Bunny fonts – privacy respecting drop-in replacement for Google Fonts
fonts.bunny.net
fonts.bunny.net
If you embed a font hosted somewhere else you expose some of your user data to them. Now with fonts there's a really simple solution: Just don't. As an added bonus, hosting fonts on your own server is faster as it goes through the same HTTP connection.
There are situations where you can't completely avoid privacy issues, and then you can try to do better than others. But if you can completely get rid of a privacy issue then obviously that's what you should do.
I never quite understood the debate around fonts. You could use the CSS/Link import that Google provides, but that's never the optimal solution. Like you I always download the fonts and use them directly via @font-face.
The only advantage I see to using Google Fonts / some privacy respecting font service like this one, is when you are first prototyping an app and want to either test fonts, or want to move quickly and not worry about setting up fonts properly. We also used in a places like Storybook where having correctly set fonts is not as important.
But even if you did use it in prototyping, it's best practice to pull down those fonts and store them locally before going to production (at least in my mind).
Am I missing something?
For reasons I am sure I will never fathom, browsers on mobile provide all the same settings options, and religiously ignore them.
Nowadays, what I do (and recommend to others) is to set Firefox to never send a referer cross-origin, so google fonts and similar don't get to see what website I'm on. I've found that very few websites break with this.
While it's not svg or on the open web, I have a particular hate for sborn.jpeg in ebooks, as I read my ebooks in dark mode at night and having occasional section break symbols (ornaments) white on black is particularly irritating. Other unnecessary images often found in ebooks include bullets, chapter titles flourishes, letters with accents, and even the chapter title itself.
The best solution here is to use standard fonts that are available in all browsers, of course.
Privacy killed the shared cache.
Yes, just serving up your own fonts is better, but this is an improvement that seems to work with only a minor change.
https://www.reuters.com/article/us-alphabet-google-privacy-l...
Yet, Google initially implemented a malicious consent form where accepting is easy and declining is impossible. They only very recently implemented a compliant consent flow which gives you an easy option to decline.
Google has already proven their bad faith and successfully got away with it, along with plenty of other companies.
But with HTTP2+, serving from your own domain has no performance impact unless you're limited by bandwidth or extreme latency, and often can improve things by avoiding another DNS/TLS/TCP connection.
I've been down this road. I don't know what it is, but many web developers are extremely adverse to doing it. Even once you've convinced people to let you do it, the first PR from a new hire is a fix for this "bug".
not sure how it's relevant here though
As I understood the answer, the expanded version would be "the only disadvantage is having to spend an unreasonable amount of time arguing about this issue, which will drag on forever since it is relatively minor."
Years ago, when I worked at MSP serving quite a big federal customer... We received a ticket what $companysite.tld isn't working. Pretty unusual, but the first things first, so I just type $companysite.tld in the browser. It works fine.
Okay, ignore then.
But, no, 15 minutes later we receive an email with a tons of people in CC and a lot of !!!!s in the subject and body what the site is still down.
I again check it from my machine (which of course was in the MSP office, not on customer premises), it works fine, DNS, tracert, yada-yada.
Our network team replies what $companysite.tld responds to ping so everything works fine from their POV. Duuuh.
Okay, I hop to the management station located in the customer's DC, test the site there... and it doesn't work there. Just a blank screen, no errors, nothing. Which is pretty strange because the site is hosted in the same DC. DNS resolves to the proper records, ICMP works including traceroute...
Well, long story short, after 30 minutes of head scratching and dozens of emails with ever longer list of people in CC it occurs to me to hit F12.
I open the developer console, switch to Network tab, type in $companysite.tld and I see what the traffic is starting to flow just fine, only to stall to a halt at... googlefonts.com (or whatever TLD they used).
At this point I just calmly sent an email explaining what the site was working just fine, it just wasn't able to properly load from the customer premises because of the block of Google services.
To summarize:
somebody from the customer ordered to block Google services on the network level (don't even ask);
network team (certified Cisco CC** folks!) implemented it by dropping traffic instead of denying - so the firewall would notify the client station about that and the browser would abort the request to googlefonts.com and wouldn't wait a full timeout for each request (don't forget DNS records resolved just fine, if they sent NXDOMAIN for it there wouldn't habe been even an attempt to connect);
network team diagnoses the availability of the web-sites by using ICMP ping... but that wasn't the first or the last time when I was quite... disappointed of their qualification.
While it is very rare for major CDNs to go down, it happens, and even more shenanigans can happen on a network level between some client and your website (and proliferation of DPI by various countries, agencies and enterprises doesn't help here too).
So if you are on the payroll just host the fonts (and honestly - all assets, if applicable) with the web-site and sleep soundly. Of course if you are paid for each "incident", then Web3.0 is all yours. *grin*
any decent browser, i mostly use firefox, have a checkbox in the font screen that prevents sites from changing the page font.
i set all sites to user Ubuntu Mono. always. all the time. everywhere.
the only downside are sites that use winding-like fontawesome. you will get "S" instead of the magnifyingglass icon... i got used to things like that. Google meet screen is particularly weird. meh.
but after you are past the initial shock, having the same font everywhere is the ideal usability hack. faster reading. less distraction. it's perfect.
and as a bonus i don't even care (as i block referrer headers xdomain), not a single request ever goes to googlefont and the likes.
eg: https://opendyslexic.org / https://github.com/antijingoist/opendyslexic
Ubuntu Mono coverage is only 1200 glyphs as per its website, that's very very few.
If I self-host my fonts, the people I have to trust are only those people I have no choice but to trust: those who get my site into the user's browser. Every additional cross-domain request I add is an extra party I have to trust.
$ whois bunny.net (...) Registrant Name: Registration Private Registrant Organization: Domains By Proxy, LLC Registrant Street: DomainsByProxy.com Registrant Street: 2155 E Warner Rd Registrant City: Tempe Registrant State/Province: Arizona Registrant Postal Code: 85284 Registrant Country: US (...)
> we're in a country with better privacy laws"
...it appears that the domain registrant is not, so you will just have to trust that the company is not in the US or not owned by a US entity (mostly relevant for the rest of the world, probably).
> with fonts there's a really simple solution: Just don't
This was worth repeating :)
This isn't an advertisement, I had a very specific use-case, but it follows into this:
Of course, just like with Google, we are the product here. Google Fonts is an analytics data collection platform, Bunny Fonts is an advertisement for their CDN services.
I'm going to stick with a /fonts/ directory, I think, despite being one of their current users. It's really not very much bandwidth for the fonts, it's not 2010 anymore, and I prefer the control (and the local development environment being the same, I don't always have internet and I don't want a dev toggle for something as silly as fonts).
Their web-site is located in the UK[0]
Their fonts CDN is originating from AS60068 which is registered in UK too[1][2]
[0] https://bgp.he.net/dns/bunny.net#_ipinfo
Now since they are no longer in the EU they want to use this opportunity to deviate from the GDPR and relax the rules even more (not that they've been enforced to begin with). Ironically, the justification for relaxing the rules is that the GDPR didn't have the expected effects - well of course if won't have any effect if you don't enforce it.
Well, this is what all the fuss is about: respecting the law. I'm not saying the laws are good or bad, just that it is the only thing that most companies really care about.
Anyone who is a bunny.net customer would have an idea. Unlike many of the myriad wesbites using Google fonts, they would also have an agreement with Bunny they could potentially enforce.
Anyone doing internet research who peruses publicly available scans of DNS ports in the last five years would likely be familiar with bunny.net as they are a large enough CDN to have many thousands of subdomains for customer IPs. It is seemingly impossible to miss this company's presence toward the beginning of the scan.
The founder of bunny.net recently posted a question in an nginx forum. This is not AWS or Google. Amazon sells goods. Google sells online advertising services. Both are primarily intermediaries (middlemen) who try to prioritise their own competing goods/services. All the data those companies collect may feed into other business that strives to study and understand consumer behaviour, e.g., placing internet-connected microphones (referred to only as "speakers") in people's homes or internet-cnnected GPS trackers in their pockets. There are strong incentives for those companies to conduct extensive surveillance. Bunny sells CDN services. At present, that's all, AFAICT.
1. https://bunny.net/our-story
This HN submission purports to mirror the recent announcement of fonts on the bunny.net blog on 16 June however it currently points to an "About" page, not the blog entry. The blog entry discloses in more detail the rationale for the decision to offer fonts.
https://bunny.net/blog/bringing-privacy-back-into-your-own-h...
There is an argument supported by legal decisions in Austria, Denmark and Germany that neither Google Fonts nor Google Analytics are GDPR-compliant.
https://www.theregister.com/2022/01/31/website_fine_google_f...
But true, I doubt Google is more nefarious than other resource provider. I am 99.9% sure that Google is not abusing cookies to extract end user data through their fonts service.
I believe you might be legally obliged to inform the user about them setting a cookie though. Alternatively, and this might be the better solution is to simply "vendor" the fonts (supplying them from your own server).
Not using fonts is not always an option
The silliness of this is that someone is going through the effort to set up hosting for a website but hosting the fonts is just too difficult and has to be delegated to a third party. The laziness of webdevs never fails to astound.
Do you have an example where doing something in an external font is not possible in one that's built into the browser?
This is the important part. Laws are not about trust.
Self-hosting is probably a better habit to acquire anyway, the only alternative being explicitly contracting with a company that offers edge CDN.
https://google-webfonts-helper.herokuapp.com/fonts
is great for quick self hosted local Google Webfonts
I thought the whole point is that using a common resource your chances of a cache hit are much higher such that they don't need to download. Having said that, if you are worried about GDPR you are probably way better off hosting them yourself anyways
Speaking as a European: I think this is a very important topic for us. I don't think Americans and American companies understand how little trust rest of us have for the American government. Working with a company that is not subject to the whims of the American government is a huge privacy win. If a company pitches me a product, they start 1 points ahead if they are based on Switzerland, Netherlands or somewhere similar.
I couldn't care less about web fonts though. I'm not downloading them from Google or "bunny.net" or anywhere else. My computer has some of the nicest-looking fonts around as system defaults, and websites can either work with that or get put into reader mode.
Enacting legislation is one thing. Somalia is excellent at enacting gun control legislation.
They are never geo-filtered either so everyone is forced to see them.
I’m usually a big advocate for privacy and this was obviously done with good intentions but there were so many better ways to do it and I doubt 99% of people do anything but click okay without reading it.
At least if the browsers did it the UI would be standardized and you could have default persistent settings.
Now that there has been a massive effort to implement it I doubt it will ever get fixed or go away. Even though the decline of supercookies and Firefox’s new 3rd party policy has largely made it obsolete.
No we can't. We can think of scummy adtech companies who feel entitled to their business model.
The GDPR very specifically says that the option to decline tracking must be at least as easily accessible as the option to accept.
The only way the EU is to blame for the pop-ups is that the regulation hasn't been enforced strictly enough.
I don't understand this line of thinking. You are declining the cookies, so obviously you prefer not to be tracked. And it's obvious that it's not the EU who made the varying, annoying, and often purposely misleading dialog boxes to decline the cookies, but the companies who want to force their tracking on you. Without the EU law, they would just do it without asking for permission. So why blame the EU?
I've never heard anybody who wasn't in or adjacent to the tech surveillance industry complain about this.
https://oblador.github.io/hush/
You're welcome!
European countries do the same for USA gov on US citizens.
In the US at least, any spying is illegal when both parties are within the US and the packets never leave the US.
And no doubt it must be even more illegal to then perjure yourself in front of congress about not having engaged in such illegal spying, when in fact you have.
These laws are a formality and have no teeth.
Noone? Why am I not surprised?
Laws can be enforced without executing people.
What is important here, and why these laws matter, is how trivial it is to get access to your data, or for companies to sell your data. That’s why I appreciate the European’s effort to have better laws for our privacy.
If you really want to be government proof, then you better host everything in a server in a remote secret location out of their reach.
`SELECT * from citizens where data_points < 50;`
And then somebody aims a botnet armed with zero-days in your direction. But yeah, that requires dedicated adversaries that actually notice you -- which is not a given, I'll agree.
EU privacy laws are a step in the right direction. It’s progress. We can build on it.
Against modern sophisticated governments who are busy, lazy, distracted to ask Netherlands to give them my data. I'm not exactly a high priority target. All I have to do is to make it a little harder for them to access my data.
Also, proper client side encryption is really difficult to break. Usually they need to compromise the client in order to read it.
What are they going to do, fly to my fringe country, knock on my door and politely ask me to stop storing encrypted blobs on their servers? No, they will not. First, their TOC does not forbid it and second, they are way too lazy to scope me out of the crowd, and third, they will only start shutting users down if their free plan starts costing them too much. I've been doing this for years and nobody seems to give a frak (Google included).
And I am just a regular guy who wants to make sure his code and passion projects (and personal / family photos) are never going to get lost even in a case of disaster. I never in my life did anything to warrant government attention.
At this point we're supposed to believe what amounts to feel-good talk.
But I keep asking: "How do we know for sure?"
I haven't done anything illegal nor do I need to protect some mega-important knowledge but I still dislike giving easy access to my data so I automated parts of my workflow to double-encrypt my most important data and send it to several off-sites plus an own self-hosted server.
Sure, they likely know remote Linux network zero-days but the odds of them wanting to target me in particular are minuscule so... ¯\_(ツ)_/¯
You are trusting them just as much as a server in any other country. Saying "Switzerland" is all marketing for privacy enthusiasts who aren't going to do anything on their own.
Be angry at the sites, not the legislation.
Have you... have you seen our politics? What makes you think that we think other people trust our government? We don't trust our government. Hell, it's trusted so little that one of our large political parties is basically entirely devoted to making sure that the government can't get anything done.
The public-facing excuse for Joe Q Public is "they can't be trusted!", "less taxes on your hard-earned money" (when corporate share of taxes has plunged from the 50-50 split it used to be, increasing individual taxes), "the government is not efficient" (usually because of lots of onerous regulations and reporting and oversight that, ahem, a certain political party insisted on to fight "abuse")
Can you think of a reason people would do that if they didn't trust those corporations more than the federal government?
But when it comes to surveillance on this quotidian level, I think private/corporate surveillance it’s far more relevant and problematic. In that regard, I’d slightly prefer a European country with good privacy laws like those you listed, because (probably) Bunny is not itself at the level of a panopticon such as Google, and the likelihood it has or would avail of avenues for resale to panopticon capable data brokers is less than it would be for US companies.
But even there, it does seem like a quite incremental improvement. The door is still wedged open, but now probably less wide, and probably with a stronger doorstop. It would be nice to not leave the door open at all.
I use DDG because I don't like Google. I can't do the same with my government.
You can only trust services like signal which make it impossible for the operators to access your data
GDPR is mainly against corporations making money out of knowing who you are across the web, it won't save you from a government actor
So you're safer from the USG inside the US.
Then again, they don't have a great track record of following those restrictions, so I doubt it really matters.
Of course it is. After American Wars in the Middle East killed and displaced millions, there is good reason to be wary of Americans and the American government.
What? Your government is the worst one to go not respecting your rights.
I think this is important to consider. In practice, it's difficult to have any recourse with an American company. In Europe it's more expected and common that government and consumer orgs take an active role. Both legal culture and culture-culture (?) are just very different, leading people to preferring to steer clear of this expensive and adversarial (compared to EU climes) environment.
Crypto AG was based out of switzerland.
You don't know who secretly owns any companies in Switzerland today. Your favorite Swiss VPN could be owned by Equifax or Acxiom for all you know.
or any government, especially our own, for that matter. Some just have a better track record at being bound by the rules they give themselves than others.
So no, this is not one of those examples, this is a great example of someone setting up a service to remove all those free, extra data points that Google harvests. Today it's fonts. Maybe tomorrow, it's the rest of their "it's not explicitly Google Analytics" offerings.
Do we know whether bunny.net is any better? In the abstract, no we don't, but we're not dealing in abstracts, so we actually do because of where they operate. A real European operation (not an international company with EU presence but an HQ outside of direct EU jurisdiction) is by default quite a bit better at not violating GDPR, and runs the actual risk of being fined into financial insolvency (rather than getting a few hundred million slap on wrist that a multibillion dollar company goes "pff, whatever, let legal sort it out" to).
By virtue of Google's track record, and by virtue of where this new service is located, and the track record of EU based services with regards to privacy compared to their US counterparts:
Yes, we can _very_ reasonably assume both of those things.
Why do you think you know how it works? What do you actually know about Google that doesn't come from outside speculation?
That link says that a website leaked an IP address to Google. It doesn't say that Google did anything with the IP address.
I guess I'll say what I always say: Look at the public privacy statements for Google, or for a particular Google product. If you have any evidence that Google does anything different from what's in that statement, contact Google and there will definitely be people interested in figuring out what's going on and fixing it.
Self host (supported by Google Fonts but not by this service): - Better privacy - Better performance (no extra DNS lookups, TLS connection)
Their default embed code is a CSS @import directive. These must never be used in production code (It's fine as a directive for the compiler for local files but not with remote URLs). Leads to FOUC and FOIT.
Also, next step in amateur hour: They serve their CSS and fonts on the same domain as their marketing website. Cookies galore.
What are those acronyms?
* FOUC: when you see content in the wrong font, then it switches to the correct font, sometimes leading to page layout jumps.
* FOIT: when you see _no_ text content because the desired font is missing with no fallbacks/the CSS directed not to use fallbacks. Once the font loads, page layout might jump.
Counterbalanced by the fact that if you just throw any old random font file on your server, it'll quite possibly be larger (in some cases considerably so) than necessary. So now you need to subset/split up the font files yourself, which takes some extra work (and the various online subsetting tools I've found often don't allow proper control over which OpenType typographic features to keep, sometimes mangle ligatures, etc., so I had to hack something together myself based on the Python fontTools), especially if subsetting a single file isn't enough and you actually need to split the fonts into multiple files.
(And in my case that whole effort wasn't actually so much for philosophical reasons, i.e. to try avoiding to use Google at all costs, but rather because Google Fonts was serving an outdated version of the font I was wanting to use, and was missing either some additional characters or bug fixes that were only added in a more recent version.)
> The quick brown bunny jumps over the lazy dog.
While the site is trying to be quirky and cute, replacing 'fox' with 'bunny' doesn't showcase what 'f' and 'x' look like.
- The quick brown bunny jumps over the lazy podgy fox.
If you want to do it with one word you can do:
- The quick brown bunny jumps over the oversexualized dragonfly.
- The quick brown bunny jumps the oversexualized dragonfly.
The quick brown bunny jumps over the lazy dog, here, fixed.
> Two driven jocks help fax my big quiz. Pack my box with five dozen liquor jugs. The five boxing wizards jump quickly. Bright vixens jump; dozy fowl quack. Jackdaws love my big sphinx of quartz. John quickly extemporized five tow bags. Waltz, nymph, for quick jigs vex Bud
The quick brown fox jumps over the glazed bunny.
I would scrap at least Avenir Next, Avenir, Helvetica Neue, Helvetica, Ubuntu, Roboto, Noto, Arial, Apple Garamond, Times New Roman, Droid Serif, Times, Source Serif Pro, Apple Color Emoji, Segoe UI Emoji, Segoe UI Symbol, Monaco, Liberation Mono and Lucida Console, and probably a couple more, for one of three reasons: that the family is superfluous, for an obsolete platform, or inferior.
(I’m not certain about that, and can’t confirm it as I don’t have ready access to Chrome on Android but I got the impression some years ago that Chrome on Android uses the system font, which is Roboto. But even apart from that, the general idea is “stop specifying specific fonts and let the browser do its thing and the user get their chosen fonts, unless what the browser does by default is too bad, like Courier New for monospace”.)
... and now you know why Roboto is explicitly included - because sans-serif won't necessarily resolve to Roboto on an Android device.
I suppose the reasoning behind having it might be that Android devices typically also have one of the fonts that appears lower in the stack, but before sans-serif... though that's not as likely if you're using a much smaller stack (also it's already quite near the end so... not sure why its typically used... could indeed be just trying to opt out of some manufacturers' undesirable alternative defaults, maybe).
```
font-family: -apple-system, BlinkMacSystemFont, avenir next, avenir, segoe ui, helvetica neue, helvetica, Cantarell, Ubuntu, roboto, noto, arial, sans-serif;
```
Am I doing it wrong by declaring it just like `font-family: sans-serif`?
So, you're "doing it wrong" in the sense that you're not actually doing the same thing, but you're not wrong in some kind of cosmic sense. :)
(This does make me wonder for the first time why, when system font stacks started to become popular, browsers didn't just make the system fonts the defaults, though. Sure, it would mean that web pages that only specified "sans-serif" would change appearance between the old and new browser versions, but if they only specified "sans-serif" they were declaring "I don't care what font you give me as long as it's sans serif" anyway.)
I guess displaying an ugly font was important for backwards compatibility so instead of fixing millions of existing wrbsites they created new keywords that you need to opt into.
Use `font-family: sans-serif` for your everything on your website except code blocks and inline code elements, which should use `font-family: monospace, monospace`. Yeah, you have to specify `monospace` twice. If you don't, monospace fonts will be unnaturally smaller than sans-serif fonts.
Please don't use serif fonts on your website, ever. Most people on the planet don't have a high resolution display and serif fonts look chipped and broken on those displays. Serif fonts make sense if you're using them inside a media query for print.
Is this really the case anymore these days? I think Firefox uses Courier New on Windows as the default monospaced font, but other than that I'm not aware of popular browsers using terrible fonts by default.
A nice aspect of using just serif or sans-serif is that users who configured their browser's font options get what they chose.
Actually, it was recently changed to use Consolas: https://bugzilla.mozilla.org/show_bug.cgi?id=1607913
$ dog A AAAA fonts.bunny.net
CNAME fonts.bunny.net. 10s "bunnyfonts.b-cdn.net."
A bunnyfonts.b-cdn.net. 10s 195.181.164.130
CNAME fonts.bunny.net. 9s "bunnyfonts.b-cdn.net."
A bunnyfonts.b-cdn.net. 9s + 195.181.164.130The license is non-standard too, something called SIL. I'm not gonna bother looking up what that weird thing permits when I can get thousands of CC0 fonts from like a dozen sites.
It's the same as Google Fonts (because they're the same fonts). Most of the fonts are released under the terms of the SIL Open Font License 1.1, and a handful of them released under the terms of the Apache License 2.0.
Most free fonts are OFL'd.
Use of Google Fonts API is unauthenticated. The Google Fonts API does not set or log cookies.
In other words, data from font serving does not feed into advertising personalization.
(Disclosure: I used to work on ads at Google)
(I would also note to everyone that you can simply disable sending referrers third party, which means that even if Google is using this data to track you, they won't know what sites you are visiting unless those sites use very specific combinations of fonts.)
There's an awful lot of weasel words in there.
If it was a simple "The Google Fonts API doesn't collect or store any user data" that would be good. But there's so much hidden language in that one sentence.
- "Designed" — Well, it was designed to do that, but it doesn't. After we're caught, we'll put out a press release saying We Can Do Better™.
- "Limit" - It limits the collection. It doesn't prevent the collection. It doesn't not collect any data. It just collects "limited" data. And "limited" is defined by us and can be revised whenever we want.
- "collection, storage, and use of end-user data" has so many ways to be abused.
- "efficiently" — Efficient for who? Google? Google's advertising department? Google's profiling department? What if there's an inefficient way? What if there's a more efficient way, but it gives Google less data?
All this may seem unkind, but Google has earned the planet's distrust. In the early years, Google didn't believe that reputation matters. It does. And that's why the legal departments of billion-dollar companies like the one I work for don't allow us to use Google products.
The wording around designing and limiting collection is acknowledging this inherent problem and letting the user know that they’ve done their best to prevent malice.
It’s not weasel wording except for anons who like hating on the internet.
For example, when I look at a Google Fonts request in Chrome developer tools I see:
x-client-data: CKe1yQEIkrbJAQiitskBCMS2yQEIqZ3KAQiVocsBCOeEzAEIhKvMAQjys8wBCL+1zAE=
Decoded:
message ClientVariations {
// Active client experiment variation IDs.
repeated int32 variation_id = [3300007, 3300114, 3300130, 3300164, 3313321, 3330197, 3342951, 3347844, 3348978, 3349183];
}
Each of those numbers represents an experimental treatment that is currently active for my Chrome instance. (It looks like more entropy because it's multiple values, but they're all derived from a single 13-bit per-instance seed.)[1] https://www.google.com/chrome/privacy/whitepaper.html#variat...
That is only true if-and-only-if we pretend those 13 bits are the only identifying information being sent to Google when requesting a font. The HTTP request is almost certainly being sent to Google wrapped inside an IP protocol packet. For most[1] requests, there are at least 24 additional bits (why 24? see: [3]) of very-identifying data in the IPv4 Source Address field. More fingerprinting can be probably done on other protocol fields, and IPv6 obviously adds an additional 96 bits. Yes, IP addresses are not unique, but ~13 bits is easily sufficient to disambiguate most hosts on a private network behind a typical NAT. Correlating the tuple {IPv4 Src Addr, x-client-data} received on a font request is trivial: it only requires a user to login to any Google webpage that includes a font request.
>> re: your [1]
A given Chrome installation may be participating in a number
of different variations (for different features) at the
same time. These fall into two categories:
Low entropy variations, which are randomized based
on a number from 0 to 7999 (13 bits) that's randomly
generated by each Chrome installation on the first run.
High entropy variations, which are randomized using
the usage statistics token for Chrome installations
that have usage statistics reporting enabled.
How many users have 'usage statistics reporting' enabled, and are there for a "High entropy variation"? Is it enabled by default and thus will only be disabled by the minority of people that know how to opt-out?[1] Google reports[2] they currently see about a 60%/40% ratio of IPv4/IPv6.
[2] https://www.google.com/intl/en/ipv6/statistics.html
[3] my previous posts on this topic - re: x-client-data https://news.ycombinator.com/item?id=23562285 re: 24-bits-per-IPv4 https://news.ycombinator.com/item?id=15167059
and https://www.theregister.com/2022/01/31/website_fine_google_f...
leads me to believe that Google has PI when people visit sites using google fonts.
Even if they don't use it for advertising purposes long term log keeping is not required to serve fonts.
It doesn't really matter what the service is doing, they didn't ask for consent to log the IP of people downloading fonts.
To be perfectly clear: it wouldn't keep me from sleeping at night and fonts permissions should be bundled with cookie consent or there should be a permission prompt (just like when asking for youtube vid.).
It isn't about whether the IP address was logged, but about whether it was sent. Which is an unavoidable aspect of loading a resource from a server.
> Google Fonts logs records of the CSS and the font file requests, and access to this data is kept secure.
Why does it point this data is kept secure if there is no PI in the first place ?
Uncheck "Allow pages to choose their own fonts, instead of your selections above"
No remote fonts anywhere.
But pages are fast to load, I get a consistent chosen font across all sites and my privacy (at least for font loading) is respected.
If you didn't have that font, you couldn't figure out the election results without clicking through to each state's page to see the results.
† It's quite nice. If memory serves me correctly, the Times even open-sourced it.
Google Fonts lets you download fonts for desktop use, in the form of .ttf or .otf rather than the .woff[2] with one file per Latin/Greek/Vietnamese/etc. script served by Google Fonts itself. If you want the same font-embedding CSS as Google Fonts itself, you can use https://google-webfonts-helper.herokuapp.com/fonts (a font browser, outdated, doesn't support font-display: swap), or https://nextgenthemes.com/google-webfont-downloader/ (a converter from Google Fonts CSS URLs to downloadable font packs, supports font-display: swap, it works well but I chose to not host the large CSS files with embedded fonts in base64 format).
As a technical curiosity, the second site can suffer a race condition resulting in partial or broken file downloads (I never tested what happens), if two people request the same font bundle at the same time, and they overwrite each other: https://github.com/nextgenthemes/open-webfonts#bug-reports-a...
I wish browsers would give users an option to set the default font-display policy to swap.
Additionally, a CDN will let that content be closer to your customer, so even if it wasn't cached with the magic of CDNs it should be faster than one origin server.
Correct. The last major browser stopped in early 2021.
> I think browsers still cache content from request to request for a domain.
Definitely! A cache still provides substantial speedup. Modern browsers fragment the cache on a per-site basis: www.example.com and www.example.org don't share, but www.example.com and forums.example.com do share.
That's pretty much always faster than a new TLS handshake, regardless of roundtrip.
PDF won the text presentation format war because among other things, PDF embedded the user's font.
for consistency, and if you care about not using google's CDN, just self-host your fonts.
sudo bash -c 'echo ":: fonts.googleapis.com" >> /etc/hosts'
sudo bash -c 'echo "0.0.0.0 fonts.googleapis.com" >> /etc/hosts'
and I haven't looked back.I just prefer having pages load quickly and don't generally think custom fonts improve the experience.
sudo bash -c 'echo ":: google.com" >> /etc/hosts'
sudo bash -c 'echo "0.0.0.0 google.com" >> /etc/hosts'Is that damn, or down, or something else? Why astreisk it out?
Reflowing is preventable using modern techniques, but honestly it doesn't seem like that big of a deal. The tradeoff is you get access to lots of different type options. More type options means more you can convey with type, which is a good thing for people who need to communicate on the web. It's more than just marketing sometimes.
Behold exhibit A: https://i.imgur.com/6F7fZVm.png
This is exactly what a FBI/CIA/GCHQ/FSB front company would say. They love to set up fronts in good-reputation countries, like Switzerland, or Slovenia in this case.
As a Slovenian, thanks for the laugh.
If I had to choose I'd take the unknown evil rather than the 100% known evil, though in this case it's dumb to use either option when you can trivially self-host.
One would expect this to be at the top of their FAQ.
Bunny is an extremely affordable CDN. The business they'd get from medium to large sites that already trust them enough to serve fonts over them should easily make up for it.
url("https://fonts.googleapis.com/comic-sans", sha="abcd1234")
This way:- If my browser has comic-sans cached, no request is made
- Caching works even if the same resource is sourced from multiple places (e.g. I can host comic-sans locally, but if they got it from a CDN, they don't need to get it again)
- If a malicious site replaces a resource, that's flagged
I think the trick would be to make this optional (but bandwidth/privacy-saving), and gradually to make this increasingly mandatory for different types of resources. AJAX calls obviously can't have SHA hashes, but JavaScript libraries can.
One issue with cross-site caching, though, is that it may enable timing-based attacks on privacy.
1) Mandating it for certain types of resources
2) Extending caching to cover the cross-site case.
Can you please explain the proposed timing-based attack?
Another attack is to determine if you visited $popularWebsite by checking if resources it uses are cached (this could be useful to, for example, the Chinese government for surveillance on its citizens).
It seems like:
- Only standard resources ought to be cached (e.g. D3, common fonts, etc.). Perhaps these could be a free registration with the browser maker (e.g. I can always get them from cdn.mozilla.org or something), with some constraints (e.g. minimum number of users, some delay, or similar). As a user, I ought to have the option to cache *all* of these (which is helpful in bandwidth-constrained settings), either on my machine or on a proxy. If I'm at caltech, I can repoint my browser to grab these from localbox.caltech.edu.
- These shouldn't offer a unique fingerprint, since it only works once. If I needed to load comic-sans.ttf, I won't need to load it next time.
- I might be able to set a fingerprint (e.g. ask you to load 25 resources, and check if they're cached), but that's really for cross-site tracking (for which there are easier mechanisms), and it only works once. Once you've cached a resource, it's cached nearly forever. Your fingerprint changes each time, so it's not really traceable.
So the more I think about this:
(1) You raised a valid (and hard!) problem
(2) There seem to be reasonable solutions
- The end user could have the option to enable/disable caching, and to clear the cache. Further configuration is also possible, e.g. to enable same-origin caching only.
- The end user could have the option to replace resources with their own regardless of where the files come from; there is one table keyed by hash and the value is the file to use instead, which might or might not be the same file (so the hash does not necessarily need to match the file that is being used instead).
- Features specific to the browser to make it more efficient could also be used when the user configures replacement of resources, e.g. if it can somehow implement jQuery in native code, or uses a different font format which is more efficient on the computer that it is running on.
- If archived copies of parts of web sites are being made, it can efficiently check if it already has some file which is being used in such a way.
However, requiring a hash probably should not be made mandatory.
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Co... https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Co...
Time is money, and it's expensive to pay people to mess with things if they don't have to.
I might not choose to make the same tradeoffs, but I can understand why others might.
Bunny Fonts: "1429 families"
Presumably Bunny Fonts is, essentially, just a pass through to Google Fonts.
Yeah, sure.
Or maybe just host your own fonts. 350KB traffic per unique visitor per month isn't going to kill your bill unless you serve millions of visitors a day.
This is in contrast with the behavior on fonts.google.com where missing characters are rendered with an inline image to explicitly show the missing glyph.
I prefer the fonts.google.com behavior here, which makes it easier to find fonts that have all the glyphs I need.
https://developers.google.com/fonts/faq#what_does_using_the_... was updated today, confirming Google Fonts doesn't log IP addresses.
Given that, it's unclear to me personally what the difference is between Bunny Fonts and Google Fonts.
I wondered if it supports fonts out of the box, but not currently.
If your origin is already fast and/or fronted with your own CDN the self-host and serve the fonts directly under you own domain. Trivial work with better security and performance.
As a www user, unless I am filing GDPR complaints against websites using Google Fonts under default configuration, i.e., served from Google computers, , I have no reason to care what fonts a website is using.