4 ms·
I don't see what this has to do with Google Fonts, it's an aside at best. What's illegal is causing a user agent to send an HTTP request (to a third party) with
by anfogoat 4y ago
I don't see what this has to do with Google Fonts, it's an aside at best. What's illegal is causing a user agent to send an HTTP request (to a third party) without the operator's consent.
- waltbosz 4y agoYes, I am confused on this point as well. By this logic, it sounds like all forms of hotlinking would be illegal, not just fonts but images, js, css, etc. How does a modern website operate under this law? Are there other options besides: 1. locally hosted resources, 2. an annoying consent popup ? Tangent: I found this 2018 article about a list of websites that block visitors from GDPR countries. I wonder how many of these blocks are still in place today. I assume they were removed after the websites became GDPR compliance. https://econsultancy.com/gdpr-which-websites-are-blocking-visitors-from-the-eu-2/ https://econsultancy.com/gdpr-which-websites-are-blocking-vi...
- anfogoat 4y ago> Are there other options besides: 1. locally hosted resources, 2. an annoying consent popup? As far as I understand it, the only situation where you are allowed to send a third party request without consent is one where there are no other ways to achieve whatever the request is in service of, and that whatever itself has to be something you don't need consent for ofc. Assuming I've got that right, then that's a no for images, JS and CSS.
- spiffytech 4y agoYep - and it's not whether data transmission is necessary for what you want to do; it has to be necessary for what the user wants you to do.
- orev 4y ago> How does a modern website operate under this law? As someone who has seen the web evolve from basic pages to the apps of today, the way “modern websites” are currently built is absolutely horrific. Web developers don’t seem to have any qualms about pulling in random crap from random places, and those random places can pull in more crap. It makes it impossible to get a simple baseline for security without an army of people reviewing code, and the web devs just shrug and say “that’s how everyone does it now”. If these laws pour cold water on some of this and force web devs to shape up, that’s fine with me.