Google Analytics Opt Out(tools.google.com)
tools.google.com
Google Analytics Opt Out
https://tools.google.com/dlpage/gaoptout
175 コメント
"Access your data for all websites" is just a label, it does not imply what you think in the context of this addon. You can actually read the entire code, it's very concise.
The current code, though.
I suppose it's possible for Google to push new versions of the plugin, so you'd have to review each of them. Does the user even get notified when a new version is pushed?
This plugin makes no sense, any informed user who cares enough about privacy to install would go for a more generic blocker anyway, such as uBlock Origin
I suppose it's possible for Google to push new versions of the plugin, so you'd have to review each of them. Does the user even get notified when a new version is pushed?
This plugin makes no sense, any informed user who cares enough about privacy to install would go for a more generic blocker anyway, such as uBlock Origin
> Does the user even get notified when a new version is pushed?
No, but the browser (in this case Firefox) is supposed to check the updates before deployment, even if only superficially.
It's also a double-edged sword, because sometimes there's an important update to the add-on that's stuck waiting to be reviewed, making the add-on useless for a couple of days.
No, but the browser (in this case Firefox) is supposed to check the updates before deployment, even if only superficially.
It's also a double-edged sword, because sometimes there's an important update to the add-on that's stuck waiting to be reviewed, making the add-on useless for a couple of days.
This reminded me of one argument I had about a legal contract one company wanted me to sign. Dropping all the legalese, the contract was roughly this: "You have no rights. We have all the rights. This contract is perpetual in eternity." After I had brought up my concerns, their representative used almost the same words that "it does not imply what you think in the context..." I figured that either they were fools or they thought I'm a fool, but in either case I'd better leave the table.
See feudalism: Serf, Oath of Fealty
> By the Lord before whom this sanctuary is holy, I will to N. be true and faithful, and love all which he loves and shun all which he shuns, according to the laws of God and the order of the world. Nor will I ever with will or action, through word or deed, do anything which is unpleasing to him, on condition that he will hold to me as I shall deserve it, and that he will perform everything as it was in our agreement when I submitted myself to him and chose his will.
> By the Lord before whom this sanctuary is holy, I will to N. be true and faithful, and love all which he loves and shun all which he shuns, according to the laws of God and the order of the world. Nor will I ever with will or action, through word or deed, do anything which is unpleasing to him, on condition that he will hold to me as I shall deserve it, and that he will perform everything as it was in our agreement when I submitted myself to him and chose his will.
What do you mean by it is just a label? Does it not grant the extension access to all sites I visit, along with passwords and cookies?
You'd think the people who read this site would be more internet literate.
"Download this browser extension so we won't track you without consent" isn't a very good proposition no matter how internet literate you are. I'd argue that the very concept of internet literacy is broken if any of this sounds normal to you.
> "Download this browser extension so we won't track you without consent" isn't a very good proposition no matter how internet literate you are.
If said browser extension actually doesn't track you, this is a non-sequitur.
Hard to argue an extension tracks you if the single only thing it ever does is print "Hello" on top of every page you visit... still that extension would need to be able to access and modify every site you visit by definition.
The exact same thing is happening here.
If said browser extension actually doesn't track you, this is a non-sequitur.
Hard to argue an extension tracks you if the single only thing it ever does is print "Hello" on top of every page you visit... still that extension would need to be able to access and modify every site you visit by definition.
The exact same thing is happening here.
The web extension honor system "security" model is broken because that extension that prints Hello at the top of the page might later be modified by a malicious actor to do something else [1].
[1] https://www.reviewgeek.com/45420/over-70-chrome-browser-exte...
[1] https://www.reviewgeek.com/45420/over-70-chrome-browser-exte...
I suppose, but I don't want to download it, so I won't. Much like I wouldn't try to delete Bonzi Buddy by downloading the Bonzi toolbar. This is just a JavaScript block (for now) but I have no idea what it means internally and having an insignia that reports back to Google everywhere I go sounds kind of like the thing I was trying to avoid in the first place.
Cannot agree more. uBlock or piHole would be much better.
I believe uBlock requires the same permission
To be fair, last time I checked, Firefox permissions system is not much granular.
Why do I need to trust and install a browser extension for this?
Why can't the same thing be achieved by using HTTP headers. E.g. like the do-not-track header was supposed to work?
Or by blocking dns lookups or an ip-range?
Why can't the same thing be achieved by using HTTP headers. E.g. like the do-not-track header was supposed to work?
Or by blocking dns lookups or an ip-range?
As someone who doesn't admin any sites with GA, what is generally being tracked with it that this would block?
I use uBlock in Chrome, and Blokada on my Android phone. Works great and highly recommend
Notably not available on mobile, where all the action is these days.
And it doesn't work on mobile. Which means if you want to be GDPR compliant you need to write your own opt-out anyways.
If GDPR is a concern, it has to be opt-in, so it wouldn't be compliant in any case.
The link is showed "404 error"
Did you get it to work eventually? The idea is that there is a google browser extension to stop all google analytics, for most of the browsers available
It works for me. https://pasteboard.co/JFaFhgI.png
Universal analytics opt out: https://github.com/gorhill/uBlock
Not that quick. Third-party analytics masquerading as first-party analytics is a thing: https://github.com/SukkaW/cloudflare-workers-async-google-an...
> Recently cloudflare-workers-async-google-analytics has been blocked by EasyList. Great Job though. So I am going to play a cat & mouse game now.
It was blockable, but the author decided to rename the file to jquery.js.
It was blockable, but the author decided to rename the file to jquery.js.
So they start to use malware techniques to get into your computer...
I'm retaining myself to quote the famous "If it looks like a duck, moves like a duck...", but I won't. :-)
That's another reason to use LocalCDN[0].
[0]: https://addons.mozilla.org/en-US/firefox/addon/localcdn-fork...
I'm retaining myself to quote the famous "If it looks like a duck, moves like a duck...", but I won't. :-)
That's another reason to use LocalCDN[0].
[0]: https://addons.mozilla.org/en-US/firefox/addon/localcdn-fork...
I see that LocalCDN is a fork of Decentraleyes [0]. Personally I'm very careful with the extensions I install in my browsers, but the new features of LocalCDN are interesting, I hope they get picked up by upstream at some point.
[0] https://decentraleyes.org/
[0] https://decentraleyes.org/
> So they start to use malware techniques
It is a spectrum, not mutually exclusive.
Ads are inherently 'mal-', in that you didn't ask for them and don't want them.
Javascript provides the '-ware'. And the question is really if they're just there to distract you or do something worse to your machine.
It is a spectrum, not mutually exclusive.
Ads are inherently 'mal-', in that you didn't ask for them and don't want them.
Javascript provides the '-ware'. And the question is really if they're just there to distract you or do something worse to your machine.
Woah, that guy seems dead set on providing Google with everyone's metadata for some reason. As if we didn't have enough to worry about on the internet.
I think people are starting to catch up on why security-minded devs were always critical on depending on JS for so many silly things (displaying texts and images, seriously?)
Still far more efficient that Google's opt out tool.
And the most efficient would be not opting out. Analytics are actually beneficial as they drive support for the type of browser and OS used.
I'd like to understand how opting-out of Google Analytics would spare you much from the massive big data tracking done via other JS libraries, ads, and especially mobile app use.
Go onto any large news site, ecommerce platform, realty/home search site, etc. and look at the network tab in your Web Developer view. Commerce may in good part "run" the world, but that traffic will expand as bandwidth expands; what data will they want to track next? => using cameras and audio everywhere to determine what your mood is, what you're talking about, what you say you want. Anything with a mic or camera could be doing this today, in theory, but the bandwidth isn't there to support it.
How can we avoid this?
Should we stop WiFi and just wire our homes well, then plug-in and enable cellular data only when we sit down or really need it?
It seems almost unavoidable, and that we've become too reliant on these things if privacy is the goal. And the bureaucratic EU policies on privacy seem like a simple game of chess for big data companies; we're responsible for this.
I'd like to understand how opting-out of Google Analytics would spare you much from the massive big data tracking done via other JS libraries, ads, and especially mobile app use.
Go onto any large news site, ecommerce platform, realty/home search site, etc. and look at the network tab in your Web Developer view. Commerce may in good part "run" the world, but that traffic will expand as bandwidth expands; what data will they want to track next? => using cameras and audio everywhere to determine what your mood is, what you're talking about, what you say you want. Anything with a mic or camera could be doing this today, in theory, but the bandwidth isn't there to support it.
How can we avoid this?
Should we stop WiFi and just wire our homes well, then plug-in and enable cellular data only when we sit down or really need it?
It seems almost unavoidable, and that we've become too reliant on these things if privacy is the goal. And the bureaucratic EU policies on privacy seem like a simple game of chess for big data companies; we're responsible for this.
I don't run any analytics on my personal site. I just use awstats and web logs.
Add https://github.com/yourduskquibbles/webannoyances to get rid of cookie banners, sticky headers, dickbars, app banners, social icons, modal popups, and more.
That just blocks common Javascript ad scripts and trackers. It doesn't block sites tracking analytics via server logs.
Just for lazy devs. :-) Use https://github.com/jehna/ga-lite to add Google Analytics to your page JS bundle and then proxy calls to the magic pixel so they look like they're first party. Nobody does this I guess because the rate of analytic blocking is low enough that it's not worth caring, but it's pretty easy to do.
Analytics opt out for your entire network: https://pi-hole.net/ /scnr
Except Pi-Hole has some serious limitations as it only acts as a DNS server.
I haven't been able to block Youtube ads on my tv for example.
I haven't been able to block Youtube ads on my tv for example.
The easiest way to avoid YouTube ads is to avoid using the YouTube website and its "Javascript player" to play videos. The Google Video download URLs to watch the video, without any ads, are right there in the hxxp://www.youtube.com/watch?v=xxxxxxx webpage. I use a tiny shell script of only 97 characters to extract them. The truth is, where YouTube ads are concerned, neither a modified dnsmasq plus RPi so-called "Pi-Hole" nor any browser extension "ad blocker" is required. No user needs to run Javascript to play videos just like no user needed to run Adobe Flash to play videos. Flash and Javascript are useful, maybe even essential, for tracking and advertising, but are unnecessary for playing video.
I would love to observe you browsing and consuming web content for a day. Sounds like this sort of thing would make it much more laborious. That being said.. could be a good thing for me to not spend so much time watching dumb YouTube videos, and reading "fun" articles.
Wikipedia hasn't been tainted like everything else. I can spend all night reading Wikipedia, and it's way more interesting than most content online. All they do is ask me for $3 every once in a while, and while I'm actually really poor... I still gave 'em $3 out of my cigarette money. I would've never had the confidence to go back to school if that resource wasn't there (or even had the realization that I love learning), but I also wouldnt wake up in the afternoon to see stuff in my browser history like "7:03 AM: Polar Bear Jail", so it's a trade-off. Beats YouTube, though
Linkified, for the other aficionados of ursus maritimus out there:
https://en.wikipedia.org/wiki/Polar_bear_jail
PS: You might enjoy Veritasium (a YouTuber).
https://en.wikipedia.org/wiki/Polar_bear_jail
PS: You might enjoy Veritasium (a YouTuber).
Perhaps not aficionados... polar bear jail is a complicated solution to a polar bear problem. The ethics of their incarceration is left as an exercise to the reader
Yeah, I can bounce from one thing to another there just soaking up info for hours.
After all these years of doing that I finally visited the Wikipedia Home page a few weeks ago. I was quite surprised with all the stuff they have there that I had no idea about. That rabbit hole is a lot bigger than I knew about.
After all these years of doing that I finally visited the Wikipedia Home page a few weeks ago. I was quite surprised with all the stuff they have there that I had no idea about. That rabbit hole is a lot bigger than I knew about.
My dad's house is on Wikipedia, and we didn't find out until half a decade after he'd bought it. Reason being it's on the historical register, nothing spooky. But, boy, was I jazzed to see a picture of the house I was sitting in with a little map under it on Wikipedia. I felt so documented.
I remember reading that by following hyperlinks in Wikipedia articles, all Wikipedia pages can be indirectly linked back to the page for "Psychology".
>Wikipedia hasn't been tainted like everything else.
The illusion of purity allows corruption to thrive. There are influence teams hired by VIPs who use Wikipedia as simply an extension of cable news/social media. To "get out in front of stories", or if they're late to the game, to scrub/"memoryhole" undesired ones. Wikipedia editing as an amusing hobby for niche nerds is an outdated concept for many topics.
Wikipedia is far too powerful a Persuasion tool to let fail. Its essay-long donation plea's are designed to garner credibility towards innocence. How nefarious could the site be? They're scrounging around for scraps each year!
The illusion of purity allows corruption to thrive. There are influence teams hired by VIPs who use Wikipedia as simply an extension of cable news/social media. To "get out in front of stories", or if they're late to the game, to scrub/"memoryhole" undesired ones. Wikipedia editing as an amusing hobby for niche nerds is an outdated concept for many topics.
Wikipedia is far too powerful a Persuasion tool to let fail. Its essay-long donation plea's are designed to garner credibility towards innocence. How nefarious could the site be? They're scrounging around for scraps each year!
I think it's understood that controversial topics and current events on Wikipedia are subject to manipulation. But I don't think TPTB are committing payroll to influence my opinion of "Ben Franklin" or "Norwegian Forest cat" or "semipermeable membrane".
It is a predominantly text-only experience. I almost never consume articles from a graphical browser; I do not require images in order to read. With YouTube, either I am downloading videos that others point out by sharing a URL, or I am searching for videos on YouTube from the command line, then downloading. I get no real benefit from using a graphical browser to interact with YouTube, although I am sure Google's online advertising services business gets many benefits.
>>The easiest way to avoid YouTube ads
I found the actual easiest way to avoid YouTube ads, and maintain support for content providers whose services I enjoy, is to get a Premium subscription. ¯\_(ツ)_/¯
I found the actual easiest way to avoid YouTube ads, and maintain support for content providers whose services I enjoy, is to get a Premium subscription. ¯\_(ツ)_/¯
The only way that works as a "business" is if Google also sells online advertising services. Nevertheless, the company must sell online advertising services as a business model in order to survive. This makes it arguable that the company is actively working against users supporting content providers by paying ("supporting") them directly. Google functions as a middleman selling online advertising services. It pays content providers a cut from the ad revenue, not from relatively small fees collected from a relatively small number of users who want pay an advertising company not to bother them. Depending on how much hazard risk one assigns to online advertising and the destruction of privacy by monopolistic actors that are seemingly immune from legal regulation and able to operate outside the law, this could be seen as some sort of "protection money". https://en.wikipedia.org/wiki/Protection_racket
Ideally signing up via India. Fortunately, I got an Indian wife with a local payment method and a VPN. Now I am paying roughly 90 euro cents per month for a student subscription, as both discounts can be combined ;)
>"I use a tiny shell script of only 97 characters to extract them."
Would you mind sharing the script?
Would you mind sharing the script?
For something like Firefox, pulling them out of exported bookmarks is as simple as:-
grep "https://www.youtube.com/watch?v=" /tmp/bookmarks.html | cut -b22-64
grep "https://www.youtube.com/watch?v=" /tmp/bookmarks.html | cut -b22-64
Why not just use https://youtube-dl.org/
Typo. 997 characters according to wc -c.
This is the one hole I haven't been able to fill. Between guilt about not contributing to people's channels which I genuinely enjoy and the ads on the tv, I commited to buying premium next year.
Seems like you would need a pi-hole alternative that acts like a proxy. I imagine there is something like that out there, just not familiar with the choices.
There is privoxy - https://www.privoxy.org/
However, as most sites are https nowdays, privoxy is effectively limited to just blocking domains, making it pretty similar to pihole ...
However, as most sites are https nowdays, privoxy is effectively limited to just blocking domains, making it pretty similar to pihole ...
Yeah would need a proper MITM setup to deal with the https
You can set your router with a firewall NAT rule to capture all DNS requests and redirect them to use Pi-Hole. Your tv will think it talks to 8.8.8.8 when in reality it will talk to your server.
doesn't stop dns over https, which stuff like chromecast employs
And that's why DNS over HTTPS was created in the first place, to get rid of ad blocking on Chromecast and Android.
On Android now Proxies don't apply anymore to apps like YouTube, and as these apps also use DoH, there's no way to block ads anymore.
All talk of "security" and "privacy" is false, as always it was all about profit. I honestly wonder if the people at Google working on DoH even knew why management supported their project, or if they genuinely believed they did something good while management secretly realised the potential profits from DoH
On Android now Proxies don't apply anymore to apps like YouTube, and as these apps also use DoH, there's no way to block ads anymore.
All talk of "security" and "privacy" is false, as always it was all about profit. I honestly wonder if the people at Google working on DoH even knew why management supported their project, or if they genuinely believed they did something good while management secretly realised the potential profits from DoH
Well, it's not like they were forced to do name resolution over DNS before... They could just as well deploy their own custom name resolvers and talk to them via IP from applications like YouTube for Android.
The scenario you're describing (DNS-level blocks) could always be circumvented.
On the other hand, if you live in the US and don't override the ISP's name servers, most probably they will spy on you and sometimes even do things like injecting ads into third party websites. This was the thing DoH was meant to solve.
The scenario you're describing (DNS-level blocks) could always be circumvented.
On the other hand, if you live in the US and don't override the ISP's name servers, most probably they will spy on you and sometimes even do things like injecting ads into third party websites. This was the thing DoH was meant to solve.
> They could just as well deploy their own custom name resolvers and talk to them via IP from applications like YouTube for Android.
The Chromecast has 8.8.8.8 hardcoded, but recently an ISP started integrating ad-blocking via DNS filtering (with 8.8.8.8 MitM) in their ISP routers. That case actually went to court.
It'll always be possible to do the filtering as prosumer, but the current state of the art of "it just works" ad blockers is something Google is fighting against (also see Manifest v3)
The Chromecast has 8.8.8.8 hardcoded, but recently an ISP started integrating ad-blocking via DNS filtering (with 8.8.8.8 MitM) in their ISP routers. That case actually went to court.
It'll always be possible to do the filtering as prosumer, but the current state of the art of "it just works" ad blockers is something Google is fighting against (also see Manifest v3)
Your response to the first scenario didn’t invalidate it - Google could have made a https://dns.google.com endpoint in 2013 before DOH and only allowed the Chromecast to work if it could get dns responses from there.
Yeah but that would require developers intentionally building an anti-adblock solution, while funding a solution like DoH allows Google to save face
What percentage of Google's users do you think have a pi hole? I buy that their changes to ad blockers in Chromium are motivated by this kind of logic, since they are used by a material number of people. But for DoH it just doesn't add up, it's such a fringe case. It's also worth noting that DoH was spearheaded by Mozilla, Google just got on the ship at the next port.
Not every thing that big corporations say they do for security reasons or whatever is a cynical ploy. Do you think they're experimenting with post quantum cryptography in Chrome Canary in preparation to drop a 50k qubit quantum computer on the market sometime soon?
Not every thing that big corporations say they do for security reasons or whatever is a cynical ploy. Do you think they're experimenting with post quantum cryptography in Chrome Canary in preparation to drop a 50k qubit quantum computer on the market sometime soon?
Some ISPs started integrating pi-hole functionality into their ISP routers, and that actually went to court.
On Android, some of the most popular apps are fake-VPNs which just register your own device as VPN with itself so they can filter ads.
This isn't about the pi-hole, this is about ad blocking becoming "too easy". You can always block DoH. But no ISP can include such a blocker by default easily anymore.
On Android, some of the most popular apps are fake-VPNs which just register your own device as VPN with itself so they can filter ads.
This isn't about the pi-hole, this is about ad blocking becoming "too easy". You can always block DoH. But no ISP can include such a blocker by default easily anymore.
Wait, how do you block DoH without blocking other HTTPS traffic?
Do you have to block every known DoH server? Looking at Google's DoH certificate they list quite a few hostnames and IPs as Subject Alt Names:
Do you have to block every known DoH server? Looking at Google's DoH certificate they list quite a few hostnames and IPs as Subject Alt Names:
dns.google
*.dns.google.com
8888.google
dns.google.com
dns64.dns.google
2001:4860:4860::64
2001:4860:4860::6464
2001:4860:4860::8844
2001:4860:4860::8888
8.8.4.4
8.8.8.8
Issued by Google Trust Services...Google is digging as many moats as they can without triggering antitrust scrutiny. They have to plan for the future, not the here and now.
One could redirect any traffic destined for the IP of the DOH server to one's own DOH server on localhost.
Unlike DNS over TLS, and plain old DNS, the only way to 'redirect any traffic' is to have a blocklist of known DoH hosts, since it's just HTTPS, port 443, traffic, you can't tell if it's your page load or a DNS query.
As of today, how many DOH servers are running from IP addresses also used for serving websites. In the testing I have done with publicly advertised DOH servers, generally, the IPs are only used for DoH (sometimes DoT, too). Of course this could change.
The localhost forward proxy I use can distinguish DoH requests from other HTTP requests because the DoH query URL structures used are mostly the same; they follow RFC8484. As of today, it is easy to probe IP addresses for listening DoH servers. The list of "known DoH hosts" is still quite small. Of course this could change.
To be clear, I am defintely not a proponent of applications ignoring user system-wide DNS settings and using DoH to obscure that fact. I have long run localhost root and DNS for myself and have no need for third party DNS, whether ISP or open resolvers.
However, as an end user I see no reason to trust any outgoing HTTPS traffic from applications authored by folks who are agreeable to online advertising as a business model.
The greatest threat I face is online advertising, not DNS lookups associated with malware. With DoH, HTTPS traffic could contain an unwanted DNS request, but prior to DoH it could also contain data to be used for tracking and advertising purposes. I felt the need to start monitoring/MITM'ing the HTTPS traffic on the private networks I control long before anyone proposed DoH. I would guess many corporations and other organisations do the same.
The localhost forward proxy I use can distinguish DoH requests from other HTTP requests because the DoH query URL structures used are mostly the same; they follow RFC8484. As of today, it is easy to probe IP addresses for listening DoH servers. The list of "known DoH hosts" is still quite small. Of course this could change.
To be clear, I am defintely not a proponent of applications ignoring user system-wide DNS settings and using DoH to obscure that fact. I have long run localhost root and DNS for myself and have no need for third party DNS, whether ISP or open resolvers.
However, as an end user I see no reason to trust any outgoing HTTPS traffic from applications authored by folks who are agreeable to online advertising as a business model.
The greatest threat I face is online advertising, not DNS lookups associated with malware. With DoH, HTTPS traffic could contain an unwanted DNS request, but prior to DoH it could also contain data to be used for tracking and advertising purposes. I felt the need to start monitoring/MITM'ing the HTTPS traffic on the private networks I control long before anyone proposed DoH. I would guess many corporations and other organisations do the same.
Not if the resolver is validating the tls certificate. That's the point of doh, make impossible to intercept dns query.
MitM is not possible with DOH if the client checks for a valid certificate.
youtube-dl for that
[deleted]
If you use android TV, you can install https://github.com/yuliskov/SmartTubeNext
that does not support casting as far as I have tried unfortunately.
No app can accept casts.
When your are using Google Cast, you don't stream from your device to the TV/Chromecast. Your device sends a package containing the app name you want to open and some basic configuration data and then the TV/Chromecast downloads a web app from Google's severs and opens it with the configuration you provided. Then your device can interact with it.
When your are using Google Cast, you don't stream from your device to the TV/Chromecast. Your device sends a package containing the app name you want to open and some basic configuration data and then the TV/Chromecast downloads a web app from Google's severs and opens it with the configuration you provided. Then your device can interact with it.
Short of installing a third-party application like smartyoutube or vanced, you are not going to be successful in blocking YouTube ads. YouTube caught up with dns filtering ad-blockers and started placing their ads in the same domain as the video content.
Ublock Origin seems to be working for me. I don't use YouTube that often, but I've never seen an add that I can remember.
Edit: I guess maybe you're just talking about on a smart TV.
Edit: I guess maybe you're just talking about on a smart TV.
ublock origin can do url based filtering, which can't be done via something like pihole where it's only at the dns level.
Thanks for the clarification. I've been using UBO for a long time and sort of take it for granted. It's pretty amazing how thorough it is. The school system I work for pushes out Addblock to all of their Chrome devices, and it doesn't even come close.
There's another solution to avoid ads that people seem to skip : get yourself a youtube premium membership. You can spread the cost across your family, and you'll stop playing cat and mouse (at least on youtube)
Note that I'm not against ad blocking in general, but if you use a website a lot, it seems fair to me to remunerate it one way or another, and at least paying for membership is not a business model based on selling your data.
Note that I'm not against ad blocking in general, but if you use a website a lot, it seems fair to me to remunerate it one way or another, and at least paying for membership is not a business model based on selling your data.
But it costs you, and they still collect your data and will sell it for ads elsewhere.
Ublock on PC, youtube vanced on android!
Ublock on PC, youtube vanced on android!
Not a stretch to assume the data on one who pays for Youtube Premium is more desired than one who does not. 'Whales' to use a term in the mobile gaming market.
Why not pay for premium?
While that works it's not quite as sophisticated as u-Block's method of replacing the offending javascript with a dummy to avoid breaking webpages.
Is that approach needed to disable Google Analytics.
Not necessarily but it helps prevent errors from JavaScript that depends on google analytics.
Use both!
Not a bad idea. Wonder how long they have hidden this add-on since this is the first time I'm hearing about it having been in existence for over an year now. Though for some reason I still don't trust Google to keep their word.
I think uBlock is more than adequate in blocking these & so much more trackers which are so prevalent.
I think uBlock is more than adequate in blocking these & so much more trackers which are so prevalent.
That's the reason you haven't heard about it, it's irrelevant considering there are over a dozen better extensions for this that do more than block GA.
I don't know why i should install this other than criminal activity. GDPR requires you to opt-in, so I don't need to opt-out.
Because websites can't be trusted to follow GDPR
that's what I mean with criminal activity.
GDPR is a civil law not a criminal law. Secondly, not all websites fall until GDPR as it's an EU law and not a global one.
GDPR applies to any organisation operating within the EU, as well as any organisations outside of the EU which offer goods or services to customers or businesses in the EU.
In a similar manner, most laws in the US regarding the internet don't use phraseology like "American Citizens" or "People who live in the United States" and instead use words like "Persons" or "One", so in theory they also apply outside of the US however since the US has no jurisdiction to enforce those laws, they don't in real terms.
Take a look at the CAN-SPAM act[0], then at your spam folder for an example of how this played out.
[0]https://en.wikipedia.org/wiki/CAN-SPAM_Act_of_2003
[0]https://en.wikipedia.org/wiki/CAN-SPAM_Act_of_2003
Yes, which is not all websites. And it's not just offering goods and services but having a large customer base. It was specifically designed not to apply to small companies in other countries. For example, if you're a local newspaper website in Ohio, then GDPR does not apply to you. And it only applies to EU cizitens, it's just that it's so hard to realise who is a EU ciziten when they're within the EU that it's easier to just apply the same measures to everyone.
It applies to everyone in the EU. If you're an American inside an EU country using the local wifi, you're covered by the GDPR
It applies to small companies just as much as to large companies. However if you're not really marketing to people in EU countries, the GDPR doesn't apply. So a local newspaper in Ohio need not worry about the occasional European visitor, but The Washington Post definitely does
It applies to small companies just as much as to large companies. However if you're not really marketing to people in EU countries, the GDPR doesn't apply. So a local newspaper in Ohio need not worry about the occasional European visitor, but The Washington Post definitely does
> It applies to everyone in the EU. If you're an American inside an EU country using the local wifi, you're covered by the GDPR
As far as I know GDPR states EU citizens not people within the EU. Member states' laws will cover everyone however GDPR is for EU citizens globally since that is their remit.
> It applies to small companies just as much as to large companies. However if you're not really marketing to people in EU countries, the GDPR doesn't apply. So a local newspaper in Ohio need not worry about the occasional European visitor, but The Washington Post definitely does
Basically you argree with what I wrote but wrote it in a way to make it look like I stated something incorrect. Why did you do that?
As far as I know GDPR states EU citizens not people within the EU. Member states' laws will cover everyone however GDPR is for EU citizens globally since that is their remit.
> It applies to small companies just as much as to large companies. However if you're not really marketing to people in EU countries, the GDPR doesn't apply. So a local newspaper in Ohio need not worry about the occasional European visitor, but The Washington Post definitely does
Basically you argree with what I wrote but wrote it in a way to make it look like I stated something incorrect. Why did you do that?
You are incorrect. It applies to data about people who are in the EU and to data processing in the EU. Citizenship does not matter. See Article 3 - Territorial Scope: https://gdpr-info.eu/art-3-gdpr/
I’m so fucking tired of google using my geolocation instead of my browser settings to decide which language to use.
Somewhere in Google:
"Hey, what is this list of language codes that browsers send in the request? Could we use it somehow?"
"Don't worry about it, we already use it to calculate fingerprints."
"Hey, what is this list of language codes that browsers send in the request? Could we use it somehow?"
"Don't worry about it, we already use it to calculate fingerprints."
I have a Google Suite account and literally it keeps defaulting things to German when I have changed multiple things back to English. For the love of god I still can't figure out how to make it default constantly to English.
At least non-Suite sites figured that out a while ago. I think you need to change your language in 3 different places though.
Adding ?hl=en at the end of the URL fixes the issues on most google pages
True. But still excruciating that Google refuse to let the users' configure that. You can't even save this settings on the browser's search engine.
If anyone is curious, it seems all this does is add a <script> element that defies _gaUserPrefs on all pages. At least the Firefox version. Here is all the code in it:
(function() {
var a = document.createElement("script");
a.type = "text/javascript";
a.id = "__gaOptOutExtension";
a.innerText = 'window["_gaUserPrefs"] = { ioo : function() { return true; } }';
document.documentElement.insertBefore(a, document.documentElement.firstChild);
})()On firefox, is there some way to execute code like this on every page you visit, or when visiting a specific page -- but without installing an extension?
I've been searching - maybe something like usercontent.css but for javascript that works?
I've been searching - maybe something like usercontent.css but for javascript that works?
Userscripts?
So it's completely ineffective on any site with a half-decent CSP? Neat.
Not gunna lie, based on the design of this page, and we're talking at least 4 design systems in the past, CSP wasn't enforced or as recommended as it is now. Maybe time for a 20% project. Assuming CSP would block it.
Disclaimer: Googler, not on ads.
Disclaimer: Googler, not on ads.
Any guesses on why it creates the script element rather than just executing the JavaScript directly? Surely nothing would actually be looking out for a __gaOptOutExtension element in the DOM? (… to say nothing of it creating an incorrect DOM by inserting the script element as an immediate child of the <html> element, rather than inside the head or body.)
window["_gaUserPrefs"] = { ioo : function() { return true; } }Chrome Extension content scripts are evaluated in an isolated JavaScript environment which does not share variables with the page's JavaScript.
By creating a script in the page itself, the "_gaUserPrefs" variable is made accessible to the Google Analytics script.
By creating a script in the page itself, the "_gaUserPrefs" variable is made accessible to the Google Analytics script.
Having to circumvent your own extension policy that prevents tracking in order prevent the tracking you were doing is not the best way to look competitive.
It's not "circumventing" a "policy." Injecting html is what you're supposed to do in this situation because it's safer than allowing contentscripts to directly execute javascript in the page context. This is how all chrome extensions do it.
Injecting HTML is a terrible idea. It has extreme overhead compared to just evaluating some JavaScript in the page context, and it will break the occasional page that expects certain things of its DOM, and it’s fairly inevitably broken when you have CSP things. The DOM belongs to the document. You shouldn’t touch it unless you actually have to to provide your functionality, and this isn’t such an extension. There’s a a proper mechanism for executing scripts in the document context, which should be used.
> There’s a a proper mechanism for executing scripts in the document context, which should be used.
Which is?
Edit: In the interest of saving time, it looks based on your other comment that you're referring to chrome.tabs.executescript, but code executed this way executes as a content script so it doesn't run in the page context and can't communicate with javascript running on the page.
If there's another way of running code in the page without injecting html I'd love to hear about it, though.
Which is?
Edit: In the interest of saving time, it looks based on your other comment that you're referring to chrome.tabs.executescript, but code executed this way executes as a content script so it doesn't run in the page context and can't communicate with javascript running on the page.
If there's another way of running code in the page without injecting html I'd love to hear about it, though.
They could always try asking me if I want to be tracked, no code injection necessary.
Ah, that makes a lot of sense and explains the bad idiom. I think, then, that it should be something like this instead?
This may well be incorrect or incomplete. I’m not properly familiar with the details here. I haven’t made any browser extensions in the WebExtensions era, all I’ve done is plenty of Greasemonkey scripts, where you can use unsafeWindow.eval() for these purposes (and there, if you instead did unsafeWindow._gaUserPrefs = …, you’d run into a SecurityError when the user code tried calling _gaUserPrefs.ioo()).
browser.tabs.executeScript({
code: `
window["_gaUserPrefs"] = { ioo : function() { return true; } };
`,
allFrames: true, // And maybe this for good measure?
runAt: "document_start",
});
(Spelled browser for WebExtensions, and chrome for most Chromium-based browsers.)This may well be incorrect or incomplete. I’m not properly familiar with the details here. I haven’t made any browser extensions in the WebExtensions era, all I’ve done is plenty of Greasemonkey scripts, where you can use unsafeWindow.eval() for these purposes (and there, if you instead did unsafeWindow._gaUserPrefs = …, you’d run into a SecurityError when the user code tried calling _gaUserPrefs.ioo()).
That wouldn't work, because it needs to execute before the analytics script. The runAt:"document_start" doesn't really do anything unless you invent time travel.
I imagine it’d be no different from whatever it does at present—this is just about replacing the script element insertion technique, it doesn’t control when this script is actually executed.
I was talking about the use of `browser.tabs.executeScript`. You have to define a content script [0] in the manifest instead. I presume that's what Google's extension does, too.
[0]: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
[0]: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
So at the end of the day it is yet another way for sites to track you.
https://www.ublockorigin.com
Just block it (and almost all other analytics) instead of opting out
Just block it (and almost all other analytics) instead of opting out
[deleted]
I just find this extension insulting. I need less Google code running in my browser, not more.
The whole idea is ridiculous that I am supposed to install a Google extension so Google doesn't track me, which I never wanted or agreed to anyway.
The real question is, is it really Google that's tracking your or the site you're visiting? (The EU GDPR doesn't care, it says it's the responsibility of the site to get informed consent, which necessarily has to define what the chosen data processor does and can do with your data.)
So what Google does with that data? To me it seems GA is just the free incentive to get sites to start using their "marketing platform", it's the entry point for their upsell conversion funnel to selling you Google Ads. The real thing. And GA is a great way to get you to get vendor-locked-in early.
So what Google does with that data? To me it seems GA is just the free incentive to get sites to start using their "marketing platform", it's the entry point for their upsell conversion funnel to selling you Google Ads. The real thing. And GA is a great way to get you to get vendor-locked-in early.
Google Analytics consultant here.
A plain-vanilla GA installation does not connect GA data to any of Google's data. Google is a Processor under GDPR & Service Provider under CCPA, meaning that the data "belongs" to the site owner and Google has no legal rights to use it for their own purposes.
BUT
A key feature of Google Analytics is integration with the rest of the Google ecosystem, including Google Ads (formerly AdWords) and Display & Video (formerly DoubleClick). It is extremely easy to connect GA data with Google's data. Configurations that give Google legal access to the data are easy and common. (If you remarket using GA, Google is not just a service provider.)
From a GDPR perspective using Google Analytics is still problematic because of Schrems II. Any data transfer to a US-controlled entity is troublesome, because the EU has declared that US does not adequately safeguard user data (the main sticking point is the lack of accountability of law enforcement & intelligence agencies to request access to the data). But that's about the US, not about Google specifically.
A plain-vanilla GA installation does not connect GA data to any of Google's data. Google is a Processor under GDPR & Service Provider under CCPA, meaning that the data "belongs" to the site owner and Google has no legal rights to use it for their own purposes.
BUT
A key feature of Google Analytics is integration with the rest of the Google ecosystem, including Google Ads (formerly AdWords) and Display & Video (formerly DoubleClick). It is extremely easy to connect GA data with Google's data. Configurations that give Google legal access to the data are easy and common. (If you remarket using GA, Google is not just a service provider.)
From a GDPR perspective using Google Analytics is still problematic because of Schrems II. Any data transfer to a US-controlled entity is troublesome, because the EU has declared that US does not adequately safeguard user data (the main sticking point is the lack of accountability of law enforcement & intelligence agencies to request access to the data). But that's about the US, not about Google specifically.
> It is extremely easy to connect GA data with Google's data.
It's extremely easy and Google do an exceptionally poor job of explaining what's going on under the hood.
> From a GDPR perspective using Google Analytics is still problematic because of Schrems II.
That and the fact that the British regulator last year explicitly called out Analytics as not being valid without a GDPR level of sent before tracking is enabled.
It's extremely easy and Google do an exceptionally poor job of explaining what's going on under the hood.
> From a GDPR perspective using Google Analytics is still problematic because of Schrems II.
That and the fact that the British regulator last year explicitly called out Analytics as not being valid without a GDPR level of sent before tracking is enabled.
Have you seen the cost for other analytics platforms like adobe cost!
https://blog.cloudflare.com/free-privacy-first-analytics-for...
https://usefathom.com/
https://plausible.io/
https://simpleanalytics.com/
Some cost-effective alternatives off the top of my head
https://usefathom.com/
https://plausible.io/
https://simpleanalytics.com/
Some cost-effective alternatives off the top of my head
You make an interesting point. Why would Google publish this, something that will only deprive them of revenue? They've already banned some browser extensions and Android apps that do this.
Maybe it helps them in some way with legal compliance, or just PR (gives them an easy way to fob off people with concerns), the benefits of which would significantly outweigh the lost revenue from the miniscule percentage of Chrome users who will install this.
Browser extension?
Equivalent to being told that all I need to do in order to get someone to stop following me is to let them in my house one more time
Equivalent to being told that all I need to do in order to get someone to stop following me is to let them in my house one more time
Can I opt out of Google AMP?
I stopped using Chrome only because of AMP and made FF my primary.
I stopped using Chrome only because of AMP and made FF my primary.
Is there anything in Firefox that makes it as easy as chrome for translating pages?
I have been using this https://addons.mozilla.org/en-US/firefox/addon/google-transl...
AMP, as the name suggests is supposed to make sites load faster, but it’s a nasty experience for me, since I cannot select and copy anything.
The site design looks like early 2000s. I wonder if this exists just to get around some regulations?
I use uBlock and the browsing experience is much better. Cannot stand pages with ads anymore.
I use uBlock and the browsing experience is much better. Cannot stand pages with ads anymore.
A cynical part of me thinks that this is another attempt by Google to say - Look now users decide if they want to be tracked using GA.
This will likely be their get-out, when it comes to UK data privacy post-actual-Brexit on Jan 1st.
(Also probably relates to Google and Facebook moving all UK users to USA Ts & Cs.)
(Also probably relates to Google and Facebook moving all UK users to USA Ts & Cs.)
1. This is not new
2. Users do not decide to be tracked. They can only opt out by installing more stuff made by an advertising company.
2. Users do not decide to be tracked. They can only opt out by installing more stuff made by an advertising company.
'Hey, I've got an idea! Let's learn more about those privacy geeks. We'll come up with a dumb-simple cross-browser extension and track them before and after extension is downloaded and installed!'
'Brilliant idea!'
'Here, I've already written the script for you, let's push it to production and keep gobbling on data.'
'Brilliant idea!'
'Here, I've already written the script for you, let's push it to production and keep gobbling on data.'
(Deliberately?) poor implementation surely.
Any requests to the Google Analytics URL could be cancelled before any network activity, rather than grabbing the file and doing nothing with it.
Any requests to the Google Analytics URL could be cancelled before any network activity, rather than grabbing the file and doing nothing with it.
I would rather have standard browser or web server attributes to opt out of analytics (google and others) and other annoying crap.
That would have been much more efficient than those GDPR banners and dialogs, but will never happen since it will be "too easy" to opt out just like the http "do not track" extension failed for being too powerful.
That would have been much more efficient than those GDPR banners and dialogs, but will never happen since it will be "too easy" to opt out just like the http "do not track" extension failed for being too powerful.
Just to let you note that this extension has been around since ages, here's a thread on HN from ~11 years ago:
https://news.ycombinator.com/item?id=1378004
Also, as a little personal trivia, I'd like to add that in all these years I never seen this installed on any browser by anyone.
https://news.ycombinator.com/item?id=1378004
Also, as a little personal trivia, I'd like to add that in all these years I never seen this installed on any browser by anyone.
Clearly that tools webpage hasn't been updated in the intervening 11 years.
gtag.js is pretty new, isn’t it.
IIRC analytics.js is much newer than 11 years as well.
Interesting. Does anyone know if it even works anymore?
Should be opt-in. The whole opt-out thing is a dark pattern.
And if you need to opt out of more services:
https://simpleoptout.com/
And if you need to opt out of more services:
https://simpleoptout.com/
I opted out of google analytics by disabling JavaScript.
How does it feel to have mostly broken websites and no interactivity?
Most websites work just fine. And I enable it selectively on the ones that don’t work that I care about.
Good for you that you can deal with that. I tried for 1 month and I gave up. It was too annoying to me.
It takes a little bit of time up front as you add sites to the whitelist. After that though, everything pretty much just works fine.
How about no ...
Why would you install this if you already don't trust Google with your data.