Skip to main content
QUICK REVIEW

[论文解读] Uncovering the Flop of the EU Cookie Law

Martino Trevisan, Stefano Traverso|arXiv (Cornell University)|May 24, 2017
Privacy, Security, and Data Protection参考文献 19被引用 15
一句话总结

本文介绍了CookieCheck,一种自动化工具,用于通过检测网站是否在获得用户同意前安装跟踪性Cookie来审计欧盟《电子隐私指令》的合规性。该研究分析了超过35,000个网站,发现65%的网站在未事先获得同意的情况下部署了跟踪Cookie,暴露了尽管已实施多年,但在执法方面仍存在系统性失败。

ABSTRACT

In 2002, the European Union (EU) introduced the ePrivacy Directive to regulate the usage of online tracking technologies. Its aim is to make tracking mechanisms explicit while increasing privacy awareness in users. It mandates websites to ask for explicit consent before using any kind of profiling methodology, e.g., cookies. Starting from 2013 the Directive is mandatory, and now most of European websites embed a "Cookie Bar" to explicitly ask user's consent. To the best of our knowledge, no study focused in checking whether a website respects the Directive. For this, we engineer CookieCheck, a simple tool that makes this check automatic. We use it to run a measurement campaign on more than 35,000 websites. Results depict a dramatic picture: 65% of websites do not respect the Directive and install tracking cookies before the user is even offered the accept button. In few words, we testify the failure of the ePrivacy Directive. Among motivations, we identify the absence of rules enabling systematic auditing procedures, the lack of tools to verify its implementation by the deputed agencies, and the technical difficulties of webmasters in implementing it.

研究动机与目标

  • 调查欧盟《电子隐私指令》在现实网站中的实施与合规情况。
  • 开发一种自动化工具,能够检测网站是否在获得用户同意前安装了分析性Cookie。
  • 衡量欧洲网站中非合规行为的广泛程度,并识别不同国家、行业和设备类型中的模式。
  • 分析非合规的根本原因,包括缺乏标准化的审计程序以及网站管理员面临的技术挑战。
  • 向政策制定者和研究人员提供当前执法机制失效的信息,并强调改进监管工具的必要性。

提出的方法

  • CookieCheck通过模拟新用户访问网站来自动化检测分析性Cookie。
  • 该工具分析初始页面加载后浏览器中安装的Cookie,以识别被归类为分析性的Cookie。
  • 如果在用户与同意机制(例如Cookie提示条)互动之前已设置任何分析性Cookie,则将该网站标记为非合规。
  • 测量活动涵盖来自25个不同国家和25个类别的35,000个网站,使用来自不同地理位置的受控爬取。
  • 我们在不同国家之间进行合规性评估,这些国家的监管严格程度各不相同,同时涵盖移动和桌面设备。
  • 通过箱线图分析比较不同司法管辖区的结果,以评估更严格的国家法律是否带来更好的合规性。

实验结果

研究问题

  • RQ1欧洲网站在多大程度上遵守了欧盟《电子隐私指令》中关于在安装分析性Cookie前必须事先获得同意的要求?
  • RQ2合规性在不同网站类别(如新闻、政府或成人内容网站)之间有何差异?
  • RQ3该指令在各国实施的严格程度是否影响了合规率?
  • RQ4用户的地理位置或设备类型是否对Cookie部署产生可测量的影响?
  • RQ5阻碍该指令有效执法的主要技术和制度障碍是什么?

主要发现

  • 在分析的35,000个网站中,65%违反了《电子隐私指令》,因为在未提供同意机制前即安装了分析性Cookie。
  • 在“新闻与媒体”类别中,非合规率高达92%,表明该行业是所有行业中违规程度最高的。
  • 成人网站表现出相对较高的合规性,仅低于法律和政府网站,表明可能存在特定行业的执法模式。
  • 在来自监管更严格(如意大利)或较宽松(如德国)国家的爬取中,部署的分析性Cookie数量并无显著差异。
  • 更换浏览器或设备类型(移动设备与桌面设备)对安装的Cookie数量几乎没有影响,表明非合规行为在各类环境中保持一致。
  • 本研究识别出非合规的五个主要原因:缺乏标准化的审计程序、缺少自动化验证工具、Cookie提示条规格不明确、网站管理员面临的技术复杂性,以及用户隐私意识较低。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。