4 ms·
We have been GDPR compliant for many months but our aim here was to meet E-Privacy demands. We don't use localStorage... Read the blog post, we don't use cooki
by JackWritesCode 7y ago
We have been GDPR compliant for many months but our aim here was to meet E-Privacy demands.
We don't use localStorage... Read the blog post, we don't use cookies.
- EGreg 7y agoOh, apologies, you are right! You don't use any kind of cookie mechanism. I just read it again: Random SHA256 String (daily regenerated) IP Address User Agent Site ID Day of the year My only question is about this "Random SHA256 String", where is it stored between requests?
- JackWritesCode 7y agoRedis Cache. It's a Fathom-wide random string that is used to prevent rainbow table attacks. The salt is refreshed at midnight every day.
- EGreg 7y agoThanks, makes total sense. So basically the only drawback I see is that all employees from behind one corporate NAT using same browser will count as one user. But don’t see a way around that if you can only use IP and User Agent strings.