U.S. Department of Commerce Web Advisory Group Minding Your Own Business The Platform for Privacy Preferences Project.

Slides:



Advertisements
Similar presentations
Cookies, Sessions. Server Side Includes You can insert the content of one file into another file before the server executes it, with the require() function.
Advertisements

U.S. Department of Commerce Web Advisory Group Implementing Machine Readable Privacy Requirements of the E-Gov Act.
P3P Implementation Tips : Observations for approaching Design, Build and Deploy PricewaterhouseCoopers Brendon Lynch.
Copyright 2004 Monash University IMS5401 Web-based Systems Development Topic 2: Elements of the Web (g) Interactivity.
CC3.12 Lecture 12 Erdal KOSE Based of Prof. Ziegler Lectures.
6/10/2015Cookies1 What are Cookies? 6/10/2015Cookies2 How did they do that?
XP Browser and Basics1. XP Browser and Basics2 Learn about Web browser software and Web pages The Web is a collection of files that reside.
Privacy and Security on the Web Part 1. Agenda Questions? Stories? Questions? Stories? IRB: I will review and hopefully send tomorrow. IRB: I will review.
Security Awareness: Applying Practical Security in Your World, Second Edition Chapter 3 Internet Security.
Internet – Part II. What is the World Wide Web? The World Wide Web is a collection of host machines, which deliver documents, graphics and multi-media.
XP Tutorial 9 New Perspectives on JavaScript, Comprehensive1 Working with Cookies Managing Data in a Web Site Using JavaScript Cookies.
ASP.NET 2.0 Chapter 6 Securing the ASP.NET Application.
CMU Usable Privacy and Security Laboratory Power Strips, Prophylactics, and Privacy, Oh My! Julia Gideon, Serge Egelman, Lorrie.
Browser and Basics Tutorial 1. Learn about Web browser software and Web pages The Web is a collection of files that reside on computers, called.
Lesson 46: Using Information From the Web copy and paste information from a Web site print a Web page download information from a Web site customize Web.
11 SUPPORTING INTERNET EXPLORER IN WINDOWS XP Chapter 11.
By: Mr Hashem Alaidaros MKT 445 Lecture 3 Title: Affiliate Marketing.
Automated Tracking of Online Service Policies J. Trent Adams 1 Kevin Bauer 2 Asa Hardcastle 3 Dirk Grunwald 2 Douglas Sicker 2 1 The Internet Society 2.
Usable Security – CS 6204 – Fall, 2009 – Dennis Kafura – Virginia Tech Privacy Preferences Edgardo Vega Usable Security – CS 6204 – Fall, 2009 – Dennis.
1 Introduction to Web Development. Web Basics The Web consists of computers on the Internet connected to each other in a specific way Used in all levels.
INTRODUCTION TO WEB DATABASE PROGRAMMING
Computer Concepts 2014 Chapter 7 The Web and .
ITIS 1210 Introduction to Web-Based Information Systems Chapter 48 How Internet Sites Can Invade Your Privacy.
P3P Soundbytes : Observations for approaching Design, Build and Deploy PricewaterhouseCoopers Ruth Nelson.
Intro to Google Apps B3: Working in Google Drive.
Chapter 16 The World Wide Web Chapter Goals Compare and contrast the Internet and the World Wide Web Describe general Web processing Describe several.
P3P A New Standard in Online Privacy Overview and Demos from Summer 2000.
1 Chapter 2 & Chapter 4 §Browsers. 2 Terms §Software §Program §Application.
Privacy Policy, Law and Technology Carnegie Mellon University Fall 2004 Lorrie Cranor 1 P3P I Week 6 - October.
Working with Cookies Managing Data in a Web Site Using JavaScript Cookies* *Check and comply with the current legislation regarding handling cookies.
CSE 154 LECTURE 12: COOKIES. Including files: include include("filename"); PHP include("header.html"); include("shared-code.php"); PHP inserts the entire.
Tutorial 1: Browser Basics.
Privacy, P3P and Internet Explorer 6 P3P Briefing – 11/16/01.
The Future of P3P Ari Schwartz Center for Democracy and Technology Lorrie Faith Cranor AT&T Labs-Research November 2002.
How P3P Works Lorrie Faith Cranor P3P Specification Working Group Chair AT&T Labs-Research 4 February 2002
P3P & Internet Explorer 6.0 New York – Feb. 4, 2002.
Chapter 8 Cookies And Security JavaScript, Third Edition.
Use of a P3P User Agent by Early Adopters Lorrie Faith Cranor Manjula Arjula Praven Guduru AT&T Labs November 2002.
CSCE 201 Web Browser Security Fall CSCE Farkas2 Web Evolution Web Evolution Past: Human usage – HTTP – Static Web pages (HTML) Current: Human.
The Teacher Is In Charge There are dozens of free services, but Gaggle.Net is the only service designed specifically for classroom use. The biggest.
Chapter 8 Browsing and Searching the Web. 2Practical PC 5 th Edition Chapter 8 Getting Started In this Chapter, you will learn: − What is a Web page −
● A system of Internet servers that support specially formatted documents. The documents are formatted in a markup language called HTML. What is the World.
COP 3813 Intro to Internet Computing Prof. Roy Levow Lecture 1.
CHAPTER 7 THE INTERNET AND INTRANETS 1/11. What is the Internet? 2/11 Large computer network ARPANET (Dept of Defense) It is international and growing.
Cookies By: Kendra Alvarez. Concepts of Cookies Cookies are pieces of information generated by a Web server and stored in the user's computer, ready for.
Computer-made Cookies Presented by Helal Lutfi. What is a Computer Cookie?  A small text file which contains a unique ID tag.  Placed on your computer.
Microsoft Office 2008 for Mac – Illustrated Unit D: Getting Started with Safari.
CMPE 494 Service-Oriented Architectures and Web Services Platform for Privacy Preferences Project (P3P) İDRİS YILDIZ
Web Browsers Web Browsers and their 'Add-ons' / 'Extensions'
Top Ten Ways to Protect Privacy Online -Abdul M. Look for privacy policies on Web Sites  Web sites can collect a lot of information about your visit.
11 SUPPORTING INTERNET EXPLORER IN WINDOWS XP Chapter 11.
Windows Vista Configuration MCTS : Internet Explorer 7.0.
Some from Chapter 11.9 – “Web” 4 th edition and SY306 Web and Databases for Cyber Operations Cookies and.
Chapter 8 Browsing and Searching the Web
Visualizing Privacy I March 7, 2006.
Chapter 1 Introduction to HTML.
How P3P Works Lorrie Faith Cranor P3P Specification Working Group Chair AT&T Labs-Research 4 February
MICROSOFT OUTLOOK and Outlook service Provider
Internet and security.
Latest Updates on BlackHawk Mines Music : Privacy Policy
Lesson #8 MCTS Cert Guide Microsoft Windows 7, Configuring Chapter 8 Configuring Applications and Internet Explorer.
What is Cookie? Cookie is small information stored in text file on user’s hard drive by web server. This information is later used by web browser to retrieve.
Unit 27 Web Server Scripting Extended Diploma in ICT
BMV Leisure & Shaftesbury Luxury Lodges GDPR Statement
CSc 337 Lecture 27: Cookies.
INTELLIGENT BROWSERS Cenk Ursavas.
Chapter 9: Configuring Internet Explorer
CSc 337 Lecture 25: Cookies.
Presentation transcript:

U.S. Department of Commerce Web Advisory Group Minding Your Own Business The Platform for Privacy Preferences Project

The E-Gov Requirements The Privacy Provisions of the E-Government Act of 2002 require both a “human readable” Privacy Policy and agency use of machine readable technology that alerts users automatically about whether site privacy practices match their personal privacy preferences.

Isn’t the Text Version Enough? Most users do not see the text privacy policy until after they have visited one or more of the site’s pages. Text privacy policies are sometimes difficult for users to locate, too lengthy for users to read, difficult to understand, and can change without notice.

Machine-Readable Policy P3P is the standard for machine-readable Privacy Policy. P3P enables web sites to translate their privacy practices into a standardized format (Extensible Markup Language - XML) that can be retrieved automatically and easily interpreted by a user's browser.

What Does P3P Address? Who is collecting data? What data is collected? For what purpose will data be used? Is there an ability to opt- in or opt-out of some data uses? Who are the data recipients (anyone beyond the data collector)? To what information does the data collector provide access? What is the data retention policy? How will disputes about the policy be resolved? Where is the human- readable Privacy Policy? What Does P3P Address?

What P3P Does Not Address P3P does not set minimum standards for privacy; nor can it monitor compliance with stated policy. –Certain types of “cookies” can be blocked based on type of cookie but not based on content of information in them. Implementation varies among browsers. –None go beyond cookies at this time.

How Does P3P Work?

How Users Are Notified Web Browser Alerts Web visitors who want to take advantage of P3P enabled sites have to set their personal privacy preferences in their web browser.

Browser Support Browser implementation of P3P is concerned with the issue of cookies When the browser encounters a cookie from a web page that either does not have a compact P3P policy, or that has a P3P policy that does not match the user’s privacy preferences, the user is alerted via icons. Browsers supporting Compact P3P Policy: –Netscape 7 –Mozilla –Internet Explorer 6 –AT&T Privacy Bird (Plug-in for Internet Explorer)

Cookies Cookies are information stored by a server on a visitor’s computer during their first visit to the site and used on subsequent visits to the site. This may be information obtained without asking (e.g., viewing habits), or information provided by the user (name, preferences). The server records this information in a text file and stores this file on the visitor's hard drive. What do your cookies say about you? Search your computer for the cookie files – You might be surprised.

Example of Cookies # Netscape HTTP Cookie File # # This is a generated file! Do not edit. home.frontiernet.netFALSE/FALSE regionid1 home.frontiernet.netFALSE/FALSE stateabbWV home.frontiernet.netFALSE/FALSE npa304 home.frontiernet.netFALSE/FALSE cityCharles+Town.mp3.comTRUE/FALSE RMID8c5a18333f09c160.2o7.netTRUE/FALSE s_vi_bzbx7Bmfehkf[CS]v4|3F09DC DFF- A000A4A |4032DDB1[CE].2o7.netTRUE/FALSE s_vi_nvnwhg[CS]v4|3F09DC DFF- A000A4A |4032DDB1[CE].2o7.netTRUE/FALSE s_vi_cx7Bczccdfx60x7Fl[CS]v3|3F09DC DFF- A000A4A |3F5F8EC2|3F09DC88|3F5F8EC3|3F5F8EFE|2|4|0|0||ltx0AGKIx04cEPASEx5Dx1Ex04lKIAx04EJx40x04lKI Ax04kBBMGA|ltx0AGKIx04cEPASEx5Dx1Ex04lKIAx04EJx40x04lKIAx04kBBMGA||||[CE].2o7.netTRUE/FALSE s_sv_cx7Bczccdfx60x7Fl[CS]v2|3F5F8EFE|[CE].2o7.netTRUE/FALSE s_vi_cx7Bczxxfifx60x7Fl[CS]v4|3F09DC9B00003CC3- A000A4F |4032DDB1[CE] These cookies contain personal information such as the city and state (Charles Town WV), area code (304), and even address (myname%40domain%2Enet or

Location of Cookie Files In Internet Explorer cookie files are in the “cookies” folder: –C:\Documents and Settings\user\Cookies How to Delete Cookies From Internet Explorer -Link to Microsoft Knowledge Base In Netscape cookies are stored in a file named “cookie.txt”

How Cookies and Browsers Interact By default, browsers allow the use of cookies. You can change your privacy settings so that your browser –Will ask you before placing a cookies on your computer, or –Will prevent the browser from accepting any cookies, or –Will handle First- and Third- Party cookies differently You can specify how you want to handle cookies from individual web sites or all web sites

Persistent Cookie stored on your computer remains there when you close your browser can be read by the web site that created it when you visit that site again.

Temporary or Session Cookie stored on your computer retained only for your current browsing session deleted from your computer when you close your web browser.

Unsatisfactory Cookie might allow access to personally identifiable information information could be used for a secondary purpose without your consent.

First-Party Cookie either originates on or is sent to the web site you are currently viewing commonly used to store information such as your preferences, for use when you re-visit the site

Third-Party Cookie either originates on or is sent to a web site different from the one you are currently viewing commonly used to track your web page use for advertising or other marketing purposes –Example: site xyz.com uses content from site 123.com. Site 123.com uses a cookies to track web page views and use by visitors to xyz.com

Setting Netscape 7 Preferences

Netscape 7 Notification A warning appears when the browser encounters a cookie that either does not have a compact P3P policy or has a P3P policy that does not match the browser preferences Netscape 7 Notification

Setting Mozilla Preferences

Setting IE 6 Preferences

IE6 Notification A warning appears when the browser encounters a cookie that either does not have a compact P3P policy or has a P3P policy that does not match the browser preferences IE6 Notification

IE 6 Privacy Reports

AT&T Privacy Bird AT&T Privacy Bird A free plug-in for Internet Explorer 6 Green BirdYellow BirdRed BirdAudible Notifications: