221 karma · joined December 30, 2020
My solution was to just highlight the last anchor if the user scrolled to the very bottom. Although this might skip the second last heading if its too close to the bottom.
See here: https://sharezone.net/privacy-policy (most visible on desktop, on mobile you have to open the "Inhaltsverzeichnis" at the bottom)
(Disclaimer: I don't live in the US and don't want to take any political stance with this)
Although strictly speaking if they would only want to do AdES and not QES, they wouldn't have to be in the EU Trusted List, would they?
Of course - this project would probably not exist without Starlink, so credit where credit is due.
Personally I find it quite sad that we're destroying the night sky in the sense that before these projects people could look in the sky and know that all humans before them had more or less the same sight. Now there are just so many satellites swirling around in your sight. I find that quite sad.
If they have a data protection officer then send him an email. Else if you're in the EU get the Data Protection Authority (DPA) of your country in the loop.
This has been ruled as being valid by courts.
One example missing in the privacy policy is information regarding "the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability;" There is more stuff that should be included, see: https://gdpr-info.eu/art-13-gdpr/.
(Technically it doesn't have to be in the privacy policy document but could be provided in some other kind of document. I guess thats not done though.)
But I think your take is not true. I can imagine that it might just be a really misinformed proposal to actually go against child abuse. I hope.
For me the question is if this is a webauthn thing in general or a security key thing (to include the domain in the challenge to prevent phishing)
So from what I understand a attacker couldn't as easily fish me by pretending e.g. to be Google. With a password or even a TOTP code the attacker could just pose as Google and forward the credentials to the actual site.
Just out of curiosity: could you provide some examples?
It's of course not how you describe it on a technical level but from a UX standpoint.
Not using SASS services (e.g. Firebase) just really sucks though.
We still use it (started with it before privacy shield was demolished) but we will have to migrate eventually. Don't know what we'll use exactly, maybe managed kubernetes with some platform for an easier workflow running on it? Idk yet.
Particularly interesting is that it is not allowed under GDPR to have a free version of an app with the condition that it shares personal data (in this case for targeting and profiling for ads) as the consent of the user is not freely given in this case - in a "Take it or leave it" situation, consent cannot be seen as freely given.
Link to the section "Consent as a condition to access the service ": https://gdprhub.eu/index.php?title=Datatilsynet_(Norway)_-_2...