4 ms·
The GDPR law is complex, but I'm 99% sure that this guy is misinterpreting it here. Sending data to Google, FaceBook and AppsFlyer (and other American companie
by yding 7y ago
The GDPR law is complex, but I'm 99% sure that this guy is misinterpreting it here.
Sending data to Google, FaceBook and AppsFlyer (and other American companies) is generally legal under GDPR.
All three companies are covered under the US-EU Privacy Shield framework: https://www.privacyshield.gov/participant_search https://www.privacyshield.gov/participant_search
Furthermore, sending PII data to a non-EU country is also allowed under GDPR as long as the company in question obeys the GDPR rules. Like I said, those rules are complex, and there could very well be some technical violations by TikTok, but that's not demonstrated here.
Browser/device fingerprinting for anti-fraud is a well established industry practice. Browser makers don't like this practice and have taken steps to make it harder, but the truth is that it's used across the industry.
The open source license violations could be actual civil, but not criminal, violations. TikTok does maintain a list of open source licenses here: https://www.tiktok.com/legal/open-source?lang=en https://www.tiktok.com/legal/open-source?lang=en It looks like it's only for its app and not its website though. Violations of the MIT/BSD license by using a npm package and forgetting to include it in the documentation, unfortunately is pretty common across the industry. That doesn't make it right, and we should hold big companies to a higher standard of compliance, but if anybody wanted to make a complaint it would have to be the copyright holder.
TL/DR: I don't think the author demonstrated anything illegal here or out of line with normal industry practice. You can argue about the morality of certain industry practices (like fingerprinting) but TikTok is far from an outlier here.
- munk-a 7y agoAs someone who worked in a field that necessitated some significant anti-fraud measures nope to > Browser/device fingerprinting for anti-fraud is a well established industry practice. Browser makers don't like this practice and have taken steps to make it harder, but the truth is that it's used across the industry. If it's that important to you switch off of the web into an App, require sign-ons against an internal system for authentication and policy people actively. Falling back on fingerprinting is a BS excuse used by folks that want to minimize user barriers and maximize the profits they're extracting by push authentication and identification off onto public resources - it isn't ever necessary and it isn't okay.
- yding 7y agoI bet you've never worked on an e-commerce system then because none of your suggestions work against e-commerce fraud, and you'd literally lose all of your money: switch off of the web into an App: Can't just shut down your website. Also, device farms and VM farms are super common so it won't even help. require sign-ons against an internal system for authentication: Sure, you can require your users create an account. Accounts can be created by the thousands by bots. Even if you use captchas, captchas don't work, and even if they did I can find you 100 people who will sign up for accounts manually and sell them to you for 10 cents a piece. policy people actively: I assume you mean police people effectively. Kind of hard to "police" your customers when a huge percentage of them sign up once, buy something, and maybe only come back 3 years later. In the meantime, their super simple passwords may have been hacked and leaked 10 times already. Maybe you should require your customers all use 2FA. Let's see how many customers you have remaining once you turn that on.
- munk-a 7y agoBut here's the thing - it does cost money and customers to properly authenticate people. 2FA will lead to less sign ups but it will give you a more secure user base - in a world where DAU is the number to live and die by then security is compromised in order to help float that DAU stat. For sign-ons collect a per account activation fee or subscription fee - if your goal is to only have real users then enforce that with money, if your goal is to allow people to freely browse your site unless they're abusing your site then yea - that's where fingerprinting comes in, and it comes in because that isn't a solvable problem. If you want to know who your users are you need to be upfront about collecting that information securely and if you want any old joe who gets a link to immediately get sucked into browsing your site and looking at ads then just stop basing your business off of dark user patterns - deliver value, charge fairly for that value, realize that lots of potential business ideas would never be profitable because people simply can't be bothered to actually put out money for that service. This whole fingerprinting debacle is part of the ad-support web assumption, and the assumption that websites can be entirely ad supported is false outside of exceptional circumstance and certainly highly limiting and concerning for free speech - expecting a business to be ad supported, that's pretty much an impossible dream, we're living in a bubble where advertisers and marketers continue to sell lies about the ratios of converting views to actual sales.
- SeriousM 7y agoEven though these practices may be legal you'll agree that 99% of the people here are not ok with them. It's not needed to send personal data around the world for tracking. The core functionality of tiktok doesn't need that at all.
- HunOL 7y ago> Even though these practices may be legal you'll agree that 99% of the people here are not ok with them Sad truth is that they are not ok with it only because it's TikTok and it has Chinese origin.
- yorwba 7y agoPeople on HN don't complain about TikTok sending data to Facebook primarily because TikTok is Chinese, but because Facebook is evil. People on Facebook may hate on TikTok for being Chinese, but I wouldn't know because I don't have a Facebook account. (I don't have a TikTok account either, so it doesn't actually matter much to me whether they snitch to Facebook. But it's about the principle of the matter.)
- rufposten 7y agoI'm the author and even if I know GDPR quite well as professional journalist I know I can't interprete a law on my own, so I additionally asked an legal expert in this field. So this is what he explained: 1. Sending data to Appsflyer is OK in general, but you have to declare to which parties the data will be sent afterwards. As most of the partners will be joint controllers of the data you have to lay open the arrangements with ALL joint controllers: "The arrangement may designate a contact point for data subjects. The arrangement referred to in paragraph 1 shall duly reflect the respective roles and relationships of the joint controllers vis-à-vis the data subjects. The essence of the arrangement shall be made available to the data subject." Tiktok just denied to show any arrangements. 2. Sending data to Facebook is ok in general, but here it's without consent, so it must be covered by legitimate interests. This has to be balanced with the interests of the user and two crucial points are how invasive and how transparent a data procesing is. Sending your search terms to a company you don't even know it's involved and de-anonymising you in the same time (in case you have a app of facebook inc. on your smartphone) hardly can be legitimate interest. 3. Sending data to a non-EU country is OK, but only if the country is secure. This is indeed complex, but: ECJ ruled, that if public authorities have access on a generalised basis to the content of electronic communications, it's not ok, it's even a FUNDAMENTAL violation of the privacy of the users. 4. Browser/Device-Fingerprinting is legally ok. But I doubt that it is used for anti-fraud/security. If it's used for tracking, they probably need consent.
- singularity2001 7y agoConsider adding this highly relevant extra information to the main post.