Live data from Hacker News

Implications of Global Privacy Control

developer.mozilla.org

41–50 of 50 posts

Re: Implications of Global Privacy Control

#41

Any takes on this from someone who knows about it?

I work as a Data Protection Officer, which is a legal role under GDPR, and am rather unimpressed by GPC. I could whine for a day, but among the most problematic issues: It's not clear if "Sec-GPC: 0" should be interpreted as: 1. "no" to collect personal data under GDPR consent; or 2. "objection" to collect personal data under GDPR legitimate interest or; 3. "no" to retrieving and storing data on a user device (e.g. c…

> Personally, I think we should simply fine the heck out of all websites until they all feature a "Reject all" button.

Personally I’m tired of cookie pop-ups on websites, a reject all button does nothing to solve the actual problem. If a users browser can somehow communicate the preference so we don’t need to click on pointless stuff then wouldn’t that be optimal?

Re: Implications of Global Privacy Control

#42

For a while now I have been adding a "sec-gpc: 1" header in the forward proxy (client/browser agnostic). Thus, at least one person is using it.

Maybe I can use the GPC header as a way to let advertisers track and target me with exciting offers. Perhaps they can create a "fingerprint" from the three headers I send: Host+Connection+GPC, as I request web pages with netcat or tcpclient through a localhost-bound TLS forward proxy. I use these clients on a daily basis for making HTTP requests. I read HTML with a text-only browser. I do not use DNS when requesting www pages. The needed IP addresses are stored in the proxy's memory. For some reason I never see any ads.

Unfortunately, the sec-gpc header does not seem to be working as I have not received any advertisements after I started using it. Perhaps I have to manually request the ads and send the telemetry since I am not using browser that auto-loads resources or runs Javascript. Maybe I need to put the IP addresses for the tracking and ad servers into the proxy's memory.

Meanwhile, I am missing out on whatever products, services and campaign drivel the advertisers might show to people who use netcat/tcpclient and send only three HTTP headers. No doubt all the online merchants using text-only e-commerce platforms must target some amazing offers to all the online shoppers using netcat/tcpclient.^1 Someday maybe I too can receive them.

1. IIRC, funnily enough, there is a commandline "e-commerce solution", i.e., online store, that has been shared on HN before, perhaps as joke.

Re: Implications of Global Privacy Control

#43
post #25

I'm an absolite outsider to this, I use edge and would use chrome if need be. It seems to me like mozilla appeals to paranoid users who don't pay for software and also don't want to see ads, and in exchange insane demands and revolt is placed upon them. One thing you learn when providing services is that the demands don't ever stop. The more you provide for free, the more demands you get. Would not want to be in this…

Tracking is not synonymous with ads. Advertising was big business back when you had to just put a jingle on the airwaves or paint a billboard and trust that the right demographic would happen on it. It is plenty possible display ads and make money from them without invasive tracking, for example duck-duck-go does so. On the other hand if you do not fight tracking, paying for the service is no defense, they will just double-rip every time, triple dip if they think they can slot ads in.

Re: Implications of Global Privacy Control

#44
post #7

The article ignores that the DNT header already had some regulatory backing, as in court decisions saying it ought to be respected. https://www.datev-magazin.de/nachrichten-steuern-recht/recht... references such a decision against LinkedIn. Instead of using that, this new proposal seems to be exactly the same thing, just with more work for website hosters (having to add nonsensical files to /well_known/) and claims t…

DNT failed because advertising and online stalking companies refused to abide by it when browsers enabled it by default. The GPC spec tries to work around this by having the spec disable the feature by default. This new spec is necessary because American legislation requires opt-out signals not to be the browser default. That means DNT, as browsers used it, is not legally an opt-out signal, because browsers default t…

[deleted]

Re: Implications of Global Privacy Control

#45

Earlier quoted context omitted.

DNT failed because advertising and online stalking companies refused to abide by it when browsers enabled it by default. The GPC spec tries to work around this by having the spec disable the feature by default. This new spec is necessary because American legislation requires opt-out signals not to be the browser default. That means DNT, as browsers used it, is not legally an opt-out signal, because browsers default t…

Wasn't this just microsoft back in the day that enabled it by default, and they were already a small player at that point (Chrome was the leader and even Firefox had more market-share back then iirc). In other words: "browsers" didn't make it the default, one small browser did. And so if _any_ browser, whatever tiny percentage they might have of the market, will make this new proposal the default, advertisers can aga…

Internet Explorer's market share was a little more to a little less than Chrome's in mid 2012. It was the only significant browser to enable Do Not Track by default as far as I know.

Advertisers wouldn't have cared until laws forced them to care. Microsoft enabling it by default ensured there would be no laws.

Re: Implications of Global Privacy Control

#46
post #8
post #4

> The main problem with DNT was the lack of legal and regulatory backing it received. Website owners could decide if they'd observe the DNT signal and there were no legal repercussions if they chose not to. This is where GPC is different. This sounds like an attempt to regulate the entire internet.

So what do you refer to all the other stuff that is accepted as "the internet" but is not websites?

... the internet? I get the impression you're trying to ask something that you haven't articulated. I don't know why it'd be assumed that this approach will stop at websites.

Re: Implications of Global Privacy Control

#47

Earlier quoted context omitted.

Wasn't this just microsoft back in the day that enabled it by default, and they were already a small player at that point (Chrome was the leader and even Firefox had more market-share back then iirc). In other words: "browsers" didn't make it the default, one small browser did. And so if _any_ browser, whatever tiny percentage they might have of the market, will make this new proposal the default, advertisers can aga…

Internet Explorer's market share was a little more to a little less than Chrome's in mid 2012. It was the only significant browser to enable Do Not Track by default as far as I know. Advertisers wouldn't have cared until laws forced them to care. Microsoft enabling it by default ensured there would be no laws.

You are right, my memory was off by a few years. In 2012 Chrome first overtook IE, in 2014 Safari overtook them, in 2015 they crossed 10% and by the end of 2016 dropped under 5%.

Microsoft's final gift to advertisers before dropping of into obscurity.

Re: Implications of Global Privacy Control

#48
post #17

these web frameworks for privacy always give me a chuckle. DnT didnt work, why would this? Advertising is an economy worth more than 7.4 trillion USD. it has evaded most attempts to regulate or restrict it in any meaningful sense in the 21st century. the GDPR serving as a bureaucratic organ to which advertisers must subscribe, or quietly ignore with all but the most modest and encumbered window dressings for the illu…

> there exists no fine that can tame it

This seems like an argument against either democracy or capitalism. Either we can never vote in lawmakers that would fine these companies into oblivion or there is no fine large enough that they would be compelled to change their ways.

Which one is it?

Re: Implications of Global Privacy Control

#49

This article is intentionally misleading: The main problem with DNT was the lack of legal and regulatory backing it received. Website owners could decide if they'd observe the DNT signal and there were no legal repercussions if they chose not to. This is where GPC is different. .... What to do when receiving a GPC signal It's up to the developer/business to decide how to treat the signal, for example, removing the us…

> CCPA only applies in Europe

CCPA applies in california, not europe. It's in the name: "California Consumer Privacy Act". Did you mix that up with GDPR?

> forcing users into sharing information with the site to be allowed to access the site

One of the CCPA rights are "Not be discriminated against for exercising their privacy rights". Denying access would almost certainly be classified as discrimination.

Re: Implications of Global Privacy Control

#50
post #22

> The GPC signal will be intended to communicate a Do Not Sell So, there is no tracking opt-out like DNT had. Do Not Sell is classic regulatory capture: It allows incumbent players to continue their current bad behavior, and directs revenue streams from smaller players (data brokers) to existing monopolies. Also, this opt out won’t interfere with Mozilla’s recently acquired ad business, which uses user data to sell a…

"Tracking" is pretty vague and trying to stop it is just unenforceable, unlike "selling personal information" which is very clear and what GPC and the CCPA and GDPR cover. I often criticize Mozilla but they're correct in replacing unenforceable DNT (which is also worse fingerprinting-wise since it has three possible values instead of being a binary on-off signal) with GPC. It's long overdue.
Post reply on HN