From the IE Team: Google Bypassing User Privacy Settings
blogs.msdn.com
blogs.msdn.com
"If you haven't taken an active, positive step to block our +1 buttons, we're going to assume you don't really care and we'll do whatever we can to show them to you, no matter what your browser's default settings are. Why? Well, because we think the default settings are bullshit, and 99 times out of 100 they're only that way because they're the default. They don't reflect actual user preferences, they reflect other browsers messing with our business plans."
Not only is that an intellectually honest position, it's a lot more accurate than assuming all IE users who haven't changed their settings don't want +1 buttons.
Seriously, the answer here is that if a browser wants to block third-party cookies by default, it should go all the way and do so, no exceptions. If social networks want to plaster the entire web with their buttons they can try asking browser users to change the setting back.
A setting is a setting.
I review pretty much every browser setting but change only about 5%. You have no way of telling how the setting ended up with its current value and without that that position is bullshit.
Of course Google doesn't know your preferences for a fact. Of course Google has no way of knowing. But based on their behavior, it seems they just don't care.
An intellectually honest Google would argue 'Look, the default behavior of your browser is badly broken, because they've made it impossible to distinguish between the small number of people who care about this third-party cookie stuff and the rest of the world, who doesn't care an iota. You care about it? So sorry, take it up with your browser manufacturer and their goofy choice of defaults.'
They don't have the guts to make this argument with words, of course, but this is exactly the argument they're making with their actions.
Google on the other hand cynically exploited it knowing full well what the intention was and not giving a shit.
I know which one I'm taking it up with and which one I'm not using any more.
But there is no honest debate to be had on this as if they openly stated their model was "fuck your privacy" they'd have a far smaller business as that would simply be unacceptable for most people. A position like that can only work if it's not public (ironically).
DNT tells a server that a user cares about not being tracked. Google doesn't support it
Browsers: "3rd-party cookies are blocked unless you add a P3P header..."
Websites: "Ok. What should be in the header?"
Browsers: "Anything... it doesn't matter. Just add the header then 3rd-party cookies are fine"
Websites: "Ok, we'll just add a P3P header saying 'Ceci n'est pas une P3P header' then. Problem solved."
The problem is, that indication is made with _lack_ of a particular token; and google includes a fake P3P header with no tokens in it. Thus, according to the protocol, google's header indicates that it does not use cookies for anything at all.
What do you think about robots.txt then? Isn't that a standard that isn't enforced as well?
Ultimately, P3P comes down to the honor system. Unfortunately, that doesn't work on the internet.
You would not be surprised if a warez program installed a keylogger on your computer, but you hold Google Chrome to a higher standard. Isn't that true for the internet too? Why equate Google to any other site on the internet?
>Ultimately, P3P comes down to the honor system. Unfortunately, that doesn't work on the internet.
Would you say the same thing if you came to know that Google employees are reading your email for fun and profit?
Btw, I'm not defending Google, they're clearly not acting perfectly here. I'm simply pointing out that this is a clear case of, "what did you expect to happen?" Any spec that still sets a cookie that is declared as not being used for any purpose seems deeply flawed.
I also found it interesting that Microsoft called out Google and not Facebook, which gives the article a political overtone.
I agree that P3P clearly needs some rethinking to stay relevant. Especially now that the cat's out of the bag on how to bypass it. (Microsoft's immediate response is to set up yet another blacklist system... some cultures just never change.)
For everyone's entertainment, the OP's comments linked to an amusing satire of P3P called P5P, or the "Pretty Please Platform for Participating Publishers." This is possibly the best collection of protocol tokens I have seen since RFC 2324.
I think MS probably needs to acknowledge that P3P is broken, and change the default so it doesn't affect third party cookie acceptance. Administrators for Windows environments that think otherwise can override the default by deploying a group policy.
Granted, the standard is written to be abused. On the other hand, Google's behavior is basically "well if you don't say no it's not rape. What, you were bound and gagged at the time? Well nothing I can do about that".
There is no real enforcement behind it and it just causes lots of confusion. Seriously I have to go lookup what each of these acronyms are in order to figure out how my privacy is being violated? What guarantees do I even have that you are obeying P3P and not simply sending it to make me feel good.
Hell while we are at it we should implement P3P for phone apps. I'm sure Path (and others) will stop uploading your address book if the P3P says "ADDRBKNOUP"
No, you don't. This is mentioned in the article.
As mentioned in the article, IE has had the basic implementation of blocking 3rd party cookies if you don't use P3P for a while. I've always wanted to use honest P3P headers but it's such a PITA to generate them correctly site-by-site. Many frameworks include a generic P3P header by default with little or no mention in documentation so that's what I end up using.
I spent many hours read specs, tutorials, and trying out P3P generators to no avail. Finally I decided it's not worth my time and just used default framework P3P headers.
You could say the same thing about robots.txt.
This sounds like the perfect job for a legion of lawyers.
In some situations, the cookies we use to secure and authenticate your Google Account and store your preferences may be served from a different domain than the website you're visiting. This may happen, for example, if you visit websites with Google +1 buttons, or if you sign into a Google gadget on iGoogle.
Some browsers require third party cookies to use the P3P protocol to state their privacy practices. However, the P3P protocol was not designed with situations like these in mind. As a result, we've inserted a link into our cookies that directs users to a page where they can learn more about the privacy practices associated with these cookies.
Information that Google collects in association with these cookies is subject to our Privacy Policy.
Doesn't seem nefarious.
How isn't this nefarious?
P3P is lacking: http://bits.blogs.nytimes.com/2010/09/17/a-loophole-big-enou...
Google is still using this flaw to override the user setting "Do not allow 3rd party cookies" to allow themselves to track users.
There is no "technically" about this, they've misused the standard to override user settings.
Instead it says "Third Party Cookies" with choices of Accept, Block, or Prompt.
That's exactly what they do.
>Instead it says "Third Party Cookies" with choices of Accept, Block, or Prompt.
No, it doesn't.
You sound as if you have researched it, but you seem to be trying to mislead folks by spreading nonsense.
Google is intentionally using the loophole. They are intentionally circumventing users’ wishes. That’s nefarious. It’s first and foremost a moral failing. That’s exactly the problem. Just because it’s possible doesn’t mean it’s right.
That the loophole exists is a separate issue that also has to be remedied – but it doesn’t make Google’s behavior any less evil.
Or is it not 'standards-compliant' when WebKit implements features that only WebKit has, even if they're from W3C standards?
And the W3C standards are most successful when they document how technology is already being used in the wild. Proscriptive web standards handed down from on high have historically not fared well. Plenty of W3C standards are duds.
"Scare quotes are quotation marks placed around a word or phrase to indicate that it does not signify its literal or conventional meaning."
"If scare quotes are enclosing a word or phrase that does not represent a quotation from another source they may simply serve to alert the reader that the word or phrase is used in an unusual, special, or non-standard way or should be understood to include caveats to the conventional meaning."
Come up with a better standard, then complain when Google breaks it. Otherwise it's just another example of Google being "evil" (that's scare quotes).
Particularly
After a successful Last Call, the P3P Working Group decided to publish the P3P 1.1 Specification as a Working Group Note to give P3P 1.1 a provisionally final state. The P3P Specification Working Group took this step as there was insufficient support from current Browser implementers for the implementation of P3P 1.1. The P3P 1.1 Working Group Note contains all changes from the P3P 1.1 Last Call. The Group thinks that P3P 1.1 is now ready for implementation. It is not excluded that W3C will push P3P 1.1 until Recommendation if there is sufficient support for implementation.
This is the last update from the group that was posted in 2006. It's never been pushed by the W3C, and the browser creators never implemented it.
edit: sorry, I was wrestling with a stubborn CPU fan, and you seemed like that CPU fan. Turns out the CPU fan was not stubborn, but well-designed, and I probably wasn't communicating well.
I have no idea what your edit means, but I'm going to take is as a compliment and believe we were both mistaken on each others arguments. Because I like to keep things cool, like a CPU fan.
Don't they? I am curious, do you have a reference for that?
Particularly
After a successful Last Call, the P3P Working Group decided to publish the P3P 1.1 Specification as a Working Group Note to give P3P 1.1 a provisionally final state. The P3P Specification Working Group took this step as there was insufficient support from current Browser implementers for the implementation of P3P 1.1. The P3P 1.1 Working Group Note contains all changes from the P3P 1.1 Last Call. The Group thinks that P3P 1.1 is now ready for implementation. It is not excluded that W3C will push P3P 1.1 until Recommendation if there is sufficient support for implementation.
This is the last update from the group that was posted in 2006. It's never been pushed by the W3C, and the browser creators never implemented it.
I don't mean to single you out, but I've just been seeing too many of them lately.
No, if you select that option, it actually blocks all third party cookies.
Microsoft is very well aware of the fact that users never change the default settings and IMHO would love to use this to break Google by default and destroy their business model. This fits in well with the usual MS tactics of spreading paranoia, incompatibility, legal threats, obfuscation and confusion.
IMHO, Microsoft would love to exploit privacy fears to remove features from the web and break it so everyone just goes back to the desktop. In my opinion, if they could get away with breaking an ajax call, because hey they might be tracking you, they would in order to kill usability of web software in favor of the desktop software model. They will try anything they possibly can to win.
Did you ever see the list of IE6 features that got canned (e.g "Smart Tags") because of the antitrust investigation? It makes me shudder what the web would be like with these jerks in control.
That's why it's a brilliant piece of passive-aggressive engineering!
It undermines both the letter and intent of P3P, while ostensibly informing the user. The exact same string is a lie to the protocol, but the truth when read by a person outside of the protocol-context!
It's kind of like a file that's both a legal and harmless GIF and a malicious executable Java JAR. (Look up [GIFAR vulnerability] for more details.)
Basically they are abusing the standard to force P3P browsers to override the user's choice to block 3rd party cookies, by telling the browser that the cookie isn't intended for tracking, but Google is using it to track users.
That's kinda of appalling privacy-wise.
Maybe it isn't maliciously intended, which is what you mean, but it is an intentional misuse of a browser feature to force user tracking.
> However, the P3P protocol was not designed with situations like these in mind.
In that case, the P3P protocol was EXACTLY designed with this in mind.
If it's the former, then I'd say P3P is horribly broken and bypassing it for "like" buttons would be the only way to make things work.
And even if it's the latter, giving a site carte blanche tracking rights seems too coarse for comfort (unless you could grant permission ONLY for "like" buttons and nothing else).
I also don't much mind what companies do with tracking cookies --- I recommend using the Vanilla Cookie extension to Chrome to create a whitelist of persistent cookies. It rather nicely avoids the problem.
http://www.google.com/privacy/ads/ http://www.google.com/ads/preferences
Privacy is something that few of these companies truly respects. Does Google really respect it? Probably not as much as they'd like you to believe, but at least they are willing to discuss it and provide opt out solutions.
>...as they preferring the privacy settings their users have directly given them rather than those set in the browser.
That's extremely misleading. That's a default as well and not something that the user have "directly given them". I seriously doubt more than 0.1% of Google users have ever visited that page.
If you are making a political statement, then that's fine, I agree that all companies, Google included, should do far better on privacy grounds than they already are.
Okay, wait. There's multiple problems here.
The first one is this: that you are only now objecting, and not upset at all about Google handing over dissidents to the Chinese govt to torture and/or kill.
Human fucking life fucking has no fucking value to you? Priorities???
Secondly, they haven't been accussed of nefariousness, they have been caught red-handed, bald faced lied about it in public, only back-pedalled when presented with irrefutable evidence, and then convicted in court. Now, you can try to spin that as "accused", but you're going to need to set the spin cycle longer than normal, because that doesn't wash (sic) with the rest of the world.
Lastly, the problem with replacing Google is finding a good replacement. Bing is useless. The only thing close to gmail for free email (and it's barely in the same ballpark) is yahoo.
I agree with your intensity, though perhaps not its specific mode of expression.
How is that different from Google/ISPs handling over persons of interest to any other government, including yours? Or you think what is allowed in that case shouldn't be allowed for China's case? Are dissidents of China better than dissidents of any other country, to deserve special treatment?
P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info."http://security.stackexchange.com/questions/8489/should-anyo...
- Superuser
- Serverfault
- Database Administrators - 8.9 questions/day
- IT Security - 6.9 questions/day
- Healthcare IT - 1.1 questions/day
The stackexchange community is all about forking. Clearly Healthcare IT, IT Security, and Database Administrators could all be tagged questions in serverfault. But apparently serverfault.com/questions/tagged/heathcare didn't sit well with the 298 people who committed to the beta. Separating power-users from IT professionals (superuser vs serverfault)is certainly reasonable even though there is a large overlap of knowledge there.Of course, without the forks, as an IT person there might be a question if your cryptography related question should go in cryptography.SE or serverfault. With a dedicated site the "correct" location for those questions is easier to determine.
But if we're going to talk about overlapping stackexchanges we have to look at those populated predominantly by programmers, because... well, they are the master forkers.
- stackoverflow
- Programmers
- Code review
- Theoretical Computer Science
- Code Golf
- Signal Processing
- Computational Science
I left out the language specific ones like Mathematica and TeX. I also omitted Software QA and Cryptography.Apparently theoretical physicists and applied? physicists are unable to co-exist on one stackexchange.
Anyway, clearly the stackexchange community thinks that forking is the answer. I think tagging is superior and I think fragmenting the community gets fewer able eyes focused on questions. Forking doesn't really hurt google users trying to find answers to questions that have already been answered.
Even while not being a professional developer I would stick Code golf, code review, and Programmers into one stack exchange. I'd also put Signal Processing, Mathematica, Tex, and Compuational Science back in Stack Overflow and let the theoretical CS folks stay separate.
(Check related subreddits)
If they really cared, they'd include a way to disallow any third party resource without having to install a plugin like RequestPolicy. That would go a long way towards fighting tracking (and multiple exploits).
This is the main reason I stick with Firefox. I don't want to use a browser built by an advertising company.
Microsoft should admit that they only care about privacy when it's convenient for them.
What about it? A browser isn't a website, so P3P doesn't apply. Its written privacy policy applies, and likely allows such behaviour.
> Microsoft should admit that they only care about privacy when it's convenient for them.
I think the point being made is: so should Google.
What about it? Tell me more.
They don't even enable Bing suggestions by default.
P3P means "we would never..." in computer speech which is unenforceable therefore useless.
Google just make no promises via P3P and places link there explaining that it doesn't and why it doesn't.
Fortunately implementations of the P3P do the right thing and fold.
So if tomorrow Chrome uploads all your keystrokes to Google, will that be a valid defense?
>P3P means "we would never..." in computer speech which is unenforceable therefore useless.
Stopping Chrome from uploading your bank passwords with today's update is unenforceable as well and hence thereby useless.
And if you are afraid that cookies can be used for tracking then disable them in your browser.
P3P imho is useless because people whom I don't want to be tracked by will serve all the reassuring tokens in P3P and do whatever they want anyway.
I want my +1 buttons to work and if that means pulling curtain on some security theater then so be it.
Yes, anyone who wants to can circumvent it anyway, but that doesn’t stop us from judging those who do so negatively†. Google can be held accountable in this case (by, for example, complaining loudly about what they do) and there is nothing wrong with doing so. Just because it’s possible doesn’t mean it’s right.
That the protocol sucks is in that context a separate and unrelated issue. It may be security theater, but that doesn’t make Google’s behavior any more moral†.
—
† Insert clever analogy here. I’m too lazy to think about one, though.
P3P was standardized but it never got traction due to various practical problems. For example, privacy policies vary in many, sometimes-subtle, ways and nobody could figure out how to build simple software to decide automatically how to respond to these policies on behalf of users. Don't take Google's word for it, see what facebook says: http://www.facebook.com/help/?page=219494461411349. epic.org doesn't use it either.
There are some appealing ideas in P3P but in real life it doesn't actually help users protect their privacy, even on sites that actually implement it (such as Bing). The P3P working group shut down long go (http://www.w3.org/P3P/).
This is article is just cheap shot at a competitor.
MS tries to market their browser as safer and with more privacy features. Presumably some users trust MS to go with safe defaults. And Google tries to break that by intentionally breaking the standard for their profit by recording the users' browsing habits on their tracking servers and you are sympathetic to Google because they would make less profit if they didn't do this?
P3P was standardized
Then it's a little unfair to describe P3P as some IE-only standard then, no? You make it sound like proprietary extension.
Not even slightly. That does a huge disservice to any standardisation process. In fact, how "only Microsoft supports it" ends up being Microsoft's problem baffles me.
It was created by a standards body. The other browser manufacturers did not implement it. Therefore, it's all Microsoft's fault?
To web developers and certainly to web users there is zero difference between a standard that only Microsoft supports and a documented, but non-standard extension that only Microsoft supports.
Do they? Then what's the point in the standardisation process? The whole point is that everyone agreed on a solution in P3P. Maybe it wasn't ideal, but it was the standard. So, faithfully, MS implemented it.
So, MS is to blame when they go alone and make their own standards, but they are now also to blame when they follow the standardisation process to the letter and other people don't?
The point of the standards process is so that we don't have multiple competing/incompatible/ambiguous header-based privacy policies. But that's not the problem here. There aren't any notable competing privacy headers because the whole approach is flawed.
No, Google deliberately set a P3P header that confuses IE into letting Google bypass the user's privacy settings.
Creating an accurate P3P header that captures the nuances of different ways data can be used is somewhere between difficult and impossible (I've tried).
So now the standard of comparison for Google is shady warez sites that flout every possible standard for maximum gain?
I'd wager that there are a lot of exploits that install spyware in the wild. That doesn't excuse Google does it.
That's hardly "shady warez sites". I love you you jumped straight to that conclusion, though. Shows your biases coming through...
The argument I was responding to seems to be that P3P is a gentleman's agreement and thus is doomed to fail. However, I expect more from Google than I would from random sites on the internet.
So Google flouting a gentleman's agreement is very different from a warez site doing it. After all, you don't expect Google to read your mail in Gmail versus the site admins of warez-mail.com reading your email. Or do you?
P3P as a solution to protecting privacy on the Internet is an utter failure. The whole approach is bogus. I realize this is a judgement call, but I don't view sending bogus P3P headers as bogus. You want your site to work the same in a default Firefox install as in a default IE install and the only way to do that in this case is sending the bogus header.
Think about it: Google knows enough about the inner workings of IE to create Chrome Frame. How in the world is not knowing enough about how P3P works in IE an excuse?
A faked P3P header breaks IE's privacy settings in a nonfixable manner.
Not for the average user. The user who uses the default web browser. The user who uses IE.
I suspect you're right and the uptake isn't what they wanted, but that's not really a valid reason for them to work against the browser settings designed to protect a user's privacy.
Don't let them track and bubble you:
Not sure if that the valid answer but it has some merits if everybody is doing that (like downloading adress book from iPhone).
Now, I have the following question: if a random website is catch doing this, is it going to marked as un-safe by security scanners?
This is a clear example of Microsoft's 'extend' and 'embrace' strategy that destroyed so many platforms. The MS series of browsers were the only ones to adopt this before being recommended as a spec. The spec was never adopted.
Yeah you heard me Google-tards. Down-vote me like you always do, I got karma to burn baby burn.
If you have some evidence that it does, I am looking forward to seeing it. But more likely, I think you just read the headline and jumped in to comment.
NYT September 17, 2010:
http://bits.blogs.nytimes.com/2010/09/17/a-loophole-big-enou... If you rely on Microsoft’s Internet Explorer’s privacy settings to control cookies on your computer, you may want to rethink that strategy. Large numbers of Web sites, including giants like Facebook, appear to be using a loophole that circumvents I.E.’s ability to block cookies, according to researchers at CyLab at the Carnegie Mellon University School of Engineering. A technical paper published by the researchers says that a third of the more than 33,000 sites they studied have technical errors that cause I.E. to allow cookies to install, even if the browser has been set to reject them. Of the 100 most visited destinations on the Internet, 21 sites had the errors, including Facebook, several of Microsoft’s own sites, Amazon, IMDB, AOL, Mapquest, GoDaddy and Hulu.
Google doesn’t support a broken feature that is exclusive to IE somehow it’s their fault. If anyone ever doubted Microsoft's PR sleaziness and propaganda tactics that blog post is proof.
I am tired of this constant meme in the comments. It's one thing not to support a standard, it's another to actually go to the effort of actively subverting it.
They are supporting it by sending out (fake) P3P headers.
If they didn't support it, they wouldn't send P3P headers. As simple as that.
You can't argue in defense of Google from an "it's nonstandard" angle, because Google is all about nonstandard Web extensions these days -- to a much larger extent than Microsoft.
You can't argue in defense of Google from a "they didn't know enough about how IE works" angle. They're Google. They created Chrome Frame, people. They know enough to solve this engineering problem.
The pro-Google bias on HN is astounding.
I can imagine how exact same commenters here supporting Google would react if Bing Ads did this to Chrome. I am sure hell would break loose with the "OMG EVIL M$" shouts.
My concern now is that this post may disappear soon thanks to inevitable flagging of any negative news about Google. This has happened to many submissions in the past.
One instance http://news.ycombinator.com/item?id=3544173
That was an article about Microsoft posting an anti-Gmail video, but the pro-Google folks didn't want people to even see the video for themselves and judge it for what it's worth.
I would rather say the creation of Chrome Frame marked the point when they threw up their hands in frustration, deciding that they were never going to solve this engineering problem.
I've seen more civilized days.
Google is supporting the feature, in a way that appears deliberately intended to bypass the user's privacy settings.
http://www.ftc.gov/os/comments/privacyreportframework/00453-...
"We discovered that Microsoft’s support website recommends the use of invalid CPs as a work-around for a problem in IE. Specifically, a FRAMESET or parent window that references another site inside a FRAME considers the referenced site as a third-party, even if it is first-party content located on the same server [10]. Microsoft suggests the following invalid CP: CAO PSA OUR. This CP is clearly invalid since it does not contain any RETENTION or CATEGORIES tokens. Even if the CP were valid, Microsoft’s recommendation undermines the purpose of P3P since it encourages web administrators to use CPs that do not represent their actual data practices. We found several technical blogs recommending similar solutions [11], [19]."
So yes, a Microsoft support site did recommend a set of invalid CPs, but this is clearly not the same trick. This is a legitimate set of CP tokens that is used to workaround an issue where 1st party content appears to IE as 3rd party content. This token set is invalid because RETENTION/CATEGORIES tokens are missing, but the web author's intent here is (theoretically) honest.
Google, on the other hand, is providing no tokens whatsoever. Instead, in their P3P header they provide a human-readable string and a link to their privacy policy. This is not an invalid but intellectually honest set of tokens that is designed to comply with the spirit of the standard, if not the letter. This is an attempt to bypass the standard in order to allow 3rd party cookies, regardless of user settings.
The fact that you are equating these two practices is completely dishonest. Even a cursory glance through this document makes it clear that the Microsoft support site is advocating something completely different and is doing so in order to enable a fairly legitimate scenario.
Here's the blacklist they suggest in their post, which they recommend "as a protection": http://ie.microsoft.com/testdrive/browser/p3p/google.txt
The "-d" lines block domains entirely, which I believe means this has the consequence of blocking Google ads entirely.
Err what? Why would disabling cookies disable displaying ads?
You seem to be overly concerned about Google being unable to track the browsing habits of some people.
http://ie.microsoft.com/testdrive/Browser/TrackingProtection...