Live data from Hacker News

Bunny fonts – privacy respecting drop-in replacement for Google Fonts

fonts.bunny.net

181–190 of 346 posts

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#181
post #162

Earlier quoted context omitted.

Yep, and also the whole EU... Every few months, they either want to make encrpytion illegal, scan more private data, scan files on end user devices, outright ban e2e encryption, or worse.

And we can thank EU for the extremely annoying cookie pop-up’s on every website. Every site has a slightly different UI and the options/button labels always vary. Declining is always a multi-step process with various checkboxes. They are never geo-filtered either so everyone is forced to see them. I’m usually a big advocate for privacy and this was obviously done with good intentions but there were so many better way…

>And we can thank EU for the extremely annoying cookie pop-up’s on every website. Every site has a slightly different UI and the options/button labels always vary. Declining is always a multi-step process with various checkboxes.

No we can't. We can think of scummy adtech companies who feel entitled to their business model.

The GDPR very specifically says that the option to decline tracking must be at least as easily accessible as the option to accept.

The only way the EU is to blame for the pop-ups is that the regulation hasn't been enforced strictly enough.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#182

Earlier quoted context omitted.

I don't think we can reasonably assume either of those things. You're speculating about both Google Fonts and Bunny fonts based on very little information.

No, and yes, respectively. If you consider "Google recording and monteizing on CORS URL requests" speculation, I'm not sure you know much about the company we're talking about here. They've been sued and fined over tracking quite a number of times. Do we know whether bunny.net is any better? In the abstract, no we don't, but we're not dealing in abstracts, so we actually do because of where they operate. A real Europ…

I used to work at Google and I'm sure I don't know how most of it works, outside the area I worked in. It's a big company and the systems are complex.

Why do you think you know how it works? What do you actually know about Google that doesn't come from outside speculation?

That link says that a website leaked an IP address to Google. It doesn't say that Google did anything with the IP address.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#183

Earlier quoted context omitted.

I always had the suspicion that the (seemingly higher) interest in privacy/FOSS in Europeans is fueled partly by anti-Americanism. In America, even if you don't trust the government, at least it's your government, so I don't feel like that plays as big a role, and any interest in privacy/FOSS (like mine) is untempered by the anxiety of an alien government's interference. :p Regardless, I love how much more Europeans…

> at least it's your government What? Your government is the worst one to go not respecting your rights.

I worry more about my government compared to the government of a county far away that has no power over me.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#184
post #31

I find it really strange where some privacy debates have gone wrong, and this is a perfect example. It's basically a form of "don't trust them, better trust us, also we're in a country with better privacy laws". Which is an imperfect solution at best, and given that I have no idea who bunny.net is it's a questionable one at best. If you embed a font hosted somewhere else you expose some of your user data to them. Now…

If you're requesting data over a network, ultimately you have to trust someone. Fwiw bunny.net is pretty well respected. I view them as one level "below" the mega-enterprise CDNs like Cloudfront/Akamai, the same way Digital Ocean is one level "below" AWS/GCP/Azure

> If you're requesting data over a network, ultimately you have to trust someone.

If I self-host my fonts, the people I have to trust are only those people I have no choice but to trust: those who get my site into the user's browser. Every additional cross-domain request I add is an extra party I have to trust.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#185

Earlier quoted context omitted.

You can't use the internet without risk. All you can do is measure relative risks and decide which are acceptable. Means, motive, and opportunity matter. Someone who is missing the motive portion is less of a concern than someone who has all three.

No one expects zero risk, it's about reducing risk. I choose to avoid American companies in favour of non-American competitors because the American government is hostile to privacy and is a warmonger.

90%+ of governments are more hostile to privacy than the US. It might make sense to prefer countries with GDPR, but the vast majority of "non-American countries" have even worse protections for your data.

> and is a warmonger.

This is flamebait unrelated to data privacy risk. If you don't want to use American companies because you have an political opposition to supporting US companies, that's also a valid opinion. You don't have to twist it into a data privacy argument.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#186
post #31

I find it really strange where some privacy debates have gone wrong, and this is a perfect example. It's basically a form of "don't trust them, better trust us, also we're in a country with better privacy laws". Which is an imperfect solution at best, and given that I have no idea who bunny.net is it's a questionable one at best. If you embed a font hosted somewhere else you expose some of your user data to them. Now…

> we're in a country with better privacy laws Speaking as a European: I think this is a very important topic for us. I don't think Americans and American companies understand how little trust rest of us have for the American government. Working with a company that is not subject to the whims of the American government is a huge privacy win. If a company pitches me a product, they start 1 points ahead if they are base…

Any government sending any request to any company is very likely to get a compliant answer if they want to operate in that market.

You can only trust services like signal which make it impossible for the operators to access your data

GDPR is mainly against corporations making money out of knowing who you are across the web, it won't save you from a government actor

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#187
post #91

Years ago I did sudo bash -c 'echo ":: fonts.googleapis.com" >> /etc/hosts' sudo bash -c 'echo "0.0.0.0 fonts.googleapis.com" >> /etc/hosts' and I haven't looked back.

...and the other 10,000 sites you interact with per year? I realize security posture is about layers, but this is pointless.

It's not for privacy's sake! I leave that to Privacy Badger.

I just prefer having pages load quickly and don't generally think custom fonts improve the experience.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#189
post #41
post #31

I find it really strange where some privacy debates have gone wrong, and this is a perfect example. It's basically a form of "don't trust them, better trust us, also we're in a country with better privacy laws". Which is an imperfect solution at best, and given that I have no idea who bunny.net is it's a questionable one at best. If you embed a font hosted somewhere else you expose some of your user data to them. Now…

It seems okay to me for the case of google. Since Google-owned sites, Adsense, Gmail, and Google Analytics are so ubiquitous, things like a font download are trivially easy for Google to correlate to your other activity. There's much less value for BunnyCDN to abuse it, because they don't have the critical mass of your other activity. Yes, just serving up your own fonts is better, but this is an improvement that seem…

I see this completely the opposite. There’s much more risk to Google to be lying about the privacy agreement applicable to Google Fonts (https://developers.google.com/fonts/faq#what_does_using_the_...) than there is to some unknown company that won’t be a target for regulators and won’t make any news for casually violating your privacy through shoddy engineering work or incompetence let alone maliciousness.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#190
post #162

Earlier quoted context omitted.

And we can thank EU for the extremely annoying cookie pop-up’s on every website. Every site has a slightly different UI and the options/button labels always vary. Declining is always a multi-step process with various checkboxes. They are never geo-filtered either so everyone is forced to see them. I’m usually a big advocate for privacy and this was obviously done with good intentions but there were so many better way…

>And we can thank EU for the extremely annoying cookie pop-up’s on every website. Every site has a slightly different UI and the options/button labels always vary. Declining is always a multi-step process with various checkboxes. No we can't. We can think of scummy adtech companies who feel entitled to their business model. The GDPR very specifically says that the option to decline tracking must be at least as easily…

If the cookies are needed for functionality the popup is not required.
Post reply on HN