8 ms·
As more time passes I begin to fundamentally believe the modern Internet isn't compatible with the GDPR or privacy as a whole. Simply the act of enabling JS wi
by tcd 7y ago
As more time passes I begin to fundamentally believe the modern Internet isn't compatible with the GDPR or privacy as a whole.
Simply the act of enabling JS within the browser is enough to have your privacy violated in thousands of different ways and data sucked up by everyone who wants it.
Simply by installing an app on your smart phone you invite SDK's that are happy to report back all the information the OS freely allows access to because why not? Data storage is cheap and collecting that data is free of charge.
But yes, data about children is collected in the millions, and the truth is there is no possible law that can prevent this from happening because it will happen anyway. One example: If FB detects a baby photo you upload, should it be deleted? I mean that baby cannot possibly consent, and you'd have thought the GDPR or some law meant uploading baby photos is impossible, but that's not the case, FB/Google WILL perform facial recognition on that baby.
Your data will be processed, used, sold and manipulated for as long as you generate it.
The GDPR helps, a little, in some ways, but it's really had very very little effect overall (apart from some damn annoying "we respect your privacy" pop-ups on websites).
If the GDPR was serious, it wouldn't be possible to collect this data at the OS level, like, at all, JS would return nothing, Android apps would return nothing (or fake data, at least).
But the GDPR is not serious, at least in some ways.
- api 7y agoI think it can only be fixed with legislation. There is too much attack surface to the point that avoiding tracking is hard even if you take extraordinary measures.
- tcd 7y agoThe GDPR IS the legislation, at least, I thought so. If you're serious about this, the network shouldn't be making these requests unless you've explicitly allowed it (meaning the request is blocked at the network/OS level).
- pjc50 7y ago"Tracking" is not a property of any particular network connection, it the act of correlation in the back end.
- Wowfunhappy 7y ago> The GDPR helps, a little, in some ways, but it's really had very very little effect overall (apart from some damn annoying "we respect your privacy" pop-ups on websites). That's because—as far as I can tell—the EU has not become serious about enforcing the law. At least not yet. It is absolutely possible to pass a law that says "you can't track people", and that's what the GDPR does. It has a semi-loophole for people who explicitly provide knowing consent to be tracked, but there are several big caveats—it must be opt in, you can't trick people to opting in, and you can't punish people who don't opt in. (And really, after all of those caveats, what percentage of your userbase will agree to be tracked?) Unless there's some aspect of GDPR which I don't understand—and please educate me if there is!—95% of the "cookie notices" currently on the web are obvious GDPR violations.
- jandrese 7y agoAre cookies violating if they don't leave the website? It doesn't seem to be a problem as long as the cookie is only used within the context of your site. It's when they're used on other websites that the tracking capabilities exceed what you can otherwise glean from the server logs. Plus, they're kind of important for sites that provide logins, or have shopping carts, or a variety of other legitimate uses for cookies.
- Wowfunhappy 7y agoCookies aren't inherently against GDPR if they're used explicitly for necessary site functionality—you don't even need to tell users about them in that case. What's not allowed is user tracking.
- sjy 7y agoSo why display the cookie warning? I assume it’s an attempt to obtain “consent” to something that would otherwise be prohibited by the GDPR, and in relation to consent the GDPR says: “Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment ... Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance.” I agree with the grandparent that many cookie warnings seem at odds with the GDPR in this respect.
- diafygi 7y agoHmmmm, I think it's a bit of an unreasonable expectation to think technology should prevent companies from breaking the law. Most meatspace laws are expected to be followed despite there being little to no physical barrier to breaking them (e.g. there's no physical barrier preventing me from throwing a brick through a window, but it would still be vandalism). Why should we expect laws in software to be different? Why should the burden of compliance be shifted from the individual/company to the infrastructure?
- freeone3000 7y agoBecause enforcement is effectively impossible. When crime becomes automated, how are humans expected to keep up the pace of enforcement?
- diafygi 7y agoCrime isn't automated. Someone has to write the script that commits the crime (or I guess ultimately design the AI framework that generates criminal bots). At the end of the line there's still a human.
- duxup 7y agoArguably any programming language allows companies to break the law. It's not a JS thing, and I feel like there is no going back from the world of web applications.