Now people say "oh but if every website hosts their own fonts the browser can't cache them" while sending me 35 megs of shitty tracking Javascript code.
There is a very clear aggressor here and it's not the EU or the regulators.
[1] https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
[2] https://github.com/w3c/webappsec-subresource-integrity/issue...
[3] https://hillbrad.github.io/sri-addressable-caching/sri-addre...
But it's not "everyone" - it's you. Your computer sends out all the information that is requested from it. That's how the internet is built. Even when a website tries to use an external font it is still your browser that asks the font host for the font.
It seems you either missed the point of what the post was getting at, or you are being purposefully obtuse about it.
I agree that it would be nicer if websites slurped up less data. But to portray a lot of this stuff as the user being the victim is ridiculous. The users are the ones that voluntarily started using browsers made by an adtech companies. There are alternatives but they don't use them! And yet they complain that their data then ends up with the adtech company because their browser, that is under their control, sends it to the company.
Of course, the web browser should do something about it... but the adtech company built that too. "That's how the internet is built" is an aggressively dismissive attitude, because there are specific companies building the Internet. Note that every new trash web standard is written by... oh, yeah, Google too.
Sidebar: I block Google Fonts. You should too.
If this was a clickable link to Google, and the EU was saying that telling people to go to Google makes you a GDPR data exporter, then I'd be up in arms about this.
But it's not.
What we're talking about are subresource references, not anchor links. Those get loaded automatically without user control, and users do not get the ability to audit them by default. So it's reasonable to argue that subresource requests are "caused" by the developer of the website, not the user.
Furthermore, this is how actual ad trackers work. It's very common for ad trackers to include a reference to either a script file or a 1x1 pixel GIF (the latter called a "tracking pixel"). This isn't a misinterpretation of GDPR, it's the heart of the issue. If we treat subresources the same as clicking a link, then GDPR is a hollow, toothless meme of a law.
Then make one that does. Or demand for one. But everybody wants to use Chrome and then they're surprised that their browser doesn't give them the control they want.
The whole point is that Google gets your data because you send it to them. Your browser and computer are under your control.
It's no wonder Apple thrives while taking away control from the user. Because when we do have control we just don't use it.
>Those get loaded automatically without user control, and users do not get the ability to audit them by default. So it's reasonable to argue that subresource requests are "caused" by the developer of the website, not the user.
It would only be reasonable to argue this if you think your computer/browser/os is not under your control. NoScript has been a thing for a long time. How many people actually use it?
The same concerns apply to NoScript and that browser extension the FSF has that bans non-Free JavaScript. If you point them at GDocs, you don't magically get a tracker-free, Free Software word processor. You just get a broken web page. The reason why users don't exercise this control is because they don't have it to begin with. It's not their webpage to modify.
On a more meta-level, you're arguing for technical controls & DRM where legal ones are needed. We don't want browsers where users can pick and choose where their data goes, but if they choose wrong and don't enable enough trackers they don't get the website they wanted. We want websites that don't have trackers on them to begin with.
The problem was the legal framework to enforce it didn't exist so the industry was just using it as a suggestion. The EFF's voluntary declaration didn't help either.
I think if it had been enforced in the style of GDPR it would have been a great thing to have.
https://andydavies.me/blog/2018/09/06/safari-caching-and-3rd...
https://www.zdnet.com/article/chromes-new-cache-partitioning...
https://arstechnica.com/gadgets/2020/12/firefox-v85-will-imp...
Then the consent question would actually be presented in a balanced way. And the preference could be stored even if you wipe cookies. At moment if you distrust cookies, your preferences expressing your distrust of cookies is constantly being reset forcing you be re-prompted again and again.
(It might be harder for regulation to require changes in browser though, and then there's legacy browsers, so I can see how we ended up here)
And legal precedence wise, laws have been requiring things of websites for a long time, but I can't think of any legislation that has required certain behavior by browser applications themselves. Since browsers, in theory, just implement open web standards, requiring something of them is effectively legislating a forced change into web standards. That's a spooky thought.
But let's be real... having individual websites ask for cookie and 3rd party request consent makes opt-out massively less popular than if this was built into the browser. If the "disable ad-targeting cookies" button wasn't hidden behind obtuse UI bespoke to each site, far far more people would opt out of them. I suspect that's a big reason why we got to this arrangement.
The browser has no way of knowing what kind of tracking is going to happen on the server it's connecting to or what jurisdiction that data would fall under.
If trackers would provide metadata indicating what kind of tracking each resource is going to do, then browsers could handle it, but trackers would never do that without being forced because they want to make opting out of tracking as painful as possible.
https://developers.google.com/fonts/faq#what_does_using_the_...
They don't say how long the raw data is kept either, on a page trying to minimize the tracking, so we can probably assume it's longer than necessary for technical purposes.
They keep it separate from their other tracking, but that's still collecting user data.
No.
The fact that you linked that page makes it seem like you agree that a CDN could collect user data.
So what would it look like to meet that bar, by your reckoning?
This is an extremely disingenuous way to phrase it. It's deliberately not hosted on a domain which would have any session information sent. There's no tacking information set by that service. I invite you to actually look at a call to this service (you'll want to Google "browser developer tools", that should get you started) and realize that there is no user data in the request. Because of course there isn't.
>...makes it seem like you agree...
Ah, the classic tactic of standing up a weak strawman and then arguing against that. Good to see you again, nemesis.
It's not disingenuous because I was going by what those terms allow. They say nothing about detail level, so when I talk about whether they could be tracking you I will talk about the worst thing those rules allow.
> It's deliberately not hosted on a domain which would have any session information sent.
Being a separate service from the rest of google is an entirely different question from whether it tracks you. And tracking doesn't need session cookies.
> There's no tacking information set by that service. I invite you to actually look at a call to this service (you'll want to Google "browser developer tools", that should get you started) and realize that there is no user data in the request.
That doesn't stop them from fingerprinting me to a moderate extent and storing that with my IP and exact time forever.
> Ah, the classic tactic of standing up a weak strawman and then arguing against that. Good to see you again, nemesis.
It's not a strawman. Strawmen don't say "makes it seem". That's my doing my best to figure out your opinion, so that I can effectively respond to it, and making it very clear that I'm guessing.
So are you saying that guess was wrong, or are you being vague on purpose here?
In terms of strawman and related, my guess would actually fall under "steelman". Assuming the opposite would have been a strawman. Because if my guess was wrong, and you don't think it's possible for a CDN to collect user data, then why did you make this conversation be about a specific CDN in the first place?
> if my guess was wrong...
As I have previously said, you're totally wrong and your misunderstanding is so far from what I said that it's hard to understand how you got there. You asked if CDNs that don't track user data needed to worry, I gave an example of one which doesn't track user data and still got into trouble.
That's not disingenuous. You disagree with me about what counts as "details to log". Nobody is acting in bad faith.
> As I have previously said, you're totally wrong and your misunderstanding is so far from what I said that it's hard to understand how you got there.
I made a post talking about the difference between a "CDN that tracks people" and a "CDN that doesn't track people".
You responded by linking a specific CDN as an example of a "CDN that doesn't track people".
So I guessed that you agreed that "CDN that tracks people" and "CDN that doesn't track people" are both things that exist.
Why is that guess "so far from what you said that it's hard to understand"?
You're saying you don't think that, so why didn't you just say "No CDNs can track people"?
If every CDN is a "CDN that doesn't track people", then what use is it to link the terms of a specific CDN? If no CDNs can track people, then it doesn't matter what their terms say!
-
But as to your argument, I think your definition of tracking is too narrow, but I don't see any way to convince you otherwise so I'm not going to attempt that.
(Then there is a separate issue with a human rights dispute between EU and US that makes things a bit more complicated)
> You either have to host everything yourself, or ask the user for consent first.
As a user, I am very very glad that this is the case.Politics dont understand the web but noticed its dengerous if left unregulated.
And EU tax avoidance is mainly done through Ireland and the Netherlands which are still member states.
You are also confusing legislation with rulings. GDPR says your business interests cannot outweigh my rights. That's it. Now courts find that leaking my IP address to third countries is something that harms me more than it does your business good. I can live with that.
Anyone with half a brain and a real intent to reduce tracking would have mandated websites abide by the existing Do not Track toggle. Unfortunately the law was instead introduced by politicians with strong lobbying from media industry. So no brain, and no intent to reduce tracking.
If the law was instead “no non-essential cookies may be stored when the do not track flag is set”, consumers would be far better off. But that’d cause significant financial impact to the media companies that lobbied for the current wording, so now the whole world is screwed.
Yes, and the result of that nuance is less privacy and more annoyance. It's an open invitation for sites to use dark patterns to get you to "agree" to tracking. (In fact they "have" to use dark patterns because they specifically aren't allowed to offer you anything in exchange). Either banning tracking outright or requiring sites to obey the DNT header would make much more sense.
Your browser opens the connection to the original website and downloads the base page. That base page references images and js and fonts hosted elsewhere, so your browser opens a connection to download those images. At this point the browser could pop open a dialogue box that says "Hey you said you wanted to communicate with foo.com but I need to grab a pic from bar.com is that cool?"
At no point in this use case does foo.com send anything to bar.com
IE 6 in the default configuration did something like that with its yellow bar, IIRC, and all it amounted to was the fastest known method (minutes, for me) to provoke warning fatigue and make people vulnerable, seeing as the same UI was used for installing ActiveX controls.
(Could be it did that all additional resources, though, not just those from a different origin? I don’t remember since I disabled the whole thing near-immediately even when I did actually use IE 6.)
This is unworkable from a usability perspective for as long as hotlinking to external resources is so commonplace. And a user permission might not be an effective way to do this, anyway, given the imbalance in bargaining power, as already seen with adblocker-blockers and such. (See also the 2006 paper, “A pact with the devil”[1].)