X-Git-Url: http://pere.pagekite.me/gitweb/homepage.git/blobdiff_plain/f3ade917c053fef7fdc86e2c3a7d7a59245f1698..8e40d1728544dd145f15c173f0e5a18a04b01b14:/blog/draft/2015-google-analytics.txt?ds=sidebyside diff --git a/blog/draft/2015-google-analytics.txt b/blog/draft/2015-google-analytics.txt index 8261809e70..5fcf9e4f55 100644 --- a/blog/draft/2015-google-analytics.txt +++ b/blog/draft/2015-google-analytics.txt @@ -3,17 +3,34 @@ +http://www.nrk.no/livsstil/_-har-ikke-kontroll-med-cookies-1.12399474 +https://kommunen.dk/kommunale-hjemmesider-sladrer-uden-tilladelse/ + Leserbrev/kronikk. Hvor bør den sendes? Sendt til NRK Ytring 2015-02-17, avslag 2015-02-18. Sendt til DN D2-magasin 2015-02-18. http://www.kulturverk.com/ http://www.magasinetplot.no/ http://www.kulturverk.com/kontakt/ -NRK ytring (nei takk) +NRK ytring (nei takk) Aftenposten innsikt Amagasinet kan faktisk være en mulighet, også Næringsavisens (sp?) D2-magasin +Kronikk tilbydt NRK Ytring (2015-02-17, takket nei 2015-02-18), Dagens +Næringsliv (tilbudt 2015-02-18, interessert, deretter stille i +ukesvis), Verdens Gang (tilbudt 2015-06-10, intet svar), Dagbladet +(tilbudt 2015-07-07, takket nei), Morgenbladet (tilbudt 2015-09-09, +intet svar, forsøkt ny adresse 2015-10-20), Klassekampen (tilbudt +2015-09-27, intet svar), Dagsavisen (tilbudt 2015-10-06, intet svar), +Aftenposten (tilbudt 2015-10-12, takket nei 2015-10-13), Dag og Tid +(tilbudt 2015-10-14) + +https://theintercept.com/2015/09/25/gchq-radio-porn-spies-track-web-users-online-identities/ + +Denne teksten sto på trykk i XXX 2015-XXX. + +
Snurpenot-overvåkning av sensitiv personinformasjon
Av Petter Reinholdtsen
@@ -217,11 +234,11 @@ universiteteter, høyskoler, grunnskoler, og det meste av offentlig forvaltning, aviser og andre medier som NRK og TV2, sammen med adopsjonstjenester og Krisesenter gjør det samme? -Tenk om de holder oversikt over norske borgeres rettigheter, -interesser, sykdommer alkoholisme, adopsjon, abort, barnehager, -politiske saker og sympatier, hvilke argumenter som vil ha mest effekt -på beslutningstagere og måter de kan påvirkes. Ville det gitt grunn -til bekymring? +Tenk om de som lytter holder oversikt over norske borgeres +rettigheter, interesser, sykdommer, alkoholisme, adopsjon, abort, +barnehager, politiske saker og sympatier, hvilke argumenter som har +best effekt på beslutningstagere og måter de kan påvirkes. Ville det +gitt grunn til bekymring? Høres det ut som en absurd og ekstrem fremtidsvisjon tatt ut fra fantasien til George Orwell, forfatteren av dystopien 1984? @@ -233,11 +250,12 @@ Du kan beskytte deg Er vi så hjelpeløse og uten forsvar mot dette angrepet på privatsfæren? Heldigvis ikke. Dagens nettlesere har utvidelser som -støtter å blokkere slike angrep. Personlig bruker jeg Ghostery, -NoScript og AdBlock. Jeg anbefaler alle å gjøre det samme, og sende -inn protest til organisasjonene bak nettsteder som bruker slik -spionprogramvare. - +støtter å blokkere slike angrep. Personlig bruker jeg Privacy Badger, +Ghostery, NoScript og AdBlock. Jeg anbefaler alle å gjøre det samme, +og sende inn protest til organisasjonene bak nettsteder som bruker +slik spionprogramvare. Merk at noen av verktøyene lekker informasjon, +i tillegg til å gjøre en nyttig jobb, sa det er lurt å bruke flere +sammen. Hvordan foregår det? -------------------- @@ -322,3 +340,168 @@ sikkerhetsutvalg torsdag 3. juli 1958 om en planlagt lyttestasjon på norsk jord, jfr. lenkene. +http://www.dn.no/tekno/2013/02/03/amerikanerne-kan-se-hvert-ord-du-skriver +https://firstlook.org/theintercept/2015/07/01/nsas-google-worlds-private-communications/ + + + +anyway, while I have you on the line. I wonder about british privacy law. in norway, it is required to have a data handling agreement in place before asking others to handle personal information on your behalf. are there similar laws in Britain? +Sat 11:02 AM +the background is to figure out if alaveteli/whatdotheyknow use in UK require an agreement with google when passing the users IP address to google to fetch javascripts for required functionallity (the captcha and the javascript pdf viewer). I suspect it is required here in Norway, and hope it is required in UK too, to raise the priority of avoiding the google dependency for the core developers. :) +Sat 11:05 AM +Very interesting. +Sat 11:19 AM +Yes, that requirement exists, but they won't care, because the U.K. ICO will never get on their case for this. +Sat 11:19 AM +In general first party websites are responsible for ensuring their whole systems are compliant with data protection laws and can satisfactorily perform all the required actions attached to this. +Sat 11:21 AM +There are different means to ensure that, and one of them is an explicit agreement eteeen the two parties. +Sat 11:22 AM +Most websites however when you contact them for that issue claim they are compliant and refer to what Google forces them to add to their own privacy policy. +Sat 11:22 AM +In effect, Google lawyers have figured out a way to make all those websites complicit: the language added covers the processing done by the website, not that done by Google. But the website is still liable for the processing done by Google. +Sat 11:24 AM +So you have to actively show to the website they are failing in their legal duty. +Sat 11:24 AM +There is a neat way to do this: access requests. +Sat 11:24 AM +(Before I get into Access Requests, it could be argued this extra language in the privacy policy, or the agreement the website has with G is the agreement itself) +Sat 11:26 AM +(it could be, as long as it ensures all rights can be respected, including access) +Sat 11:27 AM +So the only active tool you have to create the problem is "Access": Ask the website for the data collected by Google through the use of the website. This works especially if the website requires identification and stores Google Analytics values as 1st party cookie. No excuse then. +Sat 11:27 AM +Then the website has to somehow find Google, contact them, argue that G respect local laws, etc. G will not bulge. And then, you are good: either the website stops using GA, or they *knowingly* keep on using an illegal service. That's a good basis for a local complaint. +Sat 11:30 AM +The wonderful thing is that this scales really really well. And it's also the best way to make adtech more transparent. +Sat 11:31 AM +I was thinking of using that strategy with newspapers as first parties, not FOI sites though. :) +Sat 11:31 AM +right. was planning to ask for a copy of the agreement with google, which is the approach that has proven slightly effective here in Norway. +Sat 11:40 AM +You saw my comment on Mimesbronn about this, right? +Sat 11:40 AM +do not remember it, at least. the messages on mimes brønn get in faster than I manage to read them. ~300 messages in my backlog. :) +Sat 11:41 AM +I have tried the same with government authorities in Belgium and Switzerland. No one respects the law. +Sat 11:41 AM +Right. But there was specific request for Google Analytics stuff. +Sat 11:41 AM +If you want I can add any website you wish to PersonalData.IO +Sat 11:42 AM +I had some success in