Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Meeting to mull privacy standard's next step

Patrick Thibodeau   Today’s Top Stories    or  Other Privacy Stories  
 

Sign up to receive Security Resource Alerts

November 11, 2002 (Computerworld) -- WASHINGTON -- The Platform for Privacy Preferences (P3P) was released in April, and so far about 18% of the top 500 Web sites are using it. But the rate of new adoptions of this privacy specification is glacial -- about 1% a month among top sites -- and financial services, the industry that handles some of the most sensitive personal information, has a much lower-than-average P3P adoption rate.
This week the people and companies behind the World Wide Web Consortium's (W3C) P3P standard will meet to talk about the future of the spec and whether a Version 2.0 is needed or whether some tweaking to Version 1.0 can address issues raised by industry groups.
One concern is that the spec's "vocabulary" isn't rich enough to allow exact translation of a written privacy policy into a machine-readable one.
Because of that problem, the Financial Services Roundtable's BITS technology group, a Washington-based industry association representing some of the largest financial services companies, wants the W3C "to state explicitly" that P3P statements "are not meant to be legally binding documents," according to a position paper prepared for this week's meeting at America Online Inc.'s facilities in Dulles, Va.
The legal uncertainty of P3P is a big issue, said Lorrie Cranor, a principal technical staff member at AT&T Labs-Research and chairman of the P3P Specification Working Group. But the W3C "can't give a definitive answer, because we don't write the laws."
Only 11% of top finance and investing Web sites have adopted P3P, vs. 18% overall for the top 500 sites, according to Ernst & Young LLP, which began reporting on P3P adoption in August.
At the current rate, it will take eight years or so for P3P to get fully adopted, said Brian Tretick, a principal at Ernst & Young. One reason for the sluggish rate of adoption is the economy, since some companies are interested in it but don't want to spend the money. Another is uncertainty about how P3P policies will be enforced.
At this week's meeting, the P3P working group may look at the idea of developing negotiation ability into P3P, said Cranor. As it stands, when a P3P-capable Web browser interacts with a Web site, the browser reacts based on the user's privacy preferences in a yes/no manner. Negotiation ability would allow a company to interact with the user and, for instance, offer a coupon in exchange for privacy information. This would also complicate things, requiring varying privacy policies to handle the results of any negotiations, she said.
Despite various issues to be hammered out, Tretick believes that as long as Internet Explorer and Netscape support P3P, the specification isn't going away and that firms will have to deal with it or risk losing some of their ability, for instance, to use persistent cookies with some customers.




Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"This company's infrastructure group is running a disaster recovery exercise with a reluctant participant: an IT manager who's notorious as..." Read more...
"It's IT Blogwatch: in which Mozilla's Firefox Web browser continues to gain market share, smashing records as it does so...." Read more...
Read more Security posts or See all Blogs
Microsoft promises four patches next week
Google gives away home-cooked Web application security scanner
Storm botnet stages Fourth of July attacks
More top stories...
Microsoft trumpets security additions in upcoming IE8
Apple cuts price of high-end SSD MacBook Air by $500
Ultrathin showdown: Apple MacBook Air vs. Lenovo ThinkPad X300 vs. Toshiba Portege R500
All it takes is a couple hours and about $125 to breathe new life into an old laptop. Here's how.
Is Microsoft's Golden Age over? What are Gates' most memorable quotes? Find out in Computerworld's complete coverage of the end of the Bill Gates era at Microsoft.
There are some things your CIO definitely doesn't want to hear. Also don't miss the flipside, Five things you should always tell your boss.
With its latest version, Mozilla's browser continues to raise the bar for what Web browsers should be.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
Data Center Management Zone
Enterprise-Class Security Zone
The File Data Management Zone
Grid Computing on Windows Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Storage Virtualization Zone
Business Intelligence and Analytics Zone

Ads by TechWords

See your link here
Why SaaS is Vital to Email and Web Security
Why SaaS is Vital to Email and Web Security
Download this webcast, free, compilments of Webroot Software
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Windows® Enterprise Data Protection with Symantec Backup Exec™
Get this white paper now!
(Source: Symantec) With data protection becoming more distributed and IT resources increasingly constrained, businesses need a centralized data protection strategy that can manage multiple backup and recovery jobs. Learn how to address these critical enterprise challenges with dynamic disk-based data protection.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Deploying Virtualized NetWare on Linux Whitepaper
Toward More Flexible, Next-Generation Collaboration Solutions
Driving Business Success Through Workgroup Choice and Flexibility
View more whitepapers