4 ms·
I'm not speaking in any official capacity, but to at least get the conversation started off with data, here's Google's public FAQ regarding the Fonts API privac
by dewitt 12y ago
I'm not speaking in any official capacity, but to at least get the conversation started off with data, here's Google's public FAQ regarding the Fonts API privacy policy:
https://developers.google.com/fonts/faq#Privacy
What does using the Google Fonts API mean for the privacy of my users?
The Google Fonts API is designed to limit the collection, storage, and use of end-user data to what is needed to serve fonts efficiently.
Use of Google Fonts is unauthenticated. No cookies are sent by website visitors to the Fonts API. Requests to the Google Fonts API are made to resource-specific domains, such as fonts.googleapis.com, googleusercontent.com, or gstatic.com, so that your requests for fonts are separate from and do not contain any credentials you send to google.com while using other Google services that are authenticated, such as Gmail.
In order to serve fonts as quickly and efficiently as possible with the fewest requests, we cache all requests made to our servers so that your browser only contacts us when it needs to.
Requests for CSS assets are cached for 1 day. This allows us to update a stylesheet to point to a new version of a font file when it’s updated. This ensures that all visitors to websites using fonts hosted by the Google Fonts API will see the latest fonts within 24 hours of their release.
The font files themselves are cached for one year, which is long enough that the entire web gets substantially faster: When millions of websites all link to the same fonts, they are cached after visiting the first website and appear instantly on all other subsequently visited sites. We do sometimes update font files to reduce their file size, increase coverage of languages, and improve the quality of their design. The result is that website visitors send very few requests to Google: we only see 1 CSS request per font family, per day, per browser.
We do log records of the CSS and the font file requests, and access to this data is on a need-to-know basis and kept secure. We keep aggregated usage numbers to track how popular font families are, and we publish these aggregates in the Google Fonts Analytics site. From the Google web crawl, we detect which websites are using Google Fonts, and publish this in the Google Fonts BigQuery database. To learn more about the information Google collects and how it is used and secured, see Google's Privacy Policy.
For further technical discussion of how Google Fonts serves billions of fonts a day to make the web faster, see this earlier tech talk from the Google Developers YouTube channel.
- justcommenting 12y agoThis particular issue has come up in previous HN discussions, but I would draw people's attention to innocuous and quite reasonable-sounding phrases like "need-to-know basis." What does that really mean for a company like Google, whose core business model fundamentally depends on extensively data-mining user information? "Need-to-know" could mean almost anything, or whatever Google wants it to mean. This is a classic Google privacy strategy: controlling the debate by defining the terms. Despite a reassuring policy, you, as the website visitor, don't get to decide these things and to the extent possible, the fact that this is even happening is abstracted away from most non-technical users. Another example of Google's brilliance in 'controlling the debate by defining the terms': policies like this cleverly (but wrongly) lead the reader to assume that cookies are the only way Google tracks users or correlates their activities. What about TLS-based tracking mechanisms, for example? But this is a problem that's bigger than Google. When information accumulates in distinct places, the value of exploiting that information always increases. Eavesdroppers naturally move to those places to exploit that information, sometimes with a legal backing (NSA/GCHQ) and sometimes without one (Aurora attacks, and other NSA/GCHQ activities). Even if you interpret Google's pronouncements charitably, it would be a mistake to assume that using the Google Fonts API can't or won't harm user privacy. Google is a massive target for essentially all eavesdroppers, and the Aurora attacks (and other breaches with lower profiles) show that the accumulation of information--even under reasonable-sounding terms like Google's--can still end up in the wrong hands, and can be an inherently dangerous thing for user privacy.
- dewitt 12y agoThis isn't my area of ownership, (and I actually agree with a number of things you said), but as far as I know it is exactly why Google goes out of its way to NOT retain those logs, and to explicitly NOT serve this traffic off of a domain that handles user cookies or other PII (i.e., separate by design from search or gmail, etc). It seems the original author didn't understand this, so it's worth calling out here clearly.
- blfr 12y agoGoogle, whose core business model fundamentally depends on extensive data-mining of user information? Does it? Try Googling from an incognito window on your neighbour's wifi. Use a live distro if you want to be completely sure. Are the results significantly different? Are ads any worse? I have tried a couple of tests like that (on other people's devices, etc) and the only noticeable use of that trove of data Google has about me is suggested searches from my search history. Google Now can also pull an article of interest every once in a while the same way. That doesn't mean they don't have the data and won't cough it up on government's request but there seems to be very little effective mining going on.