Token Attempt: The Misrepresentation of Website Privacy Policies through the Misuse of P3P Compact Policy Tokens (CMU-Cylab-10-014)

نویسندگان

  • Pedro Giovanni Leon
  • Lorrie Faith Cranor
  • Aleecia M. McDonald
  • Robert McGuire
چکیده

Platform for Privacy Preferences (P3P) compact policies (CPs) are a collection of three-character and four-character tokens that summarize a website’s privacy policy pertaining to cookies. User agents, including Microsoft’s Internet Explorer (IE) web browser, use CPs to evaluate websites’ data collection practices and allow, reject, or modify cookies based on sites’ privacy practices. CPs can provide a technical means to enforce users’ privacy preferences if CPs accurately reflect websites’ practices. Through automated analysis we can identify CPs that are erroneous due to syntax errors or semantic conflicts. We collected CPs from 33,139 websites and detected errors in 11,176 of them, including 134 TRUSTe-certified websites and 21 of the top 100 most-visited sites. Our work identifies potentially misleading practices by web administrators, as well as common accidental mistakes. We found thousands of sites using identical invalid CPs that had been recommended as workarounds for IE cookie blocking. Other sites had CPs with typos in their tokens, or other errors. 98% of invalid CPs resulted in cookies remaining unblocked by IE under it’s default cookie settings. It appears that large numbers of websites that use CPs are misrepresenting their privacy practices, thus misleading users and rendering privacy protection tools ineffective. Unless regulators use their authority to take action against companies that provide erroneous machine-readable policies, users will be unable to rely on these policies.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Privacy Fox - A JavaScript-based P3P Agent for Mozilla Firefox

Website operators and visitors are both interested in effective communication of the privacy policies of a website. In practice, however, privacy policies are either too long and difficult for visitors to read through, or do not provide the information that visitors are looking for. Automated translation of P3P policies into human readable form is a promising solution. P3P is a W3C-defined stan...

متن کامل

Policy Refinement Checking ( Extended

We introduce refinement checking for privacy policies expressed in P3P and XACML. Our method involves a translation of privacy policies to a set of process specifications in CSP, which describe how the privacy policy is enforced. The technique is described through an example involving medical data collected by a biobank.

متن کامل

EnCoRe: Ensuring Consent and Revocation

We introduce refinement checking for privacy policies expressed in P3P and XACML. Our method involves a translation of privacy policies to a set of process specifications in CSP, which describe how the privacy policy is enforced. The technique is described through an example involving medical data collected by a biobank.

متن کامل

Towards Usable Privacy Policies: Semi-automatically Extracting Data Practices From Websites’ Privacy Policies

1. MOTIVATION Natural language privacy policies have become the de facto standard “notice and choice” method on the Web, in order to communicate a website's data practices. Yet, website privacy policies are often complex and difficult to understand. As a result, few users bother to read them [9]. It has been proposed to improve notice and choice mechanisms by making privacy practices machine-re...

متن کامل

Enhancing P3P Framework through Policies and Trust

The Platform for Privacy Preferences (P3P) is a W3C standard that websites can use to describe their privacy practices. The presence of P3P policies enable users to configure web browsers to constrain what they can and cannot do when visiting websites. It’s a good idea that unfortunately is rarely used. We identify two reasons: (i) the languages available to define a user’s privacy preferences ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010