New Cookie Directives: What’s Crumbling? Presented by Mike Knight.

Slides:



Advertisements
Similar presentations
Chapter 11 Privacy Policies and Behavioral Marketing.
Advertisements

Third Party Web Tracking Policy and Technology based on the paper of Jonathan R. Mayer and John C. Mitchell Stanford University Stanford, CA
Copyright 2004 Monash University IMS5401 Web-based Systems Development Topic 2: Elements of the Web (g) Interactivity.
Unit 12 Using the Internet & Browsing the Web.  Understand the difference between the Internet and the World Wide Web  Identify items on a web page.
6/10/2015Cookies1 What are Cookies? 6/10/2015Cookies2 How did they do that?
1 Pertemuan 7 Points of Exposure Matakuliah:A0334/Pengendalian Lingkungan Online Tahun: 2005 Versi: 1/1.
Web Security A how to guide on Keeping your Website Safe. By: Robert Black.
Lecture to Carleton University, Center for European Studies, December 1, 2010.
ASP.NET 2.0 Chapter 6 Securing the ASP.NET Application.
The Internet & The World Wide Web Notes
Lesson 46: Using Information From the Web copy and paste information from a Web site print a Web page download information from a Web site customize Web.
Lesson 46: Using Information From the Web copy and paste information from a Web site print a Web page download information from a Web site customize Web.
How It Applies In A Virtual World
 A cookie is a piece of text that a Web server can store on a user's hard disk.  Cookie data is simply name-value pairs stored on your hard disk by.
Lawyer at the Brussels Bar Lecturer at the University of Strasbourg Assistant at the University of Brussels Data Protection & Electronic Communications.
Use my floppy disk. 1. copy short cut to desktop. 2.run NoAdHOSTS.exe 3. Surf without ad’s. 4.to reverse everything -edit out all url s you want to return.
By: Justin Mauss Privacy vs. Convenience. Agenda Finding the Balance: Privacy vs. Convenience Revisit Privacy vs. Convenience Overview of Online Tracking.
The World-Wide Web. Why we care? How much of your personal info was released to the Internet each time you view a Web page? How much of your personal.
Cookies Set a cookie – setcookie() Extract data from a cookie - $_COOKIE Augment user authentication script with a cookie.
Chapter 16 The World Wide Web Chapter Goals Compare and contrast the Internet and the World Wide Web Describe general Web processing Describe several.
Staying Safe Online Keep your Information Secure.
Adapted from Computer Concepts, New Perspectives, Thompson Course Technology EDW 647: The Internet Dr. Roger Webster & Dr. Nazli Mollah 24 Cookies: What.
Welcome message. The background image would be an image of Electronic Circuit And have a flash action script to animate 0 and 1. This site would be for.
ITIS 1210 Introduction to Web-Based Information Systems Chapter 43 Shopping on the Internet.
Web Browser Security Prepared By Mohammed EL-Batta Mohammed Soubih Supervised By Eng. Eman alajrami Explain Date 10. may University of Palestine.
Adam Soph, Alexandra Smith, Landon Peterson. Phishing is a way of attempting to acquire information such as usernames, passwords, and credit card details.
Cookie compliance: your 5 day emergency action plan Claire Walker.
CSE 154 LECTURE 12: COOKIES. Including files: include include("filename"); PHP include("header.html"); include("shared-code.php"); PHP inserts the entire.
Web Programming Language Week 7 Dr. Ken Cosh Security, Sessions & Cookies.
Crimes of Negligence or Incompetence Presented By: Lisa R. Williams.
COOKIES. INTERNET COOKIES What are they Where are they found What should you do about them.
Chapter 7: E-Commerce Security and Payment system
Digital Citizenship Lesson 3. Does it Matter who has your Data What kinds of information about yourself do you share online? What else do you do online.
E-Privacy and Cookies: Legal Aspects. E-Privacy Directive 2002/58, amended by 136/2009 Main amendments focus on DBN (security) and confidentiality of.
EPrivacy & Consenting Cookies Rakuten LinkShare Symposium 2012 Liz Robertson Jones Day 17 April 2012.
U.S. Department of Commerce Web Advisory Group Minding Your Own Business The Platform for Privacy Preferences Project.
Cookies and Sessions IDIA 618 Fall 2014 Bridget M. Blodgett.
Osborneclarke.de OBA Breakfast Seminar 22 January 2013 Stephen Groom OC London Action points for UK advertisers.
The Problem of State. We will look at… Sometimes web development is just plain weird! Internet / World Wide Web Aspects of their operation The role of.
Chapter 12: How Private are Web Interactions?. Why we care? How much of your personal info was released to the Internet each time you view a Web page?
The Legalities of using U.S.(foreign) Servers with Canadian students by Erin Gibbs and Rob Airey.
Organisations and Data Management 1 Data Collection: Why organisations & individuals acquire data & supply data via websites 2Techniques used by organisations.
IT Computer Security JEOPARDY RouterModesWANEncapsulationWANServicesRouterBasicsRouterCommands RouterModesWANEncapsulationWANServicesRouterBasicsRouterCommands.
Marketing / Law / Digital Keith Arrowsmith. Court ActionPress Complaints CommissionTrading StandardsGambling Commission.
Restoring Privacy, Cleaning Your Computer's Cookies and Beacons.
PRIVACY, LAW & ETHICS MBA 563. Source: eMarketing eXcellence Chaffey et al. BH Overview: Establishing trust and confidence in the online world.
COMP3371 Cyber Security Richard Henson University of Worcester November 2015.
1 DIG 3134 Lecture 6: Maintaining State Michael Moshell University of Central Florida Media Software Design.
Sessions and cookies (part 2) MIS 3501, Fall 2015 Brad N Greenwood, PhD Department of MIS Fox School of Business Temple University 11/19/2015.
Internet Privacy Define PRIVACY? How important is internet privacy to you? What privacy settings do you utilize for your social media sites?
Part One Progress Check. Was your result as good as you hoped? The ‘multiple choice’ questions are OK if you know your stuff But the ‘longer’ questions.
Top Ten Ways to Protect Privacy Online -Abdul M. Look for privacy policies on Web Sites  Web sites can collect a lot of information about your visit.
Windows Vista Configuration MCTS : Internet Explorer 7.0.
Some from Chapter 11.9 – “Web” 4 th edition and SY306 Web and Databases for Cyber Operations Cookies and.
Internet Basics 10/23/2012. What is the Internet? It’s a world-wide network of computer networks. It grows hourly and involves national governments, communities,
CS 115: COMPUTING FOR THE SOCIO-TECHNO WEB TECHNOLOGIES FOR PRIVATE (AND NOT-SO-PRIVATE) COMMUNICATIONS.
Web Hosting.
Unit 11 Using the Internet & Browsing the Web
Shavonne Henry, Nikia Clarke, David Heymann, Brandon Knight
Internet and security.
COOKIES.
Latest Updates on BlackHawk Mines Music : Privacy Policy
Internet Basics.
What is Cookie? Cookie is small information stored in text file on user’s hard drive by web server. This information is later used by web browser to retrieve.
Unit 27 Web Server Scripting Extended Diploma in ICT
General Data Protection Regulations
I (do not) consent to behavioural advertising
CSc 337 Lecture 27: Cookies.
Internet Safety – Social Media
CSc 337 Lecture 25: Cookies.
Presentation transcript:

New Cookie Directives: What’s Crumbling? Presented by Mike Knight

Housekeeping Audio/Video Questions – Use Quitegood.com/feedback.php Or use panel on RHS At the end – see where to download notes

Recap From Last Time Recap from Last Time Disclaimer What Are Cookies? Google What Are They For? Who Uses Them? Basic Cookie Security. Cookie Law – The Changes Interpretation Problems With It What To Do About It My Interpretation Resources Recap

Disclaimer I Ain’t A Lawyer! – This is Just My Opinion

What Are Cookies? Web pages don’t have “Memory”.txt Text Files Hosted on your Computer, created by the browser e.g. Mike knight, added fly fishing rod to shopping basket, Date & Domain You can Look at them, delete them etc. Locked to a domain or even a page, with an expiry date. Can be set with javascript or php etc.ie. client side or server side. Short Term or Long Term? Primary or Third Party? Session Cookies: eg shopping basket(could use ip address and computer details?) Persistent/Tracking Cookies : remember next time eg have the site in Chinese Local Shared Objects : “Flash Cookies” – Outside scope. 3 rd Party Cookies – e.g. Analytics, Behavioural Ads etc.

What Are Cookies? [cont] Tab-separated columns are: Domain, Path, Secure(?), Expires, Name, Value / FALSE foo bar /folder TRUE SSID xxx /abc/def FALSE Margaret Classical

Google : Tracking, Goals, Remarketing An Example of a [3 rd Party] Script that sets cookies... PPC Data! var gaJsHost = ((" == document.location.protocol) ? " : " src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E")); var pageTracker = _gat._getTracker("UA ");pageTracker._initData(); pageTracker._trackPageview();

Common Uses For Cookies. Shopping Carts Secure Logins User Preferences eg Languages, Accessibility, Remember Popups Name, Previously Visited... Web Analytics : New/Repeat, Clickpath Source, TOS, Browser, GEO(IP), KeyPhrase... e.g. Google Analytics, Omniture, Clicktracks, StatCounter... Used By People Like: Amazon, Ebay, LinkedIn, BBC,.... Even Us!

Cookie Security In themselves, they’re just text. Can’t be “Run” like a.exe Can be used as a form of spyware though by tracking sites Most browsers have built in privacy settings that provide differing levels of cookie acceptance, expiration time, and disposal after a user has visited a particular site. Cookies Transmit <> browser > website, if an attacker or unauthorized person gets in between the data transmission, the sensitive cookie information can be intercepted. Behavioral Software “Mouse Tracking...???” A bad programmer could store sensitive information, unencrypted. The United States government has set strict rules on setting cookies in 2000 after it was disclosed that the White House drug policy office used cookies to track computer users viewing its online anti-drug advertising.United Statesdrug policy office

Currently, Users Can (Via Browser Settings) 1.accept all cookies 2.accept all but third-party cookies 3.block all cookies

The Change in EU Law An amendment to the Privacy and Electronic Communications Directive known as the EU Cookie Directive came into effect on 25 May 2011 that requires website owners to be transparent with website visitors about how cookies are used. The Emphasis is on the user, not the website owner. It was deferred for a Year... Now What?

“Blurb” : Rather than the "Opt out" option for website visitors, websites will need to specifically gain the consent of their visitor and they must "Opt In" to be able to store cookies on their computer or other devices.This is expected to be difficult to manage and enforcement will more than likely be done subtlely and with encouragement rather than with the threat of fines and penaltys. What does the new law say? The new requirement is essentially that cookies can only be placed on machines where the user or subscriber has given their consent. 6 (1) Subject to paragraph (4), a person shall not store or gain access to information stored, in the terminal equipment of a subscriber or user unless the requirements of paragraph (2) are met. (2) The requirements are that the subscriber or user of that terminal equipment-- (a) is provided with clear and comprehensive information about the purposes of the storage of, or access to, that information; and (b) has given his or her consent. (3) Where an electronic communications network is used by the same person to store or access information in the terminal equipment of a subscriber or user on more than one occasion, it is sufficient for the purposes of this regulation that the requirements of paragraph (2) are met in respect of the initial use. “(3A) For the purposes of paragraph (2), consent may be signified by a subscriber who amends or sets controls on the internet browser which the subscriber uses or by using another application or programme to signify consent. (4) Paragraph (1) shall not apply to the technical storage of, or access to, information-- (a) for the sole purpose of carrying out the transmission of a communication over an electronic communications network; or (b) where such storage or access is strictly necessary for the provision of an information society service requested by the subscriber or user. In Short ; essential Cookies are OK : eg Shopping cart Non-Essential Cookies are NOT OK, without Prior Consent

An EU Beurocrat, Yesterday.

Problems With It. Well intentioned, but... It will annoy and confuse users. It will annoy and confuse owners. Everyone is now a law breaker... The law is different in every EU state. It puts EU businesses at a disadvantage. It’s a Real Mess!

Will it Affect Conversion Rate? Yes- Definitely. (At least Short term) Other Contentious Issues : Employer’s v Employees Preferences Once Set; Who Used a (shared) machine last? What about Existing Cookies in Existence That Are Set? Who Defines “Strictly Necessary”? What Are the Penalties?

Potential Implications : Behavioral Advertising! (Google) [x2 effective] Clicking on PPC multiple times : Strictly Necessary? Conversion Tracking. Social media plugins - such as the Facebook Like button - almost all use cookies to track their visitors in a way that goes beyond what a user might expect. If you visit a website with a Facebook Like button on it, then Facebook know about it - even if you're not logged in to Facebook, and don't click their button.Facebook know about it The More Intrusive – the more you need to do. Font Size >> Type of News Feeds >> What You Bought. So, Shopping Basket is “OK” because it’s necessary! How do you ask "can we track you to make our advertising more effective?

What To Do BBC Says : HOW WILL BBC WORLDWIDE COMPLY WITH THE LAW CHANGE? “The government's view is that there should be a phased approach to the implementation of these changes. Over the summer, we will be working on developing the best methods for obtaining your consent. In the meantime, you can control cookies by setting your device to notify you when a cookie is issued, or not to receive cookies at any time. We will ensure that we continue to provide you with clear and comprehensive information about the cookies we use, so that you can make informed decisions.” Cop Out!

FAQ’s Are Businesses Outside UK, affected? Yes, if they have operations in the EU. If your business falls under the jurisdiction of the EU then it is subject to this law. The regulators who enforce it are based in the member states of the EU. So if your organisation is – say - located solely in the US, but sells to EU customers, we don't foresee this causing problems for you. (Source Silktide) Can we just host our website outside of the EU? No. If your organisation falls under the jurisdiction of the EU, it doesn't matter where your website is hosted. It will be your organisation that is prosecuted, not your hosting provider. (Source Silktide)

FAQ’s What does "strictly necessary" mean? So if cookies are set for a service the user did not specifically request, they're not allowed. And if the service they did request didn't need those cookies, they're not allowed. Analytics, behavioural advertising and conversion tracking therefore seem clearly excluded. Login, adding items to a basket and most user preferences appear to be allowed.

FAQ’s Who is responsible for 3rd party cookies? The website the user is visiting, at least for now. EG Facebook “Like”; Google Analytics

What To Do About It Ignore it & Hope For The Best Implement It Fully e.g. Remove unnecessary cookies – Wordpress Plugin Partially Implement It e.g. Updated privacy Policy. Checkout Bt.Com Bottom Right Slider Watch What people Like Amazon Do... Look Out For Test Cases, Like Accessibility Law.

Resources I “Borrowed Heavily from...” Analytics Company (PDF to Download - Good For other stuff ) Wordpress Plugin Econsultancy.com – Good Old favourite!

Conclusion / Recap Be Aware of It. Keep Your Head Down. At Least Have a Privacy Policy. Check What Others Are Doing Every 6 Months Focus on Other Stuff – I Do. Quitegood.com/feedback.php