Show HN: Server-Side Tracking Without Cookies in Go
marvinblum.de
marvinblum.de
Also user agents are not unique[1] but combined with IP addresses should be pretty safe to assume the fingerprint generated from both is.
[0] https://lucb1e.com/rp/cookielesscookies/ [1] https://www.eff.org/deeplinks/2010/01/tracking-by-user-agent
One of the purposes of the evercookie project was to have a collection of tracking methods that browser vendors can test against their implementation.
> * the IP is the most obvious choice. It might change, as IPs are reused by ISPs as they only have a limited pool available to them, but that shouldn't happen too frequently
> * the User-Agent HTTP header contains information about the browser and device used by the visitor. It might not be filled though, but it usually is
A couple of questions:
1. Does anyone know of a decent Firefox plugin that can subtly change the User-Agent string for each new tab? I'm not thinking changing it to a different browser rendering engine string but maybe add a random key like
hash-buster/$randomstring
2. Isn't Chrome making its User-Agent string static? (ref: https://www.osnews.com/story/131177/google-is-seeking-to-dep...). @marvinblum (looks like you're the maintainer?) wouldn't this then skew your results?[1]: https://en.wikipedia.org/wiki/Network_address_translation
I'm also fairly certain that a trace of a single user from A through B (e.g. they hit the "payment confirmed" page at a specific time, having hit a specific product page before) could be correlated with a user in a purchases/shipping database and from there to a name and address, depending on the overall system Pirsch gets used in. Bringing separate datasets into the same tooling to query them isn't particularly hard. If it's used on a simple blog with no other tracking or systems that store this data, this argument probably doesn't hold water.
Pseudonymising data at the earliest possible point fulfils another part of the GDPR (to do with controls and protection of personal data), but doesn't in itself make something not personal data, according to the UK's ICO.
Recital 26 of the GDPR states - "To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly. To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments."
But the fact of the matter is that there is so little risk here that it's likely to be a legitimate interest for the vast majority of businesses, thus not requiring consent (but still requiring adherance to the rest of the GDPR on personal data), again according to the ICO.
As you said it's still a good idea to inform the visitors about the anonymous tracking. I'm pretty sure that most websites require a cookie note anyway, no matter how annoying it might be.