7 ms·
Any submission of data requires the transmission of an IP address, which is personal data and necessitates appropriate protection. I very much hope that the De
by claudius 9y ago
Any submission of data requires the transmission of an IP address, which is personal data and necessitates appropriate protection.
I very much hope that the Debian maintainers (and hopefully also the guys preparing Fennec in F-Droid) will disable such data collection mechanisms, either completely or hidden behind an explicit opt-in instead of the opt-out suggested in the e-mail.
- kuschku 9y ago> Any submission of data requires the transmission of an IP address, which is personal data and necessitates appropriate protection. And requires an opt-in under EU law, which makes this entire thing even more ridiculous.
- codefined 9y agoThen don't send the correct source IP address, with simple statistics gathering like this I hardly expect they require a response. It would mean there would be no personal data whatsoever.
- kuschku 9y agoHow would you do that, though? The browser has to open a socket to something to do this, after all. And that already is a violation.
- Ajedi32 9y agoYou'd just send a UDP packet with a spoofed source address and forget about it. There's no need to open any sort of 2-way connection for data that's only being transmitted in one direction (from browser to metrics server).
- moosingin3space 9y agoYou could transmit the telemetry through Tor.
- sp332 9y agoTor is blocked in some places and viewed as very suspicious in others. If you're already in a place where you're trying not to draw attention to yourself, using Tor might not a good option.
- Ajedi32 9y agoWouldn't spoofing IP addresses risk the data packets being filtered out by ISPs or other upstream network providers? IMO if keeping IP addresses hidden is a concern, it'd be better to use something like TOR.
- throwaway2048 9y agoThis isnt how tcp/ip works
- wongarsu 9y agoWith udp/ip it would work, if none of the routers on the way to the destination filters spoofed IPs.
- pfg 9y agoMost ISPs filter spoofed IP addresses nowadays[1]. Even if your ISP doesn't prevent it, NAT might. You wouldn't get a whole lot of responses this way, and there'd be a strong bias because of regional differences w.r.t. filtering. [1]: https://spoofer.caida.org/summary.php https://spoofer.caida.org/summary.php
- yuhong 9y agoDoes an IP address actually require an opt-in? And if it does, does it only apply if it is being stored?
- claudius 9y agoYes[1], no[2]. An IP address is "personal relationships" data and collecting, processing or using such data is prohibited unless allowed by law or the concerned person gives consent. [1]: https://en.wikipedia.org/wiki/Bundesdatenschutzgesetz#Types_of_personal_data https://en.wikipedia.org/wiki/Bundesdatenschutzgesetz#Types_... [2]: https://en.wikipedia.org/wiki/Bundesdatenschutzgesetz#Overview_of_the_first_principles https://en.wikipedia.org/wiki/Bundesdatenschutzgesetz#Overvi...
- yorwba 9y agoThe way I interpret this, if you don't collect, process or use the IP address beyond it being incidentally involved in the transmission of anonymized data, it shouldn't require explicit consent. Otherwise literally everything that connects to the internet in some way would have to treated in that way, and that's not how the law is currently enforced.
- acdha 9y ago> Any submission of data requires the transmission of an IP address, which is personal data and necessitates appropriate protection. Do you have a citation for that broad assertion? My understanding is that this is highly variable across legal jurisdictions and even in Europe, which typically leads the way in privacy, it's not that simple. See e.g. https://www.whitecase.com/publications/alert/court-confirms-ip-addresses-are-personal-data-some-cases https://www.whitecase.com/publications/alert/court-confirms-... discussing an EU Court of Justice ruling that had two requirements: the ISP can link that IP address to an individual AND the website operator can get that information from the ISP.
- sp332 9y agoIt might not be legally protected, but that doesn't change how sensitive it is.
- ThePhysicist 9y agoWithin the new European GDPR framework, IP addresses are to be considered as personally identifiable information, so the concern is warranted. What's decisive when characterizing an information as identifiable or not is not the fact of being actually able to perform the de-anonymization of the information (e.g. via the ISP in case of an IP address), but the mere possibility of it. Legally though Firefox would be allowed to collect this anonymous data from the user by having him/her send the data e.g. to an API endpoint they provide via IP-based communication, they would just not be allowed to associate the data with the IP address of the user submitting the data. In the end, it comes down to trusting the party that collects the data, at least if they don't perform anonymization of the IP address via other means, e.g. by passing the information through a third party proxy server. BTW, GDPR does forbid to turn on such data collection by default (privacy by default), so they would be required to get the explicit opt-in from the user for that.
- joegosse 9y ago>Within the new European GDPR framework, IP addresses are to be considered as personally identifiable information,... My understanding is that many of these details are yet to be settled with GDPR. The case referenced above was not interpreted under GDPR, which has yet to take effect. The definitions of personally identifiable data data rather vague, and precedent has not been set. A quick search showed conflicting opinions, but one perspective to consider is quoted below: > In addition, businesses should note that Recital 26 to the recently adopted EU General Data Protection Regulation ("GDPR") states that the test for whether a person is "identifiable" (considered in detail above) depends upon "all the means reasonably likely to be used" to identify that person. The CJEU in Breyer did not directly consider the issue of likelihood of identification. If the BRD was not reasonably likely attempt to identify Mr Breyer from his IP address, this could potentially give rise to a different analysis under the GDPR. Consequently, it may be necessary for the CJEU to revisit this issue after enforcement of the GDPR begins on 25 May 2018. This is a few years old, so if you know of some new decision or regulation that clarifies it would be great to know! https://www.whitecase.com/publications/alert/court-confirms-ip-addresses-are-personal-data-some-cases https://www.whitecase.com/publications/alert/court-confirms-...
- Ajedi32 9y ago> Any submission of data requires the transmission of an IP address Not true. Tor has demonstrated that it's entirely possible to transmit data over the internet without revealing your IP address to the party you're transmitting to.
- quickben 9y agoAt a heavy latency cost, and under dubious asumption that regular people control all exit nodes.
- Ajedi32 9y agoActually no, it doesn't matter who controls the exit nodes as long as your only concern is keeping your IP private. (Exit nodes can indeed do bad things to unencrypted traffic, but that's irrelevant for this use case.) Latency also doesn't matter here; this telemetry could take 5 minutes to reach its destination and it wouldn't matter, so long as the data is eventually received.
- quickben 9y agoHmm, I've never thought of that. I like your idea.