3 ms·
> Everyone with a website needs to know some basic facts about their website: ... What other sites sent traffic to my website? No. If this product is capable o
by Reelin 6y ago
> Everyone with a website needs to know some basic facts about their website: ... What other sites sent traffic to my website?
No. If this product is capable of collecting that sort of data in the first place then it's not privacy first as far as I'm concerned.
> ... we don’t “fingerprint” individuals via their IP address ...
That _can't_ be true. How else would a single "visit" (their terminology) be tracked?
A self-hosted analytics solution (ex: https://github.com/mikecao/umami https://github.com/mikecao/umami) would allow you to actually preserve user privacy if you wanted to.
- xPaw 6y ago> If this product is capable of collecting that sort of data in the first place It's based solely on the http referer, which your browser sends.
- Reelin 6y agoThe post specifies that the referrer is used for computing their "visit" metric (for which IP would also obviously be needed). It doesn't specify how their service is determining the site you came from. Since they don't say, my assumption is that they're correlating data obtained in some other way because that seems to be par for the course at this point. Note that referrers are self reported, so there's an incentive for such a service to avoid relying on them. Each web site can set its own desired referrer policy, and users can further configure when, if, and how their browser sends referrers. (For example, Firefox has referer.XOriginPolicy and referer.spoofSource among other preferences.)
- xPaw 6y agoReferer includes the site you came from, what am I missing? > Each web site can set its own desired referrer policy Yes, and it won't be able to tell which site you come from if it's set to no-referer.
- Reelin 6y ago> Referer includes the site you came from, what am I missing? I never claimed otherwise? There are two separate metrics in question here. One is the "visit" metric which the post specifies is based on the referrer. The other is quantifying which other sites sent traffic your way. The post conspicuously fails to define how that second metric is computed. For that second metric, I noted that there is an obvious incentive to avoid using the referrer and that the current status quo is to rely on other methods. (In particular, fingerprinting combined with centralized analytics services that have vision into a vast amount of traffic. Note that Cloudflare easily qualifies here given the sheer number of assets and websites they host.) If the entirety of this analytics service is based solely on referrers coupled with IP addresses then the author should unambiguously state that up front. Otherwise I'm going to assume the worst for the reasons given above.
- codazoda 6y agoI'm as skeptical as others here but they do define a visit... "A visit is defined simply as a successful page view that has an HTTP referer that doesn’t match the hostname of the request. This tells you how many times people came to your website and clicked around before navigating away, but doesn’t require tracking individuals."
- Reelin 6y ago> and clicked around before navigating away You can't get that part without using either the IP or a fingerprinting method. (For what it's worth, I don't mind IP based analysis so long as the data isn't shared with third parties. I also don't consider IP analysis to be "fingerprinting" since it seems analogous to a name to me. I was just calling out what seemed to be an obvious error in the post.)