Live data from Hacker News

No Cookie for You

github.blog

441–450 of 634 posts

Re: No Cookie for You

#441
post #174

Earlier quoted context omitted.

Yes! If you use cookies for essential functionality (like keeping track of logged in status), you don't have to do anything. No banners, no annoyance for your users. I dropped all third-party crap from my site way back and haven't ever needed a cookie banner.

How long can you keep people logged in before it becomes the bad kind of tracking?

Depends only on whether the fact that they are logged in is used to process any kind of personal data.

The question is not "how long". The question is what data, and what happens to it.

Re: No Cookie for You

#442
post #434

Here's a cookie set in my browser from github in a fresh browser: Cookie: _gh_sess=eAAHHEQEjZlQKwq8kaSMpTeHC7tyMGwhVexbpZMVfDbjWCf764z4UMG7S%2FeLZpE0ML5y8%2FnmSEd2ZhiDLBHlZyA08Dj8cGob%2BGXSbGSjztMyc5pdd8uxj8qgxc78SHYw01E6pnOnWHRo7XoeTjKje%2FktOx5wObpjZj8JhfOnngdIlhfxSc1EctIth6RDFIsr2HPw9pbDczMfDwwKuswMrkMIt1JEOglF2L%2BxAdscMjeuXu2zFei58AR%2FwRQ%2FGgY3RbQigWt2w%2BKHDIY7a6pISw%3D%3D--H9M6LNV7YPDc1Dvm--vbgFN9CpCkCxTdfhd…

How is that opaque string any different than any shorter, random string that uniquely identifies the user such as "da39a3ee5e6b4b0d3255bfef95601890afd80709"? They can store whatever data they want in the session store in the backend.

They could just store certain variables explicitly like they do for these ones: logged_in=no; tz=America%2FLos_Angeles

It could get rather big of course. They could not store sessions on the backend for anonymous users.

Re: No Cookie for You

#443
post #140

Earlier quoted context omitted.

And when people want analytics they often just really want headline numbers that do not require user tracking. E.g. I've started using Fathom [1]. It's very basic, but for the sites I use it on all I really want to know is if traffic is going up or down or if any specific pages are suddenly getting lots of traffic. [1] https://usefathom.com

No pricing page, and jesus, not even a menu. They want us to sign in before they'll show us pricing? fuck right off with that bullshit.

The pricing page [1] is linked further down, and from the sitemap at the bottom of the page. You have a point they should have made it more obvious though.

https://usefathom.com/pricing

Re: No Cookie for You

#444

Earlier quoted context omitted.

I would like to add https://pirsch.io/ :)

This looks really nice, but what’s to stop it getting blocked like all the other trackers once apple/uBlock/etc. add it to their database?

You cannot stop that. You can get around it for a while by serving the script yourself and setting a CNAME record for your domain to point to us. That's why we recommend integrating Pirsch into your backend so that it can't be blocked: https://docs.pirsch.io/get-started/backend-integration/

Re: No Cookie for You

#445
post #324

Somehow the rest of the internet was sold to the idea of "EU is forcing you to put cookie banners, these are nothing but annoyance" rhetoric. Whoever pulled that off, bravo! In reality, the idea was to make people aware that they are being tracked across the web and and give them options and somehow everyone pretended that "No tracking, no banners" is not an option. I am so glad that GitHub is coming forward and poin…

I think you mean "you don't need cookie banners if you have your own identifier" which they certainly do and affords them the luxury of this blog post.

And add to that, they have paying customers.

Re: No Cookie for You

#446
post #24

Earlier quoted context omitted.

True. Also even if you do track your visitors you can use privacy friendly (and ideally selfhostable) Analytics like Plausible https://plausible.io/ so you won't need the banners either. Just don't include facebook like buttons or any of these widgets

Does anyone happen to know of a service like this that is free (not self hosted) for non-commercial, low-traffic sites? Or which costs less than ~$10 per year. I have a basic Github Pages site, and I currently don't know whether anyone is looking at it, beyond the very few who take the time to email me. I don't need (or want) to know anything about my visitors, but it would be nice to know that I'm not simply tossing…

> Does anyone happen to know of a service like this that is free (not self hosted) for non-commercial, low-traffic sites?

Panelbear is privacy-friendly, and has a free plan with 5,000 page views per month. Commercial use is allowed.

https://panelbear.com

Full-disclosure: I’m running this service. Feel free to ask me anything :)

Re: No Cookie for You

#447

This is fantastic. Thank you, GitHub. I hope this is a good demonstration of a hands-off approach at Microsoft in regard to company culture. I realize you likely still collect some analytics for yourself and that this change does nothing to alleviate that. EG, first party javascript. But it's great that it's divorced from 3rd parties. Presumably Microsoft has access to those metrics, though? I wonder how deeply that…

GitHub still sends the same personal data to their own analytics endpoint, and the privacy policy which lists third-party data subprocessors [1] has not been updated. See my comment below for details: https://news.ycombinator.com/item?id=25458635 Tracking cookies have little value for GitHub when they can collect data about users that have already been authenticated, and they send the username and user ID as part of…

A GitHub spokesperson has issued this statement [1] about a request to api.github.com: "That endpoint tracks aggregate performance metrics, and does not rely on cookies or other unique identifiers".

GitHub is still sending our usernames and other unique IDs, our device data, and the pages we visit to the collector.githubapp.com endpoint.

GitHub's claims about not tracking users are false, they do identify users in tracking requests. See this tracking URL, it's full of unique identifiers and personal data, and it is currently sent after every page load, without user consent:

  https://collector.githubapp.com/github/page_view?dimensions[page]=https://github.com/&dimensions[title]
  =GitHub&dimensions[referrer]=https://github.com/sessions/two-factor&dimensions[user_agent]=Mozilla/5.0 
  (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0&dimensions[screen_resolution]=1000x518&dimensions[pixel_ratio]
  =1&dimensions[browser_resolution]=1000x518&dimensions[tz_seconds]=0&dimensions[timestamp]
  =1608247177900&dimensions[referrer]=https://github.com/sessions/two-factor&dimensions[request_id]=
  9CF8:4938:4516EA:5FD134:5FDBE77E&dimensions[visitor_id]=6475638196559144773&
  dimensions[region_edge]=fra&dimensions[region_render]=iad&&measures[performance_timing]=
  1---600-600-600-400-400-----600-0----1608247177200--1608247176900--1608247176900--400- 
  400&&dimensions[actor_id]=47727044&dimensions[actor_login]=dessantbot&dimensions[actor_hash]=
  a274a9ae03a3b361483e273a53aba70534c609670c058fe667d8bce4d6f33bad&dimensions[cid]=1507727009.1608247109
[1] https://www.theregister.com/2020/12/17/github_will_no_longer...

Re: No Cookie for You

#449

Earlier quoted context omitted.

Probably like we do it for pirsch.io, by calculating a hashed fingerprint and throwing away the individual page hits once per day: https://github.com/pirsch-analytics/pirsch

What's the privacy benefit over storing a tracking cookie with expiry of a day? If at all, random cookie seems better for privacy as in your case if someone really wants it, they can recover the IP if the user agent is not rare by searching for all IP(4 billion IPv4), User-Agent(100 for popular browsers), the date(1 day as date is stored separately), and a salt(known to server), easily within reach of anyone.

It doesn't use cookies. Fingerprints are calculated on each page hit.

The salt must be treated like a password to make sure it's not that easy to brute force it and no one should get access to your database of course ;) It's not the strongest anonymization, but good enough considering that the hits will be deleted once a day by batch processing.

Re: No Cookie for You

#450
post #342

Earlier quoted context omitted.

I presume this is indeed what they're doing given the wording of the post: "(And of course GitHub still does not use any cookies to display ads, or track you across other sites.)" That exactly leaves out "track you on our own site". But honestly, I have absolutely zero issue with them tracking my behavior on their own site. I know how valuable it is to be able to learn/see what users are doing, and they should absolu…

Tracking individual behaviour on their own site without notification is still illegal under the GDPR, so no, they should not absolutely be able to do that.

[deleted]
Post reply on HN