25 ms·
GDPR penalty for passing on of IP address to Google by using Google Fonts
- oliv__ 5y agoThis is getting ridiculous. The paper-pushing world created by GDPR and these non-technical bureaucrats is just absurd and only a burden for smaller companies trying to get things done.
- tmaly 5y agoI think this is abusing the intent of GDPR.
- smokey_circles 5y agoIf this is specifically referencing that technically you could have served those google fonts without making the user go to Google (a proxy of your own and not a hyperlink) then yeah I'm all for it. Big if though, but to roll with it 1) finally webmasters can feel the absurd amount of data they push on us for goddamned shiny JS that barely runs on my phone. Maybe they'll cut back a little 2) Hopefully this incentivises a bit more clear border segregation. More technical effort? Yes. Better for my privacy? Hopefully. I don't like the language here though, specifically the lack of anything directly supporting my stance. But I prefer optimism and then realism
- Jon_Lowtek 5y agoThere is a serious problem with the ongoing balkanization of the internet. EU nations are almost at the point where they rule that european corporations must provide pages in a way that respects european citizen rights and follows european laws. Outrageous! And yes that means they can not integrate services from surveillance states like the USA or China without asking the user first, as the EU government thinks only their agencies should be allowed to run mass surveillance against their citizens without consent. And the EU is not the only one who thinks like that. Pretty soon services controlled by foreign powers will be unacceptable in most of the world. Currently in the USA this is limited to hosting government and military secrets on foreign systems, but i bet if some chinese network would start to creep all over the civilian american web, reporting back to their ministry of national security, the rules would change quickly. For now the USA uses its position to spy on everyone, and i don't mean "nations" or "governments", i mean everyone. American patriots don't see a problem with that, but we know what you do in Utah, and it's a crime against humanity. For the multinational corporations this whole situation of GDPR-vs-CloudAct means massive restructuring, splitting into smaller entities that service regional markets and moving the top level corporate group somewhere with minimal regulation to minimize conflicts. And such legal splits rupture their core business, at some point they can't have chinese hardware in us datacenters being administrated by indian technicians providing services to russian tourists in brazil anymore. Maybe this is the last battle the nation states fight with the global corporations and it instead breaks nationalism in favor of streamlining compliance and getting shit done. I can only hope that the global rules emerging say no to mass surveillance and yes to data privacy, but abusing human rights has always meant power and profits, and so i fear the future is dystopian.
- dusted 5y agoThis is idiotic. A website links to a resource somewhere on the Internet, the user decides to visit the website with their browser, and their browser fetches the linked resource.. This is literally the fucking point of the fucking Internet.
- p5v 5y agoWhat's next? Someone coming after you, because your have their IP in your server logs? I understand the privacy sentiment, but I find this the opposite of how you beat a giant. The proper way for Germany and the rest of Europe should be the creation of a thriving environment of viable, privacy-aware FAANG competitors. Not putting barriers in every which way.
- alkonaut 5y ago> Someone coming after you, because your have their IP in your server logs? This is literally the day job for everyone on HN: checking so you don't accidentally log IPs.
- dreamsbythelake 5y agoThis is great point, BTW. I always did not have time to "clean up" fonts - now I finally got it done. :-) In my opinion, this should be _welcomed_ by WebDev community - this does improve privacy. In theory, DE court is right - your website should force user to connect only to itself. I clearly see 2 ways of making this even simpler: use Lynx :-) or Tor Browser. The importance of Tor in today's business should increase. Yes, there are "shady" things there - but there they were in "clearnet" back in 90x ... Makes sense.
- bArray 5y agoAfter translating - the violation here is a website included third-party fonts from Google, and the fact that Google would be able to see their IP from the request violates GDPR? Seems as though anybody who uses a CDN or third-party to load _any_ resources will violate GDPR by this measure? Seems like a pretty wide interpretation of this law.
- perlgeek 5y agoThat is exactly my reading as well.
- silviot 5y agoIANAL, but it sounds to me like a very important part of the story is that Google was not listed to end user as entity that would treat their data. Another way to read this could be: failure to inform users that their IP addresses were sent to Google resulted in a 100 € fine.
- bArray 5y agoSure, but this also seems bad for the small web. Imagine for example some small blog embeds a Youtube video into their static page - suddenly they are getting 100 euro fines all over the place. Also this entire case overlooks the point that this user was tech aware enough that they knew their IP was getting sent to Google, was deeply upset by this, but didn't get an ad blocker? This feels like a contrived use of GDPR.
- kiallmacinnes 5y agoHonestly, it's not that big a leap to reach this interpretation. 1) Your IP address is considered personal data, as it can be used to identify you. In general, everyone can see and agree with this. 2) In the absence of additional protections and/or contract terms[1], the transfer of personal data out of the EU is an offense under the GDPR (well, technically it's not out of EU, but transfer to a country without GDPR equivalence). So - embedding code / data from a 3rd party into your website results in a transfer of personal data. [1] The idea of additional protections/contract terms is even questionable, but that's a whole other thing...
- HatchedLake721 5y agoSo an HTTP GET request to another domain (fonts.googleapis.com) "leaked" website visitor's IP address to Google. What the hell? Google Translate: https://rewis-io.translate.goog/urteile/urteil/lhm-20-01-2022-3-o-1749320/?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en-US&_x_tr_pto=wapp https://rewis-io.translate.goog/urteile/urteil/lhm-20-01-202... > The defendant is sentenced to pay the plaintiff €100.00 > The plaintiff has a claim against the defendant to refrain from passing on the plaintiff's IP addresses to Google under Section 823 (1) in conjunction with Section 1004 of the German Civil Code. > It is undisputed that the plaintiff's IP address was forwarded to Google when the plaintiff visited the defendant's website.
- mro_name 5y agoyes. That's a fact. A 3rd party is a 3rd party and a website leaks it's visitors to it. Just don't do it but serve your stuff from your domain.
- XCSme 5y ago> from your domain Not only from your own domain, but from your own servers. If you still server-side send the IP to Google servers, it's still sharing of personal data with a 3rd party. I wonder how this works when you rent servers from VPS providers. If you host data on their servers, does it mean you share it with them? What if this data is behind a root password? What if it's encrypted?
- arlcode 5y agoAlso Google can definitely make use of That information because they know so much about the user that a single IP connect is enough to establish that a specific user visited that website.
- randalluk 5y agoDoesn't this attitude overlook the "agency" of the "User-Agent"?
- maratc 5y ago
- perlgeek 5y agoThe reasoning behind this judgement is: The services (here: web fonts) could be supplied another way, so exposing the user's IP to google is not strictly necessary, from a technical POV. The user's IP is PII, and exposing it unnecessarily to third party is a GDPR violation. The way this is phrased, the reasoning applies to basically every static resource loaded from a CDN or other third-party website.
- lucian1900 5y agoIt’s “personal data” in GDPR. PII is the US concept and much narrower.
- kevincox 5y ago> The services (here: web fonts) could be supplied another way The problem here is that every service could be provided another way. It seems that the only actual hosting option that doesn't leak a user's IP to a thrird-party is first-party only over Tor. Do we demand that every website is built that way? It turns out that outsourcing actually has a lot of value. So where do we draw the line? Google Fonts apparently needs to be reimplemented first-party. What about Google Cloud CDN? What about an ISP that sees the user's IP in the packets?
- miohtama 5y ago> The services (here: web fonts) could be supplied another way, so exposing the user's IP to google is not strictly necessary, from a technical POV. Because an IP address needed to receive a download. This kind of decision means that any hot linking of static media assets is now in hot waters. A sensible judge would say IP address is not PII but a prerequisite to use Internet in the first place. Like a license plate on car e.g. other broken analogue of tracking. Like a power socket. However the definition of PII in Europe is overly capturing (saying this as an European.)
- valzam 5y agoThe problem of course is that IP addresses can totally be used by Google to build up a profile of your browsing behaviour across the whole web. Even if typical end User ip4 addresses change quite a lot due to ISP NATs I imagine it's still very valuable information. Obv with ipV6 and static IPs for everyone it becomes a privacy nightmare
- l0rn 5y agogerman law doesn't really know "precedent cases". However it looks like a whole new industry of lawyers sueing pages embedding stuff could arise...
- izacus 5y agoLeaking customer data to Cloudflare is also a very interesting question here.
- ar0 5y agoThey seem to count CDNs as "hosting providers" and yes, without the necessary legal frameworks in place, this is also a problem if that leaks user data: https://www.technologylawdispatch.com/2021/12/privacy-data-protection/german-court-prohibits-u-s-data-transfers-in-cookiebot-decision-why-this-decision-is-special-and-should-alert-but-not-upset-your-organization/ https://www.technologylawdispatch.com/2021/12/privacy-data-p...
- greggsy 5y agoIf your website requires CF to reliably deliver data to customers, then it’s unlikely to cause much of a stir.
- krehl 5y agoWhat about using e.g. Webflow? Can I leak the IP address of the customer if I don't know it myself?
- blfr 5y agoWhat about "leaking" the IP to your server provider and all the networks between your user and site?
- fsloth 5y agoVery good point, the courts in countries with common law work quite differently than where the courts are based on civil law. There is a quite large difference of the two systems. https://en.m.wikipedia.org/wiki/Common_law https://en.m.wikipedia.org/wiki/Common_law
- johnchristopher 5y agoWait, what prevents the next court to say that the browser vendor is responsible for the leak ? Per default the browser is not asking the user if it's okay to download fonts from Google (or any resources from any another resources provider) after all.
- posterboy 5y agoThe browser can be set to dissallow third party resources
- johnchristopher 5y agoKeyword: per default. It's an opt-out, GDPR requires an opt-in.
- isbvhodnvemrwvn 5y agoPeople who created the browser are not processing any data when you use the browser, so GDPR hardly applies. They need to be careful with bug reports, but that's it.
- johnchristopher 5y agoOf course, I am following the logic where it goes. Now, why would website operators be considered data processors for providing a link to google fonts to website users ? The website is not leaking the IP, it doesn't need if to display fonts and it doesn't use visitor's IP to display fonts. Ultimately the user of the browser is using his IP to get the fonts and this user is the one responsible for leaking his IP. The website has delivered an HTML document. It's up to the user to do what he wants with it and follow links or not.
- foxfluff 5y agoWhy is it not the author of your NIC driver who is responsible for the leak? Per default the driver isn't asking whether to send a packet to Google's IP address. Here's why: the driver is just doing what it's told to do. The responsible falls on the party who does the telling. If a website tells my browser to load resources from Google, it's not on my cpu or my nic or its driver or kernel or firewall or the browser.
- miohtama 5y agoCan you someone translate? Does this mean that hot linking any static media or asset from a third party is against the law unless explicit approval from the user is first received?
- mro_name 5y agoyes.
- arlcode 5y agoIf there are different means to host the asset and the hot linking would transfer data out of the EU (in particular to the US and to a giant marketing company) that might be problematic.
- mro_name 5y agoTraffic inside or outside EU is marginal. It's just illegal from the start. You need prior informed consent and it must be optional. If it is not technically necessary. And a CDN rarely is. I can show you some sites that do without.
- jlokier 5y agoNo. (Contrary to the sibling comment). If you have agreements in place with third party data processors to protect user privacy, this ruling does not prevent you from hot linking third party assets under that agreement. In effect, the third party acts as part of your infrastructure - just like you may already use a third party hosting provider, cloud database provider, auth provider, logging service, etc. The GDPR constrains how PII is stored and processed. It doesn't stop you from using third party providers, but it does make you responsible for ensuring user privacy is protected, by delegation through binding privacy agreements and sufficient diligence. Those types of agreements are already common. For example, if you're hosting on AWS providing service to users covered by GDPR, you should already have such an agreement. It's pretty straightforward. https://aws.amazon.com/compliance/gdpr-center/ https://aws.amazon.com/compliance/gdpr-center/ Therefore if AWS offered a generic, third party font hosting or embedded video hosting service, you could hot link to that no problem. Same with Cloudflare, Google Cloud, etc. as long as they provide the necessary agreements with you. The problem with Google Fonts is there is no such agreement in place, you can't trust Google to not profile users statistically via font requests, and even if Google says they won't do that, you can't trust that their servers in the US won't be tapped by US authorities to monitor request logs, etc.
- ianpurton 5y agoHopefully we won't see popups like "This site will forward your IP address to Google is that OK?", because I'm already beyond bored with "This site uses cookies do you accept?".
- thepangolino 5y ago
- brtkdotse 5y agoI too was pissed about the popups until I realized it the companies throwing up the popups that are to blame. Hosting all your assets by yourself, on your own servers and doing analytics without sending data to a third party is not a terribly tall order.
- questiondev 5y agothat is true but it increases the barrier to entry for those who use google fonts for system resource issues, a lot of people offload because they don’t have the space or money to self host everything one could argue that it is less eco friendly as well given how much space is going to be used repeating the same file on a multitude of servers
- brtkdotse 5y agoA Google font file is just a small file, smaller than most images. You can download it and place is along side your css files. And seeing how most websites are 20 megs+, the eco argument seems forced.
- Youden 5y agoA $5 VPS comes with several gigabytes of storage. A standard web font (e.g. Roboto) is ~1MB. Bandwidth is essentially free through CloudFlare. Who doesn't have the space or money to self-host their fonts?
- 5y ago
- deleted 5y ago[deleted]
- ealexhudson 5y agoThis is a good judgment and less onerous than people are worried about here: there's not going to be a need for a raft of pop-ups. GDPR is clear about processing personal data. If you're a website, you're a data controller, and you are responsible for the security/confidentiality/etc. of that data. If you want to use external services that's cool, but you need a formal data processor agreement in place that maintains your control of the data, and you need to list that in your privacy policy. So, can you embed fonts? Yes, it's not a problem: either they should have directly embedded self-hosted stuff and not used the supplier, or ensured a proper data processor agreement was in place. Post-Schrems II, the latter becomes more difficult if the supplier you're contracting with cannot promise the level of control over privacy/etc. that you need as a data controller, however. The alternative position is to say that it's OK to embed resources that basically allow large corporates like Google to track your activity across the web without an agreement in place. That's obviously not OK under GDPR.
- rokizero 5y agoAs a Deutscher this sounds completely nuts. Correct me if I'm wrong but any not 100% technically necessary third party request is considered illegally leaking personal data?! Or do I 'just' have to inform the users that their fonts, images and other data that could be stored in source but is not? In the case of fonts I'm pretty sure they get cached in the browser, so bundling them with the source just doesn't make sense?
- AndrewDucker 5y agoYes. If it's not technically necessary then don't do it. Host the fonts yourself rather than letting Google track people to your site.
- maxwell86 5y agoAs a German citizen, this isn’t nuts. Leaking extremely sensitive user data, like their IP addresses, to third parties, enable them to finger print users. Leaking those to third parties outside the EU, and in particular to companies whose revenue depends on this finger printing, like Google, just to serve a font, it’s the dumbest thing I’ve heard all week. The whole purpose of the GDPR is to discourage this behavior, requiring websites to inform users of all their crappy unnecessary things they want to do before they do it. The only reason Google gives you hot loading for free is to get your users data. Trading your users personal data to serve a font is brain dead. IMO this fine of 100€ is too small. They should have made it 10% of their revenue to send the clear message that this is not ok.
- izacus 5y agoIP Address is far from "extremely sensitive user data". Really.
- freemint 5y agoGiving an IP Address to Google including referrer header is. They can do a lot with this and as long as the Google Font hosting service doesn't give out assurances (they can be sued for for breaking) that this data is not used in any way which would enable Google to track a person.
- Mystlix 5y agoThis decision is incredibly coherent with the fact that tracking can be done in many ways other than with cookies. Your residential IP doesn't change that much and Google keeps track of it. Google can track your navigation through websites and associate it to your google account or shadow account just by seeing if you downloaded one of their fonts through said websites. So bravo to the Munich court for actually upholding rules against opt-out third party tracking
- ddmma 5y agoThis could be extended to any API request, if involves IP tracking
- perlgeek 5y agoI'd say for requests that return dynamic data, a case could be made that there is technical merit for the client doing the request instead of the server proxying the request.
- leobg 5y agoDistrict courts are notoriously terrible. Judges are overworked. They are incentivized for dealing with cases as quickly as possible. As a judge, you actually get penalized for handling cases diligently. Many judges can’t even touch type, so even when they do go through the motions of doing legal research, they type in a few crude keywords, skim the first results presented by the algorithm, and then call it a day.
- HL33tibCe7 5y agoUnfortunately, GDPR is an insane web of laws and regulations that any non-lawyer has absolutely no hope of understanding.
- mawadev 5y agoThis is exactly what stops me from hosting websites. I simply have given up trying to keep up with the rules. It is a massive burden if you are not a corporation trying to extract information and just want to host a simple blog from a german server. At some point, private persons and maybe small businesses won't be able to keep up and the web becomes even more centralized.
- somytsu 5y agoIt is possible to host a blog wihout third party services. Maybe small businesses should focus on minimal websites and build from that. As you grow, you can more easily affort the costs for lawyers to check if the features you want to build are GDPR compliant.
- oblio 5y agohttps://gdpr.eu/compliance/ https://gdpr.eu/compliance/ The whole thing, including guides, is much shorter than the spec for HTML: https://html.spec.whatwg.org/multipage/ https://html.spec.whatwg.org/multipage/ Probably clearer, too. And just like for specs there are even better third party doc sites you can use: https://gdpr-info.eu/ https://gdpr-info.eu/ Dry reads, but it's not like RFCs are heart wrenching novels either :-D
- anilakar 5y agoIt always puzzles me how people making six figures a year for translating real-life requirements to technical ones suddenly throw a tantrum when said requirements involve law.
- chrischapman 5y agoDisagree. The key information is no longer than an average privacy policy (and frankly, less complex) and whereas there are millions of privacy policies (which no one ever reads), there is only one GDPR. Give it one hour of close reading and you'll see just how important and useful it is. It's worth the effort because you only need to do it once.
- leobg 5y agoThe ruling says the website owner illegally shared the user’s IP address with Google. AFAIK, this is an incorrect interpret of events. The website merely tells the user’s browser that the content is intended to be displayed using a font that, if not installed on the user’s computer, can be downloaded from Google’s server. It is the the user’s browser that initiates a request to Google’s server. A request by the website itself to Google sharing the user’s IP address never actually occurs.
- isbvhodnvemrwvn 5y agoUsing this logic I can send full fingerprinting data as long as I do it from the front-end? I mean courts are not that dumb, it's still the website owner which decides what is done.
- Already__Taken 5y agoThe website owner decides what's asked to be done. The browser is still owned by the end-user can choose to make the request. This is why ad-blocking is fundamentally required.
- Andrew_nenakhov 5y agoBrowser can be configured not to send this data. If I ask you to jump from the bridge, and you do, how is it my fault that you chose to comply?
- npteljes 5y agoSo code in frontend would be "asking" in this case, in your opinion? Javascript is executed by default by all major browser deployments.
- Andrew_nenakhov 5y agoIf you are that caring about your privacy, you absolutely should use a browser that is configured in such a way that it doesn't leak your IP to anyone you didn't consent to.
- rob_c 5y agoLol. Well just going the UK doesn't follow suit with this madness
- asadkn 5y agoCurious how useful is an IP address with a simple HTTP get request? As long as a sane Referer-Policy is set, the Referer won't be sent. Sure there's a lot more to browser fingerprinting but with just an HTTP request, all the data that would be known from it is the language and the user agent. Both of which are not unique data points and shared by thousands of other users. No cookies either in this case of Google Fonts.
- arlcode 5y agoConsider the following scenario: You are logged in to to google and so are your family members. You visit YouTube.com from IP X with device (user agent) Y. Your family member visits YouTube.com from IP X with device Z. Google Fonts gets a request via the API key of mydomain.de from IP X and device Y. Google now knows that you visited mydomain.de Edit: I stand corrected that Google Fonts doesn't use an API key. I suspect they still can correlate the font request with the domain, however I have no proof. Consider this an example for other services like maps.
- aliswe 5y agoSeveral people and devices could be shared by the same IP though, either who are on the same network or in the vicinity of the same mobile mast (or in the same mall or restaurant)... that's why IP often isn't used as conclusive evidence that you are the same person just because you are on the same IP.
- magicalist 5y agoGoogle fonts doesn't have an API key.
- Jyaif 5y agoThere is not "API key" needed to request a font from Google Font...
- Puts 5y agoWell technically you share a lot more data. IP, browser agent, time (which in combination with IP can tell exactly who used that specific computer) and cookies set on the *.google.com domain. So it's actually interesting that the court only focused on the IP-address although the ruling would probably have been the same even if they widened the scope.
- HL33tibCe7 5y agoReductio ad absurdum: if serving fonts from Google is “unnecessary” and leaks information, so would be using any CDN service to deliver any content.
- pantulis 5y agoOr linking anything, for that matter
- piaste 5y agoIt unquestionably leaks information, and it is why projects like Decentraleyes exist. Whether it is "unnecessary" is the interesting question. For fonts, it's really hard to claim that you couldn't have created the website without Google's fonts CDN.
- tomp 5y agoA CDN that sells your data (or doesn’t otherwise protect it) is more accurately termed “spying network”
- paulgb 5y agoDoes this ruling distinguish between “does” and “could”, though? Because any CDN could spy if they wanted. Google fonts has a pretty reasonable privacy policy[1]. I don’t read German, so I wonder if there’s nuance here that I’m missing (like, did they find that Google actually was misusing the data?) https://developers.google.com/fonts/faq#what_does_using_the_google_fonts_api_mean_for_the_privacy_of_my_users https://developers.google.com/fonts/faq#what_does_using_the_...
- everdrive 5y agoI try to block web fonts using Pihole. This makes me want to add an overly-broad rule blocking any occurrence of the word “font” in a domain. It’s yet another web technology that really has no need to exist. My computer already has multiple fonts. There’s way that I benefit by downloading them from a remote site.
- chrischapman 5y agoThis kind of 'leakage' is key to personal profiling. If this ruling becomes widespread, profiling may prove much harder to do (which is a good thing). Edit: clarification
- account-5 5y agoI'm torn here. I can see it from both points of view. As a user I don't want any of my data going to third parties at all. As a website owner trying to provide a service to my users I want the best experience for them. This might be linking to third party services that are doing a better job than I could. I only see this going one way. The user will have to agree to the sharing of their data with third parties if they want to view third party content, or want the fonts rendered in a better was. Link NPRs text version when you don't agree.
- netizen-936824 5y agoWhat's wrong with system fonts This is a serious question, I personally prefer to set my own font for web browsing so why do people feel the need to force fonts on me and load them from google of all places?
- kevincox 5y agoI agree! The problem is that most browsers have awful defaults. I'm not sure why this is but it does mean that people end up wanting to change them. However my browser uses beautiful fonts by default and if you specify just serif, sans-serif or monospace. I wish this would be the common case so that we can just respect users font settings instead of picking what we think is the best. I write an article on this a while back: https://kevincox.ca/2021/06/23/respect-user-fonts/ https://kevincox.ca/2021/06/23/respect-user-fonts/
- Puts 5y agoNote that GDPR talks about data minimisation - data you should not share more data then necessary. If there are no other way then linking to a third party then that would be just fine. But if there is another way to do it that don't requires you to share someone else data you should do that instead (in this case self host the fonts). Also consent may not actually help here because the principle of data minimisation applies no matter what legal basis for the processing you use.
- Jyaif 5y ago
- dave333 5y agoSo would other Google resources like running Adsense ads also reveal IP addr or other private info? I think Google allows users to opt out of being tracked?
- oblio 5y agoGDPR works the other way around. By default it should be <<opt-in>>, not <<opt-out>>. You don't get to track me and then force me to tell you "don't track me", you should do nothing by default and ask me "may I track you?". Companies don't do that because opt-out is sneaky and it means they can track, say, 95% of users. With out-in, they get to track maybe 80% of users if they're allowed to use dark patterns (where they hide stuff or lie to the user what tracking actually does) and probably less than 10% if they're not allowed to do that.
- dave333 5y agoBut a site owner running Adsense won't get sued like the site owner running Google fonts did?
- oblio 5y agoThis comment thread provides more insight, I think: https://news.ycombinator.com/reply?id=30135827&goto=item%3Fid%3D30135264%2330135827 https://news.ycombinator.com/reply?id=30135827&goto=item%3Fi... And regarding lawsuits, small fish websites don't really matter. Look at this case, breaking the law meant a €100 fine. I feel that reasonable people are super afraid of the GDPR. Just read it, it's shorter than a spec. Talk to a lawyer if you're still super afraid. It applies to every business but it's targeting huge corporations tracking stuff, not the average Johann.
- Puts 5y agoI think this is actually a really interesting ruling because it's based on Article 6 and not Schrems II. The problem is that they are not taking enough steps to share as little data as possible which is a fair point, but it would also be interesting to see if Google Fonts actually is legal in the sense that personal data (IP, browser agent, timestamp) may end up in the US and used for other purposes (tracking) then just delivering a font.
- zoobab 5y agoPretty good news, Google is a Spy machine that should be bannes in the EU, if you enforce the Schrems2 decision.
- ksec 5y agoMy working theory of GDPR is that absolutely anyone on earth who has used the internet could be found to have broken the rules. -Benedict Evans
- tzs 5y agoYou don't even have to use the internet. It applies to printed data too. Your Rolodex could be a GDPR nightmare.
- yayr 5y agoSo what happens if you include e.g. a Wikipedia image or a youtube video? Is that a GDPR violation too? These scenarios also lead to making the users IP available to a third party. If so, how do we avoid breaking the web while keeping privacy needs in balance?
- xaedes 5y ago> how do we avoid breaking the web while keeping privacy needs in balance? One thing that I feel would help: Massive decentralization. Self-hosting of content and regular synching of the hosted content on the server sides; or tunneling, think duckduckgo. Self-hosting would make knowledge storage more redundant which protects against (also partial) network blackouts. On the other hand this knowledge is then harder to control. Removing or redacting content would have to rely on the particular sites to "pull the updates" from the upstream. Copyright will also be problematic: each site would have to make copies of content with the (probably commercial) intent of serving it to consumers. Still I can't help to think we need more decentralization and self-hosting.
- Loeffelmann 5y agoSo your solution is to introduce a massive amount of redundancy so Google doesn't know you downloaded a font.
- 7373737373 5y agoSounds good, but a solution like Peertube would leak the user's IP to even more (and unknown) third parties
- kevincox 5y agoPeople don't just use third-parties because it is fun. They do it because it reduces cost. If we have to build every service from the ground up as first party is that good economically. Does every website need to build its own CDN now?
- jgalt212 5y agoI think the amount of information being leaked here is minimal. i.e. fonts are cached and thus Google only knows you visited health.com and not health.com/scarydisease. unless your landing page was health.com/scarydisease.
- denton-scratch 5y agoI don't know why people use fonts served from Google on their websites. Just serve the fonts from the server the site is on. It's like having javascript libraries served by 3rd parties; it's less robust.
- manmal 5y agoI think it allowed browsers to cache font files across websites. But that might not even work anymore as I understand many browser vendors are moving towards resource isolation.
- iggldiggl 5y agoThere still is the fact that you're getting fonts that are automatically subset into partial font files per character set, so if your pages mostly only use one or two character sets (like Latin and possibly Latin-extended), the browser only needs to download the font files for those particular character sets – at the same time you still retain the flexibility of using the full range of characters supported by that font if the occasion demands it, though. (With Latin plus Greek plus Cyrillic and possibly some OpenType features like proper small caps you can get into the hundres of k range, and support for East Asian languages easily gets you into the megabyte range.) Plus in theory fonts optimised for the respective combination of browser and OS. The former probably isn't as critical any more, as almost everything should support WOFF2 (or at the very least WOFF) these days, as for the latter – I know OSs each have their own font rendering peculiarities, but no idea how much the difference might be in practice.
- rnestler 5y agoI guess one advantage could be to better use browser caches for these things? If you visit multiple websites that include the same fonts or javascript libraries, the browser can reuse the cache for them.
- rpadovani 5y agoThis was the case once upon a time. Nowadays, cache is partitioned by website (https://developers.google.com/web/updates/2020/10/http-cache-partitioning https://developers.google.com/web/updates/2020/10/http-cache...)
- afrcnc 5y agook...this is just downright silly and dumb now on the other hand, always host your fonts
- verytrivial 5y agoI find it hilarious that the entire internet tracking and surveylance industry simply thinks it is entitled to this level of information now.
- dsego 5y agoAlmost like delivery services industry that are entitled to know your residential address.
- npteljes 5y agoThis is exactly the entitlement your comment parent was on about. A third party should not have active insight into the first party's business like that - or their customers'. GDPR is a very welcome step forward in this regard, and I hope that more of such will come.
- infamia 5y agoThe sort of logic imputed by the GPDR would put an end to mailing parcels too. You could drive across town to deliver the package, you didn't need it delivered via the post. After all, every package shipped in the mail involves a third party who knows the sender and recipient's address and name. Best get to banning that sort of potential skulduggery ASAP! This is really an idiotic law in that it punishes the symptom (a third-party web request), but ignores the underlying problem (data strip mining by Google, Facebook, Twitter, etc.). Punishing the data strip mining, but leave the third-party web requests (which is an intrinsic feature of the web) would at least make some logical sense.
- npteljes 5y agoNo, the mailing parcels are fine. As long as they have proper employees that deliver the packages, and not a third party that does deliver, but also collects everyone's name, address, package sizes and estimated values, and projects household income, advertising cohort and then sells this to yet another third party. See the difference? Regarding the instrinic part of the internet argument, that's just an appeal to nature. Naturally the internet is such and such, and therefore it's good (and also currently widespread). That's not a reason why that should be. We forbid plenty of such intrinsicly human things by law, because that's how ~the ruling class can stay in power~ lots of people can live together in relative safety. For example hurting someone else is perfectly natural, I think. I think it happened lots of times before it became a sort of law to not do that. And of course it happens now in many direct and indirect ways, because people want to express, for example, just how angry they are at another. Yet I don't see how we shouldn't restrict this very intrinsic thing. Also, but this is just conjecture, I think this application of GDPR would allow third party requests IF they are not logged for example. Because then the data collection doesn't happen. In TFA, the third party is Google, and that might be the thing that makes the difference.
- keewee7 5y agoGermany is terribly backwards when it comes to IT. It's insane that such a backward country should have that much say on EU regulations. I'm not kidding. Countries like Denmark and Estonia are light-years ahead of Germany in terms of eGov and mobile payments.
- intunderflow 5y agoIt's always the Munich court making these stupid rulings. How long until they fine an ISP for forwarding my packets over a Google AS on the way to its destination.
- c01n 5y agoOn the one hand I don't want lawyers, government and politicians to shape cyberspace. But I also like this ruling it seems to set a precedent for users to be able to opt-in to APIs (and probably javascript the obvious next step if this goes on). Client-server interactions should be transparent, this will prevent allot of privacy related issues. It also makes the web more decentralized, getting developers back into a host your own stuff mentality.
- discardable_dan 5y agoOn its face, this appears to be death of the third-party CDN. The largest issue is this means companies will no longer be able to use third-party hosting services like Squarespace which rely on shared (technically third-party) CDNs. A secondary, but similar, issue, is that now all embeds are opt-in: streams, videos, everything must first be clicked on to even load the thumbnail. A third, and less-important, issue is that advertising providers are basically over: the website, on load, can't query the third-party ad service to figure out what ad to display. Which I'm fine with, abstractly, but it's also a very large revenue issue.
- gnud 5y agoUsing a third party is not illegal in itself. But you need an agreement with the third party as to how they will store/process any user data they collect. This is fairly fundamental under GDPR. It's the 'data controller'/'data processor' split. I suspect (but IANAL of course) that most CDNs would fail here, because the blanket agreements they offer are basically worthless. But it's easy to imagine a CDN that has a different business model (charges a tiny amount pr. resource stored, for example), and is completely fine under the GDPR.
- discardable_dan 5y agoHow can a CDN fail to retain an IP address, at least for the purposes of knowing where to send the response? The ruling doesn't say that Google stored the IP, causing the issue, but merely that the user's IP showed up in a packet sent to Google.
- csomar 5y agoI don't understand German but understand HTML/HTTP. Technically, you only get HTML from the website you visited. Then, YOUR browser, requests more data based on that HTML. So technically, it is your browser who requested the font and as a result leaked the IP address. Am I getting this correctly or not?
- yawaworht1978 5y agoKind of, the good thing is, if the user used chrome(good chance), the billing just goes to a different department.
- Puts 5y agoYou would not have made that request in the first place unless that company did the request in the background for you.
- rpadovani 5y agoTechnically, yes, but legislation is not code, and many other things have to be considered. I cannot sign that I will sell my firstborn, but _technically_ I've read, understood, and accepted a contract
- deleted 5y ago[deleted]
- drakonka 5y agoReading our layman developer interpretations of the legalities here is very interesting, but that aside this really makes me rethink my own use of Google hosted fonts in my projects. Whether it is the browser responsible for making the request or my website being responsible for asking the browser to make the request, hosting the font myself is a readily available option. From the perspective of respecting users' data, why call out to Google at all when I don't really have to, for _any_ resource where there's a straightforward alternative? I say this as someone who does use Google Analytics as well (which I am removing). But mostly for me it isn't a case of dropping all third party convenience services, but a case of remembering to be _mindful_ of what I'm doing.
- aembleton 5y agoI wonder if this will have an impact on https://gdpr.eu/ https://gdpr.eu/ as they use Google Fonts
- dsego 5y agoSomeone should sue them.
- quantum_state 5y agoDoes this mean the network stack is illegal based on GDPR?
- avereveard 5y agotold you ip were personal data: https://news.ycombinator.com/item?id=16910675 https://news.ycombinator.com/item?id=16910675 you'all buried the comment as you didn't want to listen but, as I said back then, reality doesn't care about fake internet points. but hey, you liked gdpr right? it's going to be fun for ambulance chaser around europe: https://news.ycombinator.com/item?id=16910301 https://news.ycombinator.com/item?id=16910301
- irthomasthomas 5y ago250 points in 3 hours and this post is not front page? What is going on with HN today?
- kall 5y agoTreating IP addresses as PII continues go be incredibly tedious and as far as I can tell, they are PII because providers are forced by law to keep those records. Is that correct? It would be so much better to just reduce and safeguard that information instead of handing it out to any rando with a court order.
- floatingatoll 5y agoSadly, the United States used to have a treaty law in place that delivered the easy solution you describe. In mid-2020, the treaty was found not to provide the necessary protections, and invalidated by EU courts; no replacement treaty was negotiated or signed by the US, and so here we are.
- Merovius 5y agoI'm confused about the text. It is not obvious, what the defendant actually did. The assumption from most people seem to be that they used a `<script>` tag or the like, with a Google URL. But the text does not imply that. On the contrary, it repeatedly uses the word "weitergabe" and "weiterleitung" ("forwarding"), which is just not accurate for this process - it seems to imply that the defendant actively made a connection to Google and sending the IP over it. Of course, this might just be an artifact of the legalese and non-technical phrasing of the verdict. But does anyone know what actually happened, on a technical level?
- eps 5y agoFinally. Took them long enough. There is literally no other business reason for Google to maintain Google Fonts, but to augment its tracking insights. None. That's the sole purpose of the very existence of Google Fonts.
- j-pb 5y agoIf you've ever had the pleasure of dealing with the licensing nightmare of foundries, it's quite easy to see that a small group within google had enough and started the project. We've literally spend tens of thousands of dollars on our font archive, but decided that we can't continue to use these fonts on projects anymore, due to "we can change the licence at any time" clauses and rent seeking behaviour, that is eerily similar of the stock photo industry licensing (which pretty much has ruined photographers) and scientific publishers (which pretty much have ruined science). I hate google as much as the next guy, but our small design company is in their dept for creating google fonts, and we plan on contributing to the the repository if we ever create a font as part of a project.
- arlcode 5y agoBut there is nothing that prevents anybody to build a similar product but charging a fee for it. The payment being "user data" is the problem. Not the product in and of itself. If you are in the EU such a platform would probably need to be GDPR compliant. I'm sure there is a opportunity for a font market that fulfills your needs. It might not be easy but eventually studios like you will probably have to charge clients an ongoing fee for "premium assets". The end user is paying for it and while you and your clients are probably fine with it, the lawmakers are obviously not.
- j-pb 5y agoWith all due respect, your response doesn't make much sense. Google fonts is primarily a github repo with specifically licenced fonts. Google paid a lot of the artists and foundries behind these fonts for an open licence. Therefor there is no need to build a "similar product", when the existing one is alrady free as in free beer, without any hidden data-/ad-funding. We are are primarily a PRINT-MEDIA shop. Non of GDPR applies to this, non of our customers or customer clients pay for anything with their data, because paper doesn't have an uplink. Yet the google font project is as much key to our survival as sci-hub is for the scientific community.
- anfogoat 5y agoThis isn't at all surprising but I still got scoffed at when I suggested that serving third party fonts, css, scripts, whatever without prior consent or contracts would be a violation. Tragically, I was just robbed of my told you so and was met with a mere well, this seems ok when I sent this to the very people who couple of years ago thought this would be nuts and that I was exaggerating. Part of the pathology of the kind of folk who like to cheer everything the EU does I guess. My question is, why aren't we worried about the hops between a website and a user? There's who knows how many networks and routers in between them, and the packets might even hop outside the EU momentarily (!!!!!). Surely this needs some attention as well? Should we maybe consider an internal EU-only network? Or maybe the Commission could come up with a whole new routing scheme? I'm sure Europol would have tons of very sane ideas for one.
- marcus_cemes 5y ago> why aren't we worried about the hops between a website and a user I asked about this below, apparently it's reasonable and strictly necessary. It's what the user expects. Even though it's technically possible for the infrastructure layer to provide full packet anonymity, until then it's the web developers responsibility. I do not agree with this, but that's my opinion.
- marcus_cemes 5y agoPersonally, I can see only two parties benefiting from this: the plaintiff and lawyers in general. Google will continue to be Google. Users will be faced with more annoying consent notices that they don't read. Website developers, of which I am one (bias disclosure), who are not very good lawyers will have more technical complexity in order to respect the law. Small companies who rely on services such as CDNs and font providers are now worried about having to host things themselves and the complexity that will ensue to be GDPR compliant (everyone's new least-favourite term). Hacker News gets a divisive flamewar over the subject and this will be yeeted from the front page.
- lixtra 5y agoIn other news: ip packages hop from one host to another and a dozen hosts see the private ip and the websites IP. Certainly the website should have asked the user before exposing their ip on the route.
- perlgeek 5y agoThe difference here is that there's a technical necessity for the routers to see the IP.
- lixtra 5y agoNo, there are many ways around it (i.e. tor, vpn). The internet provider (or user) is just too lazy to provide proper privacy. Just like the website owner is too lazy to self-host the fonts. Edit: in fact PII should not pass unencrypted, so if you don’t protect the IP (classified as PII) then you‘re not compliant.