Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>I'd wager that very few P3P headers used in the wild are an accurate and complete representation of the privacy policy of the site.

So now the standard of comparison for Google is shady warez sites that flout every possible standard for maximum gain?

I'd wager that there are a lot of exploits that install spyware in the wild. That doesn't excuse Google does it.



As has already been discussed in numerous places, Google, Facebook, Amazon and even Microsoft have broken P3P implementations in several places.

That's hardly "shady warez sites". I love you you jumped straight to that conclusion, though. Shows your biases coming through...


Broken implementations are different from intentionally subverted ones. If FB is doing this, they deserve blame too.

The argument I was responding to seems to be that P3P is a gentleman's agreement and thus is doomed to fail. However, I expect more from Google than I would from random sites on the internet.

So Google flouting a gentleman's agreement is very different from a warez site doing it. After all, you don't expect Google to read your mail in Gmail versus the site admins of warez-mail.com reading your email. Or do you?


But it's a gentleman's agreement between Microsoft and... no one. The user didn't ask to have their cookies blocked and Google certainly didn't ask to be a part of this scheme. It's not really an agreement when only one party has agreed to it.


Shady warez sites? Huh?

P3P as a solution to protecting privacy on the Internet is an utter failure. The whole approach is bogus. I realize this is a judgement call, but I don't view sending bogus P3P headers as bogus. You want your site to work the same in a default Firefox install as in a default IE install and the only way to do that in this case is sending the bogus header.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: