The GDPR blog post
medium.com
The GDPR blog post
1–10 of 144 posts
Re: The GDPR blog post
#2Re: The GDPR blog post
#3> Medium uses browser cookies to give you the best possible experience. To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy.
I must agree to logging user data and sharing it with processors?
EDIT: come to think of it, it might be a new, GDPR-specific, dark pattern. I can use the site without clicking "I agree", and the existence of that button sort of implies the consent is not assumed. The wording of the message ("you must agree") is just trying to bait consent.
EDIT2: I just read[0] that biggest sites in my country are treating closing the GDPR popup as giving consent to everything. This definitely does not sound as explicit, informed consent. I sincerely hope it'll land them in a world of hurt.
--
[0] - (PL link) https://zaufanatrzeciastrona.pl/post/klikasz-x-w-komunikacie...
Re: The GDPR blog post
#4A popup (probably what used to be cookie warning) on Medium says: > Medium uses browser cookies to give you the best possible experience. To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy. I must agree to logging user data and sharing it with processors? EDIT: come to think of it, it might be a new, GDPR-specific, dark pattern. I can use the site w…
Re: The GDPR blog post
#5Is there not any issue with having a hashed version of the email, given the entropy of an email address is quite small?
Re: The GDPR blog post
#6Re: The GDPR blog post
#7A popup (probably what used to be cookie warning) on Medium says: > Medium uses browser cookies to give you the best possible experience. To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy. I must agree to logging user data and sharing it with processors? EDIT: come to think of it, it might be a new, GDPR-specific, dark pattern. I can use the site w…
Re: The GDPR blog post
#8A popup (probably what used to be cookie warning) on Medium says: > Medium uses browser cookies to give you the best possible experience. To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy. I must agree to logging user data and sharing it with processors? EDIT: come to think of it, it might be a new, GDPR-specific, dark pattern. I can use the site w…
Re: The GDPR blog post
#9Is there not any issue with having a hashed version of the email, given the entropy of an email address is quite small?
Re: The GDPR blog post
#10Is there not any issue with having a hashed version of the email, given the entropy of an email address is quite small?
To save the information that a certain email address has explicitly withdrawn consent, they need to store it. The alternative is to send out a new email the next time someone adds then. I think the interpretation of GDPR this particular instance of information storing is still open, but they have done everything possible to keep it safe. Should the list of hashes be leaked, the best an adversary can realistically do is check known emails against the list of hashes.