Live data from Hacker News

Am I logged in or not? GDPR case study on the example of Chrome browser change

blog.lukaszolejnik.com

51–60 of 507 posts

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#51
post #6

I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…

> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.

Guess what - the old Internet created plenty of content for free, without incentive of monetization, yet people still did it. The Web has suffered greatly as a result of the bullshit mindset that just because you put something online, you are entitled to make money for it.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#53

Earlier quoted context omitted.

> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.

Don't create the content if you have such poor ethics and imagination that violating people left right and center is the only way you can sustain yourself. How many people even realize the extent and repurcussions of the information you are taking from them?

Generally it isn't the content creators doing this. It's the ad companies, as content creators are busy creating content and not advertising schemes. What is needed is ethical ad monitization choices.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#54
post #6

I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…

Yes, every website now asks for consent to "use cookies" because GDPR "requires us to to ask this". These are weasel words, there is absolutely NO NEED to ask for this. The word "cookie" occurs only once in the GDPR directive text, in a list of examples of personally identifiable data, next to "IP address". Yet no site ever asks me for permission to use my ip address, somehow. The GDPR does have a requirement to ask…

The cookie law predates GDPR by quite a bit doesn't it?

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#55

Earlier quoted context omitted.

> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.

Guess what - the old Internet created plenty of content for free, without incentive of monetization, yet people still did it. The Web has suffered greatly as a result of the bullshit mindset that just because you put something online, you are entitled to make money for it.

I think you need to rethink who's entitled here.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#56

Earlier quoted context omitted.

> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.

Guess what - the old Internet created plenty of content for free, without incentive of monetization, yet people still did it. The Web has suffered greatly as a result of the bullshit mindset that just because you put something online, you are entitled to make money for it.

Right, that’s why I specifically said “monetary incentive”. There will always be non-monetary reasons to create content.

Are you proposing that trying to make money using the internet is morally wrong? Or just that collecting user data is wrong? Or that collecting data without consent and a clear explanation is wrong? Because if the line is drawn at the latter, then that’s what GDPR is for, and so I don’t understand why people would be upset about having to click through a bunch of notices that try to make it clear how user data is being used.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#57
post #5

Please, Google, fix those mistakes soon, and avoid a PR fiasco.

Nobody really cares outside this tech bubble. There won't be a PR fiasco, because it's hard to explain why it's bad for a non techie end user.

"Google simplifies the login experience in Chrome", is essentially what's happening here and it's far from obvious how to sell it as a doomsday scenario as I read the mood correctly of many HN users.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#58

"apt-get install apache2" violates GDPR (logs IPs). It's not a difficult line to cross at all.

Lets try the law on this one:

Is the IP personal data for the GDPR? If I read the GDPR, the Debian foundation is not capable to pinpoint 1 person so it seems to me it is not (An ISP or someone receiving an IP to person mapping from them is something different):

  ‘personal data’ means any information relating to an
  identified or identifiable natural person (‘data subject’); 
  an identifiable natural person is one who can be
  identified, directly or indirectly, in particular by   
  reference to an identifier such as a name, an
  identification number, location data, an online identifier 
  or to one or more factors specific to the physical, 
  physiological, genetic, mental, economic, cultural or
  social identity of that natural person;
Furthermore, the Debian foundation has a legitimate interest in monitoring their machines and protecting them against attacks. Logs containing IPs are a common practice, so there is a legal base for processing IPs even if they would be personal data:

  processing is necessary for the purposes of the legitimate
  interests pursued by the controller or by a third party, 
  except where such interests are overridden by the 
  interests or fundamental rights and freedoms of the data 
  subject which require protection of personal data, in 
  particular where the data subject is a child.
All of this assuming they use the IP for apache logs only, and don't send these logs to third parties for data mining or whatever.

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#59
post #6

I think that currently pretty much every service, device and website violates the GDPR. The GDPR requires consent or some other legitimate reason to store data about a person. I see dark patterns everywhere. I never give consent. But I get tracked to death everywhere all the time. Even before I touch anything on a website, it plants dozens of cookies on my machine. But cookies are not even the problem. Fingerprinting…

> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.

Super-simple answer: it's the law (GDPR). Kopplungsverbot. Art. 7 (4) GDPR. End of story.

It says: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract. "

It's like a butcher shop saying "the meat could be free if we could only reduce our cost by not caring about hygiene".

Edit: oops, the methaphor doesn't work at all :-D

Re: Am I logged in or not? GDPR case study on the example of Chrome browser change

#60

Earlier quoted context omitted.

> He is not giving consent. He is just trying to get through this pile of nonsense to reach the content. Then don’t access the content? Why should the user get content that someone has worked to create without having to give anything in return (whether that’s in the form of payment or information). There would be no monetary incentive to create content anymore.

The faux-progressive modern perspective is to consider ostensibly true things as literally true.

Yeah, I’m confused about what you’re trying to say as well. I can’t tell if you’re in favor of or against my argument.
Post reply on HN