Now people say "oh but if every website hosts their own fonts the browser can't cache them" while sending me 35 megs of shitty tracking Javascript code.
There is a very clear aggressor here and it's not the EU or the regulators.
Now people say "oh but if every website hosts their own fonts the browser can't cache them" while sending me 35 megs of shitty tracking Javascript code.
There is a very clear aggressor here and it's not the EU or the regulators.
https://andydavies.me/blog/2018/09/06/safari-caching-and-3rd...
https://www.zdnet.com/article/chromes-new-cache-partitioning...
https://arstechnica.com/gadgets/2020/12/firefox-v85-will-imp...
[1] https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
[2] https://github.com/w3c/webappsec-subresource-integrity/issue...
[3] https://hillbrad.github.io/sri-addressable-caching/sri-addre...
But it's not "everyone" - it's you. Your computer sends out all the information that is requested from it. That's how the internet is built. Even when a website tries to use an external font it is still your browser that asks the font host for the font.
It seems you either missed the point of what the post was getting at, or you are being purposefully obtuse about it.
I agree that it would be nicer if websites slurped up less data. But to portray a lot of this stuff as the user being the victim is ridiculous. The users are the ones that voluntarily started using browsers made by an adtech companies. There are alternatives but they don't use them! And yet they complain that their data then ends up with the adtech company because their browser, that is under their control, sends it to the company.
Of course, the web browser should do something about it... but the adtech company built that too. "That's how the internet is built" is an aggressively dismissive attitude, because there are specific companies building the Internet. Note that every new trash web standard is written by... oh, yeah, Google too.
Sidebar: I block Google Fonts. You should too.
If this was a clickable link to Google, and the EU was saying that telling people to go to Google makes you a GDPR data exporter, then I'd be up in arms about this.
But it's not.
What we're talking about are subresource references, not anchor links. Those get loaded automatically without user control, and users do not get the ability to audit them by default. So it's reasonable to argue that subresource requests are "caused" by the developer of the website, not the user.
Furthermore, this is how actual ad trackers work. It's very common for ad trackers to include a reference to either a script file or a 1x1 pixel GIF (the latter called a "tracking pixel"). This isn't a misinterpretation of GDPR, it's the heart of the issue. If we treat subresources the same as clicking a link, then GDPR is a hollow, toothless meme of a law.
Then make one that does. Or demand for one. But everybody wants to use Chrome and then they're surprised that their browser doesn't give them the control they want.
The whole point is that Google gets your data because you send it to them. Your browser and computer are under your control.
It's no wonder Apple thrives while taking away control from the user. Because when we do have control we just don't use it.
>Those get loaded automatically without user control, and users do not get the ability to audit them by default. So it's reasonable to argue that subresource requests are "caused" by the developer of the website, not the user.
It would only be reasonable to argue this if you think your computer/browser/os is not under your control. NoScript has been a thing for a long time. How many people actually use it?
The same concerns apply to NoScript and that browser extension the FSF has that bans non-Free JavaScript. If you point them at GDocs, you don't magically get a tracker-free, Free Software word processor. You just get a broken web page. The reason why users don't exercise this control is because they don't have it to begin with. It's not their webpage to modify.
On a more meta-level, you're arguing for technical controls & DRM where legal ones are needed. We don't want browsers where users can pick and choose where their data goes, but if they choose wrong and don't enable enough trackers they don't get the website they wanted. We want websites that don't have trackers on them to begin with.
The problem was the legal framework to enforce it didn't exist so the industry was just using it as a suggestion. The EFF's voluntary declaration didn't help either.
I think if it had been enforced in the style of GDPR it would have been a great thing to have.