Live data from Hacker News

Bunny fonts – privacy respecting drop-in replacement for Google Fonts

fonts.bunny.net

221–230 of 346 posts

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#221
post #194

Earlier quoted context omitted.

Can I be angry at both? Legislation is only required to regulate bad behavior by some set of entities. As such, legislation should be written assuming that those entities will exploit any loopholes. Malicious compliance is exactly what the EU should have expected and planned for.

They are now forced to tell you what they are doing. That it makes you angry is a design goal.

Well, not quite. They are forced to stop hiding what they were doing. They could make everything opt-in, and it could be simple single checkbox or button, they are not forced to do any of what they are currently doing.

And if it makes people angry at the legislation, the lying back-stabbing “your privacy matters to us” arseholes in marketing are successfully making that goal backfire.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#222
post #216
post #213

Earlier quoted context omitted.

> And we can thank EU for the extremely annoying cookie pop-up’s on every website. Every site has a slightly different UI and the options/button labels always vary. Declining is always a multi-step process with various checkboxes. I don't understand this line of thinking. You are declining the cookies, so obviously you prefer not to be tracked. And it's obvious that it's not the EU who made the varying, annoying, and…

Of course the outcome of random unfriendly and annoying UIs is the only predictable outcome... so why wouldn't the EU responsible? Who else would be? Would some design guidelines be helpful? Maybe but it's still fundamentally flawed and I doubt it'd be enforced. As I said the only possible option where there could be design cohesion is via the browsers (or maybe a EU-controlled open source JS plugin but that's even w…

> Of course the outcome of random unfriendly and annoying UIs is the only predictable outcome... so why wouldn't the EU responsible? Who else would be?

"Of course burglars choosing less protected houses is the only predictable outcome... so why wouldn't the makers of security systems be responsible? Who else would be?"

I still don't get it. Without the EU laws, it wouldn't be magically easier to block tracking cookies, they wouldn't offer a choice at all? What are you arguing for?

> As I said the only possible option where there could be design cohesion is via the browsers (or maybe a EU-controlled open source JS plugin but that's even worse).

We tried that, it failed: https://en.wikipedia.org/wiki/Do_Not_Track

> I don't ever use the cookie popups because fine-tune control of cookies doesn't have much privacy ROI. I want to use cookies on most sites and ublock does the rest.

The cookies for functionality/session are not affected by the cookie popup.

> I highly, highly doubt the tiny percentage of people not using an adblocker but are still technical enough to uses cookie popups regularly and effectively is really worth the cost.

I use an adblocker and still decline on the cookie popups. I assume you are doing, too, otherwise you wouldn't complain about popups you don't see?

> Has the ever been a study that shows the real-world utility of forcing sites to use cookie popups?

Me able to decline them is real-world utility. If a majority or at least significant portion of users is successfully tricked into accepting the cookies, then that calls for a refinement of the law along with better enforcement, not for retraction of the law. "Let them have it", what a bleak, defeatist thing to suggest.

You are blaming the makers of the law for what is very obviously the fault of the perpetrators, who are trying to get around the law in profoundly shady and just downright shitty ways.

I am glad the EU law exists, without it there wouldn't even be the option.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#223
post #213

Earlier quoted context omitted.

> And we can thank EU for the extremely annoying cookie pop-up’s on every website. Every site has a slightly different UI and the options/button labels always vary. Declining is always a multi-step process with various checkboxes. I don't understand this line of thinking. You are declining the cookies, so obviously you prefer not to be tracked. And it's obvious that it's not the EU who made the varying, annoying, and…

There are many ways to solve this issues, and EU chose one of the worst ones, that for most people doesn't help at all.

Sounds good, can you name a few ways?

I'm being serious. If there are better ideas, which there probably are, let's put them out there.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#224

Earlier quoted context omitted.

That is the website owners implementing the rules in the worst way possible, either through incompetence or through deliberately trying to annoy (or fool) you into accepting everything. Be angry at the sites, not the legislation.

Can I be angry at both? Legislation is only required to regulate bad behavior by some set of entities. As such, legislation should be written assuming that those entities will exploit any loopholes. Malicious compliance is exactly what the EU should have expected and planned for.

> Malicious compliance is exactly what the EU should have expected and planned for.

It usually isn't compliance, malicious or otherwise.

It is malicious “we know we are breaking both the letter and the intent, but we know they don't have resources to properly enforce against everyone, so we are going to chance it for as long as we can”. The vast majority of these consent systems are not compliant with any of the relevant regulations (ePrivacy Directive, GDPR, CCPA, …). They will fix it when they get a slap on the wrist. If they get anything it will be a slap or a warning because while anyone in their right mind is pretty sure that the non-compliance is deliberate, that is nigh-on impossible to conclusively prove.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#225
post #31

I find it really strange where some privacy debates have gone wrong, and this is a perfect example. It's basically a form of "don't trust them, better trust us, also we're in a country with better privacy laws". Which is an imperfect solution at best, and given that I have no idea who bunny.net is it's a questionable one at best. If you embed a font hosted somewhere else you expose some of your user data to them. Now…

> have no idea who bunny.net is

$ whois bunny.net (...) Registrant Name: Registration Private Registrant Organization: Domains By Proxy, LLC Registrant Street: DomainsByProxy.com Registrant Street: 2155 E Warner Rd Registrant City: Tempe Registrant State/Province: Arizona Registrant Postal Code: 85284 Registrant Country: US (...)

> we're in a country with better privacy laws"

...it appears that the domain registrant is not, so you will just have to trust that the company is not in the US or not owned by a US entity (mostly relevant for the rest of the world, probably).

> with fonts there's a really simple solution: Just don't

This was worth repeating :)

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#226

Earlier quoted context omitted.

No one expects zero risk, it's about reducing risk. I choose to avoid American companies in favour of non-American competitors because the American government is hostile to privacy and is a warmonger.

90%+ of governments are more hostile to privacy than the US. It might make sense to prefer countries with GDPR, but the vast majority of "non-American countries" have even worse protections for your data. > and is a warmonger. This is flamebait unrelated to data privacy risk. If you don't want to use American companies because you have an political opposition to supporting US companies, that's also a valid opinion. Y…

> This is flamebait unrelated to data privacy risk.

It's not flamebait, it's a legitimate reason. A country who has been killing people in various wars/invasions is unlikely to behave ethically when it comes to privacy.

If you behave unethically in one area, I have every reason to assume that you'll also behave unethically in another area.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#227
post #31

I find it really strange where some privacy debates have gone wrong, and this is a perfect example. It's basically a form of "don't trust them, better trust us, also we're in a country with better privacy laws". Which is an imperfect solution at best, and given that I have no idea who bunny.net is it's a questionable one at best. If you embed a font hosted somewhere else you expose some of your user data to them. Now…

> we're in a country with better privacy laws Speaking as a European: I think this is a very important topic for us. I don't think Americans and American companies understand how little trust rest of us have for the American government. Working with a company that is not subject to the whims of the American government is a huge privacy win. If a company pitches me a product, they start 1 points ahead if they are base…

> I don't think Americans and American companies understand how little trust rest of us have for the American government.

Have you... have you seen our politics? What makes you think that we think other people trust our government? We don't trust our government. Hell, it's trusted so little that one of our large political parties is basically entirely devoted to making sure that the government can't get anything done.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#228

Earlier quoted context omitted.

I always had the suspicion that the (seemingly higher) interest in privacy/FOSS in Europeans is fueled partly by anti-Americanism. In America, even if you don't trust the government, at least it's your government, so I don't feel like that plays as big a role, and any interest in privacy/FOSS (like mine) is untempered by the anxiety of an alien government's interference. :p Regardless, I love how much more Europeans…

> I always had the suspicion that the (seemingly higher) interest in privacy/FOSS in Europeans is fueled partly by anti-Americanism. Of course it is. After American Wars in the Middle East killed and displaced millions, there is good reason to be wary of Americans and the American government.

[deleted]

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#229

A CDN for this? Sorry, but just store the fonts on the same d**n server you're serving the site from. Files are tiny, it's not 1080p video we're talking.

d**n? Is that damn, or down, or something else? Why astreisk it out?

Damn if you want it spelled out.

Re: Bunny fonts – privacy respecting drop-in replacement for Google Fonts

#230
post #31

I find it really strange where some privacy debates have gone wrong, and this is a perfect example. It's basically a form of "don't trust them, better trust us, also we're in a country with better privacy laws". Which is an imperfect solution at best, and given that I have no idea who bunny.net is it's a questionable one at best. If you embed a font hosted somewhere else you expose some of your user data to them. Now…

> have no idea who bunny.net is $ whois bunny.net (...) Registrant Name: Registration Private Registrant Organization: Domains By Proxy, LLC Registrant Street: DomainsByProxy.com Registrant Street: 2155 E Warner Rd Registrant City: Tempe Registrant State/Province: Arizona Registrant Postal Code: 85284 Registrant Country: US (...) > we're in a country with better privacy laws" ...it appears that the domain registrant…

This is run by BunnyCDN, I've been one of their smaller users for a few years now (live video hosting and delivery, mostly .m3u8, mpegts, HTTP Live Streaming type of stuff) and I've always found their service reliable and cheap. One of the primary reasons I liked them was that their API is REALLY fast at making changes to the files (you make the call and 100ms later the file attributes / content have been updated throughout all their delivery locations) and the interface is pretty easy to use.

This isn't an advertisement, I had a very specific use-case, but it follows into this:

Of course, just like with Google, we are the product here. Google Fonts is an analytics data collection platform, Bunny Fonts is an advertisement for their CDN services.

I'm going to stick with a /fonts/ directory, I think, despite being one of their current users. It's really not very much bandwidth for the fonts, it's not 2010 anymore, and I prefer the control (and the local development environment being the same, I don't always have internet and I don't want a dev toggle for something as silly as fonts).

Post reply on HN