4 ms·
You can do basically this without cookies with daily random salt (which is not stored longterm) added to the ip + useragent hash mentioned in the article.
by Hitton 3y ago
You can do basically this without cookies with daily random salt (which is not stored longterm) added to the ip + useragent hash mentioned in the article.
- cuu508 3y agoIt's not quite the same though. In the cookie case, you can detect a returning visitor by the presence of the cookie, you do not need to assign an unique identifier. In the hashing case, the hash of the IP and UA counts as PII, at least for the 24 hours while you still have the salt.
- patrakov 3y agoYou can completely, at all, avoid storing PII for the purpose of estimating the number of unique visitors. The answer is to use HyperLogLog (see e.g. https://en.wikipedia.org/wiki/HyperLogLog https://en.wikipedia.org/wiki/HyperLogLog or http://antirez.com/news/75 http://antirez.com/news/75) on a strong fingerprint of the user's device. In this case, only some small amount of aggregate data across all seen fingerprints is stored. NB: this is completely irrelevant except as a mathematical curiosity, because GDPR prohibits any processing of PII (in this case - the fingerprint), not just storing it anywhere, without a legal basis.
- cuu508 3y ago> NB: this is completely irrelevant except as a mathematical curiosity, because GDPR prohibits any processing of PII (in this case - the fingerprint), not just storing it anywhere, without a legal basis. Hmm, but using PII in anonymized form is allowed, right? But how do you anonymize PII without processing it?