Discussion if Google Fonts is GDPR compliant
github.com
github.com
For the popular fonts, a user probably already has them in their browser cache from other sites, so they load instantly.
Having sites redundantly host identical font files separately is a step backwards for users, who wind up waiting longer for a page to load, or experiencing the jarring FOUT (Flash Of Unstyled Text).
Or you could just use a selection of common system fonts, and not host any fonts at all.
This is thrown around a lot, but very rarely with hard numbers to support it. A cold DNS cache costs at least one roundtrip, a cold SSL session cache costs several, a new SSL connection (presently) costs at least 2.
Meanwhile, all the above is necessary to talk to an origin site anyway, and networking performance for the best part of 10 years has been dominated by latency (i.e. roundtrips) rather than throughput.
Hoping the user had an idle connection to the Google CDN when measuring cold request start is wishful thinking
Meanwhile self-hosted reuses all of the above and enables assets to be combined into a single transaction, which vastly improves the behaviour of TCP cold start
Skip to "Here is a comparison of hosting Open Sans locally vs Google CDN."
They found it was faster to use a Google CDN. One of the things this article suspects is that CDNs will have better world-wide coverage, and therefore overall latency, than hosting your font yourself.
I'd like to see a comprehensive study of your counter point, though.
If setup time is amortized across all assets on a site, as it is when self-hosted, the true cost of the 220KiB font download will be vastly lower -- closer to 100ms assuming a sufficiently warm TCP connection over even an 8Mbit link, and significantly less again with faster links.
As for browser-side caching, this is once again wishful thinking and there is no room for it in any kind of engineering discipline
Both of these are still a lot slower than simply installing the font in the OS (or browser) and loading out of the filesystem block cache (or using the already-loaded font in browser memory). Open Sans is Apache License 2.0, so it should be easy for browsers/OS to provide it as a standard font instead of merely the "web safe" set of fonts.
Do we trust the server we're connecting to with their own TLS certificate revocation status? DNS? What about all hops along my network path? Email headers?
I doubt this was the intent. Using the Internet is inherently public. Privacy is hard and needs a clear separation / promise to the user. With that, Governments should have an awareness campaign so people know when they visit their bank website that they may be accessing third parties for fonts and tracking and that only their financial information is private.
I've not met 1 company who met all aspects of this law.
I'd guess this also means that any asset in a 3rd party CDN would be non compliant with gdpr
What about all the networks between you and Amazon?
The GDPR is Working as Intended.
Ironically the foreign big ones have enough resources to comply to the law, small local ones don't and will die/never be created in the first place.
> the regulating authorities can pick whoever they want to prosecute
It doesn't really work that way, at least not in germany, anyone can just sue (or threaten to sue) their competition over this (they already started) there is no such thing as this mythical benevolent authority who could stop this wanton destruction you are talking about.
This is wrong. Competitors (and only competitors) can send a cease-and-desist letter based on competition law, because ignoring GDPR gives an unfair advantage - even that only in Germany because the tool used here ("Abmahnungen") are a unique german thing.
They are also a common thing between companies that don't "like" each other and if you send one you can expect to get one back. Receiving one costs ~1000 € (goes to the opposing lawyer) so they don't hurt much and the only one profiting is the lawyer.
> the only one profiting is the lawyer
how would I not profit from my competition having to pay money, I don't care if I get the money.
Yep, that's what I've been saying all along, but people don't seem to understand.
The real cost of regulation isn't the cost of non-compliance and the punitive measures that follow. It is the cost of compliance, reporting, addressing an endless stream of complaints and requests for information.
Large companies have the resources to handle that, small ones don't.
This is the world we live in. When the market fails to protect users, eventually there might actually be consequences.
So constructively, how do we solve this CDN problem while causing the least harm to both businesses and users? Perhaps identify assets by cryptographic signature rather than URL?
npr.org went back from WWW to what feels like WAP for those not giving consent.
Of course, if you're someone who profits off of abusing users, you may see the GDPR as wholly negative.
Because users were faced with a raw deal, now we have regulation.
Regardless, I don't think it's clear that the benefits of the market being left to itself haven't outweighed the costs. My snap judgment (which isn't that useful when assessing massively complex topics like this) is that the benefits dwarf the costs.
Much of the internet services that have emerged over the last 20 years have been paid for by personal information that users have traded away in exchange for these services. Everything from Gmail, to Google searches, to Facebook, to millions of Youtube videos, to the vast amounts of self-help content one can find about any topic, is ad-funded, which depends in large part on this exchange of personal information for web services.
The problem is people are taking all of these services available on the web for granted, and recklessly assuming we would have all of them without the ability to target ads using collected PII, and with the added burden of complying with the onerous GDPR requirements.
People who are struggling to get by are not going to have the time, energy, or expertise to comparison shop. And when their identities get stolen because their personal information was leaked by a provider, they're just going to get crushed.
Those proposals of yours didn't happen for a reason: they are not in the interest of the capitalist class, and the way modern markets are set up, capitalists have way more power than other individual citizens.
Denied effective means of organizing to protect themselves from exploitation and abuse, is it any wonder that when the masses vote for politicians advocating regulation?
Find a variant of market Libertarianism where the majority of the population can actually defend their rights rather than get steamrolled and you'll see less regulation.
The cost to innovation is too steep a price for the additional safety gained. As it is, we don't live in a safe world either way. We are constantly struggling against the forces of uncertainty.
It is only through innovation that we better enable ourselves to contend with these forces.
Look at all of the web innovation that has arisen over the last two decades. It's given us a significant boost in our ability to manage the world around us.
Restrictive regimes like GDPR inhibit the free flow of action that generates innovation. It's bad bargain.
>>Those proposals of yours didn't happen for a reason: they are not in the interest of the capitalist class, and the way modern markets are set up, capitalists have way more power than other individual citizens.
I don't agree with your classist categorizations, but let's just say there is a powerful special interest that stands in the way of a given political solution.
I'd argue that any effective solution would need to be implemented over the lobbying and resistance of one or more of said powerful special interest groups.
If a political solution didn't need to be implemented over the objections of one of these groups, then I'd argue that it's almost certainly not effective, for one or more reasons.
So I'd say it's better to not implement a political change, if the ideal solution is not viable.
Worst case, assume they are actually correlating this for ad tracking: you might get more relevant ads instead of generic junk that you have no interest in. That's actually the opposite of abuse.
Someone that knows more on how this work can you answer if Google can see more then your IP? like user agent or cookies ?
So yes, cookies, but the ones for the domain where the fonts are hosted, not the one you are visiting. Not sure about the referrer. User agent for sure.
The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems, […] by providers of electronic communications networks and services and by providers of security technologies and services, constitutes a legitimate interest of the data controller concerned.
Did you read this and it was not enough for you, Btw is DDOS and not DOS attacks (in case it was not a typo)
It is in Google's best interest to sneakily track people despite claiming not doing so, and they can be very good at it and do in a way that's undetectable from the outside. In fact, I would be surprised if they're not doing this already.
Are you saying Google has crossed the line into social intelligence territory like china has?
Is there evidence for this, beyond "google is bad!!1!" ?
(Notes wifi is "off")
(Notes GPS is "off")
(Notes Location sharing somehow got turned on)
Hey, we need your help! How was $eatery_you_ate_at_last_night ?Can you give us direction how busy the $Business_you_parked_nearby is?
And, this https://www.google.com/maps/timeline?hl=en&authuser=0&pb
Google shouldn't even be collecting this. But they are. We know not how they use it. But if you have the data, of course you're using it!
In the current form the title "Google Fonts not GDPR compliant" is just FUD, as the argument "Google Font is ok because Google LLC is certified under the EU-U.S. Privacy Shield frameworks" holds some water imho.
I think it's a very valuable post but I agree the title needs fixing.
In a nutshell, if I buy VPN access to a European GDPR compliant provider, do I get the rights listed in the GDPR?
The original title was however not FUD: Some Web site owners in Germany have received legal warnings for their use of Google Fonts which was considered as not GDPR compliant ( https://translate.google.com/translate?hl=en&sl=de&u=https:/... .)
While I wish that were the case, the Privacy Shield framework only legitimizes the cross-border transfer of the data. It doesn't have any bearing at all on the need for notice to users, contractual relationship with them as a processor/sub-processor, or the compliance of Google's use of that personal data once the cross-border transfer has occurred.
The same question for using random-js-library from googleapis.com: You're trying to tell me that giving Google (and anyone who somewhere between me and them takes control of that domain) full arbitrary code execution privileges within your origin is worth saving a one-off download of some JS library? I don't think so.
The same can be used with all other "subresources" like stylesheets and fonts! However Google specifically makes this hard as they have been known to update the served font from time to time, which if you are using SRI will break the font entirely.
That's true, but SRI is still rarely deployed; and no surprise there: the official Google docs don't use SRI in their "paste this into your code" examples: https://developers.google.com/speed/libraries/
Also, Edge still doesn't support SRI.
So, yes, for some UAs this specific problem (resource integrity) is a solved problem, but like I said, it's far from the default.
The other issues - lack of necessity, load time, degraded visual quality, giving user data away for free to an advertiser etc. - remain untouched.
But to be completely honest, lack of user agent support shouldn't be a reason to not use a feature. Edge doesn't support it, so Edge users are less secure. There are also user agents that have CORS restrictions disabled or don't support HSTS, but i'm still going to use and rely on both of those for security.
And it sounds like you and I disagree completely on the usefulness of fonts. For me a font isn't "unnecessary" any more than paint isn't necessary on a house. Sure, you could live in a house without paint, but I want paint on my house. As for longer load times, and degraded visual quality. The previous is being dealt with via new font-display css descriptor, and in browsers that don't support that they have timeouts of normally 3 seconds at most, and the former is an opinion that I absolutely don't share.