9 ms·
Sorry for the German only link, but this is from today and didn't make the rounds yet. It is not really about Shopify itself, but about the use of CDNs - which
by wusel 4y ago
Sorry for the German only link, but this is from today and didn't make the rounds yet. It is not really about Shopify itself, but about the use of CDNs - which would be even more worrisome. Shopify Support couldn't help the shop owner.
- 2000UltraDeluxe 4y agoIIRC, the Portugese authorities already deemed CloudFlare as non-compliant. Same issue as with Google Fonts, etc.
- friendzis 4y agoGDPR core is pretty simple: You cannot do stuff (process, store, transfer to third parties) with PII unless X condition is met. An internet site, on first visit (being genuine first visit or just cookieless visit) cannot do things with PII, because there is just no way to even tell if X is met, therefore not only data storage (IP address in Apache access logs included) is illegal, but moreso transfer to third party via CDNs and what not. GDPR is ugly. The only thing it allows you to do before you get confirmation to process PII is to show static page requesting for permissions. That's basically it. You can't do any "cloudy" stuff prior.
- iso1631 4y agoStoring IP addresses for technical requirements is legal (for example you need to keep the IP address in memory because you have an open TCP session). Likewise a session cookie is fine too. Keeping those IP logs for security reasons is also legal (assuming you keep them safe for an applicable amount of time) Using that data for analysis is not legal.
- dmitriid 4y ago> GDPR is ugly. The only thing it allows you to do before you get confirmation to process PII is to show static page requesting for permissions. That's basically it. You can't do any "cloudy" stuff prior. No, GDPR is not ugly. Yes, you can do "cloudy stuff". The bullshit narratives around GDPR need to stop, however people driving the narrative are extremely incentivized to siphon and sell all the data they can get your data, so the narrative is always bullshit.
- throwaway13337 4y agoYou're just incorrect here. Part of the GDPR does good things against bad actors like ad/tracking companies. But most of these companies are so big that it just works as a moat to keep out small competitors in that space. The more widely-affecting thing that the GDPR is doing is to make it impossible to legitimately run a business like the one that the article is talking about. An online shop that uses shopify which uses a CDN. A small online shop using a CDN is who is actually hurt with GDPR.
- dmitriid 4y ago> You're just incorrect here. I was expecting you to show where I'm incorrect. And yet, it's the same emotionally-charged "omg moat, large companies, impossible to run a business". Which doesn't disprove what I say, but further supports my case: the bullshit narrative around GDPR persists even if it has literally no basis in reality. > A small online shop using a CDN is who is actually hurt with GDPR. Most CDNs have GDPR-compliant services in the EU. Those listed in the article literally have separate pages specifically addressing compliance with GDPR. There are banks in the EU handling sensitive customer data which use the very same CDNs and services under significantly stricter laws than GDPR. But sure. Tell me how it's impossible to legitimately run a small business that operates under significantly fewer obligations, and retains significantly less customer data.
- throwaway13337 4y agoOddly this argument feels familiar - like we've sparred in the past over GDPR on another hacker news article. I won't continue this as it seems like it's more a flame war where no side can convince the other. I'll say this, though: please imagine who I am who feels so passionately about this. Likely, I am a small business that has been affected personally by the GDPR though I am not in advertising or tracking. Maybe I'm just a small business owner trying to navigate the uncertain waters created by these rules. That's what brings out the passion. I imagine you are someone who is passionate about privacy and against adtech. As am I. We're probably ideologically similar. So please try to square why someone who is ideologically similar has such a strange idea. It might be that I am misinformed but it might be that you don't have the same experience as me.
- allisdust 4y agoGDPR is simple. It's a mechanism to keep foreign tech companies out of EU while not explicitly banning them (as it would result in reciprocal measures) by increasing the cost of doing business in EU. For those that do go all the way and try to follow the laws, periodic flaws found in implementation (which are inevitable given how complex these laws) are penalised heavy enough to make them think twice. If this is not there, software companies in EU which aren't competitive in general will be steamrolled by companies from other countries (but primarily from USA). China also does this to ensure home grown tech eco system while at least being more truthful about.
- kuschku 4y agoHow is GDPR ugly? It's easy to build websites, even interactive ones, that comply. If you build a mobile app, you are also supposed to only ask for permissions once you actually need them. Replace interactive embeds with a dumb replacement of the actual content and e.g., "we want to show you an embedded tweet here, [allow once] [allow always]". Don't use CDNs for delivering assets, they've long stopped being useful anyway. Don't use Google Analytics. In general, build websites like we used to in the early 2000s. And yes, you can even do cloud-y stuff like that. You can run k8s on your hetzner dedicated servers, you can run MinIO as your s3 store, none of that is stopped at all by these rules. You can even run an interactive website like HN without any GDPR violation or cookie prompts at all.
- oytis 4y agoSo no embeds, no CDNs, no analytics, lots of popups asking for permissions and going back to 2000s (just with cookie banners) in general. Isn't that ugly?
- kuschku 4y agoOf course you can have embeds. Just replace them with a blurhash and make them click to load. That also avoids pretty much all of the popups. Sure, no CDNs and no analytics, but that's what I'd call an absolute win. Nothing of value was lost.
- indrora 4y ago> only ask for permissions once you actually need them Hard on Android, where "did my wifi go away" means asking "can I have access to your phone's internal state including call logs and if you're in a call right now?" > replace interactive embeds with a dumb replacement Sucks when you depend on that content or the content has to be interactive under the TOS of the service you're using. > [CDNs have] stopped being useful Not at all. In many a corporate network as well as situations where you're paying for transit (e.g. AWS) they still make sense. > build websites like we used to in the early 2000s Ah yes with Flash for our interactivity, __Just throw an executable format that has a hard to render, proprietary ISA running unsupervised__, that worked for us then it should work fine today? I'd say "Let's build more websites like we did in 2010". That's right around when Javascript peaked. > Minio due to their licensing change, a lot of legal departments have banned minio.
- pvg 4y agoYou just wait for an English version of the story to appear. From scripture: re: language https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=author%3Adang%20english%20language%20site&sort=byDate&type=comment https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... re: from today https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=author%3Adang%20no%20harm%20in%20waiting&sort=byDate&type=comment https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
- scarface74 4y agoSafari’s built in translation is surprisingly good. It didn’t even read like a machine translation.