Designing for accessibility — you can help!

We have the concept of designing for accessibility for the disabled, but we need to include the idea of designing on the web for accessibility to those who are reaching us through national firewalls, or simply concerned with privacy and security. In cooperation with Reporters without Borders, I’m putting together a guide for safer anonymous use of the Internet, this summer.

Right now, we’re documenting and collecting methods that compromise privacy even with the use of anonymity software such as Tor.

Use of some technologies will make a site inaccessible to people practicing “safe surfing.” For example, people with concerns about strong anonymity will surf with javascript turned off in their browsers. If you are concerned that your site should be accessible particularly to users in countries with free speech restrictions, you need to design a site that does not use javascript for anything crucial to navigation or understanding the site.

Javascript can be “leaky” — as a server-side technology (code that is sent from the web site to be run on the surfer’s machine) the user has no control over what a bit of javascript code will ask for. Javascript can reveal the true IP number of a user shielded by a proxy, among other information.
Another piece of code we advise anonymity users to bypass is the Adobe PDF plug in. At the time I write this, this plug in ignores the proxy settings on the user’s machine, and fetches the file to display in the browser window directly. I’ve sent email to Adobe hoping they’ll fix this problem before we publish our guide in the fall.

If you are a person who plays with network security, we’d like you to find ways that plug-ins, applications and system settings can by-pass proxy settings and compromise user anonymity. Comment here contact us through http://tor.eff.org/. Thanks!

33 Responses to “Designing for accessibility — you can help!”

  1. ska says:

    >Javascript can be “leaky” — as a server-side technology
    Thats nonsense. You give the right description –
    >code that is sent from the web site to be run on the surfer’s machine
    but that is called *client*-side.
    >the user has no control over what a bit of javascript code will ask for
    Thats incorrect too. As a client-side app you can control JS code and deny or allow certain actions. That’s how Privoxy works, and the bunch of other proxies. The problem is that the only reliable way to control JS is from browser which implements JS-machine, in all other cases JS code can be obfuscated etc. And the browsers’ developers don’t want to spend their time on such a feature – that’s understandable..
    >Javascript can reveal the true IP number
    How?! JS by itself in a properly written JS machine cant obtain IP address of the computer it runs on. Of course it can create cookie and that cookie will become an identifying sign for everyone who sees it; further you use the browser without Tor with the cookie set in the Tor mode – and you are caught 🙂

  2. i refer java over anything else.. cookies arent a problem most of the time..

  3. […] continued here « Devaluing anonymous political […]

  4. unix linux says:

    >Javascript can be “leaky” — as a server-side technology
    Thats nonsense. You give the right description –
    >code that is sent from the web site to be run on the surfer’s machine
    but that is called *client*-side.

  5. php, mysql says:

    >Javascript can reveal the true IP number
    How?! JS by itself in a properly written JS machine cant obtain IP address of the computer it runs on. Of course it can create cookie and that cookie will become an identifying sign for everyone who sees it; further you use the browser without Tor with the cookie set in the Tor mode – and you are caught

  6. В советское время рецепты салатов «Столичный» и «Оливье» неоднократно ухудшались, одни ингредиенты заменялись другими. В наше время под названием «салат Оливье» подразумевается смесь варёного картофеля, майонеза, солёных или маринованных огурцов, зелёного горошка и иногда колбасы или курицы, и к настоящему салату «Оливье» отношения, разумеется, не имеет. Простота изготовления и доступность ингредиентов сделали этот салат чрезвычайно популярным блюдом как в советские годы (он был непременным атрибутом советского праздничного стола на 7 ноября и Новый год), так и в наши дни. Другое название современного рецепта этого салата — «Зимний» (возникло из-за того, что его ингредиенты легко доступны в зимнее время, в отличие от ингредиентов «летних» салатов).

  7. net-market says:

    You talk about cookies, and java, and activeX and I am sure these are all security “problems”. However, there are a lot more. Pentium IIIs and better each have a personal ID in them,and I have a hard time believing the bios can disable it, after all, it is an op code. Also, I suspect that most bios have a serial number that could be accessed, and what about your windows key code, your ethernet card’s mac address. I am sure there is more, but this should be enough to make you think.

  8. i think java scripts can do it .

  9. JJC says:

    You talk about cookies, and java, and activeX and I am sure these are all security “problems”. However, there are a lot more. Pentium IIIs and better each have a personal ID in them,and I have a hard time believing the bios can disable it, after all, it is an op code. Also, I suspect that most bios have a serial number that could be accessed, and what about your windows key code, your ethernet card’s mac address. I am sure there is more, but this should be enough to make you think.

  10. Oteller says:

    We hope this year will end the economic crisis

  11. alyans says:

    Thanks for your suggestions…

  12. image share says:

    bu blog bence daha fazla yazı ve bilgi içermeli, editör daha fazla konuyu bu forumda paylaşmalı, eğer türkçe bölümde açılırsa ben bu konuda yazılarımı gönderebilirim..

  13. Thanks share.this is a great article.

  14. Hi, I hope it’s good for my writing assignments, if I get a note if I do not repeat here

  15. Artem says:

    Thanks for your suggestions

  16. thanks for the info it was very informative 🙂

  17. Thank you for taking the time to post!

  18. I had trouble finding this information on the Internet!

  19. I agree that some things probably could be done differently

  20. Great, thanks. Very cool post

  21. Also, I suspect that most bios have a serial number that could be accessed, and what about your windows key code, your ethernet card’s mac address. Javascript can reveal the true IP number of a user shielded by a proxy, among other information.

  22. toner dolum says:

    In addition, many people need these informations everyday.

  23. Its a shame to ignore the great possibilites that the use of javascript can present especially the powerful jquery library. That said, one must be exceptionally careful that it is not left open to exploit. One of the major problems is the use of scripts blindly, ie including scripts that people have shared online without understanding all of the implications. I would also apply the term client-side technology to javascript rather than server-side.

  24. baki karakoc says:

    Great, thanks sharing

  25. Thank you. An issue that can be easily overlooked.

  26. I hope Adobe has now fixed this.

  27. Bravo, I enjoyed every moment of reading this, and I really appreciate stating this.