Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't side with Google on this one but here is an interesting tidbit: Microsoft support site advocated the same trick... a reference to this can be found on page 6 of this PDF

http://www.ftc.gov/os/comments/privacyreportframework/00453-...



This is a totally disingenuous comment. From the linked PDF (note: this also occurs on page 7, not page 6, for those who wish to verify):

"We discovered that Microsoft’s support website recommends the use of invalid CPs as a work-around for a problem in IE. Specifically, a FRAMESET or parent window that references another site inside a FRAME considers the referenced site as a third-party, even if it is first-party content located on the same server [10]. Microsoft suggests the following invalid CP: CAO PSA OUR. This CP is clearly invalid since it does not contain any RETENTION or CATEGORIES tokens. Even if the CP were valid, Microsoft’s recommendation undermines the purpose of P3P since it encourages web administrators to use CPs that do not represent their actual data practices. We found several technical blogs recommending similar solutions [11], [19]."

So yes, a Microsoft support site did recommend a set of invalid CPs, but this is clearly not the same trick. This is a legitimate set of CP tokens that is used to workaround an issue where 1st party content appears to IE as 3rd party content. This token set is invalid because RETENTION/CATEGORIES tokens are missing, but the web author's intent here is (theoretically) honest.

Google, on the other hand, is providing no tokens whatsoever. Instead, in their P3P header they provide a human-readable string and a link to their privacy policy. This is not an invalid but intellectually honest set of tokens that is designed to comply with the spirit of the standard, if not the letter. This is an attempt to bypass the standard in order to allow 3rd party cookies, regardless of user settings.

The fact that you are equating these two practices is completely dishonest. Even a cursory glance through this document makes it clear that the Microsoft support site is advocating something completely different and is doing so in order to enable a fairly legitimate scenario.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: