Live data from Hacker News

GDPR penalty for passing on of IP address to Google by using Google Fonts

rewis.io

461–470 of 656 posts

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#461
post #340

Earlier quoted context omitted.

It's loading fonts. So squarespace needs to host those fonts, fine. But more to the point, it could be argued even the Squarespace CDN is "different" from the actual website, so we need CDN shims that forward local domain requests to the CDNs and return the results. All to hide an IP number for downloading fonts." Moreover, "host it yourself" is easy if you're technically skilled, but very, very difficult if you aren…

Technical skill is kind of a requirement if you want to achieve something that's technical by nature - such as website development or web hosting. And hosting a font file entails dumping it next to your index.html file and adding some very basic CSS. Not exactly difficult.

> And hosting a font file entails dumping it next to your index.html file and adding some very basic CSS. Not exactly difficult.

If you are a 60-year-old woodworker living in Appalachia trying to set up an online store to sell hand-carved flutes, this task is essentially impossible.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#463

Earlier quoted context omitted.

>> This is exactly what happened... Not quite? Wouldn't the users browser have sent its own IP address to Google? That's different that "forwarding" it, and it may not even be enough for Google to connect the user to that site.

Yes, but the website ordered your browser to contact Google without informing you, for no obvious purpose. That's not exactly how consent works.

[deleted]

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#464

Earlier quoted context omitted.

I too was pissed about the popups until I realized it the companies throwing up the popups that are to blame. Hosting all your assets by yourself, on your own servers and doing analytics without sending data to a third party is not a terribly tall order.

Actually, your comment made me wonder how far does this go? Where does "third party" end? If I self host on Hertzner or Linode, I imagine their infrastructure logs IP addresses like Google Fonts here. But surely that doesn't require consent. Why not, what's the difference? What if you host with a much sketchier provider? I could see politicians thinking users would want to know if their requests were served by, say,…

With Hetzner you can get a GDPR compliant Data Processing Agreement (DPA) when using them for hosting.

https://www.hetzner.com/news/vertrag-zur-auftragsverarbeitun...

It's ok that their infrastructure logs IPs that it has to. They commit via their DPA to protecting personal data such as embedded in those logs, not logging what they don't need, not keeping it longer than necessary, only sharing it with third parties that agree similar protections, anonymising and aggregating as needed, etc.

You probably want an agreement like that with a hosting provider for another reason, not just IP logging: They have physical access to all your on site storage, user databases, etc. It's good that they commit to treating data on those physical systems with appropriate respect.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#465

Earlier quoted context omitted.

Yes, but the website ordered your browser to contact Google without informing you, for no obvious purpose. That's not exactly how consent works.

The web site did no such thing -- it served up a document that contained the reference. It is the end user that CHOSE to delegate interpretation of that document to a web browser (ad a counter example, look at how RMS browses the web). Yes this is less practical. But since the decision only deals with what is "possible", then logically it should be fully consistent. Now from a practical standpoint, I'd like to see a…

It strikes me that this is exactly the same scenario, in reverse, that we have with people being convicted of "hacking" a website by entering a URL that wasn't supposed to be exposed. Things like "consent" and "authorization" are murky when we delegate our will to computer programs like browsers and servers.

If URL "hacking" is illegal, then we have decided as a society that persuading a piece of software to do something does not equate to informed consent on the part of the person operating it (and by extension that we're meant to make some sort of guess as to what they do intend).

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#466
post #455
post #369

Earlier quoted context omitted.

Not a lawyer, but to my knowledge, GDPR does not care if something technically "can be blocked" with some effort. It cares if there was clear, voluntary consent to share a particular bit of data - which wasn't the case here.

Then GDPR should blame the browser vendors for shipping with JS execution enabled by default and demand that JS execution for all browsers be turned off by default. To repaint the stories spun by the grand parents: If I hold up a dagger and announce the fact, why would you run into the dagger anyway without protection? Put on some armor, dude. The client browser had all the information it needed to not make the reque…

Would you serve users who have disabled JavaScript?

> If I hold up a dagger and announce the fact, why would you run into the dagger anyway without protection? Put on some armor, dude.

That's really your position? If people get stabbed, it's their fault, everyone should just put on armor when they leave the house?

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#467

Reductio ad absurdum: if serving fonts from Google is “unnecessary” and leaks information, so would be using any CDN service to deliver any content.

Yes. Fuck CIA^H^Hloudflare.

Care to elaborate?

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#468

Hopefully we won't see popups like "This site will forward your IP address to Google is that OK?", because I'm already beyond bored with "This site uses cookies do you accept?".

On the other hand, there was a post on the front page recently that said that showing opt-in 3rd party cookie prompts resulted in over 90% refusal rate.

Ignorance is a bliss, but if given a choice to not share extra info with random companies, many will in fact take that opportunity.

So a popup warning that your visit to this website will be recorded by Google may be just what the doctored ordered to shake people of their nirvana and make them look at things a bit more closely.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#469
post #262

Earlier quoted context omitted.

This case is about IP address exposure, not cookies. This would still happen. So everyone showing youtube videos would be affected unless users also start agreeing to IP exposure… this could probably be avoided by extending the sites terms.

I see quite a few web pages in Germany that do not load JavaScript or any other content from YouTube,Twitter, Facebook until you explicitly opt in. Basically, the content is replaced by a placeholder saying “click here to load external content from.” - it’s technically not very hard to do so, and I quite like it. I don’t need to be tracked by any of those entities everywhere I go. Tracking and creating profiles is on…

> it’s technically not very hard to do so, and I quite like it

For the average user, it's yet another thing to click without thinking, just to be able to visit a page.

> Consent is required before exposing the IP address and is must be explicitly given

There's the crux of the problem, it's difficult to know what to consent for without first displaying the website, so you implicitly give consent for "just the bare minimum", until you accept the rest. This sounds great, but is both an absolute nightmare for website developers (it's not very easy to do, with how the internet was designed, inline scripts, fonts, CDN stylesheets) and for "most" end-users who just expect good defaults and don't want to sign a consent form every time they visit a website.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#470
post #460

Finally. Took them long enough. There is literally no other business reason for Google to maintain Google Fonts, but to augment its tracking insights. None. That's the sole purpose of the very existence of Google Fonts.

If you've ever had the pleasure of dealing with the licensing nightmare of foundries, it's quite easy to see that a small group within google had enough and started the project.

We've literally spend tens of thousands of dollars on our font archive, but decided that we can't continue to use these fonts on projects anymore, due to "we can change the licence at any time" clauses and rent seeking behaviour, that is eerily similar of the stock photo industry licensing (which pretty much has ruined photographers) and scientific publishers (which pretty much have ruined science).

I hate google as much as the next guy, but our small design company is in their dept for creating google fonts, and we plan on contributing to the the repository if we ever create a font as part of a project.

Post reply on HN