5 ms·
Hi, author of the article here. Just to give a little more background here. Cabin doesn't store a row in a database for each visit. It only stores one row, pe
by mulhoon 4y ago
Hi, author of the article here.
Just to give a little more background here.
Cabin doesn't store a row in a database for each visit. It only stores one row, per day per domain. The attributes for that row are simple tally counts - visits, uniques, bounces etc. So no identifier is stored, and the hits go into the tally. We do not store the fact that a user has visited x amount of times. The demo here is to show how the technique works.
Cabin used to detect only the presence of any last-modified date to determine if the visit is unique or not. But extending it to distinguish hits 1,2 and 3 (by adding 1 second to the start of the day) now allows us to count the bounce rates too.
- lolinder 4y agoThanks for sharing! I personally don't have an issue with it, but one thing that might set some of the people here at ease is if you stopped incrementing the timestamp after the second visit. This would give you three possible states anyone could be in: never visited, visited once, and visited more than once. It's less data, but still enough to give you your bounce rate and your total visits while minimizing the number of boxes you're sorting individual visitors into.
- jefftk 4y agoYour landing page says "no cookies or consent banners" and "compliant with all privacy laws", but the timestamp approach stores data on a user's computer in a way that is not "strictly necessary in order to provide an information society service explicitly requested by the subscriber or user". Could you explain how you see your approach as compliant with the ePrivacy directive? Full text: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058&from=EN https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... Guidance: https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2012/wp194_en.pdf https://ec.europa.eu/justice/article-29/documentation/opinio...
- IshKebab 4y agoYeah this is just a cookie by another name. Probably already used by supercookies. The GDPR doesn't single out cookies so you can't get around it by using a different storage device.
- jefftk 4y ago> The GDPR doesn't single out cookies so you can't get around it by using a different storage device. Quibble: this isn't a GDPR issue, it's an ePrivacy issue. Two different regulations.
- eloff 4y agoSo the moral of the story is to use passive fingerprinting that is able to identify and track individual users, because then you can skip the cookie banner and be compliant with the law? I think I would rather use this and rely on the courts to interpret it fairly if it ever came to that, which it won't.
- ohbtvz 4y agoHave lawyers familiar with EU law vetted your technique? Could you share their legal reasoning? If not, why would anyone ever take the risk to use your product and face huge fines?
- senko 4y ago(Not OP) I am all for privacy, use uBO, Firefox Focus / Incognito and Google alternatives. But if I have to consult a lawyer each time I write some code or write up a blog post, I'll take up gardening instead.
- ohbtvz 4y agoNo need for this kind of hyperbole. I wouldn't ask this question if the OP's post didn't contain grandiose claims such as "No cookies, no consent banners, no ad networks, 100% GDPR & CCPA compliant, low footprint web analytics." OP made a claim about their compliance with EU law. I'm asking for proof or at least an explanation.
- jefftk 4y agoThe OP is a "privacy-first web analytics" company; this is totally something they should be asking their lawyers. Note that their list the GDPR on their "Privacy law compliance" page (https://docs.withcabin.com/privacy.html https://docs.withcabin.com/privacy.html) but not ePrivacy...
- rcoveson 4y agoHow about just consulting a lawyer each time you abuse a protocol to get user's software to behave in a way that is invisible to them and benefits you? There is already a correct way to tell a browser to tell the server something with each subsequent request: Cookies. Nobody needs to "write some code" here; it's already written. Working around the protocol isn't engineering, it's just lying. This blog post is just another cynical degredation of trust between users and their browsers, and browers and the servers they talk to. Just another part of HTTP that we can't use for what it was designed for anymore because servers want so desperately to track visitors uniquely and a significant subset of visitors would prefer not to be remembered uniquely.
- Terretta 4y agoHow do you distinguish two users with the same date stamp, to know they are two diff visitors? User A: last-modified: Wed, 30 Nov 2022 00:00:00 GMT User A: last-modified: Wed, 30 Nov 2022 00:00:01 GMT User B: last-modified: Wed, 30 Nov 2022 00:00:00 GMT User B: last-modified: Wed, 30 Nov 2022 00:00:01 GMT Next you see: User ?: last-modified: Wed, 30 Nov 2022 00:00:02 GMT Which user is it? And have you had 2 count of visits, or 3 count? How do you know? Finally, these aren't really counting visitors, but views, of this URL, by this browser, right? There's a conventional taxonomy of terms for web stats, something like: - users (as in MAU) - visitors or uniques (typically daily uniques) - visits or sessions (multiple views from one visitor in a cluster) - views or pageviews (.html pages) - hits or requests (every object gotten from server: .html, .js, .jpg, etc.) Looks like your GIST is causing a remote user agent to store a count of its own views. // I haven't tried it, just a quick skim of the blog and the gist, raising this question. I'm probably missing something.
- jrmg 4y agoHow I'm interpreting their explanations is that they don't (can't) tell which user it is. They just know you've had two two-time visitors, and one one-time visitor.