-
Notifications
You must be signed in to change notification settings - Fork 568
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Website] remove trackers and embeds and make the site legal in the EU #4465
Comments
@D3V1LC0D3R commented 12 hours ago:
+1 to completely removing the following:
In the case of third-party embeds that require JavaScript (such as YouTube's),
One working example of the former that comes to mind is how GamingOnLinux does https://www.gamingonlinux.com/2021/08/impressive-free-and-open-source-rts-0-ad-alpha-25-is-out-now It contains the following at the very end:
Other than having an I don't know much about WordPress and I don't know how straightforward this |
@rusty-snake 's website rewrite solves this afaik.
|
@SkewedZeppelin commented 38 minutes ago:
Yes, the rewrite does not appear to be affected by this, but it's still WIP https://rusty-snake.github.io/firejail/ So while the wordpress site is considered the official/canonical one (which I |
Links to issues related to the rewrite for cross-reference: |
👍 The only third-partys are fonts.googleapis.com which can be removed and youtube.com which can be made click2play+youtube-nocookie.com or changed to first-party or peertube if we want. |
I don't think GDPR works like this at all, your interpretation would probably make most Wordpress pages or those which embed youtube videos sites illegal. For example, German Wordpress (https://wordpress.com/de/) links also to stats.wp.com and uses Google APIs and I think German interpretation of GDPR is stricter than some other EU countries. Can you point to legal analysis where third party resources in frame of GDPR are discussed? Having said that, removing trackers and/or switching away from Wordpress makes sense. |
Even the website of the "Bundesbeauftragter für den Datenschutz und die Informationsfreiheit" (en: Federal Commissioner for Data Protection and Freedom of Information; https://www.bfdi.bund.de) includes
Not sure if @D3V1LC0D3R mean that referring to the GDPR or as a privacy best practice.
(site rant) Had anyone said copyright? |
to my knowledge it is illegal in germany: https://usercentrics.com/knowledge-hub/non-compliant-cookie-banner/ |
EDIT: image source: https://www.finch.com/blog/cookie-consent-tools-and-nudging/ |
as a matter of fact github uses illegal data collection practices as well (they have an eventlogger and a browser fingerprinter without any consent) |
Well if you have a GH account you accepted GH's privacy statement, but if not ... |
no accepting a policy does not mean that a company do anything to you. You have to be well informed (or did you know that every github email includes a tracking pixel < img src="https://github.com/notifications/beacon/[ID].gif" height="1" width="1" alt="" / >) |
@rusty-snake commented on Aug 11:
That would be nice and to expand a bit on it: I'm more inclined towards just
Nice; click2play (/click2loadTheEmbed) would be the most important change IMO, I don't know about the pros/cons of youtube.com vs youtube-nocookie.com; the
A PeerTube mirror would be great (see #4076). If by "first-party" you mean comitting videos to a repository, I'm not sure if By the way, since there is no issue tracker in the rewrite repo, should we open |
I could enable it, however nobody will see it there.
https://www.ghacks.net/2018/05/23/why-you-should-always-use-youtubes-privacy-enhanced-mode/ |
I think you are confusing uses of cookies (and related requests) with links to third party sites. |
🚀 Third-parties are removed from https://rusty-snake.github.io/firejail/.
|
I use this:
You can find various variations of it online. |
i guess this is mostly solved, thanx |
Bug and expected behavior
When opening your webpage following trackers are loaded:
expected behaviour: ask before you load thirdparty resources or disable them completely
Reproduce
Steps to reproduce the behavior:
Additional context
i hope this was not intentional as you're literally breaking european law (GDPR)
Checklist
The text was updated successfully, but these errors were encountered: