Thirdparty: Difference between revisions

Line 25: Line 25:
To frame the following proposal and discussion, these are some simple examples of behavior on the web:
To frame the following proposal and discussion, these are some simple examples of behavior on the web:


:1. User visits multiple shopping sites, which have resources from ad sites embedded in iframes, images, or requests made directly from script. They are unaware the advertiser can track their movements across those sites.
#User visits multiple shopping sites, which have resources from ad sites embedded in iframes, images, or requests made directly from script. They are unaware the advertiser can track their movements across those sites.
 
#User visits a site that embeds the Facebook "Like" button, but does not want their Facebook login cookies automatically sent.
:2. User visits a site that embeds the Facebook "Like" button, but does not want their Facebook login cookies automatically sent.
#User visits their credit union, which uses third party resources for banking functions, and wants those functions to work.
 
#User visits a site that uses OpenID, Facebook Connect, or other federated login service, and wants to be able to log in to those services and use them with the site. ''Todo: OpenID may actually not require cookies on the first party site at all -- information is passed in a backchannel. Need to confirm. What about other authentication-related services?''
:3. User visits their credit union, which uses third party resources for banking functions, and wants those functions to work.
 
:4. User visits a site that uses OpenID, Facebook Connect, or other federated login service, and wants to be able to log in to those services and use them with the site. ''Todo: OpenID may actually not require cookies on the first party site at all -- information is passed in a backchannel. Need to confirm. What about other authentication-related services?''


= Proposal Overview =
= Proposal Overview =
148

edits