're still talking about dynamically generated pages, so really the performance hit, which is negligible, is gonna be similar. But where the headache comes in is grabbing every query string on every page, adding to it if need be, rebuilding it with existing information that's irrelevant for the page you're on, etc. Whereas with sessions (using cookies), you just grab the info you need in each particular page, and it persists without any additional code.

      Like, if you're writing, say, a basic shopping cart, then the items ordered need to be in the querystring every single page, even if the customer is say, reading the privacy policy. Also, it's all gone if the user, say, types in a different web page on your site manually.

      The other way of using it is for holding a GUID from a DB, but then, you're looking at a lot more DB hits.

      With sessions, as long as your webserver cleans 'em up, and you have enough memory in the webserver, it's a pretty good performance option, plus, you don't have to deal with the headache of rebuilding the querystring every page.... Or shit, I just thought of that... if you're doing a form submit, then you have to dynamically make a hidden field for everything in the querystring and submit the form normally. Ugh. Nasty.

  4. Who do the W3C think they are? by Angry+White+Guy · · Score: 4, Funny

    Who are they to tell us how to run the web? You'd think that they were a big group of people who pretty much invented the web by the way they act.

    --
    You think that I'm crazy, you should see this guy!
    1. Re:Who do the W3C think they are? by Anonymous Coward · · Score: 0

      They are. Al Gore heads the orginisation. :rolls eyes:

  5. P3P is required by Anonymous Coward · · Score: 1, Interesting

    Well, my issue with P3P was that my shopping cart, that is cookie based, stoped working on some IE6 browsers. It ends up that IE6 will not accept cookies from any server that does not use P3P compact headers when set at certain (read most) security levels. Nice to do, but it would be nice if anyone spoke of it in major forums before it happened. It took days to figure out what was wrong, and more time to figure out that it did not support (or require might be a better term) any form of P3P to operate. It just wanted compact headers. What I really want is some docs to figure out how to generate those headers. I actually had to spend some money to get some firm to generate those for me. I am not happy with this. Any free software to do this? Any good white paper on the subject?

    -GReg

    1. Re:P3P is required by Angry+White+Guy · · Score: 5, Informative

      From the p3ptools website...

      3. You should also have a compact policy associated with the cookie itself. This is done by sending the compact policy string of text along with the HTTP header when setting the cookie. The format of this text will vary depending on which web server software package you are using on your site. See Deployment Guide Section 3.1 "Using HTTP Headers" and Deployment Guide Appendix A for a discussion of various implementations.

      The appendix is HERE.

      --
      You think that I'm crazy, you should see this guy!
    2. Re:P3P is required by pheede · · Score: 1

      Sure, lot's of software is available to create P3P policies, including compact headers.

      A nice one is IBM's P3P Policy Editor.

    3. Re:P3P is required by Anonymous Coward · · Score: 1, Informative

      There's a good free P3P editor (in Java) available on the IBM alphaworks site ( http://www.alphaworks.ibm.com/tech/p3peditor ) which I used to generate the policy for our site.It was very easy to use - the hardest part was reviewing the generated output with the suits in Customer Service =;)

    4. Re:P3P is required by Anonymous Coward · · Score: 0

      You implemented something for your site eh? Yet you can not even take the time to make a simple link for the URL you mention? Do you assume that people would rather C&P your link as opposed to just clicking it or are you just too lazy to use tags?

  6. P3P by dolo666 · · Score: 3, Informative

    There are some papers about P3P HERE.

    I think that if it puts spammers, pr0n peddlers and other crooks on the ropes, I'm all for it.

    1. Re:P3P by Anonymous Coward · · Score: 0

      This web services security book also will also explain P3P in detail.

  7. Since this is Slashdot and I'm lazy... by Phroggy · · Score: 0, Offtopic

    ...can someone summarize what this means to me? I'm not doing e-commerce or banner ads. Should I add something to my sites indicating that I don't track people? My home page uses cookies to track preferences and stuff; how does this affect that?

    --
    $x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
    $x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
  8. The Eyes in the Sky by Anonymous Coward · · Score: 0

    HAHAHAHAHA
    We're watching you!

  9. If this really mattered to most of us by dubbayu_d_40 · · Score: 2, Interesting

    we wouldn't use our freaking credit cards, right? I suspect just a few people are making a lot of noise.

    1. Re:If this really mattered to most of us by error0x100 · · Score: 1

      Huh? I use my credit card (online and otherwise), AND I also happen to care whether or not corporations are illegally (illegal in my country anyway) selling my personal information to third parties. I don't understand what you're trying to say. That using your credit card is somehow proof that you don't mind your personal information also being sold? I don't see how the two correlate.

    2. Re:If this really mattered to most of us by dubbayu_d_40 · · Score: 1

      Ultimately this info is purchased so that people can market stuff to you. This is what you hate. Does your CC market other products to you? Do they sell your info? Most do. They know what, where and when you buy. Or is it that you are afraid this is being sold to an evil org like SPECTRE?

    3. Re:If this really mattered to most of us by error0x100 · · Score: 1

      Do they sell your info? Most do. They know what, where and when you buy

      No, thats paranoid. MOST of the places I've used my CC with, have NOT sold my personal information to anyone. And if they have, they sure haven't given me any reason to suspect that they have - I have only ever received ONE piece of junk (snail) mail that I did not know (for sure, but I have a strong suspicion, and it has nothing to do with my CC) how the company got my info. My main email address I have so far also managed to keep clean of junk (e)mail, just by being careful who I give it to, and creating 'special' email accounts for some places. For example, I use a special email address for Amazon, which has never received anything other than the occasional Amazon newletter.

      I mainly use my credit card for (a) ordering books (mostly from Amazon, but also from one South African online bookstore), (b) Paying my website host, and (c) a few miscellaneous retail/food purchases, i.e. restaurants, or occasionally buying clothes.

      Whats SPECTRE?

      Maybe in the US "Most sell your info", because the law is more corporation-friendly there, but in South Africa it is illegal for a company to sell your personal information without your EXPLICIT, SIGNED (clicking "I agree" does NOT count) and KNOWLEDGABLE consent. That is, they must be able to prove that you reasonably *knew* you were signing over to them the rights to sell your personal info to others. A few places do take chances, because it is usually difficult to find out *who* sold your personal info, but by and large most places are fairly well-behaved around here in this regard. My bank which issued my CC has a strong privacy policy (even though I can say nothing else good about them).

      So no, I'm not "just paranoid" about "evil organizations".

  10. Corporate America is scared of FTC regulation by Anonymous Coward · · Score: 0

    They say: "We say we won't do bad things. Trust us becasue we say so. If we lie, you can sue us later."

    Compare with the European way: The gov't says that corporations mustn't do bad things. If they do, they can be sued.

    P3P is basically about American sites saying something that is supposedly trustworthy, because otherwise they'd be lying. However, no one has why P3P should be better for The People than having FTC and the EU enforcing rules that prevented sites from violating privacy in any case.

  11. Re:Please help with Linux driver by Anonymous Coward · · Score: 0

    Have you tried orinoco.o?

    See http://www.sot.com/en/linux/server/hcl/network.sht ml

    STFW rather than ask questions here, this isn't the right forum.

  12. The deal with cookies by stevejsmith · · Score: 4, Insightful

    Not really on topic at all, but I was always wondering, what's the big deal with cookies!? All they can do is store information THAT YOU GIVE THEM (or that they arbitrarily assign to you)! In fact, you don't even need cookies to do that. You can just do it with Perl or PHP. Yeah, sure, there are some flaws with cookies in IE, but there are flaws with everything in IE! Hell, Slashdot uses them! The media has somehow given them a bad name. Most sites require cookies, and they work quite well, actually. Would you really want to enter your user name and password for every like you click? No, I don't think so. I'll never understand...

    1. Re:The deal with cookies by J_DarkElf · · Score: 1

      The problem is they can be used to track you across websites, remember?

      Site A has an ad banner from Banner company X, which serves a cookie.
      Site B also has an ad banner, and company X now knows when you were on site A, and site B.
      Say both are dealing with tools, then company X will be in a perfect position to start profiling you. You have never given them this info consentually, but still they have information on you.

    2. Re:The deal with cookies by stevejsmith · · Score: 1

      But can't you do that in an infinite amount of ways? I can think of two other ways to do that: JavaScript and Apache logs! Using Javascript commands you can see what websites the viewer went to before that. Using Apache you can see what viewer visited what, and then piece it together. Or better yet, use the Javascript in conjunction with PHP/Perl and then every time a user goes to a site with a banner from company X, they get another list of the site's you've visited. Eventually, they'll be able to recreate your entire web experience, especially if it's a big company such Doubleclick. How come nobody has ever made a fuss about the JavaScript commands or Apache logs?

    3. Re:The deal with cookies by Anarchos · · Score: 2

      You can't access a list of websites a viewer has visited using Javascript. History.back/go/forward are using to navigate a user's history, but the website can never learn that those urls actually are.

      Apache logs aren't viable because companies would have to sift through and parse their huge apache logs in tandem. If they use different log formats or different web servers (some people do use IIS you know, this becomes even harder.

      Two flawed ideas doesn't equal an infinite amount of ways.

      --

      "A good conspiracy is an unprovable one." -Conspiracy Theory
    4. Re:The deal with cookies by Fweeky · · Score: 2, Insightful
      The problem is they can be used to track you across websites, remember?

      Then deny cookies from third parties. Even IE can do that.

      You can even use IE's P3P support to check their privacy policy and allow them to set cookies if you agree to it.

      Cookies are fine. Cookies are the only sensible method of tracking state across the web, be that simple user logins to web applications. The alternative is just as easily leaked URL-encoded session information, and you can't reject that automatically.
    5. Re:The deal with cookies by stevejsmith · · Score: 1

      What about the referrer command? Sure, it only goes back one page, but if you have a banner ad on every page, it gets the job done. And doesn't PHP have some way of seeing what the previous pages were? I think it does, but I could be wrong...

    6. Re:The deal with cookies by Fastolfe · · Score: 1

      The best server logs can do is tie an IP address to a referring URL, which in the case of banner ads, is no new information. (The advertiser has to know what site the banner ad is on so that they can collect their revenue.) This information is probably encoded in the URL itself.

      While in some cases, an IP address might be sufficient to tie one person from one site to another, it can neither be trusted to be persistent nor unique. Users may be re-assigned a new dynamically-allocated IP address from one hour to the next, and multiple users may share a single HTTP proxy (or NAT system). How many AOL users share a common set of HTTP proxies?

  13. good privacy... by Anonymous Coward · · Score: 2, Insightful

    ...comes with good ethics.... good ethics comes with good motives... good motives comes with epathy and understanding. All branches are limbs of the same tree - problems within a society are the dysfunction of that society. Change the society and things like this would not need to be discussed; they'd be a forgone conclusion.

  14. New version? by 3141 · · Score: 1, Funny

    I'm quite happy with P2P, though I might upgrade when P3.11P comes out.

  15. Well, Slashdot's not using it... by NineNine · · Score: 2, Insightful

    As far as I can tell, even Slashdot, the bastion of privacy (paranoi) isn't using it either. Tough to advocate something that you don't do yourself, huh?

    1. Re:Well, Slashdot's not using it... by Ari+Rahikkala · · Score: 1
      Slashdot is not a single entity.

      Slashdot doesn't use well standardised XHTML/CSS, either. Nor does Slash, the code back-end, use many good programming principles that any Slashdot editor and most users would advocate - or at least so I've been told. Nor do a great many Slashdotters use an open-source OS (remember that poll about operating systems a while ago, some people still have the more shocking parts of the results in their sig)

      Ergo, saying "Slashdot is not using it" is not saying much at all...

  16. Useless idea by woogieoogieboogie · · Score: 3, Insightful
    The flaw in P3P is that it assumes people have preferences in these matters. Most people simply do not care. For those who do care, it is even more flawed because nobody has the will power to avoid their favorite websites because of disagreements over the sites privacy policies. How many Slashdotters would quit using Slashdot if Slashdot needed to sell some customer information to stay afloat?

    It is a solution looking for a problem

    --
    ... Governments are instituted among Men, deriving their just Powers from the Consent of the Governed...
  17. We have it, but... by dcavanaugh · · Score: 2

    At my company, we have a corporate website and individual portals for our clients, all of which implement P3P. It's essentially mandatory, once your customers start using IE6. I would prefer to have the customers abandon M$ entirely, but most can be expected to follow the path of least resistance, which means IE6 more often than not.

    Many (15%?) people set their "cookie security" to "high". This makes cookies fail on all non-P3P websites, causing all kinds of application misbehaviors. So we either have an inconvenient/hard-to-follow set of instructions about enabling cookies, or we set up P3P on the server side. In our case, we never share or cross-market our client data with anyone, so P3P is administratively simple as well.

    On the other hand, I don't see what stops the sleazier companies from simply lying about privacy via P3P. After all, these are some of the same people who sell everything you do to Doubleclick and quietly switch your privcacy preferences to "yes, spam me" (hint: 4-letter auction site; starts with "E"). What's another lie when there is direct marketing revenue at stake?

    1. Re:We have it, but... by error0x100 · · Score: 2, Insightful

      On the other hand, I don't see what stops the sleazier companies from simply lying about privacy via P3P

      This seems to me to be THE major flaw in this idea. The sort of companies who want to gather your personal information and sell it to third parties without your consent are, in most cases, PRECISELY those companies who are are not going to tell they are doing it. If they were at all ethical (*), they wouldn't gather and sell your info to begin with.

      (*) Apart from unethical, in many countries other than the US, it is also outright illegal to do so.

    2. Re:We have it, but... by runchbox · · Score: 1

      The biggest IE6 issue with privacy is not the P3P requirements that only happen on 'High', but the 3rd party cookie blocking that happens on medium. It's there to stop Doubleclick, et al, but it wreaked havoc on an application my ex-employers were offering as framed content for other comany's web sites. Again, no warning from Microsoft that the rules of the game were changing.

      --
      If voting changed anything, they'd make it illegal -- Jello Biafra
    3. Re:We have it, but... by dcavanaugh · · Score: 2

      I blame Doubleclick for this, at least as much as Microsoft. Thanks to Doubleclick, it was inevitable that the browsers would become hostile to 3rd party cookies. M$ simply did it first.

      Considering how little IE does to suppress popups and other crap, it's odd that M$ suddenly decided to declare war on 3rd party cookies.

      It never occurred to me that there could be a non-marketing application for 3rd party cookies, so I don't mind having IE ditch them.

    4. Re:We have it, but... by Fastolfe · · Score: 1

      Apart from unethical, in many countries other than the US, it is also outright illegal to do so.

      I would view it no differently from a company posting a readable privacy policy on their site saying they don't sell your information. If they sell it, that should be against the law.

      At a minimum, one might assert that the privacy policy is part of a contract I'm agreeing to by providing them with my personal information. If I provide that to them because they lied in their privacy policy, I might have grounds to sue.

      I'd be interested in a real lawyer's take on this..

  18. Meaningless drivel by Chilled_Fuser · · Score: 1

    The sly part is Microsoft implementing P3P without telling anyone. Session management across the web getting slayed, and developers left slack jawed in frustration as to why.

    I'm for self-regulation. P3P is self-regulation. I think it's a good idea...but only when everyone knows about it!

    1. Re:Meaningless drivel by KjetilK · · Score: 2

      Well, P3P has been on my radar since 1998, when I first read about it, I think this was the article. There are many things that you can blame M$ for, and I'm personally M$-free, but developers should be paying minimal attention.

      --
      Employee of Inrupt, Project Release Manager and Community Manager for Solid
  19. Too Complex? by smd4985 · · Score: 3, Insightful

    i'm not overly familiar with p3p (p2p i understand ;) ), but my ex-girlfriend has a website devoted to viewpoints on p3p (http://www.p3p-viewpoints.org/). from what i understand, the major issue with p3p is that it is overly complex. some user studies have shown that users don't effectively understand what p3p means or how it affects them. more info at the website...

    --
    smd4985
    1. Re:Too Complex? by Anonymous Coward · · Score: 0

      i'm not overly familiar with p3p (p2p i understand ;) )

      :) .. hmm .. we have PPP, P2P, P3P and PGP, I can see how that may confuse Joe Public, hehe. The first two are network related (but not related to one another), and the second two are privacy related (but not related to one another).

    2. Re:Too Complex? by Fastolfe · · Score: 1

      I agree with this, but just as much from the server side as the client side.

      If every Joe Website has to spend a half-hour either reading through the formidible XML specification, or filling out 16 pages of a web application to generate a P3P policy, nobody is going to do it. The "compact" policy is a step in the right direction, but still either requires a significant amount of up-front investment reading and learning P3P or the same 16-page online P3P generator process.

      It's annoying, especially when your site doesn't really deal much with user data. Why should I spend so much of this time just to document the fact that yes, I collect HTTP server logs, and yes, I run them through a log analysis system?

      For the users, it's the same. For those that bother to look at their browser settings, in IE it's just "low", "medium" or "high". If the setting looks OK, that's what they pick. But then things break for them and they don't know why, and that trivial privacy setting turns out to be a little more restrictive than they really care about, so they set it lower or turn it off.

      The vast majority of people just don't care, and those that do care find that few web sites volunteer their privacy information with P3P anyway, except those that make a business out of tracking people with cookies. They almost certainly have P3P policies already, but who knows if they're truthful or accurate?

  20. We had to... by neosiv · · Score: 2, Informative

    My company's website needs cookies enabled. So a week ago when we ran a survey all of a sudden all of our IE 6 users were not working at all. We had no idea of why these users could not get through other than that they had IE 6 and their cookies were not enabled. We searched the web for any signs of this and yet still nothing. It wasn't until one of our employees looked at the IE site and saw the section about P3P that we figure out what was wrong. Essentially all our cookies were being rejected by IE 6.0 because we did not have a P3P policy.
    The next day we created a policy and haven't had a problem with IE 6 cookies since. Sad but true. Any site that relies on cookies are going to need a P3P policy.

  21. What's In It For Me? by John+Hasler · · Score: 2

    > Then why isn't there much enthusiasm for P3P
    > support in browsers?"

    When I care about a site's privacy policy (and sometimes I do) I read it myself. I'm not about to trust my browser to tell me it's ok. When I don't care, I don't care. What good is P3P to me?

    --
    Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
  22. What's the point? by Anonymous Coward · · Score: 0

    When all users really need is a "Privacy" link on the home-page?!?!?!

    That's worked okay for years. The P3P spec seems quite complicated for what it acheives...

    1. Re:What's the point? by Angry+White+Guy · · Score: 2

      This is a way for you to control your information. You set guidelines, and the websites have to operate within those guidelines. Could a website lie? Sure. But now you're forcing them to lie rather than grudginly accepting a convoluted mess of a privacy policy.

      --
      You think that I'm crazy, you should see this guy!
  23. P3P is flawed by zachlipton · · Score: 4, Insightful

    Part of the reason why the adoption of P3P has been so slow is that it may actually make privacy problems worse.

    The problem is that users (and perl programmers) tend to be lazy. And lazy users check the little "this is the default setting so stop showing me dialog boxes" checkboxes in order to make things easier for them. The problem with this is that with P3P, a website can "claim" to not sell/rent your email address, but because the user set their default options to accept that, their address is automatically sent to the website and they don't have the opportunity to consider the implications and evaluate it themselves.

    Also, P3P is a total PITA to write and the one editor that I know of (free from ibm) seems to be long since dead (and downright confusing too). It can also open companies up to legal trouble since a discrepency between a P3P file and the actual practices of the website could be grounds for a lawsuit (IANAL).

    1. Re:P3P is flawed by Jon+Peterson · · Score: 5, Insightful

      That pretty much sums it up. It's a complete pain to implement. Getting your management to sit down and write (and sign off on) a decent privacy policy is hard enough, but to then translate that into some arcane XML format both difficult and pointless.

      "So, remind me why our extremely clear and readable privacy policy that explains the nuances of medical ethics and the Internet has to be re-hashed into someone elses over-complex set of quasi-technical categories?"

      "It's so that users can simply select from a small number of generic pre-set privacy levels, and let their browser manufacturer tell them whether we take good care of their data!"

      It's a dumb idea. It's a miss-appliance of technology.

      --
      ----- .sig: file not found
  24. P3P not that hard by Anonymous Coward · · Score: 1, Insightful

    I implemented P3P support for our web site at a previous company I worked for.
    P3P isn't that hard to figure out... Anyone who actually reads the W3C docs, and Microsoft's docs on how IE implements P3P, can easily support P3P. And it wasn't a "surprise", Microsoft had been telling the world that IE6 would support P3P from about a year before IE6 came out.
    It took about 1 day to set up and implement P3P on our web sites (some IIS, some Apache/PHP).

    How useful is it? It depends on web sites honestly reporting their information in the P3P info. I'm sure most big legit companies accuratly report their privacy policy in the P3P info.

    But what's to stop some unscrupulous Web site from lying? It's not like it's against the law to lie in your P3P info... Nobody is going to punish you for doing it. So, does it really make the web safer?

  25. Well, yes! by Dion · · Score: 1

    I can only agree, p3p is only useful for the paranoids that don't know what they are doing.

    P3P is useless as the untrustworthy sites will simply lie about what they do with the info, so it buys us nothing.

    IE+P3P+Hotmail is an annoying combo, because if you send people a link in mail to a hotmail account M$ think they need trap people in a frameset, neatly displaying "we ownz y00" and keeping people from bookmarking the site they are visting, however the most annoying effect is that it is impossible to get a cookie set in the framed site (so logging in just doesn't work on most sites), without a compact P3P header.

    Luckyly you can just add some garbage P3P header:
    P3P: CP="CAO ADM OUR IND PHY ONL PUR NAV DEM STA"
    and IE will allow the framed site to work normally, it did take a lot of angry users to find that particular IE+hotmail-misfeature.

    In closing: death to IE and hotmail, may they both be taken behind the barn and shot through the head ASAP!

    --
    -- To dream a dream is grand, but to live it is divine. -- Leto ][
  26. p3p is not a PET by ajkessel · · Score: 4, Interesting

    The Electronic Privacy Information Center has published a report on Why P3P is not a PET (Privacy Enhancing Technology) (PDF file). It's worth a read as it challenges a lot of the justifications and goals of P3P.

    1. Re:p3p is not a PET by stephanruby · · Score: 2
      The Electronic Privacy Information Center has published a report on Why P3P is not a PET (Privacy Enhancing Technology) (PDF file). It's worth a read as it challenges a lot of the justifications and goals of P3P.

      In the report, the Vice President of Sales at iVillage complains that because of P3P; Internet Explorer incorrectly mislabeled the privacy policy of iVillage as inadequate. (Page 5, first paragraph in the PDF report.)

      Well, their privacy policy *is* inadequate. Their policy is too freeeeaaakking long. It's nine pages long and contains three thousand seven hundred words. I am not going to read that every time I discover a new web site.

  27. Some Resources by maggard · · Score: 5, Informative
    Gotta recommend IBM's great little free Java-based P3P Policy Editor as a fast & straighforward way to create compact polcies.

    Also for folks using Windows IE (the majority) ATT&T offers up their free eternally-beta AT&T Privacy Bird which gives folks visual and auditory feedback (both controlled/turned off in Prefs) on site's P3P settings. Quite informative actually, I discovered just how awful Yahoo's policies are when I used their headline aggregator (just who are they selling my newsreading habits to?) [rhetorical question]

    The P3P folks have put together a great website at P3P Public Overview which is chock-full of useful information. On the other hand here is an interesting critique and here another, suprisingly both by lawyers. Security guru Richard Smith also has an important (though hopefully now fixed?) page on supercookies and how MS IE 6's touted protections can be got around.

    Mozilla of course supports P3P and it's useful to understand just how MS IE 6 suppports and applies P3P and cookies.

    --
    I don't read ACs: If a post isn't worth so much as a nom de plume to its author then I wont bother either.
    1. Re:Some Resources by leighklotz · · Score: 1

      I'm sure IBM's tool is fine, but it's not free (it's got a standard 30 or 90 day IBM Alphaworks license) and the Installshield installer is unusable on Linux -- it looked through every file on my system trying to find a JVM). I posted a note on the IBM site asking for an update with a workable installer.

  28. Need some insight from web pros... by MoThugz · · Score: 2

    OK, I run a personal site powered by PHP. I try to keep my site as HTML-compliant as I possibly can, so far everything is fine until I added a Flash header to my site.

    Somehow there is a severe lack of info on how to make Flash codes HTML compliant. I figured maybe I should use the <OBJECT> tag to somehow smuggle the Flash code from an external file.

    OK, end of unrelated rant, now for the P3P thingy. I figured this will be important for my site in the future because I'm considering engaging in e-commerce (very small scale), so what the heck.

    The thing is, the examples of P3P XML files I looked at from various sources always contain sensitive elements like business.contact-info.postal.address (using loosely, I know that it's supposed to be .postal.street, .postal.city bla bla). If I'm a full-fledged business, that info might not be so sensitive... heck, I would want everyone to know the physical location of my business.

    But what if it's a home-based business? I surely don't want customers knowing my home address and dropping in whenever they like, a main reason why I chose to do online business in the first place. So in order to safeguard the privacy of my customers, I now seem to be compromising my own.

    If there is a proper workaround for this issue (without any legal problems), can some intelligent and experienced individual point it out to me? Are all those business.contact-info.* tags required in the first place? It seems that every compliant site have them.

    Thanks in advance.

    1. Re:Need some insight from web pros... by Angry+White+Guy · · Score: 2

      Set up a P.O. Box or use a mail forwarding service.
      Mailboxes etc. has a handy resource for a majority of small business questions. Check it out here.

      This isn't a plug ( I don't work for them), but your business is their business. Even if you don't use their services, their small business page has great information on it.

      --
      You think that I'm crazy, you should see this guy!
    2. Re:Need some insight from web pros... by MoThugz · · Score: 2

      Thanks, but the link is mostly about planning and implementing your business. I do have most of that part covered. But thanks for the P.O. box idea, never thought of that before.

    3. Re:Need some insight from web pros... by Angry+White+Guy · · Score: 1

      No problem.

      Hey you! Become an early adopter of new technology! That way I don't have to work so hard when I steal your ideas!

      --
      You think that I'm crazy, you should see this guy!
    4. Re:Need some insight from web pros... by Fastolfe · · Score: 1

      I declined to put this contact information in my P3P policies and the sites that I did this for validate fine with w3c's validator. As near as I can tell, they don't appear to be mandatory. You might have to read the spec closely to see if that's accurate or not.

      Remember, P3P is just a web recommendation. It's neither a standard nor law. There's nothing legal or illegal at this point about the contents of these policies (or lack thereof), except perhaps if you deliberately lie and say you aren't doing something that you really are doing.

  29. Because... by Anonymous Coward · · Score: 0

    P3P doesn't offer any real security anyway...

    It's an overall stupid idea bound to make security even worse if it gains popularity.

  30. An impossible task by wiresquire · · Score: 1

    As lawyers are likely required to review the privact policy, I believe that the spec is impossible to implement, specifically:
    - the spec refers to 'compact' policy. I have not seen an example of a contract or agreement that would meet 'compact' by any stretch of the imagination.
    - the spec refers to non-ambiguity.I have not seen an example of a contract or agreement that is not purposely ambiguous.
    - statements are positive. What, no 'except', 'subject to', 'contrary to above' ??
    - finally, xml is well formed.

    --

    So does Anonymous Coward have good karma?

    1. Re:An impossible task by John+Hasler · · Score: 2

      > I have not seen an example of a contract or
      > agreement that is not purposely ambiguous.

      You've not seen many contracts, then. Most lawyers strive to eliminate ambiguity.

      Any lawyer who puts ambiguity in a contract of adhesion (which these things are) is a fool. The courts will always interpret such ambiguities in the consumer's favor.

      --
      Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
  31. Set your cookies to expire at the end of the sess by rrhal · · Score: 1

    Data miners use the GUIDs in these cookies to see
    how often a given user comes back to the site. If
    everybody set their cookies to expire it would drive
    them up a wall.

    Either that or we should all standardize on one MSN
    cookie so we all have the same GUID.

    --
    All generalizations are false, including this one. Mark Twain
  32. One problem remains by thasmudyan · · Score: 2, Interesting

    I think P3P is a step in the right direction. With tools like this one from IBM every site owner can create his P3P policy very easily. Those policies will help categorize sites and provide a nice filtering possibility.

    Of course one problem remains: since it's entirely up to the site owner, he/she can enter EVERYTHING. There is no way to know whether a particular site stays true to the poolicy it has created. Your data isn't safe just because the one stealing (and selling) it says it is. On the other hand, there is probably no way of verifying stuff like this, so P3P is the best shot we got.

  33. You make it sound so stupid... by Anonymous Coward · · Score: 0

    Yes, (some) geeks care about little things like civil rights. Just because so few people care about these things, does it mean they are irrelevant?

    Sure, 99% of the population probably believes that the government is their friend; that it will never repress them in any way; that it will respect their rights as a human being. And most of the time they'd be right.

    But what if some person or group manages to subvert government into a tool for repression? At that point you'd wish you had not given them the tools for repressing you, that you had protested when you had the chance.

    Sorry for going offtopic here; it is just that I abhor it whenever people are talked down just because they care about something fundamental to human existence.

    In the words of one country, "life, liberty, and the pursuit of happiness". In the words of another, "liberte, egalite, et fraternite" (sorry for the missing accents).

  34. What stops me? by Afty0r · · Score: 2, Insightful

    "Do you have P3P policies for your website? If not, what stops you from creating one?"

    Return on investment.

    Creating a P3P policy would take alot of my time - I would have to research and learn the format and possiblities of the language, then write the policy, reconcile it with various departments within the company, then finally integrate into the site, and potentially have to deal with questions from confused visitors.

    Implementing P3P on my site would cost me no money, but a great deal of time.

    TIME IS MONEY

  35. Re:Why Cookies? by Tokerat · · Score: 2

    ...if, for example, a user orders something on your site through a NAT firewall, say from a university dorm or something. Now supopose another student on the NAT happens to go to your website at the same time. If you are tracking by IP, these two appear to be the same user (due to the singular IP of the Internet gateway both of them share), so, essentially, you have just given full access to your customer's account to an unauthorized party, which of course, is a Very Bad Thing.

    This can also apply to home users, or businesses, or anywhere else a NAT is set up. Uh-oh.

    Throw some cookies in there and now suddenly each users request becomes uniquely identifiable, and although not entirely secure, it certainly is much more difficult than "accedentally."

    --
    CAn'T CompreHend SARcaSm?
  36. And now you understand by Scareduck · · Score: 2

    ... why so few people have implemented this. Our website actually has one of these thingys -- we just put it up, in fact, because its absence was causing trouble with some IE releases. Wading through the P3P docs to come up with a meaningful XML privacy description document is a non-trivial undertaking. The funny thing is that, IIRC, having this little shred of XML puts us ahead of a bunch of other commercial sites that don't do it.

    --

    Dog is my co-pilot.

  37. Shouldn't all web traffic be secure? by Anonymous Coward · · Score: 0

    This might be off topic, but shouldn't all web traffic travel through https? Howecome we allow so much information to travel around unencrypted? What is the barrier to adopting a secure protocol for all web traffic?

  38. Why bother... by Archfeld · · Score: 2

    NO ONE actually believes anything these sites say. They will sell their grandmothers organs for a dime, and we know that if they are violating their policies left and right, nothing will happen. Even if the company says no, as soon as they switch hands or go under that potential capital will be utilized one way or another. The key is successfull obsfuscation on the client side. You can't avoid footprints, so leave HUGE one in clown shoes all over the place, in different ID's.

    --
    errr....umm...*whooosh* *whoosh* Is this thing on ?
  39. I love P3P by Anonymous Coward · · Score: 0

    It causes random websites to stop working for people using IE6. Then I tell those people, "try Mozilla."
    And somehow, more than all my raving about the good things about Mozilla, more than trying to explain in a hundred different ways why tabbed browsing and popup killing and everything is so good, this is one of the things that causes those stragglers to switch to a real browser. And then they discover all the other features and stick with it.

    Implementing P3P the way they did is one of the best things M$ has ever done. :)

  40. Re:Set your cookies to expire at the end of the se by NineNine · · Score: 1

    Yeah, that's a great idea. You should write an article: How to Be a Complete Web Leech and Screw Over Every Site You Visit For Free!

    I mean really, isn't it *terrible* that web sites might know how often you come back to the site? You know what that leads to, right...? First it's that, and from that, they can figure out your height, weight, favorite food, and even dick size! You'd better protect that privacy at all costs!

  41. ...and how long did it take them to... by Anonymous Coward · · Score: 0

    deliberate over whether to call it P3P and not P4 (or P^4)

  42. Re:Why Cookies? by zsmooth · · Score: 3, Informative

    The alternative to using cookies is not tracking by IP address, but passing some session variable around every request. Yes, it's a pain (unless you use a framework that will handle it for you). Yes, it doesn't always work. I don't know of ANY web developer that would even consider tracking someone based on IP address, for the reasons you stated.

  43. write a script... by zogger · · Score: 2

    ..write a script to gently but firmly ask politiely that your visitors arriving using IE would have a better and more secure "total internet surfing experience" if they "upgraded their browsers" to "a better one" then provide some links to them.

    Like, why keep taking it and taking it and taking it and taking it? Don't insult them, just show them a different thing that's "better" for them. Most people just slap don't know, the "internet"is "windows and explorer" because it came with their new conpooter and "microsoft" somehow "owns" the internet. We have to do everything we can to get this brainwashing reversed..

  44. Why (not) implement? by malachid69 · · Score: 1

    Personally, I had never heard of it. Since I wrote the webserver I am running (replaced Apache), I am pretty sure that I don't currently support it. Might take a look at it though....

    However, Opera aleady allows me to block the popups....

    And, what marketer is going to use P3P when they read this:
    "Imagine that, in an effort to reduce the mail she receives, Cindy has told her browser that she wants to be warned whenever a site says that it will use her information to send her marketing promotions."

    It only helps if those you want to block decide to use it.

    --
    http://www.google.com/profiles/malachid
  45. Don't understand how P3P improves privacy by Anonymous Coward · · Score: 0

    I mean why should I trust a site just because the site sends me some text saying - "trust me, because I promise to do A, B,C"
    That's ridiculous. If any entity wants to gain my trust it has got to EARN it. Empty promises = waste of bandwidth.

  46. p3p adoption and tradeoffs by mnot · · Score: 2, Informative

    Ernst & Young have a regular P3P Dashboard Report[PDF] that summarizes adoption of P3P by large Web sites.

    Privacy is a difficult issue; P3P has been derided because it doesn't do enough (actively negotiate or protect your privacy), because it does too much (intrusion into the browser, difficult to implement) and generally because it's too complex.

    As a result, it's a compromise that noone is 100% happy about, but it does give us something to work with. Standards that try to do everything for everyone almost always fail.

    The W3C is, next week, holding a workshop to look at the future of P3P; I haven't had a chance to read the position papers yet, but the fact that they're holding a workshop shows that they know there's more work to do.

  47. Re:Why Cookies? by Tokerat · · Score: 2

    Hmm, yes I didn't think about that. Good call.

    Implemented simply with a GET request which has some kind of ID number in it. Essentially, though, Cookies are just a more sort of hidden way to do this.

    Whenever I see one of those absurdly long URLs with all kinds of session info in it, I wonder why the developers couldn't just use a little JavaScript and an <INPUT TYPE=HIDDEN VALUE="whatever">. When you click on a link, instead of using the HREF, use an onClick="go('thisLink.html')", where the go() function will set the appropriate hidden form values and use a form.submit(). The server will parse all nessesary info, including session info, from the POST request, and redirect or dynamically generate as nessesary. Of course, if the user takes action on an <INPUT TYPE=SUBMIT>, this becomes quite trivial.

    Of course, that's a lot of trouble for the same functionality you get from cookies, and in some situations (depending on implementation) could be a little too trusting of the end user as well... I never understood why people where bothered by cookies in the first place.

    --
    CAn'T CompreHend SARcaSm?
  48. P3P means nothing by cybpunks3 · · Score: 3, Interesting

    Just because there is a P3P privacy policy doesn't mean the policy itself is being truthful or accurate. There is no real accountability or certification of P3P policies, so companies can put any sort of generic boilerplate BS in their P3P policies and as long as there IS one, the browser will accept cookies, etc...

    It can say "oh yeah, we're not selling your information to 3rd parties or anything" when in fact they are. If you trust what it says, then you allow the site to set cookies. You shouldn't be trusting the word of the site itself. It should be a 3rd party certification.

    That's not really protecting privacy, IMHO.

    If P3P policies could be used as evidence in court cases for misrepresentation, then it might force companies to provide more accurate P3P policies, but I haven't heard of any lawsuits coming from inaccurate P3P policies. You'd have to KNOW their policy was misleading in order to take them to court anyway, which is hard to do.

  49. Re:Why Cookies? by mgkimsal2 · · Score: 2

    The same people that shut off cookies also shut off javascript - often shutting off javascript INSTEAD of cookies. The only real option is to put everything in the URL, which is damn ugly. Also, imo, increases the chance that someone will try to play around with the session ID in the URL, simply because it's there.

  50. No external auditing by Karora · · Score: 2


    There is no external auditing of P3P that I can see.

    I set this up on one website I built, but why? I was able to say whatever I wanted. If my browser acted on this sort of information I would be forced to disable it, since it is not, and cannot be trusted without an external verification.

    --

    ...heellpppp! I've been captured by little green penguins!
  51. Mozilla and P3P by jmd! · · Score: 2

    The story and comments here are incorrect.

    Mozilla doesn NOT, in fact, support P3P. It did at one point. Support was removed, because, as I understand it, P3P is "dumb".

    Netscape reincludes it in there releases, but it hasn't been in Mozilla proper for some time now.

  52. Where the slippery slope goes by smiff · · Score: 2
    I see that as a slippery slope leading nowhere.

    The slippery slope will lead to profiling agencies, much like credit reporting agencies, who sell your profile to employers, landlords, lawyers, law enforcement, and anyone else who wants to make a decision about you.

    they just don't care. I'm a geek who understands the tracking that goes on (I've written Web tracking software in the past) and for the most part, I don't care.

    This is one reason the Electronic Privacy Information Center argues that P3P is not a privacy enhancing technology. Websites will eventually demand that you reveal everything, or they won't let you access the site. If people don't care, they will comply. The end result will be like cookies (only with your name, age, address, and other personal data attached). Handing your full identity over to every site you visit will simply become the de facto standard.

    1. Re:Where the slippery slope goes by koreth · · Score: 2
      The slippery slope will lead to profiling agencies, much like credit reporting agencies, who sell your profile to employers, landlords, lawyers, law enforcement, and anyone else who wants to make a decision about you.

      It will lead to that?

      I agree it might lead to that, though even then I'd remain skeptical of the negative impact; the implicit assumption is that any of those people will give a damn what I'm doing on the web. Some might, but then some landlords and employers already care about things they have no business caring about, so this is hardly a new threat. There are already laws on the books saying they can't refuse to hire me or rent me a room based on irrelevant information.

      More fundamentally, though, are you saying we should forbid people from exchanging information that could have harmful uses? To me that's the slippery slope; that way lies draconian DRM technology and the laws to back it up ("you might pirate our movies") not to mention simple censorship.

      If people are free to exchange information at will -- which is something I believe in -- there are consequences that cut both ways, and to me, at least, it's next to impossible to retain the good consequences while eliminating the bad ones.

      But we do agree, at least, that P3P isn't all it's cracked up to be. I think for a lot of site maintainers it's no more than "that thing I had to go read up on to get IE6 users to stop complaining that my site was forgetting their login names between visits."

  53. Game geek ponders ... by pjammer · · Score: 1

    WC3.exe? 3PvP?

    Am I the only one who read the headline and thought: "Well, I've never had a privacy problem playing Warcraft III 3Player skirmish!"

    Oh, bloody hell. I'm just a game dweeb. Never mind.

  54. Re:Why Cookies? by Anonymous Coward · · Score: 0

    Submitting forms "breaks" the back-button in many browsers.

  55. Reason why P3P doesn't work... by Dark+Coder · · Score: 2

    There is nothing to prevent the web site operator from lying between their teeth in setting a false P3P policy.

    P3P Seal of trust? Good and strong as the weakest link of chain. Just think Thawte or Verisign.

    P3P embedded in Mozilla or IE browsers? Yeah, right. Gotta see the code in order to trust the browser.

    How much trust and confidence does that inspire to "We, the Web Surfers?"

    None, Nothing, Na-da!

    1. Re:Reason why P3P doesn't work... by acceleriter · · Score: 1
      P3P Seal of trust? Good and strong as the weakest link of chain. Just think Thawte or Verisign.

      Or worse, TRUST-E.

      --

      CEE5210S The signal SIGHUP was received.

  56. Mozilla support by Cloud+K · · Score: 2, Informative

    Quote: browsers like Mozilla/Netscape & Internet Explorer are committed to giving support for P3P

    Mozilla, commited to P3P?

    I refer you to this bugzilla thread:
    http://bugzilla.mozilla.org/show_bug.cgi? id=128639

    which has been going since March. Several people supported P3P, but the people in charge weren't having any of it.

  57. Re:Please help with Linux driver by marcell · · Score: 1

    whenever u answer on the question like this one, it _was_ the right place to ask :)

  58. P3P privacy problem in a nutshell by Anonymous Coward · · Score: 0

    The problem with P3P is that each user decides:

    1. what level of info they are prepared to release (as a blanket decision applying to all sites that will be allowed the info), i.e. email address, snail address, phone number etc

    2. what sort of use may be made of this info (effectively, what sites have permission to grab this info)

    This info can then be grabbed by any site that claims the agreed 'safe' level, even though it's unnecessary for general browsing or even general site traffic analysis statistics.

    Effectively, the user chooses to discard all anonymity, or not to 'trade' via the internet.

  59. ...and MS has the best tracking facilities by bagofbeans · · Score: 1

    Through Hotmail and Passport, MS can largely guarantee that your identity is correct - certainly on XP systems. With IE6 forcing P3P on commercial sites, the MS databases will be in the best position to accurately profile web users.

    I think cookie-tracker schemes and companies like Doubleclick will be wiped by this, and MS will dominate the served advertisement market before too long.

  60. Tools for the lazy? by autopr0n · · Score: 2

    Hrm, I take it you can setup a p3p thing in the same way you setup a cookies.txt. Just drop the thing in the right URL?

    Are there any tools out there that let you edit a p3p XML file quickly and easily? I'm to lazy to look up the specs and edit an XML file in notepad right now (and I have other things to do).

    --
    autopr0n is like, down and stuff.
  61. Not really by autopr0n · · Score: 2

    Not only do they need to 'log on', but they need to keep logging on (like fark) or have their log on tied to an IP address. For huge sites this becomes a major headache, as it requires HUGE Databases of pointless information.

    Really, why should I have to store gigs of data so that people can chose what background color or what kind of porn they want to see when they visit my site?

    --
    autopr0n is like, down and stuff.
  62. Why I am not using P3P by Qzukk · · Score: 1

    Aside from the somewhat confusing specification (I have copied a working P3P xml file, and made changes and still can't get it to work "right" in IE) I can't figure out how to make the P3P standard cover our particular case.

    As a "web application" development and hosting company (read: writing and hosting custom shopping carts mostly), I can make a P3P policy that covers our use of the information easily. However, what about the 30+ companies I host for? Do I need seperate policies for each of them? If I write a policy for them, and they don't like it, will they sue me? Even if the policy is true? Can I write one policy for the whole batch and hope that the "good" companies don't sue me for being included with the companies that sell all your information AND your newborn babies for cash?

    Not only that, but the information-sharing parts aren't all that hot... all of them appear to assume that the policy creator/hoster is the "primary" user of information... in my case, I only use administrative access (backups, restores) to the information, its the individual companies who use the personal information.

    I could use "other-recipient", but I have this bad feeling that browsers will balk at that. The definition of "ours" talks about other entities that we collect data for, but it just seems a little shady that way.

    In the end, I suppose I'll wind up having each company create their own.

    --
    If I have been able to see further than others, it is because I bought a pair of binoculars.
  63. Re:Please help with Linux driver by Anonymous Coward · · Score: 0

    Thanks for encouraging this practice.

  64. Yes! by rogerzilla · · Score: 1

    I insisted that we do it for our site (a large financial services company). It's a very large piece of work if done properly, but we're getting there.

  65. All I want to know is... by g0at · · Score: 1

    ...is this really 50% better than P2P? Cuz I'll abort my limewire download right now.

  66. PxP? by e8johan · · Score: 2

    Oh, I though P3P was P2P, just cooler! :]

  67. You can also use SSL key by Chris+Pimlott · · Score: 2

    You can also use the SSL session key as a identifier. Of course, that requires the entire session to be encrypted, which is not practical in most situations.