P3P was standardized but it never got traction due to various practical problems. For example, privacy policies vary in many, sometimes-subtle, ways and nobody could figure out how to build simple software to decide automatically how to respond to these policies on behalf of users. Don't take Google's word for it, see what facebook says: http://www.facebook.com/help/?page=219494461411349. epic.org doesn't use it either.
There are some appealing ideas in P3P but in real life it doesn't actually help users protect their privacy, even on sites that actually implement it (such as Bing). The P3P working group shut down long go (http://www.w3.org/P3P/).
This is article is just cheap shot at a competitor.
I'd wager that very few P3P headers used in the wild are an accurate and complete representation of the privacy policy of the site. Most are either deliberately confusing IE (as you put it) or copied from a tutorial by a developer who just needed to fix the damn login button for stupid IE users.
Creating an accurate P3P header that captures the nuances of different ways data can be used is somewhere between difficult and impossible (I've tried).
Why are you giving Google, of all companies, a pass because they just "copied from a tutorial"? Google is probably the least deserving company in the entire world of the engineering ignorance defense.
Think about it: Google knows enough about the inner workings of IE to create Chrome Frame. How in the world is not knowing enough about how P3P works in IE an excuse?
Google said it isn't possible to create an accurate P3P header that describes how they use cookies. Having previously tried to parse the standard document, I'm inclined to believe them.
If that's the case, the responsible course of action is not to send a P3P header at all. Sending a deliberately false one to circumvent third-party cookie restrictions is simply not cool.
If they can convince people to install Chrome Frame, I'm sure they can figure out how to tell people to enable 3rd party cookies. My guess is they'd have a lot harder time explaining why the user should do that.
And yet they spent all that time doing it ... Seriously, who is Chrome Frame for if not the average user? And they inform you about it as soon as you visit google.com in IE.
I suspect you're right and the uptake isn't what they wanted, but that's not really a valid reason for them to work against the browser settings designed to protect a user's privacy.
They can't provide a P3P header saying that won't let 3rd parties track you with it? That would "Break" their +1 functionality? I'd like an explanation of that.
Broken implementations are different from intentionally subverted ones. If FB is doing this, they deserve blame too.
The argument I was responding to seems to be that P3P is a gentleman's agreement and thus is doomed to fail. However, I expect more from Google than I would from random sites on the internet.
So Google flouting a gentleman's agreement is very different from a warez site doing it. After all, you don't expect Google to read your mail in Gmail versus the site admins of warez-mail.com reading your email. Or do you?
But it's a gentleman's agreement between Microsoft and... no one. The user didn't ask to have their cookies blocked and Google certainly didn't ask to be a part of this scheme. It's not really an agreement when only one party has agreed to it.
P3P as a solution to protecting privacy on the Internet is an utter failure. The whole approach is bogus. I realize this is a judgement call, but I don't view sending bogus P3P headers as bogus. You want your site to work the same in a default Firefox install as in a default IE install and the only way to do that in this case is sending the bogus header.
So the fact that P3P doesn't solve all the problems it set out to solve justifies Google intentionally using it to compromise visitors' privacy in a way that directly contradicts the purpose of the header? And this is okay because it's an MSIE feature they're circumventing?
The functionality being "broken" is functionality that users DO NOT WANT and have EXPLICITLY OPTED OUT OF by configuring their browser to reject tracking cookies. If they weren't tracking cookies, you could send a VALID P3P header and your app would work.
Actually it's the default in IE, not a feature people opted into. I'd be a lot less sympathetic to Google if it was a feature people opted into rather than one that IE users were unaware of.
XP SP2 made the firewall default and enabled. If Chrome disabled it for themselves and started uploading user files when the computer was idle, will that make it okay since it was Microsoft who installed the firewall by default and not the user?
MS tries to market their browser as safer and with more privacy features. Presumably some users trust MS to go with safe defaults. And Google tries to break that by intentionally breaking the standard for their profit by recording the users' browsing habits on their tracking servers and you are sympathetic to Google because they would make less profit if they didn't do this?
I recognize it's a judgement call, but I'm sympathetic to breaking P3P because P3P is a crappy standard that doesn't actually do much to protect your privacy. In 2012, P3P is best known as the thing that breaks your single sign-on solution in IE.
That third one is accept that you lost 99% of IE users, since almost no IE users can actually understand something like P3P and who is asserting what and why that claim should be trusted, and thus leave that scary looking setting at the default level.
I made the point in another post that it was a "standard" and my post was immediately made invisible. Sometimes you can never win when people insist on ignoring the point for the strawmen.
He didn't say it's an "IE-only standard", he said it was an IE-only feature. It may be standardized, but that doesn't mean that it's implemented in other browsers.
Lets not get lost in semantics. True it's a documented standard, but only Microsoft supports it and given its many drawbacks no one else is likely to add support any time soon. It might as well be proprietary.
Not even slightly. That does a huge disservice to any standardisation process. In fact, how "only Microsoft supports it" ends up being Microsoft's problem baffles me.
It was created by a standards body. The other browser manufacturers did not implement it. Therefore, it's all Microsoft's fault?
It is Microsoft's problem that they have IE default to rely on what nearly everyone agrees is a crap solution to protecting privacy on the Internet.
To web developers and certainly to web users there is zero difference between a standard that only Microsoft supports and a documented, but non-standard extension that only Microsoft supports.
It is Microsoft's problem that they have IE default to rely on what nearly everyone agrees is a crap solution
Do they? Then what's the point in the standardisation process? The whole point is that everyone agreed on a solution in P3P. Maybe it wasn't ideal, but it was the standard. So, faithfully, MS implemented it.
So, MS is to blame when they go alone and make their own standards, but they are now also to blame when they follow the standardisation process to the letter and other people don't?
You don't get a free pass because you're following a W3C standard. The way P3P is implemented in IE made web developers lives harder in exchange for virtually no additional privacy protections to users.
The point of the standards process is so that we don't have multiple competing/incompatible/ambiguous header-based privacy policies. But that's not the problem here. There aren't any notable competing privacy headers because the whole approach is flawed.
Are you going to say the same thing about the FileSystem API, Dart, and NaCl? Google is probably the worst browser vendor when it comes to having competing implementations of their proprietary features.
There was a standardization process, then the committee in charge of it gave up on it because it wasn't going anywhere except IE. See the home page of the working group (http://www.w3.org/P3P/). It's time IE woke up to that reality.
P3P was standardized but it never got traction due to various practical problems. For example, privacy policies vary in many, sometimes-subtle, ways and nobody could figure out how to build simple software to decide automatically how to respond to these policies on behalf of users. Don't take Google's word for it, see what facebook says: http://www.facebook.com/help/?page=219494461411349. epic.org doesn't use it either.
There are some appealing ideas in P3P but in real life it doesn't actually help users protect their privacy, even on sites that actually implement it (such as Bing). The P3P working group shut down long go (http://www.w3.org/P3P/).
This is article is just cheap shot at a competitor.