Facebook to Microsoft: P3P is outdated, what else ya got?
zdnet.com
zdnet.com
I don't have a problem with what Google and Facebook are doing here. By choosing to use them I implicitly accept their policies anyway. If I chose not to use them, I'm sure their public nature means that every privacy blocker out there can blacklist them for me.
Surely the real problem is that IE by default believes malicious sites that claim to respect my privacy?
About 10 years ago I worked on a site that put together a P3P policy, it was a nightmare. Like many other sites, we needed multiple P3P policies. Your ecommerce site probably has different things it stores compared to your marketing pages, for example, and you certainly don't want your marketing or blog pages saying that you are storing name/address/credit-card and scaring the crap out of people wondering how you are even getting that info off their system.
You can still find the decade-old tools over at p3ptoolbox.org that help you build a P3P policy, God forbid you try to build it by reading the spec. It also seems ironic that p3ptoolbox.org doesn't have a P3P policy and hasn't been updated since 2005.
In principle, having a site declare its practices might not prevent you from being tracked, but it might result in legal consequences or bad publicity for the site in question. Not every problem has a purely technical solution.
I have a fine idea: why not block a whole site if it offers a 3rd party cookie? I mean if the site offers evil tracking cookies than the site must be evil right? Or maybe this whole thing is just part of Microsoft's smear campaign.
Is this a rhetorical question?