Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'd wager that very few P3P headers used in the wild are an accurate and complete representation of the privacy policy of the site. Most are either deliberately confusing IE (as you put it) or copied from a tutorial by a developer who just needed to fix the damn login button for stupid IE users.

Creating an accurate P3P header that captures the nuances of different ways data can be used is somewhere between difficult and impossible (I've tried).



Why are you giving Google, of all companies, a pass because they just "copied from a tutorial"? Google is probably the least deserving company in the entire world of the engineering ignorance defense.

Think about it: Google knows enough about the inner workings of IE to create Chrome Frame. How in the world is not knowing enough about how P3P works in IE an excuse?


Google said it isn't possible to create an accurate P3P header that describes how they use cookies. Having previously tried to parse the standard document, I'm inclined to believe them.


If that's the case, the responsible course of action is not to send a P3P header at all. Sending a deliberately false one to circumvent third-party cookie restrictions is simply not cool.


Sure. Though of course that means some functionality will be broken for all IE users with default privacy settings.


Sure, but in a fixable manner. I can always turn on third-party cookies if I like.

A faked P3P header breaks IE's privacy settings in a nonfixable manner.


Fixable for technical people, sure.

Not for the average user. The user who uses the default web browser. The user who uses IE.


If they can convince people to install Chrome Frame, I'm sure they can figure out how to tell people to enable 3rd party cookies. My guess is they'd have a lot harder time explaining why the user should do that.


This is silly. I highly doubt Google is having any luck convincing average users to install Chrome Frame. This is not a counter argument.


And yet they spent all that time doing it ... Seriously, who is Chrome Frame for if not the average user? And they inform you about it as soon as you visit google.com in IE.

I suspect you're right and the uptake isn't what they wanted, but that's not really a valid reason for them to work against the browser settings designed to protect a user's privacy.


What functionality would that be? Tracking what pages the visitor browsed via the +1 buttons?


They can't provide a P3P header saying that won't let 3rd parties track you with it? That would "Break" their +1 functionality? I'd like an explanation of that.


>I'd wager that very few P3P headers used in the wild are an accurate and complete representation of the privacy policy of the site.

So now the standard of comparison for Google is shady warez sites that flout every possible standard for maximum gain?

I'd wager that there are a lot of exploits that install spyware in the wild. That doesn't excuse Google does it.


As has already been discussed in numerous places, Google, Facebook, Amazon and even Microsoft have broken P3P implementations in several places.

That's hardly "shady warez sites". I love you you jumped straight to that conclusion, though. Shows your biases coming through...


Broken implementations are different from intentionally subverted ones. If FB is doing this, they deserve blame too.

The argument I was responding to seems to be that P3P is a gentleman's agreement and thus is doomed to fail. However, I expect more from Google than I would from random sites on the internet.

So Google flouting a gentleman's agreement is very different from a warez site doing it. After all, you don't expect Google to read your mail in Gmail versus the site admins of warez-mail.com reading your email. Or do you?


But it's a gentleman's agreement between Microsoft and... no one. The user didn't ask to have their cookies blocked and Google certainly didn't ask to be a part of this scheme. It's not really an agreement when only one party has agreed to it.


Shady warez sites? Huh?

P3P as a solution to protecting privacy on the Internet is an utter failure. The whole approach is bogus. I realize this is a judgement call, but I don't view sending bogus P3P headers as bogus. You want your site to work the same in a default Firefox install as in a default IE install and the only way to do that in this case is sending the bogus header.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: