Recent Blog Articles on P3P

Rigo Wenning <[email protected]> Fri, 19 Aug 2005 18:08:23 +0200
Newsgroups gmane.comp.web.p3p.policy
Organization W3C
Message-ID <[email protected]>
--nextPart3701451.vYlKXxUmHy
Content-Type: text/plain;
  charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

Dear all,=20

starting with a Wall Street Journal Article[1] from Walter Mossberg=20
there were recent remarkable Blog-Entries.

Mossberg started off complaining about tracking cookies. He said, those=20
cookies would fit his spyware definition and wanted a real prompt for=20
tracking-cookies (going straight). Implementing P3P on the Server means=20
exactly that: going straight. Note that a lot of sites today have P3P=20
Policies.

Eric Peterson blogged[2] in a response that prompting the user for=20
cookies would generate a very painful browsing experience. I think he=20
is right. As a professional paranoid, I have instructed my browser to=20
prompt on cookies. Some sites propose you the same cookie every time=20
you get to the next page. This means an average of 2-6 clicks per page.=20

Now, being fatalistic does not seem to be a solution. The critic from=20
Peterson was taken up by Joe Wilcox in the Microsoft Monitor Weblog=20
[3]. He describes the P3P capabilities of Internet Explorer and has=20
some trouble explaining P3P. I think, P3P is not " P3P support means=20
when that prompt comes, say for microsoft.com, the user has the option=20
of accepting or rejecting the cookie and applying the response to all=20
future cookie requests."

The trouble with cookies is that "22993519736004617" has no meaning for=20
the user. This is opaque and generates fears, often far beyond the real=20
danger of a given cookie. P3P[4] tries to tackle that by adding metadata=20
to the cookie explaining what it collects and does and how this=20
personal information is retained/distributed etc.

P3P means that metadata about the cookie has been exchanged, so the user=20
and his agent (browser) knows what this cookie is about. So the "Spy"=20
part is already cleared. P3P in fact helps to distinguish between good=20
and bad cookies and increases user trust by telling them what the=20
cookie is supposed to do. In a nice implementation, the browser would=20
then offer the possibility to block/erase/fake acceptance for that=20
future cookies based on a user reaction, a kind of constant learning.=20
With P3P, such a tool could even ask if the user wants to block cookies=20
of that _category_.=20

IE had a good first start with the cookie-blocker based on the P3P=20
compact format. But IE remains at 15% of P3P's capabilities. Privacy=20
Bird[4] shows some of the notification wisdom achievable. But the=20
software vendors still owe us a tool that takes full advantage of P3P=20
to take away the necessity of Articles like the one from Walter=20
Mossberg.

So an interesting question to Microsoft and Firefox would be, how much=20
of P3P they intend to implement. Going straight here means implementing=20
an existing Standard ;)

1.http://online.wsj.com/article_email/0,,SB112129842537185221-IBjfINilaV4op=
ynaICHa6mFm4,00.html
2.http://weblogs.jupiterresearch.com/analysts/peterson/archives/009281.html
3.http://www.microsoftmonitor.com/archives/009285.html
4.http://www.w3.org/TR/P3P/
  http://www.w3.org/P3P/

Best,=20
=2D-=20
Rigo Wenning            W3C/ERCIM
Staff Counsel           Privacy Activity Lead
mail:[email protected]        2004, Routes des Lucioles
http://www.w3.org/      F-06902 Sophia Antipolis


--nextPart3701451.vYlKXxUmHy
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQBDBgQCCRlGO2Cxp/0RAoQQAJ9sO2/jojN5Wcfk7j1QOKe6qkKBHgCdGD/p
wN4lwEbpSf/KqW36jnhGQA4=
=Y4Mu
-----END PGP SIGNATURE-----

--nextPart3701451.vYlKXxUmHy--