9 ms·
Visiting a site that uses Disqus when not logged in sends URL to Facebook
- harmafelicia 10y agoThis is a testimony that I will tell to every one to hear. I have been married four 4years and on the fifth year of my marriage, another woman had a spell to take my lover away from me and my husband left me and the kids and we have suffered for 2years until I met a post where this man DR LUKA LELE have helped someone and I decided to give him a try to help me bring my lover back home and believe me I just send my picture to him and that of my husband and after 48 hours as he have told me, I saw a car drove into the house and behold it was my husband and he have come to me and the kids and that is why I am happy to make every one of you in similar to met with this man and have your lover back to your self. His email:DRLELESPELLTEMPLE@OUTLOOK.COM
- deleted 10y ago[deleted]
- brlewis 10y agoSome years ago I looked at Facebook's ToS for implementing "log in with Facebook" and at that time it looked like it precluded an implementation that would only send requests to Facebook if the user chose Facebook login. I don't think it's for sure that disqus could fix this problem if they wanted to.
- detaro 10y agoThe facebook SDK surely can't reliably tell if it was loaded on page load or only after the user clicked a "Facebook" button? And they support OAuth, so you don't have to use their code at all on the client side.
- d2p 10y agoI don't know the details, but I can't see a reason why they can't just not include the SDK until they need it (sure, this will add a delay before they can use it, but seems better than this current implementation for privacy!).
- chatmasta 10y agoIt's obviously in facebook's interest to load the SDK as much as possible. Even if you are not logged in, they can get a lot of valuable tracking information from the server logs, including IP address, referrer, any fb cookies other than login, etc. In fact, so long as a client loads the sdk on multiple sites, even if logged out, Facebook can still track that client across sites visited (simple list of referrers associated withvthis cookieset)
- j_s 10y agoBack in the day, Heise apparently caught some flack for protecting their readers while still allowing Facebook "likes". It feels to me like the typical Facebook approach: do what they want to do or a little bit more, monitor the blowback and walk it back as little as possible only if required to keep everyone happy. https://yro.slashdot.org/story/11/09/03/0115241/heises-two-clicks-for-more-privacy-vs-facebook https://yro.slashdot.org/story/11/09/03/0115241/heises-two-c... https://www.heise.de/extras/socialshareprivacy/ https://www.heise.de/extras/socialshareprivacy/ -> http://panzi.github.io/SocialSharePrivacy/ http://panzi.github.io/SocialSharePrivacy/
- sp332 10y agoThat was basically just a trademark dispute. They claimed it was confusing to show a Facebook "like" button that didn't work like Facebook's actual "like" button. It's fine if you use your own assets to indicate what the button does, but you can't use a Facebook logo or their thumb icon.
- j_s 10y agoI understand Facebook chose to use trademark law to threaten to block the Heise app id and even their entire domain (any sharing of the paper's content on Facebook). Facebook continues to use every tool at their disposal to protect their expansion of the privacy invasion of their product.
- j_s 10y agoAs mentioned in the article there was a related discussion yesterday, where removal of ad network stuff doesn't really matter since Disqus is used for comments: I've removed all ad network code from my blog (troyhunt.com) https://news.ycombinator.com/item?id=13326792 https://news.ycombinator.com/item?id=13326792 This included a screenshot of DoubleClick still being blocked on Troy Hunt's blog.
- Raphmedia 10y agoI wish all website would wait for the user to turn on social features before offering them. I'm not interested in any of them, the scripts shouldn't be loaded for nothing. Take a look at this way to do it: http://panzi.github.io/SocialSharePrivacy/ http://panzi.github.io/SocialSharePrivacy/
- em3rgent0rdr 10y agothat looks great! I like how the buttons are originally grey, which is a clear visual indicator that they are not enabled.
- __derek__ 10y agoAgreed. I use PrivacyBadger[1] to block the download of assets from third-party domains. That way I can selectively enable anything that I want from the blocked domains. [1]: https://www.eff.org/privacybadger https://www.eff.org/privacybadger
- dylanfw 10y agoBruce Schneier's security blog implements something like this, providing an on/off switch for each social network's "Like", "+1", etc. https://www.schneier.com/ https://www.schneier.com/
- reitanqild 10y agoh-online used to do something like this as well.
- WA 10y agoHeise now uses a new tool they developed called Shariff. Looks better imho and is easy to use. It also shows a like counter if you proxy requests to FB's Graph API through your server. https://github.com/heiseonline/shariff https://github.com/heiseonline/shariff Would recommend this over their old two click social share. Your link is a fork of the old Heise tool. It looks dated on mobile.
- K0nserv 10y agoAs a user I use uBlock Origin to block all 3rd party JS by default. This protects me from loading ads, social widgets(trackers), and trackers. A lot of the web is completely broken when you don't run 3rd party JS so each site requires a bit of whitelisting before it will function correctly. As a website owner I try to lead by example by not including any 3rd party JS(or any JS at all for that matter). Specifically avoiding trackers from Google or Facebook.
- codazoda 10y agoThis tracking stuff is a plaque and I'm part of the problem. I run an unpopular site with random bits of information on it that uses AdSense to give me a few bucks a month and Disqus to allow comments. Uhg. I really need to think about whether I want to be part of the problem.
- em3rgent0rdr 10y agosomebody in the other thread mentioned https://www.discourse.org/ https://www.discourse.org/ as an open-source alternative to disqus, although there were some people that downvoted it, so I don't know how good it is.
- daxelrod 10y agoDiscourse is primarily a better alternative to bulletin-board style forums. Here's their docs on embedding, which seems like it would make it act a little more like disqus. https://meta.discourse.org/t/embedding-discourse-comments-via-javascript/31963 https://meta.discourse.org/t/embedding-discourse-comments-vi... Note that a major difference is that you apparently have to go into the forum page to leave a comment, you can't do it from the page you're discussing.
- greggman 10y agoDisqus = paste some markup in your page and done Discourse = set up at least a 2gig server then figure out how to integrate with your site. On that level they aren't really comparible.
- em3rgent0rdr 10y agoPrivacyBadger blocked his Disqus embed. I think a good test of whether your site/blog is privacy conscious is to see if PrviacyBadger reports any tracker.
- jzl 10y agoUgh, thanks for this. I've made it a goal to start understanding all the little tricks and details of modern day tracking techniques that allow Facebook, Amazon, etc., to know everything that I do. Anyone know if there's a good one-stop-shop website for this topic? I've found lots of separate articles about the it but no central clearinghouse of information.
- GrinningFool 10y agoI'm reviving my blog, and currently plan to explicitly ask: 1. May we retrieve common libraries from third party CDNs? Doing so helps support this site by saving on our bandwidth costs, but may expose information about you to those third parties. 2. This site allows commenting through Disqus. We have no control over what Disqus does with your data, and so your information may be exposed to Disqus and any third parties they communicate with. Would you like to enable comments? 3. (Similar for tracking, if I decide to do something other than log parsing.) Default 'no' to all, and I still need to find a way to ask the questions in a way that doesn't disrupt simply viewing a blog post that someone linked. Perhaps if someone returns, I'll prompt then. Anyone have thoughts on if this sounds sane?
- d2p 10y ago1. If you're only interested in saving bandwidth and don't care about cache hits from overlapping with other sites, maybe you can host static content somewhere free (GitHub Pages?) or even just set a long cache header (ensure version numbers in filenames, cache for > 1 month) since presumably you're going to serve them the first time before the user has answered anyway? 2. I'm thinking of putting a "Click to load comments" box in place of Disqus on my blog so nothing gets loaded unless the user clicks. Seems better than bothering the user up-front. 3. I use Google Analytics - I figure it's common enough that if people don't like that, they'll already have it blocked, so there isn't really any additional tracking they won't want (unless the twitter timeline widget is tracking; which it might be, but I suspect I'll remove it soon anyway).
- Normal_gaussian 10y agoNotes; 1. Serving from github still shares the tracking information. It can be argued that github is better than cloudflare/facebook, however bear in mind github has politically motivated staff. Long cache is a great idea. Alternatively cut out unnecessary js. 2. Nice idea, it does hamper the ease of use of your blog though - I would never click to view, though I did read some that were visible when I finished the article. 3. Do you find the information from this useful? In a way that isn't trivially parsable from server logs? I ask because we are reviewing the quality of our user analytics, and our ga seems rather pointless atm.
- rasz_pl 10y ago>I’m certain Disqus could fix this, most likely they are getting paid for this tracking
- d2p 10y agoFWIW - Disqus commented on my article - there's a link to their comment right at the top of the article now.
- dmix 10y agoTLDR: it was because Disqus added the Facebook SDK in the last week or so, for some new feature they're testing. They're looking into this. ^ That sounds legit to me... I believe this was the primary reason why Facebook made an SDK and Like button in the first place...for data mining. Pretty clever. This is the consequence of building on a platform like FB, you exchange your visitors browsing habit data for access and FB expands their graphs of IP<>websites to improve their ad targeting. And with Disqus is won't be as obvious because the publisher might not be aware that it leads to an FB connection. So regardless if it was unintentional this is a relevant story for the trade offs of using platforms.
- the8472 10y ago> Troy cited tracking as one of the reasons for removing ads Ads should be loaded into <iframe sandbox referrerpolicy="no-referrer"> It would still give them some information (affiliate ID and user IP) but no cookies or tracking of user interaction with the page itself.
- pg_is_a_butt 10y agoof course microsoft directors are encouraging people to stop delivering ads... that is how google beat them. you thought he really cared about privacy? you're all idiots.
- sfblah 10y agoI think Ghostery stops this.
- grp 10y agoI believe ghostery is one of those kind of adblockers that checks if the ads and trackers target the right people, no? Sort of a meta-tracker. But maybe I'm too paranoid.
- Spooky23 10y agoIt's an unfortunate reality. Once Amazon figures out who you are, they send a feed of everything to you at or buy to FB.
- chubot 10y agoI noticed the same thing about a week ago when I was setting up comments for my blog [1]. I hate bloated websites, so I copied the Disqus markup and opened up Chrome dev tools, and saw the Facebook URL along with dozens of other resources being loaded. I ended up researching WAY too many comment systems, and eventually settled on Reddit. Not ideal, but better than all the alternatives. Blog commenting is pretty broken right now, I guess due to the dominance of social networks. I wanted to write my own blog comment service in rage but thought better of it. Disqus seems pretty sloppy. I was surprised to learn that they were an early YC company. [1] http://www.oilshell.org/blog/2016/12/29.html http://www.oilshell.org/blog/2016/12/29.html
- daurnimator 10y agoHow did you use reddit as a commenting system? It's something I've thought about before but didn't know someone has already built it
- ChristianBundy 10y agoI'm guessing they've just set up a subreddit, which they post in each time they make a new blog post. In the past I've seen "Join the conversation on Reddit: ${link}" at the end of blog posts, but maybe they're doing it differently.
- cinquemb 10y agoI'm not a user of reddit, nor familiar with their ins an outs, but does reddit allow for threads in an iframe? maybe that could be an option?
- daurnimator 10y agoAs the sibling poster suggests: I was thinking of somehow embedding a reddit comment thread onto the page. Either via an iframe (if you own the subreddit you can control the CSS on the other side to make it match), or some JS library that did XHRs to reddit's API.
- 10y ago
- foxhop 10y agoI'm working on an alternative to Disqus called Remarkbox - http://www.remarkbox.com http://www.remarkbox.com One of my early design decisions is to be as lightweight and fast as possible. This means no oauth, no ads, and only core features that you would expect to find in a comment system.
- ploggingdev 10y agoJust tried it out, very cool man. My suggestion would be to make the design more appealing, it looks a little bland now. And also promote the privacy oriented mission of the service a lot more. Currently there is no mention of privacy/tracking, you only mentioned no ads. And https is a must in 2017. Just a few question: * When do you plan to launch? * What is the backend built with? Good luck man.
- foxhop 10y ago* When do you plan to launch? I'm soft launching with beta users right now. * What is the backend built with? Python, Pyramid, SQLAlchemy (which supports PostgreSQL, Mysql, and SQLite3), uWSGI, Nginx, Ubuntu
- d2p 10y agoFor me, the problem is that the smaller a service is, the less reputation they have to lose by screwing everyone over. I don't know who you are or that you won't inject ads or affiliate links into my site in a few months (or sell your domain to someone for a few quid that will). (This doesn't mean I think your intentions are bad; I just think it's a bad idea to trust people you don't know on the internet!). I don't mind included scripts on my page from huge orgs that have a lot to lose by doing bad things but there aren't that many companies that fall into this (Disqus did, but possible shouldn't ;))
- foxhop 10y agoThat is an interesting point you bring up. The stigma that small businesses have to overcome when being, well small. I think for the most part recently the bigger companies are the ones putting one over on end users. (changing terms, shutting down services). I'm planning on building a business around this service, and reputation will matter. I don't plan to sell out because I eat my own dog food. I built Remarkbox for a personal itch, an itch I feel other people may also have.
- deleted 10y ago[deleted]
- rsync 10y agoJust a note ... It is possible for someone to say "hugs"[1] at the end of their discourse and still be a liar and a cheat and a terribly bad actor. No idea, of course, about any of these people - but don't let cost-free, content-free expressions alter your (bullshit/fraud) detector. [1] See comment on OPs blog from "disqus here"
- d2p 10y agoSure, I just posted a link to make it easy to find their comment. I'm giving them the benefit of the doubt that this is an accident and they're working on it, but I'll believe they care when the fix is live and I can see it with my own eyes :-)
- BYK 10y agoThanks for calling my honest reply a lie and me a liar, really appreciate it. I'm @madbyk on Twitter and you can also Google my full name to catch my other lies and bad acting on some of my recorded talks.
- d2p 10y agoToday Disqus deployed a fix for this issue; you can read their comment on the blog posts here: https://blog.dantup.com/2017/01/visiting-a-site-that-uses-disqus-comments-when-not-logged-in-sends-the-url-to-facebook/#comment-3091263180 https://blog.dantup.com/2017/01/visiting-a-site-that-uses-di...