Live data from Hacker News

Facebook’s tracking of non-users ruled illegal again in Europe

techcrunch.com

1–10 of 395 posts

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#2
>“The cookies and pixels we use are industry standard technologies and enable hundreds of thousands of businesses to grow their businesses and reach customers across the EU,” said Facebook’s VP of public policy for EMEA

If it is "industry standard", does that make it ethical?

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#3
post #2

>“The cookies and pixels we use are industry standard technologies and enable hundreds of thousands of businesses to grow their businesses and reach customers across the EU,” said Facebook’s VP of public policy for EMEA If it is "industry standard", does that make it ethical?

[deleted]

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#4
Looking forward to May (when GDPR officially comes into force). Provided that it doesn't end up like the cookie law (and there are explicit provisions in GDPR and ePrivacy to avoid that) this might shake up the ad industry:

* Explicit consent for non-essential data use, you always need to provide opt-out without degrading the service

* Opt-in/out separately for every activity (no more "research purposes")

* Data deletion and takeout. Maybe in the future EU will also introduce some standards for the takeout, which will allow us to migrate between services much easier (as we now can switch between banks or telcos in a semi-automatic way)

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#5
post #2

>“The cookies and pixels we use are industry standard technologies and enable hundreds of thousands of businesses to grow their businesses and reach customers across the EU,” said Facebook’s VP of public policy for EMEA If it is "industry standard", does that make it ethical?

It doesn't matter, since it doesn't even make it legal.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#6
In order to make these decisions enforceable we need to collaborate with ISPs to anonymize traffic. Government action is necessary. I've contemplated far too long on this problem and there's no other solution. You can make them say that don't store your data, but that's pretty much always a lie. We can build browsers that reject cookies, but you can't get rid of your IP. All these services can simply track you through your IP. A significant change in networking infrastructure is required, and I'm hopeful that quite a few countries will resort to that soon for reasons of national security.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#7
post #4

Looking forward to May (when GDPR officially comes into force). Provided that it doesn't end up like the cookie law (and there are explicit provisions in GDPR and ePrivacy to avoid that) this might shake up the ad industry: * Explicit consent for non-essential data use, you always need to provide opt-out without degrading the service * Opt-in/out separately for every activity (no more "research purposes") * Data dele…

What we are seeing is that the ad providers are considering themselves "controllers" under the GDPR and the tracking of device ad identifiers as critical to their business. Hence, their plan is to inform of the collection via a privacy policy but not to offer users the opportunity to affirmatively consent to allowing their advertising ID to be tracked. It's dispiriting.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#8
post #7
post #4

Looking forward to May (when GDPR officially comes into force). Provided that it doesn't end up like the cookie law (and there are explicit provisions in GDPR and ePrivacy to avoid that) this might shake up the ad industry: * Explicit consent for non-essential data use, you always need to provide opt-out without degrading the service * Opt-in/out separately for every activity (no more "research purposes") * Data dele…

What we are seeing is that the ad providers are considering themselves "controllers" under the GDPR and the tracking of device ad identifiers as critical to their business. Hence, their plan is to inform of the collection via a privacy policy but not to offer users the opportunity to affirmatively consent to allowing their advertising ID to be tracked. It's dispiriting.

their interpretation isnt nessiarily going to hold up.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#9
post #6

In order to make these decisions enforceable we need to collaborate with ISPs to anonymize traffic. Government action is necessary. I've contemplated far too long on this problem and there's no other solution. You can make them say that don't store your data, but that's pretty much always a lie. We can build browsers that reject cookies, but you can't get rid of your IP. All these services can simply track you throug…

There are many situations, think university or corporate networks, where you cannot rely on the IP address for tracking. There are ISPs that don't have enough IP addresses for users so they many-to-one NAT them and most users won't even notice.

Even behind an ISP or corporate NAT with cookies disabled, there are other ways of tracking. If JavaScript is enabled, browser fingerprinting can be very disturbing in its ability to single you out, depending on your configuration.

More generally, I always found this obsession with tracking non-users one of the creepier aspects of Facebook when I finally used it circa 2011 - 2012. The amount of information it had about me that could only have come from web browsing before I had signed up, such as local takeaways and restaurants I had used, was impressive but unnerving.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#10
post #6

In order to make these decisions enforceable we need to collaborate with ISPs to anonymize traffic. Government action is necessary. I've contemplated far too long on this problem and there's no other solution. You can make them say that don't store your data, but that's pretty much always a lie. We can build browsers that reject cookies, but you can't get rid of your IP. All these services can simply track you throug…

What do mean? Isn’t this verdict a pretty good example of how the law actually is enforceable?

For Facebook to lie in such a lawsuit would require hundreds of their employees being willing to lie under oath. It just doesn’t make sense, considering they would risk harsh criminal sanctions and have only their usual salary as an upside.

As for IP-based tracking: if it were as effective as cookies, websites would use IPs and not cookies.

Post reply on HN