Implementing Plausible on our websites - need your input!

I assume[1] that this is part of why the team is so torn when it comes down to this topic, it could definitely help the project move forward.

There is a fine line between getting (too much?) data and being economically sustainable, Analytics might help the project stay afloat and even continue growing as stated in the blogpost. :rocket:
There is definitely a balance that most companies do not care having and just go full throttle targeting money and filling up everything with ads + tracking.

Here, it is about finding a compromise and maybe having a bit more tools while doing it in the "most right way possible".
Doesn't mean it is perfect or 100% "white" but tech is always a sane middle-ground to settle on.
Moreover, money is needed so that we don't have a company sweeping away all the work done by the foundation or whatever other danger we could face here. There is only so much you can do with donations while infrastructure costs are bleeding you out. :sweat_smile:

I think that some people will unfortunately not read further and stop at "we are being tracked" whatever is the solution you'll invoke and all the good-willed transparency you put in place.
Seeing it as full black (evil corp) or full white (0 data collected ever). No point fighting over getting those people back, it is IMO a lost cause already. :melting_face:
Not saying it is what everybody will do, most will probably understand that it is a light gray we do have and will love the end to end honesty.

I heard that apparently, you're free to run Linux as your work computer.
Definitely the most flexible freedom for the OHF employees yes. :hugs:

Given the current situation with Chrome's Manifest V3 + everybody's different setup, maybe a small guide for all the most common ways to achieve such blocking with images for the audience could be helpful and make people less upset? :mending_heart:

Makes sense. Here is a screenshot of that doc in case you still want to move forward.

I think that on mobile, Brave with some agressive settings would block most of the stuff with its strong stance of privacy. Privacy is unfortunately a wide topic to cover 100% perfectly. :face_without_mouth:

You're talking about Proton's NetShield? If yes, I guess it is a cool way to have it blocking a few extra things yes.
If you can, you could also consider having it directly setup on your network router to block things at the DNS level potentially? That way you don't need to configure it 1 by 1 on each device but stop them straight at the gateway.

If you want to go all in, solutions like LittleSnitch or LuLu can give you the extra fine details to push it even further. A bit annoying sometimes to whitelist everything but it meanwhile really shows what each website is really calling in terms of 3rd parties every time you visit one.
You could moreover block entire services from bothering you across your entire machine.


  1. I am not part of the OHF team in any way as of today, hence can only speculate given what Missy is writting ↩︎

2 Likes

Huh. I don't know what it would take to build this, but I don't hate this idea...

I think we could also reasonably do what we do with previewing blogs before we publish them.

Probably too late to do that now? @MrDarrenGriffin curious on what you think here.

It was just an suggestion, you have already "revealed" your "preferred" ways of working :joy:

lol definitely not my preferred way of working :joy: I came into this job asking why we were on Facebook at all. :laughing:

2 Likes

thanks.
not very simple to block that...
also, why the hate for those cookie popups? seems way simpler for the user to reject all once than having to setup all that additional security software to block sneaky Plausible. (to me it is because it doesnt popup telling you it collects data, and is way more difficult to disable. No matter the data itself, or this blog post for that matter)

indeed Proton, safe haven in Switzerland, which I pay to keep my traffic and data out of the xxx-eyes countries, and be sure they never (need to) surrender to reigning bullies.

Well i actually "managed" to Totally wipe all traces , and "bailed out" of FB, 4 years ago, And never ever missed it
I took me Days ! , and i "learned" that for some "obscured idea" , that
Hold On !!! ... EVERYTHING beside " everything you do/type/click on etc etc, Then Everything you i.e scroll past in your "flow" and Don't specifically click won't see/don't like etc(which they ofcause also stores)
But everything you scroll past because what ever reason IS STORED, under a Category " You Might LIKE, maybe not Now !, but You might Be Interested in the Future, tomorrow, later, regardless if it's fakenews, obscure, discriminating etc. etc. ... i was baffled 15 Years of Datas, some places i had to delete 1 by 1 posts ... Insane :laughing:

Technically, if you're fine with writing raw markdown with no fancy WYSIWYG and sharing those without too much fine-grained permission rules, might be quite simple to spin up. :light_blue_heart:

Even some headless CMS could be used for that. :+1:t2:

Okay, just to make things clear because apparently Plausible is framed as being a sneaky tool that is asking for your soul here. :sweat_smile:
Their article goes a bit more into the details but overall, you don't need a cookie banner because there are no cookies in the first place.

Now, you also need to realize that the websites that implement a cookie banner have a few drawbacks:

  • first, you will load I don't know how many megabytes of 3rd party JS on the client side, that will slow down the entire experience and will add to the usual bloat that comes into your face
  • the banner will be coming from a 3rd party (99% of the time), like a service located in a different continent with whom your data will be processed if you do say yes or no
  • they will promise that they do not but overall, it is as good as trust me bro and then will make the news in 3 years or so that actually, they did since day 1 :grinning_face_with_smiling_eyes:
  • if you say yes to all cookies, then I guess you accept it willingly haha
  • if you say no to all (once you maybe found it buried under 5 dark-pattern menus), they will still process + collect data on you. How and why you might ask? Oh, thanks to the power of :rainbow: legitimate interest :rainbow:.
    Isn't gray areas in laws just a wonderful marvel of human creativity? :star:
    In the exact same way as Facebook uses that kind of excuse by saying our customers WANT our tracking and ads [...] because they agreed to the TOS when signing up to the platform and reading the 90 pages of lawyer-speak crap
  • last point that might be important to know, but whatever is the cookies situation, none of this guard rails anything at all when it comes down to the 3rd party scripts that will be loaded on the client-side when accessing the website (you can inspect those in your browser -> devtools -> network tab)
Some sources

Meta situation: noyb win: Personalized Ads on Facebook, Instagram and WhatsApp declared illegal
LinkedIn example: https://browsergate.eu/
Another LinkedIn special: I Verified My LinkedIn Identity. Here's What I Actually Handed Over. | THE LOCAL STACK

The deeper you go, the scarier it gets.
Don't turn a blind eye: if you see a cookie banner, you're already F'ed and no amount of clicking will help you. :grinning_face_with_smiling_eyes:

Here there is literally a plain and official way of blocking it with nothing shady.
Plausible is moreover even more transparent by showing you how you could bypass blockers. Thing that OHF decides to NOT do behind your back because they value their users and their respect.
Yet most won't even second-guess it and just do that (quite common practice actually).

I stated before, a few ways you could bypass all of this in my previous message: DNS blockers at the router-level + outbound firewall. Will get you covered for 99% of the use cases, even shady and disrespectful websites out there.
Thankfully, you won't need any of that to still browse and use OHF's FOSS tools. :+1:t2:

I won't derail this topic haha, but same here: do some research on Proton if you're really concerned about your privacy. :hugs:

The initial blog post shows what would be stored and what won't.

You could get a long way with client side Javascript yes (especially if the code is closed source). :smiling_face_with_tear:
The idea proposed by the team here, is to collect only things that might give a signal without collecting personal info and identifying anybody, so that the team could have some sort of signal.

And again, you won't even need to trust the OHF's team words, you can just double-check by inspecting the public dashboard they're willing to expose.
Here is the actual production dashboard publicly shared by Plausible's own Plausible analytics. You can see what they do collect using their own tool on their own website so that everybody can see with their own eyes what's collected.

As far as I understand it, OHF wants to do something very close to it.
Does Plausible's dashboard sound outrageous and crazy?
It is kinda the same as the HA analytics page shared in the first post and people are fine with it (if not mistaken?).

I have no reasons to question OHF, and in regards to "Plausible" i really don't care to either read about it or bother ( More important things in Life :slightly_smiling_face: )
In Fact both community.homessitant and home-assistant .io is Not blocked by uBlock O, Neither my HA installs.
Don't even remember why they become "Trusted" :joy:
Edit: My Commend to Missy about FB, was just a reaction/respond to her Commend about same

Let's get back to the goal here. I think that trying to make HA better is a good thing.

Any proposal put forth is going to be fraught with problems. The path forward is to figure out how to make it work, not the reasons why it's not going to work.

We have been presented with the concept of collecting data and analyzing that data which will allow the HA team to focus on areas that need improvement. Do we agree that that will work? I don't know that this has been answered. (My small voice squeaks that it will)

If so, Plausible the most effective tool? (A "no" piep)

If not, what is a better way to collect data? (cui-cui ... I think that user feedback can do that just as well.)

If you have every used a tuya device, a Reolink camera, a search engine, bought something from Amazon, AliExpress or DoorDash, you've already been raped. Pausible is barely a fondle. If you're using an LLM, you're doing the fondling.

So back to the goal, making HA better. How can we make this proposal work?

1 Like

It's already answered, and it's not an proposal
If you have "commends/concerns" to the specific points they are going to collect ( With Plausible ) Leave a Commend

tbf, we don't even know the answer! We believe it will (and in a lot of our experiences in past roles, this kind of data does help).

To be very clear, this is only to improve and prioritize the work around all of the foundation's websites, not Home Assistant itself (nor ESPHome or Music Assistant). This implementation is to help our web devs and technical writers who develop our documentation.

And I'll be honest - there are way less pitchforks than I expected. :sweat_smile: But I knew that flagging this specifically to the forums community would help us identify any gaps we may have in our communication. So far the reaction has been more "I will block this" over "You aren't clear in what you're doing".

1 Like

Let's see once it's published on the main blog and released to more eyes. :sweat_smile:

2 Likes

yes, that would be my request too.

and it should be a better guide what was shown in that screenshot, because hardly helpful that is (to me at least)

please touch these strategies:
1- on the router (and why not take Unifi screenshot to explain..)
2- on desktop browser
3- on mobile

So what you are saying is that you have not been collecting any analytics at all on your website all this time and would like to start now? From reading the full blog post draft I see no issues in what you are trying to do and I always try to provide helpful information for non profits whenever I can so that these projects can improve more and more. The “what is not tracked” list seems to cover all the important ones that most people would be concerned with. I am sure my OPNsense fireware with Adguard would probably block most of the other info but I could white list your pages to get the data to you.

I appreciate the transparency from the team on this, and I wanted to offer a counter-perspective to the general pushback in the thread.

Having spent a career doing security consulting for major corporations, I have seen what truly invasive corporate data harvesting looks like. This proposal is the exact opposite of that.

Using a self-hosted instance of Plausible, limiting it to the public websites (and explicitly not touching our local Home Assistant instances), and making the dashboard entirely public is an incredibly responsible, privacy-respecting approach.

A modern organization needs basic, aggregate data to improve its web presence and manage a merch store effectively. Trying to do that completely blind is unsustainable. You can count me among what is likely a silent majority of users who are completely fine with this implementation.

Thanks for laying this out so clearly and doing it the right way.

9 Likes

Yep, exactly! :sparkles:

Lemme flag this to the team and see how they feel about it.

2 Likes

And a week later it will be background noise to the users.

1 Like

Collecting user data is always a bit risky business. I hope you are aware that this must, for all your EU customers, be aligned with GDPR.
I personally prefer situation where my devices are mine including the data that those devices are sending around. I know that this is not always possible but I’m trying to avoid anything that is SaS operable.

This is why the team didn’t risk reinventing the wheel (poorly) but just used an available solution that works well on that regard. :hugs:
And self-hosting it will also remove quite a lot of BS from the equation. :+1:t2:

1 Like

It is not that plain simple as you suggest it is.

I’m not GDPR expert and I’m not claming to be.

To be aligned with gdpr as I know doesnt mean only oh we have a software that is gdpr compliant and data are self hosted.

As I know to be gdpr compliant you will have to create internal documents and procedures. It is not something that can be done on a forum.

They will have to engage people that are GDPR specialist to prepare everything that is needed before they start to do this.