Giter Club home page Giter Club logo

disconnect-tracking-protection's Introduction

The Tracker Protection lists are licensed under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License. https://creativecommons.org/licenses/by-nc-sa/4.0/

Please email [email protected] if you’d like to license the lists for commercial use.

If you believe that we’ve missed a tracker, or categorized a domain incorrectly please fill out and submit the form found here.

Pull requests are not reviewed and will be closed.

Copyright (c) 2024 Disconnect, Inc.

disconnect-tracking-protection's People

Contributors

carbureted avatar disconnectbot avatar disconnectme avatar disconnectus avatar patjack avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

disconnect-tracking-protection's Issues

feature_request(service): remove AddToAny from blacklist

(Originally posted in Mozilla issue tracker)

1. Summary

It would be nice, if AddToAny service will be removed from Firefox blacklist. At the time social buttons of service block in Firefox (beginning at Firefox 63) by default.

If I need to make another actions, that AddToAny buttons works for Firefox users with Always value of Trackers key, please, tell me.

2. Example

<!-- AddToAny BEGIN -->
<div class="a2a_kit a2a_kit_size_32 a2a_floating_style a2a_vertical_style" style="left:0px; top:150px;">
<a class="a2a_dd" href="https://www.addtoany.com/share"></a>
<a class="a2a_button_mastodon"></a>
<a class="a2a_button_diaspora"></a>
</div>
<script async src="https://static.addtoany.com/menu/page.js"></script>
<!-- AddToAny END -->

3. Expected behavior

If Only in private windows value of Trackers key:

Only in private windows

Buttons are shown:

Expected

4. Non-expected behavior

Else Always value of Trackers key:

Always

No buttons:

Non-expected

5. Argumentation

5.1. Do Not Track

Privacy Policy from official site:

Do Not Track (DNT):

    + When a supported browser's DNT header is enabled, we prevent tracking across sites where AddToAny is used.
    + For example, we disable Like & Tweet buttons to prevent Facebook & Twitter tracking when DNT is enabled.
    + See our full Do Not Track Compliance Policy.

Full Do Not Track Compliance Policy in AddToAny site.

5.2. EFF

As user, I use Privacy Badger of Electronic Frontier Foundation (EFF) for tracking preventing → Privacy Badger allow AddToAny:

Privacy Badger

Firefox support EFF blacklists.

5.3. Disabling tracking

See on my Codepen pen:

a2a_config = a2a_config or {}
a2a_config.no_3p = true
a2a_config.track_links = false

This code prevents any tracking:

Thanks.

Not classified suspicious third parties

https://webbkoll.dataskydd.net/sv/ uses your database to classify third party requests.
So far the following seem to be missing:

  • a.komoona.com
  • a248.e.akamai.net
  • ad.71i.de
  • ad.ad-srv.net
  • ad.sxp.smartclip.net
  • ad29.ad-srv.net
  • ads.stickyadstv.com
  • ads.yahoo.com
  • adserver.71i.de
  • advertiser.wbtrk.net
  • aka.spotxcdn.com
  • apex.go.sonobi.com
  • api-img.billiger.de
  • assets-cdn.com
  • banners.webmasterplan.com
  • bree.com
  • c.t4ft.de
  • cdn.emetriq.de
  • cdn.iqcontentplatform.de
  • cdn.komoona.com
  • cdn.m-pathy.com
  • cdn.onthe.io
  • cdn.tradelab.fr
  • cdn1.lockerdome.com
  • cdn2.lockerdome.com
  • cdnjs.cloudflare.com
  • cloudfront-labs.amazonaws.com
  • cm.adgrx.com
  • code.jquery.com
  • common.i12.de
  • cs.adingo.jp
  • cs.gssprt.jp
  • cs.komoona.com
  • cse.google.com
  • d.alcvid.com
  • data08.adlooxtracking.com
  • data43.adlooxtracking.com
  • delivery.swid.switchads.com
  • dmp.theadex.com
  • dyn.emetriq.de
  • event.movad.de
  • glaring-torch-8314.firebaseapp.com
  • gzhls.at
  • hb.vntsm.com
  • html-links.com
  • images-na.ssl-images-amazon.com
  • images.apester.com
  • impressions.revenue-tracker.com
  • its.tradelab.fr
  • j.adlooxtracking.com
  • js.himediads.com
  • load.s3.amazonaws.com
  • lockerdome.com
  • match.basebanner.com
  • native.sharethrough.com
  • p.cpx.to
  • p.lp4.io
  • partner.vxcp.de
  • pde.lp4.io
  • pix.impdesk.com
  • pixeltrack.eyeviewads.com
  • pr-bh.ybp.yahoo.com
  • responder.wt-safetag.com
  • revenue.com
  • s.cpx.to
  • s.kau.li
  • s.komoona.com
  • s.ytimg.com
  • s3-eu-central-1.amazonaws.com
  • s79.mxcdn.net
  • s79.research.de.com
  • sc.iasds01.com
  • scontent.lrcdn.net
  • ssl.p.jwpcdn.com
  • stat.komoona.com
  • sv.monkeybroker.net
  • sync.1rx.io
  • sync.go.sonobi.com
  • sync.intentiq.com
  • sync.rhythmxchange.com
  • t.alcvid.com
  • t.zqtk.net
  • t4ft.de
  • track.eyeviewads.com
  • tt.onthe.io
  • uip.semasio.net
  • uobsoe.com
  • wss.lockerdome.com
  • www.google.com
  • www.googletagmanager.com
  • x.bidswitch.net

Unable to create Samsung Developer acct.

consider removing the panopticlick test domains

do-not-tracker.org
eviltracker.net
trackersimulator.org

These try to load code to actually test fingerprinting. By simply blocking the domains your just saying "Yay, we block those 3 harmless test domains" but the actual tracking techniques that they present would then remain undetected on every other domain on the web.

Does this exclude sites that support EFF's Do Not Track policy?

Hello! Does Disconnect exclude sites that support https://www.eff.org/dnt-policy? This PR suggests that this may be the case: #4

Context: I am a former author of Privacy Badger Firefox and now a maintainer of Brave browser, which uses this list for tracking protection. If you are whitelisting sites that post EFF's DNT policy, Brave should be enabling DNT on those sites (we do not by default). I would suggest that this be documented somewhere for downstream users of this repo.

akamaihd.net

FYI, akamaihd.net listed as a Facebook domain, and even though lots of Facebook traffic resolves there, it is an Akamai domain that is used by other clients as well.

Unblock Google Tag Manager

In your Blocking List, you also block Google Tag Manager.
Since Google Tag Manager is not collecting any data, you should remove it from your list.

If someone opts out of tracking, you disable Google Analytics or other Trackers already. But Google Tag Manager can also be used for essential features without any tracking of users.

Consider reclassifying shareaholic.com as "Content"

All Shareaholic CDN assets (images, fonts, CSS, JS) are loaded from apps.shareaholic.com which causes site functionality and site admin interfaces which are part of WordPress and Drupal Admin areas to break.

For example - WordPress:
http://jay.meattle.com/wp-admin/admin.php?page=shareaholic-settings

Blocking all resources loaded from shareaholic.com feels extreme as it breaks functionality across 200,000+ WordPress and Drupal site admin screens.

Possible solution:
Re-classifying shareaholic.com as Content seems more appropriate and it would at least stop breaking Admin interfaces in some cases. If someone has the "strict" list turned on in Firefox, then they at least have been given the heads up that site functionality can break.

pricegrabber.com

Belongs to Symphony Technological Group via Connexity, not Experian.

Please whitelist non-personalized/non-tracking AdSense ads

Please consider whitelistsing requests to Google domains that contain the &npa=1 URL parameter.

These requests are for non-personalized/non-tracking ads (usually contextual page-relevant ads) that don’t serve ads based on the user’s past browsing behavior, and don’t store information about the page/ad that requested the ad.

“Although these ads don’t use cookies for ad personalization, they do use cookies to allow for frequency capping, aggregated ad reporting, and to combat fraud and abuse.”

(These are the same exceptions as found in the GDPR.)

More information:
https://support.google.com/adsense/answer/7670312

Disconnect.me should whitelist these to encourage publishers to adopt non-tracking ads.

MailChimp signups blocked as advertising

disconnectme/disconnect#337

A disconnect.me user reported that submit form on www.virtkick.io doesn't work for him. I tried disconnect.me and I reproduced the problem. Why are you blocking legitimate JSONP requests to MailChimp?

Resource interpreted as Script but transferred with MIME type text/html: "about:blank".
mailchimp ajax submit error: parsererror 

I can confirm this is an issue, MailChimp email signups are blocked under Advertising, causing signups to fail silently on many sites.

AWS Cognito

Getting The resource at “https://cognito-idp.us-east-1.amazonaws.com/” was blocked because tracking protection is enabled. using "Disconnect.me strict protection" on FF Nightly.

Please consider whitelisting AWS Cognito. Without this it's impossible to login to any site that uses AWS Cognito for authentication.

Disconnect may break loading some or all AMP pages

This was observed with focus ad blocker, but may impact other disconnect based blockers.

See ampproject/amphtml#6163 for our investigation.

To reproduce:

  • Activate ad blocker
  • Search https://www.google.com for "obama" or "trump"
  • Find results marked as "AMP"
  • Try to load them
  • Loading Spinner is never removed.

In general, AMP does not do any tracking itself (documents and most resources are served from a cookieless domain). It can instrument traditional tracking services, so things should just work if you block those.

Lead Forensics tracking domains not blocked

Intrusive profiling company, Lead Forensics, uses the following tracking domains (non-exhaustive list):

secure.leadforensics.com
lead-123.com
mon-com-01.com
infra-gtc.com
lansrv040.com

Appears to follow the form:

//www\.example\.com/js/[0-9]+\.js and noscript as //www\.example\.com/[0-9]+\.png

Disconnect list should include sharepoint.com as a web property owned by Microsoft.com in the Content category

This issue is causing a breakage bug in Firefox right now, please see https://bugzilla.mozilla.org/show_bug.cgi?id=1518872.

The reason is that Firefox classifies live.com as a third-party tracker on sharepoint.com without realizing that both of these domains belong to the same entity (Microsoft). Having sharepoint.com classified on the Content category in addition to the other Micorosft domains there would allow Firefox to work around this bug by correctly recognizing the entity relationship between these two domains.

I would appreciate the help in adding this domain to the list. Thanks!

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.