5 ms·
That sounds like the entire internet is unlawful. How would a German access any content outside of Germany without going through the tens-hundreds of intermedia
by zebracanevra 4y ago
That sounds like the entire internet is unlawful. How would a German access any content outside of Germany without going through the tens-hundreds of intermediate routers? There's nothing stopping those routers from logging IPs going through them.
- kmeisthax 4y agoThe issue isn't the existence of intermediary routing, it's the export of data outside the EU by an EU site. A German resident that wants to access Google or any other US site is fine. The packets are allowed to exit the EU because that's what they asked for. Using Google Fonts means that your EU users have to access Google, a US company, in order to read your site. Most browsers are configured to do this automatically and opting-out of that would be time-consuming and break the whole web. And using Google Fonts gives Google the unprecedented ability to snoop on third-party sites. Yes, they have promised not to do this, but their host government has also promised to break Google's promise for them. Taking that same logic and applying it to intermediary routing, the only time in which you'd have a GDPR export case is if you tried to access an EU website and your traffic was rerouted into the US or China. Which actually happens way more often than it should.
- wildrhythms 4y ago>using Google Fonts gives Google the unprecedented ability to snoop on third-party sites What 'snooping' is happening during a CSS import?
- kmeisthax 4y agoHosting a subresource of another website gives you `Referer`, at the very least. And the set of fonts requested is fingerprintable even if your browser didn't send that header. You can also fingerprint the browser further to tie that information into your ad profiles. Google promises explicitly to not do this, and I believe them. However, they can still be compelled by law enforcement to break their own promise, and that's what the EU is reasonably angry about.
- account42 4y agoIrrespective of cross-origin caching, `Referer` should have been neutered long ago to always specify the base URL of the site hosting the resource (or killed entirely). Also Browsers should send exactly the same headers when in image and page contexts - if I want to view an image it means I want to view an image on its own and there should be nothing the site can do about it.
- kmeisthax 4y agoIf we lived in an alternate universe where the same-origin policy applied to all subresources from the get-go, then I would agree with you. But we don't. And in this universe - the one where every website can include subresources from any other by default - you absolutely need an opt-out to say, "no, I really don't want to host this one image for the entire WWW, just my own domain". Referer is that opt-out.
- account42 4y agoUser privacy should always override website concerns - we are talking about what user agents should do here. If there is sufficient reason to believe that users would benefit from restrictions on cross origin embedding then we can always define a new header like was done for X-Frame-Options (which of course user agents are free to ignore if the user wants that).
- Jack5500 4y agoI'm not saying that I agree with the current situation, but as of now it's risk for the developer to use Google Fonts. To answer your question more specifically, I guess you could argue that it's a layer problem. Lower layers can't prevent "leaking" your ip with the current state of the internet, upper layers can and should.
- jjulius 4y ago>... as of now it's risk for the developer to use Google Fonts. Couldn't the developer download and host the font locally instead of calling back to Google's servers to load the font?
- teknopaul 4y agoYes
- cardanome 4y agoYes. The person claiming Google Fonts would be "illegal" in Germany is misinformed. It is simply considered best practice to self-host Google Fonts now and you are absolutely safe doing so. The basics of privacy law is basically don't violate the privacy of your users for no good reason. There is no technical justification to use a Google's third party service for fonts, especially as that potentially allows Google to track users. (You could still use Google's hosting if you were to get prior user consent though. Just have a fallback font. That wouldn't be worth it though.) So yes, you can use third party services and CDNs on your website but it needs to be either technically necessary or you need for user consent beforehand.
- Jack5500 4y agoJust to make sure, I didn't say illegal, just unlawful. I agree with everything else you said.
- Archelaos 4y agoTo further contextualise the judgement: This was a trial before a medium level district court (Landgericht). So there has not yet been any landmark court decisions on this specific issue in Germany.
- LtWorf 4y agoThe point is: Do not use CDNs
- adzm 4y agoCaching does not even work like it used to with a cdn so self hosting things like fonts is preferable in general.