Google bans niche browsers from Gmail?
reddit.com
reddit.com
Their reasoning is so baffling, and technically incorrect about browser performance and security, that there is one conclusion to be made: Google and the Chrome team is dishonest about why they're partially deprecating the webRequest API.
Extensions are free to observe requests and page content, and exfiltrate data at will, but you no longer have full control over the requests Chrome is making. It is about control, not your privacy and security.
The big organisations behind browsers have been spinning it this way for years, and unfortunately the majority still haven't realised the truth. It's the same strategy that makes "think of the children" and "war on terrorism" arguments so pernicious --- taking away freedom by reasoning that it's for a cause so "ostensibly good" that no one would be seen arguing against.
They know some would argue against.
What gives this away as "spin" is that they will not make these changes optional.
A Google user cannot opt out of signing in with Javascript enabled and permitting a device fingerprint to be taken. Even in the case where the user can accept the risks of allowing sign in without JS, e.g., automated sign-in -- which as we know is very convenient for many HN readers -- there is no way to opt out.
For example, the user may have email accounts that she does not use for anything sensitive, throwaway accounts. More savvy users, who truly are concerned about security of Google Mail, might purposely avoid using @gmail accounts for important matters.
It is of little benefit to such users if Google fingerprints their devices "in order to keep [those] accounts safe".
However, the benefits to Google of identifying users via device fingerprinting are numerous. Google is an online advertising sales company.
Between my laptop running Linux, on which I am root and no changes in software are made unless I specifically authorize it, and an Android tablet which is constantly downloading "updates" from Google (and uploading god-knows-what), I know which one makes me feel more private and secure.
E-mail clients don’t serve ads.
For security reasons, they block linked content by default, meaning google can’t track what I do with my e-mails.
Google can terminate an account any time without any reason, if they do that, I won’t lose access the e-mails I’ve received or sent.
My screen refresh rate is 60Hz, ping from here to gmail.com 36ms, this means web interface has at least 3x latency compared to a locally running app.
I don’t care about their web interface re-designs, or browser compatibility issues like the one discussed.
Gmail can’t turn off IMAP as it would break e-mail on smartphones. Large share of these smartphones run old versions of Google Android which will never be updated, this also helps to ensure their IMAP access is here to stay.
A) Assuming you keep copies of all folders/emails locally B) Assuming Google isn't evil and won't delete all your mail first before shutting down your account, thus causing your IMAP client to sync their deletion
B) I’m not sure Google ain’t evil. Even if they’re good, if I fail security on my side, some other evil person, unrelated to google, may be able to delete all my e-mails before shutting down my gmail account. That’s why e-mail client alone is good but not enough, also need backups of that local DB.
We can't know that. There is no recourse when they do screw people and it would look the same from the outside whether it was an automated system or a manual one (or more likely, a mix of both).
B)That's why you do backups. (In the same vein as RAID is not a backup, IMAP by itself isn't one too).
An easy way to do that is to have an IMAP client on another machine that you sync manually.
I have reproduced this on OpenSUSE Tumbleweed, with stock Falkon browser (QT+Webkit) and javascript enabled. I have confirmed that this is accomplished through UA sniffing. I reproduce the message in plaintext below:
Sign in with a supported browser To help protect your account, Google doesn’t let you sign in from some browsers. Google might stop sign-ins from browsers that:
Don’t support JavaScript or have Javascript turned off. Have unsecure or unsupported extensions added. Use automation testing frameworks. Are embedded in a different application.
Time to get off my ass and switch email providers, finally.
[EDIT] incidentally, is this what we can expect to see on more and more sites as Google's new version of Recaptcha rolls out?
I still have a few Gmail accounts for clients, and my Fastmail accounts get about half the spam.
I find it a security threat that websites are able to tell what extensions I have installed, supported or otherwise.
Maybe in the future we could run the website in one version of the DOM, hidden from the user, and then have the adblocker make a separate DOM that is displayed to the user. That loses almost all of the anti tracking and most of the security benefits though.
It wasn't really fully resolved until the browser engine was switched to Blink/Chromium.
Now, of course Opera is ~indirectly managed by the chinese government, so no-one should be using it. Please just trust me on this one. The desktop browser is now built in Poland (not Norway/Sweden). The remaining technical management is very weak when it comes to things like principles.
That is generally speaking a true statement, regardless of which Chinese company you're speaking of. Do you want a source on that?
"Opera is a freeware web browser ..., developed by Opera Software, a Norwegian software company, ... with the majority of ownership and control belonging to Chinese businessman Zhou Yahui, founder of Beijing Kunlun Tech and Chinese cybersecurity company Qihoo 360."
The same document is now obsolete - it claims "If you're using a browser that isn't supported, you'll see Gmail in HTML view." This is not true, as in fact what you'll see is "up yours, go away".
What is happening here is Google is only requiring Javascript to be turned on when the user signs in so Google (or its partners) can uniquely track users, even when users have indicated they do not want to be tracked, such as using session-only cookies, clearing stored cookies after signing out, enabling the DNT header, etc.
I don't sign into any Google services in my web browser. If I need to sign in with Google, I use incognito or a separate browser profile if it's constantly necessary for some set of tasks.
They're still probably tracking me, but I don't care as much about that as I do about not getting locked into any one platform. The only Google service I'm really hooked on is their search but I'll switch away from that the second that it becomes unbearable to use. I've done stints on DDG and I'll be perfectly happy using that whenever Google search really starts going south.
Credential stuffing is a large enough problem for account takeover and the cost to a user of losing their gmail account so high that at some point a team has to make tradeoffs about what can and cannot be used to log in.
edit: am Googler, not working on this area. Have background in account takeover/browser fingerprinting.
As if there were not already enough domains (and redirects) required... just to log in
Think about how many important accounts you link through email and then think about how, if you don’t pay for gmail, Google doesn’t owe you access to your email or any service at all.
It feels great being free and you can setup forwarding so you can pick up the stragglers.
You also get the added spam freedom and security benefit of changing both your email and password which is great since we have no idea what leaked email/password lists are floating around out there... it’s like the ultimate unsubscribe!
https://support.apple.com/en-us/HT206181
"Invite others to your documents and work on them together in real time. Collaboration is built into the iWork apps on iPhone, iPad, iPod touch, Mac, and iCloud.com"
Last time I remember using modern-ish GUI Office-type programs that felt this respectful of system resources was years ago when I used Linux, and I dropped OpenOffice (too damn heavy and slow) for some of the single-purpose alternatives like Gnumeric (is that even around anymore?). Apple's various utility and basic productivity programs are really damn good (god I love Preview) and a big part of what keeps me suffering through all the bad things about Apple products.
Virtually 100% of my clients can open Word / Excel / Powerpoint documents, and you'll have to pry Excel from my cold, dead hands =). I personally love the power features of Excel, and even do some VBA scripting to automate some workflows in Excel and Outlook.
I don't do much real-time collab on documents at the same time with other folks on my team, so I can't attest to that - though I hear that Msft has come a long way here and the Fluent roadmap looks really promising.
If you have a column of phone numbers with leading zeroes, coming in from a csv, it decides it's a number and drops the leading zero, which breaks the phone number.
And everyone knows, Microsoft Office isn't perfect...
However you also gain something. For me personally actually three things:
* I no longer feel like the service I’m using is like a rug that can be pulled from under my feet at any moment
* My data (mail, documents, etc.) are now actually under my control and not in some “arbitrary“ format on a server I can’t reach except from my browser
* As a bonus feature, my mail is only read by me and my behavior is tracked by no one
> if you don’t pay for gmail, Google doesn’t owe you access to your email or any service at all.
Also, fastmail web UI was okay but not great. I do like the new GMail UI better.
I have been using fastmail for one year and had zero other problems. If we don't move away from gmail, we will lose email, which is one of the only true decentralized and free protocols still left.
I think it's time we organise ourselves as small mail provider organisation. Anybody feeling the same please ping me.
Basically, you have to take a set of ritual steps to "warm" various email resources (such as domains, addresses, and IPs) to be flagged as "known" and "legitimate". For example, IP addresses: you should send warming emails to a valid address that you control for a few weeks to just show up on lists without having spam marks against you.
It's insane.
Compare to Yahoo. The first one to my @yahoo.com address was classified as spam, but then after I told Yahoo that it was not spam, subsequent ones come through fine.
Has anyone ever successfully got SPAM management working using the native O365 tools?
Could you provide some examples where a user was denied access to his/her email?
Then if you create a rule at the new provider that files those messages into a dedicated folder, that folder essentially acts as a todo list for accounts that need updated.
Get rid of dependancy on others, you dont need it. And with some basic knowlidge it is not even hard. You dont need google or anyone else for email communication.
I have a dual CPU workstation and the jump to a proper server is just insane, even to me.
Also with a $100 worth UPS, raspberry pi lasts forever. And pi is all you need.
However, as i pay Google for many other services, that means I am vulnerable to total and permanent account lock out if someone steals my credit card and gets it flagged by Google as fraudulent, as has been reported by more than one blog post. As long as Google does not address the issue of customer service being within their top 25 list of priorities, it is insane for anyone to use Gmail for important mail identities.
I still use K-9 Mail to handle my non-gmail accounts. I find it very usable with how it threads my work emails.
Although from what I understand its not actively developed anymore and the last post I see on the playstore says Sept 2018. I'm open to suggestions if anyone has them, especially if they are available via F-Droid.
That’s hardly an app. I love fastmail and have been a happy paying customer for years. But that’s their biggest pitfall.
They love their product and making it better so I think constructive criticism is welcomed there.
You can do this in Fastmail (presuming you don't have the reading pane turned on, i.e. are in the same layout as Gmail).
> expanding / contracting threads at once
Shift-click a message header to apply to all at once, or "Shift-E" kb shortcut to expand all.
> having drafts inline with the thread that I can leave and return to seamlessly
We take a slightly different approach, but using Cmd-Shift-S will toggle you instantly between your draft and the thread you are replying to, preserving your scroll position in both.
EDIT: this message alerted me to the fact that there is a "hide reading pane" option so I am experimenting with that to see if this solves my problem. Also it would be SUPER helpful if the arrow keys would navigate through the message list like gmail does, J/K continues to be less comfortable for me.
If I check one of the messages/threads in the messages pane, such that I'm selecting it for being marked as read or deletion or something like that, in the right hand "read" pane, the message/thread on the right side turns into a single bar that is unreadable. in gmail I can select as many messages as I want and move back and forth between the "messages" and "Read thread" panes, using the enter key to read, semicolon to expand thread, and "u" to return to the message list, and the selections remain.
I have not been able to identify any similar flow in Fastmail; it forces me to deal with only one thread at a time, and I cannot read a message/thread that is also selected; clicking on it deselects it. So I can't select a series of messages and also read them, it would take a rethink of Fastmail's UX architecture for it to be possible.
> Shift-click a message header to apply to all at once, or "Shift-E" kb shortcut to expand all.
OK, Gmail's semicolon / colon toggle is much easier to use and also includes collapsing the thread also can this be added?
> We take a slightly different approach, but using Cmd-Shift-S will toggle you instantly between your draft and the thread you are replying to, preserving your scroll position in both.
OK, that is definitely more awkward. in gmail I can just scroll up to read the other messages in the thread, which is important because I often have to go back and read messages I'm responding towards. In fastmail, this would mean the "edit draft" button would give me an inline composition window that scrolls with the thread. This could be added to Fastmail with a lot of work but the UX at least does not prohibit this from being graphically feasible.
For sure to each their own and no app is perfect. (I would love Fastmail on android to have offline functionality for instance)
If ProtonMail did a calendar though I would be using ProtonMail right now
I use IMAP and SMTP, and it just works. I can move and delete mail. No weird All mail folder, semi-automatic weird Trash, resurrecting messages and duplicates that are annoying to get rid of.
Overall, I hope they don't add complicated gimmicks or weird behaviours like gmail.
I found out about SPF, DKIM, and DMARC and set them up, followed all the other instructions on assorted Google sites, and still no go. Apparently the blocks can take weeks to clear or may even be permanent. The reject emails say to contact postmaster@google.com which, of course, is pointless since I can't email the domain. I don't even think there's anything behind it if I could. There's no way to contact any person or group regarding the block which I think must have happened due to spoofing.
From what I can see, domains these days are assumed to be commercial for mass mailings and having one's own for incidental use is an outlier.
I'm not actually upset, though. Such is life when you rely on entirely free services provided by another company. It's almost like the role Google plays in my life is that of some natural phenomena, perhaps as seen by an ancient civilisation: omnipresent, inscrutable, unthinkingly capricious. Such is the way is the world, my son.
As a web developer though I know the agent shortcut is tempting. Without it I imagine we'd have to wait for a quorum of popular browsers before dropping feature detection for any given capability.
EDIT: Chrome's user agent doesn't work, but Firefox's does. I suppose it works because if Google's sign-in form sees a Chrome user agent, it expects a certain different browser fingerprint, so it rejects it. But maybe it's more lenient on the fingerprint match if it sees a Firefox user agent. This one worked for me, from https://techblog.willshouse.com/2012/01/03/most-common-user-...
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0What exactly will it break?
Some examples (there are lots more via IRC/Reddit/...):
https://github.com/qutebrowser/qutebrowser/issues/4302 https://github.com/qutebrowser/qutebrowser/issues/3822 https://github.com/qutebrowser/qutebrowser/issues/1187
> if(browser == firefox) {new_feature_chrome_does_not_support()} else {old_feature()}
instead of
> if(new_feature in navigator) {new_feature()} else {old_feature()}
This goes against Google's own web accessibility guidelines circa 2008 that they seemingly ignore now, but was the reason I left internet explorer to begin with.
Then my host pushed, despite objections from the community, atmail, a proprietary gmail-alike webmail interface. It is even more buggy, and slow as hell, but hey, at least it looks "cool".
Fixed it in the end by just bookmarking the two account pages separately.
I think we'd see that deal cancelled before Google dropped support for Firefox.
Until it is no longer in Google's interest to do so.
Sure, you have a nine million character password with eight hardware factors to turn on your light bulb... but you have to realize that's rather uncommon.
All the big service providers have a large problem with botnets logging in to accounts with stolen credentials, or with fake spam accounts they created themselves. They do this with automation and so detecting automation is a good way to detect and stop them without major inconvenience to users (who generally don't automate their own Google accounts).
The nature of this technique means their servers can't tell the difference between a niche browser and a dedicated abuse tool. If a tool claims to be Chrome and gets spotted because it's not, the obvious fallback is to just make up new user agents that are rare or unusual. Sure, the traffic is very visible to humans who may be watching post-hoc, but a UA is just a string so it can be constantly changed. Blocking bad traffic means adapting to changes in it automatically and quickly. So eventually this pushes companies towards just locking out browsers nobody uses because it's too hard to tell them apart from malicious automation software.
That's unfortunate: it makes it harder for someone to get traction with a genuinely new rendering engine. But those cost billions of dollars to develop these days and even Microsoft doesn't want to play that game anymore, so it's a rather theoretical loss compared to the gains, which are large and real.
Source: I used to work on this stuff.
A world in which there are no hacked accounts is also one in which there is no freedom. Choose carefully...
I mean, why would anyone who goes out of their way to use a "niche browser" even have a Gmail account?
Edit: My point here is that Google is so invasive and fundamentally hostile to privacy that using it with anything more secure than Firefox seems futile. And if you love some niche browser so much, go for it. But use Firefox for Gmail. Or even better, use Thunderbird.
Except using Tor browser, which doesn't block ads.