Companies must stop using Google Analytics
imy.se
imy.se
The entire course (located on here: https://medieinstitutet.se) is based on Google Analytics.
Now her entire value is tied to the use of Google Analytics, she will almost certainly fight very hard to ensure that these skills remain relevant, nobody would want to retrain for 6-12mo on new analytics systems (or, god forbid, not be an analyst at all!).
I think we don't really assess the amount of lock-in we allow when we learn something that supposedly makes our lives simpler. Google Analytics was sold as a solution to you making your own analytics, because that's hard! and the cost is that google gets your information too- which most webmasters don't care about individually.
However now we're in a situation where at least a few thousand people depend on this precise tool existing, and will be economically useless if it is banned.
Personally I find this astonishingly foolish of the people who train exclusively on these tools instead of first principles and primitives.
That said; we also have "Cloud Engineer" as a job title, so I'm not sure we will learn this lesson.
there are privacy-compliant products in that sense, unless you've been literally told "click here and click there" you should be able to employ old concepts with new tools.
> Personally I find this astonishingly foolish of the people who train exclusively on these tools instead of first principles and primitives.
I wouldn't be surprised for this to be a "click here and click here" kind of training. I've seen a painful amount of those. And then, when the inevitable "new and improved ui" comes along, these people are lost and require a new training.
Not all, but there's many.
This is how corporations and the will to profit undermines first principal knowledge and leaves a wake of fake education that ultimately needs to be unlearned or unwisely held as a fragment of useful adrift in an island of potential non-logical nonsense
Or this could be the right time to check one of the self hosted alternatives (Matomo, Snowplow, etc), apply what she learned about Google Analytics, learn how to do it on those systems and sell her skills on two different classes of customers: the ones that will keep using Google Analytics, the ones that will try alternatives, at least not to be fined if not out of genuine compliance with the local laws.
Getting this background requires a non trivial amount of time. It's easy to take our ability to generalize different computer based tools when you already understand digital computer architecture and know a few programming languages. The vast majority of people do not start from such a broad base of knowledge when choosing some software tool to learn.
> However now we're in a situation where at least a few thousand people depend on this precise tool existing, and will be economically useless if it is banned.
Not really, there is no GoogleAnalytics-industrial complex yet, but yes apparently they have quite a lot of lock-in on nonprofits. I see this story as a privacy regulatory story driven by the EU and GDPR. They will order GoogleAnalytics to fix violations, and then Google roll another version of GA. Customers who want to take a stronger stance on privacy would migrate off GA.
I doubt there is anyone whose entire livelihood depends on GoogleAnalytics (I don't think your relative's "entire value" does, for example) and even if there was, they could reskill in the medium-term, but anyway you could make the same comments about certification, lock-in and perverse incentives about AWS, or plenty of other companies in previous decades.
Your run-of-the-mill business drone will be trained on Word/Excel/Outlook and be hard to impossible to retrain on anything else (either because of actual stupidity or resistance to change). This already starts at school where "Informatik" is often just learning where to click in Microsoft products.
Similarly, tradespeople often specialize in certain tools and products. Your average car repair guy will often be forced to specialize in one brand of car. Your home appliance guy will preferrably sell and repair one brand of washing machine, dryer, dishwasher.
Not because of skill issues, but maybe forced because they work for a dealership that sells a particular make exclusively or, less often, a specialty shop; most “car repair guys” outside of those environments have to be generalists.
> Your home appliance guy will preferrably sell and repair one brand of washing machine, dryer, dishwasher.
IME, the sales are done by shops that carry many brands, and delivery, installation, repair donw by firms that often have relations with the retailers and handle whatever you get from them, including multiple unita of different brands that come together with the same team. They may also have relations with the manufacturers, but those don’t seem usually to be exclusive.
Yes, I'd expect any car guy to be able to change your tires. Or change your oil. But even resetting the oil-change alarm or tire-pressure sensor can be a hurdle here:
Manufacturers also use skill issues to their advantage to bind tradespeople. Modern cars do need manufacturer-specific diagnostic devices that used to be unobtainable for independent shops. Since that practice has been largely forbidden by the authorities, now the software, cabling, and diagnostic output are made intentionally hard to understand without having taken the corresponding lessons that the manufacturer provides for a modest fee.
If a seasoned mechanic is unable to figure out how to reset the Maintenance Reminder or look up how to sync Tire Pressure sensors, run away.
In the same way that one can use knowledge of one programming language as a means to leapfrog into other languages, other skilled trades are similar. Perhaps there's something that could be said about an ICE mechanic trying to dabble on Electric but that's not the point you're making. So yeah. I know you're trying to make a point about lock in, but when I think of people I want to hire for tasks who might say "Oh, sorry, you have a Volkswagen and I only know how to work on GMC" I wouldn't take my GMC to them either. It shows a fundamental lack of skill in that they don't understand the broader concepts and their universal applications. If I, a programmer, can figure out my Volkswagen, my GMC, my Mazda, my Nissan, certainly a mechanic can. If my appliance repair specialist can only do Whirlpool when I ask for help on a Bosch that's red flags.
One might specialize. Sure. But to refuse? Weird. But I fear I might be getting lost in the weeds here because its all about the approach. "Sorry, too busy to take on work on things that aren't my specialty": yep, understood. "Sorry, I don't know <model> I only know <other model>" bad.
It is not impossible but if you try to go to a random shop you found on Google and fix your Citroen or Renault you might be surprised.
I guess some mechanics will prefer to work with a smaller number of models, because they're much faster if they're familiar with the model, but new models come out every year, and they need to learn how to fix those. If a mechanic can learn to fix the newest VW, they can learn to fix the newest Renault, it just might not be worth their time if they have enough work to do.
I believe person learning GA could learn any other analytics tool. It is just not worth their time.
Any mechanic can fix a Citroen, but is it worth the floor time it'd take to get the parts and figure out french quirks vs working on something they know that they'd make the same money in a third the time.
Having done shade tree work on various cars, I'd totally turn down any Subaru engine bay work if I was already close to swamped.
Most specialty equipment costs less than a mechanic can earn in a day. You even order the parts from the same company no matter if the bumper is for a Mazda, VW, or an Alfa. Or a Kawasaki motorcycle for that matter. This lock-in behavior is, luckily, mostly illegal.
In the US, for a very long time, you had to find an "import specialist" mechanic, even long past the point where Japanese brands had gone mainstream. Part of this might have been because of the availability of metric tools at the time; my family had a set of metric wrenches specifically because they had to do occasional light maintenance on their early Datsuns and Toyotas.
I can recall that the mechanic in my neighbourhood was decidedly unwilling to service a new Hyundai in the late '90s. He complained they were 'disposable'.
Specialized items require specialized tools. Specialized tools, like all other tools, require maintenance and they change.
A shop dealing with domestic produced automobiles can significantly reduce profit-bleed by not servicing vehicles that require special tools, special diagnostics, special machines, etc.
It's simply a math equation. Do I serve enough of these vehicles daily/quarterly/yearly to make these expenditures profitable for me? The shops you're referring to answered no to that question.
Yeah, I work at a corporate office and have made it a mission to see what kind of work they do, and majority of the time...it's pointless meetings and meetings that involve pointing to IT workers and saying "do this". I check many of their daily schedules, and see what kind of stuff they talk about in meetings...just wow. Am I an "asshole"? Sure you can call me that, but I can call them useless in turn because I wonder how many more qualified people out there who can replace these workers.
Have you ever dealt with an average IT department in a non-tech company? This attitude doesn't help anyone and I really want to believe that only a small minority of tech people think of any other worker anywhere as an "asshole".
I get they have to deal with a bunch of technical inepts constantly falling for phishing attacks and occasionally teams will make outrageous requests to them that simply can't be done, but their attitude is terrible.
If you ask for something simple but "scary", like a firewall or internal network change, they will immediately assume you are just some idiot and speak dismissively to you in a very obvious manner. It's extremely frustrating because they won't even bother to read your emails that justify the change and will just invent some unrelated excuses about why they can't or say they will get back to you later (they don't).
Ironically the only way to get anything done through them is to have my team members create a bunch of duplicate tickets (1 per person), and schedule multiple pointless meetings with them that essentially just consist of me reading my emails to them out loud.
Non-technical teams in the company get the same treatment but lack the technical background to counter them. Frequently I've had team leaders come to me to get a second opinions on the stuff IT tells them and it bothers me how much they seem to clearly exaggerate the difficulty of things. To the point where I can't help but wonder if they are just pretending to know what they are doing, and use their better-than-you attitude to mask their own ineptitude.
So overall I feel the negative reputation of IT departments is earned.
Scotty Engineering principle at work. I'm no stranger to that, it's often enough the only strategy keeping higher management from completely swamping you with work.
What an ironic comment.
Sorry, any early-career worker looking down their nose at anyone else (or pretending to have any idea what their job entails, especially because they “looked at a calendar”) might as well go back to middle school. They definitely need to grow up.
I say this with the perspective of someone who has slowly had to have many more of these meetings added to his calendar over the years.
Some are very important, some are reasonable but often bloated, but so many are a waste of time.
At the very least: they’re 5-10 mins of work spread over an hour. It’s occasionally maddening.
When I was really junior, I'd go to meetings and think that the vast majority of the time was wasted. As I became more senior, I realized that a lot of that wasted time is for providing context, relationship building, and alignment. You may not need those things for your current task, but your leadership and partner teams may need these things.
Yes, a lot of meetings could be emails, and a lot of meetings could be better run (agendas and objectives in the invite, action items assigned at the end), but unless you're working somewhere awful, most meetings probably have a reasonable purpose and aren't all filler. Lots of jobs require way more meetings, and probably aren't filled with context relevant to you.
Looking down on non-engineering positions is a personality trait I associate with inexperience. It's absolutely something I'd consider when denying a promo.
My entire point was that there is a major difference between the two & that while the instinct to look down on others for this organizational symptom is immature, it’s not unfounded or without basis to highlight the issue: they’re blaming the wrong thing however.
And I often find that in those types of meeting communication & relationship building is the absolute last thing that is happening. Most of these meetings are CYA, checklist, type meetings.
Meetings that literally only exist to allow someone to demonstrate they had a meeting about something.
Worse, the actual communication that is happening is usually in side channels.
Having good meeting culture requires everyone involved to improve it. If you want meetings to be better, set them up, add an agenda and objectives, and run the meeting so that it's effective. If you can't run the meeting, if it doesn't have an agenda or objectives, ask the person who created it for them. Ask for action items at the end of the meeting, if no one is calling for them. If it's mostly status meetings, propose a better process to track and communicate status.
If you're working through side channels, you're part of the problem.
Calling people assholes, rather than improving the situation, is an indicator of inexperience.
I’m actually impressed.
Call me in 20 years, maybe you’ll have learned something.
Assuming people are assholes, and blaming them for situations is just run of the mill toxic. Working through side-channels rather than addressing a problem is also run of the mill toxic.
Just because Joe or Judy "feels" a certain way doesn't mean it should actually have bearing on anything. Really...
Enough placating those with the least logic and self control.
People's feeling matter in the long term, because it's the difference between them wanting to work with you, and them being forced to work with you. If I had to pick between a genius coder with awful people skills, and an average coder with exceptional skills, I'd essentially always pick the average one.
Do you not see the difference?
Well that's absolutely not the place for it.
If your little fee fees get hurt you keep it to yourself and focus on the task at hand. Then after the task is complete you either pull the offender aside to address the problem or you bring it to a superior to be addressed. It in no way should have any bearing on the work at hand.
This is basics of work place decorum, right?
A lot of that seems to be about office politics, which historically been something which engineers and office workers in general has disliked. It is a generally unhappy fact that relationship building and office alignments is what dictate who get promoted, who get raises, who get the desired assignments and who don't.
It might be true that those who refuse playing that game is associated with inexperience. In my experience, employees who get tired of it generally leave large companies, which leaves behind only inexperience employees or those who enjoy the game.
100% agree. In early or IC roles, it's easy to think "just let me go do X" (or worse, "talking about X or Y is a waste of time when X is the obvious answer") without seeing the bigger picture that there's tremendous value in making sure other teams are aware of what X is, why it's important, and having a chance to weigh in or ask questions. Certainly there are valid complaints about some people's meetings, but those shouldn't overshadow the alignment/communication value meetings can have.
Its always us vs them.
Seriously, some looking down the nose comments
Is it better or worse to assume they're being a problem on purpose?
I won't say 'average' but I will say 'common enough to make changing software a huge issue'.
The person trying to make things better and seeks out knowledge at great cost
Or
The person who is willfully ignorant and actively refuses knowledge handed on a platter?
Because one of those is the typical IT pro and the other is the worker drone....
Show me a product that provides so much more value for my team than Excel that it would be worth a retrain.
LibreOffice, free open source software. Just as good as Excel and... free.
But yeah, for some things there are not yet complete free software alternatives, but the gap is really getting small these days. I think for most common use cases for most people, LibreOffice is more than enough. If you need more advanced features that are only available in the propietary variant, try to find ways to not be dependent on that feature, or find an alternative way to do it with free software. If you are creative, there are usually many ways how you can do your work using free software.
But yeah it does take some dedication to this idea. But what you get back is probably, on the long run, gonna be of more benefit to you for the future than if you would invest it in learning the propietary software. Unless you really have a special love for the propietary software company, and you are sure you want to grow more and more into their ecosystem and have no need to have any personal freedom over the software you use.
Here's the thing, for 90% of use cases, those are all effectively equivalent. You really shouldn't need any retraining whatsoever. A spreadsheet's a spreadsheet, and a word processor is a word processor. You type the text in the box and then hit print or whatever. Nothing new to learn.
Now admittedly, there are some power user features which are different, which is why I said they're only 90% equivalent. But most people don't use those anyway. Yet they will intensely oppose using a different but 90% equivalent thing because they haven't spent years being trained to use it - even though it's almost exactly the same thing they're using.
It's just a weird and bizarre mental hangup that seems to be natural to many humans.
If you're in tech, you will see the same thing with programming languages, frameworks, applications, etc. And it's on both sides, not just the users, but also the people hiring them too. "Oh, you've only worked with WordPress, you haven't been trained in Drupal?" "Oh, that's PHP, I only work in Python." "Well we're looking for a Ruby developer, not a C# developer." "That's React, I only know Vue.js"
It's mostly all general-purpose programming languages, libraries, and frameworks. Sure some details are different. There's a bit of a learning curve. But if you are actually capable with one, then picking up another nearly equivalent alternative should not be viewed as some impossibly complex thing that will take years of retraining.
There is a thing called "intelligence". There are several definitions of it, the one I'd like to use here is "the ability to infer general principles and common workings from small isolated samples and apply those principles and workings".
So if you are sufficiently intelligent, you can infer, from observing a few (or even one) doorhandle being pushed, that his is the general way to open doors. You can then apply this principle maybe even to different doors, windows, rotating knobs, etc. The fewer samples you need to learn and the broader your application range after learning, the more intelligent you are. In the stupidest case, one only learns to open one specific kind of door in one specific way, like a cat might.
You are writing from the point of view of someone sufficiently intelligent to derive the working principles of software and apply it to other software packages that generally serve the same purpose. However, there are people who are not intelligent enough to do that. Those people do get by by just following instructions, learning by rote which buttons to click for which purpose. Those people are the "door opening cats" of the office application world.
Less intelligent people like those do exist (50% do have an IQ<100 after all...), they do get jobs and they can be successful within limits. Just as Stackoverflow/ChatGPT-copy&paste-programmers do get by somehow.
Which is why I'm also a fan of intelligence-test-type job application processes. The ability to learn, for higher-level jobs, is far more important than preexisting knowledge. And intelligence is the best known predictor for the ability to learn.
Change purely for the sake of change is bad and people are right to resist it.
The vast majority of businesses have no compelling reason to switch off Microsoft Office. Would the world be a better place if there were more feasible options? Maybe. But that's not the concern of either a random business or its employees.
Home appliance repair is knowing the general layout of each major appliance, a bit of specialized knowledge on how to dismantle them without braking them, and which modules are responsible for which function, and finally knowing how to source the replacement parts and knowing which common items are best kept on hand for convenience.
Very few people are doing board level repair for appliances, especially when the replacemeent boards are typically very inexpensive for any modern machine (save for main boards and for induction plates in induction stoves, which are typically so expensive that it is smarter to replace the entire appliance rather than repair the broken module).
As long as you don't depend too much on highly vendor-specific stuff, most of the stuff a "cloud engineer" uses day-to-day is just the same fundamentally - EC2/Azure VM/GCE, ECS/Azure Container Apps/Cloud Run, Security Group/Azure Network Security Group/Google Firewall, whatever. Different names, same or very similar stuff.
There are certainly some cases where that breaks down, but it’s usually in specialized areas that I’d have to do some upskilling on in my preferred cloud anyway.
The benefit of the cloud is its service and resource (i.e. building block) oriented nature. There’s a level of transparency to cloud-based services that just didn’t really exist before.
I work here:
https://aws.amazon.com/professional-services/
There is a lot more to any of the cloud providers than just VMs and networking. I haven’t done anything hardly with a raw EC2 instance in 5 years except for one or two deployment pipelines. AWS alone has 130 services. True many of them are hosted versions of open source products
I work with call centers (Connect), Athena (Apache Presto), Step functions, and I have done some IOT work and of course Lambda and a lot more. I don’t do anything with traditional VMs. My specialty is “application modernization” meaning my work is a combination of DevOps and traditional application development using AWS services.
There are all kinds of specialties within any of the major cloud providers.
Well, Lambda has a multitude of competitors (although to my knowledge they are only competing on the principle of serverless computing, so you'll still have to re-write scripts using these), and same for IoT integration.
The rest I'd say is pretty exotic stuff... and thanks for mentioning AWS Connect, that looks like something I'll have a deeper look into - do I get it correct that this is something like a combination of JIRA Service Desk/OTRS, some form of SIP telephony service plus a webchat and AI assistant?
It’s the standard type of software you use when calling into a call center with a mixture of automated help and operators.
Like I said above, if you know your specialty well, it’s not hard to map your expertise to AWS services. It took me two years from never opening the AWS console but having literally decades of software development/architecture experience to working at AWS in consulting. I worked at a 60 person startup before.
I’m more challenging the notion that all any of the cloud providers offer is a bunch of VMs and the surrounding networking infrastructure.
Granted, I'm biased because I work at a development-focused shop so my experience is the development/infra side of AWS and Azure as well as a healthy load of legacy on-prem servers (I leave my fingers off of GCP though, heard too many horror stories). We follow KISS - so just from a quick grep through our Terraform files it's almost all EC2, S3, Cloudfront, ELB, ACM, RDS, EFS, Beanstalk, ECS and EKS plus Cloudwatch for logging/monitoring, well wrapped in modules. That's stuff one can find pretty much everywhere, especially as most of our workloads are shifting to EKS.
The things you use are IMHO more targeted for specialist use cases, and I can clearly see the value-add... I'd pay good money to never have to see JIRA again in my life.
It seems very inappropriate to allow a data collecting tool to dictate what information is relevant for a specific company.
However, most young businesses will waste tons of time and money reinventing the wheel of these systems and trying to customize them to their business’ unique needs, but the much more effective path is to really (re)think through your business process and figure out how to align it with the grain of the tool instead. This option is only obvious to those with experience in failing to execute on the former option, unfortunately.
To your point, an effective analyst doesn’t just present data, they have to understand the entire world around that data - tooling, people, processes.
When people are banned, it's the platform deciding the reputational risk of association isn't worth the money you bring in. Given reputation impacts can be huge - it's hard to see how you'd ever be the right side of that equation.
Even worse, the platform may decide it's not even economic to make sure each banning is fair....
Ultimately I suspect the only way to rebalance the balance of power is to use collective power.
So having large number of friends on the platform that will campaign on your behalf, taking out insurance ( another pooled method ), or even having formal Unions.
In essence that puts some of the economic cost of getting the decisions right onto the platform users ( as the friends/union does the work, and makes the case ). Pooled insurance has a similar economic basis ( platform users bear the cost of the insurance ).
Lets say for example that you somehow make $120,000 a year over expenses with instagram (don't ask how, it's just an example). This is far more than you previously made in your last job by double. The problem is it takes nearly 100% of your working time to make this income on that single platform. Any less amount of effort and your income drops significantly. Now, you are in a trap where you cannot split your efforts between platforms, you have to go full in on one.
Your solution would be to make far less money... um, safely? Whereas a far more realistic solution would be to ensure that you don't live to close to the edge of your means and put 1/3rd of your income back in savings in case the day the platform fails/kicks you occurs.
So you could think about not operating as an individual who can be picked off, but operating in a collective way - either through friends, insurance, or unions.
ie what's your support network if you are dropped through no fault of your own.
As an example imagine learning programming - without some real world practice. And if you do some real world practice you have to choose which tool to use.
I take your broader point - but I think it's inevitable that most courses of this type are based around a particular tool chain.
Most Data Science courses use Python for example.
But I don't agree with the python comparison. Python is only a language and even Numpy/Pandas still need you to know the concepts and knowledge attained using them are definitely transferable.
All I'm saying, the fact that a course uses a particular tool chain isn't the determinant factor to whether a course is good or not.
totally agree here
>All I'm saying, the fact that a course uses a particular tool chain isn't the determinant factor to whether a course is good or not.
I totally agree! My comment was related to the commented mentioned that the whole 6 month training is worthless if GA get's blocked
I guess we aren't that far apart :)
Well before I even started my first development job, I had used BASIC, Turbo Pascal, Assembler, C, Euphoria, Java, C++, Javascript, and Visual Basic.
My first dev job didn't use any of those, however. I had to ramp up on PHP, SQL, Perl, Python, and a little Ruby. Took two weeks to become productive, albeit not a master.
Over the years since then, I've used a wide variety of other tools (languages, frameworks, compilers, editors and IDEs, etc.) I can't imagine where I would be if I still insisted on using BASIC and writing code like
10 PRINT "Hello!"
20 GOTO 10
In the end, they're all just tools to do the job. You don't refuse to use a screwdriver just because you learned to use a hammer first.
Imagine being a 'frontend developer' who can only use squarespace.
More likely: Imagine being a 'frontend developer' who can only use React.
We all need a door into this stuff, a place to be dropped in to start putting it together. Maybe the OP’s sister in law is totally out of luck, or maybe she’s now got a few of the hundreds of tools she’s going to need to build out a career. Luckily she has a brother in law in the industry, hopefully he’s the helpful type.
So sadly these things don't tend to go away, they just evolve.
Economically set back, maybe. "Useless" (with its implication of permanence) is way OTT.
I don't think it's permanent, but it does make them economically useless until such a time as they retrain.
Consider transitioning from Excel to LibreOffice or Google Sheets. On the surface it's the same, but doing advanced things requires considerable time investment and is very uncomfortable.
Silly hypothetical. I can't imagine a scenario where a company heavily utilizes advanced Excel, and then decides they want to use Google Sheets instead.
Besides, we're programmers, and learning new tools all the time. Things are deemed obsolete regularly.
I can't imagine a company that has built it's foundations on AWS migrating off of AWS. Such an endeavour would be more painful than transitioning spreadsheet tool by at least multiple orders of magnitude on basically every metric you can come up with.
That's also a broad definition of programmer. Most people (even programmers) come in a few categories:
1) People just solving a problem, tinkerers and explorers, people who are not really programmers first but it solves a need to get further work done.
2) People who just want a job that pays; lots of these, bootcamp folks mostly though I don't mean to make it sound negative -- nothing wrong with people that just want a decent paying job.
3) People who learned enough skills as teenagers to be well paid and are coasting or specialising in that area. I know lots of people like this, I believe on some level that even I am like this, though generally curious I tend to mainly focus on my area and only expand slighty around it and slowly. If you swapped out Linux for VAX I would be terribly displeased. See also: SystemD
4) People who love to learn about computers and how they work. This is probably the rarest person, and I was this person in my teenage years. It doesn't matter to this kind of person the economic viability of a project: the only thing that matters is that they do something. This is the people who make GameBoy Colour games in 2023. Or the people writing console emulators or doing DemoScene.
The majority of people don't keep learning, they learn their area and improve upon it.
I firmly believe that an AWS Cloud Engineer (or AWS programmer) would strongly prefer to move to another AWS shop.
Having used both I’d say that the differences between Unix and VMS are much greater than the differences between Excel and Google Sheets.
A better comparison might be between Linux and BSD.
Comparing something as vast and broadly reaching as "Cloud" is a disengenous comparison to something as specific as a tool like Google Analytics, kind of a wierd comparison IMO. The entire pattern of tech is towards the "cloud" - even if you refuse to use the big ones like Amazon, Microsoft, or Google, it's still technically "cloud" if it's managed servers (wherever they may be).
To be honest I never got into the hype behind Google Analytics and I'm glad that I never spent more than 5 minutes at a time dropping the occasional tag on sites I built. (I've also never worked for anyone big enough where the analytics ultimately proved useful or valuable anyway). These tags are now easy to remove by deleting a few lines of code. I really wonder if the larger orgs really should have spent the extra few hours / weeks of development to develop an in house solution all along...
Is it? Tons of cloud people I know are very narrowly specialized and certified on AWS or Azure. They certainly don't ever apply for jobs using the other...
I'm sure they could retrain. But I'm also sure they don't want to.
I wouldn't blanket block a resume that said "cloud engineer", I'd just make sure to probe that they aren't just an "AWS engineer" or "Azure engineer".
A title I have frequently worked under is “Cloud Engineer”.
I’m strongest in AWS, secondly Azure. But I also am extensively using Linode’s platform and Kubernetes too.
My best friend’s title has also been “Cloud Engineer” and he is exclusively in AWS. He doesn’t really know more about Azure than he needs to get things connected to AAD.
How anyone could know that without asking eludes me. If you’re hiring for a position, you have a responsibility to know.
They use different jargon, they love to market themselves on their differences (because why compete on price?), but the fundamentals are really very similar and the skills transfer.
Anyone who’s telling you that Cloud X is vastly different from Cloud Y is either trying to sell you something, or has gotten their knowledge from someone who was selling them something.
Heck plenty of people come into ProServe with no AWS experience. But they know their areas of specialty well and it only takes a couple of months to use AWS specific services.
Thank you for this. No more second thoughts about pointing cloud.example.com at our local HPE rack.
Off the grid Homesteaders aren't more profitable than people who engage in the compromise of society.
Data analytics has some statistics in it, these days probably a pinch of training ML models and using them and understanding them in the basics as well. Source: I did some work for a company specializing in creating courses for actually learning data analyst skills, as a preparation for switching careers towards data analyst jobs. I myself helped creating course content. The course is officially certified for job-seeking people as a means of learning a new job.
It's interesting to observe how the existence of a mediocre course in Sweden is leveraged to make the popularity of Google Analytics a major concern.
And maybe the course is not even that Google-dominated. Looking at the content here https://medieinstitutet.se/utbildningar/digital-analytics-di..., they use both Google Analytics and Adobe Analytics and mention other tools like Hotjar.
Just taking Google employees alone, a few *tens* of thousands of people depend on this tool. Millions of non-Googlers depend on the tool.
All that said, there are other analytics systems out there mixpanel, amplitude, roll your own, etc. they might not be quite as full-featured but 95% if the value comes from a few features everyone has
The argument for Universities right here.
I always find the opinion that Universities should make students job ready to be naive, even if well intentioned. There's a place for certifications that focus on job readiness, and there needs to remain a place that focuses on first principles and primitives.
I went to University about a decade into my career as a programmer to fill in the pot holes and absorb the first principles and primitives. I advocate that route every time I can. It's great if people can get a certification and start working with GA right away, and they have a place to level up their career with the money they make if they want to.
Those skills are very transferable to new products and very little of the worth I bring is from my certs
I also have a sysadmin background and my journey to the cloud has been "I can learn new things that make things easier or just use some pretty standard Linux VMs at any time".
Most new entrants to cloud learn the following:
* an object storage system (GCS, S3)
* A functions as a Service system (Cloud functions, Lambda) -- if you are lucky, Cloud Run; since that also gives you Docker.
* Message systems (Pub/Sub, SQS)
* Maybe an orchestrator (GKE, ECS), but only surface level.
* Some very minor information on how to create and access VMs; but it's clumsy, since you have to also learn Linux, this is unused.
For me, I can always fall back to my foundational knowledge of DNS, Networking, Linux and the systems I used to run, like databases, app services, mail systems, queue systems etc;
For people who are trained only on FaaS and SQS they do not have foundational knowledge to fall back on. That's not to say they can't get it, but it's not helping them make money and it's usually not taught, and worse: it's not something you ever reach for- and people typically learn through failure or by doing.
For me: Cloud just makes my life easier.
But I can also use an iPad as a consumption device; if I was only ever given iPads I would not be able to write C++ or Perl. That's just the nature of exclusively using simplified tools and abstractions.
Most people who are “devops” with <8 YoE are unlikely to have touched non-cloud systems. Worse still, whether you want to admit it or not: some people are "DevOps" with no prior developer or sysadmin experience. (Since the term "Systems Administrator" is out of vogue but the need for systems administrators has never gone away.)
There are so many bootcamps for this too, and they mainly focus on AWS skills.
Here's a few bootcamps that people might decide to take to break into "DevOps" of which none are assuming prior knowledge, though techworld with Nana does teach a little Linux.
https://www.techworld-with-nana.com/devops-bootcamp
https://clarusway.com/aws-devops/
https://www.udemy.com/course/aws-devops-bootcamp/
https://techproeducation.com/courses/aws-devops-engineering/
https://aws.amazon.com/training/classroom/devops-engineering...
You don't need certain skills today; instead you can use higher order systems instead. That doesn't mean there's no value in understanding (to use a programmer example) a linked list.
Equally knowing how a queue system works from the OS to bytes on a wire can make a world of difference in some contexts.
You can live in the higher order world and use the tools that make life simple (google analytics, in the case of this thread) but you are jailed to not understanding the systems that they are made from and while you are exposed to some concepts not everything transfers cleanly. "What is the PostgreSQL equivalent of a ML.PREDICT in Google Spanner!".
To give another contrived example; a huge reason people learn Latin or complete computer science courses is not because they will be speaking Latin or using Comp Sci concepts; it is because it sets a foundation for learning other systems, a sort of proto-field that permits you to see the relationship building blocks on which other systems exist.
Even if we would train them on first principle primitives, recruiters don't view it that way. That's even true in the software dev world. If you don't have 3 years of experience in Java, then it doesn't matter that you're a 5 years experienced software engineer in all kinds of languages.
That's an elitist perspective that doesn't include the average worker making a living by knowing their tools and not much else.
My personal situation is possibly the least background elite possible and even I know that first principles are important in a field that is shifting -- which happens to be most fields, just tech is a bit faster at churning.
Not quite the same, the core concepts and skills of a Cloud Engineer should be easily transfereable between providers and even to on-prem infra.
Data engineering could be another path to explore.
I'd view your sister-in-law's certification course as more of a first step than an end. It could open doors but still have to stay relevant with broader skills.
Completely agree. So it is their personal decision. It has been forever.
People getting Macromedia Dreamweaver certifications instead of web development, and so on.
The side effect is that for each of those tools, there's an army of people that spent years studying them, and will push them at every opportunity they can.
And interestingly, those tools keep being pushed at places even when perfectly fine alternatives exist that won't give you almost any of those problems and don't require any specialization.
Skills are very seldom tied to a specific product these days, so she will be good.
I don't bill myself as such, but I am basically a "Cloud Engineer". My expertise is in no way dependent on a particular cloud, and I've done work in GCP, AWS, Azure, Rackspace, and even a private cloud or two. A VM is a VM, Postgres is still (more or less) PG regardless of who is hosting it. Sure, there are specifics, but even cloud-specific stuff really doesn't differ too much, and it's pretty easy to find the common memes between the two. I can assign a role to VM in AWS, an IAM service account to a VM in GCP, and an "identity" in Azure. All 3 then permit the VM to make API calls to the respective cloud. All 3 fetch their access token in basically the same (but incompatible, of course) ways: HTTP request to a magic link-local IP.
A lot of the concerns I deal with, such as "can we survive an outage? what types?" depend on concepts like failure domains that apply equally to a cloud or to a datacenter.
But at some point, I had to dip my toe into a new cloud. I started a new job, and they used this thing called "Azure", and at that point, I'd never heard of it before. But you approach it with an open mind and the right balance of "some of my old knowledge might be relevant, but this new thing might also work differently and I should be prepared to build a separate mental model around it if the old knowledge is leading me astray."
… and I'd expect the same from someone doing "data analytics"; I'd expect something like "math is math, how I collect the data might change, what APIs I use to process it might change but the math is the same."
If a 6-12 month training has no skill transferable to another analytics tool, I strongly suspect the training was useless to begin with. Other analytics tools are not so dramatically different from GA that you'd lose all methodology on what to monitor, how to conduct a study, etc.
To make an analogy, you don't suddenly become useless if you move from Java to C#.
Going from Haskell or Scheme to Rust or even Python is going to take some time before you're completely comfortable with all the built-in's the standard libraries, the "pythonic" or "rustic" way of writing, tools and so on.
It's a lot of hidden things, you're not completely useless of course, but it's not like you write "production quality" code and have the ability to work completely independently or be an SME (like you probably were) within 1 month or even 2. It's a lot of little work to get back to where you were professionally.
Because it's not just a training course that is lost, it's all the incidental knowledge that was picked up on the job too.
(Also Haskell to Rust is pretty straightforward, the typesystem knowledge you learn in Haskell usually means the harder parts of learning rust are made easy. Having done that transition, 1 month is reasonable to be productive in Rust)
It's not hard at all, it's just that we have become too lazy and mentally dependent on big tech companies!
If all you want is user tracking, a few lines of JavaScript is all you need on the frontend. A popular WordPress plugin named jetpack gives you almost all data needed for site analytics, for example.
There are other tools too like tableau and python based tools like pandas and numpy which help you with all kinds of analysis.
Humble techies are everywhere with their tools, you just have to trust them a little bit, that's all! It's almost like trusting your Uncle Joe's pizza dude next door instead of the familiar Domino's or McDonald's. It takes a while but you'll eventually discover there's no difference.
Compared to something like a Cisco networking certification: The CCNA will cover practical use of their products, sure, but they're also going to teach you subnetting, both standard and Cisco proprietary routing protocols and how they work, in theory, as well as how to employ them in practice. I've mostly moved on from using Cisco products day to day, but all of the understanding was directly translatable to any other platform I've worked with.
On one level it's an important observation, on another it's mundane: DBAs will fight one another over Oracle vs DB2 vs SQL Server. Traditional bare-metal DBAs will fight RDS. C programmers are upset by Rust. People who invested a lot of effort in shell scripting for SysV init dislike systemd or s6.
But Google lost me by:
A) Making it impossible to convert your old data into the new Analytics version
B) Abandoning the API which allowed you to code your own reports. Over the years, I wrote a ton of code that talks to the API. This is all worthless now.
I recently switched to self-hosted Matomo. At first I did not think much about it, but now after I got used to it, I have to say it is much better than GA. The interface is so much nicer and snappier. And more logical.
Apart from that, I like that it is open source. If there ever is a point in the road where the makers of Matomo decide on a non-compatible fork, I'm sure the community will write a converter that converts the old data into the new format.
And after using it for a while, it hit me: You can write your own reporting tools by just querying the MariaDB database! Using SQL is so much better than it was to fight the insanely complex and unintuitive Google Analytics API.
If I really wanted to still use Google Analytics, I would just write a converter, which pumps all the Matomo events into Google Analytics. That would be a GDPR-compliant way to use Google's tools. But I don't. I'm done with Google Analytics forever. Matomo is the promised land for me.
Of course, it would be just as simple to use the salt as-is, in that case, since you have to look it up anyway.
If you use a random salt, then you need to store it or else the stored value has no utility. However you implement retrieval of that salt it can just be brute forced.
The entropy can be in the salt, you're all making it sound way too easy. The requirement is "non-reversible". Given infinite time everything can be brute-forced, but this is the mossad/not-mossad problem.
It's good enough for storing passwords, where the salt is plain-text.
Even without any cracking at all, shared salt would mean that rows can be correlated if the attacker can identify a single row and correlate that to the target.
Let's say you use up the game and use per-row salts, like here: https://stackoverflow.com/questions/4159827/another-question...
Given an attacker wanting to pull out information about a specific user, and they have on their hands your salted dataset, the salts, and a handful of IP addresses that the target is known to be associated with from other datasets, it's still trivial to brute-force.
Even increasing it to a set of a few thousand IP addresses (say, a handful of /24s) it should be perfectly realistic, assuming you don't use enough rounds that your infrastructure is spending a majority of its CPU-time only performing psuedoanonymizing hashing.
Oh, and if you use per-row salts, is any of that data still usable in the first place?
The above is besides the point of the IPv4 address space being small enough to exhaust and shows why this is an issue for IPv6 addresses as well.
The term of art in that case is 'pepper'.
After rereading, I suspect by 'shared' you meant 'non unique' rather than 'public'?
> In cryptography, a pepper is a secret added to an input such as a password during hashing with a cryptographic hash function. This value differs from a salt in that it is not stored alongside a password hash, but rather the pepper is kept separate in some other medium, such as a Hardware Security Module.
A salt is a unique random value added to each value when hashing. Obviously, such a salt needs to be stored alongside each value because it’s random and unique. If you don’t store it how could you possibly ever figure out what it is?
A pepper is a shared value added to lots of different things before they are hashed. It isn’t unique to each value, so it doesn’t need to be stored alongside them. Although it still needs to be stored somewhere. But hey, you could also store it alongside every value you store. This is a thing sometimes done when you do ‘per user’ pepper, where for example the pepper is itself a a username or something - so your pepper is also in the database alongside the passwords - but that doesn’t make it a salt.
If you are using the same piece of data to season multiple things before hashing, you are using ‘pepper’ not ‘salt’.
If you know the salt then you can trivially brute-force it yourself and now you are not GDPR-compliant.
If you don't know the salt then you'll have to use a new salt for each IP and then all hashed IPs will be unique and you have no way of correlating them so it is all completely worthless.
for i in 0..<(1<<32):
if H(i, salt) == h:
return iThe solution being overkill does not mean my first comment 'That's why you use a salt, which is what I assume is meant by "non-reversibly"' is wrong.
Now, with IPv6 for most consumers the first 64 bits is generally enough to define the edge network device that would be covered by a single IPv4 these days.
One complication is that hashing removes this structure. If you use any good algorithm, you will need to test the entire address to recover any part of it.
I am very wary of IPv6 addresses being so heavily biased into 00 or ff segments that the address space doesn't actually add much entropy. So, I'd go with no, it's not safe to hash them. But if you get some random ones, I am really not sure.
Server-wide salt. Randomly generated every 24h or server reboot (whichever is sooner).
The salt is not saved alongside the hashed IP, it is not saved anywhere whatsoever. There is no log of previous salts.
You can still track a user session across multiple page calls, but the hash can not track them across different sites.
The data we were leaking was e.g. the fact Foo was employee at ACME, simply because we sent events occurring on the estate of Acme for user Foo.
It's not as straightforward as proxying. Or, as we did, removing some bits from the IP.
CDON used GA's IP anonymization through truncation, it was not deemed enough. [1] The IP itself becomes is not personal data after truncation but it's unclear if the truncation happens before it leaves the country. And combined with the other personal data (e.g. cookies), it is considered personal data. [2]
Coop proxied all calls to GA and use the same generic IP address for all users. [3] They don't get a fine but have to stop using GA.
[1] "1.3.15 Effektiviteten hos vidtagna skyddsåtgärder av Google och CDON" https://www.imy.se/globalassets/dokument/beslut/2023/beslut-...
[2] "2.2.2 Integritetsskyddsmyndighetens bedömning" https://www.imy.se/globalassets/dokument/beslut/2023/beslut-...
[3] "1.3.14.2 Coops implementering av server side container" https://www.imy.se/globalassets/dokument/beslut/2023/beslut-...
1.3.14.2 Coop's implementation of the server side container The purpose of the server side container that Coop has implemented is to improve the security related to the data sent. More specifically, the aim is to on a good and safely be able to protect the personal privacy of those registered. Server side the container acts as a proxy between the registrant's browser and the Tool where Coop has chosen to implement the server side container in a way that makes them the registered browser's public IP address is never transmitted to the Tool. Implementation can be described as follows. A registrant visits the website www.coop.se in your browser. The Google Analytics script is downloaded from the server side container instead of being downloaded directly from Google Analytics servers. This results in the registrant's IP address as well as information about user behavior, device information, customer status, online identifiers and transaction data (according to points 1–5 above under section 1.3.10) are transferred to the server side container, instead directly to Google Analytics. Once the Google Analytics script has been downloaded from the server side container, a new call is made from the server side container to Google Analytics servers. Since the call is made from the server side container, no transfer of the registrant's public IP address to Google Analytics. Coop has configured the server side container in such a way that all data as above, except it was recorded public IP address, passes through the server side container to Google Analytics. Google Analytics receives data sent from the server side container and that data (information) that has been sent is popularized in reports by the measurement set up on the website www.coop.se. The treatments that take place through the aforementioned – i.e. to receive, convert and forward the call - takes place in the working memory of the server side container. It means all processing takes place in real time and that no data is permanently stored. In other words, stored public IP addresses were not registered in the server side container and they are not exposed rather against Google Analytics servers. All communication from the browser, via server side container, to The tool is also encrypted.
This process cannot be reversed as the information is not stored and the conversion not based on a one-to-one relationship that enables the use of a "key" to recreate the public IP addresses. Coop has activated Google's function for IP anonymization. It means that the IP address sent to the Tool is truncated. This is done by Google removing one part of the IP address before the IP address is stored on disk. For an IPv4 address, last is replaced the octet in the address with a zero. For an IPv6 address, the last 80 bits are replaced with zeros. The action cannot be reversed but as this action is done by Google i Coop has also chosen to implement the tool as a server side container. In Coop's case, the IP anonymization feature is enabled and applied to the generic IP address sent via the server side container. In context, however, the function is redundant considering that the server side container prevents the public of the registered IP addresses from being sent to the Tool. Coop's assessment is that server side the container as a measure is a sufficient protective measure, but that it does not harm that even have the IP anonymization function activated in the Tool.
Do you happen to know which section of the ruling it is where they discuss why Coop needs to stop doing this? It's a PDF and the translation tool I'm using on my phone is a pain.
I am looking for something where I can track which button he pressed, how many times, which part of the app are the most used and underused, do some funnel of the happy paths, things like that. Like not to know who is the user but really app based and how the user uses the app. Before I used to use Google Tag Manager for that. But it’s not GRPD compliant so I can’t use it.
If you're only interested in session data without collecting any cross-session knowledge, all you have to do, basically, is tag your page and listen to dom events.
It is impossible to believe a team as well-funded as Analytics could/would not find a way to automatically migrate gtag.js to GA4. They should have made the upgrade transparent by simply converting requests behind the scenes so legacy analytics properties could exist perpetually, while forcing new property registrations to use GA4.
There are arguments that GA4 would fail the same requirements. Denmark hold that view but it hasn't been tried. Their argument is that a EU-citizen that goes to Asia and visits a site there, will have his information sent to US servers and not EU servers. I find this argument objectively absurd considering how internet works but it possible that's how the law works. We wouldn't know before it has been tried though and I'd be sceptical about anyone claiming to know the result.
Agreed, this is absolutely ridiculous. And I say this as an EU resident! I’d rather NOT have websites start checking residency/citizenship to decide my data ownership.
The CLOUD Act requires US based companies to comply with US requests for data even when that data is stored exclusively outside the US. It's in direct conflict with the GDPR.
However I don't see that, and thus Europeans familiar with the relevant cases give “dominance of Americans” as the reason.
The European Comission has repeteadly tried to figure out a framework that would let US providers access EU markets safely, respecting EU laws. Every single attempt has been broken because there is no way for an US company to respect EU law and also comply with the CLOUD act.
The bit of law you suggest would essentially make it impossible for a company to respect both EU law and US law.
Sources for this extraordinary claim, please.
As an EU citizen I'm interested in the EU protecting my privacy, not for nationalistic reasons, not to prop up EU's industries. I care that my data isn't willy-nilly given away under some opaque mechanisms controlled by large corporations, because as many here on HN like to remind me: capitalism is amoral, this is some regulation instilling morals into the system.
I want to be aware and protected about where my data is being used, for what purposes, and I want to have the power to control how corporations can use my data, or if they can use it at all. This kind of data can be modeled into a version of what a system sees as "me", through the interactions I had with it, building a profile of what moves, and interests me, I want to be able to know and control who can know, and to what degree, who I am.
If you are against that, please explain why.
The EU has a fundamentally different viewpoint on data privacy to the USA. And they are entitled to it. The EU has roughly as many citizens as the USA under a single governance; why should they not collectively argue?
Many Europeans do, also, think the USA is mad on other issues and are unwilling to see a situation where the USA's chosen solutions to things are the de facto solutions. They see data privacy as one of the last opportunities to resist that.
(Alas here in the UK we decided we didn't want to be part of that solidarity, and we are apparently desperate to capitulate.)
As a side note, why is it only ever non-American states that are said to "prop up" their own businesses? It's a two-way street.
The regulation just makes sure Europe stays unimportant in tech. We will always be a secondary market that services get taken to once they've become successful elsewhere.
It's not even about any specific regulation anymore. Just the fact that they've been so trigger happy with regulations is enough to chase away investors and startups.
I would also like to remind people that the EU did adopt the Data Retention Directive in the past that forced ISPs to keep logs of every website people visited. That kind of soured any belief I had of EU politicians caring about our privacy.
>According to the Data Retention Directive, EU member states had to store information on all citizens' telecommunications data (phone and internet connections) for a minimum of six months and at most twenty-four months, to be delivered on demand to police authorities.
On the one hand, I kinda agree with DK, on the other hand that would bring on the fears of US-liberal HNers who lose all their freedom to sell user data.
Consider an online store shipping physical goods. It asks you for a shipping address. This shipping address is PII and must be treated as such. The facts that you may reside elsewhere and that multiple other people may be residing on that address are both irrelevant to the GDPR.
https://www.fieldfisher.com/en/services/privacy-security-and...
https://commission.europa.eu/law/law-topic/data-protection/r...
The decisions don't explicitly mention a version, they say these particular sites: "...shall cease to use the version of the Google Analytics tool used on 14 August 2020". They don't say if that's UA or GA4. The original complaints from NOYB refer to UA, but the issues cited in this decision would apply to GA4 as well.
So when the DPA says "Companies must stop using Google Analytics", there's no reason to think they only mean the version that was already shut off when they published that post.
"This shall be done in particular by ceasing to use that version of the tool Google Analytics as used on August 14, 2020, if not sufficient protective measures have been taken."
[1] https://www.imy.se/globalassets/dokument/beslut/2023/beslut-...
Remember, you aren't the customer if you embed Google Analytics, Google is.
edit: if you want analytics, honestly just roll your own... you can't trust advertising companies with your users' data
But, host your own is definitely recommended IMO; a lot of the GDPR issues are resolved if you just host your own, because no data is shared to a 3rd party. Then you only need to worry about getting some approval and data retention. I'm sure data retention is a non-issue if you process raw analytics data (that can be traced back to a user) into generalized statistics, too.
Why does anyone need all that?
Useful information is more like, what users clicked, what platform did they use, how much time they spent on the website and things like that. Those aren't that hard to just track yourself.
With that being said, I don't make everything myself, but just the thought that I'm not obliged to use the best-practice standard solution to the problem is liberating to me and it makes me so much more productive in actually doing stuff.
When I research about programming languages I'm always amazed how almost every feature existed in the 70s as well, just no one bothered to use it.
But I am coming around to the idea that self hosted(atleast partially) might be cheaper and better if you are a single dev/a small team.
The learning curve on the tools/hosting providers out there is has become very steep. Plus the costs are unclear with a lot of cloud providers and monthly subscription charges across the services you need can quickly stack up or the prices can suddenly change.
I tried deploying an app to AWS a few months back. You get a year's worth of credit when you start out. But the database I used was not covered(I did not realize all the database options were not covered). I got charged a pretty penny(Luckily it was not life shattering, but it was a shock. I hate to imagine what would have happened if I did this for a bigger app)
Tried Google Analytics a few times over the last few years. But again it has become complex, so I would had to spend a ton of time learning it to even just get started.
Had a few SAAS providers suddenly hike up prices or change pricing models or just shut down.
We have been using dedicated servers of late. A single server seems to be able to handle multiple client apps along with hobby/test apps for a fixed price. Yes it is not as easy as putting in an email and credit card and using a service. But the price and peace of mind has been worth it. Plus we just write a few scripts to automate things. In case the work load becomes too much we can hire a person to do that and 1 person will do. Compared to having to hire a specialist for each major cloud service we use.
AWS is a toolbox you can use to construct your app deployment/hosting environment. Unless you know or want to know how to (for example) setup routing on VPCs, it may be better to go with someone actually hosting apps rather than infrastructure.
My go to 'cloud' path is just a digital ocean droplet, using docker containers to spool up whatever you need and connect it all on a docker network.
A single server (2-4 cores) running quite literally ANY modern backend framework (node, go, C#) should be able to handle _thousands_ of requests per second, I'm not sure where or when this idea has disappeared, it seems like everyone automatically assumes their small SaaS or webshop needs an autoscaling kubernetes 20 rack workhorse of a server. Not the case at all!!!!
Scale when you need to - if you're getting the kind of traffic where you need to, by then you won't need to worry about the added cost to do the actual scaling / upgrading.
Sorry for the winded / ranty answer, I've done this like 20+ times at this point and always had to battle against the "let's put it on AWS with kubectl and 2349023 redundant instances!", when in the long run it was never needed...
(With caveats: This is a toy pipeline. More work required to make it robust and probably not a great option for any site with reasonable traffic. But easy to get started and play.)
[1] https://github.com/matomo-org/matomo-nginx/blob/master/sites...
Imagine you are a great speaker and instructor and have an audience. Right now you GIFT it to YouTube, Twitter, etc. and they monetize it for you, give you a tiny percentage, and even constantly direct your audience to competitors and other distractions. In fact YouTube even sells an option to advertise your videos on your competitor’s videos!
I say — opt out. Run your own everything! Your own community software (instead of Discord). Your own videoconferencing, livestreaming, chats, presentations, gated content, accept payments with crypto in addition to PaymentRequest. It’s hard to build an open-source alternative that is good enough (no, Mastodon and Bluesky aren’t — yet).
Which is why (shameless plug warning) I spent 12 years and $1 million dollars with my team to build it. https://github.com/Qbix/Platform
Use it — as 1 of hundreds of features, you can have your own analytics on your own database on your own community site. The other features are here: https://qbix.com/features.pdf
PS: Don’t get me wrong. Keep using YouTube to host your content, etc. But relegate it to hosting short form teasers and highlights and testimonials all of which link to your site. People can discover you on the big sites but if they are serious about your long-form content and community they should buy a membership on YOUR site and have a direct relationship — then deplatforming or coersion will be the last of your worries.
Also, the features pdf lists "nodejs" and "php" as features.. I don't mean to be snarky here, but I am simply not sure what this product is?
But all those overlapping screen shots make it look like there's been an explosion at the website factory and the smart thing is for me to run in the other direction.
1/3 of the Youtube videos are just "This video is unavailable".
I couldn't look at it that much longer because the colorful stars falling out of my mouse cursor was so distracting I had to close the tab.
When I visit YouTube, Facebook or Twitter, they seem extremely "busy", overrun with ads, and rather ugly, but we are used to them. I am not sure it's so bad to have a clean layout. But I am open to constructive criticism.
None of what I'm saying is criticism BTW. Just observation.
On desktop, it's pretty easy to open one of the menus on the top and then have it fail to close. Since the site disables the scrollbars while a menu is open, it breaks the site until you figure out the magic spot to move the mouse to make the menu close again. The magic spot doesn't seem to be in the same place every time. Seems buggy. I spent most of my time on this site with one of the menus open, unable to scroll down and see beyond the first page.
The worst part? The links in the menus don't work. A peek in the source code suggests they are supposed to be links, but clicking them doesn't do anything because they're just <div>s (not real <a> links) and the click event handler simply calls preventDefault (QTools.js line 107). That finicky navbar nearly ruins the entire site. I'm almost entirely unable to navigate around. This site is, unfortunately, pretty broken on desktop Chrome. Test your site on desktop in addition to mobile.
I got the site to hit an explicit debugger breakpoint in Q.js line 10293 just by clicking around the top menu buttons. The author of that code didn't bother writing an exception handler, they just had it trigger the debugger.
I do find it offputting; the site definitely has the feel of "a programmer hacked this together without any input from a designer." The massive drop shadow from the embedded videos actually covers up some of the text on desktop. The font is VERY thin--make sure to check your site on Windows and not just macOS. More generally: hire a designer. Programmer designs stick out in a bad way, and users seeing a broken marketing site will assume the product is broken, too. I certainly do.
1. Install Chrome for Windows from the Google website. As of today, that version is 114.0.5735.199 (Official Build) (64-bit). I am testing on Windows 11 and I used a fresh install of Chrome on a machine that has never had Chrome before. This machine has a standard 60Hz display which may matter for my theory at the end.
2. Go to qbix.com.
3. Hover the mouse over "Communities". Now hover over its submenu items. Observe that they do not highlight on rollover like they're supposed to, and clicking on them does not do anything.
4. Now quickly move the mouse outside of the menu. Observe that the mouse escapes the menu, and the menu does not close. Move the mouse around the rest of the page. Observe that the menu continues to stay open. Observe that you can't scroll the page. In this state, the site is unusable.
5. Move the mouse back inside the menu, then slowly move the mouse across the edge of the menu. Observe that now the menu closes.
I have reproduced the same in Edge and Vivaldi; the issues appear to manifest in Chromium-based browsers on Windows. I tested on macOS and iOS and the issue does not show up there. I can provide a screen capture if needed. Without looking deeper, I wonder if this page is trying to use JavaScript to close the menu based on a mouse event that it misses when you move the mouse too fast. I wonder if the entire navbar is implemented in JavaScript instead of a modern CSS-only technique with regular links.
The worst thing is when some users see a heisenbug that you can't seem to reproduce on a similar environment.
Please try creating a fresh cloud Windows instance rather than using your usual computer so you can be sure you are seeing what a fresh user on a new computer would see. I have done so--this reproduces in the preinstalled Edge on a brand new c6a.large Windows Server 2022 instance in AWS. I can provide a click-by-click screen capture starting at the AWS Management Console if desired--I've found this is a good way to prove bug reports to companies and demonstrate that it has nothing to do with my computer.
Here is the screen capture. This video shows the creation of a fresh Windows instance in AWS EC2 and then the reproduction of all of the above issues in that fresh instance. Follow my exact clicks and you will see it, too.
It would definitely be more appealing to the masses if it was brought more in line with a more minimalist 2023 aesthetic, IMO.
- There's a confetti effect following my cursor around - There are constant animations playing everywhere, even over video embeds - A lot of the spacing is uncomfortably tight - Shadow effects overlap other content - There are some 30 menu options, buttons everywhere, many video embeds that I'm supposed to listen to?
None of this is enticing me to consume any content on your website. I'm feeling uncomfortable even trying to browse the site to find out what your product is. I've learned that a significant portion of the web runs on PHP and that you have an app and a token of some sort? And you're looking for investors? I'm sure there's very cool ideas in here, but I'm lost in the vast amount of information with inscrutable organisation.
All that aside, there's a big reason that a lot of landing pages look similar: it works. First impressions count for a lot.
It’s actually about 55% for YouTube. Creators are in demand and it’s competitive to keep them.
How much of that one million dollars dollars went to creating the confetti effect following the mouse cursor around on https://qbix.com/ ?
That's far more useful than hoping that people have JS enabled or tracking stuff blocked.
(I.e. Can see that they visited an order page, then back to FAQ's, then clicked on a "whats is x" link - so should probably update the content on the order page to explain what X is)
Obviously it depends on what data you actually need, but that gets me most of the way there without gathering a load of data that isn't needed
I usually describe the cost of GA as "subsidized by your customers' data".
I think for most use cases users would want to know if their content is consumed/read. Maybe how long someone spends on it and where they came from. For this sort of stuff you can write a small script to parse your logs. I did something along these lines to parse Caddy logs to get some idea of how many people visit a link. That's really all I needed and the great part is that I run it whenever I want an update, so it's not consuming resources constantly. The logs are cleared and the output is saved before logs are cleared so I know Article 1 had 39 views (or less!) and Article 2 had 5 views and so on...
So I think we're overdoing it and we would benefit from taking a few minutes before going down the rabbit hole of analyzing EVERYTHING.
IFF you have access to your logs.
Not necessarily. If I read the article correctly, it is about sending data to the US:
> The complaints allege that the companies, in violation of the law, transfer personal data to the United States.
So if the 3rd party is inside the EU, you might be fine. Or at least you may run into different GDPR issues.
What I'd be curious to see is the ROI on these tools. They obviously work in some cases, but do they always work? We currently employ three business intelligence developers, and two developers who actually build products. What's the most hilarious about it, however, is that despite employing three BI's I can't tell you if they earn their keep, because their data doesn't show that.
I sometimes check access logs and pipe some grep queries into a line counter, or uniq by IP address to have a rough idea of how many people look at a particular part of, or tool on, my website. Maybe twice a year or so. Helps prioritise which things are worth maintaining/updating based on what's still being read (found by search engine or linked from third parties)
It's more then enough for me.
And a few clients whom I enabled it for, told me they very much liked the simplicity. Less data as a feature!
I found a bad bug in their JS which means that on some pages it just silently fails and doesn't log anything, which means your analytics are even more inaccurate than ever (given the browser restrictions). I was totally broke and I wanted to use their paid service for a few months, so I offered them the fix in exchange for a few months free service (maybe $30 credit?). They told me basically "don't worry, we'll find the bug ourselves one day, we don't need your help."
But I've been in one, where a customer offered "patches", despite our software not being open for contributions. Not only were they inconsistent with our standards, they were hard to read and had some subtle security issues on careful review. I'm still suspecting it was an attempt to plant a backdoor.
In any case, even if legit, it was a lot of work on our side to just review and clean it. Far more than if we just did it ourselves.
This is different for OSS, which should have external contributions as main workflow. Ours wasn't prepared for external contributions.
Maybe the same is with Plausible?
Tracking events is actually useful to see which features are used etc.
It's not all marketing and evil ads.
Having said that, GA4 is awful as a casual user.
IMHO, it's not totally your fault; private information shouldn't be shared with others. It's your responsibility to verify what ChatGPT is writing before you use it; it's OpenAI's responsibility to not share private information.
Yeah we have copilot subscriptions at work and an Azure GPT-4 instance that is being trained with enterprise data.
When I worked at companies using google analytics, 99.9% of the time they could have gotten this data from server logs with something like awstats or goaccess.
To this day, I still don't get what's the point of embedding some javascript to do extra-requests or a tracking pixel, when the data was already given once.
Not that they actually get questioned properly about actual stats, but they can confidently say they have GA set up and it’s showing some numbers, so just trust us.
Google is “trusted”. Why would the person setting their budget put faith in some hand rolled/open source solution ?! /s
Additionally, a common argument is that the server side logs contain a lot of logs from bots/crawlers and GA (and alike) can filter them. The other side of the coin is that GA (and alike) are not able to track users with Adblockers.
EDIT: not sure why I'm downvoted - the OP asked for some reasons why people use client side tracking and I listed them. I didn't say that I support these practices, but maybe I should have made that explicit to comply with the overall sentiment of this site.
Does anyone have any experience? How bad does CG-NAT mess this up over a large enough cohort of users?
The best way to get feedback is to talk to your users face to face, or do a questionnaire.
Reading the linked rulings it seems like it's not the IP (even though it's only blanked at the last octet) but rather other cookie values, which may in turn be traceable to the user?
Of course if a cookie value is sent and in some other system that same cookie value is stored next to a user's name, then that cookie value is definitely PII and can't be sent via GA, that much I understand.
The key passage from the longest ruling (DI) seems to be
Dessa identifierare har skapats med syftet att kunna särskilja individuella besökare, såsom klaganden. De unika identifierarna gör därmed besökarna på Webbplatsen identifierbara. Även om sådana unika identifierare (enligt punkt 1 ovan) i sig inte skulle anses göra enskilda identifierbara, måste det dock beaktas att dessa unika identifierare i det aktuella fallet kan kombineras med ytterligare element (enligt punkterna 2–4 ovan) samt att det är möjligt att dra slutsatser i förhållande till information (enligt punkterna 2–4 ovan) som medför att uppgifter utgör personuppgifter, oaktat om IP-adressen inte överförts i sin helhet
Basically: the random ids aren't enough by themselves, nor is the IP, but the IDS together with partial IPs and something else is.
I don't know what the bottom line is though. And that worries me a bit. Any analytics will be at risk of doing this. In my desktop app analytics we blank IPs etc, but just storing some hardware data (ram amount, cpu freq, windows version, screen resolution...) means that we eventually have enough entropy to say with certainty that each user we have has a unique set of parameters in the data we log. It's almost impossible to NOT fingerprint perfectly if you gather even just basic hardware and OS info, for example. But there is of course zero possibility that we could use the data backwards and say "ok which single physical person is it that has a 16 core machine and 16Gb ram" making it "not PII"?
I think the key issue in these cases with GA is that it's more a chain leading to actual PII. E.g. the cookie value that GA has access to, can realistically be stored somewhere where there is also PII such as an email address. And that's enough to violate the GDPR.
SEO and Marketing Dept. of any company.
You need an interface that visualizes the data and decentralizes access and analytics as much as possible.
Since Google Analytics is free and more or less part of one of the biggest marketing stacks (Google Ads) you will find a lot of marketing stakeholders with at least some knowledge of the tool. But perhaps the landscape will change with the very rocky start of Google Analytics 4
The argument kept coming down to "GA is the standard; GA is what people know". Which is... true, if not somewhat circular.
My other suggestion was try multiple; run GA and Matomo together, for example, for a bit. Or GA on just the public marketing site, and something else on the internal application. Nope, because they wanted to track every single ad spend all the way through to registered user usage of the internal business application. Knowing that the $70 you spent in Tacoma geo lead to 3 users registering then knowing that those 3 people routinely used a budgeting tool more than the $90 spent on 8 people who registered from Toronto... apparently those sorts of analytics might be needed in the future, so we have to have this.
Instead of "let's just install both for a few weeks and try them", this became "let's 'investigate' multiple options and write reports about the pros and cons of each". Nuts. My larger concern was that, for testing/dev purposes, we'd not have as easy a time of 'resetting' an analytics DB that was not under our control (resetting or maybe creating new/unlimited sandboxes for each test run). I didn't find any way in GA (or really any hosted solution) to handle testing well. But maybe that's not a big concern among 'enterprise' analytics users?
It's just another thing everyone does and one would be stupid not to, right, right? The lemming mentality always makes me sad because so many bad things in our society are a result of it.
And every time someone says that rolling your own is a waste of time,.. I roll everything my own, including CMS / SPA frameworks, because it's a giant waste of time to do otherwise in the long run. The only time I waste regarding rolling on my own is when tobacco is involved.
Of course there's more to it, depending on the app needs. In my case it also auto refreshes the contents on a js timer.
What UX regressions did you have in mind as troubling? Things like resetting one's password if forgotten? Well all those things need to be turned into their own ajax calls and php scripts as well and sometimes reworked to fit mobile users needs. For resetting passwords specifically I just copied what Twitch.com does.
- updating the URL state when someone clicks on a button
- proper back-button support in the browser that takes me back to the prior 'page'
- being able to navigate to any URL deep in your app and get a valid response (ideally rendered server-side so there's no client-side loading delay).
Things like these are hard, and the reason why it's common advice to use a framework and not hand roll. If you hand roll but don't support these things gracefully, you're making a case for not hand rolling.
It really just worked without much troubleshooting. Most trouble I've had was with cookies and cross-origin problems (or weird client requests).
This set of possibilities spans all cases and none is actually a positive signal.
Companies (and any entity that has an online presence for that matter) are entitled to know what people are doing in their platform and use any appropriate tool for that purpose. They are not entitled to share that with anyone without the explicit warning and approval of their users.
The Web as a digital predation ground where the amoral fleece the ignorami must stop.
While (commercial) life is not exactly an ethical showcase, the digital version as it has come to evolve is particularly out of kilt with common norms.
Your average person at your average company will one day think, "how are people finding out about us?". They do a Google search for how to answer this question for their company and find Google Analytics.
This is certainly not hostile. May be slightly ignorant, but can you blame them?
But the web has not been transformed from a web of users to a web of data mined "product" without very conscious moral choices by many commercial actors.
So using the by law (GDPR) required consent management (cookie banner) where the user has the chance to opt out of any tracking would make them not "lazy, ignorant or hostile" anymore?
I think users should have tight control over their own data and what they share but being against all 3rd party ad or analytics vendors would be against digital user acquisition for 99% of websites out there.
That’s not how it works. If there’s personal data being transferred to the US, you are in violation according to the Schrems II ruling. If you only collect non-PII, you should be fine. Make sure though that your definition of PII matches the regulator‘s definition.
GDPR simply makes collecting personal data without consent illegal. This is why a lot of American centric sites block us from accessing them, they want your data, and they don't want to ask for it.
Or they just think that the costs to adapt their solution, or any law infringement implications don't worth the effort.
> law infringement implications
They comes from using people data in ways that you have no asked permission for. They don't want to ask for it because it's quite hard to spin "we want to mine your data for a Cambridge Analytica style social manipulation".
Adaption isn't that difficult, the cost comes from people saying no. They don't want to give that option.
> You say "or" but then just give examples of what I said. > law infringement implications
No, you mean law infringement implications, like they actually selling your data, I mean some law office, running behind companies not compliant and trying literally money extortion against them.
Also, requiring it when it is not technically required for the product is illegal. So even throwing up a splash screen for EU visitors with a single "allow all" button would be illegal.
The GDPR is actually a quite well designed law for what it tries to do, its just that enforcement lags behind.
One could argue that since it's a US-based company it can't be Shrems II compliant, but you can make that argument about a lot of things.
You might have a legitimate interest in processing the IP, but because of the aforementioned issues, you cannot provide sufficient controls nor protection of Personal Data.
As such, using Cloudflare as your Data Processor, exposes You, the Data Controller, to DPA scrutiny. As always with GDPR/DPA and EU, whether it is illegal/non-compliant depends on each DPA.
https://medium.com/@christhaefner/shopify-illegal-in-germany...
- GDPR: hosted in EU vs US, so your data is traveling less far. The things the plausible can do with the data is more or less the same.
- No cookies: don't see the point of that tbh, they will probably perform even more invasive tricks like finger printing to replace the cookie requirement
Bottom line, the website visitors data is still logged, stored and tracked - only now with a different actor.
It's clear you didn't even bother to look at plausibles data policy [1] before assuming what it does and doesn't collect. The TL;DR: it does not fingerprint, and it does not collect any identifiable information, be it about your device or your person.
> Bottom line, the website visitors data is still logged, stored and tracked - only now with a different actor.
Only basic device info is logged (not even IP addresses are stored). And it's very easy to self host so that different actor may be yourself.
[1]: https://plausible.io/data-policy#first-thing-first-what-we-c...
Google Analytics also does not provide PII to their end users per se. But I have seen many tools and solutions do just about anything to circumvent that. Merging analytics with transactional data and site logs. Adding company info to visitor data. There is an entire industry there.
So, an imaginable use case would be to self host it. Intercept to circumvent the limitation.
The reason why I am so cynical is not because of the motivations of Google Analytics or Plausible. It is what motivates the end users, the companies who are using these statistics.
I get the cynicism about the industry in general since Google led this merger between web analytics and advertising, but there are plenty of providers in the analytics space that aren't following that path.
- Simple and easy: wait until the product matures
- Open source: but no foundational governance, like Apache for example.
- Promise never to sell to investors, but nothing is in place to actually prevent that from happening. Note this common practice via a social enterprise.
- 45 kg reduction of CO2 compared to Google per average website(!): clear violation of EU law (2006/114/EG) in my opinion.
- They suggest to proxy their service to circumvent consumers who actively block traffic to plausible. This is OK, because they are good.[0]
As a web developer, I didn't see it as a big problem. We always do it to maximize ad revenue, find out where users leave to increase conversion rate, and simply to improve UX. But even when the intent is to improve UX, tracking is inappripriate.
Imagine if a robot vacuum recorded videos of your home and uploaded them so that bunch of ML engineers can see and use it to improve the algorithm. Or the videos of your car's camera (both of inside and outside). I mean, I'm not surprised if this is already happening, but it's a disturbing thought and should be regulated.
We can certainly develop functional services without tracking users.
If you have to set up your own server (or at least your own subdomain that points to a GA server IP) then it's more likely to go wrong. I'm sure it'll happen, though.
https://www.technologyreview.com/2022/12/19/1065306/roomba-i...
Yup, happing. Recent news on a lady whose vacuum took a pic of her on the toilet being leaked.
All these things are under attack. I agree that cross-site tracking for ad purposes is bad, but this obsession with privacy goes too far. If you run around outside naked sorry you don't get to demand no one look. There are private spaces and non-private spaces, and I don't believe in eliminating non-private spaces.
edit: and to clarify, an app on your home computer controlling your lights or appliances, that should be a private space with opt-in usage tracking for UX improvement, a server on the internet that you are interacting with, that is not a private space. While you shouldn't be allowed to track across servers, yes I believe the server owner should has every right to anonymously track the views and areas of the website that people spend time on, and certainly they have every right to track purchases and do analytics on them.
No need to imagine, they do:
If want something lighter that is just a turn key solution but lets you grow (collecting more data for users who gave you consent, or being super strict about privacy without consent) then go with Wide Angle Analytics (our product).
The time when GA was the only option is long gone.
I wish the US had stronger antitrust enforcement .
No need to put a consent dialog if you are not stalking people.
As an example, the article mentions these specific audits were triggered by complaints by NOYB.
Our website analytics module is simple and gets the job done in one single easy-to-use dashboard.
However, if you want to dig deep, you can use funnels, journeys and other features to get more insights out of our analytics.
Usermaven collects all client-side events automatically so it makes it really easy for marketing teams to get insights without involding devs.
We also offer simple ready-made reports for SaaS businesses to get product insights.
> To integrate your website or SaaS app with Usermaven, you'll need to add a simple tracking script into the Header (<head></head>) section of your website. Make sure this snippet is present on every page that you want to track.
(The tracking script's URL is https://t.usermaven.com/lib.js)
So similar issues as with Google Analytics – site visitor's data is being shared with an US company.
Also this paragraph from your GDPR page had me scratching my head a bit:
> Usermaven agrees to abide by the standard contractual clauses where data is transferred from the EU to the US.
Is that written before Schrems II?
The focus on Google Analytics is really funny because plenty other company use similar tech to track users (pardot pixel, hubspot etc...) And both parent company are us bases so similar 'transfer to us' is being made with much more PII than google analytics.
(Noyb is probably coming to you as well as Facebook).
I can't recommend Fathom (https://usefathom.com) enough. They have a huge focus on privacy-first tracking. You don't need to show a cookie banner and you can still track events etc.
If you want $10 credit for signing up, use https://usefathom.com/james but otherwise, https://usefathom.com
Seriously, Google Analytics sucks. Use anything other than that.
Instead, we should have a law against a panopticon.
I wonder how fast we'd have such a law if Google were a Chinese company ...
Perhaps the way to get rid of Google Analytics is thus to start a Chinese company and make everybody use their analytics tool.
Also given some scamy things google was found to be doing in their ad business and personal experiences people I know had when running different statistics and ad providers along side of google and noticing gross divergence I _personally_ really wouldn't trust google analytics or ads at all if I where a business.
I really don't get it: you don't need to sell out your users to google, Facebook, etc to get page view counts, time page loads, get browser statistics, etc. What is it that site developers actually think they're getting out of abusing their users?
In a newer update, they allow region tracking based on cities. I think this is too much information. I did not enable this and hope they won't add other more intrusive features.
After I hit the FP of HN two times in a month, their billing warned me of overusage. One email, In which I explained the situation from me, and I got a very friendly email back, from a human, in which they allowed me to stay on my small plan despite the overuse.
But I think they just track at the Chrome-level now.
So using GA is really just a way for you to see what Google sees about your site.
Blocking GA use... I don't think it really hurts Google any more. I think they get all they need -- more than they ever got through GA -- through trackers in Chrome.
Like holy crap, I agree with you but your website is unreadable with that may as well be a banner ad of a navigation bar that keeps popping in and out of existence every time I scroll down.
Not mine, and I only just started using it. But it's easy to implement, and shows "just enough" analytics data for me. Nice simple option.
Google Lighthouse immediately started pissing and bitching about slow page load times because it had to wait for Google Analytics to load.
My site still does not really show up much in Google Search.
I binned Google Analytics because it basically did fuck all of any use.
I don't have one of those fucking idiotic cookie popups, because it doesn't need one, no-one needs one, and they're entirely meaningless noise.
https://www.dailyscandinavian.com/income-tax-transparency-no...
If I know my colleague doing the same work makes more money than me, that gives me leverage to request and receive a raise. If I know the CEO of my company makes 1000x my salary, that gives the workers collective bargaining leverage.
The only people who benefit from keeping their income private are the wealthy.
I also have a google sheet listing the basics of each of those tools: https://gaalternatives.guide/sheet
Regulators are only going to get tougher with service providers, it's wise to prepare.
https://wideangle.co/blog/is-google-analytics-illegal-under-...
The writing was on the wall for years now.
Some DPAs like CNIL fire warning shots first, giving 4 months to comply. Then the fines keep rolling.
https://european-alternatives.eu/category/web-analytics-serv...
I'm the co-founder of Pirsch (pirsch.io), so if you have any questions regarding analytics (any, not just ours), let me know. For our solution I can assure you that it's GDPR compliant and doesn't require a cookie consent banner.
- European Court of Justice (CJEU)
I always thought that by asking for permission in the privacy statement, and in the cookie banner analytics cookies are also explicit usually, it would be OK.
But indeed, even if you refuse the analytics cookies (I do that automatically, who doesn't?), that still does not stop the website from transferring PII to google analytics. I am assuming that here, not a user of analytics, but i suppose it will still work without cookies, maybe just a little less accurate.
The CJEU ruling about the US is mainly due to the fact that US service providers have to hand over all data if US government agencies request it.
Using any analytics, hosted in US, in the EU or hosting it myself, will involve moving and storing PII.
To be clear, I agree we should keep PII in EU. But I doubt that an EU solution will improve anything for the end user.
If GDPR is irrelevant to whatever you’re trying to say, I think you’re in the wrong thread.
You can argue with that all you want but its just the reality of the industry
And am I saying it is an excuse or anything? No, I'm just stating how things are
Sad I have to put so many disclaimers in such a simple comment but people like to read into things that aren't there or jump to conclusions.
15 years ago, US and EU GDP per capita were about the same. Now the USA is 50% higher. Even West Virginia is richer per person than France.
I hope all Alphabet IP ranges get blackholed on the ISP level if they continue to perpetuate this hellscape we call targeted advertising.
then what are the alternatives of google analytics. Google is big guient that are collecting all world data. alternative platforms are doing the same. We are not secure anywhere i think.
Privacy is already brocken, no options.
Don't stalk people is the alternative.
And thus you question every attempt to fix it?
GA, GTM, GSC are the top tools we have to use.
If you are a business website owner
I.e they can switch to a European vendor that do tracking and analytics.
Static IP-adresses are considered identity by EU court[0]. There have been several verdicts where EU court have ruled them subjective to GDPR.
[0] https://curia.europa.eu/juris/liste.jsf?language=en&num=C-70...