Housekeeping: Adobe Typekit is being flagged by Ghostery browser extension as a problem program

I’ve gotten a few complaints this week from some overly paranoid people that say they can’t see WUWT anymore in Firefox, but can in Safari. The problem seems to be related solely to a browser extension called “ghostery” which is somehow flagging Adobe Typekit (used to provide custom fonts on WordPress) as some sort of malware.

I suspect this happened all of the sudden due to some sort of “upgrade” that was automatically installed for Ghostery.

Adobe Typekit is used by thousands upon thousands of websites, it is completely safe. Just look at the list of major websites in the lower right that use it:

ghostery-rating-typekitSource: https://www.ghostery.com/en/apps/typekit_by_adobe

Personally, I think the Ghostery browser extension is a complete waste of time, as what it does is handled by other malware and AV programs installed in your computer, but some people insist on using it anyway and bizarrely demand that I change WUWT to accommodate them. Well folks, tough noogies, I can’t, I don’t have any control whatsoever over such things.

However, the end user does, and here is the simple solution to the problem:

Problem:

Ghostery browser extension is blocking Typekit

Solution:

Go to Options > Blocking Options > Trackers > Widgets and uncheck “Typekit by Adobe”.

Source: http://help.typekit.com/customer/portal/articles/807568-troubleshooting-guide-using-web-fonts

If you don’t want to perform this simple task, then there’s no other solution except to uninstall Ghostery.

Thanks for visiting WUWT – Anthony Watts

 

 

 

The climate data they don't want you to find — free, to your inbox.
Join readers who get 5–8 new articles daily — no algorithms, no shadow bans.
0 0 votes
Article Rating
171 Comments
February 28, 2015 10:17 am

It’s not Ghostery, it’s obama’s new Net Neutrality enforcement app Buggery.

Reply to  Mark and two Cats
March 1, 2015 11:40 pm

All the pseudo-technical millennials pushed for a buzz phrase they did not understand – “Net Neutrality”. Welcome to an Internet world of higher prices, less innovation and yes less competition.

February 28, 2015 10:17 am

iirc (its been a bit since I looked) if you use a cookieless sub domain to pull the fonts from (ie adobe or google) ghostery doesn’t flag this but I am not sure this is even possible on hosted WP.
however it is a good security practice if possible,

Vail Marston
February 28, 2015 10:52 am

You can also configure Ghostery to allow Typekit only for specific sites, so just WUWT, if you prefer. This is done vial the Ghostery icon on toolbar if you have that displayed.

Peter Pearson
February 28, 2015 12:30 pm

The term “dancing pigs” is used in data-security circles to signify people’s tendency to disable security in order to enjoy frivolous cute stuff (see Wikipedia, “dancing pigs”). Here we have a case in point: our host, Anthony Watts, advising a security-conscious fan to disable a security measure, in order to enjoy some improvement of dubious importance (custom fonts), with a thoroughly non-expert assurance that it’s “completely safe”.
As an enthusiastic, long-term fan of WUWT I hate to be negative, but on this point a brief scolding seems necessary. Visitors have excellent reasons to enable security measures in their browsers, and the webmaster who asks them to “go naked” without balancing the risk against some important benefit deserves to have his web page look awful and drive viewers elsewhere.

Reply to  Peter Pearson
March 1, 2015 10:11 pm

Why misrepresent this issue? Running the Ghostery extension in your browser does nothing for your “security” so Anthony recommended no such thing.
Anyone who calls the Ghostery extension a “security measure” should retire themselves from the Internet.
https://www.ghostery.com/en/about
“… use Ghostery. It’s the web’s largest, most comprehensive and most user-friendly privacy tool.
They should actually say, “…use Ghostery and break all manner of common functionality of webpages such as commenting and embedded video”.

CodeTech
February 28, 2015 12:56 pm

Yeah, I was unable to view WUWT for a while last week, realized what it was, and enabled it in ghostery. As a web developer I can assure you that Adobe Typekit is not completely benign, however. They changed what they were doing and ghostery added it to the block list for good reason.
I’ve built several web sites that are intended to be separate from the “rest of the internet”, sites that I don’t WANT indexed by search engines, don’t WANT their images indexed on TinEye, don’t want them to be linked to by facebook or google+. I can assure you, keeping these intrusive sites out is a challenge, each and every day.
And in case you’re wondering what kind of sites, imagine an internal corporate application, where staff enter transactions and access private data while out in the field. Part of the security is obscurity (not all of it, but it’s a part). Meanwhile, we have well meaning but unwanted sites doing their best to find out what these corporate apps are doing and trying to expose them to every hacker, script kiddy, and content thief. It’s trivially simple to bypass GeoIP, so while I’m trying to limit access to the areas a company operates we have people in Russia, China, and Vietnam busy trying to crack passwords.
Yeah, I use WordPress for some of my stuff too (in fact, I use this very theme on two of them), and I use Google Fonts (less intrusive).
I install ghostery on all my computers because it prevents a stunning amount of internet traffic, and reduces the amount of activity that gets tracked and plugged into someone’s marketing plan. Frankly I find the commercialization of the internet to be repulsive and a greater intrusion on privacy than ANYTHING that ANY government has EVER tried to do, EVER.

Unmentionable
Reply to  CodeTech
February 28, 2015 4:58 pm

“Frankly I find the commercialization of the internet to be repulsive and a greater intrusion on privacy than ANYTHING that ANY government has EVER tried to do, EVER.”

Please excuse the tangent but seeing that you’ve bought up to topic …
I wouldn’t let government off the hook so easily as you have there.
I directly blame government for all manipulative exploitative scamming adds on TV as they are the airwaves licensing authority, and which willingly permit criminal scams to go to air, and do zip about it. they do not act to protect the gullible trusting members of the public from such ‘services’ operating, with permission, over regulated broadcast airwaves. Silly them, right?
Except these gullible and trusting members of the public have pre-trusted the government to be actively acting and monitoring for the public interest as the regulator, to keep scam artistes off the airwaves.
All a relevant minister has to do is tell the next TV station that broadcasts such scam adds on TV, that their broadcast license will be immediately suspended for a period of seven days if they do it, and escalate sanctions to full license cancellation from there, if necessary, with any second or third infringement.
Well, they don’t do that. Why? Oh, it’s just that political donations from TV station operators and owners will get scarce if they do.
So government does not regulate to eliminate digital bandits on TV, that are operating right in front of public and police. Government is instead effectively protecting scammers and allowing gullible trusting naive people that think government protects them from being ripped-off without recourse. Thus destroying public trust, and debauching the society, whilst poisoning faith in the political system and law itself.
Justice is supposed to be seen to be done, and it isn’t.
Same thing applies to the internet. We just keep getting told its too hard and can’t be done. But it can be done. Having government law enforcement trample on internet interaction and further intrusive systematic monitoring is the main public aversion.
Which is fair enough, as who wants that? Certainly not me.
So what we get instead is free-range online crims scamming and data mining, and endless privacy intrusions via digital peeping-Toms.
It’s almost enough to make me give up on the internet. If Government can not be trusted in this vital area, then anonymity is not only advisable, but is essential, as a personal protective measure against both governments, corporates and scammers.
Consequently, no one in the private sector nor public sector who’s not us, can have a legal right or capacity to identify, locate and store our data – ever!
If Government not only doesn’t protect public data but in the purported attempt to do so becomes a far greater pest and liability to privacy and personal protection, then government also can have no legal right to identify and log personal activity. In which case all actions and process of Government and also hardware makers to locate and identify internet users beyond their basic ISP account registration must be abolished in law, and anonymity asserted in codification to be a basic human right, required, demanded and essential for personal self-protection.
It’s because we passively accept rank government disingenuousness about this, and the dysfunctional resulting status-quo, that the constant attacks on private online data and bank accounts continue to have no end in sight and with zero realistic attempts being made to protect the public! The effort is all the other way, to undermine pubic protection in every possible way at any opportunity.
So we must be able to protect ourselves. We can never rely on someone else to protect us, for us. That approach is a sure-fire recipe for total failure to protect personal data.
And that is what we have.
There is no such thing as someone else being responsible for storing and protecting your personal data and information. It’s an insidious nonsense that cyclically does the opposite of protection.
Which means ensuring we can not be identified when online. Assured anonymity is our only viable or realistic protection option short of abandoning online interaction.
Which is immediately dismissed as too late – the horse has bolted!
Well so were many things, until we decided to change how we do things. We used to throw faeces into the streets, then we realized it was a mistake, it was toxic, it created harm, so we changed everything about that.
We can change everything online, we can undo and reverse the elimination of anonymity. The loss of it was not inevitable, is was not automatic, it is not even necessary, it was done to us and it has damaged us, it has created harm. It has removed all protection, we are now exploited from every direction and that it is the diametric opposite of the public interest being protected.
So I do not accept government is not responsible, oh yes, government is 100% responsible for the situation we now have.

Reply to  CodeTech
February 28, 2015 8:37 pm

As a “code tech” who’s been around since BEFORE Videotex (look it up if you don’t know what that was), I WELCOME the commercialization of the web. Sorry, but we would not have our current ability to create stunning web sites – and web apps – without there being gold in them ‘thar Internet hills.
Now, is it rather excessive? Yes. Rather inevitable, though. I can remember when a commercial television show was 53+ minutes of show; and when “public” television wasn’t at least 1/5 “sponsor acknowledgements” and “fund raising drives.”
I realize the headaches of securing a private app, and keeping it secure. But I worry not so much about the commercial “snoopers” – they are big enough, and used by enough developers, that the word gets out fairly quickly when they try something new; and only once have I had to roll my own solution to block one, since someone else has almost always beaten me to it (and published).

Reply to  CodeTech
March 1, 2015 10:26 pm

Really, a while? The first time I visited WUWT and the page was blank on one of my test machines I knew in a second it had to be the crappy Ghostery extension and of course likely something they classified as a “widget”. Anytime webpage functionality does not work you can always count on Ghostery for breaking it – It is what I call a sure thing.
They claim to have over 20 million pseudo-technical users now too? I cannot imagine how much time they are wasting for website owners and the frustration they are causing their pseudo-technical users.
I looked through their features,
https://www.ghostery.com/en/features
…and could not find where they said, “Ghostery is guaranteed to break webpage functionality such as commenting and embedded video.”

CodeTech
Reply to  Poptech
March 2, 2015 2:07 pm

You really have a problem with this, don’t you?
Personally I thought the instructions for Ghostery were pretty straight forward, and I actually WANT certain “webpage functionality” to be broken. I refuse to ever install “disqus” on any site I build, for example, and I only selectively enable it for sites I visit. I recommend the same to others, too. For my own sites I wrote my own commenting system that doesn’t harvest and sell users’ personal information.
The first time I hit WUWT and got the white page I assumed it was yet another time that WordPress had screwed up or had a service outage, both of which happen more often than they should.
I’m not “paranoid”. I’m sick of being used as a pawn for ignorant billionaires to skim yet more money from the internet, and I despise the fact that the work I do in development is often being added to someone’s marketing database.
As a tech person, don’t rant against a tool people use to block intrusions into their lives, and don’t complain if a tool you are using is getting blocked. Work around it, work with it, and give users a choice.

Reply to  Poptech
March 3, 2015 12:32 am

I have a problem with misinformation being given to non-technical users. Such as, that this is a security issue or that any of the scripts Ghostery blocks are malicious.
Where does Ghostery tell its end users that non-malicious web-page functionality such as commenting and embedded video with be broken by using their extension?
My complaint about Ghostery has not changed and that it should never be recommended to a non-technical user, as you have just demonstrated – even technical users are unable to determine when it is breaking legitimate content on webpages.
You just admitted to have an ideological problem with Internet monetization. I have seen this behavior far too much in the tech world where people irresponsibly push their ideological beliefs on others not taking into account the end-user’s experience.
The end user wants things to work and they have a right to know that something they are using is going to break things.

CodeTech
Reply to  Poptech
March 3, 2015 7:59 pm

I really don’t understand you.
There are many things where you and I are on the same page. But when you disagree, you adopt a hostile and stubborn tone that is quite disagreeable.
Prior to installing any extension in Chrome I read their blurb. In the case of Ghostery, the blurb is very clear. It says that the primary purpose is to DISCOVER what is loading behind your pages, LEARN what they are for including links to sites and privacy statements. Then it gives you the opportunity to block them.
It’s not just about “monetization”. The majority of crap that gets constantly fed to my browser is nefarious activity hiding behind a small amount of usefulness. In the old days we would have called that a Trojan Horse, now we somehow justify it to ourselves.
There is NO REASON for facebook, twitter, and google to have as much data about individuals as they have. It is reprehensible that in addition to the stuff that we voluntarily give them, they want more and are stealing it without most peoples’ knowledge or consent. If it was just about “monetization” then why do google and facebook actively BLOCK advertising that I attempt to do, and quite literally hold me hostage, demanding money before they will even allow anything that looks like advertising to appear to anyone else?
Here’s an actual cut and paste from FB:

You just mentioned “limited time“ in your post “…snipped…”. Try boosting it to reach more people.

Followed by a link where I can spend $20 to have 100 people even SEE what I typed.
I don’t care that a few web pages are broken, the majority are anyway. I want enough people to block these intrusions so that the people pushing them finally have to admit defeat. I would be happy if 90% of users used ad blockers and ghostery, and actively complained to sites when removing the trojan horses breaks their pages. If 90% blocked all of this meaningless garbage, the remaining 10% would find that all that was waiting for them online is all of the ads that smarter people are not seeing.
Ghostery is a godsend in a world of identity theft, profiling, and unwanted bandwidth usage. And that’s not paranoia, it’s common sense. I would Never, Ever voluntarily give ANY company or government the information about me that these people casually steal every day, from literally BILLIONS of people. And neither should ANY thinking person.

Reply to  Poptech
March 3, 2015 8:26 pm

Now you sound completely deranged.
How exactly does Google and Facebook hold you hostage? Did you not click yes to their licensing agreements when you choose to use their products and services?
Why are you being irresponsible and misrepresenting scripts used for web analytics as Trojan Horses?
Why do you want to rob honest hard-working website owners of their income?
Ghostery does absolutely nothing regarding identity theft.
You really need to rethink your insane rantings.
The fact that you do not care that basic web page functionality breaks for non-technical users using Ghostery tells any rational individual all they need to know about your motives. You have no interest in helping people but rather are intentionally creating problems and lying to people to push a deranged agenda.
Where does Ghostery say that using their extension will break basic web page functionality?
End users have a right to know this instead of letting them go off half-cocked, ignorantly blaming website owners when they should be blaming the hacks who are causing the problem – the makers of Ghostery.

CodeTech
Reply to  Poptech
March 3, 2015 10:17 pm

And… this is the moment I realize you are insane. Buh-bye now.

Reply to  Poptech
March 3, 2015 11:34 pm

That’s it? No real response?

February 28, 2015 1:44 pm

lol was curious so removed and reinstalled it (to get fresh copy) and sure enough this page pure white LOL
a default install though SHOWS that its being blocked so people should be able to find out easy enough

Keith Minto
February 28, 2015 1:47 pm

Thanks, Anthony,
That was the problem. what a relief !

Keith Minto
Reply to  Keith Minto
February 28, 2015 4:32 pm

As mentioned above, the problem was intermittent and then the site was off permanently, The URL would appear the the two vertical column borders,and no text, so, I did not suspect Ghostery.

L Hilpert
February 28, 2015 2:07 pm

According to Adobe:
What information is collected by the Typekit service?
Fonts served
Kit ID
Account ID (identifies the customer the kit is from)
Service providing the fonts (e.g., Typekit or Edge Web Fonts)
Application requesting the fonts (e.g., Adobe Muse)
Server serving the fonts (e.g., Typekit servers or Enterprise CDN)
Hostname of page loading the fonts
The amount of time it takes the web browser to download the fonts
The amount of time it takes from the web browser downloading the fonts until the fonts are applied

CodeTech
February 28, 2015 2:11 pm

By the way, for those who aren’t using Ghostery, here’s what it blocks on this page alone:
Amazon Associates,
Facebook Social Graph,
Facebook Social Plugins,
Google Adsense.
Google Analytics,
Gravatar (I enabled it),
KISSmetrics,
Twitter Badge,
Twitter Button,
Typekit by Adobe (I enabled it).
This isn’t ad blocking, it’s tracker blocking. All of these keep track of what sites you visit and in addition to using that information to tailor advertising, they also use it for social profiling, and there are probably nefarious purposes as well. I can’t even begin to express how much I don’t want google, twitter, and facebook to know what sites I frequent.

Keith Minto
Reply to  CodeTech
February 28, 2015 2:44 pm

Completely agree.
Some time back on this site, there was a test you could perform to see how visible you are to others. According to this test, with Ghostery, I did not exist.

Michael Wassil
Reply to  CodeTech
February 28, 2015 3:26 pm

Two words: Tor Browser. Nobody knows who you are.
https://www.torproject.org/

Patrick
Reply to  CodeTech
February 28, 2015 10:43 pm

I just installed it and went to my usual news site here in Australia, the Sydney Morning Herald. And sure enough all those you list appeared, and were subsequently blocked. I didn’t bother checking if my firewall/av engine was setup to track block these.

Reply to  Patrick
March 1, 2015 5:43 pm

Patrick why would an AV or a Firewall block non-malicious webpage scripts? People here need to stop spreading misinformation to pseudo-technical people.

Patrick
Reply to  Patrick
March 1, 2015 10:51 pm

Well, I should have said “internet security” engine, which does include firewall, AV and popup/ad/tracking blocking capabilities. I just have not checked to see if that “engine” has the same capabilities as Ghostery. So, I installed to have a look-see.
Not sure if that spreading misinformation comment was directed at me. If it was, I have not spread misinformation to anyone.

Patrick
Reply to  CodeTech
February 28, 2015 10:45 pm

And right off the bat, the response from IE while browsing is faster. Hummmm…

MattS
Reply to  CodeTech
March 1, 2015 7:43 am

See the comment above yours, Typekit isn’t collecting any information that could be used for targeted advertising (personally, I fail to see why targeted advertising is a bad thing) or social profiling. It’s collecting information on it’s run time performance.

Reply to  MattS
March 1, 2015 11:29 am

this isn’t really the issue, when offsite fonts used there’s an insertion method/vector that can (and has) been used to do xml/css attacks.
when browser blocks offsite fonts there less risk.

jdgalt
February 28, 2015 2:33 pm

I used to use Ghostery and dumped it for blocking too much legitimate material.
Now I use two other extensions instead — NoScript and RequestPolicy. These let you control exactly which sites are allowed to use JavaScript or Flash, and exactly which references to other sites are allowed, respectively. They do require fiddling in the case of sites that make lots of references, but they enable me to block the nasty pop-under ads while keeping all the content I want to see.
Preventing tracking is a lost cause anyway, unless you’re willing to run Tails or something similar.

February 28, 2015 3:28 pm

For an enlightening experience, and disappointing, run panopticlick.eff.org from the Electronic Frontiers Foundation.

February 28, 2015 3:30 pm

Tails forces TOR

February 28, 2015 4:38 pm

Thanks.
I solved the problem by removing ghostery a couple days ago.
its a pain in the neck

Keith Minto
Reply to  Steven Mosher
February 28, 2015 6:36 pm

Not necessary to remove it completely if it is useful.
The tutorial sorts the problem out. Ghostery has improved over the years but it takes some fiddling to work it out, especially if it runs in the background and you do not experience problems.
I have Typekit by Adobe blocked for all sites except this one, the slider is to the right and is red but the button on the right is green, problem fixed.

Reply to  Steven Mosher
March 1, 2015 5:39 pm

Computer illiterate Mosher does not know how to use Ghostery either, this simply confirms everything I have been saying.

February 28, 2015 4:45 pm

It seems Cisco’s IronPort gateway uses web reputation-based policies, and is also flagging Adobe Typekit as potential malware. Bad news for those who peruse WUWT during lunchtime at work. I’m behind the firewall, and the entire site is blocked as having a bad web reputation. This started on 2/27/15.

February 28, 2015 6:06 pm

I use Firefox and Ghostery and have no problems seeing the site, and I never have. And I’m not overly paranoid.

Atomic Hairdryer
Reply to  Mark
February 28, 2015 6:25 pm

You will have problems if you update Ghostery as it’ll just show a blank page if you have Typekit blocked.
As to why you may want to, well, Adobe is notorious for datamining. Any Typekit user may also want to check out the service agreement which grants Adobe rights to any custom fonts you or contributers may use. The tracking part is contained in Adobe’s definition of kit:
“7.8 “Kit” means the computer, web or other medium-compatible software package created by You through the Service comprised of Your preferred settings, Licensed Font choices, and formats, style sheets, and other software code, along with any JavaScript that may be delivered through the Service to wrap and identify each Kit and corresponding Publisher and to manage and track Use of Licensed Fonts in connection with Published Media.”
Along with how, or why Adobe manages and tracks users. If the site isn’t using Adobe fonts, there’s no real reason to allow Typekit. If you run this site through Wireshark, you will see it contacting Adobe before it allows the content to be displayed though.

Glen
February 28, 2015 7:12 pm

i`m surprised that more security kits do not block adobes software as Adobe are the biggest malware creator on the planet. there is no excuse for website developers to keep rogue companies such as adobe in business by using their trashy software when many alternatives are availaible

Unmentionable
February 28, 2015 7:14 pm

If you run this site through Wireshark, you will see it contacting Adobe before it allows the content to be displayed though.

You’ve just convinced me to remove or substitute adobe software on my PC.
If one uses their own font selections in Firefox, does that override the adobe page logging in WUWT?

jakee308
February 28, 2015 7:19 pm

Firefox did an upgrade recently (to 36 and then 37) which broke one of my addons so it could be that something like that is happening.
I reverted to the previous version and the problem went away.
I’m waiting for an FF upgrade down the road to see if that fixes the addon or the addon gets updated.

February 28, 2015 7:53 pm

mei in machina

Global cooling
February 28, 2015 9:17 pm

I installed Ghostery yesterday and then visited my usual pages. Quite expected trackers were found. Let’s keep it for a while.
Adobe typekit had got my attention before this post because Firefox informs about it loading. It is not very slow but having 3rd party stuff takes its toll. What are the benefits of using Adope’s types? My own blog looks fine with WordPress and expond theme without it.
Site owners want to know the visitors. The problems start when Google Analytics and others start to create user prolifes of the individual visitors. Facebook even tries to connect that information to my real identity. Not a good idea from the privacy point of view. Visitors shoud remain anonymous and individual visits should not be connected.

Fletcher
February 28, 2015 10:50 pm

People still use firefox? I uninstalled it they day the fired their CEO for exercising his first amendment rights.

CodeTech
Reply to  Fletcher
March 1, 2015 4:04 am

Really? I wasn’t following that. I just know that at the moment even IE works better that FF… I test everything on the big 3 (FF, Chrome, IE) and have Mac users test on Safari. Only FF continually screws up all the layout details.

waterside4
March 1, 2015 12:25 am

Fletcher at 10:50 pm.
Good point.
Got me wondering is there any ethical products out there who do not support the great global warming scam.
Eg Google, Firefox, Intel, Apple etal all spend vast sums on the propaganda.
Much as I dislike that great old Irish invention the Boycott, could not all Anthony’s fans on here
use our buying power.
Is there any truely indipendant browser out there?
Thanks.

Reply to  waterside4
March 1, 2015 4:40 am

Iceweasel under Trial/TOR

pochas
Reply to  waterside4
March 1, 2015 7:44 am

Ya gotta realize, everyone has to sell to the GW believers or lose half their market. That includes car companies, fossil fuel producers, electric utilities, everyone. You can’t blame them.

Gene Selkov
March 1, 2015 1:23 am

I have blocked all web font kits by aliasing their provider sites to localhost. Besides never having problems like this, doing so allowed me to get rid of serif fonts. I read this blog and pretty much everything else in Helvetica.

March 1, 2015 2:56 am

I just wrote a custom filter line for Adblock Plus for typekit.net and it works fine.
I have an expensive GPU just so that I can take advantage of my high resolution display – and not have to see CRAYON-fonts.

March 1, 2015 6:30 am

I’m having no problem with Firefox, however Intrnet Explorer doesn’t display WUWT and other WordPress sites properly (all I get is a list of links along the left hand margin).
If this also is Ghostery, how do I rid myself of it in IE?
So far, I’ve chosen to not use IE.