@Bundesregierung
Warum nur? Regelt das nicht bereits ein Gesetz, dass bei fehlender Zustimmung keine Daten erhoben werden dürfen - OptIn?
Just released: #swad v0.2
SWAD is the "Simple Web Authentication Daemon", meant to add #cookie #authentication with a simple #login form and configurable credential checker modules to a reverse #proxy supporting to delegate authentication to a backend service, like e.g. #nginx' "auth_request". It's a very small piece of software written in pure #C with as little external dependencies as possible. It requires some #POSIX (or "almost POSIX", like #Linux, #FreeBSD, ...) environment, OpenSSL (or LibreSSL) for TLS and zlib for response compression.
Currently, the only credential checker module available offers #PAM authentication, more modules will come in later releases.
swad 0.2 brings a few bugfixes and improvements, especially helping with security by rate-limiting the creation of new sessions as well as failed login attempts. Read details and grab it here:
@jurjen_heeck nou ik bedank!
Ik blijf het onvoorstelbaar, schandelijk, schandalig en abject vinden dat de PUBLIEKE omroep me een pagina voorschotelt waar ik er “social cookie” moet nemen om de content waar ik mede belasting voor betaald heb te kunnen serveren!
Het is een ASOCIAAL #cookie!
Wir wollen die #Cookie-Flut im Internet verringern. Das hat die #Bundesregierung im letzten Jahr beschlossen und ist jetzt in Kraft getreten.
Released: #swad v0.1
Looking for a simple way to add #authentication to your #nginx reverse proxy? Then swad *could* be for you!
swad is the "Simple Web Authentication Daemon", written in pure #C (+ #POSIX) with almost no external dependencies. #TLS support requires #OpenSSL (or #LibreSSL). It's designed to work with nginx' "auth_request" module and offers authentication using a #cookie and a login form.
Well, this is a first release and you can tell by the version number it isn't "complete" yet. Most notably, only one single credentials checker is implemented: #PAM. But as pam already allows pretty flexible configuration, I already consider this pretty useful
If you want to know more, read here:
https://github.com/Zirias/swad
DId lots of smaller improvements to #swad ... but first, I had to hunt down a crash . Finally found it was caused by my #poser lib (to be fixed later): A connection there can resolve the hostname of a remote end and does so in a thread job to avoid blocking. If the connection dies meanwhile, the job is canceled. Seems my canceling mechanism relying on a signal to the thread is, well, not reliable (the signal can arrive delayed). Ok, for now just disabled name resolution to sidestep that.
Now, integration with #nginx is much better. I intrdoduced (optional) custom headers to transport the authentication realm and the redirect URI, plus state management in the session, so these can be passed to the "auth" endpoint. This requires to make sure nginx always passes the session #cookie, Unfortunately, I still need a "hacky" redirect configuration for login in nginx. If auth_request could just pass the response body, this would be unnecessary ....
The nginx configuration shows #swad running on "files" and another nginx running on "wwwint" serving #poudriere output there. This nginx instance helpfully adds cache hints, which I have to override, so a redirect works as expected when for example the swad session times out.
"#Haftung von #Cookie-Anbietern bei fehlender Einwilligung"
-> Haftet der Anbieter nach dem nach dem #TDDDG?
https://www.dr-datenschutz.de/haftung-von-cookie-anbietern-bei-fehlender-einwilligung/
Österreich: VwGH-Entscheidung zu #Cookie-Bannern
Der VwGH bestätigt: Eine erschwerte Cookie-Ablehnung verstößt gegen die #DSGVO.https://ris.bka.gv.at/Dokument.wxe?Abfrage=Vwgh&Dokumentnummer=JWT_2024040424_20250116L00
@privacyDE (Stiftung Datenschutz):
„Noch immer verstoßen viele Cookie-Banner gegen gesetzliche Vorgaben. Oft wird die Ablehn-Funktion hinter sog. Dark Patterns versteckt. Dabei handelt es sich um ein Design, das das Auffinden der Ablehn-Funktion erschwert. Die österreichische Entscheidung stärkt das Recht der Nutzenden.“
New pre-print online:
‘The EU Digital Services Act: what does it mean for online advertising and adtech?’
By Pieter Wolters and me.
We explore the question: what does the Digital Services Act mean for online advertising?
We show that some types of ad tech companies, such as ad networks, should be considered platforms.
Comments are welcome! It's a pre-print, so we can still improve it.
Due to clouds, rain & snow, we likely won't see much of the total lunar eclipse in Montana and Wyoming overnight (~12:30 to ~1:30). Instead, here is a delicious-looking Oreo cookie eclipse!
Made these for a book club who just finished The Soulmate Equation https://www.diningandcooking.com/1941494/made-these-for-a-book-club-who-just-finished-the-soulmate-equation%f0%9f%92%99/ #cookie #CookieDecorating
#Cookiewall tra silenzi e scuse: non tutto ciò che infastidisce lede un diritto e non tutto ciò che lede un diritto infastidisce.
Leggere un articolo online inizia a essere seccante a causa dell’impiego diffuso dei #cookie #paywall. Viene però il dubbio se al di là del fastidio, che santo cielo possiamo liberamente provare per qualsivoglia cosa dell’universo mondo, non ci sia anche una violazione di qualche tipo di diritto.
https://www.gdpready.it/blog/cookie-paywall-fra-silenzi-e-scuse/
Il post di @m0r14rty su @privacypride
@mattgrayyes the sheer fact there's neither a "#DeclineAll" button that declines all nor that they don't interpret a #DoNotTrack-#Cookie as a 'decline all' should be illegal!
Im aktuellen Newsletter (28.02.2025) der #Datenschutzstelle #Liechtenstein geht es um drei Themen, welche mehrfach in der DSS aufkamen bzw. von ihr in Verfahren gerügt wurden: Hinweis zur optischen Gestaltung von #Einwilligungsmanagement-Tools (#Cookie-Bannern) auf Webseiten
Vorsicht bei der selbst-deklarierten #DSGVO-Konformität von Softwarelösungen oder Cloud-Diensten
Hinweis zu Risiken bei der Nutzung von #DeepSeek
https://www.datenschutzstelle.li/aktuelles/aktuelles-aus-der-datenschutzstelle-4
Les cookies de ma mère ! Refuser les cookies, oui ! Cliquer à chaque site... euh... C'est quoi un cookie au fait ?
Tanguy , ancien président de R.A.P. vous explique tout ça dans @mediapartblogs . https://blogs.mediapart.fr/tanguy-delaire/blog/260225/2-les-cookies-de-ma-mere