Geolocation API removed from unsecured origins in Chrome 50
developers.google.com
developers.google.com
And because having your fine location cross the wire unencrypted is a terrible idea :)
https://www.cloudflare.com/ssl/#cloudflare-ssl-options
cloudflare's "flexible ssl" option encrypts the connection between their datacenter and the user, but not the one between the datacenter and the actual web server
i guess it's better than nothing if your host doesn't support ssl but the false sense of security could be harmful
Honestly if google really wanted to push this, they would do something to penalize http only ads. That would really pressure advertisers to upgrade or lose.
* Images served over unencrypted connections will have 50% of their pixels randomly scrambled.
It won't work with file:/// urls, but localhost is fine.
At least it was for me in 49 a couple weeks ago.
navigator.getUserMedia({
video: true,
audio: true
},
console.log.bind(console, 'success'),
console.log.bind(console, 'error')
);
Chrome v50.0.2661.94 (64-bit) on OS XDon't get me wrong - I think this is a good thing. And I don't know that the answer is a big, publicized drop of all these changes at once, although that would have certain advantages. But a trickle of dropped features that non-technical folks will never see announced is going to be a lot of fun for web developers.
In other words they are trying to hide the geolocation data from proxies, Carriers, ISPs and someone possibly MitM attacks
Edit: Apparently there are free certificate suppliers, but will those be sustainable if HTTP is eventually fully phased out? Browsers display errors with self-signed certificates, so it still seems problematic in the long run to have to depend on the good graces of other parties if you want to serve web content.
Glad this was included. Is https even meaningful when on a local server?
window.navigator.geolocation.getCurrentPosition(function() { console.log(arguments); })
This shows me the coordinates and no Error is thrown.Chrome version:
Version 50.0.2661.94 mGeolocation API is pretty powerful. It's one thing for a random website to know approximate location, but to be able to track location within 10m is something else.
I'm weird, but it always grates slightly when companies throw their weight around - even if the endgame is a positive outcome.
Plus the cynic in me assumes they have an advertising product in the works and this is facilitating it.
> There is zero reason for an ad to be using the Geolocation API. IP-based geolocation is more than enough.
There was also zero reason for billboards by highways, before there were highways. :)
Obviously this is all a sliding scale and has nuance, but I'd say ads should not be using anything that is behind a permission prompt, like geolocation. Tremendously hostile to both the user and the site hosting their ad.
More than likely they'll just correlate browsing habits with location and sell that information to third parties, though. High quality advertising is just not in this reality.
I mean, for all you know, I'm in a domestic abuse shelter. Are you going to take responsibility for my well-being if your clients' database gets leaked? And are you confident that your clients know how to competently secure a database if they can't even use HTTPS?
edit: Sorry, partial post due to accidentally hitting enter.
While we do use geolocation and ads on one of our sites, it's only a single page so this doesn't really affect us that much. I can see it causing big problems with ad-supported sites / services that use geolocation as a primary feature though as I've experienced first-hand the revenue drop that HTTPS causes.
The reason for wanting the user's location doesn't matter. It's incredibly irresponsible to send the user's location (or any other user data) over the network unencrypted.
Edit: never mind, that is apparently also "insecure", leading me to think they are doing this because they get a kickback from the SSL cert vampires somehow.
In a way, it's good -- privacy on the web improved more in the last 3 years than in the previous 15 -- but it's also a massive charade.
Do they support just downloading a file from them and then uploading it my server, as proof that I control the domain? That should be enough.
You can use one of the alternate clients people have written, or write your own:
https://github.com/xenolf/lego
https://github.com/ericchiang/letsencrypt
Or use this web interface:
Also you can configure it to give you longer lasting certs.