Live data from Hacker News

Blacklight – A Real-Time Website Privacy Inspector

themarkup.org

61–70 of 106 posts

Re: Blacklight – A Real-Time Website Privacy Inspector

#61
Here are some bad ones:

https://themarkup.org/blacklight/?url=thoughtcatalog.com

https://themarkup.org/blacklight/?url=factinate.com

https://themarkup.org/blacklight/?url=sacbee.com

https://themarkup.org/blacklight/?url=mediabiasfactcheck.com

https://themarkup.org/blacklight/?url=www.thestar.com

https://themarkup.org/blacklight/?url=space.com

https://themarkup.org/blacklight/?url=laptopmag.com

https://themarkup.org/blacklight/?url=hollywoodlife.com

https://themarkup.org/blacklight/?url=nfl.com

https://themarkup.org/blacklight/?url=kyma.com

The worst so far: https://themarkup.org/blacklight/?url=thehindu.com

https://themarkup.org/blacklight/?url=m.economictimes.com

Re: Blacklight – A Real-Time Website Privacy Inspector

#62
There's some good stuff in here, but they're also using a very expansive definition of "tracker" that in some cases I think is just unfair.

For example Adobe TypeKit serves fonts. It's not ad tech at all. The only thing it tracks is how many times a font was served. Adobe does also have ad tracking technology but TypeKit isn't part of it.

Likewise the tool's author seems to misunderstand AWS CloudFront, which is a CDN and does not itself do any tracking nor is it connected to any Amazon ad tech.

Re: Blacklight – A Real-Time Website Privacy Inspector

#63
post #3

That's really well done. I tried several ecommerce, airline, travel, etc, sites. I was surprised with the extent of fingerprinting and 3rd party sites. For example, American Airlines, aa.com: 17 ad trackers, 32 third party cookies, canvas fingerprinting, session keyboard and mouse tracking, data to facebook, linked in, amazon, and more. Ouch.

I'm using uBlock and uMatrix so I'm not surprised. However I've been blocking such with whatever was at hand since javascript started out... In the start it was easy, just don't load javascript. Now it's even easier, just install uBlock and uMatrix and watch the whole modern web break together... :-)

Re: Blacklight – A Real-Time Website Privacy Inspector

#64
post #62

There's some good stuff in here, but they're also using a very expansive definition of "tracker" that in some cases I think is just unfair. For example Adobe TypeKit serves fonts. It's not ad tech at all. The only thing it tracks is how many times a font was served. Adobe does also have ad tracking technology but TypeKit isn't part of it. Likewise the tool's author seems to misunderstand AWS CloudFront, which is a CD…

I guess you tested one of your sites? I agree that typekit is not an ad tracker, and neither is cloudfront.

https://themarkup.org/blacklight/?url=www.utilitydive.com

Re: Blacklight – A Real-Time Website Privacy Inspector

#65

Earlier quoted context omitted.

> everyone agrees that this is theft No.

I'm not aware of any court case where downloading and watching movies without the rights owner's permission was considered OK. Instead, the downloader always had to pay a fine.

That's actually legal in my homeland. There are specific conditions (e.g. personal use without economic goals) but it's generally OK. Note however that this applies to downloading from a server where the transfer goes one way. Torrenting would constitute copyright infringement as it is a two way transfer and counts as sharing copyrighted works.

Re: Blacklight – A Real-Time Website Privacy Inspector

#66
post #62

There's some good stuff in here, but they're also using a very expansive definition of "tracker" that in some cases I think is just unfair. For example Adobe TypeKit serves fonts. It's not ad tech at all. The only thing it tracks is how many times a font was served. Adobe does also have ad tracking technology but TypeKit isn't part of it. Likewise the tool's author seems to misunderstand AWS CloudFront, which is a CD…

TypeKit does indeed send tracking data back to Adobe through the domain p.typekit.net. This is also likely reflected in Adobe's privacy policy.

Luckily, it is possible to use Content-Security-Policy or client-side scripts to block this domain while allowing use.typekit.net, which simply hosts the font files.

Re: Blacklight – A Real-Time Website Privacy Inspector

#67
post #66
post #62

There's some good stuff in here, but they're also using a very expansive definition of "tracker" that in some cases I think is just unfair. For example Adobe TypeKit serves fonts. It's not ad tech at all. The only thing it tracks is how many times a font was served. Adobe does also have ad tracking technology but TypeKit isn't part of it. Likewise the tool's author seems to misunderstand AWS CloudFront, which is a CD…

TypeKit does indeed send tracking data back to Adobe through the domain p.typekit.net. This is also likely reflected in Adobe's privacy policy. Luckily, it is possible to use Content-Security-Policy or client-side scripts to block this domain while allowing use.typekit.net, which simply hosts the font files.

Like I said, they keep track of font usage. The billing is based on usage. That domain sets no cookies and the privacy policy doesn't permit the data to be used for ads: https://www.adobe.com/privacy/policies/adobe-fonts.html It's not ad tech.

I think this is the problem with the "high score" approach to measuring the privacy impact of a site. Number of third-party cookies or "trackers" is not a great proxy for how well a site actually protects your data in ways you care about.

I would also add New Relic as an example of a site that really shouldn't be in a list of "ad tech."

Re: Blacklight – A Real-Time Website Privacy Inspector

#68
post #44

This is just like a highscore game ... 33 Trackers | 60 Third-Party Cookies https://themarkup.org/blacklight/?url=edition.cnn.com 32 Trackers | 53 Third-Party Cookies https://themarkup.org/blacklight/?url=wsj.com The newspaper business is digging it's own grave. "This website could be monitoring your keystrokes and mouse clicks."

Do you pay for your news then I assume?

Note that one of their two examples is wsj.com, which only serves news to paying subscribers and still includes large ad banners.

Re: Blacklight – A Real-Time Website Privacy Inspector

#69

I feel like we should unify the copyright and privacy laws. If I copy a Disney movie without their knowledge and then extract value from it, for example by watching the movie without paying, everyone agrees that this is theft. And punishment is generally strong to excessive. If a website copies my private data without my knowledge or even after I decline permission by sending DNT headers, that is somehow considered c…

What is "private data"? Is your hair colour private data? Is the browser you use private data? Why? Or why not? Does it matter if I only record hair colour and the browser you use, or if I combine it with other data?

These kind of things may sound okay superficially, but once you start defining things clearly in a way that can be incorporated in a workable law things get very hard very fast.

Copyright, on the other hand, is much easier.

Re: Blacklight – A Real-Time Website Privacy Inspector

#70

This is just like a highscore game ... 33 Trackers | 60 Third-Party Cookies https://themarkup.org/blacklight/?url=edition.cnn.com 32 Trackers | 53 Third-Party Cookies https://themarkup.org/blacklight/?url=wsj.com The newspaper business is digging it's own grave. "This website could be monitoring your keystrokes and mouse clicks."

39 Trackers | 91 Third-Party Cookies | Evading Trackers | (Possible) Keystroke & Mouse Monitoring https://themarkup.org/blacklight/?url=arstechnica.com

At least Ars will allow you to disable almost all of that if you subscribe. I mean, they've got to pay their staff somehow, and if it's not subscriptions or ads then how?
Post reply on HN