GDPR: New Website features and statistics export option

We plan to upgrade the Einstein@Home Web site this coming week in order to deploy new features that make our project more GDPR compliant. To that end users will see some new options that I will summarize here.

  • New users may only create an account by registering through the Web site. After your account is created, you may connect to Einstein@Home using a client. We recommend to always install the latest BOINC Manager to ensure compatibility with the current and upcoming changes.
  • Existing users will be asked to consent to our privacy policy and forum guidelines upon their next website login.
  • There is a new privacy option: Do you consent to exporting your data to BOINC statistics aggregation Web sites? This is set to 'No' (disabled) by default. You may enable the feature in Account -> Preferences -> Privacy.

    • Sites that aggregate project stats, such as BOINCstats, may not function for you if you do not enable this option.

These features are already in place on our test project: Albert@Home.

In order to make the transition easier, there will be a two week period after the Web site is updated but before the statistics export option goes into effect. This grace period will end on December 17th. Users should still go to the privacy preferences page, and enable statistics exports in preparation of the new policy.

PS - Some other BOINC projects may also require users to consent to statistics exports soon. This means you must enable a similar statistics export option on their respective Web sites.

Update: 2018-11-29 - The changes to the Web site have been rolled-out. The statistics export option will go in effect December 17th.

Comments

bcavnaugh
bcavnaugh
Joined: 25 Jan 14
Posts: 20
Credit: 307273960
RAC: 0

So we can no longer use

So we can no longer use BAM!?

Are you not going support BAM! any longer?


Crunching@EVGA The Number One Team in the BOINC Community. Folding@EVGA The Number One Team in the Folding@Home Community.

earthbilly
earthbilly
Joined: 4 Apr 18
Posts: 59
Credit: 1140229967
RAC: 0

I read we have a

I read we have a choice

 

There is a new privacy option: Do you consent to exporting your data to BOINC statistics aggregation Web sites? This is set to 'No' (disabled) by default. You may enable the feature in Account -> Preferences -> Privacy.

 

Or is BAM different?

Work runs fine on Bosons reacted into Fermions,

Sunny regards,

earthbilly

Shawn Kwang
Shawn Kwang
Joined: 3 Nov 15
Posts: 289
Credit: 3054836
RAC: 1542

My understanding is that BAM!

My understanding is that BAM! is an account manager (AM), as oppose to a statistics aggregation site. Now the same person runs BOINCStats and developed BAM!, and you download BAM! from the same Web site as BOINCStats.

Now I don't use these services, but my understanding is the following. If you do not enable the statistics aggregation, BAM! should still work. However, your stats will not be aggregated on BOINCStats. Maybe someone who uses Albert@Home with BAM! could test this out for us and get back to me (via DM).

Einstein@Home Project

Killersocke@Einstein
Killersocke@Einstein
Joined: 12 Apr 06
Posts: 5
Credit: 47017901
RAC: 0

In the first post is

In the first post is a spelling mistake ( https://ablertathome.org/)

the correct link is:

https://albertathome.org/de/home

Shawn Kwang
Shawn Kwang
Joined: 3 Nov 15
Posts: 289
Credit: 3054836
RAC: 1542

Thanks Killersocke! I've

Thanks Killersocke! I've fixed the link.

Einstein@Home Project

Killersocke@Einstein
Killersocke@Einstein
Joined: 12 Apr 06
Posts: 5
Credit: 47017901
RAC: 0

kein Problem

kein ProblemSmile

DanNeely
DanNeely
Joined: 4 Sep 05
Posts: 1364
Credit: 3562358667
RAC: 0

RIP any useful stats.

RIP any useful stats.

bcavnaugh
bcavnaugh
Joined: 25 Jan 14
Posts: 20
Credit: 307273960
RAC: 0

Welcome to the Take Over of

DanNeely wrote:
RIP any useful stats.

Welcome to the Take Over of the World by the EU


Crunching@EVGA The Number One Team in the BOINC Community. Folding@EVGA The Number One Team in the Folding@Home Community.

Killersocke@Einstein
Killersocke@Einstein
Joined: 12 Apr 06
Posts: 5
Credit: 47017901
RAC: 0

"....This is set to 'No'

"....This is set to 'No' (disabled)....by default"

This option was in my account enabled

Oliver Behnke
Oliver Behnke
Moderator
Administrator
Joined: 4 Sep 07
Posts: 984
Credit: 25171376
RAC: 50

Killersocke@Einstein

Killersocke@Einstein wrote:

This option was in my account enabled

Where? On A@H? This option doesn't even exist yet on E@H.

Cheers,
Oliver

Einstein@Home Project

Oliver Behnke
Oliver Behnke
Moderator
Administrator
Joined: 4 Sep 07
Posts: 984
Credit: 25171376
RAC: 50

bcavnaugh wrote:Are you not

bcavnaugh wrote:
Are you not going support BAM! any longer?

Well, we might have to suspend account creation via BAM! for the time being. The GDPR requirements and their implementation in BOINC are still work in progress. That means not all parts are fully in place yet. That also concerns the BOINC Manager (client GUI) that doesn't yet support the Terms Of Use display and acceptance we need which is why we need to suspend remote account creation until that's fixed. This also affects BAM! which uses the same facility for creating accounts AFAIK. We're happy to reinstate all of that as soon as the new process is fully supported by all parties. Until then we need to channel new accounts through our website.

Sorry for the inconvenience,

Oliver

Einstein@Home Project

Thyme Lawn
Thyme Lawn
Joined: 13 Jun 15
Posts: 7
Credit: 12137755
RAC: 0

Existing users will be asked

Existing users will be asked to consent to our privacy policy and forum guidelines.

This statement indicates that existing users need to positively consent to the the new privacy policy and forum guidelines, but there's currently no mechanism on those pages (or the equivalent ones on A@H) where this can be done.  If we do have to consent to these modifications my understanding is that implied consent doesn't satisfy GDPR.

Also, if changes are made to allow existing users to positively consent to the changes what's going to happen to accounts where consent is actively withheld on those pages and (more to the point) to accounts where an active consent/reject indication is never made?

"The ultimate test of a moral society is the kind of world that it leaves to its children." - Dietrich Bonhoeffer

Oliver Behnke
Oliver Behnke
Moderator
Administrator
Joined: 4 Sep 07
Posts: 984
Credit: 25171376
RAC: 50

Thyme Lawn wrote:...there's

Thyme Lawn wrote:

...there's currently no mechanism on those pages (or the equivalent ones on A@H) where this can be done...

You'll be asked to either accept our terms of use or not (or even delete your account) upon your next login. We'll clarify that in the text above.

Quote:

what's going to happen to accounts where consent is actively withheld on those pages and (more to the point) to accounts where an active consent/reject indication is never made?

You won't be able to use our website anymore.

Cheers,
Oliver

Einstein@Home Project

bcavnaugh
bcavnaugh
Joined: 25 Jan 14
Posts: 20
Credit: 307273960
RAC: 0

At least the website is now

At least the website is now updated and showing the settings.

It is not an inconvenience is the start of the seconded ending of BOINC

This Process should ALL be covered in the BOINC Client Software, you install it your are saying Yes.


Crunching@EVGA The Number One Team in the BOINC Community. Folding@EVGA The Number One Team in the Folding@Home Community.

Chooka
Chooka
Joined: 11 Feb 13
Posts: 134
Credit: 3701045759
RAC: 1273146

I'd like to say well done to

I'd like to say well done to the team that implemented this. It could have been a real mess like over at WGC but this was a very smooth rollout and easy to follow instructions to export data.

Great job.

I'm glad there was a way around this GDPR stuff as credit and crunching with ranking is what this is all about (well to me anyway)


Oliver Behnke
Oliver Behnke
Moderator
Administrator
Joined: 4 Sep 07
Posts: 984
Credit: 25171376
RAC: 50

bcavnaugh wrote:This Process

bcavnaugh wrote:
This Process should ALL be covered in the BOINC Client Software, you install it your are saying Yes.

I think we all agree with you on this. The problem is that BOINC is open source software so you can't really enforce a strict timeline for new features - while the GDPR does. This is why we opted to go live with this. We want to be on the legally safe side. That said, we're already working actively to get the required extensions into the BOINC Client/Manager and then also into the account managers like BAM!. As always, it's just a matter of time but we're on it.

Best,
Oliver

 

Einstein@Home Project

jjch
jjch
Joined: 19 Oct 16
Posts: 1
Credit: 1014667762
RAC: 161385

I would like to know if these

I would like to know if these changes will allow Einstein@home to now be included as a project for the Gridcoin team.

I prefer E@H over Milkyway@home or Seti@home but Gridcoin was not including E@H anymore.

Oliver Behnke
Oliver Behnke
Moderator
Administrator
Joined: 4 Sep 07
Posts: 984
Credit: 25171376
RAC: 50

This is mostly independent of

This is mostly independent of the sadly ongoing Gridcoin issue which I commented on here.

Oliver

Einstein@Home Project

Solarrus
Solarrus
Joined: 3 Apr 10
Posts: 11
Credit: 19319337
RAC: 0

It will be better, to make it

It will be better, to make it more beautyful and friendly.

Shawn Kwang
Shawn Kwang
Joined: 3 Nov 15
Posts: 289
Credit: 3054836
RAC: 1542

I want to remind people that

I want to remind people that in one week, our stats exports will change and honor the option Do you consent to exporting your data to BOINC statistics aggregation Web sites? 

If you want to have your stats exported, and have not changed this setting, to YES, please do so in Account -> Preferences -> Privacy. Also, I have been informed that at the BOINCstats Web site, your user history may be lost if you do not consent to the stats exports before we update our systems on 2018 Dec 17th. If this is something you care about (BOINCstats history), please change your privacy preferences.

Einstein@Home Project

jenn trengove
jenn trengove
Joined: 21 Nov 18
Posts: 1
Credit: 750
RAC: 0

Updated! Let's go catch some

Updated! Let's go catch some waves, man 

Oliver Behnke
Oliver Behnke
Moderator
Administrator
Joined: 4 Sep 07
Posts: 984
Credit: 25171376
RAC: 50

Welcome to the family and

Welcome to the family and thanks for supporting us!

Einstein@Home Project

thinking_goose
thinking_goose
Joined: 16 Nov 09
Posts: 1
Credit: 601704
RAC: 0

(I don't understand GDPR) Is

(I don't understand GDPR) Is it necessary? The stats don't identify individuals, just a group of computers. Maybe if world-facing IP addresses were included, but I'm not sure they are as I've never checked from outside.

Jonathan Brier
Joined: 18 Oct 05
Posts: 3
Credit: 42876389
RAC: 0

I almost missed this, was

I almost missed this, was there an email sent notifying of this breaking change?  It is a pretty easy thing to overlook a notice in BOINC manager. I hope that sharing of stat history missed is possible if features are implemented that stop the sharing when this opt-in enforcement begins.  

Second participants who want to share in one project should be given the option to share all their projects stats without needing to go to every project website. This is a feature addition to BOINC so why not make a universal preference controllable via the BOINC client?

Shawn Kwang
Shawn Kwang
Joined: 3 Nov 15
Posts: 289
Credit: 3054836
RAC: 1542

@Greg,  (I don't understand

@Greg, 

(I don't understand GDPR) Is it necessary? The stats don't identify individuals, just a group of computers.

GDPR not only covers the individuals themselves but any information they give to us. Or at least that is according to what our Data Protection Officer (DPO) as well as any legal advice we have received. Thus we must ask for users' consent when distributing this data.

@Jonathan

Was there an email sent notifying of this breaking change?

We typically make these kind of announcements on the BOINC Manager News as well as in the forums, as well as Twitter. How to contact thousands of people for E@H is not a trivial problem and we try to use multiple message platforms. Also, we typically don't email volunteers because it's a privacy preference to opt-out of emails, and thus we won't reach everyone that way either!

Second participants who want to share in one project should be given the option to share all their projects stats without needing to go to every project website. This is a feature addition to BOINC so why not make a universal preference controllable via the BOINC client?

BOINC is not a monolithic entity but a software program; or a few different software programs that work together. Each project downloads BOINC and runs it for its own ends. There is no universal BOINC preference as there are separate BOINC projects, each with their own interpretations of GDPR. (Some are USA-based, others in the EU.)

What you write of is similar to the Science United project.

Einstein@Home Project

Magiceye04
Magiceye04
Joined: 18 Feb 06
Posts: 31
Credit: 812466187
RAC: 789327

bcavnaugh schrieb:DanNeely

bcavnaugh wrote:
DanNeely wrote:
RIP any useful stats.

Welcome to the Take Over of the World by the EU

I agree with bcavnaugh. From now on we dont have useful stats any more.

And i think Einstein@Home really, really strong overshoot the mark of the GDPR.

To add the option is OK, but the standard should have been "YES"

Why should i compute for Einstein any longer if i dont know how i perform compared to the rest of the world?

The number of answers to this thread will match more or less to the number of people who switch the GDPR-fear off.

This will just be another chapter for the Absurditätenkabinett (sorry, only german)

smiley_emoticons_segen.gif

 

 

johnnymc
Joined: 6 Mar 11
Posts: 5
Credit: 84688968
RAC: 0

Are all boinc projects

Are all boinc projects offering this option and if so, turning it off by default? That's a lot of work for me performing the task of approving sharing of my data on all projects I participate(d) in.

Mind you I am not a statistic hound or else I would be purchasing top of the line hardware to assist in the myriad of distributed projects existing. The sharing of information calculated by each participant helps show others considering joining these projects how many others are participating as well.

Life's short; make fun of it!

MzSnowleopard
MzSnowleopard
Joined: 29 Aug 07
Posts: 1
Credit: 107287
RAC: 0

Done... Thank you for the

Done... Thank you for the notice.

Marc Keijzers
Marc Keijzers
Joined: 15 Apr 18
Posts: 1
Credit: 941417
RAC: 0

Done.

Done.

mutant
mutant
Joined: 5 Aug 07
Posts: 1
Credit: 2637899
RAC: 0

Are the points similar to

Are the points similar to "Whose Line Is It Anyway?" points?

Paul
Paul
Joined: 3 May 07
Posts: 123
Credit: 1784920768
RAC: 425531

I don't understand why so

I don't understand why so much information is shared with such services.  All they need is your cross-project ID and your credit.  Right?

I don't even see any of the computer/hard drive/memory bandwidth information on those sites.  Am I missing it?  How is this information relevant for there purposes?  Is there no requirement in the GDPR that shared information is necessary, appropriate, and granular?

Tinu1976CH
Joined: 15 May 06
Posts: 1
Credit: 29334938
RAC: 947

changes done great new

changes done

great new site

interesting login option: agree and login - no, logout - no, delete account

Boinc Stats TinuCH1976

solling2
solling2
Joined: 20 Nov 14
Posts: 219
Credit: 1577454655
RAC: 18597

Is it for sure that the data

Is it for sure that the data export doesn't include email of participants? I assume that any stats site will get anonymized data only?

Oliver Behnke
Oliver Behnke
Moderator
Administrator
Joined: 4 Sep 07
Posts: 984
Credit: 25171376
RAC: 50

MagicEye wrote: And i think

MagicEye wrote:

And i think Einstein@Home really, really strong overshoot the mark of the GDPR.

To add the option is OK, but the standard should have been "YES"

 

What you're asking is a violation of Art. 25 GDPR. Rest assured that we carefully analyzed the situation and made informed decisions after getting legal advise. We're trying to implement these things in the least invasive way possible, in our own interest.

MagicEye wrote:

Why should i compute for Einstein any longer if i dont know how i perform compared to the rest of the world?

 

First, we hope you're mainly participating in E@H to support our science ;-) Second, you may still compare your stats against everyone else who wants to publish their data for comparison.

Cheers,
Oliver

Einstein@Home Project

DanNeely
DanNeely
Joined: 4 Sep 05
Posts: 1364
Credit: 3562358667
RAC: 0

johnnymc wrote:Are all boinc

johnnymc wrote:

Are all boinc projects offering this option and if so, turning it off by default? That's a lot of work for me performing the task of approving sharing of my data on all projects I participate(d) in.

Mind you I am not a statistic hound or else I would be purchasing top of the line hardware to assist in the myriad of distributed projects existing. The sharing of information calculated by each participant helps show others considering joining these projects how many others are participating as well.

 

Most projects currently are not.  Of those that have commented publicly, I'm not aware of any that have interpreted the ambiguities in the law as strictly as E@H's lawyers have.  (And I suspect most smaller and/or non-EU based ones are either taking a wait and see approach or are unaware of the potential issue at all.)  IF E@H's interpretation is overly strict or other projects are overly lax won't be known until at least one, and possibly several, rounds of litigation between companies whose business includes collecting and making money from user data and EU Govts/privacy advocates have gone through the courts.

 

E@H's strict interpretation likely has something to do with its European arm being based in Germany.  Largely in reaction to learning how thoroughly the Satsi (East Germany's Secret Police) were spying on the population, modern Germany is particularly sensitive to privacy concerns. 

Oliver Behnke
Oliver Behnke
Moderator
Administrator
Joined: 4 Sep 07
Posts: 984
Credit: 25171376
RAC: 50

solling2 wrote:Is it for sure

solling2 wrote:
Is it for sure that the data export doesn't include email of participants? I assume that any stats site will get anonymized data only?

You'll find all the details in our privacy policy (section D.2).

Cheers,
Oliver

Einstein@Home Project

Oliver Behnke
Oliver Behnke
Moderator
Administrator
Joined: 4 Sep 07
Posts: 984
Credit: 25171376
RAC: 50

Paul wrote:I don't understand

Paul wrote:

I don't understand why so much information is shared with such services.  All they need is your cross-project ID and your credit.  Right?

Well, this is a question of what intentions and purposes these stats sites or leaderboards have. I think the original design wanted to provide the community with the means to compare users and computers on more than just the (cross-project) ID, for instance their country of origin or the operating system or CPU type used.

Apart from that, this is question that should be directed to BOINC as a whole or the various stats sites as it's independent of the individual projects and rather a part of the general BOINC ecosystem. We as a project just try to stay compatible with the rest of the BOINC ecosystem, and that includes the stats sites, while ensuring legal compliance in the interest of our users.

Best,
Oliver

 

 

Einstein@Home Project

Tern
Tern
Joined: 27 Jul 05
Posts: 309
Credit: 99440614
RAC: 0

My simple problem with GDPR -

My simple problem with GDPR - it DOES NOT APPLY TO ME. I do not have to abide by any of it's rules or regulations whatsoever. I realize that others DO - but do not appreciate my having to do even a single "click" somewhere because of it. As a programmer, I know what data you store and that you have no way of knowing if this law applies to me or not, so CAN'T default me to a "yes", but it's just annoying. Plus the law as written is over-complicated, unreasonable, unworkable, overly intrusive, impractical... I could go on. But - not my problem, except for all the places I have to make some extra "click."

Magiceye04
Magiceye04
Joined: 18 Feb 06
Posts: 31
Credit: 812466187
RAC: 789327

The only relevant information

The only relevant information ist my email-adress. And i hope it will be kept secretly also in the future. ;)

All other data is not personal, only statistics. Nothing to be secured.

And of course i will continue crunching from time to time. But not as enhusiastic as in the past.

Paul
Paul
Joined: 3 May 07
Posts: 123
Credit: 1784920768
RAC: 425531

MagicEye wrote:All other data

MagicEye wrote:
All other data is not personal, only statistics. Nothing to be secured.

Well, you can say it's not personally identifiable information (PII), like your full legal name, but it is "linked" to PII, like your eye color and your age.  Those are just statistics, too.  The shared account information includes your account name, join date, country, and time zone, just for starters.  And, in addition to that, the computer details for all you computers are shared, which is almost unique to you when taken all together.  It's not as if it is anonymized; that would be a completely different thing.  I mean, I think I'm going to keep sharing it too, but it should be treated as unique.  Pseudo-unique?  And, that means it shouldn't be shared lightly.

DanNeely
DanNeely
Joined: 4 Sep 05
Posts: 1364
Credit: 3562358667
RAC: 0

Bill Michael wrote:My simple

Bill Michael wrote:
My simple problem with GDPR - it DOES NOT APPLY TO ME. I do not have to abide by any of it's rules or regulations whatsoever. I realize that others DO - but do not appreciate my having to do even a single "click" somewhere because of it. As a programmer, I know what data you store and that you have no way of knowing if this law applies to me or not, so CAN'T default me to a "yes", but it's just annoying. Plus the law as written is over-complicated, unreasonable, unworkable, overly intrusive, impractical... I could go on. But - not my problem, except for all the places I have to make some extra "click."

 

It doesn't apply to you for entities (websites, businesses, etc) who are based outside of Europe.  But European entities are required to follow the GDPR for all of their users; where ever in the world we are.  E@H is partially based in Europe and thus is required to follow their interpretation of the GDPR for all of us.

morpheus
morpheus
Joined: 20 Mar 05
Posts: 4
Credit: 1236793374
RAC: 12193

Hmm...

Hmm...

.:morpheus:.

Joel Martain
Joel Martain
Joined: 12 Mar 10
Posts: 1
Credit: 1691227
RAC: 0

Project output looks awfully

Project output looks awfully empty today. I guess it's related to this topic. 

https://boincstats.com/en/stats/5/user/list/12/0/0

Oliver Behnke
Oliver Behnke
Moderator
Administrator
Joined: 4 Sep 07
Posts: 984
Credit: 25171376
RAC: 50

Sort of, yes. BOINCstats has

Sort of, yes. BOINCstats has a safety-procedure that is supposed to prevent faulty data imports. That got tripped by the significant change in our data exports so the guys had to give their manual "Go" for the import. They've done that now and the data will be updated during the next import run tonight (CET).

Cheers

Einstein@Home Project

Shadow
Shadow
Joined: 13 Mar 18
Posts: 3
Credit: 40255
RAC: 0

So If He Dies, He Dies! It

So If He Dies, He Dies!

It is done, I go back to ussr hug....Rocky3

Shadow
Shadow
Joined: 13 Mar 18
Posts: 3
Credit: 40255
RAC: 0

I can say one thing about

I can say one thing about EU!

And that is, They know how to pull the plug when needed and when they pull the plug. They really pull the plug. But what Happens afterward and even if you or anyone else, lose anything it will be none of their concern. So can we get on with the unleashing or what? Beside Is was in EU from their start anyway.  :)

LOL 

Shadow
Shadow
Joined: 13 Mar 18
Posts: 3
Credit: 40255
RAC: 0

You do not know the way.

You do not know the way.

DanNeely
DanNeely
Joined: 4 Sep 05
Posts: 1364
Credit: 3562358667
RAC: 0

I think I can sum up

I think I can sum up everything about how well E@H managed their Global Destruction of Public Records went by listing a few accounts that got nuked:

ATLAS AEI Hannover

Armin Burkhardt speaking for MPI/FKF

LIGO Hanford Observatory

AEI eScience group, for the German Grid (D-Grid)

Atlas Admins E@H secondary account

Steffen Grunewald, for Merlin/Morgane

All of which were, AFAIK accounts associated with the E@H program itself.

Mumak
Joined: 26 Feb 13
Posts: 325
Credit: 3515638807
RAC: 1686937

Well, I missed that deadline

Well, I missed that deadline and enabled the export option only today.
What now, are all my stats erased forever and sent to /dev/null ?

-----

Oliver Behnke
Oliver Behnke
Moderator
Administrator
Joined: 4 Sep 07
Posts: 984
Credit: 25171376
RAC: 50

Hi Mumak,your stats should

Hi Mumak,

your stats should reappear within a day, obviously without historical data, though.

Best,
Oliver

Einstein@Home Project