Recent Blog Articles on P3P
Rigo Wenning <[email protected]> Fri, 19 Aug 2005 18:08:23 +0200
| Newsgroups | gmane.comp.web.p3p.policy |
|---|---|
| Organization | W3C |
| Message-ID | <[email protected]> |
--nextPart3701451.vYlKXxUmHy Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline Dear all,=20 starting with a Wall Street Journal Article[1] from Walter Mossberg=20 there were recent remarkable Blog-Entries. Mossberg started off complaining about tracking cookies. He said, those=20 cookies would fit his spyware definition and wanted a real prompt for=20 tracking-cookies (going straight). Implementing P3P on the Server means=20 exactly that: going straight. Note that a lot of sites today have P3P=20 Policies. Eric Peterson blogged[2] in a response that prompting the user for=20 cookies would generate a very painful browsing experience. I think he=20 is right. As a professional paranoid, I have instructed my browser to=20 prompt on cookies. Some sites propose you the same cookie every time=20 you get to the next page. This means an average of 2-6 clicks per page.=20 Now, being fatalistic does not seem to be a solution. The critic from=20 Peterson was taken up by Joe Wilcox in the Microsoft Monitor Weblog=20 [3]. He describes the P3P capabilities of Internet Explorer and has=20 some trouble explaining P3P. I think, P3P is not " P3P support means=20 when that prompt comes, say for microsoft.com, the user has the option=20 of accepting or rejecting the cookie and applying the response to all=20 future cookie requests." The trouble with cookies is that "22993519736004617" has no meaning for=20 the user. This is opaque and generates fears, often far beyond the real=20 danger of a given cookie. P3P[4] tries to tackle that by adding metadata=20 to the cookie explaining what it collects and does and how this=20 personal information is retained/distributed etc. P3P means that metadata about the cookie has been exchanged, so the user=20 and his agent (browser) knows what this cookie is about. So the "Spy"=20 part is already cleared. P3P in fact helps to distinguish between good=20 and bad cookies and increases user trust by telling them what the=20 cookie is supposed to do. In a nice implementation, the browser would=20 then offer the possibility to block/erase/fake acceptance for that=20 future cookies based on a user reaction, a kind of constant learning.=20 With P3P, such a tool could even ask if the user wants to block cookies=20 of that _category_.=20 IE had a good first start with the cookie-blocker based on the P3P=20 compact format. But IE remains at 15% of P3P's capabilities. Privacy=20 Bird[4] shows some of the notification wisdom achievable. But the=20 software vendors still owe us a tool that takes full advantage of P3P=20 to take away the necessity of Articles like the one from Walter=20 Mossberg. So an interesting question to Microsoft and Firefox would be, how much=20 of P3P they intend to implement. Going straight here means implementing=20 an existing Standard ;) 1.http://online.wsj.com/article_email/0,,SB112129842537185221-IBjfINilaV4op= ynaICHa6mFm4,00.html 2.http://weblogs.jupiterresearch.com/analysts/peterson/archives/009281.html 3.http://www.microsoftmonitor.com/archives/009285.html 4.http://www.w3.org/TR/P3P/ http://www.w3.org/P3P/ Best,=20 =2D-=20 Rigo Wenning W3C/ERCIM Staff Counsel Privacy Activity Lead mail:[email protected] 2004, Routes des Lucioles http://www.w3.org/ F-06902 Sophia Antipolis --nextPart3701451.vYlKXxUmHy Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (GNU/Linux) iD8DBQBDBgQCCRlGO2Cxp/0RAoQQAJ9sO2/jojN5Wcfk7j1QOKe6qkKBHgCdGD/p wN4lwEbpSf/KqW36jnhGQA4= =Y4Mu -----END PGP SIGNATURE----- --nextPart3701451.vYlKXxUmHy--