21 ms·
EU government websites have undisclosed adtech trackers from Google and others
- clarkmoody 8y ago"Do as we say, not as we do."
- krastanov 8y agoOn the contrary, I expect them to apply the law to themselves in the same manner they would apply it to, say, an important NGO whose IT staff have non-maliciously forgotten to update their stack. It is pretty common for large organizations, whether gov, NGOs, or corporate, to have issues where the left hand does not know what the right does. It is only a problem if these screw-ups are mission critical or if they stay unfixed for long. Mistakes happen, we should be judged by how we prevent the bad ones and how we act after they happen.
- briandear 8y agoGDPR doesn’t apply to member states. See chapter 1, Article 2, paragraph 2, section b.
- krastanov 8y ago1.2.2.b indeed provides an exception for member states but explicitly only for the purpose of "Chapter 2 of Title V of the TEU". (this is a ridiculous level of indirection...) Do you have an understanding of "Chapter 2 of Title V of the TEU"? My reading of it is "the members are responsible for the security of the union, yada yada..." so it sounds like the typical exception that governments have, but I am am not quite certain of my interpretation. Jeez, the EU institutions are really good at being inscrutable :(
- jdietrich 8y agoChapter 2 of Title V of the TEU broadly describes the functioning of the European Union and the obligations of Member States with regards to the security and foreign policy of the union. The exemption in 1.2.2.b would rarely if ever apply to domestic matters. https://en.wikisource.org/wiki/Consolidated_version_of_the_Treaty_on_European_Union/Title_V:_General_Provisions_on_the_Union%27s_External_Action_Service_and_Specific_Provisions_on_the_Common_Foreign_and_Security_Policy https://en.wikisource.org/wiki/Consolidated_version_of_the_T...
- ozaark 8y agoIn the US a common version of this is for ADA laws on government websites. Many(most?) .gov domains aren't compliant. [1] Interestingly, successful lawsuits for private company websites breaching ADA have increased over the past couple of years. [1] Non-compliant: senate.gov , supremecourt.gov , congress.gov , justice.gov , etc
- tracker1 8y agoWorking on a compliant application currently... the irony, is you can't use the main function of the app without being at least relatively sighted (the app displays scanned documents for confirmation)... but heaven forbid if my color contrast is 2% too little.
- pakitan 8y agoWe're sued right now by a troll law firm for breach of ADA. I'm not even sure there is such thing as "compliant". ADA basically says "well, we're not accessibility experts, just follow WCAG 2.0 and you'll probably be fine". The problem is that while WCAG 2.0 is, IMO, a well designed set of guidelines, it's not meant to be used to assess a site as "compliant" or "non-compliant". This situation is beyond ridiculous.
- tareqak 8y agoI doubt most government legislators would be aware of this sort of thing (the components, libraries, and platforms that make up a given government entity's web presence).
- angott 8y agoThat's the major problem. A person writing regulation to deal with this problem would need to know what a CDN is, why they are required in modern web development, the pros and cons of self-hosted vs. cloud-based analytics solutions, etc. I really wouldn't want to be the person tasked with explaining these issues to the average politician (although some rare exceptions obviously apply).
- marcrosoft 8y agoIf you step back further, this is just one example of many where regulators don't understand the consequence of their laws. You can extend this to any policy like gun control/rights, abortion, etc. Some facts: * We will never know the full ramifications regulation has on a market. It is impossible to calculate objectively the _full_ effect. * Regulation _always_ has unintended side effects. (Alcohol prohibition and violence, etc) * A regulator that doesn't understand the entire problem will likely increase the unintended side effects.
- tareqak 8y agoI totally agree with you that it is not possible for a regulator to predict the future with respect to how their decisions impact a market. However, I think that is only an argument against hasty regulation, as opposed to regulation in general.
- marcrosoft 8y agoI agree that hasty regulation would probably have more unintended side effects; however the other points still stand. Prohibition, for example, is always accompanied by a black market. There is _always_ an unintended consequence of any regulation. GDPR will likely add a tax on individuals as large companies pass through compliance expenses to us. Real privacy threats (INCLUDING THE EU) GDPR is meant to block will still continue to operate.
- jrockway 8y agoWhat are y'all using for self-hosted analytics? I have used Google Analytics and Mixpanel out of sheer convenience, but I know many users are uncomfortable sharing their data with those sites. To relate this to the article: what should these government agencies be using? Or should they not be looking for Javascript errors, A/B testing, etc. at all?
- nukeop 8y agoPiwik.
- GunlogAlm 8y agoI tried Piwik but it seemed so cripplingly slow. Trying to load the analytics often took minutes. Has anybody else experienced this?
- zepearl 8y ago> Trying to load the analytics often took minutes Do you mean loading the UI which displays the graphs etc...?
- GunlogAlm 8y agoYes, I worded that poorly. I meant loading Piwik's UI; it was cripplingly slow and often timed out. I had little luck in narrowing down the cause, but it was hardly a thorough investigation on my part, IIRC.
- zepearl 8y agoAssuming that your disks, DB, CPUs and RAM were all ok, maybe you did not set up PiWik's jobs that are supposed to aggregate the metrics every XX hours/days... ? https://matomo.org/docs/setup-auto-archiving/ https://matomo.org/docs/setup-auto-archiving/
- smacktoward 8y ago
- cobookman 8y agoWhat happens if EU found to be violating GDPR. Does it fine itself 5% of tax rev?
- user5994461 8y agoThat'd be great. More money to fund public services.
- SiempreViernes 8y agoTaking money from a publicly funded agency and redistributing it within the government does not create more funds.
- billions 8y agoSeems like the government employees should have some skin in the game. Maybe lay off a percentage of the workforce for poor performance? Maybe the committee that interrogated Zuckerberg should be publicly interrogated themselves. Why fine the tax payer?
- Retric 8y agoI don’t know how the EU operates, but in the US there is no specific agency that could get the US government in trouble with it’s self. Instead, at the federal level you have each state as it’s own thing, specific elected officials, and federal agencies. That breakdown continues at the state and local level. Anyway, a federal agency, state, or elected official may get in trouble, but that would not then bubble up to the entire federal government.
- reaperducer 8y agoPerhaps not to an individual, but states and cities sue federal agencies all the time. IANAL, but I believe it is possible to sue the "entire federal government." When someone commits a federal crime, the paperwork reads "United States vs. {$alleged_miscreant}." So it seems to me that the opposite should also be possible.
- based2 8y agolike google font cdn.
- jdietrich 8y agoThird-party tracking is not inherently illegal under GDPR, even without consent. GDPR regulates personal data; if you're collecting genuinely anonymous usage data that cannot be attributed to a specific individual by any reasonable means, you don't need consent. I can't say how compliant any of these websites are, but the presence of a third-party tracking cookie does not automatically mean that a website is in breach. Nothing in the article clearly points to a breach of the GDPR. Edit: I'm being downvoted for this comment, so I'd invite you to actually read the legislation. https://gdpr-info.eu/ https://gdpr-info.eu/
- JangoSteve 8y agoI didn't downvote you, but from the article: > The group said this could be used to "infer sensitive facts about [users'] health condition and life situation" and be resold to target ads. "These citizens have no clear way to prevent this leakage, understand where their data is sent, or to correct or delete the data," it said. The second quoted sentence in particular, if true, would seem to be in violation of GDPR, more specifically several sections/articles within Chapter 3.
- sisu2019 8y agoyeah yeah sure, unless you are $CURRENT_TRADEWAR_ENEMY then suddenly everything is PI and here is your fine, shut up and pay. It's plain to see that there are two version of this law: anything the EU or a member state (well maybe not those pesky Hungarians though) does is OKE DOKE and everything YOU want to do is a terribly expensive violation.
- Theodores 8y agoWhat about the cookie law? I don't get what has happened to the 'cookie law'. I have never seen a tutorial on how to do analytics properly, where you ask first and then run the 'gtag' script. The tutorials always show 'bang this in the header' and that is it. I would be interested in any article that shows how to do this properly, so on user interaction the cookie is created. I can figure it out for myself but that is not the point. I just see an absence of articles on how to do Analytics in a cookie compliant way where nothing is written on the visitor's computer unless they are okay with it. So if anyone has the article that has eluded me, please post. As an example of my misunderstanding, not with GA but with the BBC: If you go and clear BBC News cookies it comes up with some privacy notice thing at the top of the page but puts half a dozen cookies down. I thought you had to click okay before a cookie was splurged onto your computer. Have I misunderstood how it is supposed to work? Can you just disgorge the cookies and just show some boring cookie notice after that initial event?
- microdrum 8y agohttps://www.reddit.com/r/adops/comments/b2nton/lets_be_honest_google_is_a_lazy_monopolist/ https://www.reddit.com/r/adops/comments/b2nton/lets_be_hones...
- cromwellian 8y agoIsn't it a little disingenuous to call analytics tools "adtech". Yes, you can integrate analytics with adtech platforms, by even in isolation, knowing how your users use your own site and how they arrived there, allows you to better serve them. In a physical place of business, for example, a retail store or restaurant, keeping track of what times or parts of the store were busiest, or where people spent the most time, would allow you to eliminate waste from your business, and sometimes that involves knowing how many unique customer foot traffic you're getting.
- cwkoss 8y agoIs it possible to use google analytics without the resulting data being accessible by google ads or search teams? I would assume that they don't let you opt out of org-internal data sharing.
- JangoSteve 8y agoThere is technically a way to link/unlink Google Analytics from Google Ads: https://support.google.com/google-ads/answer/1704341?co=ADWORDS.IsAWNCustomer%3Dfalse&hl=en https://support.google.com/google-ads/answer/1704341?co=ADWO... There are also ways to configure Google Analytics to fuzz IP addresses, essentially de-anonymizing them, as well as setting up explicit data retention periods. EDIT (responding to grandparent comment): Even so, I'm not sure it's disingenuous to call products adtech which are provided by a company whose main business is advertising, and which are often configured to contribute to the advertising business, even if it's possible to use them for purposes other than advertising. At that point, maybe it's just adtech that's being repurposed.
- kalyan02 8y agoAbsolutely. Corporate/Enterprise accounts can opt-out of it.
- Nextgrid 8y agoI wouldn't trust any opt-out functionality from a company whose bottom line is based on harvesting as much data as possible off everyone.
- jacquesm 8y agoEven my bank feels it is necessary to run Google Analytics tags on the pages with the account balances. Morons.
- chii 8y agoImagine how much money you'd be able to syphon if you could access the javascript that serves these pages!
- doikor 8y agoFrom my banks web site? Effectively zero. Nothing will happen unless you validate the transactions using two factor authentication (user id + code app/single use paper code) (In my experience all bank web sites work like above here in Finland)
- slig 8y agoOne possible attack is to change the details of a transaction before the page post it. To the user it would appear as she's transferring money to Bob, but it'd go to Eve.
- magicalhippo 8y agoMy bank has two-factor using some special applet thingy on my phone (not a regular app, it's tied into the SIM card somehow). It shows me the details (amount and destination account) which I have to confirm using my password (in combination with a key from the SIM). Much more difficult to circumvent, assuming the user pays attention...
- chii 8y agoThen, the malicious script can just pop up an official looking dialog box with a message saying that they are 'testing' the confirmation system, and please accept/agree to the next sms/alert from the app. Having direct control of the user interface is very powerful.
- marcrosoft 8y agoI think they should read their own rules and hit themselves with a fine of 10 million or 2% whichever is greater and distribute it among those who were effected. Edit: or at least consider that their rules are ridiculous.
- zavi 8y agoIs it possible to sue them for this?
- a1a 8y agoThink there is a need for a clarification. It says _member states_ of EU have trackers on their websites. Not EU itself.
- hopler 8y agoSo? EU laws are a suite of national laws.
- ionised 8y agoWhat the hell are you talking about?
- UncleEntity 8y agoDepends on if you think fonts.googleapis.com and fonts.gstatic.com cookies are "trackers on their websites" both of which are found on http://europa.eu/rapid/press-release_STAT-19-1728_en.htm http://europa.eu/rapid/press-release_STAT-19-1728_en.htm Though I did have to do a bit of clicking around until Privacy Badger found something so it looks like they at least are trying.
- StreamBright 8y agoIt would be a great move from some of the more privacy aware countries to block entirely these trackers on national level.
- mschuetz 8y agoI wish.
- rubbingalcohol 8y agoMass censorship is so hot right now!
- Nextgrid 8y agoHonestly, this is the kind of censorship I would support (as long as there's a way to opt-out). Would you be bothered if your ISP or similar blocked access to malware command & control servers? This is basically the same - these analytics services are essentially spyware and the companies behind them should be held to the same standard as any spyware operators.
- rubbingalcohol 8y agoWe're talking about Google Analytics here. I'm not a fan and I don't use it, but I don't need the state deciding which web domains are kosher for whatever arcane reasons that can be devised.
- buzzerbetrayed 8y ago> Would you be bothered if your ISP or similar blocked access to malware command & control servers? Yes, that would bother me. I prefer to make my own choices about what I can and cannot access on the internet. Why would I want my ISP doing that for me? As far as implementing this on a national level goes - I would trust the government much less than I would trust my ISP with that kind of power. At least I can switch to another ISP if mine started abusing it.
- StreamBright 8y ago
- kilburn 8y agoSo... the report says 0 spanish websites were found having trackers. I've tried 3 random links of said websites, all taken from the report [1-3]. Ublock detected and blocked google analytics in all of them ([1] has urchin.js too). [1] http://www.lamoncloa.gob.es/Paginas/index.aspx http://www.lamoncloa.gob.es/Paginas/index.aspx [2] https://www.riojasalud.es/ciudadanos/problemas-de-salud/30-enfermedades-de-transmision-sexual https://www.riojasalud.es/ciudadanos/problemas-de-salud/30-e... [3] http://www.juntadeandalucia.es/servicioandaluzdesalud/principal/noticia.asp?codcontenido=17319 http://www.juntadeandalucia.es/servicioandaluzdesalud/princi...
- robador51 8y agoAnalytics is not the same as ad tracking
- sverige 8y agoWhat is it that they need to analyze that they can't get from their own servers?
- codezero 8y agoThis is a good question to which there are a lot of good answers that are often poorly received on HN so you’re unlikely to get a solid answer. I’ll take the hit though. It’s not just pageview logs, but GA has great tools to analyze those logs, do reporting on some decent set of actions and to bring it all together in a simple to use interface. You can take your server logs and then what will a non technical person do with them? Not much. That said, you can deploy GA while opting out of behavioral data and ad network features, and even fuzz ip addresses. Analytics has the stigma of ad networks because they historically existed to validate ad spend. We’re past that point and they are often used with strict first-party intent. There’s nothing preventing us from imagining all the malicious things any analytics tool could do, and imaginations run wild. Disclosure: I work for an analytics company that doesn’t want to own your data, but I understand why folks have a knee jerk reaction to analytics of any kind.
- michalskop 8y agoI was looking once (about a year or two ago) on Czech (EU member state) government websites and about 90% of them were using something from Google, usually Analytics. But some of them required even Captcha (so no way to access it without being vetted by Google, an US company).
- renholder 8y agoThe title is intentionally misleading (click-bait?). EU government websites does not equal EU members' government websites. For our American friends, that would be akin to saying the federal government, when you mean the states' governments.
- sam_lowry_ 8y agoIndeed, major European Union websites do not use Google Analytics for 10 years or so. They switch to Piwik soon after the cookie law came into effect.
- arendtio 8y agoI think this story is gold. I like the GDPR, but I think this story shows how easy it is to violate it or how difficult to follow it. In my opinion, the EU should offer reference implementations for all their 'internet' laws. If they make a law which requires privacy policies they should supply some examples (under some license which allows using them). If they create a law to let users choose if they want to be tracked, they should offer a script which does just that. Such a reference implementation would give a concrete implementation of how the law could be followed and make it easier for everyone to implement it (e.g. for themselves). Otherwise, millions of people have to interpret the law and it is painful for everyone involved: creators cannot be sure that their implementation is correct and consumers have to use illegal implementations until everybody knows how the law is meant to be implemented.
- Animats 8y agowww.parliament.uk: Google Analytics and Google Tag Manager. www.army.mod.uk: All the above, plus Doubleclick and Google Ads. Google Tag Manager is especially dangerous, because it's a Javascript injection system and a known attack vector.[1] [1] https://securityboulevard.com/2018/04/malicious-activities-with-google-tag-manager/ https://securityboulevard.com/2018/04/malicious-activities-w...
- kmlx 8y agofrom your link: "Any external assets which load on your website should be kept to a minimum so that you can maintain the most control over everything. " made me chuckle. that ship has sailed about 20 years ago.
- Animats 8y agoFor a site that's not ad-supported, there's not much need for external assets.
- jammygit 8y agoIn Canada, most of the health services / clinic websites I've been to over the last year use a mishmash of google scripts. I'm actually not certain whether things like google fonts gives them any data (is it just an IP and nothing about the site in question?). It seems inappropriate to put google maps in there though, but again I'm not certain
- blihp 8y agoThey might get the referrer (i.e. the URL the page the request came from) and information about the browser since it's your PC/phone that actually contacts Google's servers to request the resource. As long as the URL doesn't encode any PII, that will be it. I'd guess that bigger thing that companies like Google get from hosting resources like fonts etc. is that it provides them yet another, and much broader, market research data point re: what browsers are people using, what fonts/scripts are sites using and so on. So even if you completely avoid Google products/services like Android/Chrome/Chromebook/etc., they'll still get a bit of usage data from both you and the site.
- interfixus 8y agoWhere I live (Denmark), these days nteraction with public administration mainly happens through web interfaces, like it or not. And believe me, when I log into some state service, Google follows. Because even in what is supposedly my private business, pages are infested with links to analytics, fonts, tag managers, and assorted other Mountain View skullduggery. In my daily life, I have uMatrix, cookie killers, and other defenses keeping me reasonable free of all that nonsense. But the mandatory, enforced central logon ("NemID") - which I must use for all public logging in as well as for my bank and similar stuff - is such an unholy clusterfuck of malice and incompetence that I long since gave up the fight and assigned it its very own, completely unfiltered Firefox profile, simply in order to at least sometimes get things done. So yes, Google knows exactly where I'm going page for page, not only if I visit, say, the national police website, but if I am deep in filling out forms for the tax authority, consulting with health services, using my web bank, answering a court summons, whatever. I'm fairly certain much of it is actually illegal. But any complaint goes up against a massive wall of ignorance and incomprehension, often a far greater challenge than an expert reply.
- bArray 8y agoSo, what's the punishment for the EU not following its own legislation? Surely they should have to follow their own rules?
- mrweasel 8y agoI don't know about the EU as a whole, but the Danish government just exempted itself from large parts of the GDPR, mostly regarding fines. That's a little idiotic, given that the government loses/leaks more personal data than anyone else.
- tumetab1 8y agoRemember remember; The data leaked through CSC; That the government pretended; It never was important.
- bArray 8y agoWhy bother implementing rules if groups can be exempted or just not follow them? Seems like insanity to me. Either GDPR matters or it doesn't. Just imagine how much money was spent in updating systems to be compliant - and then the EU itself isn't!
- mulander 8y agoGDPR aside, the most annoying thing I saw was Polish 'Agencja Wywiadu' (the CIA equivalent) having a recruitment page[1] stating how careful people should be when applying. To not tell friends, to do it in person etc. and when you look at it, the whole page is filled with tracking from Facebook, Twitter and Google. I tweeted at them but they don't seem to care... [2] [1] - https://aw.gov.pl/rekrutacja/ https://aw.gov.pl/rekrutacja/ [2] - https://mobile.twitter.com/mulander/status/1023981741395128320 https://mobile.twitter.com/mulander/status/10239817413951283...
- __m 8y agoThanks for bringing this to attention, so it can be fixed. Who would have thought that HN would become such a great advocate for the privacy of EU citizens?
- Operyl 8y agoI took it differently, personally. To me it’s a double standard, we spent so much time going after the private companies with this law, that to have so much of the government’s own groups fail to even do a review of their own damn sites? Ugh. Since the governments are not subject to the GDPR, it doesn’t have teeth, and I would not be surprised if it fails to get resolved.
- Nursie 8y agoA lot of them will be technically not in breach, claiming anonymisation etc gets them out of it. This is the line I have always had from Gov.uk, for instance. But it's pretty crappy that they haven't tried to follow the spirit of the law. And it's pretty crappy that all my interactions with the government, as a UK citizen, are reported back to the Google mothership.
- Operyl 8y agoThankfully we as savvy users are able to strip away information we don’t want sent to companies, via browser extensions and what have you. I’m concerned about the less savvy users who, frankly, never have even thought about this being an issue.
- havkom 8y agoJust a side note in relation to the title, EU institutions are not subject to GDPR. They are instead subject to the similar Regulation (EU) 2018/1725 of the European Parliament and of the Council. Much smaller administrative fines among other things. https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1552577087456&uri=CELEX:32018R1725 https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=15525770... However, the linked article discusses not EU government/institutions but rather EU member states public authorities web sites. Such web sites are subject to GDPR but each member states decides whether administrative fines should be possible to impose on public authorities (and if so their max amounts) according to GDPR Article 83(7).
- Nursie 8y agoI've tried to raise this, specifically about UK government websites before. The gov.uk people didn't want to know, and told me it was OK - google promised to anonymise the data they were collecting. And we should just trust this, that google are given all the data they need to track everything that UK citizens do to interact with their government online, but they won't.
- kmlx 8y ago1. persoanlly i'd rather trust goog than any government out there. at least with goog i know where i stand, and i know what it takes for them to change course. with governments there's no recourse except for voting every 4ish years. 2. if you've got ublock or some other tech installed then you can easily ignore your own advice.
- negus 8y ago"The group said this could be used to "infer sensitive facts about [users'] health condition and life situation" and be resold to target ads" Could. But will not. There are strict policies in Google ads on this.
- westpfelia 8y agoEnforced policies? I realize there is probably not a good way to judge this but I have become skeptical to most big business and their adherance to 'policies'.
- negus 8y agoReputational risk is too high for this. And medical ad targetting is being regulated in many countries.
- TeMPOraL 8y agoI don't think reputational risk applies much to big companies. From Equifax through Facebook and yes, Google - lots of companies have done things in the past years that should have killed or crippled them, and yet they're still chugging along, none worse for the wear.
- candeira 8y agoThe Australian Tax Office, Aussie Medicare and the my.gov.au site all use Google Analytics! Unless you use countermeasures (I have Privacy Badger installed), Google is getting quite a bit of information from your use of the sites, even if all they get is the metadata. It's freaking nuts.
- k_sze 8y agoIn Chinese we have a saying: 「只許州官放火,不許百姓點燈。」 "Only state officials are allowed to commit arson; the populace is not allowed to light a lamp." "lamp" as in "oil lamp" or "candle" in general.