to block all third party cookies. If you have not changed those
settings, this option essentially accomplishes the same thing
as setting the opt-out cookie.”7
In February 2012, Stanford graduate student Jonathan
Mayer published an online report revealing that Google and
the other defendants had discovered, and were surreptitiously
exploiting, loopholes in both the Safari cookie blocker and the
Internet Explorer cookie blocker.8 Safari’s cookie blocker
turns out to have had a few exceptions, one of which was that
it permitted third-party cookies if the browser submitted a
certain form to the third-party. Because advertisement
delivery does not, in the ordinary course, involve such forms,
the exception ought not have provided a pathway to installing
advertiser tracking cookies. But according to Mayer’s report,
Google used code to command users’ web browsers to
automatically submit a hidden form to Google when users
visited websites embedded with Google advertisements. This
covert form triggered the exception to the cookie blocker, and,
used widely, enabled the broad placement of cookies on Safari
browsers notwithstanding that the blocker—as Google
publicly acknowledged—was designed to prevent just that.
The other defendants, meanwhile, accomplished similar
circumventions. As a result, the defendants could—and did—
place third-party cookies on browsers with activated blockers.
7
Compl. ¶ 79.
8
Compl. ¶ 75; Jonathan Mayer, Web Policy Blog, Safari
Trackers (Feb. 17, 2012),
http://webpolicy.org/2012/02/17/safari-trackers/.
9