I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…
> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.
Am I logged in or not? GDPR case study on the example of Chrome browser change
51–60 of 507 posts
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#52"apt-get install apache2" violates GDPR (logs IPs). It's not a difficult line to cross at all.
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#53Earlier quoted context omitted.
> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.
Don't create the content if you have such poor ethics and imagination that violating people left right and center is the only way you can sustain yourself. How many people even realize the extent and repurcussions of the information you are taking from them?
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#54I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…
Yes, every website now asks for consent to "use cookies" because GDPR "requires us to to ask this". These are weasel words, there is absolutely NO NEED to ask for this. The word "cookie" occurs only once in the GDPR directive text, in a list of examples of personally identifiable data, next to "IP address". Yet no site ever asks me for permission to use my ip address, somehow. The GDPR does have a requirement to ask…
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#55Earlier quoted context omitted.
> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.
Guess what - the old Internet created plenty of content for free, without incentive of monetization, yet people still did it. The Web has suffered greatly as a result of the bullshit mindset that just because you put something online, you are entitled to make money for it.
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#56Earlier quoted context omitted.
> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.
Guess what - the old Internet created plenty of content for free, without incentive of monetization, yet people still did it. The Web has suffered greatly as a result of the bullshit mindset that just because you put something online, you are entitled to make money for it.
Are you proposing that trying to make money using the internet is morally wrong? Or just that collecting user data is wrong? Or that collecting data without consent and a clear explanation is wrong? Because if the line is drawn at the latter, then that’s what GDPR is for, and so I don’t understand why people would be upset about having to click through a bunch of notices that try to make it clear how user data is being used.
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#57Please, Google, fix those mistakes soon, and avoid a PR fiasco.
"Google simplifies the login experience in Chrome", is essentially what's happening here and it's far from obvious how to sell it as a doomsday scenario as I read the mood correctly of many HN users.
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#58"apt-get install apache2" violates GDPR (logs IPs). It's not a difficult line to cross at all.
Is the IP personal data for the GDPR? If I read the GDPR, the Debian foundation is not capable to pinpoint 1 person so it seems to me it is not (An ISP or someone receiving an IP to person mapping from them is something different):
‘personal data’ means any information relating to an
identified or identifiable natural person (‘data subject’);
an identifiable natural person is one who can be
identified, directly or indirectly, in particular by
reference to an identifier such as a name, an
identification number, location data, an online identifier
or to one or more factors specific to the physical,
physiological, genetic, mental, economic, cultural or
social identity of that natural person;
Furthermore, the Debian foundation has a legitimate interest in monitoring their machines and protecting them against attacks. Logs containing IPs are a common practice, so there is a legal base for processing IPs even if they would be personal data: processing is necessary for the purposes of the legitimate
interests pursued by the controller or by a third party,
except where such interests are overridden by the
interests or fundamental rights and freedoms of the data
subject which require protection of personal data, in
particular where the data subject is a child.
All of this assuming they use the IP for apache logs only, and don't send these logs to third parties for data mining or whatever.Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#59I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…
> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.
It says: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract. "
It's like a butcher shop saying "the meat could be free if we could only reduce our cost by not caring about hygiene".
Edit: oops, the methaphor doesn't work at all :-D
Re: Am I logged in or not? GDPR case study on the example of Chrome browser change
#60Earlier quoted context omitted.
> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.
The faux-progressive modern perspective is to consider ostensibly true things as literally true.