惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
CERT Recently Published Vulnerability Notes
U
Unit 42
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
Cisco Talos Blog
Cisco Talos Blog
P
Proofpoint News Feed
H
Heimdal Security Blog
Help Net Security
Help Net Security
H
Help Net Security
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
P
Palo Alto Networks Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
S
Secure Thoughts
The GitHub Blog
The GitHub Blog
博客园_首页
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Microsoft Azure Blog
Microsoft Azure Blog
Hacker News: Ask HN
Hacker News: Ask HN
博客园 - 【当耐特】
J
Java Code Geeks
S
SegmentFault 最新的问题
Application and Cybersecurity Blog
Application and Cybersecurity Blog
P
Proofpoint News Feed
The Last Watchdog
The Last Watchdog
O
OpenAI News
博客园 - 三生石上(FineUI控件)
Recent Announcements
Recent Announcements
B
Blog RSS Feed
V2EX - 技术
V2EX - 技术
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
T
Tenable Blog
PCI Perspectives
PCI Perspectives
C
CXSECURITY Database RSS Feed - CXSecurity.com
The Hacker News
The Hacker News
Schneier on Security
Schneier on Security
Google Online Security Blog
Google Online Security Blog
美团技术团队
G
GRAHAM CLULEY
D
DataBreaches.Net
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 聂微东
W
WeLiveSecurity
Vercel News
Vercel News
S
Security Affairs
T
Tailwind CSS Blog
V
Vulnerabilities – Threatpost
博客园 - 司徒正美
G
Google Developers Blog
D
Docker
Webroot Blog
Webroot Blog

Blog of Simple Analytics

The EU wants to kill cookie banners Google is tracking you (even when you use DuckDuckGo) German court rules Meta’s tracking tech violates GDPR Closing the data gap - Simple Analytics x Usercentrics The EU-US data deal may be dead in the water You are missing 20% of your website data with GA4 How a reverse trial will push Simple Analytics to the next level Google will start tracking all your devices (WTF?) Big Tech Fails EU’s Digital Services Act: Only Wikipedia Passes the Test Meta fined $102 million by the Irish Data Protection Commission Europeans spend 575 Million hours per year clicking cookie banners The most interesting GDPR fines GDPR and fines: all there is to know Google loses key antitrust case Web Analytics for Crypto Companies Web analytics for publishers Google pulls Uno Reverse card: Rolls back decision to kill third-party cookies Privacy Monthly July 2024 Privacy Perspectives June 2024 Privacy Monthly June APRA fumbles targeted advertising Privacy Monthly May Meta loses key privacy battle Google delays cookie phase-out once again Privacy Monthly April 2024 Web Analytics and Consent Cookies 101 Privacy Monthly March 2024 German authority cracks down on cookie banners Google Tag Manager vs Google Analytics Google search alternative Data retention in Google Analytics Guide to Google Analytics and Cookie consent What are Google Analytics' identifiers? How to export data from Google Analytics Privacy Monthly February 2024 The Criteo case: a big deal for Big Tech What the Digital Markets Act means for privacy Google Settles in $5B Incognito Mode Lawsuit Legal troubles for Adobe Analytics Web analytics for nonprofits HIPAA and mental health Why Meta subscriptions are under attack, and why it matters for privacy Privacy Monthly: December Simple Analytics AI Host analytics on Cloudflare Zaraz Add Google Analytics to Convertkit Google Analytics Pricing - Paid vs Free Road to 1 Million ARR - October update CCPA and Data Protection: all there is to know Analytics without a cookie banner Enterprise Analytics Privacy Monthly: November 2023 Delete Act: all you need to know Mobile App Tracking Under Fire The road to 1 Million ARR - September Update Privacy Monthly: October 2023 HIPAA violations First challenge to the EU-US data transfer framework Direct Marketing under GDPR Road to 1 million ARR - August Update CCPA vs CPRA: what is new? Privacy Monthly: September 2023 A/B Testing with Simple Analytics Dobbs v. Jackson ruling is a privacy mess Privacy Monthly: August 2023 What are your rights under the CCPA? When does the CCPA apply? How does the HIPAA compare to the CCPA and GDPR? Why Meta is in a world of trouble CJEU: cookie-based analytics collects sensitive data Road to 1 million ARR - July update All about the new Data Transfer Framework Road to 1 Million ARR - June update What is PHI under HIPAA? Sweden declares Google Analytics illegal Searching for GA4 Alternatives? Top 10 Reliable Options for Google Analyticss Ultimate HIPAA Compliance Checklist: Essential Steps for Healthcare Providers Privacy Monthly: June 2023 More troubles for Google Analytics The path to 1M ARR - May Update Data Processing Agreements Minimal Product Analytics Facebook data transfers declared illegal Is Google Analytics CCPA-compliant? Help us with your input Cookie banners: How to stay GDPR compliant? GDPR Compliance Checklist Privacy Monthly: May 2023 Simple Analytics: Privacy-first website analytics Improve your e-commerce performance with analytics European Facebook blackout is closer than we think Know your website’s Carbon Emissions - and how to reduce it The path to 1M ARR - April 2023 How to add video tracking using Google Tag Manager? How to track form submissions using Google Tag Manager? Why is my Simple Analytics data different from Google Analytics? Debug Simple Analytics script How to Import Google Analytics Data to Simple Analytics
Privacy Monthy January 2024
Carlo Cilent · 2024-01-11 · via Blog of Simple Analytics

Kickin off 2024 with yet another Privacy Monthly- and this time around, Google steals the spotlight. The Silicon Valley giant lost a major antitrust case over its Play Store, had to settle a privacy class action over Chrome’s Incognito mode, and must deal with a major (and yet unpatched) exploit in its widely used OAuth authorization system. Google aside, the EU is close to finalizing the AI Act, Meta is (finally) encrypting Messenger chats, and more!

  1. Big trouble for Google
  2. AI Act nearly finalized
  3. Messenger now encrypted by default
  4. Congress temporarily extends FISA 702
  5. EDPB discusses pay-or-ok approach to privacy
  6. Landmark CJEU rulings on credit scoring
  7. X under DSA investigation
  8. Noyb challenges X over political advertising
  9. Morgan Stanley reaches settlement over embarrassing data breach

The UK Government chose Simple AnalyticsJoin them

Big trouble for Google

In December Google settled a class action over Incognito mode tracking. The lawsuit claimed $5 billion in damages but the amount of the settlement is undisclosed. We wrote more about Google’s Incognito mode blunder here.

In the meantime, the Icelandic privacy authority fined several municipalities for using Google Workspace and other Google Cloud services in schools. While Google itself was not responsible for any violation, the decision suggests that some of its services might be too privacy-invasive for use in an educational setting.

In non-privacy related news, Google lost a major antitrust lawsuit against Epic Games over the Google Play Store. If Google were to lose on appeal, the case might create a dangerous precedent for Google and weaken the Play Store’s lucrative monopoly over app distribution on the Android platform.

As if legal issues weren’t enough, a security researcher recently disclosed a major vulnerability in Google’s OAuth systems. An oversight in the email linking system for Google accounts allows former employees to retain access to their organizations’ service providers after their company Google account has been deactivated. This vulnerability could result in breaches of personal data as well as invaluable business information, including trade secrets.

The researcher informed Google in August and only went public with the details after Google failed to address the vulnerability. Major service providers such as Slack were informed of the vulnerability ahead of time, in order to limit the negative consequences of the disclosure. To date, Google has not mentioned this vulnerability on its blog or announced a fix.

AI Act nearly finalized

After a three-day negotiatory marathon, EU legislators reached a provisional agreement on the AI Act.

The agreement was made possible by mutual concessions between the Parliament and the Council: for instance, the Parliament agreed to carve out narrow exceptions for the use of real-time biometric identification in law enforcement, in exchange for a ban on emotion recognition technology in workplaces and schools.

The Act will probably be finalized soon, as EU legislators intend to push for the finishing line before a new Parliament is elected.

Messenger now encrypted by default

Meta announced that it is rolling out end-to-end encryption for Messenger. Messenger’s end-to-end encryption uses the same Signal protocol that power WhatsApp’s.

End-to-end encryption was already available since 2016 through user settings but will now be default. Better late than never, I suppose.

Congress temporarily extends FISA 702

The US Congress extended FISA Section 702 by four months, postponing the proposed and hotly debated reform of the law. The proposed reforms aim to limit reverse targeting- a form of warrantless surveillance that bypasses some of the protections afforded to US citizens under the law.

FISA is quite relevant to EU privacy law. By allowing for extensive surveillance over European data, Section 702 creates a privacy risk for EU-US data transfers. A reform of Section 702 could have important consequences for data transfers and for the future of the new data privacy framework between the EU and the US.

EDPB discusses pay-or-ok approach to privacy

In December the European Data Protection Board (that is, the European body that brings all the EEA’s data protection authorities together) discussed the pay-or-ok approach to privacy and its compatibility with the GDPR. The Board did not publish any documents on the topic yet.

While pay-or-ok is by no means a new issue, it became a hot topic after Meta started offering paid, ad-free subscriptions as part of its new (and controversial) compliance strategy for targeted advertising.

Landmark CJEU rulings on credit scoring

The EU Court of Justice issued two rulings on credit scoring practices. Given the increasingly widespread use of credit rating, these rulings could play an important role in the future.

The main takeaway is that individuals affected by credit scoring enjoy specific rights and safeguards under the GDPR (specifically, those provided for certain forms of automated decision-making under Article 22). The Court also held that a credit scoring agency cannot store information on insolvency for a longer time than public registers.

X under DSA investigation

On December 18 the European Commission started investigating X’s compliance with the Digital Services Act- a recent Regulation that imposes content moderation duties on major online platforms.

This is not surprising. X (then still named Twitter) abandoned the EU code of practice on disinformation in June 2023, right before the DSA entered into force. Effectively, the platform turned its back on voluntary commitments that would become legal obligations in a matter of months. This confusing move made the platform an obvious target for DSA enforcement and drew criticism from the EU Commission.

Long story short, the investigation was to be expected, and X is off to a bad start.

Noyb challenges X over political advertising

In more X-related news, NGO noyb filed a complaint over targeted political advertising carried out by X on behalf of the European Commission. This complaint is a follow-up to another recent complaint against the Commission itself.

Noyb claims that a Dutch citizen was shown ads based on politics-related keywords, including names of prominent right-wing politicians. The organizations believes this targeting strategy is a violation of both the GDPR and the Digital Services Act (and we agree, for what it’s worth).

Bottom line, the** Commission engages in the very practices the EU is trying to ban**. This case is quite embarrassing for the Commission regardless of the outcome.

Morgan Stanley reaches settlement over embarrassing data breach

Finance giant Morgan Stanley reached a $6.5M settlement over a data breach. The lawsuit was initiated by a multi-state coalition after the company compromised personal data by failing to erase it from decommissioned devices.

Morgan Stanley outsourced the decommission to a moving company with no IT expertise. This resulted in company computers and servers being sold on the market with company data and personal data still available in the device’s memory- sometimes in unencrypted form.