3 ms·
Last weekend I decided to remove all third party services/javascript from my website, replacing them with external links (for the share button or the contact fo
by luord 6y ago
Last weekend I decided to remove all third party services/javascript from my website, replacing them with external links (for the share button or the contact form), nothing (for google analytics[1]) or with web mentions (for disqus).
Not sure how viable it is since it was actually more work than I thought it'd be, but at least I feel better now about my site not loading external stuff and setting unnecessary cookies. Now I guess I should actually write more stuff to see if I get mentions (and to test how vulnerable to spam it is, I suppose). I haven't ruled out looking into other ways to implement federated comment systems—or similar, like web mentions—though[2].
[1]: That said, I'm using cloudflare so I guess I do get its analytics.
[2]: And there's always the self-hosted option.
- kstrauser 6y agoI set up a Matomo server and use it for my own analytics. I like the information it gives, and love that no one but me has access to any of the data.
- southerntofu 6y ago> remove all third party services/javascript from my website Congratulations on that! I personally believe it should be the foundation for any website, but well... > how vulnerable to spam it is, I suppose This depends on how you implement it. You may implement simple rate-limiting/quotas, manual verification, or go the fancy way and implement signatures and/or vetting (not widely implemented yet in the ecosystem). > I'm using cloudflare Please consider not doing that. It's even worse than having 3rd party JS on your website. At least with 3rd party JS, i can disable JS in my browser or use an adblocker. When you use Cloudflare, you ask a private company to strip & search every person who'd like to access your website, and many persons are stuck in the process. Cloudflare does have an option to let users from Tor access your website. But if you don't tick it, the default setting will leave all privacy-sensitive people at your doorstep, with a bad experience of your site. If JS is enabled, the CAPTCHA will loop forever driving us insane. If JS is disabled, the CAPTCHA won't even load. Cloudflare is one of the worst things that can happen to Internet freedom, by centralizing all communications (especially as part of a free tier that encourages many non-profits to move over) and terminating TLS connections on there. If you enjoy free-software, privacy and computing ethics, please never use any Cloudflare product or equivalent. If you have problems with DDOS, many hosting providers have very good solutions that do not infringe on your or your readers' privacy.
- XCSme 6y agoI also did that recently, I started writing a short blog post about how I did it without losing core functionality: https://www.usertrack.net/blog/self-hosted-alternative-3rd-party-scripts https://www.usertrack.net/blog/self-hosted-alternative-3rd-p...