Privacy settings in Internet Explorer 6
Cookies can have great utility but raise privacy and security concerns. One new feature of Internet Explorer 6 is to better able to define what types of cookies your machine will accept, and from which sites. You should not reduce the settings to a lower warning level as you will reduce security on your machine. In most cases you can avoid the prompts by following the instructions below.
If Internet Explorer blocks cookies from a particular site you get an icon of an eye and a no entry sign somewhere along your Internet Explorer status bar.
.
The first time this happens you will get an explanation screen:
![]()
When you visit an Internet site you may get a message that cookies are required. Instead of changing your overall settings add the particular site to a list of accepted sites.
To make the browser accept the cookie in the future:


These steps add the site to the Managed Web sites list with a setting of Always Allow. Cookies will no longer be blocked from the selected domain.
Cookies and the utility vs privacy balance.
What is the new Privacy tab about in Internet Explorer 6?
What does this change mean to me?
What is a P3P compact policy?
How does the P3P compact policy affect how Internet Explorer treats cookies?
What is the difference between a first party cookie and a third party cookie?
Why does the cookie type matter?
When will the browser treat a first party cookie as if it were a third party cookie?
How do I add a site manually?
Are my cookies settings from Internet Explorer 5 still OK?
I thought I used Advanced Privacy settings to block a site, but the site is still reading cookies on my machine, what happened?
I thought I used Advanced Privacy settings to accept a site, but I'm still getting the privacy icon when I access it, what happened?
The Advanced Privacy settings don't seem to work correctly. What could be wrong?
Cookies and the utility vs privacy balance.
Cookies are small files delivered by a website and installed on a user's computer. Cookies can be beneficial, supporting complex and secure transactions. They can also compromise user security and privacy. Because of the potential for harm users should make some explicit decisions about what cookies they will accept and which they will block. As a practical matter, however, users usually choose convenience over making an explicit decision.
In traditional transactions a user decides what to share depending upon the degree of trust the user has in the requestor and exactly what information the requestor wants. In the browser environment it is not usually a simple matter for the user to determine who is asking and what they are asking for. Prior versions of Internet Explorer did not provide much user control over what type of cookies would be automatically accepted and which would be automatically rejected. Because of the nuisance of constantly repsonding to pop-ups with inadequate information users often forgo some level of privacy and security in favor of convenience.
The privacy vs. utility balance can be improved if the user can more easily learn (a) who wishes to gather information (b) what information they want (c) how they intend to use that information and (d) how long they intend to retain the information.
What is the new Privacy tab about in Internet Explorer 6?
The Privacy tab in Internet Options for Internet Explorer 6 allows more control over automatically accepting or blocking cookies according to a user's privacy settings. The privacy tab in Internet Options is where these controls are set and modified. The default setting is "medium" which blocks 3rd party cookies without a privacy policy and blocks both 3rd and 1st party cookies that use "personally identifiable information without implicit consent."
What does this mean to me?
You may find that some websites do not work as intended either because of the web site structure or lack of P3P compliance. It is better policy to add that particular site to your exceptions than to change the general settings.
It may result in an increased number of prompts and alerts, at least initially, depending upon the type of web sites you visit. These will become less frequent as you add commonly visited websites to your list for special handling. They will also become less frequent as sites catch up and make their privacy policies available in P3P format.
What is a P3P compact policy?
The World Wide Web Consortium (W3C) established the Platform for Privacy Preference Project (P3P) to enhance user control over release of private or personal information. Under this scheme users do not have to directly read and interpret each organization's privacy policy. Instead organizations set out their website privacy polices in a standard format. A P3P compact policy is the machine-readable summary of the website's full P3P policy. The P3P compact policy contains details on how the site collects information, what information the site collect, and what the site does with the collected data. The standard format allows the browser to compare the policy to the users selected privacy settings.
The policy is placed in the HTTP header and can be applied to a single page, multiple pages, individual cookies or the entire site. Qualified browsers automatically retrieve and interpret these policies. The browser can then flag discrepencies between a site's practices and the user preferences.
How does the compact policy affect how Internet Explorer treats cookies?
Interent Explorer 6 can read P3P compact policies. Whether the browser allows or blocks cookies from a particular site depends upon several factors (1) whether a P3P compact policy exists, (2) the comparison between the policy and the user's privacy settings, and (3) whether the cookie is first party or third party.
What is the difference between a first party cookie and a third party cookie?
A cookie is first party if it is from the same domain as the primary page (what is showing in the address bar). A cookie is third party if it is from a different domain as the primary page. For example, if a page with the address of http://www.3P3.com tries to set a cookie that originates from http://w3C.com that cookie would be 3rd party.
Why does the cookie type matter?
The first party cookies are generally accepted while third party cookies are more often blocked. While third party cookies can be completely legitimate they are also most often used by pop-up banners and advertisements. Because it is less obvious who is responsible for the third party cookie, they more often violate privacy.
When will the browser treat a first party cookie as if it were a third party cookie?
The different treatment of first party vs. third party cookies becomes important when a site uses frames. The frameset is the structure that creates the frames. Its address will be the basis for identifying the origin of the cookie. It will be the source that is examined to determine the existence of a 3P3 compact policy. If a page from a different domain appears within those frames it will be treated as third party.
When you attempt to use services on a secondary Web site that you access through a frameset (or portal), Internet Explorer might block cookies because the secondary Web site is in the third-party context. The Medium privacy level blocks third-party cookies that do not have a compact policy or third-party cookies that have a compact policy specifying that personally identifiable information is used without your implicit consent. To work around this add the site to the list of allowed sites.
Open Internet Explorer.
You will need the correct direct URL for the site - not through a frame or portal.
If you don't know the direct address try this:
Put your cursor on the link leading to the target page
Right click the link.
Select Properties.
To copy the link information from the address field that appears roughly in the middle of the properties box.
Right-click the address
Choose Select all
Right-click again
Choose Copy
Or try this:
With the target page showing in the frame, click once on the target page.
Right click the target page.
Select Properties.
Copy the link information from the address field that appears roughly in the middle of the properties box.
Select T ools from the menu bar and select Internet Options... from the drop down menu.
Click the Privacy tab.
Select Edit.
In the Address of Web Site box enter the URL (address) of the web site
Click Allow.
These steps add the site to the Managed Web sites list with a setting of Always Allow.
Are my cookies settings from Internet Explorer 5 still OK?
Any cookie settings you made in Internet Explorer 5 or earlier are no longer valid. In earlier versions of Internent Explorer, security levels for cookie settings were configured on a per-zone basis on the Security tab in the Internet Options dialog box. These settings are removed in Internet Explorer 6.
I thought I used Advanced Privacy settings to block a site, but the site is still reading cookies on my machine, what happened?
Any cookies that are currently stored on your computer can still be read by the Web site that created them (without a prompt). This behavior occurs even if you have selected to block or prompt for cookies by using either the Block or Prompt options for either first-party or third-party cookies on the Advanced Privacy Settings dialog box.
To work around this delete any existing cookies. Subsequent visits to the website will either allow or block cookies according to your current settings.
To delete any existing cookies that are stored on your computer
- In Internet Explorer, on the Tools menu, click Internet Options.
- On the General tab, under Temporary Internet files, click Delete Cookies.
I thought I used Advanced Privacy settings to accept a site, but I'm still getting the privacy icon when I access it, what happened?
By design, the Privacy icon appears in the status bar each time Internet Explorer restricts a cookie based on your privacy settings or when Internet Explorer retrieves a cached file that has a history of privacy violations from the Temporary Internet Files folder. The Privacy icon might still appear if you change your privacy settings during the current browser session so that the cookie is no longer restricted.
To work around this behavior, press F5 to refresh the Web page, or delete the contents of your Temporary Internet Files folder.
To delete the contents of your Temporary Internet Files folder
If cookies are being accepted from a site you meant to block, or if they are being blocked from a site you meant to allow, check the URL and make sure it is spelled correctly.
Created by the PeopleSoft Knowledge Management Team.
Copyright © 2003
All rights reserved.
Created: db 07/07/2003