[478] in Privacy_Forum

home help back first fref pref prev next nref lref last post

[ PRIVACY Forum ] Web Cookies: Yummy, Opaque, Ironic, or Bizarre?

daemon@ATHENA.MIT.EDU (privacy@vortex.com)
Mon May 11 21:24:22 2009

X-Barracuda-Envelope-From: privacy-bounces+privacy-forum=mit.edu@vortex.com
Date: Mon, 11 May 2009 18:00:29 -0700
To: privacy-list@vortex.com
Message-ID: <20090512010029.GI17716@vortex.com>
MIME-Version: 1.0
Content-Disposition: inline
From: privacy@vortex.com
Reply-To: PRIVACY Forum Digest mailing list <privacy@vortex.com>
Content-Type: text/plain; charset="iso-8859-1"
Errors-To: privacy-bounces+privacy-forum=mit.edu@vortex.com
Content-Transfer-Encoding: 8bit




                Web Cookies: Yummy, Opaque, Ironic, or Bizarre?

                 http://lauren.vortex.com/archive/000564.html


Greetings.  Pretty much since the earliest days of the Web, and the
initial use of browser "cookies" for session state control and other
purposes, cookies themselves have been controversial.

Cookies (the term in a compsci context goes back to the days of
character attributes in serial CRT computer displays, and before 
that -- yes -- to Cookie Monster on "Sesame Street"), are simply
tokens that contain arbitrary data and are planted and/or retrieved
from users' computers by Web sites.

There is a great deal of unjustified paranoia surrounding the use of
cookies, but legitimate concerns as well -- the latter mostly related
to the ability of cookies to track users without their knowledge
across multiple sites.

As Web browser technology has advanced, providing users with greater
controls over how cookies are handled has been a significant aspect of
Web evolution.  Firefox has extensive per-site controls for this
purpose.  On the other hand, a gripe I have with Google's otherwise
excellent Chrome browser is (the last time I checked) the lack of
per-site cookie controls.

There are some situations where cookies are invaluable -- especially
when dealing with complex sessions that pass through various
operational states, sessions that require login or various other forms
of authentication, and so on.  I use cookies myself for such
applications, though I restrict usage to so-called "first-party"
cookies -- cookies that all are presented or retrieved to/from the
same site with which the user is currently interacting.

Occasionally you run into situations where cookies are arguably being
used inappropriately, but without any intended nefarious purposes.

Yesterday I noted a particularly ironic case -- the site
"TransparentDemocracy" -- which is focused on ballot and election
transparency, a laudable effort ( http://transparentdemocracy.org ).

The irony is that currently it's impossible to access the site in any
manner if you don't accept their cookies.  I mean totally impossible.
You can't reach the home page.  You can't access contact info.  You
can't read their privacy policy (about cookies or anything else).  All
you get is a notice that cookies are required, and then the door slams
shut.

I usually consider the fairly rare situation of sites that completely
block access when cookies aren't accepted as being in the "red zone"
of cookie misbehavior, and my concerns about this were forwarded to
the site's administrators.

A response was immediately forthcoming, informing me that, indeed, the
cookie situation was the result of an attempt to expeditiously launch
the site, and that they would now move to change their implementation
in a manner that would likely address my concerns.

There's no denying that I was somewhat amused to see a site with the
world "transparency" in its name blocking access in that manner!
Their quick response to the issue is to be congratulated.

My view is that simple viewing of sites and basic, non-logged in
interactions should not usually require that cookies be accepted --
whenever possible.

Google is a good example of how to handle such a dynamic gracefully.
Google does use a lot of cookies for various of their services.  But
you can still use Google Search, view YouTube videos, and use various
other Google services even if you reject all associated cookies.
True, you can't use services that require login, nor can you access
most personalized services if you won't accept the cookies.

But the point is that if Google chose, they could require the
acceptance of cookies to access any of their services in any manner,
and they have wisely chosen not to do so.

Browser cookies are like seasoning in foods.  Sometimes they are
absolutely essential to an edible meal, but they can also be used
gratuitously, overbearingly, and even antagonistically.

Like with so much else in life, the keys with browser cookies are
appropriate choices and moderation.

And -- by the way -- the secret with Oreo cookies, even after all
these years, is still to twist them apart and scrape the creme filling
off with your teeth -- again with moderation, of course.

Cookie Monster knew what he was talking about.

--Lauren--
Lauren Weinstein
lauren@vortex.com
Tel: +1 (818) 225-2800
http://www.pfir.org/lauren
Co-Founder, PFIR
   - People For Internet Responsibility - http://www.pfir.org
Co-Founder, NNSquad
   - Network Neutrality Squad - http://www.nnsquad.org
Founder, GCTIP - Global Coalition 
   for Transparent Internet Performance - http://www.gctip.org
Founder, PRIVACY Forum - http://www.vortex.com
Member, ACM Committee on Computers and Public Policy
Lauren's Blog: http://lauren.vortex.com
Twitter: https://twitter.com/laurenweinstein
_______________________________________________
privacy mailing list
http://lists.vortex.com/mailman/listinfo/privacy


home help back first fref pref prev next nref lref last post