4 ms·
This is, for better or for worse, how the internet works. There may be better alternatives, but we're stuck with this for now. The truth is that an extraordinar
by marcus_cemes 5y ago
This is, for better or for worse, how the internet works. There may be better alternatives, but we're stuck with this for now. The truth is that an extraordinary amount of websites use a third-party resources, jQuery from CDNs, fonts from Google, etc. This ruling will never stand in higher courts imo, because it would break the internet through fear.
I'm curious to know whether DNS and your IP being in the the header of packets travelling through various different countries that can be sniffed is also considered as unwilful data sharing?
- npteljes 5y ago"Can be sniffed", and "Provider is making a third party sniff" are two different things. Legally and ethically too. Right now you're right, the internet works this way. But that doesn't make it right, or fair, or anything, it just is. And it's also no reason it couldn't work in a different way.
- foxfluff 5y ago> This ruling will never stand in higher courts imo, because it would break the internet through fear. It wouldn't break the internet. The internet was fine when the vast majority of sites hosted all their own content and didn't ask your browser to load crap from dozens of domains. It wasn't even that long ago. Honestly I think it was better.
- marcus_cemes 5y agoBut it has since evolved, greatly, in complexity. Just because things were like something once, doesn't make it easy to go back. Hey, I'm all for more privacy, I'd like to go back to how it was before but keep the good parts from today, but this would make it harder for the small guy without some advancements in IT, private CDNs and easier font management. IT is already a nightmare just to keep it from breaking.
- Isinlor 5y agoThis ruling will 100% be upheld in the higher courts. The website is arguing that they have a legitimate interest in downloading fonts from Google in client browser, but as the court correctly states the website can provide these fonts directly. There is no reason to infringe on the user privacy, so there is no legitimate interest. And therefore use of Google fonts was without a legal basis. BTW - The website could have used a different legal basis out of 6 available, like consent. See: https://gdpr-info.eu/art-6-gdpr/ https://gdpr-info.eu/art-6-gdpr/ > I'm curious to know whether DNS and your IP being in the the header of packets travelling through various different countries that can be sniffed is also considered as unwilful data sharing? Unless there is another way to achieve the same purpose there is a legitimate interest in processing that data for the purposes expected by the client i.e. providing internet service.
- marcus_cemes 5y agoI'm not a layer (web dev in my spare time), but how far does "provide more directly" go? A private ISP? There's no limit, only what seems to be considered by the courts as "reasonable". Then again, that is how law is interpreted most of the time, no?
- Isinlor 5y agoWhen you do anything with personal data in the EU you have to have a legal basis. There are 6 and only 6 possible legal basis: https://gdpr-info.eu/art-6-gdpr/ https://gdpr-info.eu/art-6-gdpr/ But most businesses will be choosing from: - the data subject has given consent to the processing of his or her personal data for one or more specific purposes; - processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; - processing is necessary for compliance with a legal obligation to which the controller is subject; - processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. You can do basically anything with things like IP addresses as long as you have valid consent from the client i.e. they need to actually know, or at at least be able to learn, what you are doing with their data and decide that it is ok. So, no guessing here, just be transparent, and assume no consent by default. In case of ISP they have to process your personal data because it is necessary for the performance of a contract of providing the internet service. Also, no guessing here. The legitimate interest clause is a "catch all" clause for anything that legislator did not think about, so it is very vague by design. You do not want to choose this as a legal basis for data processing if you do not want to deal with legal uncertainty. But if you do choose it, you should have strong arguments that you really need this legal basis. If similar companies to yours are able to do exactly the same thing in a way that is less impactful on privacy then you can expect that courts will not grant you a legitimate interest. You can also do legal tests do determine whether you have a legitimate interest: - The purpose test (identify the legitimate interest); - The necessity test (consider if the processing is necessary); and - The balancing test (consider the individual’s interests). See more detail here: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/legitimate-interests/how-do-we-apply-legitimate-interests-in-practice/ https://ico.org.uk/for-organisations/guide-to-data-protectio... Also, based on my observation if you are not doing anything really egregious and you are willing to cooperate with data protection agencies (DPA) you do not have to worry about anything. If DPA decides you are doing something wrong they will tell you about it. And if you just adjust, like start to host fonts on your servers, they will let it slide or give you a small slap on the wrists. The really high fines are reserved for malicious conduct or gross incompetence with actual harm already done to people.
- bouke 5y agoThat we’ve been doing a certain thing in the past, is no excuse to allow it to continue going forward. It is a good that we are challenging practices that we have taken for granted and validate whether we want such practices to continue.
- ratww 5y ago> I'm curious to know whether DNS and your IP being in the the header of packets travelling through various different countries that can be sniffed is also considered as unwilful data sharing? The IP has to be there for the return TCP packet, so under GDPR this falls under "strictly necessary" information. If someone sniffs you, they now have your PII. They can't do anything with it that is not "strictly necessary" without your consent, otherwise they're also on violation of GDPR. The only people trying to "break the internet through fear" are the doomsayers.
- marcus_cemes 5y agoSorry, I don't mean to play the devil's advocate, this has already gone way off-topic so take what I say with a pinch of salt. But technically, the IP is not strictly necessary? I can imagine a feasable future where it could be replaced with an anonymised IP from a larger pool generated by your ISP, with TLS for the payload. This could be solved at the internet infrastructure layer, and not required by to be solved by website developers.
- npteljes 5y agoTo handle resources, like a jQuery library, I'd love seeing URNs being used. A Universal Resource Name is supposed to uniquely identify a resource solely by its name, and say nothing about where to find it - which is the job of its sibling, the URL. A website could state that they need "urn:uuid:6e8bc430-9c3a-11d9-9669-0800200c9a66", and then the browser could decide where to look that up. In my local cache? The cache distributed with the browser? The ISP's repository of resources? The original first party? My VPN provider's fancy anonymized lookup service? Whatever the case, it feels like a robust way to handle shared resources, and of course to introduce a myriad new ways to break UX but hey it's progress!
- ratww 5y ago> I can imagine a feasable future where it could be replaced with an anonymised IP from a larger pool generated by your ISP, with TLS for the payload. This is already a thing with NAT and Carrier-Grade NAT. However if the IP + port + time trio, coupled with other information (such as browser, stack, timezone, behavior) can be used to de-anonymise the user, this also instantly becomes PII. > This could be solved at the internet infrastructure layer, and not required by to be solved by website developers. It could, but until we get there, website developers will have to deal with it.