Promise of P3P stalls as backers regroup

NEWS
Six months after its recommendation as an Internet standard, a major privacy initiative is entering an awkward adolescence as software heavyweights adopt it and individual Web sites leave it to languish. In ordinary economic times, a protocol like the World Wide Web Consortium's Platform for Privacy Preferences (P3P) might have a hard time gaining traction in the marketplace, as mainstream consumers generally exhibit lax security practices when it comes to their own online privacy. But in an economic downturn, the privacy protocol also is subject to a lack of interest by Web developers with scarce resources. P3P allows surfers to specify which information they are willing to automatically share with Web sites, such as names and shipping addresses. When a site seeks information that has not been cleared, such as a credit card number, a warning is displayed. Ideally, the process would make Internet users feel more comfortable with the information being shared and more likely to shop or browse. However, in a downturn the urgency attending its development in years past has diminished along with the economic opportunity it was meant to foster. "The downturn in technology and the e-commerce sector in general has lessened the push or the demand for P3P that we saw even two years ago," said Stephen Keating, executive director of the Privacy Foundation. "The trend line is now longer than we'd expected. We're now seeing that companies like IBM and Microsoft are interested in how privacy issues may affect e-commerce, but the timeline to figure that out is much longer than it appeared to be." The second economically sensitive problem is that privacy, perhaps already low on Web authors' list of things to do, has dropped further as resources grow scarcer. "I've talked to a lot of people about this, and for many it's just not a priority," said Lorrie Cranor, the chair of the W3C's P3P working group, an AT&T researcher and the author of a book about P3P published last month. "It's not that they have anything against it, it's just one more thing to do. Meanwhile, everyone's budgets are tightening and they're not sure there's a payoff." Widespread adoption in doubt
Next month, AOL Time Warner will host a meeting of the W3C -- a major Web standards group with authority over the privacy technology -- to debate what sorts of revisions may be required. The protocol, which establishes how Web sites and Web browsers can use pre-established parameters to negotiate the use of cookies, privacy policies and other information-gathering techniques, came under the W3C's auspices in 1997. The W3C released its P3P recommendation six months ago, and since then both Microsoft and AOL Time Warner have introduced some P3P features into their browsers, Internet Explorer and Netscape. But discussions on 12 and 13 November in Dulles, Virginia, might well turn to wider issues than new bells and whistles for P3P. The more crucial question facing working group members attending the W3C's Workshop on the Future of P3P may be when or whether P3P will ever see widespread demand and adoption. According to an ongoing survey being conducted by Ernst & Young, the percentage of top 500 Web domains -- as determined by Comscore/Media Metrix -- that use P3P has stagnated in recent months. (By counting domains rather than individual sites, the researchers are looking at all sites within yahoo.com, for example, as opposed to treating mail.yahoo.com and news.yahoo.com separately.) In September, 25 percent of the top 100 Web sites had some sort of P3P functionality, defined either as having a P3P reference file in an accessible location, or including a link to a P3P policy within the site's HTTP header. For the top 500 sites, that percentage dropped to 17 percent. Those results are virtually unchanged from August, with only four Web domains within the top 500 becoming P3P-enabled, according to Ernst & Young. Only one of those was in the top 100. Broken down by industry, the "shopping" category did best with a 28 percent adoption rate. At the other end of the spectrum, not a single government site in the top 500 used P3P, the study showed. Financial services sites, under increasing regulatory pressure to protect the data of their clients, turned in a below-average adoption rate of 11 percent. That indicates the degree of confusion over how P3P and the growing canon of privacy law intersect, study authors said. "The financial services sector is still in a low adoption rate," said Brian Tretick, principal with Ernst & Young. "That's because there's a lot of concern over how it applies in a regulatory environment." Effective privacy disclosure
Some companies working on Web privacy are looking to the financial services industry for examples of how not to attack the problem. Last year, the Gramm-Leach-Bliley Financial Services Modernization Act in the US required that financial institutions disclose to customers how they use private information. The result was a flurry of dense, legally phrased documents that many doubt reached their audience. "The banks spent millions to tell people what they do with all personal information and give people the opportunity to opt out," said David Steer, representative of Truste, a San Francisco online privacy not-for-profit organisation. "And in the end, people just threw them away." Partly as a result of the Gramm-Leach-Bliley Act, banks and financial services companies are among those that have organised with Truste, and with law firm Hunton & Williams' Center for Information Policy Leadership, to devise a new method of privacy disclosure. The new scheme is a nontechnological effort to post the highlights of a privacy statement in a format modelled on the "Nutrition Facts" label the US Food and Drug Administration requires on most food packaging. "The symbols and labels initiative started because privacy policies were becoming way too long for consumers to read," Steer said. "Web sites need a policy that does two things: it has to be a contract and it has to explain in clear English (the) policies that become only more complex over time. So this 'nutrition label' of privacy is a way of calling out the bits of information that consumers really care about." Another scheme to help Web surfers come to quick conclusions about a site's privacy policy is AT&T's privacy bird, a P3P-based indicator that rates a site's privacy policies as red or green depending on the surfer's preferences. Inspiring changes
While the Gramm-Leach-Bliley mailings may have been the catalyst for one new method for publicising a privacy policy, another federal law that is months away from going into effect may inspire a new flock of P3P adherents. The Health Insurance Portability and Accountability Act of 1996 (HIPPA) was written to ensure that workers don't lose their health insurance when they lose or change jobs, but also to protect the privacy of health records. HIPPA could spur significant growth in P3P adoption, Steer said. "You're seeing laws that really put a lot of the burden on companies to beef up their privacy practices," Steer said. "Health care companies are now scrambling to find a solution (to HIPPA) and they're saying if we're going to spend millions of dollars on privacy, then let's do it right. We will see more P3P adoption but it won't be a rush, it will be a trickle of sites that become P3P compliant. But then, at the end of the day, we're going to have to go out there and teach people how to use it." And that, according to lawyers familiar with the technology, will be no small task. "You can't change your Web site without going through and changing your P3P," said Eric Goldman, assistant professor at Marquette University Law School in Milwaukee and former chief counsel for Epinions. "It's really time consuming and costly to re-architect your site...to maintain your site as P3P-complaint regardless of changes you make. And so I think the underlying assumption of P3P was companies will be happy to do this because so many users will demand it, but until users demand it companies will not go through and make all the changes required to be in compliance." Ultimately, neither education nor the law may wind up having as much effect on P3P as the march of technology. P3P saw a significant boost in adoption after Microsoft installed basic P3P functionality in Internet Explorer 6. AOL Time Warner soon followed with P3P features in Netscape 7. The IE 6 implementation "had a pretty big impact on Web site adoption," said the W3C's Cranor. "That sent signals to Web developers that P3P is real, because it was built into a widely deployed product." Microsoft's implementation, which blocked some third-party Web site cookies if they were not P3P-compliant, sent a signal with some teeth in it. "By default, some of these cookies were now going to be blocked," Cranor said. "And that was a wake-up call to Web sites who discovered that their cookies were being blocked and they had no idea why. That was their first introduction to P3P."
For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section. Have your say instantly, and see what others have said. Go to the Security forum. Let the editors know what you think in the Mailroom.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

36 minutes ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

1 hour ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

1 hour ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

2 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

4 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

10 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

12 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

12 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

13 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

14 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

15 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

15 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

15 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

16 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

16 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

17 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

17 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

17 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

20 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

21 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs