Google, Microsoft butt heads over IE privacy skirting
'Plenty of blame to go around' for both companies, says privacy researcher
Computerworld - Google yesterday countered Microsoft's contention that it's skirting Internet Explorer's privacy protection, saying it's "impractical" to comply with IE's rules.
One privacy researcher said there was enough blame to apportion to both Google and Microsoft.
The latest dustup over Google's privacy practices began early Monday, when Microsoft's top executive for IE accused Google of circumventing the browser's default privacy defense so that Google's ad network could track IE users' online movements without their permission.
Microsoft's charges were similar to ones made last week after the Wall Street Journal said Google was sidestepping the privacy protection of Apple's Safari, which is bundled with Mac OS X and is the only authorized browser on the iPhone and iPad.
On Monday, Dean Hachamovitch, who leads the IE team, said Google was getting around Microsoft's browser, too.
"Google utilizes a nuance in the P3P specification that has the effect of bypassing user preferences about cookies," Hachamovitch said in a blog post.
P3P, for "Platform for Privacy Preferences," is a 10-year-old Web standard that websites can use to describe how they use cookies and user information. By default, IE blocks all tracking cookies from sites that do not present a valid P3P compact policy (CP), a string of codes sent to browsers as part of the HTTP header.
Google, said Hachamovitch, was gaming P3P to trick IE into accepting tracking cookies, even though Google's Compact Policy Statement does not spell out the search giant's intent. "Google bypasses the cookie protection [in IE] and enables its third-party cookies to be allowed rather than blocked," Hachamovitch charged.
Google returned volley today.
In a statement issued by Rachel Whetstone, senior vice president of communications and policy, Google asserted that it was "impractical to comply" with IE's P3P request because doing so prevented sites and services from providing features, including sign-in to multiple Google services.
"Today the Microsoft policy is widely non-operational," said Whetstone, citing a 2010 report that claimed more than 11,000 websites were not issuing valid P3P policies. "The reality is that consumers don't, by and large, use the P3P framework to make decisions about personal information disclosure."
Whetstone went on to say that Google has "been open about our approach" to P3P, and said Microsoft itself had recommended using invalid P3P codes as a work-around for a problem in IE. "This recommendation was a major reason that many of the 11,176 websites provided different code to the one requested by Microsoft," she said.
The study referenced by Whetstone was conducted by a team at Carnegie Mellon University's CyLab and published in September 2010 (download PDF).
In the report, the researchers noted the widespread circumvention -- some apparently purposeful, some accidental -- of IE's cookie-blocking with malformed P3P compact policies. Among the companies involved, the report named Amazon, Facebook and Google.
"I think there is plenty of blame to go around," said Lorrie Faith Cranor, an associate professor of computer science at Carnegie Mellon, the director of its CyLab Usable Privacy and Security Laboratory and the faculty member who lead the team that produced the 2010 report.
She said Microsoft was partly to blame for not complaining about companies circumventing its privacy policy and not taking steps to modify IE. Cranor reported her team's findings to Microsoft in the fall of 2010, but she did not receive any formal reply. However, Cranor said that shortly afterward, Microsoft scrubbed its support site of the workaround recommendation Whetstone mentioned.
Privacy watch
- Privacy advocates vow to continue CISPA fight
- CISPA concerns spread in Congress
- Privacy watchdog, lawmaker push for Google probe
- Privacy groups launch protest against CISPA bill
- Senators call for probe of employers seeking Facebook info
- 36 state AGs blast Google's privacy policy change
- FAQ: What Google's 'Do Not Track' move means
- Google commits Chrome to support 'Do Not Track'
- Google, Microsoft butt heads over IE privacy skirting
- Microsoft slams Google over iPhone, Mac privacy boner


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All Privacy White Papers
- Close a Dangerous Vulnerability: Automated Methods for Managing Admin Rights
- In this exclusive webcast from Viewfinity, you'll hear how to leverage Group Policy Object settings to close this vulnerability by elevating privileges for...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
All Privacy Webcasts
