Advertisement
Promo

Security threats Toolkit

Google's cookie cut may not be enough for EU

Tom Espiner ZDNet.co.uk

Published: 18 Jul 2007 14:52 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A member of an influential EU privacy group has said it will meet to discuss whether Google has gone far enough in reducing the amount of time the Google cookie stays on computers.

Alexander Dix, Berlin's security and privacy representative, told ZDNet.co.uk that the Article 29 Data Protection Working Party, a group of European privacy experts, welcomed Google reducing its cookie time to two years, but said the group would discuss whether Google has gone far enough.

"It's certainly an improvement, but we will have to discuss whether this is enough," said Dix. "It's a good thing that Google has addressed the question of a cookie time limit."

Cookies are small files stored on a computer so that it can be recognised when it revisits websites, enabling the site to remember the user's preferences for things like e-commerce, and sites that require log-in.

Dix said that Google renewing the cookie every time a person used either Google or a site using Google applications, such as Google Analytics, was not a major privacy concern, as users could control cookies by configuring their browser.

"People can influence cookies by configuring their browser — they can just accept one session. Users have more choice than with their log profiles."

VIDEO

Dialogue Box
Dialogue Box 6.8: Top tech trumps

What are likely to be the most important tech stories over the next few months? Rupert and Charles discuss the contenders

View full video+

Even so, the privacy expert said that cookies were still a concern for the data watchdog, especially cookies users have accepted or rejected without knowing they have done so. However, Dix said that a bigger concern was the anonymisation of server log data, and that the only major search company to disclose its server log data-retention policy had been Google, which anonymises server logs after 18 to 24 months. Major search players such as Microsoft and Yahoo have yet to disclose their server log data-retention policy, Dix said.

"Certainly Microsoft and Yahoo have not discussed server log profile retention so far. Google has, and we would welcome it if Yahoo and Microsoft did the same," said Dix.

Server log data shows how a computer has been used to search, and can be mined to provide information. Dix said that the major search players had not disclosed how they intended to use that information.

"Our main concern about all search-engine providers is that they are transparent about what they intend to do with the information — a concern Microsoft hasn't addressed so far. Maybe they have a privacy-friendly policy — I don't know. They should certainly tell users if they have one," said Dix.

A senior spokesperson for Yahoo Europe said the company will make an announcement on data-retention policies "in a matter of weeks".

"Our policies reflect the fact that our users' trust is one of Yahoo's most valuable assets. Maintaining that trust and protecting our users' privacy is paramount to us. Our data-retention practices vary according to the diverse nature of our services. We don't break out that information currently as we view it to be commercially sensitive," said the spokesperson.

"We only keep data as long as is required by law and is useful for our business purposes. In some cases, that is as short [a period] as a few weeks. This data is used to benefit our users in many ways. That includes protection against fraud, personalised content, product innovations based on what we learn about how users interact with our site, and best-in-class free services paid for by targeted advertising," the spokesperson added.

Microsoft declined to comment.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters