Discussion
Loading...

Discussion

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Neil Brown
@neil@mastodon.neilzone.co.uk  ·  activity timestamp 6 days ago

Fact vs fiction: ICO debunks myths on storage and access technologies

That this exists is a bit weird?

https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/09/fact-vs-fiction-ico-debunks-myths-on-storage-and-access-technologies/

  • Copy link
  • Flag this post
  • Block
RevK :verified_r:
@revk@toot.me.uk replied  ·  activity timestamp 6 days ago
@span neil Hmm "like device fingerprinting, where they involve storage or access"

My understanding is that normally device fingerprinting involves no "storage" on the device, just what the device already has/is.

  • Copy link
  • Flag this comment
  • Block
Neil Brown
@neil@mastodon.neilzone.co.uk replied  ·  activity timestamp 6 days ago
@span revk which may be "access"
  • Copy link
  • Flag this comment
  • Block
RevK :verified_r:
@revk@toot.me.uk replied  ·  activity timestamp 6 days ago
@span neil I may have to go re-read PECR, I thought it covered "access" of what you "stored", but as always, I may be wrong.

If it is indeed "access" to "any" information, then every single GET includes information from the device, such as the URL you are requesting, the referring page, etc, which the server "accesses", and would make every single web request come under PECR. So I am not sure it can be that wide and make any sense (LOL, assuming it makes sense).

  • Copy link
  • Flag this comment
  • Block
The Penguin of Evil
@etchedpixels@mastodon.social replied  ·  activity timestamp 6 days ago
@span revk @span neil so does the IP header 😁
  • Copy link
  • Flag this comment
  • Block
Neil Brown
@neil@mastodon.neilzone.co.uk replied  ·  activity timestamp 6 days ago
@span revk It does not limit "access" to what one has "stored".

Fun game: if a server logs a browser user agent string, from an http request, has the provider thereby "accessed" information from the user's device, even though it was sent automatically? :)

  • Copy link
  • Flag this comment
  • Block
AMS
@AMS@infosec.exchange replied  ·  activity timestamp 6 days ago
@span neil @span revk Even worse: what if you log p0f results for the connection?
  • Copy link
  • Flag this comment
  • Block
RevK :verified_r:
@revk@toot.me.uk replied  ·  activity timestamp 6 days ago
@span neil Quite!!!
  • Copy link
  • Flag this comment
  • Block
RevK :verified_r:
@revk@toot.me.uk replied  ·  activity timestamp 6 days ago
@span neil Out of interest, does it work both ways.

If I get a web page, I'm "accessing" information on the server. Does PECR apply to me?

  • Copy link
  • Flag this comment
  • Block
⊥ᵒᵚ⁄Cᵸᵎᶺᵋᶫ∸ᵒᵘ ☑️
@falken@qoto.org replied  ·  activity timestamp 6 days ago
@span revk @span neil "you know, I'm starting to think #ofcom doesn't know how the Internet works"

#pecr

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.2.21 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login