5 ms·
> How would you feel were someone to follow you around everywhere you went? On the Web, this happens already (try a browser add-on such as RequestPolicy which
by handinmouth 12y ago
> How would you feel were someone to follow you around everywhere you went?
On the Web, this happens already (try a browser add-on such as RequestPolicy which will show you the numerous sites that track you all over the Web - often 20 or more per page).
- MichaelCrawford 12y agoThat I find particularly creepy, so I blackhole many of the analytics servers with my /etc/hosts: 127.0.0.1 hosted-pixel.com 127.0.0.1 cdn.hosted-pixel.com When web bugs first appeared, there was a huge public outcry. Now that they call it "analytics" or "big data" everyone seems cool with it. However I can't block everything with hosts; some of the tracking scripts come from the same hosts as I actually use. I'm planning to write a firefox addon which will do stuff like remove the Facebook "Like" buttons. Even if I don't click the button, Facebook knows that it served me the script.
- maxerickson 12y agoAd block rules like this block content except on the home site: ||twitter.$domain=~twitter.com Additional domains can be unblocked: ||twitter.$domain=~twitter.com|~another.com
- MichaelCrawford 12y agoHey thanks - I owe you one.
- Panino 12y ago> Even if I don't click the button, Facebook knows that it served me the script. You can stop a lot of trackers by minimizing referer leaks. Firefox has the config option network.http.sendRefererHeader which defaults to 2, "always send referer." 1=same FQDN, 0=never send. So by setting it to 0 or 1, a typical tracker that's gotten past your /etc/hosts entries, adblock, etc. will see you requesting their pixel image but never see the sites that initiated those HTTP GETs. There are no silver bullets, just good tools, and reducing the referer footprint is one of them.
- JetSpiegel 12y agoYou can use Policeman https://addons.mozilla.org/en-US/firefox/addon/policeman/ https://addons.mozilla.org/en-US/firefox/addon/policeman/ Or on Github for a more bleeding-edge version https://github.com/futpib/policeman/releases https://github.com/futpib/policeman/releases
- dfc 12y agoI have always loved requestpolicy but for some reason something about RPContinued makes me nervous. Policeman would be a great alternative if Sync worked[^1]. I cant use policeman if it means I have to jump through the same hoops on every firefox installation in order to get things set up. [^1]: https://github.com/futpib/policeman/issues/28 https://github.com/futpib/policeman/issues/28 Plus issues 92 and 95.
- hrjet 12y agoThanks to @JetSpiegel I just became aware of Policeman. And I am not sure why you are nervous about RPContinued. So, I went ahead and created a wiki for this: https://github.com/UprootLabs/gngr/wiki/List-of-request-blocking-software https://github.com/UprootLabs/gngr/wiki/List-of-request-bloc... If there are any known issues with RPContinued or there are other extensions that are not listed, please feel free to add them. Thanks.
- dfc 12y agoWhat is the mysterious "switchboard" column?
- MichaelCrawford 12y agoThat's used by the phone company to patch you into the NSA.
- hrjet 12y agoThe name for the concept comes from the name of the HTTP-SwitchBoard extension (predecessor to uMatrix). It's skeuomorphic. The extensions which have a switchboard like interface enable the user to block requests based on the request's domain name, the primary frame's domain-name, and also the type of request. In contrast, extensions like NoScript have a global switch. If I allow scripts from DontBeEvil.com, they are enabled on all domains. They don't prevent XSS attacks, for example. If there's a better name for this concept, please do suggest one.
- singold 12y agoMaybe EFF's Privacy Badger could help? I use it and like it, you can unblock individual scripts on a per page basis. https://www.eff.org/privacybadger https://www.eff.org/privacybadger
- asuffield 12y ago> Now that they call it "analytics" or "big data" everyone seems cool with it. It generates massive value that everybody benefits from. People appreciate that.
- pdkl95 12y agoI wonder how much real value is actually generated from web bugs. A lot of interesting stuff can be generated from server logs; much more if you use analyzers. I just wonder how much of the set of "analytics" that requires involving 3rd parties (web bugs and other referrer tricks) is actually useful and a value. The set that is a value "that everybody benefits from" is going to be even smaller. I'm sure most people want this data, and see a lot of potential use. Usually, there is a big difference between "want" and "need", and I suspect a lot of the current attitude that throws analytics on everything is some experimentation, a limited amount of real value, and a whole lot of people joining in because they can (fad, bandwagon effect, it's what a tutorial said, etc).
- MichaelCrawford 12y agoI spend a lot of time analyzing my own logs. I get a lot of value from it. I am completely cool with someone analyzing their own logs if I visit their site. What I'm not cool with, is them finding out what _other_ sites I visit. I regard the current focus on analytics as unduly obsessive. How much do you need to know about your customer to flog your products? Just because you can measure something, it doesn't mean that it's going to do anyone any good to measure it. I used to do direct mail; all we ever did was what today is known as A/B testing - we'd send "test drops" to different lists, with different prices, different wording in the offer letters and so on. It worked really well.
- pdkl95 12y agoTo clarify my previous post, I'm totally fine with server-logs. As the 2nd-party to the conversation, the server has to know who the request is from, and can log it. These logs can certainly provide a lot of value. As you mention, I'm more concerned with tracking as a 3rd-party[1]. There is, obviously, at least some real benefit in these cases that would not be possible when only using server logs. It's probably a lot less than most people think. A lot of that data (or similar-enough data when measured in e.g. how much it benefits sales or makes marketing cheaper) can probably be found elsewhere. If we knew what the core benefits (needs, not wants), we might (in an ideal world) even be able to have some sort of social negotiation where the data can be provided in some form (or an alternative, or by making sure the real social cost is covered properly). [1] While the law currently doesn't work this way, involving a 3rd-party unauthorized should really be considered some new type of (criminal) wiretapping in states that require 2-party consent.