Live data from Hacker News

GDPR penalty for passing on of IP address to Google by using Google Fonts

rewis.io

511–520 of 656 posts

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#511
post #275

On the one hand I don't want lawyers, government and politicians to shape cyberspace. But I also like this ruling it seems to set a precedent for users to be able to opt-in to APIs (and probably javascript the obvious next step if this goes on). Client-server interactions should be transparent, this will prevent allot of privacy related issues. It also makes the web more decentralized, getting developers back into a…

It does not necessarily set a precedent: use of APIs hosted fully within GDPR countries would be unaffected by this Google Fonts judgment, which only concerns a GDPR site using non-GDPR resources without user consent.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#512

Can you someone translate? Does this mean that hot linking any static media or asset from a third party is against the law unless explicit approval from the user is first received?

No.

This means that embedding any resource from a non-GDPR destination URL is a violation of GDPR law unless explicit opt-in approval from the user is first received.

If you are subject to GDPR law, then the above applies to all sites owned and operated by you and your subsidiaries. If you are not subject to GDPR law, then the above does not apply.

Resources could be hosted by http:, https:, ftp:, or any other protocol. Resources could be .js, .gif, .html, or any other format.

If you’re asking “can I dynamically detect the user’s country of origin and enable GDPR protections only if I determine they’re in that country?”, no: the user has a right to legal protection if they are a citizen of a GDPR-protected country and are residing in a GDPR-bound country, regardless of what their IP address is.

(I am not your lawyer, this is not legal advice.)

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#513

Earlier quoted context omitted.

You don’t even need to host yourself the asset, just setup a reverse proxy that drops personal information and redirect the request to the source (Google, or whatever). It’s a simple Nginx rule.

Oh, super simple! The local bakery down the street just needs to figure out what a reverse proxy is, what a redirect is, and what Nginx is and how set rules for it, and then weigh the pros and cons vs self-hosting assets. I’m sure that’s easily doable for them, aren’t regulations fun?

No, the bakery’s _website provider_ should do that.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#514
post #111

Earlier quoted context omitted.

And they decided to pay? FFS… well, that was certainly educational. It has a very chilling effect on innovation no doubt.

You are doing Your Thing™ and the lawyers are doing Their Thing™, and you are both incompetent at the other one. The worst you could do to a lawyer is that maybe you could embarrass them about their lack of network engineering knowledge, but they in turn can extract real money from you through various means. Also defending oneself results in involving a different lawyer enriching lawyers as a whole anyways.

> maybe you could embarrass them about their lack of network engineering knowledge

I’m fairly certain it’s possible to do much worse to a laywer, especially a technically clueless one.

Defending oneself from a frivolous lawsuit (e.g. judge has already said ‘you can’t do that’) in a sensible country like Germany might not cost you anything.

Much, much more likely however, is that they wouldn’t go to court at all (because, you know, they would lose, and even if both sides pay their own cost they’d lose more money than they could potentially make).

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#515

Wait, what prevents the next court to say that the browser vendor is responsible for the leak ? Per default the browser is not asking the user if it's okay to download fonts from Google (or any resources from any another resources provider) after all.

Why is it not the author of your NIC driver who is responsible for the leak? Per default the driver isn't asking whether to send a packet to Google's IP address. Here's why: the driver is just doing what it's told to do. The responsible falls on the party who does the telling. If a website tells my browser to load resources from Google, it's not on my cpu or my nic or its driver or kernel or firewall or the browser.

Thank you for your comment but this point has already been invalidated. See https://news.ycombinator.com/threads?id=johnchristopher#3013... and replace "browser" with "NIC".

No need to backtrack.

> The website has delivered an HTML document. It's up to the user to do what he wants with it and follow links or not.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#516
post #460

Finally. Took them long enough. There is literally no other business reason for Google to maintain Google Fonts, but to augment its tracking insights. None. That's the sole purpose of the very existence of Google Fonts.

Oh come off it. There's a reason it's popular: it's useful. You can search for fonts and use them without having to host them yourself.

I argue for downloading fonts yourself and hosting them yourself: https://google-webfonts-helper.herokuapp.com/fonts

But let's not pretend that isn't an extra step that some people regard as unjustified.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#517
post #102

Earlier quoted context omitted.

Yeah, that's exactly the agency argument. It's not as if the plaintiff's browser is actually under control of the defendant, a user agent is not forced to follow the instructions that are contained in a website it requested on behalf of its user.

> not forced to follow the instructions Again, you're talking about an opt-out. GPDR (the law) requires an opt-in.

> Again, you're talking about an opt-out. GPDR (the law) requires an opt-in.

It is opt-in. You decided to use a browser that implements the full HTML spec. Just use a basic browser.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#518
post #499

Earlier quoted context omitted.

But there is nothing that prevents anybody to build a similar product but charging a fee for it. The payment being "user data" is the problem. Not the product in and of itself. If you are in the EU such a platform would probably need to be GDPR compliant. I'm sure there is a opportunity for a font market that fulfills your needs. It might not be easy but eventually studios like you will probably have to charge client…

With all due respect, your response doesn't make much sense. Google fonts is primarily a github repo with specifically licenced fonts. Google paid a lot of the artists and foundries behind these fonts for an open licence. Therefor there is no need to build a "similar product", when the existing one is alrady free as in free beer, without any hidden data-/ad-funding. We are are primarily a PRINT-MEDIA shop. Non of GDP…

Perfect than you can just continue to use Google Fonts as is.

I suppose Google does not pay artists and foundries out of the goodness of their hearts.

They pay them to earn money through user data. If this is illegal a different service will turn up eventually.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#519
post #320

Earlier quoted context omitted.

> even though the provider has nothing to do with the interaction I beg your pardon, but in this case "the provider" (website) has directly sent the user's browser to a third party (google fonts) by including an instruction in the code (HTML) that the provider has sent to the user's browser. The browser did not decide to contact google fonts all by itself; it was directed to do so by the provider. Arguing the provide…

I don't think you get the agency argument. Of course the request to the third party provider is causally related to the website sending the instructions. But while that is necessary for it to happen, it is not sufficient . The user agent's execution, on behalf of the user, makes it happen.

> I don't think you get the agency argument.

I do get that argument; I just don't think it holds any water.

If one hires a hitman to kill someone, that one may still be held accountable to manslaughter, even if that specific person didn't kill anyone themselves. It may also not matter how many degrees of separation are there between that person and the hitman: as much as putting a (Bitcoin) bounty on someone's head (with a "smart contract" or whatever) may be considered manslaughter, even if nobody knows who the actual hitman is.

"Agency" is not a magic get-out-of-jail card.

Also, one may try convincing a judge "Your honor, it's true that I wrote the code that encrypted the plaintiff's network and wrecked a havoc, but I did NOT execute it; the plaintiff could have instructed his CPUs to not execute my code"; I don't know if this argument would hold.

Finally, there might be a "reasonable burden" argument in this case. It's reasonable to expect that website builders would know how browsers/internet work. It's not reasonable to expect that website visitors (general populace) would know that. Hence, the burden of GPDR compliance is better put on the builders' shoulders, which is exactly what happened in this particular case.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#520
post #432
post #421

Earlier quoted context omitted.

You may not serve a website to german visitors from GCP at all, certainly not without getting consent first.

Does it mean Google, AWS, DigitalOcean, Cloudflare, Akamai, and everybody else (except Hetzner) are now outlawed in Germany? Because, as I said, I cannot ask for consent before serving the initial HTML, unless someone develops a magical IP-less protocol for delivering consent. I'm not sure if even Hetzner server is OK, it's still a third party even if Germany-based.

If we take another ruling [0] seriously, Hetzner is dicy only because they recently added a US datacenter. For the others, yeah.

You could rent colo, go with a friendly neighborhood hoster like uberspace or with something like Telekom Cloud (lol).

[0] https://www.taylorwessing.com/en/insights-and-events/insight...

Post reply on HN