Defaulting to discourse.org CDN for avatars is a privacy and security risk

This is not correct

http://avatars.discourse.org/.well-known/dnt-policy.txt

The issue is not serving these letters, it generating them at scale, especially when algorithms change. Its 300ms of work to generate the original and then another bunch of work for each resize, in scale this adds up.

see:

https://meta.discourse.org/t/optimizing-letter-avatar-rendering/33082

So yeah, if you are not happy with our do not track policy and want to take the hit yourself, disable the site setting.

4 Likes