ipfs-docs
ipfs-docs copied to clipboard
Evalute removing Google Analytics for an open-source, privacy respecting reader-metrics solution.
I'm not sure how long this has been here, but browsing through this page: https://docs.ipfs.io/how-to/host-git-style-repo/ uBlock blocks the domain google-analytics.com meaning anyone browsing this page is at risk to having their traffic traced and sold by google
luckily I block all google domains via iptables, so I'm not at risk here (without uBlock) but this is a huge security risk for anyone else browsing your page
please consider less dangerous analytics solutions if you really want to track your visitors. (a disturbing practice in itself)
Thank you for submitting your first issue to this repository! A maintainer will be here shortly to triage and review. In the meantime, please double-check that you have provided all the necessary information to make this process easy! Any information that can help save additiona round trips is useful! We currently aim to give initial feedback within two business days. If this does not happen, feel free to leave a comment. Please keep an eye on how this issue will be labeled, as labels give an overview of priorities, assignments and additional actions requested by the maintainers:
- "Priority" labels will show how urgent this is for the team.
- "Status" labels will show if this is ready to be worked on, blocked, or in progress.
- "Need" labels will indicate if additional input or analysis is required.
Finally, remember to use https://discuss.ipfs.io if you just need general support.
I'm not sure about Google Analytics (GA) being a security threat, however it is a big privacy issue. There have been informal conversations in the IPFS team about removing GA from IPFS, but they haven't really gotten anywhere. An issue was raised in the ipfs/blog repo, but the discussion has gone stale.
I'd personally like to rip GA out of this repo, but there are certain metrics GA provides that are useful: visit count, country, language, goal conversion, popular pages, etc. Saying that, there are other analytic solutions that provide these metrics without violating user privacy.
One alternative that sticks out is Pluasible. We could also try to build our own, but that'd be out-of-scope for this repo.
visit count, country, language, goal conversion, popular pages, etc.
Saying that, there are other analytic solutions that provide these metrics without violating user privacy.
I was literally about to write a response saying exactly this before I continued reading XD
tbh though, rolling your own would ensure privacy is respected even against alternatives being bad players, despite the action being out of scope... I'm only encouraging it because it's reassuring to know it won't have to be re-written later if/when this happens.
P.S.: while yes, it's not really a "security" issue, I always say you can't have privacy without security...
a house with glass walls isn't very secure, the eyes of your enemies can see right through it.
^ my quite common counter-argument for security vs privacy
P.S.: while yes, it's not really a "security" issue, I always say you can't have privacy without security...
I think it would be more accurate the other way around: No security without privacy.
@johnnymatthews , what would be the appropriate forum to weigh in on this issue? I also am anti-google as a general rule.
@ardunster, I think for now this issue is a good place to discuss your thoughts on de-googlifying IPFS Docs.
@Tcll Thanks to multiple voices (such as yours!) calling for this change, Google Analytics has been removed in favor of Plausible Analytics, an open-source and privacy-friendly analytics system.
All the stats are open, so check out the dashboard if you'd like: https://plausible.io/docs.ipfs.tech