What we know about you when you click on this article
vox.com
vox.com
Tracking pixels are incapable of such feats. At best they have your IP address from the latest visit, and information about your behavior on that site. I don’t see how they can magically conjure information you haven’t provided.
If you don't provide that data, they can guess based on browsing history (e.g. if you look up baby products, you're likely in the 20-30 age range). They can use AI to see how your online behavior matches up with other people in a known demographic. All of that data paints a surprisingly clear picture, even if you don't create an account (e.g. browsing data by IP is likely from the same person/family).
But I'm really curious here, because I'm an applications developer and sort of in the dark about a lot of web technology. If I wanted to create a website that just absorbs the kind of information you're alleged is possible, how precisely is that done? How do I access the user's browsing history that you claim is possible? Is there a tutorial on this hand-waving AI-magic? Even if I had somehow acquired a mega database of granular user data, how do I key in on the random-user-that-just-loaded-my-page?
Sorry if I being incredulous. It's because I am.
Like egdod said at the bottom of this comment thread, downvoted into oblivion: "Javascript is a cancer and should be disabled whenever possible."
If a page is blank, or just says "this app needs javascript to run", then it's insta-close: so not only am I not running javascript, I get a productivity boost too!
Edited to remove reddit comparison.
That’s about as helpful as saying the best way to avoid being tracked is by not using the web.
So, since you say disabling JS is infeasible.. to what extent? What websites work with JS disabled, what might I miss out on? Is it possible to compromise, perhaps a browser can be configured to whitelist certain JS APIs? Perhaps we create a JS-lite standard? I don't know. Let's talk about it though.
I like that kind of discussion. It is worth noting that I have always had JS enabled, but I would like to hear the opinions and perspectives of everyone.
If you don’t accept JS, nothing renders.
'superkuh could very well have been downvoted for commenting on downvotes contrary to the guidelines, rather than for anything about the other content (which otherwise looks fine).
> Please don't comment about the voting on comments. It never does any good, and it makes boring reading.
https://news.ycombinator.com/newsguidelines.html
The guideline is there specifically to prevent threads like this, devolving into meta discussion rather than focussing on the submission. Post constructive comments, (silently) give compensatory upvotes to those you think are wrongly downvoted, and move along.
It just becomes frustrating to see this pattern of behavior and how pronounced it has become. I frequently disagree with comments but they often generate good discussion. This is how we all get smarter. Instead, the potential is deterred by downvotes.
Many of us have family members fighting cancer, and there are cancer patients and survivors reading HN. I don't think a casual statement equating that terrible disease with a mere programming language is appropriate here or in any public forum.
By way of contrast, I would have upvoted a comment like this:
I avoid JavaScript whenever I can. I feel safer that way. I use FooBlock Organic to selectively whitelist JavaScript for sites that need it and that I trust. I recognize the irony of using a browser extension which is itself written in JavaScript, but it's open source and I've reviewed the source code carefully. I even contributed some patches to make it easier to use.
It would be nice if at least, the only way to be able to downvote, would be to also post (require) a comment.
I don't know, 80% of the web I'm interested in is text - like your comment - images and video. None of them require JS. Websites need JS more than I do, it seems.
My experience as a noscript user of several years is that the time I lose to one-time delays as I mark some domains trusted is vastly outweighed by the time I save avoiding repeated distended pageload times from sites suffering from multi-domain js bloat.
Usually, about 75-85% of js domains for a given page are delivering some peripheral service like tracking, advertising, or analytics, in my experience, and loading all these unessentials can represent significant performance loss as well as other detriments.
Yes, it is. I try to never use my bank card and always pay for things (even big purchases) in cash. For online stuff I try to use Bitcoin as much as possible.
Obvious in hindsight, but the profile picture is probably a goldmine for targeted advertising. Not sure if anybody does that but using that for age estimation would probably be way more accurate than the guesses I’ve seen implicitly (lots of ads like “people in <age group> love this product”) and explicitly.
In the long run, I think this might be the future, to have a server to render websites into a readable format for you.
https://webbrowsertools.com/privacy-test/ https://panopticlick.eff.org/ https://tenta.com/test/ https://dnsleaktest.com/
This page has lots good info on this topic. https://browserleaks.com/
I'd love to examine this. Podcasts for example, have almost none of this tracking (as enforced by Apple) and no pay wall. And frankly, since journalism costs pretty much however much you're paying your staff I'd love to see the argument for how much the CEO of vox gets paid when compared to the cumulative loss of privacy and self-determination that their readers have suffered.
Server-side JS is, well, just an inferior choice IMHO. But that's down to taste or the task at hand. But server-side it sure is no cancer.