4 ms·
If someone adds <img src="http://blah.us http://blah.us"> to their website, and that image is hosted in the United States, how does that not also violate French
by VikingCoder 5y ago
If someone adds <img src="http://blah.us http://blah.us"> to their website, and that image is hosted in the United States, how does that not also violate French data protection?
The user's browser makes a request to a US server, including the user's IP address.
I legit do not understand how to make French people happy with these laws.
- cdot2 5y agoI've been having to remove google fonts because we had some germans say we're breaking their laws by using them
- littlecranky67 5y agoTo be fair, nowadays there is hardly any benefit. Since browsers use cache partitioning (mostly because CDNs were tracking users) there is no benefit in not serving it yourself (although yes, licensing restrictions now apply but there is plenty free fonts to use).
- tremon 5y agoWhy remove them? Why not proxy/cache the fonts from your own server?
- ihuman 5y agoDepending on the license, that might cost more, or not be an option at all. For example, Adobe doesn't allow you to host their fonts; you have to link to their CDN. https://helpx.adobe.com/fonts/using/font-licensing.html#web-host https://helpx.adobe.com/fonts/using/font-licensing.html#web-...
- mrunkel 5y agoExcept he explicitly referenced Google Fonts
- gjs278 5y ago
- ThePhysicist 5y agoIt probably does violate French data protection. There were similar lawsuits in Germany over the use of Google Fonts. Making a users browser interact with a US-based or US-owned service is currently very thin ice.
- zaptrem 5y agoAll they need now is some sort of ISP level filter to make sure nobody loses their privacy to US servers. They could call it a "Great Firewall" maybe.
- mmastrac 5y agoProtecting the privacy of citizens is not akin to society-wide censorship, a la China. This is a disingenuous argument.
- RustyConsul 5y agoKind of. I'm still losing my ability to choose. I've often found the slippery slope 'Fallacy' to not be so much of a fallacy in reality when it comes to power.
- mdavis6890 5y agoYep, next to be banned is fake news articles, then entire sites that contain some fake news articles, then sites that contain links to other sites that have fake news.... [Edit] for clarity
- dntrkv 5y ago“Slippery Slope” is only a fallacy when you can’t reasonably draw a line from the proposed idea to the “dangerous” end result.
- tick_tock_tick 5y agoAnd yet requires a similar solution.....
- colordrops 5y agoBy not embedding third party content on your site.
- merrywhether 5y agoI’m guessing that if you are a US-based site then you are exempt and it’s only if you start an EU presence that you would need to worry about this?
- hamilyon2 5y agoI suppose GA effectively tracks you across IP addresses and maybe even across private sessions on one very popular browser.
- lucideer 5y ago> how does that not also violate French data protection? The regulations don't ban collecting IPs (nor any PII). They just regulate it to the point that it must be deemed necessary according to certain criteria. I would imagine linking an image may be fine in 95% of cases, but what it would mainly depend on is the logging practices of the image hosting company. Their business would be bound by EU regulation if they are choosing to sell service to an EU-based website, and it's likely that image host that would be liable for compliance. It's worth adding quite a lot of the regulation here is tied to company size, revenue and scale of data sharing in general, so if you are for example a small business/non-profit you're very likely to be fine either way.
- tyfon 5y agoIt would probably depend on the purpose. If the purpose is the show the image and all logging is done to an access file and not processed into advertising models I'd think it would be ok. if the purpose is to collect PII and build advertising models like it was with the google fonts or the 1 pixel images then it is not ok.
- drusepth 5y ago>Their business would be bound by EU regulation if they are choosing to sell service to an EU-based website, and it's likely that image host that would be liable for compliance. Is the image hosting company really _choosing_ to sell service to an EU-based website if someone adds <img src="http://blah.us http://blah.us"> to their (French) website? It seems like it'd be an unreasonable expectation upon a company (especially one in a completely different country/jurisdiction) to e.g. ensure their existing logging practices _also_ comply with French, Austrian, etc laws. Surely the user who adds/posts the image on a French site would/should be liable here, not the host of the US-based image (service?), no?
- lucideer 5y agoThis largely depends on whether the French website is a paying customer hosting their own images in a deliberate fashion (e.g. Amazon being responsible for facilitating GDPR compliance of S3 logs), or if it's a randomly hotlinked non-owned image. In the latter (hotlinking) case the French website would almost certainly be entirely responsible if they operate at scale (excepting user generated content). In the former, it's obviously less clear cut (and also as mentioned revenue & scale are going to be very relevant). Practical example: a private individual posts a hotlinked image on a French forum. Relevant questions: - is that user profiting at large scale from data logged on the image server? No. - is the forum website owner? No. - is the image host deriving revenue directly from proactively collecting, analysing and profiling user data from readers of that forum post who are based in the EU? Possibly. - is the image host doing so at large scale? Maybe. 3 & 4 are definitely true of Google Analytics, but broadly won't be true of many image hosts, so your image linking example won't be an issue most of the time.
- o_m 5y agoThat easily be fixed by using CSP: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/img-src https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Co...