Ad blockers are popular Chrome add-ons, which let us manage various websites abilities to serve ads in our browsers.
Many ad blockers include a script blocker. Like NoScript in Firefox, ad blockers may interfere with various Blogger features - such as the "Don't track" script, in the dashboard.
If you publish a Blogger blog, and you have a problem with any pages in the Blogger dashboard, you will want to whitelist "blogger.com" in your ad blocker.
You will do better if you not whitelist "blogspot.com". BlogSpot includes many Blogger blogs - and third party code on those blogs. If you are not very picky about what Blogger blogs you view, you won't do well permitting scripts on every Blogger blog.
Adblock Plus is an extension, in Chrome.
I use "Adblock Plus" as an ad blocker, on my Chrome installations. "Adblock Plus" installs as an app, or an extension.
There are several ad blockers available, for Chrome.
I use the "Adblock Plus" extension, in my Chrome installations.
Start with "More tools" - Extensions.
Select "Options" for "Adblock Plus".
Adblock Plus "options" are also accessible from the browser toolbar. Right click on the ABP icon, and select "Options".
Select the "Whitelisted domains" tab.
Let's whitelist "addthis.com".
Paste / type "addthis.com" into the box. Hit "Add domain".
And now, "addhis.com" is whitelisted.
And having whitelisted "addthis.com", I can support a useful third party social sharing blog accessory, by permitting ads that they host.
Some #Blogger blog owners use ad blockers in their browsers - and see problems with using various Blogger features. The Stats "Don't track", for instance, is vulnerable to ad blockers, and similar filters.
Fortunately, it's not difficult to whitelist "blogger.com" in your adblocker.
target="_blank"
Showing posts with label "Don't track". Show all posts
Showing posts with label "Don't track". Show all posts
Saturday, June 18, 2016
Wednesday, April 20, 2016
Blogger Magic - Enabling Scripts, In Your Browser
Similar to the need to properly filter cookies in the browser, we have the need to properly filter scripts.
Cookies and scripts are completely different elements - but proper filtering of each is essential, to making many Blogger features operate properly.
If you have a problem with Blogger - either accessing / using the dashboard, or using / viewing a blog - one of the simplest things to check, complementing cookie filter settings, is the browser script filter settings.
The browser is the most important component, when setting up security - and scripts, like cookies, are a common challenge.
Script filters are adjusted differently, for each browser. Consider the multiple domains used by Blogger / Google - and layered security, on any computer, used by the owner and readers of any blog.
Setting the script filters in Chrome.
With Chrome, you enable scripts, using Settings ("Customize and control Google Chrome") - aka the 3 bar toolbar icon.
In Settings, if necessary, click on "Show advanced settings" at the very bottom of the page.
Under Privacy, click on "Content settings", which gives you the "Content Settings" wizard. Here, you have selections for Cookies and Javascript - including "Manage exceptions" for each section. Select the recommendation.
Hit "Done" - and close the Settings tab.
From "Privacy", hit "Content settings".
Under "JavaScript", select "Allow all sites to run JavaScript (recommended)".
Alternately, you may select "Do not allow any site to run JavaScript" - then use "Manage exceptions", and allow all blog(s) that you publish, and the many Blogger and Google domains, to run JavaScript. Make your exceptions complete, for best results.
Setting the script filters in Firefox.
Firefox does not contain any native script filters. The most popular add-on for Firefox is NoScript - and this is how most Firefox users filter scripts.
You'll need to designate "blogger.com", "google.com", and any Google domain excepting "blogspot.com", as trusted - when you load any display for the domain in question. An untrusted domain will show a "NoScript Untrusted" icon in the status area at the bottom of the window. To enable each domain, you position the cursor over the NoScript icon and select "Allow (domain URL)" in the popup menu.
Setting the script filters in Edge / Internet Explorer.
With Internet Explorer, you enable security settings - both cookies and scripts - from the browser menu, using Tools - Internet Options. Optionally, you may access the "Internet Options" applet directly from the Windows Control Panel.
Setting the script filters in Opera.
With Opera, you enable cookies and scripts from the Advanced tab, in the Preferences wizard. The Content menu contains selections for scripting.
Setting the script filters in Safari.
With Safari, you enable scripts, using the Preferences wizard. The Privacy wizard, in Preferences, contains selections for scripts ("Cookies and website data”).
Script filters cause problems with Stats "Don't track ..." and other Blogger features.
Many problems, reported in Blogger Help Forum: Get Help with an Issue, with various Blogger features - and the Blogger dashboard - involve script filters.
Stats and the "Don't track ..." option used to involve third party cookies, for many years. In March 2016, the "Don't track" wizard was rewritten to run under the URL of the blog, when being set - and now requires enabling scripts from the blog URL.
Consider how your blog is published.
If your blog is published to "blogspot.com", consider the non "blogspot.com" alias that may be relevant to your country. If your blog is published to a custom domain, consider the custom domain URL.
Many computers have other relevant settings, which block scripts.
Many blog owners and readers will have computers, and networks, with additional protection. Scripts, in the browser, may not be the only filter that needs to be checked - but this is a start, to learning how to control the script filters.
Having checked and corrected your script filters, continue by checking browser cookie filters - then check cookie and script filters, outside the browser. Also check settings on any ad blocker add-on - which may be an app, or a browser extension.
Be aware that many settings may not be obvious - and that both obvious and obscure settings may be updated, without your intention or knowledge.
Many #Blogger problems are cause by overly restrictive script filters. If you, a blog owner or reader, are going to use Blogger successfully, you need to configure your browser properly - for both cookies and scripts.
Cookies and scripts are completely different elements - but proper filtering of each is essential, to making many Blogger features operate properly.
If you have a problem with Blogger - either accessing / using the dashboard, or using / viewing a blog - one of the simplest things to check, complementing cookie filter settings, is the browser script filter settings.
The browser is the most important component, when setting up security - and scripts, like cookies, are a common challenge.
Script filters are adjusted differently, for each browser. Consider the multiple domains used by Blogger / Google - and layered security, on any computer, used by the owner and readers of any blog.
- Chrome.
- Firefox.
- Edge / Internet Explorer.
- Opera.
- Safari.
Setting the script filters in Chrome.
With Chrome, you enable scripts, using Settings ("Customize and control Google Chrome") - aka the 3 bar toolbar icon.
In Settings, if necessary, click on "Show advanced settings" at the very bottom of the page.
Under Privacy, click on "Content settings", which gives you the "Content Settings" wizard. Here, you have selections for Cookies and Javascript - including "Manage exceptions" for each section. Select the recommendation.
- JavaScript: Allow all sites to run JavaScript
Hit "Done" - and close the Settings tab.
From "Privacy", hit "Content settings".
Under "JavaScript", select "Allow all sites to run JavaScript (recommended)".
Alternately, you may select "Do not allow any site to run JavaScript" - then use "Manage exceptions", and allow all blog(s) that you publish, and the many Blogger and Google domains, to run JavaScript. Make your exceptions complete, for best results.
Setting the script filters in Firefox.
Firefox does not contain any native script filters. The most popular add-on for Firefox is NoScript - and this is how most Firefox users filter scripts.
You'll need to designate "blogger.com", "google.com", and any Google domain excepting "blogspot.com", as trusted - when you load any display for the domain in question. An untrusted domain will show a "NoScript Untrusted" icon in the status area at the bottom of the window. To enable each domain, you position the cursor over the NoScript icon and select "Allow (domain URL)" in the popup menu.
Setting the script filters in Edge / Internet Explorer.
With Internet Explorer, you enable security settings - both cookies and scripts - from the browser menu, using Tools - Internet Options. Optionally, you may access the "Internet Options" applet directly from the Windows Control Panel.
- IE uses a zone defense setting, where you designate "blogger.com" and "google.com", in Security, as being in the Trusted zone. Please note that "blogspot.com", in general should not be in the Trusted zone - .
- You will want the published URL of your blog(s) - including any country local domain URLs, in the Trusted zone.
- Default settings for the Trusted zone will allow proper filtering of scripts.
- Verify proper settings, with "Trusted sites" selected, and the Security level slider control set to "Medium". Hit "Custom level", and examine the Settings list.
- Look for the "Scripting" section, 3/4 of the way to the bottom of the list.
- You will observe 6 options under "Scripting". Default settings will have all options Enabled, except "Allow Programmatic clipboard access"; you may wish to Enable this to allow easy use of Post Editor.
- Hit "OK", and "Yes" if necessary, then "OK" again.
Setting the script filters in Opera.
With Opera, you enable cookies and scripts from the Advanced tab, in the Preferences wizard. The Content menu contains selections for scripting.
Setting the script filters in Safari.
With Safari, you enable scripts, using the Preferences wizard. The Privacy wizard, in Preferences, contains selections for scripts ("Cookies and website data”).
Script filters cause problems with Stats "Don't track ..." and other Blogger features.
Many problems, reported in Blogger Help Forum: Get Help with an Issue, with various Blogger features - and the Blogger dashboard - involve script filters.
Stats and the "Don't track ..." option used to involve third party cookies, for many years. In March 2016, the "Don't track" wizard was rewritten to run under the URL of the blog, when being set - and now requires enabling scripts from the blog URL.
Consider how your blog is published.
If your blog is published to "blogspot.com", consider the non "blogspot.com" alias that may be relevant to your country. If your blog is published to a custom domain, consider the custom domain URL.
Many computers have other relevant settings, which block scripts.
Many blog owners and readers will have computers, and networks, with additional protection. Scripts, in the browser, may not be the only filter that needs to be checked - but this is a start, to learning how to control the script filters.
Having checked and corrected your script filters, continue by checking browser cookie filters - then check cookie and script filters, outside the browser. Also check settings on any ad blocker add-on - which may be an app, or a browser extension.
Be aware that many settings may not be obvious - and that both obvious and obscure settings may be updated, without your intention or knowledge.
Many #Blogger problems are cause by overly restrictive script filters. If you, a blog owner or reader, are going to use Blogger successfully, you need to configure your browser properly - for both cookies and scripts.
Sunday, March 6, 2016
Stats "Don't Track" - You Cannot Satisfy Everybody
Blogger recently redesigned the Stats "Don't track ..." option - and removed third party cookies from the picture.
The "Don't track ..." wizard is now accessed from the blog URL. The wizard still produces cookies - but they are ordinary first party cookies, which are much less feared than third party cookies.
But, every silver lining has a cloud.
In making the "Don't track" wizard accessed under the blog URL, Blogger created a new requirement - which is no more understood, by some blog owners, than "third party" cookies.
"Don't track" now runs scripts from the blog URL, instead of the Blogger dashboard.
In order for a blog to observe - and preserve - the "Don't track" setting, any computer that the owner uses has to permit first party cookies - and all scripts - from the blog, instead of from the Blogger dashboard.
Since "Don't track" is designed to be used by the blog owner, this new requirement should not be a problem. Every blog owner should be able to trust herself / himself, to not add dodgy code to his / her own blog.
Owners of blogs published to custom domains will have to tweak the URL used by the "Don't track ..." Stats wizard, to set "Don't track" - since custom domains do not support HTTPS.
Many security products block scripts from personally owned blogs.
Unfortunately, general security practice is to block scripts from "blogspot.com", "blogspot.xx" (for every "xx" for every country local domain"), and preferably for blogs published to custom domains.
You can trust scripts from "blogger.com", and the Blogger dashboard. You cannot trust the individual blogs, since you cannot trust every blog owner. Even if you could trust some people not to intentionally try to hack your computer, you cannot trust everybody to not stupidly install malicious software from a very convincing hacker, providing one more "gotta have this" blog accessory.
And since you cannot trust the individual blogs, you will have filters. And those filters have to be adjusted, to trust your own blogs - if you want to ignore your own pageviews.
Some blog owners add security software, and don't know how to maintain the filters.
There are too many Blogger blog owners who have installed protective software on their personal computers - without knowing how to adjust the filters, in the protective software. And some of those owners think that it is a Blogger responsibility, to provide them instructions, how to adjust the protective software on their own computers - when only they are capable of knowing what they installed.
The new version of the Stats "Don't track" option is an improvement, because it no longer requires third party cookies - and involves the associated security risk. Unfortunately, it now requires blog owners to permit scripts, from the blogs themselves.
This is not a security risk, in that only personally owned blogs need to be trusted - but the blog owners do need to know how to adjust the filters involved. And not everybody with a computer knows how to configure their security accessories.
The "Don't track ..." wizard is now accessed from the blog URL. The wizard still produces cookies - but they are ordinary first party cookies, which are much less feared than third party cookies.
But, every silver lining has a cloud.
In making the "Don't track" wizard accessed under the blog URL, Blogger created a new requirement - which is no more understood, by some blog owners, than "third party" cookies.
"Don't track" now runs scripts from the blog URL, instead of the Blogger dashboard.
In order for a blog to observe - and preserve - the "Don't track" setting, any computer that the owner uses has to permit first party cookies - and all scripts - from the blog, instead of from the Blogger dashboard.
Since "Don't track" is designed to be used by the blog owner, this new requirement should not be a problem. Every blog owner should be able to trust herself / himself, to not add dodgy code to his / her own blog.
Owners of blogs published to custom domains will have to tweak the URL used by the "Don't track ..." Stats wizard, to set "Don't track" - since custom domains do not support HTTPS.
Many security products block scripts from personally owned blogs.
Unfortunately, general security practice is to block scripts from "blogspot.com", "blogspot.xx" (for every "xx" for every country local domain"), and preferably for blogs published to custom domains.
You can trust scripts from "blogger.com", and the Blogger dashboard. You cannot trust the individual blogs, since you cannot trust every blog owner. Even if you could trust some people not to intentionally try to hack your computer, you cannot trust everybody to not stupidly install malicious software from a very convincing hacker, providing one more "gotta have this" blog accessory.
And since you cannot trust the individual blogs, you will have filters. And those filters have to be adjusted, to trust your own blogs - if you want to ignore your own pageviews.
Some blog owners add security software, and don't know how to maintain the filters.
There are too many Blogger blog owners who have installed protective software on their personal computers - without knowing how to adjust the filters, in the protective software. And some of those owners think that it is a Blogger responsibility, to provide them instructions, how to adjust the protective software on their own computers - when only they are capable of knowing what they installed.
The new version of the Stats "Don't track" option is an improvement, because it no longer requires third party cookies - and involves the associated security risk. Unfortunately, it now requires blog owners to permit scripts, from the blogs themselves.
This is not a security risk, in that only personally owned blogs need to be trusted - but the blog owners do need to know how to adjust the filters involved. And not everybody with a computer knows how to configure their security accessories.
Wednesday, March 2, 2016
The New Stats "Don't track" Option, And Script Filters
The new Stats "Don't track" option is an improvement, to many blog owners.
"Manage tracking your own pageviews", as before, starts from the Stats dashboard page. The wizard now runs from a sub directory of the blog managed by the dashboard - and uses a normal (first party) cookie.
Now, blog owners no longer must enable third party cookies, to make Stats ignore their page views. This is an improvement - but it can still present a challenge, for some blog owners.
Besides filtering "third party" cookies, not all blog owners and readers will permit complete control by content under the individual blogs.
If you want "Don't track" to work reliably, enable scripts for the blog URL.
If you want the "Don't track" option to work reliably for your blog, you now must enable scripts to run under the published URL.
We have to trust scripts run from "blogger.com" - that is the Blogger dashboard. The Blogger dashboard is produced by Blogger Engineers - and if we trust Blogger to host our blogs, we have to trust their code.
Scripts which run under the individual blogs - "blogspot.com", local country domains, and custom domains - can be added by the owner of each individual blog. Not all blog owners should be trusted.
People who mistrust third party cookies may also mistrust scripts which run under "blogspot" etc. Unfortunately, to make "Manage tracking your own pageviews" work, you (the blog owner) now have to open up any script filters, which block content run as part of your blog.
Start from the Stats dashboard page.
Click on "Manage tracking your own pageviews".
"Manage tracking your own pageviews" now runs under the blog published URL. This removes "third party" cookies from the problem.
With a custom domain published blog, you must use the wizard in "HTTP:" mode.
By default, the new wizard runs in SSL mode. This will be a problem, with blogs published to custom domains.
If the blog is published to a custom domain, you will need to change "https" to "http".
Check "Don't track my views for this blog." - then close the tab / window.
The new wizard, "Would you like to have your pageviews counted when you visit this blog?", now runs as "blogging.nitecruzr.net", for this blog.
If you publish to a custom domain, and you can correct the URL, you will see the same, for your blog. If you publish to "blogspot", you can see the same also. This is a script - and the script is subject to security filters.
And yes, there is no "Save" button, or link. Just the box.
Click the box or don't. As soon as you click, it's set. If you change your mind - now or later - click the box, again, and clear the option.
You should trust your blog - even though you do not trust other blogs, in general.
Generally, as the blog owner, you can safely trust content run under your blog. You probably should not trust "blogspot.com", and all blog publishers, however. This means that you will require multiple filter rules - for every browser and security add-on, that contains a script filter.
If you publish to "blogspot.com", and live in a country which has a local domain, such as the UK, you need a rule to permit the local domain alias.
If you have multiple blogs - and want to block pageviews from being counted, for each blog, you need permissive filter rules for each blog.
If you publish your blog to a custom domain, you need a rule to permit the domain URL. For this blog, I need
If you do not permit the proper URL(s) for your blog, you will find Stats counting your own pageviews. Possibly, this will happen even with "Don't track my views for this blog." checked. In some cases, the check mark will be cleared, when you close the window.
Owners of #Blogger blogs who don't want their activity tracked by Stats now see a new "Don't track" wizard. Using the "Don't track" option no longer requires enabling third party cookies - and worrying about the security issues.
Unfortunately, this now means that the "Don't track" wizard may now be vulnerable to filters which restrict scripts that run under blogspot, and any custom domains.
"Manage tracking your own pageviews", as before, starts from the Stats dashboard page. The wizard now runs from a sub directory of the blog managed by the dashboard - and uses a normal (first party) cookie.
Now, blog owners no longer must enable third party cookies, to make Stats ignore their page views. This is an improvement - but it can still present a challenge, for some blog owners.
Besides filtering "third party" cookies, not all blog owners and readers will permit complete control by content under the individual blogs.
If you want "Don't track" to work reliably, enable scripts for the blog URL.
If you want the "Don't track" option to work reliably for your blog, you now must enable scripts to run under the published URL.
We have to trust scripts run from "blogger.com" - that is the Blogger dashboard. The Blogger dashboard is produced by Blogger Engineers - and if we trust Blogger to host our blogs, we have to trust their code.
Scripts which run under the individual blogs - "blogspot.com", local country domains, and custom domains - can be added by the owner of each individual blog. Not all blog owners should be trusted.
People who mistrust third party cookies may also mistrust scripts which run under "blogspot" etc. Unfortunately, to make "Manage tracking your own pageviews" work, you (the blog owner) now have to open up any script filters, which block content run as part of your blog.
Start from the Stats dashboard page.
Click on "Manage tracking your own pageviews".
"Manage tracking your own pageviews" now runs under the blog published URL. This removes "third party" cookies from the problem.
With a custom domain published blog, you must use the wizard in "HTTP:" mode.
By default, the new wizard runs in SSL mode. This will be a problem, with blogs published to custom domains.
If the blog is published to a custom domain, you will need to change "https" to "http".
Check "Don't track my views for this blog." - then close the tab / window.
The new wizard, "Would you like to have your pageviews counted when you visit this blog?", now runs as "blogging.nitecruzr.net", for this blog.
http://blogging.nitecruzr.net/b/statsCookieManage
If you publish to a custom domain, and you can correct the URL, you will see the same, for your blog. If you publish to "blogspot", you can see the same also. This is a script - and the script is subject to security filters.
And yes, there is no "Save" button, or link. Just the box.
Don't track my views for this blog.
Click the box or don't. As soon as you click, it's set. If you change your mind - now or later - click the box, again, and clear the option.
You should trust your blog - even though you do not trust other blogs, in general.
Generally, as the blog owner, you can safely trust content run under your blog. You probably should not trust "blogspot.com", and all blog publishers, however. This means that you will require multiple filter rules - for every browser and security add-on, that contains a script filter.
- Block all "blogspot.*". (Please!).
- Permit "yourblog.blogspot.com".
If you publish to "blogspot.com", and live in a country which has a local domain, such as the UK, you need a rule to permit the local domain alias.
- Permit "yourblog.blogspot.co.uk".
If you have multiple blogs - and want to block pageviews from being counted, for each blog, you need permissive filter rules for each blog.
- Permit "yourblog1.blogspot.*".
- Permit "yourblog2.blogspot.*".
- etc.
If you publish your blog to a custom domain, you need a rule to permit the domain URL. For this blog, I need
- Permit "blogging.nitecruzr.net".
If you do not permit the proper URL(s) for your blog, you will find Stats counting your own pageviews. Possibly, this will happen even with "Don't track my views for this blog." checked. In some cases, the check mark will be cleared, when you close the window.
Owners of #Blogger blogs who don't want their activity tracked by Stats now see a new "Don't track" wizard. Using the "Don't track" option no longer requires enabling third party cookies - and worrying about the security issues.
Unfortunately, this now means that the "Don't track" wizard may now be vulnerable to filters which restrict scripts that run under blogspot, and any custom domains.
Monday, February 29, 2016
Stats And "Don't track", And Custom Domains
Blog owners have been trying to block tracking their own Stats pageviews, for a few years.
This option has long been unusable, for blogs published to custom domains. Recently, Blogger Engineering updated the option - and the dashboard page with the link.
The new Stats option to "Manage tracking your own pageviews" is an improvement, over the old dashboard page.
The new Stats option page is run as part of the blog - not the Blogger dashboard - so it does not require third party cookie access. Unfortunately, this provides no obvious help, to people who publish their blogs to custom domains.
To see the problem, start from the Stats dashboard page.
Click on "Manage tracking your own pageviews".
And, you get "This site can’t be reached" or a similar error.
Custom domain published blogs do not support HTTPS access - even from the Blogger dashboard.
So, change "https:" to "http:", in the address window.
If you manually remove the "s", you can access the "Would you like to have your pageviews counted when you visit this blog?" wizard.
You can't access the "Manage tracking your own pageviews" for a custom domain published blog, by simply clicking on the dashboard link.
This suggests an interesting detail. Now that "Manage tracking your own pageviews" runs under the blog URL, it will be subject to script filtering - for "blogspot.com", any applicable country local domains, and / or a custom domain URL.
You may need to correct your browser script filter, to make "Don't track" work, now.
Owners of custom domain published #Blogger blogs have been wanting to block Stats from counting their own pageviews, for a few years. This option is now available - but not in an obvious way.
This option has long been unusable, for blogs published to custom domains. Recently, Blogger Engineering updated the option - and the dashboard page with the link.
The new Stats option to "Manage tracking your own pageviews" is an improvement, over the old dashboard page.
The new Stats option page is run as part of the blog - not the Blogger dashboard - so it does not require third party cookie access. Unfortunately, this provides no obvious help, to people who publish their blogs to custom domains.
To see the problem, start from the Stats dashboard page.
Click on "Manage tracking your own pageviews".
And, you get "This site can’t be reached" or a similar error.
Custom domain published blogs do not support HTTPS access - even from the Blogger dashboard.
So, change "https:" to "http:", in the address window.
If you manually remove the "s", you can access the "Would you like to have your pageviews counted when you visit this blog?" wizard.
http://blogging.nitecruzr.net/b/statsCookieManage
You can't access the "Manage tracking your own pageviews" for a custom domain published blog, by simply clicking on the dashboard link.
This suggests an interesting detail. Now that "Manage tracking your own pageviews" runs under the blog URL, it will be subject to script filtering - for "blogspot.com", any applicable country local domains, and / or a custom domain URL.
You may need to correct your browser script filter, to make "Don't track" work, now.
Owners of custom domain published #Blogger blogs have been wanting to block Stats from counting their own pageviews, for a few years. This option is now available - but not in an obvious way.
Subscribe to:
Posts (Atom)















