SShortSingh.
Back to feed

30% of 1,775 Scanned Websites Leak Tracking Data Before Users Give Consent

0
·4 views

A developer who built a consent-management tool scanned 1,775 real websites to measure how often trackers fire before any user interaction. The scan found that on 30% of sites, a known tracker set a cookie or a Google tag ran with consent granted before the visitor clicked anything. The methodology used headless Chromium to simulate a first-time visitor with no prior consent, logging all network requests, cookies, and storage writes on page load. Only definitive violations were counted — cookieless tags and tools operating in Google Consent Mode's denied state were excluded, making the 30% figure a conservative floor. Under GDPR and ePrivacy rules, non-essential trackers must not run until a visitor has made an explicit choice, meaning a consent banner appearing after page load is already too late.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

HelloNash.ai and Backboard Studio Released as Open Source Projects

The team behind Backboard Studio and HelloNash.ai has announced that both platforms will be made open source. The decision was framed as an act of solidarity with the broader AI community. Backboard Studio is positioned around the concept of Sovereign AI, emphasizing user ownership of their own intelligence and data. The announcement underscores a privacy-first stance, with the developers stating that users' business affairs are not their concern.

0
ProgrammingDEV Community ·

Why the AI Harness, Not the Model, Is the Real Engineering Challenge

As AI adoption grows, engineers argue that the true complexity of production AI systems lies not in the language model itself but in the surrounding infrastructure, known as the AI harness. This harness governs critical decisions such as model selection, input routing, output validation, and orchestration logic. Two teams using identical foundation models can achieve vastly different results depending on how well their harness is designed. Experts suggest AI engineering is shifting from prompt crafting toward software architecture disciplines like observability and system design. Teams that invest in building reliable, well-orchestrated harnesses are seen as better positioned to ship production-ready AI products.

0
ProgrammingDEV Community ·

How Solo Devs Can Secure Internal Services with TLS and mTLS on a Zero Budget

A developer running a small two-server production setup — one hosting Redis, another running Postgres alongside NestJS containers — found that firewall rules and private networking alone did not encrypt inter-service traffic. To address this without costly managed PKI tools or Kubernetes-based solutions, they built a self-hosted Certificate Authority using only OpenSSL. The approach enables both standard TLS and mutual TLS (mTLS), where both client and server authenticate each other, making it suitable for service-to-service communication. The guide covers certificate generation, key custody rules, and lifecycle management including rotation and expiry monitoring. It is aimed at solo developers and small startups who need production-grade encryption without a dedicated security infrastructure budget.