Live data from Hacker News

No Cookie for You

github.blog

611–620 of 634 posts

Re: No Cookie for You

#611

Earlier quoted context omitted.

Hi! Please also look into the collector.githubapp.com analytics endpoint, the request does not seem to be compatible with GDPR in its current form. Either unique IDs tied to the user will have to be removed, or express consent will have to be requested. https://news.ycombinator.com/item?id=25461825

This is just not true. See my comment elsewhere in this thread: Why is it not GDPR compliant. You do not need consent under the GDPR. You need a (documented) "lawful basis for processing" personal information. Consent is just one of several lawful bases and honestly it's the most useless one, if you need consent your business model is screwed. It's perfectly possible for GitHub to process personal information without…

1) consider analytics part of the "contract legal" basis, arguing that analytics to improve the usability of the website is a fundamental part of running a website.

Sure, you can argue that, but it has no merit.

The only reason that you can write that sentence with a straight face is due to the current affairs of the web. You know the thing that GDPR tries to rectify.

And analytics do not need personally identifiable information.

Try the three-part test suggested here: https://ico.org.uk/for-organisations/guide-to-data-protectio...

Purpose test: You can argue it has legitimate interest. And with a big enough loop-hole it might even pass despite it having no merit.

Necessity test: Absolutely not.

Balancing test: No chance.

Re: No Cookie for You

#613
Visiting https://github.com on a clean browser profile results in these cookies being set:

    _gh_sess "2RS32uKu1a6pH8js1RreBWXcr4EdQMHXr/6PdyOeH7tgLbeIdxTaYni5fcFWff4wXTvqv8+lSeJ2W0RWHu0hgN4toFeR8B22x/HGuIx6gdIi4dvd2xQ4gtnuvhBVLTwnYjNGNcnT7ODFlerX+Li9HL33KXUvP/LDMlXTxCP+sJycF1x83Wqh8r2JFTGpcKgaQ22maisp6gfNVJI6MLnFQrKu/LxnuuMfPcVHzCEBjxDejJ/19ucDUVGnZ5LwP4JGTp1+RumiuA8MPxUTaktbLg==--TmIIVNRcipKqc2yt--6HedWH9JiNkUgNKKyGf30A=="
    _octo "GH1.1.1254465225.1608314039"
    logged_in "no"
The article is written in a way that we assume that they're not using any cookies unless necessary, but it seems that the actual implication is that they've re-categorised these cookies as "essential".

Re: No Cookie for You

#614

Earlier quoted context omitted.

A GitHub spokesperson has issued this statement [1] about a request to api.github.com: "That endpoint tracks aggregate performance metrics, and does not rely on cookies or other unique identifiers". GitHub is still sending our usernames and other unique IDs, our device data, and the pages we visit to the collector.githubapp.com endpoint. GitHub's claims about not tracking users are false, they do identify users in tr…

this isn't about tracking users, it's about cookies. no cookies doesn't mean no tracking. it's just a workaround to improve UX. "visiting our website does not send any information to third-party analytics services" - but presumably third parties are still able to access this data on request. their privacy policy probably reflects this. if you visit a website and don't want to be tracked, make it as hard as possible f…

Don't confuse "we don't set cookies" with "we don't set non-essential cookies".

They say no "non-essential" cookies, but an anonymous user just landing on the homepage gets a cookie with some unique-looking tokens.

I've seen many companies just hire the right lawyers that would sign off on all sorts of tracking cookies as "yeah, this is essential, since we can't track users without it, and tracking users is essential to our business model".

Re: No Cookie for You

#615
post #574
post #515

Earlier quoted context omitted.

No, it absolutely does not "[apply] to anyone anywhere processing personal information of people inside the EU." I don't know why people keep saying this, I have no idea where this misconception came from. https://ec.europa.eu/info/law/law-topic/data-protection/refo... >When the regulation does not apply >Your company is service provider based outside the EU. It provides services to customers outside the EU. Its clie…

Recital 23 of the GDPR provides some more information about when an organisation would be considered as targeting users in the EU: "In order to ensure that natural persons are not deprived of the protection to which they are entitled under this Regulation, the processing of personal data of data subjects who are in the Union by a controller or a processor not established in the Union should be subject to this Regulat…

The EU can say this all they want, but the reality is it has zero teeth for any organization conducting business outside the EU, with no actual presence in the EU.

EU laws simply do not apply to the world, even if the EU thinks they should.

Re: No Cookie for You

#616
post #607
post #570

Earlier quoted context omitted.

I accept but don't save any cookies except certain whitelisted ones. So I get a lot of cookie policy banners and I always click the full 'accept all' option because at best it'll just eat into their database storage and I'll arrive with no stored cookies the next time I visit the site. The browser allows me to accept all cookies or non-third-party cookies automatically but I still get these stupid cookie policy banne…

> I accept but don't save any cookies except certain whitelisted ones. That's basically what happens in private mode (incognito), I guess. Would be nice if browsers used private mode by default, and you could "whitelist" certain sites you trust / want to remember your login.

This is not what most people would like. But you can tell your browser not to save any cookies except some whitelisted sites, e.g. in Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Plat...

Re: No Cookie for You

#617
post #586

Earlier quoted context omitted.

Just install this extension: https://www.i-dont-care-about-cookies.eu/

Sure, there exists an extension for pretty much everything, but it's not an ideal situation that you need to install an extension for stuff like this. Also, having too many extensions slows down the browser (because they need to parse/manipulate DOM) and extensions themselves are also a security/privacy risk and finding the good ones for every browser can be tedious. Besides, my mom has no idea what's "a browser exte…

So tell her what it is :)

Most people just need one extension: uBlock Origin (or built-in Opera/Brave adblock) with a filter list from prebake.eu. No more ads and cookie banners. Easy as that.

Re: No Cookie for You

#618
post #615
post #574

Earlier quoted context omitted.

Recital 23 of the GDPR provides some more information about when an organisation would be considered as targeting users in the EU: "In order to ensure that natural persons are not deprived of the protection to which they are entitled under this Regulation, the processing of personal data of data subjects who are in the Union by a controller or a processor not established in the Union should be subject to this Regulat…

The EU can say this all they want, but the reality is it has zero teeth for any organization conducting business outside the EU, with no actual presence in the EU. EU laws simply do not apply to the world, even if the EU thinks they should.

> The EU can say this all they want, but the reality is it has zero teeth for any organization conducting business outside the EU, with no actual presence in the EU.

Perhaps not, but the EU is the world's second-largest economy (only $2tn behind the US and $4tn ahead of China) accounting for about 1/5th of the global economy.

If one wants to operate a company that does international business, one will probably want to do business in the EU, which means following EU law in such matters.

Re: No Cookie for You

#619

(GitHub CEO) Hi everyone, thanks for all the enthusiasm about this change. We are happy to have removed cookie banners from GitHub, and not to participate in third-party tracking of user behavior. Our privacy policies and subprocessor list will be updated next week following our customary 30 day user notice period. We do this in the open in a pull request, so you can see the changes now: https://github.com/github/sit…

> We are happy to have removed cookie banners from GitHub

I'm a regular visitor to GitHub from the EU, most of the time not logged in and in private browsing mode, so I usually appear like a completely new entity that hasn't consented to anything. I only started noticing cookie banners on GitHub in the last month or two.

So... in the past, did you not have cookie banners because you didn't have tracking cookies until recently, and all this is a big publicity stunt? Or were you breaking the law up until a month or two ago by having tracking cookies but not asking for my consent?

Re: No Cookie for You

#620
post #545

I wish browsers had built-in mechanism for showing the cookie banners. After all, cookies are just an HTTP header sent from server and it's up to the user-agent to handle it. There could be a standard header such as cookie-privacy-policy which would point to url containing the policy in standadrd format (html?) and the browser could show it in standard way (by user's settings). Personally I would be happy with just a…

Back in the days there was the P3P protocol ( https://en.wikipedia.org/wiki/P3P ) supported by IE and Edge, but it didn't work out and was abandoned. There is also `Do Not Track` header but it is not respected by most of websites. You can also reject all cookies in any web browser, but then majority of web pages will not work properly.

To be clear, P3P didn't work because Mozilla and Google and poured gasoline on it, and then Facebook lit a match. Had competing browsers not been desperate to brand it as some sort of weird proprietary Micro$oft thing, we might have a better version of it today (as happened to most features of that era).
Post reply on HN