30
Building privacy-friendly websites Amelia Andersdotter & Anders Jensen-Urstad WordCamp Europe June 27, 2015 “Our freedom is built on what others do not know of our existences.” —Aleksandr Solzhenitsyn dataskydd.net

Building privacy-friendly websites - dataskydd.net

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Building privacy-friendly websites - dataskydd.net

Building privacy-friendly websitesAmelia Andersdotter & Anders Jensen-Urstad

WordCamp EuropeJune 27, 2015

“Our freedom is built on what othersdo not know of our existences.”

—Aleksandr Solzhenitsyn

dataskydd.net

Page 2: Building privacy-friendly websites - dataskydd.net

“Everyone has the right to respect for his private and family life, his home and his correspondence.”—European Convention on Human Rights, article 8

Page 3: Building privacy-friendly websites - dataskydd.net

Data protectionA collection of tools for achieving privacy.

Data securityWhen procedures work as foreseen.

Page 4: Building privacy-friendly websites - dataskydd.net

Right to know ❧Right to consentUser-centricData minimizationEffective sanctions?

Page 5: Building privacy-friendly websites - dataskydd.net

Right to knowRight to consent ❧User-centricData minimizationEffective sanctions!

Page 6: Building privacy-friendly websites - dataskydd.net

Right to knowRight to consentUser-centric ❧Data minimizationEffective sanctions

Page 7: Building privacy-friendly websites - dataskydd.net

Right to knowRight to consentUser-centricData minimization ❧Effective sanctions

Page 8: Building privacy-friendly websites - dataskydd.net

Right to knowRight to consentUser-centricData minimizationEffective sanctions ❧

Page 9: Building privacy-friendly websites - dataskydd.net

Public sector websites

Private visitsGoverning vs. governance

Page 10: Building privacy-friendly websites - dataskydd.net

99% of Swedishmunicipalities use either...- third-party trackers- tracking cookies - third-party service behaviors

Page 11: Building privacy-friendly websites - dataskydd.net

European Union LawPresent:Directive 2002/48/EC E-Privacy. Art 5(3): “cookie law”Directive 1995/46/EC Data ProtectionDirective 2014/53/EU Radio Equipment StandardisationMember State laws on public administrationComing:General Data Protection Regulation (GDPR)Law Enforcement Data Protection Directive

Page 12: Building privacy-friendly websites - dataskydd.net

So what to do?

1. Encrypt all the things.2. Don’t expose your visitors to others. (At least not without consent!)

Page 13: Building privacy-friendly websites - dataskydd.net
Page 14: Building privacy-friendly websites - dataskydd.net

HTTP

Page 15: Building privacy-friendly websites - dataskydd.net

HTTPS

Page 16: Building privacy-friendly websites - dataskydd.net

• SSL certificates are cheap• Let’s Encrypt (letsencrypt.org) will make them free and automated: $ sudo apt-get install lets-encrypt $ lets-encrypt example.com• Use HTTP Strict Transport Security (HSTS)

(Bonus: HTTPS now used as a ranking signal by Google.)

Page 17: Building privacy-friendly websites - dataskydd.net

*click*

Referrers

Page 18: Building privacy-friendly websites - dataskydd.net
Page 19: Building privacy-friendly websites - dataskydd.net

Don’t tell other websites about yourvisitors

<a href="http://foo.bar" rel="noreferrer">I don’t leak referrer information.

</a>

W3C HTML5 Recommendation, 4.8.4.8

(Plugin: https://wordpress.org/plugins/noreferrer)

Page 20: Building privacy-friendly websites - dataskydd.net

<meta name="referrer" content="no-referrer" />

Referrer Policy, W3C draft

(Firefox, Chrome, Safari, Microsoft Edge)

Page 21: Building privacy-friendly websites - dataskydd.net

No More Shall We

Third-Party

Page 22: Building privacy-friendly websites - dataskydd.net

Google Analyticsusage among Swedishmunicipalities

Page 23: Building privacy-friendly websites - dataskydd.net

If you insist on Google Analytics...

ga('set', 'anonymizeIp', true);ga('set', 'forceSSL', true);

Page 24: Building privacy-friendly websites - dataskydd.net

Piwik• Open source, PHP + MySQL• You own the data• Various privacy options• Can be used without cookies

Totally radical alternative: don’t track.

Page 25: Building privacy-friendly websites - dataskydd.net

Third-parties: Disqus• Doesn’t allow anonymous comments• Is in possession of your comments• Claims broad rights forever• Tracks user activity across sites• Shares various data with third parties

Page 26: Building privacy-friendly websites - dataskydd.net

The Quest for a Disqus alternative• Plain ol’ built-in comment system• Self-hosted open-source Disqus-like software (e.g., Isso, HashOver)• Integration with forum software (e.g., Discourse, Vanilla Forums)

Page 27: Building privacy-friendly websites - dataskydd.net

Third-parties: Social media• Vendor-provided embedded like/share buttons track people• Use locally hosted images/fonts instead!• Or... two-click solution:

Page 28: Building privacy-friendly websites - dataskydd.net

Once More, with Feeling

Use HTTPS.Don’t leak referrers.No third-party resources without consent.

Page 29: Building privacy-friendly websites - dataskydd.net

In conclusion...

Individuals matter.It’s possible to protect privacy.Join us! ❦

Page 30: Building privacy-friendly websites - dataskydd.net

Thank you! ¡Gracias! Gràcies!Amelia [email protected]@teirdesameliaandersdotter.eu

Anders [email protected]

@ndrsjuanders.unix.se

Slides, references, code, etc.:https://dataskydd.net/wceu2015

dataskydd.net