Live data from Hacker News

Google Webfonts, the Spy Inside?

fontfeed.com

41–50 of 79 posts

Re: Google Webfonts, the Spy Inside?

#41
post #20

Earlier quoted context omitted.

Google, whose core business model fundamentally depends on extensive data-mining of user information? Does it? Try Googling from an incognito window on your neighbour's wifi. Use a live distro if you want to be completely sure. Are the results significantly different? Are ads any worse? I have tried a couple of tests like that (on other people's devices, etc) and the only noticeable use of that trove of data Google h…

Have a look: https://www.google.com/settings/u/0/ads If you don't trust that, then a great way to find out what any advertising company knows about you is to act like an advertiser and look at what user data you can get. I don't mean call up google advertising and pretending that you're head of marketing at $BIGCOMPANY (you could, but it's not what I meant), but try looking at the product pages made for advertisers.

Your comments seem to underscore how Google controls the debate by defining the terms on privacy issues. You seem to be saying "Concerned about privacy? You could check up on Google by acting like one of its advertising customers.." which sort of highlights the parties Google is most interested in being transparent with (for completely understandable business reasons).

But of course in order to do that, you also have to have a login, cookie, etc. for a panel that Google controls, and that exposes only a tiny subset of the information it could most obviously and trivially correlate about user activities.

These just aren't really things people trying to visit wordpress sites should have to consider..

Re: Google Webfonts, the Spy Inside?

#42
post #11
post #8

Earlier quoted context omitted.

using font files from a popular public cdn like google fonts is a good idea as they are generally highly available and are generally already cached on the user's machine from use on other sites.

Kbar, why do you need "highly available" fonts when you can bundle them in your web site? If the web site is up, fonts will work, if not fonts won't be needed anyway. Regarding caching, anyone knows how browsers cache content? I.e. if I host my own fonts and someone visits me, then visits another web site with same fonts.. are they retrieved from the cache or downloaded yet again? I'm guessing they are downloaded aga…

If they're not being loaded from the same url (e.g. from Google), then they're not the same fonts as far as the browser can tell.

Re: Google Webfonts, the Spy Inside?

#43

This may be an unpopular sentiment, but here goes. The hyperbole over this kind of reasoning threatens the very fabric of the Web. Snowden did the world a service in revealing all of the NSA hacking going on, but the paranoia that is resulting from this is breaking the original spirit of the Web. It is, after all, a Web of links, and those links were intended to be not just between siloed content, but between differe…

A simple "noreferrer" (or referer if you like) tag on elements or in pages would solve a lot of this. 3rd parties would obviously still get the request, but they wouldn't know what page it comes from.

Interesting that "norel" got adopted so quickly for spam. So it shouldn't be hard to have a "noreferrer" tag added, right?

Yes, users can install addons to modify header behaviour, but site designers should be able to use third parties without disclosing things, too. Not just privacy, but security. Currently, apps need to implement a bouncer page to hide sensitive referrers.

Re: Google Webfonts, the Spy Inside?

#44
post #38
post #33

Earlier quoted context omitted.

Oh come on, that first sentence is uncalled for. Cromwellian (while awesome, and someone who never fails to impress me with his writing) is not speaking for Google, or even other Googlers. He is speaking for himself. As is his right, I'd hope you'd agree, even if you (like many) would disagree with some of the things he writes. (Edit: you changed the first sentence. Which reads better, thank you. Though I would actua…

My first sentence does not imply that he's speaking for Google, or other Google employees. cromwellian is an employee of Google, and I would regard his opinion here as being contemptuous of privacy. Edit: okay, I see the implication now of me referring to all Google employees in that sentence. I had intended for the plural to refer to "more than one", which I think is a safe bet - but it could also be construed as re…

>>> And here we see the contempt for privacy that employees of Google hold

Um... yes it did. You're trying to portray all of the employees of Google as being against privacy, and that's just simply not the case.

Besides that, the argument cromwellian was making is hardly unique to Googlers.

Re: Google Webfonts, the Spy Inside?

#45

Earlier quoted context omitted.

(not talking for google) Two quick points: - The fonts have to be hosted somewhere. And the more common the hosting site is, the better the browser cache behavior is. - The cache behavior prevents requests from going out. If the font is cached, then there's no web request going back to google. And there's no web request on the wire for NSA/GCHQ/Verizon to sniff. As for the terminology, I personally think that there s…

It really depends on the relevant counterfactual; yours makes total sense from the vantage point of lots of developers, but I tend to prioritize privacy and autonomy. When I visit catphotos.wordpress.com, my intention is not to leak information to Google even though they have great fonts. My intention is just to visit the website. So the counterfactual I would frame the discussion with would be something more like se…

> I wish WordPress had been more thoughtful about the trade-offs they made

More accurately, you wish that WordPress had agreed with your priorities. They clearly did think about this and made a different decision and it's unfair to suggest otherwise.

Re: Google Webfonts, the Spy Inside?

#46
post #23
post #6

On the face of things, concern over this type of 'privacy violation' seems to be reasonable. However, coming from a page that is loading content from Fontfeed, Twitter, Gravatar, Google APIs, Fontshop and lo...Google Analytics, I think it's a bit of a silly argument. If you want privacy, don't expect the sites you are hitting to take care of that for you. If you expect others to enforce security for you, well then, y…

This doesn't imply that, as a webmaster, you should be fine with asking browsers to load external resources from third parties with potential privacy implications, just because privacy-conscious users should have disabled it by themselves.

I'm not sure, as a webmaster, that I have any better control over my user's data than Google's font service does. If I think I do, I'm probably naive.

Re: Google Webfonts, the Spy Inside?

#47
post #31

This may be an unpopular sentiment, but here goes. The hyperbole over this kind of reasoning threatens the very fabric of the Web. Snowden did the world a service in revealing all of the NSA hacking going on, but the paranoia that is resulting from this is breaking the original spirit of the Web. It is, after all, a Web of links, and those links were intended to be not just between siloed content, but between differe…

And here we see the contempt for privacy that some employees of Google hold. What would you regard as private, pray tell, if it's not being able to access a web page without telling Google (and other advertizing companies) that you're doing so? You regard a pursuit for that freedom as "paranoid"? Linking is the great power of the Web, and is why it is what it is today. That's all. Scripting is sometimes useful, but m…

I've held this basic view of the Web far longer than I've been a Google employee (http://timepedia.blogspot.com/2008/05/decentralizing-web.htm...)

I wrote one of the first anonymizing proxy servers for the Web (http://cypherpunks.venona.com/archive/1996/02/msg00885.html) which was later referenced by others (Ian Goldberg references it here: http://www.cs.berkeley.edu/~daw/papers/privacy-compcon97-www...)

In the early days of Cypherpunks, I collaborated with Hal Finney, one of the founders of the technology behind BitCoin (http://cryptome.org/2014/09/hal-finney-cpunks-1992.htm) In fact, I sold a startup in 2000 that was based on HashCash, the forerunner to Reliable Proof Of Work/Blockchain.

I wrote one of the first Shamir sharing utilities for Unix, Cryptosplit. I authored one of the first Remailer 2.0 proposals on Cypherpunks, on ways of networks of PGP remailers to defeat traffic analysis. I wrote an anonymous forwarding, and later, a double blind anonymous mailing list software where neither the recipients of the list are known, nor the address of the mailing list itself. (http://cypherpunks.venona.com/archive/1993/09/msg00509.html)

I have been involved in cryptography and privacy since the mid 90s and I care deeply about it. But I am not an extremist. Just like I believe in capitalism, but I am not a libertarian/Objectivist/anarcho-capitalist, and I tend towards progressivism and regulation as reasonable requirements.

There is a fundamental tension between transparency and privacy.

We are heading into a scary world where the cost of cameras, microphones, and networking is going to zero, and the size is tending to zero. That means tracking will be cheap and ubiquitous. We will need to find a way of dealing with the implications of this, without going to live in a log cabin in the woods. Some of that is technological, some of it will be political/legal, and some of it will be cultural.

I love the Web, it's the greatest human invention since the printing press, but I fear for the balkanization of it, and the Internet. We need to tread carefully and not go overboard in being reactionary, lest we hurt the thing we love.

This is not being "contempuous" of privacy. It's considering the tradeoffs, looking at the threat model, and looking at the cost/benefits of various levels of privacy protection, all the way from "none" to "perfect privacy", and what the repercussions of that might be.

Re: Google Webfonts, the Spy Inside?

#48
post #35
post #7

Earlier quoted context omitted.

The only person that really cares about your privacy is you. It's cognitive dissonance to believe otherwise.

And yet plenty of people with the knowledge and means to ensure their privacy online and elsewhere get spectacularly vocal about the privacy of those who have neither.

I think we should get spectacularly vocal about protecting people-who-don't-know-better's privacy rights. We created this damn thing called the Internet, and sold it to them as this awesome tool. We should at least try to secure it better.

It is my belief that decentralizing services is one possible solution to this problem. At a minimum, having the user store their data at home on servers they plug-in and turn-on may be the solution. We're a ways out from that, but I'd much rather see people pushing the argument toward decentralization than faulting a website owner for using nice looking fonts for their gluten free pie crust recipe. Everyone knows what happens when hackers get access to your pie crust. They eat it.

Re: Google Webfonts, the Spy Inside?

#49

Earlier quoted context omitted.

Have a look: https://www.google.com/settings/u/0/ads If you don't trust that, then a great way to find out what any advertising company knows about you is to act like an advertiser and look at what user data you can get. I don't mean call up google advertising and pretending that you're head of marketing at $BIGCOMPANY (you could, but it's not what I meant), but try looking at the product pages made for advertisers.

Your comments seem to underscore how Google controls the debate by defining the terms on privacy issues. You seem to be saying "Concerned about privacy? You could check up on Google by acting like one of its advertising customers.." which sort of highlights the parties Google is most interested in being transparent with (for completely understandable business reasons). But of course in order to do that, you also have…

Please see my other comments on this thread about privacy terminology, norms, etc. But yes, I think that when considering the debate, one should look at both sides for an honest understanding of what's going on.

Tinfoil-hatting a login for intel gathering's a stretch. Please use whatever you feel necessary (e.g., TAILS) for keeping your privacy while doing a little recon on what google's offering about its users to advertisers.

Ultimately, wordpress chose to refer to google for font loading. That's their choice and right, and it's what people reading wordpress will have to deal with.

Re: Google Webfonts, the Spy Inside?

#50
post #32

What the hell is wrong with the fonts my browser already has installed?

Going through exactly this when trying to optimize a site for a large company. Designers ended up with a little cursive font for headings. Getting approval from bigcorp takes forever. So many months in, that's the design.

There's no cursive-looking font that is commonly available on all machines. So we either have to use a font, or render images. Since it's used in more than a couple places, the font ends up taking less time.

Or I could try fighting the design, customer relationship, corporate branding, etc. teams to convince them the site's better off with just "Sans-Serif". In short: fonts aren't going anywhere.

Now, it would be nice if a dozen or two fonts of varying styles were included by default with browsers. But I imagine that'd just lead to designers raging about how is trying to limit creativity and enforce conformity.

FFS, many fonts don't even render properly on Firefox on Windows (like on medium.com) so I highly doubt usability is being considered as a main priority here.

Post reply on HN