The Platform for Privacy Preferences (P3P) Workshop on the Relationship between Privacy and Security Lorrie Faith Cranor P3P Specification Working Group.

Slides:



Advertisements
Similar presentations
What Companies Need to Know about P3P
Advertisements

Web Privacy with P3P Lorrie Faith Cranor P3P Specification Working Group Chair AT&T Labs-Research July 2002
U.S. Department of Commerce Web Advisory Group Implementing Machine Readable Privacy Requirements of the E-Gov Act.
P3P Ro Young-jin. What Is P3P? Platform for Privacy Preference Project Developed by W3C Provides a standard way for Web sites to communicate.
1 Configuring Internet- related services (April 22, 2015) © Abdou Illia, Spring 2015.
Identity Management Based on P3P Authors: Oliver Berthold and Marit Kohntopp P3P = Platform for Privacy Preferences Project.
Minding Your Own Business The Platform for Privacy Preferences Project and Privacy Minder Lorrie Faith Cranor AT&T Labs-Research
The Platform for Privacy Preferences Project (P3P) Lorrie Faith Cranor AT&T Labs-Research P3P Interest Group Co-Chair October 1998.
PETs and ID Management Privacy & Security Workshop JC Cannon Privacy Strategist Corporate Privacy Group Microsoft Corporation.
Computers and Society Carnegie Mellon University Spring 2006 Cranor/Tongia/Farber 1 Privacy Week 7 - February.
Privacy and Security on the Web Part 1. Agenda Questions? Stories? Questions? Stories? IRB: I will review and hopefully send tomorrow. IRB: I will review.
Usable Privacy and Security Carnegie Mellon University Spring 2008 Lorrie Cranor 1 Introduction to Privacy January.
1 Configuring Web services (Week 15, Monday 4/17/2006) © Abdou Illia, Spring 2006.
Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 1 Introduction.
Personalization vs. Privacy Invasion © 2001 Ann Schlosser, University of Washington Business School.
Lorrie Cranor 1 Introduction to P3P Lorrie Faith Cranor.
P3P: Platform for Privacy Preferences Charlin Lu Sensitive Information in a Wired World November 11, 2003.
Lorrie Faith Cranor AT&T Labs-Research Online Privacy Promise or Peril?
C MU U sable P rivacy and S ecurity Laboratory Making privacy visible Lorrie Faith Cranor October 19, 2007.
ASP.NET 2.0 Chapter 6 Securing the ASP.NET Application.
CMU Usable Privacy and Security Laboratory Power Strips, Prophylactics, and Privacy, Oh My! Julia Gideon, Serge Egelman, Lorrie.
Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 1 Deploying P3P.
An Analysis of P3P Deployment Hyun Jin Kim Sensitive Information in a Wired World November 11, 2003.
1 The World Wide Web. 2  Web Fundamentals  Pages are defined by the Hypertext Markup Language (HTML) and contain text, graphics, audio, video and software.
Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 1 Privacy Policy.
 Proxy Servers are software that act as intermediaries between client and servers on the Internet.  They help users on private networks get information.
Computers and Society Carnegie Mellon University Spring 2007 Cranor/Tongia 1 Privacy Week 5 - February 13,
The Privacy Tug of War: Advertisers vs. Consumers Presented by Group F.
Lesson 46: Using Information From the Web copy and paste information from a Web site print a Web page download information from a Web site customize Web.
Lorrie Faith Cranor AT&T Labs-Research Online Privacy What are People So Concerned About and What is Being Done About it?
Norman SecureSurf Protect your users when surfing the Internet.
11 SUPPORTING INTERNET EXPLORER IN WINDOWS XP Chapter 11.
Automated Tracking of Online Service Policies J. Trent Adams 1 Kevin Bauer 2 Asa Hardcastle 3 Dirk Grunwald 2 Douglas Sicker 2 1 The Internet Society 2.
Usable Security – CS 6204 – Fall, 2009 – Dennis Kafura – Virginia Tech Privacy Preferences Edgardo Vega Usable Security – CS 6204 – Fall, 2009 – Dennis.
Working with Applications Lesson 7. Objectives Administer Internet Explorer Secure Internet Explorer Configure Application Compatibility Configure Application.
Privacy Policy, Law and Technology Carnegie Mellon University Fall 2005 Lorrie Cranor 1 P3P Legal, Policy, and.
P3P A New Standard in Online Privacy Overview and Demos from Summer 2000.
Conditions and Terms of Use
Privacy Policy, Law and Technology Carnegie Mellon University Fall 2004 Lorrie Cranor 1 P3P 2 Week 6 - October 12,
Privacy Policy, Law and Technology Carnegie Mellon University Fall 2004 Lorrie Cranor 1 P3P I Week 6 - October.
Computers and Society Carnegie Mellon University Spring 2005 Lorrie Cranor and Dave Farber 1 Privacy Week 9 - March.
Web Page Design I Basic Computer Terms “How the Internet & the World Wide Web (www) Works”
Privacy, P3P and Internet Explorer 6 P3P Briefing – 11/16/01.
The Future of P3P Ari Schwartz Center for Democracy and Technology Lorrie Faith Cranor AT&T Labs-Research November 2002.
How P3P Works Lorrie Faith Cranor P3P Specification Working Group Chair AT&T Labs-Research 4 February 2002
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
1 WS-Privacy Paul Bui Ryan Dickey. 2 Agenda  WS-Privacy  Introduction to P3P  How P3P Works  P3P Details  A P3P Scenario  Conclusion  References.
User Interfaces for Privacy Design and Evaluation of the AT&T Privacy Bird P3P User Agent Lorrie Faith Cranor AT&T Labs-Research
P3P: User Empowerment Tools for Web Privacy Daniel J. Weitzner World Wide Web Consortium 23 April 2001 National Association of Attorneys General.
Use of a P3P User Agent by Early Adopters Lorrie Faith Cranor Manjula Arjula Praven Guduru AT&T Labs November 2002.
1 Personalization and Trust Personalization Mass Customization One-to-One Marketing Structure content & navigation to meet the needs of individual users.
12 Developing a Web Site Section 12.1 Discuss the functions of a Web site Compare and contrast style sheets Apply cascading style sheets (CSS) to a Web.
Privacy Policy, Law and Technology Carnegie Mellon University Fall 2005 Lorrie Cranor 1 Introduction to P3P Week.
1 World Wide Web Concepts (Chapter 18) 인공지능연구실. 2 목 차  Elements of the Web  Web Browsers  Keeping Tracking of your Favorite Web sites  Security and.
U.S. Department of Commerce Web Advisory Group Minding Your Own Business The Platform for Privacy Preferences Project.
P3P-The platform for Privacy Preference Project 資管研一 戴志洋 R 資管研一 余丹楓 R
C MU U sable P rivacy and S ecurity Laboratory 1 Privacy Policy, Law and Technology Introduction to P3P October 2, 2008.
Cookies By: Kendra Alvarez. Concepts of Cookies Cookies are pieces of information generated by a Web server and stored in the user's computer, ready for.
8 th Semester, Batch 2009 Department Of Computer Science SSUET.
Introduction Web analysis includes the study of users’ behavior on the web Traffic analysis – Usage analysis Behavior at particular website or across.
Protecting your search privacy A lesson plan created & presented by Maria Bernhey (MLS) Adjunct Information Literacy Instructor
CMPE 494 Service-Oriented Architectures and Web Services Platform for Privacy Preferences Project (P3P) İDRİS YILDIZ
11 SUPPORTING INTERNET EXPLORER IN WINDOWS XP Chapter 11.
Windows Vista Configuration MCTS : Internet Explorer 7.0.
Visualizing Privacy I March 7, 2006.
How P3P Works Lorrie Faith Cranor P3P Specification Working Group Chair AT&T Labs-Research 4 February
Configuring Internet-related services
Web Privacy Chapter 6 – pp 125 – /12/9 Y K Choi.
The Platform for Privacy Preferences Project
Presentation transcript:

The Platform for Privacy Preferences (P3P) Workshop on the Relationship between Privacy and Security Lorrie Faith Cranor P3P Specification Working Group Chair AT&T Labs-Research May 29,

Lorrie Faith Cranor 2 Security vs. privacy Data privacy – policy about data collection and use  What data will be collected, how it will be used, whether it will be shared, etc. Data security – how privacy policies are enforced  Security software, physical security, etc. Security and privacy go together  Great privacy policy, but break-ins due to bad security  data not protected  Great security, but privacy policy allows data to be sold to highest bidder  data not protected The Platform for Privacy Preferences

Lorrie Faith Cranor 3 Privacy policies Policies let consumers know about site’s privacy practices Consumers can then decide whether or not practices are acceptable, when to opt-in or opt-out, and who to do business with The presence or privacy policies increases consumer trust The Platform for Privacy Preferences

Lorrie Faith Cranor 4 Privacy policy problems BUT policies are often  difficult to understand  hard to find  take a long time to read  change without notice The Platform for Privacy Preferences

Lorrie Faith Cranor 5 Original Idea behind P3P A framework for automated privacy discussions  Web sites disclose their privacy practices in standard machine-readable formats  Web browsers automatically retrieve P3P privacy policies and compare them to users’ privacy preferences  Sites and browsers can then negotiate about privacy terms The Platform for Privacy Preferences

Lorrie Faith Cranor 6 P3P history Idea discussed at November 1995 FTC meeting Ad Hoc “Internet Privacy Working Group” convened to discuss the idea in Fall 1996 W3C began working on P3P in Summer 1997  Several working groups chartered with dozens of participants from industry, non-profits, academia, government  Numerous public working drafts issued, and feedback resulted in many changes  Early ideas about negotiation and agreement ultimately removed  Automatic data transfer added and then removed  Patent issue stalled progress, but ultimately became non-issue P3P issued as official W3C Recommendation on April 16, 2002  The Platform for Privacy Preferences

Lorrie Faith Cranor 7 P3P1.0 – A first step Offers an easy way for web sites to communicate about their privacy policies in a standard machine-readable format  Can be deployed using existing web servers This will enable the development of tools that:  Provide snapshots of sites’ policies  Compare policies with user preferences  Alert and advise the user The Platform for Privacy Preferences

Lorrie Faith Cranor 8 P3P is part of the solution P3P1.0 helps users understand privacy policies but is not a complete solution Seal programs and regulations  help ensure that sites comply with their policies Anonymity tools  reduce the amount of information revealed while browsing Encryption tools  secure data in transit and storage Laws and codes of practice  provide a base line level for acceptable policies The Platform for Privacy Preferences

Lorrie Faith Cranor 9 Regulatory and self-regulatory framework ServiceUser The Internet Secure channel P3P user agent Cookie cutter Anonymizing agent Privacy Tools The Platform for Privacy Preferences

Lorrie Faith Cranor 10 The basics P3P provides a standard XML format that web sites use to encode their privacy policies Sites also provide XML “policy reference files” to indicate which policy applies to which part of the site Sites can optionally provide a “compact policy” by configuring their servers to issue a special P3P header when cookies are set No special server software required User software to read P3P policies called a “P3P user agent” The Platform for Privacy Preferences

Lorrie Faith Cranor 11 A simple HTTP transaction Web Server GET /index.html HTTP/1.1 Host: Request web page HTTP/ OK Content-Type: text/html... Send web page The Platform for Privacy Preferences

Lorrie Faith Cranor 12 … with P3P 1.0 added Web Server GET /w3c/p3p.xml HTTP/1.1 Host: Request Policy Reference File Send Policy Reference File GET /index.html HTTP/1.1 Host: Request web page HTTP/ OK Content-Type: text/html... Send web page Request P3P PolicySend P3P Policy The Platform for Privacy Preferences

Lorrie Faith Cranor 13 Transparency P3P clients can check a privacy policy each time it changes P3P clients can check privacy policies on all objects in a web page, including ads and invisible images The Platform for Privacy Preferences

Lorrie Faith Cranor 14 P3P in IE6 Privacy icon on status bar indicates that a cookie has been blocked – pop-up appears the first time the privacy icon appears Focus is on P3P policies for cookies The Platform for Privacy Preferences

Lorrie Faith Cranor 15 Users can click on privacy icon for list of cookies; privacy summaries are available at sites that are P3P-enabled The Platform for Privacy Preferences

Lorrie Faith Cranor 16 The Platform for Privacy Preferences

Lorrie Faith Cranor 17 AT&T Privacy Bird Free download of beta from “Browser helper object” for IE 5.01/5.5/6.0 Reads P3P policies at all P3P-enabled sites automatically Puts bird icon at top of browser window that changes to indicate whether site matches user’s privacy preferences Clicking on bird icon gives more information Current version is information only – no cookie blocking The Platform for Privacy Preferences

Lorrie Faith Cranor 18 Chirping bird is privacy indicator The Platform for Privacy Preferences

Lorrie Faith Cranor 19 Click on the bird for more info The Platform for Privacy Preferences

Lorrie Faith Cranor 20 Privacy policy summary - mismatch The Platform for Privacy Preferences

Lorrie Faith Cranor 21 Users select warning conditions The Platform for Privacy Preferences

Lorrie Faith Cranor 22 Bird checks policies for embedded content The Platform for Privacy Preferences

Lorrie Faith Cranor 23 Why web sites adopt P3P Demonstrate corporate leadership on privacy issues  Show customers they respect their privacy  Demonstrate to regulators that industry is taking voluntary steps to address consumer privacy concerns Distinguish brand as privacy friendly Prevent IE6 from blocking their cookies Anticipation that consumers will soon come to expect P3P on all web sites Individuals who run sites value personal privacy The Platform for Privacy Preferences

Lorrie Faith Cranor 24 P3P early adopters News and information sites – CNET, About.com, BusinessWeek Search engines – Yahoo, Lycos Ad networks – DoubleClick, Avenue A Telecom companies – AT&T Financial institutions – Fidelity Computer hardware and software vendors – IBM, Dell, Microsoft, McAfee Retail stores – Fortunoff, Ritz Camera Government agencies – FTC, Dept. of Commerce, Ontario Information and Privacy Commissioner Non-profits - CDT The Platform for Privacy Preferences

Lorrie Faith Cranor 25 P3P deployment overview 1.Create a privacy policy 2.Analyze the use of cookies and third-party content on your site 3.Determine whether you want to have one P3P policy for your entire site or different P3P policies for different parts of your site 4.Create a P3P policy (or policies) for your site 5.Create a policy reference file for your site 6.Configure your server for P3P 7.Test your site to make sure it is properly P3P enabled The Platform for Privacy Preferences

Lorrie Faith Cranor 26 What’s in a P3P policy? Name and contact information for site The kind of access provided Mechanisms for resolving privacy disputes The kinds of data collected How collected data is used, and whether individuals can opt-in or opt-out of any of these uses Whether/when data may be shared and whether there is opt-in or opt-out Data retention policy The Platform for Privacy Preferences

Lorrie Faith Cranor 27 Example privacy policy We do not currently collect any information from visitors to this site except the information contained in standard web server logs (your IP address, referer, information about your web browser, information about your HTTP requests, etc.). The information in these logs will be used only by us and the server administrators for website and system administration, and for improving this site. It will not be disclosed unless required by law. We may retain these log files indefinitely. Please direct questions about this privacy policy to The Platform for Privacy Preferences

Lorrie Faith Cranor 28 P3P/XML encoding The Platform for Privacy Preferences <POLICY discuri=" name="policy"> <DATA <DATA ref="#business.contact-info.online.uri"> Web Privacy With P3P We keep standard web server logs. P3P version Location of human-readable privacy policy P3P policy name Site’s name and contact info Access disclosure Statement Human-readable explanation How data may be used Data recipients Data retention policy Types of data collected

Lorrie Faith Cranor 29 Types of P3P user agent tools On-demand or continuous  Some tools only check for P3P policies when the user requests, others check automatically at every site Generic or customized  Some tools simply describe a site’s policy in some user friendly format – others are customizable and can compare the policy with a user’s preferences Information-only or automatic action  Some tools simply inform users about site policies, while others may actively block cookies, referrers, etc. or take other actions at sites that don’t match user’s preferences Built-in, add-on, or service  Some tools may be built into web browsers or other software, others are designed as plug-ins or other add-ons, and others may be provided as part of an ISP or other service The Platform for Privacy Preferences

Lorrie Faith Cranor 30 User privacy preferences P3P 1.0 agents may (optionally) take action based on user preferences  Users should not have to trust privacy defaults set by software vendors  User agents that can read APPEL (A P3P Preference Exchange Language) files can offer users a number of canned choices developed by trusted organizations  Preference editors allow users to adapt existing preferences to suit own tastes, or create new preferences from scratch  For more info on APPEL see The Platform for Privacy Preferences

Lorrie Faith Cranor 31 Other types of P3P tools P3P validators  Check a site’s P3P policy for valid syntax Policy generators  Generate P3P policies and policy reference files for web sites Web site management tools  Assist sites in deploying P3P across the site, making sure forms are consistent with P3P policy, etc. Search and comparison tools  Compare privacy policies across multiple web sites – perhaps built into search engines The Platform for Privacy Preferences

Lorrie Faith Cranor 32 Current tools P3P user agents  IE6  AT&T Privacy Bird  JRC P3P Proxy P3P editors, generators, and validators  IBM P3P Editor  W3C P3P Validator  Privacy Council Compact Policy Generator  … and many more … The Platform for Privacy Preferences

Lorrie Faith Cranor 33 Many possibilities for P3P tools P3P user agent integrated into anonymity tool P3P user agent integrated into electronic wallet or form filler P3P user agent that can automatically generate standard privacy policy “food label” reports P3P user agent that can validate seals Search engines that weight results according to P3P policy Comparison shopping services that include privacy policy as one factor in comparison Tools that provide feedback to web sites on whether their policies match user preferences  Aggregate feedback  Feedback in header extension Server-side tools to tag collected data with P3P policy information Tools to automatically generate compliance reports based on P3P policy The Platform for Privacy Preferences

Lorrie Faith Cranor 34 Impacts Somewhat early to evaluate P3P Some companies that P3P-enable think about privacy in new ways and change their practices  Systematic assessment of privacy practices  Concrete disclosures – less wiggle room  Disclosures about areas previously not discussed in privacy policy Hopefully we will see greater transparency, more informed consumers, and ultimately better privacy policies The Platform for Privacy Preferences

Lorrie Faith Cranor 35 Resources For further information on P3P see:    Coming later in 2002! The Platform for Privacy Preferences