Oui, Utiq est un désastre en terme de respect de la vie privée. On nous avance que tout a été mis en place pour respecter les lois de protection des données mais si les utilisateurs ne peuvent même pas comprendre ce qui se passe et n'en sont pas informés, c'est totalement inutile
Ca fait trois ans que je suis de loin la technologie Utiq. La CNIL a bien évidemment donné son accord à l'époque car on touche directement à la vie privée des utilisateurs avec les opérateurs et il fallait des arguments forts pour convaincre que ça allait être ok avec le RGPD.
C'est juste totalement contraire à la lettre et à l'esprit du RGPD, et effectivement que la @CNIL n'en dise pas un mot est pour le moins problématique. Mais vu qu'elle a déjà abandonné l'idée de combattre les cookiewalls assortis d'un paywall... Il n'y a hélas plus rien à espérer
Le cookie de consentement est passé de 3 à 6 mois de validité et tous les opérateurs français ont ajouté le support de leur box Internet depuis 1 an (https://t.co/jzu0EinzK9), ce qui change complètement la donne en terme de tracking par rapport à un avis de la CNIL d'il y a 3 ans
Happy to announce that we have a 2-year postdoc position on web security and online tracking available in our team! Contact me directly if interested.
📍Where: Lille, France
⌛ Duration: 24 months
📅 Start date: September 2026
👉 More information: https://t.co/C1Aiw8CjaN
AmIUnique is starting a new adventure on mobile! 🎉📱
We have just launched our first Android application to study if users can be identified through an application without using a single permission.
Link: https://t.co/pOJfPrQbAw
Retweets are greatly appreciated 😊
This application is a first step to investigate the fingerprintability of the mobile ecosystem. We plan on releasing another app similar to the https://t.co/kgVEkz6sAG website where you will be able to see how your own fingerprint compares to all the other collected fingerprints.
When you launch AmIUnique and tap "Scan my device", the application will collect your device fingerprint and display a selection of key attributes. Our goal is to analyse all the fingerprints we will receive to understand if the way Android is built can pose a privacy problem.
I'm looking for a postdoctoral/research associate to join my group at @NYUAbuDhabi in sunny Abu Dhabi! ☀️🏖️💻
Postdoc application: https://t.co/3v5z7N3uOp
Don't have a PhD? Apply to be a research associate: https://t.co/W568Bv8CBg
Three good reasons to apply: 1/2
After several success iterations of SecWeb, @stecalzavara and I have decided that it's best for the Web community to merge with MADWeb, as we want to avoid fragmenting the community. So, please consider submitting to https://t.co/QvJaJ3UAHr (weather is nicer in San Diego ;-))
Google won't deprecate third-party cookies after all. This seems to be the worst outcome for me as heavy investment has been made in the past four years to develop alternatives that will now work alongside existing 3P cookies. Tracking will be more present on the web as a result.
After much back and forth, Google has decided to keep third-party cookies in its Chrome browser. Turns out all the fuss over the years wasn’t in vain after all; the ad industry’s cries have finally been heard. https://t.co/B55WrS098H
Our paper on Server-side tracking will be presented by @Fouad__Imane at #PETS2024 on Thursday! Come say hi to her to know more! Unfortunately, I had to cancel my trip at the last minute 😢
I'm super happy to announce that our paper on server-side tracking (SST) made with @Fouad__Imane and @Cristianapt was accepted at PETS!
"The Devil is in the Details: Detection, Measurement and
Lawfulness of Server-Side Tracking on the Web"
PDF https://t.co/iVR6bykDXW
More info 🧵
@vtoubiana Looking at https://t.co/6adHD1ho6s, Safari seems to have lost about 4% share between May 2023 and May 2024. I'm guessing the browser choice screen imposed by the DMA may have increased the trend even more if Apple is willing to run a campaign on this.
To finish, a big takeaway of our study is that there is a real need to look closer at server-side tracking because of the harm it can cause. After working 2+ years on this topic, it is hard to investigate because it was designed that way and it needs to be properly regulated.
For this study, we focused on detecting a small subset of SST servers. We relied on different crawls made in 2020 and 2022 to detect websites that shifted from the traditional tracking model to the server-side tracking one and found some websites that operated that change.
The second problem is about the responsibilities and liabilities of the different actors in the data collection. Now that there is an additional intermediary server in the mix, who is responsible and liable for that? How can users exercise their rights to access their data?
With Imane and Cristiana, we decided to tackle this subject in 2022 on both the technical and legal aspects. And wow, it is hard. Since its goal is to hide as much as possible on the server side, it really changes the way we do measurement studies as everything is opaque.
I'm super happy to announce that our paper on server-side tracking (SST) made with @Fouad__Imane and @Cristianapt was accepted at PETS!
"The Devil is in the Details: Detection, Measurement and
Lawfulness of Server-Side Tracking on the Web"
PDF https://t.co/iVR6bykDXW
More info 🧵