4 ms·
This particular issue has come up in previous HN discussions, but I would draw people's attention to innocuous and quite reasonable-sounding phrases like "need-
by justcommenting 12y ago
This particular issue has come up in previous HN discussions, but I would draw people's attention to innocuous and quite reasonable-sounding phrases like "need-to-know basis." What does that really mean for a company like Google, whose core business model fundamentally depends on extensively data-mining user information? "Need-to-know" could mean almost anything, or whatever Google wants it to mean. This is a classic Google privacy strategy: controlling the debate by defining the terms.
Despite a reassuring policy, you, as the website visitor, don't get to decide these things and to the extent possible, the fact that this is even happening is abstracted away from most non-technical users.
Another example of Google's brilliance in 'controlling the debate by defining the terms': policies like this cleverly (but wrongly) lead the reader to assume that cookies are the only way Google tracks users or correlates their activities. What about TLS-based tracking mechanisms, for example?
But this is a problem that's bigger than Google. When information accumulates in distinct places, the value of exploiting that information always increases. Eavesdroppers naturally move to those places to exploit that information, sometimes with a legal backing (NSA/GCHQ) and sometimes without one (Aurora attacks, and other NSA/GCHQ activities).
Even if you interpret Google's pronouncements charitably, it would be a mistake to assume that using the Google Fonts API can't or won't harm user privacy. Google is a massive target for essentially all eavesdroppers, and the Aurora attacks (and other breaches with lower profiles) show that the accumulation of information--even under reasonable-sounding terms like Google's--can still end up in the wrong hands, and can be an inherently dangerous thing for user privacy.
- dewitt 12y agoThis isn't my area of ownership, (and I actually agree with a number of things you said), but as far as I know it is exactly why Google goes out of its way to NOT retain those logs, and to explicitly NOT serve this traffic off of a domain that handles user cookies or other PII (i.e., separate by design from search or gmail, etc). It seems the original author didn't understand this, so it's worth calling out here clearly.
- blfr 12y agoGoogle, whose core business model fundamentally depends on extensive data-mining of user information? Does it? Try Googling from an incognito window on your neighbour's wifi. Use a live distro if you want to be completely sure. Are the results significantly different? Are ads any worse? I have tried a couple of tests like that (on other people's devices, etc) and the only noticeable use of that trove of data Google has about me is suggested searches from my search history. Google Now can also pull an article of interest every once in a while the same way. That doesn't mean they don't have the data and won't cough it up on government's request but there seems to be very little effective mining going on.
- lallysingh 12y agoHave a look: https://www.google.com/settings/u/0/ads https://www.google.com/settings/u/0/ads If you don't trust that, then a great way to find out what any advertising company knows about you is to act like an advertiser and look at what user data you can get. I don't mean call up google advertising and pretending that you're head of marketing at $BIGCOMPANY (you could, but it's not what I meant), but try looking at the product pages made for advertisers.
- justcommenting 12y agoYour comments seem to underscore how Google controls the debate by defining the terms on privacy issues. You seem to be saying "Concerned about privacy? You could check up on Google by acting like one of its advertising customers.." which sort of highlights the parties Google is most interested in being transparent with (for completely understandable business reasons). But of course in order to do that, you also have to have a login, cookie, etc. for a panel that Google controls, and that exposes only a tiny subset of the information it could most obviously and trivially correlate about user activities. These just aren't really things people trying to visit wordpress sites should have to consider..
- lallysingh 12y agoPlease see my other comments on this thread about privacy terminology, norms, etc. But yes, I think that when considering the debate, one should look at both sides for an honest understanding of what's going on. Tinfoil-hatting a login for intel gathering's a stretch. Please use whatever you feel necessary (e.g., TAILS) for keeping your privacy while doing a little recon on what google's offering about its users to advertisers. Ultimately, wordpress chose to refer to google for font loading. That's their choice and right, and it's what people reading wordpress will have to deal with.
- lallysingh 12y ago(not talking for google) Two quick points: - The fonts have to be hosted somewhere. And the more common the hosting site is, the better the browser cache behavior is. - The cache behavior prevents requests from going out. If the font is cached, then there's no web request going back to google. And there's no web request on the wire for NSA/GCHQ/Verizon to sniff. As for the terminology, I personally think that there should be some standards for defining the terminology and criteria, so that we can get human-readable privacy policies without getting uselessly vague, into a discussion of how some backend systems work, or into a giant mess of legalese.
- justcommenting 12y agoIt really depends on the relevant counterfactual; yours makes total sense from the vantage point of lots of developers, but I tend to prioritize privacy and autonomy. When I visit catphotos.wordpress.com, my intention is not to leak information to Google even though they have great fonts. My intention is just to visit the website. So the counterfactual I would frame the discussion with would be something more like self-hosting fonts by default and prioritizing privacy over performance (different strokes for different folks, and I realize it can be a significant performance hit). To respond to your "more common the hosting site is" comment, Wordpress is also extremely common, and they probably could have devised alternative solutions by making different trade-offs. Cache behavior resulting in fewer requests can be a double-edged sword, too: if you cache fonts with clients, you're probably also caching a bunch of other things that may decrease your privacy in other ways. There are many layers of indirection, especially with NSA/GCHQ/Verizon. I wouldn't argue that this and another services offered by Google don't add value for developers and even users (they absolutely do), but my argument is mainly that there are costs--maybe distant/abstract/indirect costs in terms of privacy/autonomy that are difficult to discuss in concrete terms, but costs worth considering nonetheless. I wish WordPress had been more thoughtful about the trade-offs they made.
- lallysingh 12y agoI agree with everything you say. I think that we're still very early in developing acceptable norms for privacy -- we'll sadly have to have real collateral damage before people wake up to it. I don't know how to proceed in developing the terminology, calculus, and as a result, standards and norms for good privacy without going either "screw it all, your reality is now public information" or "pre-paid gsm phone modem to tor/privoxy". It's the middle bit that has the reasonable space in there, but it's hard to track down and there are certainly different reasonable spaces there for different people. Ugh.