Re: Flash Cookies - LSO

Dear Ranieri Pires, 

This is not possible in P3P 1.0. The P3P Working Group had identified your 
scenario and had specified this in the P3P 1.1 Specification. OUR-HOST Extension

The OUR-HOST element allows sites to declare hosts that are owned by the 
entity in the associated policy or that are acting as agents of that entity. 
User agents may use this extension to distinguish between such a host and 
actual third-party hosts.

Unfortunately, browsers never supported the P3P 1.1 Specification, so it 
remained a Working Group Note. 

As a consequence, you can't declare a same origin anywhere so far. Browsers 
will assume that and are two different things and 
they will apply their security policy to it accordingly. 


Rigo Wenning
W3C Legal counsel

On Wednesday 29 June 2011 17:11:01 Ranieri Pires wrote:
> How to save a flash cookie Local Shared Objects (LSO) in 2 domains?
> Example: My SWF is in, but I need the cookie (LSO) is
> recorded and Is there a P3P policy that
> allows this?
> Ranieri

Received on Monday, 4 July 2011 07:18:43 UTC