Live data from Hacker News

Google Tag Manager, the new anti-adblock weapon (2020)

chromium.woolyss.com

871–880 of 902 posts

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#871
post #542

Earlier quoted context omitted.

It shouldn’t be on the todo list of the average user to be knowledgeable on this subject, just like the average consumer should not have to be an expert in airbags to expect the ones installed in their car to work.

I think there's a huge assumption implied in an analogy between airbags and user tracking. Airbags save lives. Anti-tracking guards against some hand-wavey philosophical concerns regarding privacy (in an inconsistent fashion, even... It's hard for me to buy that we need to make user-behavior tracking for ad targeting illegal in a world where user-purchase tracking for credit reporting is legal).

My point is that an average consumer does not and should not need to understand some complex embedded technology in the products they buy and use, and that their lack of interest and understanding of such technologies can’t be used to infer their intent on a broader subject (privacy,safety,health, etc)

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#872

This kind of data collection abuse is why I think we need more addons like AdNauseam [1]. Unlike uBlock Origin, it's not available from the Chrome web store anymore, which is a good sign that Google hates these types of addons more than they hate simple blockers. Blocking A/AAAA domains with custom URLs to prevent tracking is almost impossible, so instead let's flood the trackers with useless, incorrect data that's n…

I used to use AdNauseam a while back, until ads started to show suddenly. So I switched to UBlock Origin, and ads stopped to show again.

After I read your comment, I disabled UO and installed AN again. Maybe some update fixed the issues. But it didn't. I'm now back using UO again.

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#874
post #749

Earlier quoted context omitted.

It's not illegal to store such information in default logs per se, even without explicit consent, if it would fall into the "legitimate interest" category[0], e.g. you need it to operate the service and prevent abuse, and there is no less intrusive way to e.g. reasonably monitor for and prevent abuse. However, you cannot share such logs without consent, you still have an obligation to inform users about your legitima…

Gdpr.eu is not an official EU resource. There is no official guidance saying that IP address in logs falls under "legitimate interest" and every lawyer I asked advised against it "just to be on the safe side". One actually added: Do you really want to test our government's understanding of "legitimate interest" for your business in court?

>Gdpr.eu is not an official EU resource.

Yes, but I never claimed that they were. The text that I linked is a copy of the official GDPR text (and recitals), not an article they wrote on the topic. I used their website, because I find it more usable as they added cross-references links and recital links. But if you prefer, read the official EU version[0], which is the same in content and in words.

>There is no official guidance saying that IP address in logs falls under "legitimate interest"

I haven't said that. I said storing IPs in logs might be legal, if there is a legitimate interest and/or there is consent.

There are actually two official recitals straight up addressing that topic. Recital 47 states (in part): "[...] The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned. The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest." (This is not meant to be an exhaustive list)

Recital 49 states (in full): "The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems, by public authorities, by computer emergency response teams (CERTs), computer security incident response teams (CSIRTs), by providers of electronic communications networks and services and by providers of security technologies and services, constitutes a legitimate interest of the data controller concerned. This could, for example, include preventing unauthorised access to electronic communications networks and malicious code distribution and stopping ‘denial of service’ attacks and damage to computer and electronic communication systems."

These recitals were specifically added to address some points that had already been litigated in the past in various European courts.

>and every lawyer I asked advised against it "just to be on the safe side".

Good for your lawyers (that you keep mentioning all across threads). I don't know your lawyers, but they seem overly cautious - even for lawyers - and maybe a little bit under-educated on the subject matter. But they still have a point. You cannot just store access logs containing IP addresses, you have to have a legitimate interest, and be able to articulate this legitimate interest, and see if law makers and courts would consider your "interest" to be "legitimate". Which is easy when it comes to fraud detection and network security/abuse (thanks to the recitals), less easy when it comes to other areas, and pretty easy when it comes to different areas that are clearly against the text or spirit of the GDPR; e.g. nobody will buy an argument of "my legitimate interest is that I want to earn money from tracking and selling user data".

[0] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

[1] https://gdpr.eu/Recital-47-Overriding-legitimate-interest or https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

[2] https://gdpr.eu/Recital-49-Network-and-information-security-... or https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#875
post #212

Earlier quoted context omitted.

Not sure about the parent poster, but I am here mostly for the comments, and rarely visit the linked content.

Doesn't exactly this behavior create echo chambers and lead to polarization?

I dont think so. I'd think Echo chambers are created by lack of diversity in the user base. I think HN has a lot of actual diversity, and its possible to see controversial topics disputed without unceremonial downvoting.

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#876
post #854

Earlier quoted context omitted.

> Do you think businesses just magically get talked about with zero investment in marketing dollars? Yes. It's hardly magic. If some business or service provides a great value or "a better way of being" people naturally get excited and tell their friends. I'm not a domain expert but my understanding is that these organic word-of-mouth referrals and recommendations are waaaaaay more effective than any other form of ma…

> There are marketplaces that operate efficiently on word of mouth alone. Which ones? Please enlighten me.

First, there are the various "black" markets. There was no appreciable change in availability, quality, or price before and after pot legalization, for example.

The high end of most services and products doesn't need to market, they're "saturated" by word-of-mouth alone. For example, I met a guy once who was part of a very high-end IT consultancy. They had A-list customers, all the work they could handle, and their website was a single line of text that basically said, "You have a problem? Email us". In other words, most markets have a subset of "quiet" companies that thrive on word-of-mouth alone.

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#877
post #870

Earlier quoted context omitted.

But that's the phraseology. You specifically mentioned reasons / attitudes. If this is another "dog whistle" argument, I think you need far more evidence before you smear another user what you assume their motivations are; It's possible to use terminology borrowed from right-wing parties, language is free to use - and ThalesX has explicitly stated their position.

Care to clarify your question?

What specifically leads you to believe ThalesX has nationalistic/right-wing reasons/attitudes other than the wording of that one phrase he used.

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#878

Earlier quoted context omitted.

> completely predictable It's completely predictable that there are people who don't want to comply. Collecting personal information is a lucrative business. Re. Website logs: in fact it's perfectly clear that a website log retained for the purposes of site management is fine. It's on the face of the regulation.

> It's on the face of the regulation. Right, collection for the purpose of running the site and all that. But does that mean "I run my site without having ever configured apache's HTTP access logs off the default, but I never read the logs" is fine? Because that sounds like collecting more PII (in the form of stored IP addresses) than is strictly needed to run the site. https://law.stackexchange.com/questions/42438/d…

> probably wise for even site administrators who aren't doing advertising-related data collection to pop the banner.

I disagree.

As far as I can see, GDPR enforcement is not heavy-handed. You get a warning before any attempt at enforcement; then you get a modest "warning" fine.

Also, I'm not aware that the silly cookie banners provide any protection against GDPR enforcement; it's how you handle the data that matters, not a two-liner banner offering [OK] [Later] buttons.

If you want to "be on the safe side", handling data correctly will help; cookie banners won't.

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#879
post #864

Earlier quoted context omitted.

Please reply to my direct question. In which way did the USSR under Stalin allow worker control of the means of production? This isn't a changing of goalposts, it is simply ignoring obvious lies and propaganda from a regime famous for its lack of regard for the truth.

Through factory committees.

If you honestly believe that the workers in a factory under Stalin could decide how much of a good they wanted to produce, or decide if they wanted to increase automation, or even decide if they were allowed to go to the toilet, then you really don't understand how the USSR worked.

The Soviets (factory committees) at best held some sway during the early days of the revolution, before Lenin seized power. By the time Stalin replaced Lenin they were long since just a propaganda tool, hollowed out of any democratic control whatsoever and turned to a simple bureaucratic management unit entirely controlled by the party hierarchy.

Re: Google Tag Manager, the new anti-adblock weapon (2020)

#880

Earlier quoted context omitted.

> It's on the face of the regulation. Right, collection for the purpose of running the site and all that. But does that mean "I run my site without having ever configured apache's HTTP access logs off the default, but I never read the logs" is fine? Because that sounds like collecting more PII (in the form of stored IP addresses) than is strictly needed to run the site. https://law.stackexchange.com/questions/42438/d…

> probably wise for even site administrators who aren't doing advertising-related data collection to pop the banner. I disagree. As far as I can see, GDPR enforcement is not heavy-handed. You get a warning before any attempt at enforcement; then you get a modest "warning" fine. Also, I'm not aware that the silly cookie banners provide any protection against GDPR enforcement; it's how you handle the data that matters,…

Handling data correctly may not be feasible, especially for smaller users on shared-hosting solutions.

https://news.ycombinator.com/item?id=30402052

... and again, the problem is "correctly" is in the eye of a judge after an alleged violation has occurred.

Post reply on HN