• Resolved DJviolin

    (@djviolin)


    Our organization’s DPO says (located in Hungary under GDPR law) we also need to list WP Cerber’s cookies under a cookie selection dialog when a new visitor opening our site (hence the Dfactory Cookie Notice plugin is not complaint), turned them off by default.

    I sent him this link from your site, where you talking about cookies.

    As webmaster of our site, I told him my concerns about this, because I also responsible for security. I told him attackers probably don’t give a damn too much writing robots which accepting law agreements before trying to hack our site. He told me the user also needs to accept cookies which are neccesary for the site’s operation, regardless if it’s a firewall plugin or not…

    I want to ask WP Cerber’s creators to have a clear documentation what each cookie does and what purpose they have? This way I also can have a clear idea and I can send this link to our DPO. I think lot of other organization will benefit from this.

    I don’t have a template for such cookie documentation, I also following the European Commission’s docs about cookies:
    https://ec.europa.eu/info/cookies_en

    I also want an option in the admin and a js function, where I can enable or disable the cookies of this plugin. I know it’s a lot to ask for, but at the current state, the plugin is not suited for governmental use and have a grey hole about it’s cookie policy.

Viewing 6 replies - 1 through 6 (of 6 total)
  • Plugin Author gioni

    (@gioni)

    I understand your concerns and obligations to comply with GDPR, but it’s crucial to understand that:

    1) WP Cerber’s cookies do not hold any personal data
    2) WP Cerber’s cookies are not used to track any person
    3) WP Cerber’s cookies are regenerating regularly

    The last point makes impossible writing correct technical documentation.

    The only suggestion that I have for now is to provide a shortcode that will display WP Cerber’s cookie names. You will be able to use this shortcode on a privacy policy or a cookie consent page.

    Regarding the ability to enable/disable WP Cerber’s cookies: we will work out a solution soon.

    Thread Starter DJviolin

    (@djviolin)

    Thank You for your answer!

    Yes, this was my answer as well. The problem is:

    • There is the european GDPR law, which we need to comply
    • There is the National Data Security and Information Safety Authority, which interpreted GDPR in their own way, which we need to comply
    • There is our DPO, who is responsible to give guidance for us, how we need to comply

    You can bet, when we arrive at the last point, complying with the GDPR law become much harder for a village with the population of 2600+, than the European Comission’s website…

    For now, I used the prefix in Cerber’s cookie names and a wildcard in my Cookie policy, where I describing Cerber’s cookies: fw_#

    Right now, the current accepted method of dealing with cookies according to our DPO: block every cookie until the user not accept them, also mandatory to include a selectable form to control which cookie groups the user want to enable. That’s why the dfactory Cookie Notice plugin is not compaint with our national law.

    Because of this last point, controlling cookie loading on code level also important for every plugins.

    • This reply was modified 4 years, 2 months ago by DJviolin.
    • This reply was modified 4 years, 2 months ago by DJviolin.

    Hello. I would also be interested in the shortcode you mentioned. Is it anywhere in the documentation?

    Plugin Author gioni

    (@gioni)

    @pauljbis It will be implemented in the next version soon.

    Plugin Author gioni

    (@gioni)

    The cookies shortcode has been implemented: https://wpcerber.com/wp-cerber-security-8-6-8/

    Thread Starter DJviolin

    (@djviolin)

    Thank You for the implementation! Greatly welcomed!

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘Have a clear documentation about WP Cerber’s cookies and their purpose’ is closed to new replies.