Is Google ignoring Internet privacy? [Update]
COMMENTARY Google (GOOG) got caught last week bypassing privacy settings on Apple's (AAPL) Safari browser. Now it appears the search giant also did an end run around Internet Explorer, according to Microsoft (MSFT).
Specifically, the software maker says Google circumvents IE's so-called P3P Privacy Protection feature, a Web standard that lets websites tell a browser what they intend to do with information they collect about a user. Google "utilizes a nuance in the P3P specification that has the effect of bypassing user preferences about cookies."
Smartphone privacy noose tightens on GoogleGoogle wants to track calls related to online ads
Facebook's New Privacy Bust: Users Log In but They Can't Log Out
Technology Has Become the Marketing Snoop's Scapegoat
According to the Wall Street Journal, Google and other advertising network owners used special code to bypass Safari's privacy settings, letting it track Web users. Google, which appears to have immediately stopped the practice, says this resulted from an effort to make its "+1" buttons -- the equivalent of Facebook's "like" buttons -- work properly. Google's own statement about the Safari issue says that the company needed to work around that browser's privacy defaults "to provide features that signed-in Google users had enabled":
Unlike other major browsers, Apple's Safari browser blocks third-party cookies by default. However, Safari enables many web features for its users that rely on third parties and third-party cookies, such as "like" buttons. Last year, we began using this functionality to enable features for signed-in Google users on Safari who had opted to see personalized ads and other content-such as the ability to "+1" things that interest them.
Google says that Safari -- unlike other major browsers -- blocked cookies by default and that the ability to set other cookies (namely, ad-related ones) was something the company "didn't anticipate." That's a curious explanation, given Google's vaunted technical expertise, particularly in working with browsers and websites.
Whose Web is it, anyway?
Microsoft Internet Explorer added support for P3P back with IE6 (the latest version is IE9). In other words, P3P has been around for years. If a site doesn't have a P3P privacy policy, IE dumps cookies after a browsing session. As with Safari, that is the default setting. The difference is Microsoft didn't invent P3P; rather, it's a standard part of Web technology.
Microsoft and Google have regularly traded shots over privacy, each trying to paint the other as serial violators. Trouble is, skirting Web standards goes straight to the heart of how the Internet operates. Without some basic level of cooperation between competing entities, consumers around the world don't know what to expect, arousing regulatory concerns. And the government is unlikely to be impressed by Google's claims that advertising cookies don't collect "personal information."
That is especially true when Google's new privacy policy indicates that along with cookies the company uses unique application numbers, local storage on consumer machines, and log and device information across its services (which would include search) to obtain information. As a recent New York Times piece on the data-collection techniques used by Target and other companies shows, you don't need a lot of personal information to learn what consumers are doing and even who they are.
[Update: CBS MoneyWatch contacted Mozilla, which makes the Firefox browser, to see if it had noticed Google bypassing privacy controls. Here's the statement attributed to Alex Fowler, global privacy and public policy lead: "Our testing did not reveal any instances of Google bypassing user privacy settings.]