Live data from Hacker News

GDPR penalty for passing on of IP address to Google by using Google Fonts

rewis.io

51–60 of 656 posts

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#51

Earlier quoted context omitted.

yes. That's a fact. A 3rd party is a 3rd party and a website leaks it's visitors to it. Just don't do it but serve your stuff from your domain.

Doesn't this attitude overlook the "agency" of the "User-Agent"?

Yeah, the plaintiff's browser made the request after all, no?

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#52

Earlier quoted context omitted.

yes. That's a fact. A 3rd party is a 3rd party and a website leaks it's visitors to it. Just don't do it but serve your stuff from your domain.

Doesn't this attitude overlook the "agency" of the "User-Agent"?

What does the browser's user agent have to do with this?

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#53

Earlier quoted context omitted.

yes. That's a fact. A 3rd party is a 3rd party and a website leaks it's visitors to it. Just don't do it but serve your stuff from your domain.

Doesn't this attitude overlook the "agency" of the "User-Agent"?

Isn't regulation precisely the act of acting in behalf of the citizens because they are seen as "too stupid" to know what they are doing?

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#54

So an HTTP GET request to another domain (fonts.googleapis.com) "leaked" website visitor's IP address to Google. What the hell? Google Translate: https://rewis-io.translate.goog/urteile/urteil/lhm-20-01-202... > The defendant is sentenced to pay the plaintiff €100.00 > The plaintiff has a claim against the defendant to refrain from passing on the plaintiff's IP addresses to Google under Section 823 (1) in conjunction…

[deleted]

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#55
post #4

The reasoning behind this judgement is: The services (here: web fonts) could be supplied another way, so exposing the user's IP to google is not strictly necessary, from a technical POV. The user's IP is PII, and exposing it unnecessarily to third party is a GDPR violation. The way this is phrased, the reasoning applies to basically every static resource loaded from a CDN or other third-party website.

This seems logical and reasonable to me, though it seems others are surprised/appalled. What would a technical solution that respects privacy look like? The website making the call to Google in the background (minus user details) and forwarding the response onward? Why isn't it done that way, it feels like it's the more obvious solution if you're not trying to track users. Early internet was very wary of 'hotlinking'…

I think one of the main reasons it is done via hotlinking is that it is easier for the „webmaster“ to copy a JS snippet than to do something server side or self host. Most of these webmasters aren‘t developers.

This is particularly true for anything that comes as a „module“, like GDPR cookie notices (that are very frequently included via a JS snippet loaded from a third party site).

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#56
post #23

So an HTTP GET request to another domain (fonts.googleapis.com) "leaked" website visitor's IP address to Google. What the hell? Google Translate: https://rewis-io.translate.goog/urteile/urteil/lhm-20-01-202... > The defendant is sentenced to pay the plaintiff €100.00 > The plaintiff has a claim against the defendant to refrain from passing on the plaintiff's IP addresses to Google under Section 823 (1) in conjunction…

Why "what the hell"? This is exactly what happened, and a logical consequence the moment IP addresses are classified as private data. Which it is in a system where it can be used to find the civil identity of the user, which is the case in Germany via Vorratsdatenspeicherung and the rampant misuse of the legal system. Note how the decision contains the question of whether leaking the IP was necessary. They noted it i…

Look and learn from Yubico, they don’t show any YouTube embedded videos until you agree to functional cookies:

https://www.yubico.com/?lang=sv

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#57
post #34
post #6

german law doesn't really know "precedent cases". However it looks like a whole new industry of lawyers sueing pages embedding stuff could arise...

Leaking customer data to Cloudflare is also a very interesting question here.

They seem to count CDNs as "hosting providers" and yes, without the necessary legal frameworks in place, this is also a problem if that leaks user data: https://www.technologylawdispatch.com/2021/12/privacy-data-p...

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#58
post #34
post #6

german law doesn't really know "precedent cases". However it looks like a whole new industry of lawyers sueing pages embedding stuff could arise...

Leaking customer data to Cloudflare is also a very interesting question here.

If your website requires CF to reliably deliver data to customers, then it’s unlikely to cause much of a stir.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#59
post #31

Earlier quoted context omitted.

Running a website in Germany seems like a god damned nightmare: https://allaboutberlin.com/guides/abmahnung-creative-commons

That specific scam does not have to work anymore though. Abmahnungen in Germany are the most stupid and lawyer serving system in the world, but the CC image scam got closed by judges deciding no monetary harm was done. Possible that these lawyers are still trying, but note that the article started 2018.

Do you have a link. I read that recently this specific scam was picking up steam in the US and was concerned about the implications here in Germany.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#60

Hopefully we won't see popups like "This site will forward your IP address to Google is that OK?", because I'm already beyond bored with "This site uses cookies do you accept?".

Go to uBlock Origin settings and check every item in the 'annoyances' list. I haven't seen a single cookie banner for a few years now.

(This is assuming you're using uBO, because who the hell isn't these days?)

Post reply on HN