Read one page, ask many servers
Opening a web page rarely means asking just one server. The font comes from a font service, a counting script from an analytics service, the video from a platform. Each of these requests tells one more company at least your IP address and usually the website you are on. And a script can change a page after it has loaded without you noticing.
This website does none of that. Here your browser talks to a single server, and it runs no script. This post shows where that is laid down, how it is checked and what it costs.
The rule lives in a header
With every page, the server sends the Content-Security-Policy header. It tells the browser what a page may load and do:
default-src 'none'; style-src 'self'; font-src 'self'; img-src 'self'; base-uri 'none'; form-action 'none'; frame-ancestors 'none'; upgrade-insecure-requests
| Directive | Effect |
|---|---|
default-src 'none' | The basic rule: only what another directive explicitly allows is loaded. For scripts, embedded frames, audio, video and background requests there is none. |
style-src 'self' | Stylesheets only from our own server. Style rules written directly into the HTML are blocked. |
font-src 'self' | Fonts only from our own server. |
img-src 'self' | Images only from our own server. |
base-uri 'none' | No page may redirect the base address of its links. |
form-action 'none' | Forms may not be submitted anywhere. |
frame-ancestors 'none' | No other website may embed these pages in a frame. |
upgrade-insecure-requests | The browser fetches unencrypted addresses of our own content over an encrypted connection. |
The policy does not rely on our diligence. It is an instruction to your browser: if a script did end up in a page by mistake, a browser that honours the policy would not run it.
Two more headers belong with it. Referrer-Policy: no-referrer instructs the browser not to reveal, with any request, which page you came from. Strict-Transport-Security makes it remember for two years that this domain is only ever requested over an encrypted connection.
Checked twice: before publication and in the browser
Good intentions do not hold by themselves. So before every publication a check script searches every built page: for scripts, for style rules in the HTML and for addresses of third-party servers, in links as well as in embedded files and in the stylesheet. A match stops the publication, and the previous release stays online. The second check is done by your browser on every request, using the header above.
The script also catches ordinary links to other sites. That is why this website links nowhere outside itself.
Our own fonts. No statistics.
The three font families EB Garamond, Geist and Manrope are files on this website's server. They come from the fonts' published packages; to deliver them, neither the server nor your browser asks anywhere else. The font files are listed in the website's bill of materials, their hashes in the published file inventory.
Visits are not analysed. The web server keeps no access log, there are no statistics, not even aggregated ones, and the website sets no cookies.
The price: what this website cannot do
- No form. There is no contact form, no comments under this post and nothing to subscribe to. You can reach us by email; the addresses are in the imprint.
- No search. A search would need a script in the browser or a program on the server that processes input. Neither exists here.
- No embeds. No video, no map, no embedded post from another platform.
- No outbound links. Sources appear as text that you have to copy, for example in the comparison.
- No numbers. We do not know how many people read this page or which page nobody finds.
What this does not solve
The rule describes what your browser does on this website. It is not evidence of the origin of every component on the server. To deliver a page, the server processes your IP address and the request. System and security logs are kept for its operation and may, for example, include the IP address of a failed administrator sign-in; the system journal is limited to seven days.
The header comes from the same server as the page. Anyone in control of the server could change it too. And what your browser does of its own accord, such as resolving names through your network's DNS service, is outside the website's control.
The rule applies to this website, not to sign-in and webmail at privymail.eu. Both need JavaScript: during sign-in the browser does the computation that keeps the password on your device. Where a form is protected against automated submissions, it solves a computational puzzle. And webmail is an application in the browser.
Further reading
How the website processes data is described under Privacy. The software and the fonts are listed under Open source, the signed state under Transparency. How that inventory is produced is explained in This website can be verified. Sign-in has posts of its own: on the password protocol and on protection against automated form submissions.