HN user

JackWritesCode

344 karma
Posts36
Comments179
View on HN
usefathom.com 3mo ago

Fathom Acquires Gauges

JackWritesCode
2pts0
planetscale.com 3y ago

Running Query Insights on PlanetScale

JackWritesCode
15pts1
planetscale.com 3y ago

PlanetScale Scaler Pro

JackWritesCode
131pts42
planetscale.com 3y ago

Generated Hash Columns in MySQL

JackWritesCode
5pts0
illegal.analyticsscanner.com 4y ago

Show HN: Illegal Analytics Scanner

JackWritesCode
13pts13
www.singlestore.com 4y ago

An Engineer's Guide to Building a Database for Data-Intensive Applications

JackWritesCode
4pts0
blog.ymirapp.com 4y ago

The serverless revolution is alive and well

JackWritesCode
2pts0
usefathom.com 5y ago

Building the Fastest Website Analytics

JackWritesCode
5pts3
usefathom.com 5y ago

Designing a Million Dollar Brand

JackWritesCode
1pts0
usefathom.com 5y ago

Everyone Has Something to Hide

JackWritesCode
4pts0
usefathom.com 5y ago

Everyone Has Something to Hide

JackWritesCode
2pts0
usefathom.com 5y ago

Does targeted digital advertising work?

JackWritesCode
1pts0
usefathom.com 5y ago

How to build a privacy-first software business

JackWritesCode
3pts0
usefathom.com 5y ago

Hosted vs. self-hosted website analytics

JackWritesCode
4pts0
usefathom.com 5y ago

Big tech finally challenges Fathom Analytics

JackWritesCode
2pts0
usefathom.com 5y ago

What happened to our infrastructure when a customer went viral

JackWritesCode
2pts0
usefathom.com 5y ago

What happened to our infrastructure when a customer got over 10M views?

JackWritesCode
2pts0
usefathom.com 5y ago

I quit my job to work on Fathom Analytics full time

JackWritesCode
1pts0
usefathom.com 6y ago

What tech stack does Fathom Analytics use?

JackWritesCode
2pts0
usefathom.com 6y ago

My 1 year review of Laravel Vapor

JackWritesCode
3pts3
usefathom.com 6y ago

Let’s talk about Friday and the Cloudflare outage

JackWritesCode
1pts0
usefathom.com 6y ago

SaaS Lessons

JackWritesCode
7pts0
usefathom.com 6y ago

We fired our first customer

JackWritesCode
4pts0
jackellis.me 6y ago

Reflections on Turning 27

JackWritesCode
2pts0
usefathom.com 6y ago

20 Years to Overnight Success

JackWritesCode
4pts0
laravel-news.com 6y ago

How to add unlimited custom domains to Laravel Vapor

JackWritesCode
2pts0
usefathom.com 6y ago

Fathom Analytics launches simple uptime monitoring

JackWritesCode
1pts0
usefathom.com 6y ago

I quit my job to work full time on my startup

JackWritesCode
1pts0
usefathom.com 6y ago

I quit my job to work on Fathom Analytics full time

JackWritesCode
5pts0
usefathom.com 6y ago

Dear internet: We must ban targeted advertising immediately

JackWritesCode
102pts98

Fathom's script forgets everybody by default, it's literally built into the tech. No EU personal data is touching Canada.

The background of Schrems II was that the US government can compel US companies to track foreign nationals and it would be lawful under US law. This is where the argument of "company in X under Y laws" comes into play. For example, Amazon is a US company. An EU subsidiary is still subject to it's parents control. If that parent is a US company, it's subject to US surveillance laws. Hello Schrems II.

So I'm not fully following why we're having a discussion around processing happening in Canada when personal data (IP Address) hits our EU Isolation infrastructure.

If you have any sources you can cite where the European Commission states BC as an exemption to Canada's adequacy ruling, please throw it back to me. I've not seen that.

1. I understand the piece about "stamp" of adequacy. But when the Schrems II ruling happened, the world learned that we cannot always rely on "stamps" and need to look into the laws. At this moment in time, the European Commission says that Canada has adequacy ruling as a whole and there is no note about it not apply to British Columbia.

So my question to you is: Which part of the Personal Information Protection Act in BC would undermine the EU's adequacy decision towards BC? The reason I'm pushing on this question is because the "stamp" occurs for a reason. Please let me know where the PIPA would lead to the European Commission labelling BC as inadequate.

2. We're mixing things up here with Amazon, Google and Azure. Those companies are subject to FISA 702[1] and EO12333[2]. We are not subject to these surveillance laws here in Canada. I've spoken at length about this before, about how the US government could compel one of these companies to secretly spy on people using their EU infrastructure. So our company is not in the same position.

I'll wait for your specifics around the PIPA.

[1] https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveilla... [2] https://en.wikipedia.org/wiki/Executive_Order_12333

I was linked to this post by a friend regarding the comments you made about Fathom's GDPR compliance.

1. The GDPR is regulation from the European Union

2. PIPEDA has an Exemption order for BC (British Columbia, Canada) and applies "in respect of the collection, use and disclosure of personal information that occurs within the Province of British Columbia".

Firstly, the Exemption order states "Whereas the Governor in Council is satisfied that the Personal Information Protection Act, S.B.C. 2003, c. 63, of the Province of British Columbia, which is substantially similar to Part 1 of the Personal Information Protection and Electronic Documents Act, applies to the organizations described in the annexed Order;"

Secondly, which part of BC's Personal Information Protection Act would undermine it's adequacy ruling under the GDPR?

Finally, let's get into Fathom's pageview/event collection script and explain how it works:

1. There is no collection, use and disclosure of personal information that occurs within the Province of British Columbia

2. EU traffic is automatically routed via EU Isolation and processed on German-owned servers. This allows us to stop US government snooping on EU traffic

3. Fathom Analytics is incorporated in BC. But nobody in BC has access to our EU Isolation infrastructure. I'm the CTO of Fathom Analytics and I have access to our EU Isolation infrastructure. I'm not in BC. Additional access to EU Isolation is from Germany only. Heck, not even GitHub Actions has access to EU Isolation, we self-host GitLab to keep things completely isolated. We put a lot of time and effort into this.

I'll wait back to hear back from you on which parts of the BC's PIPA undermine the adequacy ruling. Our lawyer here in Canada is incredibly well versed in Canadian privacy law, so we can definitely loop her in if there's any confusion here.

I hope that addresses your point and helps inform other people who may be reading this.

No access logs are kept, users aren't profiled or tracked across multiple sites. Ad-blockers blocking privacy-first solutions encourage use of Google Analytics. Being able to bypass ad-blockers is a competitive advantage over GA, which then leads to companies dropping GA, which leads to less data hitting Google's servers. You can read more about ad-blockers vs privacy-first analytics here: https://usefathom.com/blog/ad-blockers-war

I completely agree! For the people following back home, who don’t want to move away from MySQL, can you let us know how to achieve a <10ms GROUP BY aggregation with a high cardinality column (11 million distinct values for “pathname”).

The query was:

SELECT SUM(pageviews) as total, pathname FROM pageviews GROUP BY pathname ORDER BY total DESC LIMIT 10.

If we don’t hear an answer from you, I’ll be really upset. Otherwise, we may have to add your ideas to the article!

By migrating to SingleStore, we didn’t have to change any persistence logic (we were already using SQL and Laravel Eloquent). Having explored doing that for Elasticsearch, it wasn’t something we wanted to do.

Looking back, I’m glad we went in this direction. Fathom has grown beyond what we could’ve imagined. Let’s see what happens over the next five years.

Clickhouse isn’t really relevant for a lot of us. SingleStore outperforms clickhouse and the latter isn’t MySQL wire compatible. Far more features come with SingleStore too. And if you speak to people running Clickhouse, they’re also maintaining a Postgres set-up. With SingleStore, you get your OLTP and OLAP in one database. So our users & sites table sit in memory (backed up by disk), meaning ultra fast read/write speeds (comparable to clustered/high availability Redis). And then we put our pageviews/events in columnstore (disk) which offers rapid performance for analytical queries.

Laravel Bootcamp 4 years ago

Very well written for newcomers. But I also appreciated the clarification in the auth section. I’ve used Laravel for years and the auth had confused me. Bootcamp makes things clearer.

Yup. The Illegal Analytics Scanner is deployed to Germany. We then load the website, observe the pixels loaded, run the IP returned through an IP lookup, and see who controls the server. If it's a US cloud provider, it's not lawful in the EU.

The Schrems II ruling occurred back in 2020. Max Schrems & noyb have filed 101 complaints, and we're now going to see DPAs make decisions (meaning the ruling is enforced). What's new now is that a DPA has actually made a decision against Google Analytics (and US cloud providers).

I can only speculate on what's going to happen.

That if they're processing EU website visitor traffic, they're in violation of the Schrems II ruling, and violating the GDPR. Very messy situation right now.

Correct. That's absolutely right. I'm not 100% sure how my comment wasn't clear, but I will apologize to everyone if I confused them. Anyway, Plausible updated their analytics to use Bunny yesterday, which is a win for their customers. We wrote more about this solution back in 2021 (https://usefathom.com/blog/eu-isolation) after a lot of work. We spent a lot of time looking into possible options, the law, and are pleased that our innovation is going to help other companies.

Yup, just to be clear, I wasn’t talking about site data, I was talking about the processing of Personal Data (IP & User Agent).

You were using Netlify previously, which is a US provider and backed by AWS, and then Cloudflare for the testing.

But yesterday I can see you moved to Bunny (an EU cloud provider), which is great news for your customers, party time!

Provided you’re using Hetzner behind Bunny, that looks like solid Schrems II compliance to me.

Just posted this thread to a friend and they said I wasn't being 100% clear, so I apologize. I'll clear things up.

Using EU servers that are owned by a US company (e.g. AWS deployed in the EU, DigitalOcean deployed in the EU) is a violation of the Schrems II ruling. The way you check this is by looking at the IP addresses the analytics software are using, seeing where they're located and who they're owned by. You can then run that IP in ipinfo.io to get information about who controls that IP. If it's a US cloud provider, regardless of server location, it's a GDPR violation.

The English translation of the ruling can be found here. They go into detail within the rulings about the transfer of Personal Data (IP & User Agent) to servers that cannot be protected from US surveillance laws: https://noyb.eu/sites/default/files/2022-01/E-DSB%20-%20Goog...

"This is a very detailed and sound decision. The bottom line is: Companies can't use US cloud services in Europe anymore. It has now been 1.5 years since the Court of Justice confirmed this a second time, so it is more than time that the law is also enforced." - Max Schrems

Your website visitors Personal Data is processed on US-controlled cloud providers. I've provided evidence that folks reading this need to be careful when choosing analytics software, and I'll leave it at that. I hope to see Plausible move to an EU Isolation approach which doesn't involve US cloud providers.

Yes they do. It's not just about data being stored, it's data processing as a whole. You cannot casually pass EU data subject Personal Data to US-controlled infrastructure.

CDN is processing of Personal Data in the clear. Please read Use Case 6 of the EDPB's recommendations, specifically what they say about US cloud providers (https://edpb.europa.eu/sites/default/files/consultation/edpb...).

And I'm not interested in commenting on what I think Plausible would or wouldn't risk, as it's not relevant.

Sure, happy to explain further. You have found the testing /event but there is another (make sure your ad-blockers are off).

I've put together the details here in an image, so it's easy to follow (https://imgur.com/a/9wEanqD). Hope that explains what I'm talking about.

Sending data from the EU to US-controlled cloud infrastructure is illegal. Please read the noyb article again, read the Schrems II ruling and read the EDPB's advice.

I'm confused. Open up Plausible, look for /event in your inspect element (devtools in chrome), look at the IP address that it connects to. Run that IP through ipinfo.io and see which country comes up. If it's the US, it's illegal (as per this entire thread).

What's childish about me not wanting people to potentially get fined?