3 ms·
How are you going to block it "trivially" if you don't know which script to block? They recommend changing the name of the GTM script, and paired with changing
by probotect0r 5y ago
How are you going to block it "trivially" if you don't know which script to block? They recommend changing the name of the GTM script, and paired with changing the content slightly, you won't be able to tell which script is GTM and which is actually important to the functioning of the site.
- jacquesm 5y agoYou'll know that after loading the first couple of bytes though.
- _flux 5y agoSo they need to change the first couple bytes then, automatically. Essentially I don't understand how possibly could free adblocking lists defeat advertisers or trackers if they truly cared about them: simply have a system running with the latest adblock lists against their test site, and if it is able to filter them, have an engineer make a modification—or have the system automatically pull up a pre-made modification or even generate a new one. In addition, the content-driving JS and the site JS could be bundled in one and obfuscated. Best functioning filters are secret ones and thus only the technically minded minority has access to them.
- gizzlon 5y agoIf it's 99.99% the same I think we will manage :)
- coffeefirst 5y agoThis was my exact thought when I wrote that comment. Then I remembered Manifest v3. ITP, ETP, and plugins that can block requests based on heuristics will make pretty short work of this. In Chrome, come Manifest v3, plugins won't be allowed to. So... this is all uglier and more complicated than I thought.
- c0balt 5y ago+It's gonna be very hard to detect once they actually bundle up (which I suspect only a few will do) the tag manager and obfuscate
- dlubarov 5y agoWhere does Google recommend changing the name of the script? The author claims that they do, but their link just recommends self-hosting the script. In Google's recommended JS, the path is exactly the same, only the hostname is different ("www.googletagmanager.com" replaced with "<DOMAIN NAME>"). Self-hosting by itself might make blocking marginally more difficult, but there are other reasons to do it: - Browsers these days segment caches by origin, so there's no caching benefit to using Google as a CDN. - With HTTP2, a first-party request is likely to immediately go through an existing (multiplexed) connection, saving a handshake. - It's arguably better for privacy, as users and legislators seem to be concerned about links to Google leaking IPs (https://news.ycombinator.com/item?id=30135264 https://news.ycombinator.com/item?id=30135264).