Live data from Hacker News

GDPR penalty for passing on of IP address to Google by using Google Fonts

rewis.io

621–630 of 656 posts

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#621
post #31

Earlier quoted context omitted.

Running a website in Germany seems like a god damned nightmare: https://allaboutberlin.com/guides/abmahnung-creative-commons

That specific scam does not have to work anymore though. Abmahnungen in Germany are the most stupid and lawyer serving system in the world, but the CC image scam got closed by judges deciding no monetary harm was done. Possible that these lawyers are still trying, but note that the article started 2018.

The linked article also never went to court because they decided to pay instead:

> September 21: After months of silence, we have received another letter from Kanzlei Schröder. This time, they threaten to take us to court unless we pay 400€ by October 1. We decided to pay. That was our last interaction with Kanzlei Schröder.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#622

Earlier quoted context omitted.

What value exactly is there in Google seeing that IP X requested font Y, assuming there’s no Referer header - which there won’t be, assuming Referer-Policy is set sanely (which by default it is in all browsers)?

> assuming there’s no Referer header - which there won’t be, assuming Referer-Policy is set sanely (which by default it is in all browsers)? In Firefox 96 network requests to 3rd parties (in this case Google) still seem to include the 1st-party hostname as REFERER header.

Which is really shitty behavior from a browser that wants to claim to care about privacy.

But even without a referer it gives Google some information, even if its just that this user (ip, useragent, other identifying bits) is currently exists.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#623
post #340

Earlier quoted context omitted.

Technical skill is kind of a requirement if you want to achieve something that's technical by nature - such as website development or web hosting. And hosting a font file entails dumping it next to your index.html file and adding some very basic CSS. Not exactly difficult.

> And hosting a font file entails dumping it next to your index.html file and adding some very basic CSS. Not exactly difficult. If you are a 60-year-old woodworker living in Appalachia trying to set up an online store to sell hand-carved flutes, this task is essentially impossible.

The 60-year-old woodworker living in Appalachia will be relieved to know that browsers are able to display text in their online store without having to add any font files at all. If the 60-year-old woodworker living in Appalachia decides they absolutely must have a custom font on their website then self-hosting that font file is not any more impossible than adding the HTML/CSS required to fetch it from Google.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#624

Earlier quoted context omitted.

> c) embed in such a way that it shows a user-controlled notification that opening the embed will connect to Instagram and as a consequence sends data to Meta. This is how we arrive at cookie popups and annoying "you're leaving our website" notifications. I posit that perhaps both of these could be a feature of HTTP protocol and the browsers - i.e. a browser could just display a small standard icon in its UI notifyin…

> i.e. a browser could just display a small standard icon in its UI notifying user that he's consenting to cookies If you need to notify the user that he is "giving consent" then there is no consent. > and another one notifying him that he's being redirected outside of the domain he's in There is rarely a reason to redirect to other domains. The most common case is making outbound links go through a redirect for trac…

>> and another one notifying him that he's being redirected outside of the domain he's in

> There is rarely a reason to redirect to other domains. The most common case is making outbound links go through a redirect for tracking purposes - and that I won't miss.

You misunderstand this part, which is forgivable if you're outside Germany. This is about the mandatory "You're leaving X, we do not have control on their data collection or endorse this site's contents. Do you want to continue?" you'll see on German-language website because a court in Hamburg says that they're implicitly liable if they didn't state that.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#625
post #375
post #240

So what happens if you include e.g. a Wikipedia image or a youtube video? Is that a GDPR violation too? These scenarios also lead to making the users IP available to a third party. If so, how do we avoid breaking the web while keeping privacy needs in balance?

> how do we avoid breaking the web while keeping privacy needs in balance? One thing that I feel would help: Massive decentralization. Self-hosting of content and regular synching of the hosted content on the server sides; or tunneling, think duckduckgo. Self-hosting would make knowledge storage more redundant which protects against (also partial) network blackouts. On the other hand this knowledge is then harder to…

So your solution is to introduce a massive amount of redundancy so Google doesn't know you downloaded a font.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#626

Earlier quoted context omitted.

no, because that's where to visitor want to go by explicit free will. Not so a hidden 3rd party.

The CDN is a hidden 3rd party, no?

Yes, but they have a contract with the VPN and the VPN has a data protection officer. Here they just send data to Google and Google has not made any promises to protect the data.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#627
post #23

Earlier quoted context omitted.

Why "what the hell"? This is exactly what happened, and a logical consequence the moment IP addresses are classified as private data. Which it is in a system where it can be used to find the civil identity of the user, which is the case in Germany via Vorratsdatenspeicherung and the rampant misuse of the legal system. Note how the decision contains the question of whether leaking the IP was necessary. They noted it i…

I have to say that this is such an example of new technology being scary but the problems with old technology being ignored. I'm still waiting for the ability to have mail received from someone or a company without giving such parties my name and physical address. This could very easily be implemented in many ways, but somehow does not exist. There is no reason for a mail order company to know my full name and physic…

I feel that is more an argument for improving post than one against GDPR.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#628
post #627

Earlier quoted context omitted.

I have to say that this is such an example of new technology being scary but the problems with old technology being ignored. I'm still waiting for the ability to have mail received from someone or a company without giving such parties my name and physical address. This could very easily be implemented in many ways, but somehow does not exist. There is no reason for a mail order company to know my full name and physic…

I feel that is more an argument for improving post than one against GDPR.

It's an argument for, as I said, that people have a tendency of disproportionately focusing on the harmful effect of new things, all the while ignoring anything that is sufficiently old.

I find giving ulterior parties my name, and the physical location on the planet I live far more scary than being tracked by cookies without such cookies being able to be tied to such things.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#629

So an HTTP GET request to another domain (fonts.googleapis.com) "leaked" website visitor's IP address to Google. What the hell? Google Translate: https://rewis-io.translate.goog/urteile/urteil/lhm-20-01-202... > The defendant is sentenced to pay the plaintiff €100.00 > The plaintiff has a claim against the defendant to refrain from passing on the plaintiff's IP addresses to Google under Section 823 (1) in conjunction…

yes. That's a fact. A 3rd party is a 3rd party and a website leaks it's visitors to it. Just don't do it but serve your stuff from your domain.

> from your domain

Not only from your own domain, but from your own servers. If you still server-side send the IP to Google servers, it's still sharing of personal data with a 3rd party.

I wonder how this works when you rent servers from VPS providers. If you host data on their servers, does it mean you share it with them? What if this data is behind a root password? What if it's encrypted?

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#630

Earlier quoted context omitted.

The plaintiff’s IP address was also leaked to every intermediate router and potentially to the DNS server(s) that resolved the IP address.

Yes, but there is one small difference: The sharing with ruters etc. is required to operate the service (website). Using a Google CDN for fonts isn't (required for operating a website). The ruling explicitly points that out. Furthermore DNS is handled by the contract you signed with you ISP or you explicitly changing it. Same for some other parts.

> Google CDN for fonts isn't

Where is exactly is the line for needed for operating a website and being optional?

What if you create your website in wix.com, the data from your domain will be shared with them AND it is needed for this data to be shared for operating the website.

EDIT: To make it clear, I always recommend self-hosting fonts and agree that Google CDN fonts should be avoided. But even if you self-host the fonts, those are still hosted on a server that is very unlikely to be your basement.

Post reply on HN