Show HN: How privacy-friendly is your site?
webbkoll.dataskydd.net
webbkoll.dataskydd.net
As I wrote elsewhere in the comments we're planning to redesign the results page and rewrite all the text later this year. The current page hasn't changed much since mid-2016. Need to refresh/expand technical advice, be more clear about the limitations of the service, etc. I'll note down all suggestions here.
I'd also like recommend a similar project that was inspired by Webbkoll: https://privacyscore.org/ -- it's slower, but also integrates things like testssl.sh, and most importantly lets you make lists of URLs to check. It uses OpenWPM [0] which has been used for many interesting studies,[1] such as "Online Tracking: A 1-million-site Measurement and Analysis".[2] (Webbkoll uses Phoenix+Puppeteer)
[0] https://github.com/citp/OpenWPM
[1] https://webtransparency.cs.princeton.edu/webcensus/index.htm...
Will definitely be doing a few updates this week.
155 Cookies, 319 Third-party requests, 125 Third-parties contacted
Beat it if you can :)
Not a clear win, but also "impressive."
136 cookies, 846 third-party requests, 159 third-parties contacted
113 Cookies, 491 Third-party requests, 121 Third-parties
Total: 725
Using the header form will be more efficient on HTTP/2 due to HPACK reducing it to roughly one byte.
Using the meta tag is typically easier to deploy.
https://webbkoll.dataskydd.net/en/results?url=http%3A%2F%2Fj...
Pretty happy with the results. I have to have access to referrer headers for it to work.
Beyond that, there are some things I can tighten up in regards to some other xss headers so I’ll take care of those.
Also, I don’t keep traffic logs. Sometimes (maybe a couple times a year) I will do a small log capture for a few minutes if I need data to test an upgrade or feature experiment but that’s it.
This information is at odds with Microsoft’s own status on the feature (https://developer.microsoft.com/en-us/microsoft-edge/platfor...) which indicates that Edge does not yet support it (“in development”), and the cited source http://caniuse.com/referrer-policy which also says IE and Edge don’t support it, but that they do support an older, more restricted version of the spec.
<meta name="referrer" content="never">
Should also note that it's possible to have fallback values (https://www.w3.org/TR/referrer-policy/#unknown-policy-values).It's minor, but you could add Apache and/or Nginx and/or Lighttpd examples for many of the recommendations.
For a government website you could argue that there should be no third parties using the information about the visitor's interaction with the government. But a lot of government websites still use 3rd party scripts that specifically use information about your for ad targeting.
Your site is very informative, and easy even for a non-webdev like me to grasp.
https://webbkoll.dataskydd.net/en/results?url=http%3A%2F%2Fs...
Kudos to the authors, thank you for helping making the web a better place.
> The site is loading libraries from one or more CDN:s. Self-host the files.
Is it on the ground that browsing pattern can be leaked via http referrer?
While I don't doubt dataskydd's good intentions, their advice about referrers is a sign that we live in Clown World.
Yes, your browser's tendency to provide a referrer might well give away information you would prefer it didn't. Unfortunately for you, the browser vendors have chosen to provide browsers that do that.
In a parallel universe it would be obvious that this is a problem (among many) for the browser vendors to address. In Clown World, you are supposed to rely on each and every site providing a special response header.
"Note: Because the source of a link may be private information or may reveal an otherwise private information source, it is strongly recommended that the user be able to select whether or not the Referer field is sent. For example, a browser client could have a toggle switch for browsing openly/anonymously, which would respectively enable/disable the sending of Referer and From information."
(https://tools.ietf.org/html/rfc1945#section-10.13)
This recommendation was not followed in any meaningful way, but Referrer Policy (https://www.w3.org/TR/referrer-policy/), which supports a whole bunch of different policies and is very easy to implement (and now widely supported), at least makes things slightly better.
I'm guessing the reason others are downvoting you is that Referer Policy is exactly that: it's the attempt of modern browsers to address this problem (a problem that yes, they did create, but the fact they're supporting Referer Policy at all at least shows that the problem was created out of incompetence rather than malice).
> Invalid domain: http://http//www.coruscade.com
Either change the placeholder or, preferably, detect whether the user’s input contains http:// and adjust accordingly.
Needs work.