Google no longer providing original URL in AMP for image search results
twitter.com
twitter.com
Of all the anti-competitive actions google has taken around search results, AMP is by far the worst. I hope they get smacked down for it in the upcoming anti-trust lawsuit. And kudos to Apple for refusing to change the URL bar like Google does on Android.
For average non techie users, the URL bar isn't particularly helpful. They use page content. And AMP pages do show the original page domain name.
Also techie and non-techie people have been using the same browsers for how many decades now? Aren't the majority of people in many countries on the internet? It seems like the average non-techie users succeeded in figuring things out so far.
It would have been nice if client side TLS certificates were more popular. Then your browser could warn you that you're not using your client cert when connecting to a certain website and not allow you to complete the connection. That would be a better solution as opposed to relying on users to manually check the URL.
Edit:
What I posted above is not correct. What I should have said was that the server would validate the client certificate by checking a certificate authority (either managed by the server itself or a 3rd party).
That is not how TLS works. A server can trust a client based on the certificate the client presents. A client can't distrust a server based on the certificate the client presents.
"The phishing site would lack the private key needed to validate your client-side certificate" is nonsense. Neither the real site nor the phishing site have the private key used to generate the CSR; only the client that sent the CSR has that, and validating a cert does not involve the private key in any way. If you're thinking of a new protocol where the server itself generates an arbitrary asymmetric keypair and shares it with the client, then a) that's not TLS, b) that could just as well be done with a symmetric key (since this is just pre-shared key auth) where the server presents a nonce to the client to sign and verifies the client signed it, and c) a fake server can just not do that.
You're correct; I posted inaccurate information.
> validating a cert does not involve the private key in any way.
What I should have said was that the server would validate the client cert by checking whether the certificate is valid according to the authority that signed it (which could be the server serving as a CA itself or a third party CA).
As for the original question, I guess it's possible for a phishing website to not bother validating the client certificate presented at all and allow the TLS negotiation to succeed.
If there was something that could instruct a browser to only send a given client certificate if it only receives a certain server certificate, then it would be much harder for a phishing website to work, because the browser would not send the client certificate to the wrong server.
> I guess it's possible for a phishing website to not bother validating the client certificate presented at all
Why would a phishing site do anything to discourage a connection from a potential victim? Of course a phishing site would accept an invalid or missing certificate! Even if the site was impersonating something like amazon.com, Amazon hasn't issued client certificates to all of its users so the whole point is moot.
It's possible that I am misunderstanding it, but it appears that the point of contention is what the server will do when it receives a certificate from the client.
Ideally, it would check if it's valid by checking it against a CA. So, if someone who manages the server signed the CSR, then the server can validate the certificate with a CA that it manages. If it uses a 3rd party CA, then it would validate it using that.
What I'm not sure about is whether a browser can map a particular client side certificate to present to a server based on the server side certificate presented to the client. If it could, then it would be easy to determine whether one has connected to the correct server since the browser wouldnt' try to present the client side TLS cert to the wrong server.
> Even if the site was impersonating something like amazon.com, Amazon hasn't issued client certificates to all of its users so the whole point is moot.
Which was the point of my original post. If we had worked in making the process of generating and using client side certificates more user friendly, then companies would have done so as part of the account creation process (meaning poeople would use their client cert in addition to their username and password as part of the authentication process).
What we have now is major companies like Amazon using SMS based 2FA that would easily be compromised by re-routing the verification code message to another device since that factor is not under my control, but at the mercy of the phone company.
That way, if I go to a phishing website that pretended to be Hacker News, my client certificate would not be sent and my browser could warn me by saying that the connection is not using a client certificate. Right now, if we only rely on server side certificates, there's nothing stopping a phishing website from using Let's Encrypt to show the secure connection icon in the URL bar and tricking me into thinking it's a legitimate server.
Even if the user uses the client cert with a phishing site, the phishing site doesn't have the ability to impersonate the user against the real site because the private key is still on the client's device.
In addition, if a browser is configured to automatically use a client cert for all requests to a particular domain, then even that leak doesn't happen because the browser would automatically not use the cert with the phishing domain.
Google scraped and stole all the traffic for covid19 since 3 months just like it did for other topics
They're not faking the URL; a signed exchange contains data that can only have come from the original site. It's a secure way of handling caching/CDNs/etc, and it'll be a net improvement for security that allows sites to put less trust in third-party servers and scripts.
Its a similar vein to how many of the objections to AMP were being white-washed with "its open source, if you have a problem with it why aren't you submitting a pull request??"
This is literally already happening with the info sidebar, the reason signed exchanges matter is so they can throw up the smokescreen about how its cryptographically verified to come from the original page, so why are people upset.
Any site that objects and refuses to implement this stuff will just disappear from the first page which is reserved only for Accelerated By Google sites. (Which is already happening for AMP links on mobile searches).
I've clearly missed something. Can you help me?
Perhaps I need to read them more closely.
The calculation appears to be that given the chance, some website controllers will choose to trade confidentiality of public pages for better load times. In business terms, this seems a pretty straightfoward win in many cases, so I can see why some would sign up.
A publisher is free to switch to AMP, but choice needs to be given to the user to agree or leave the site the same way it happens with cookies. I wouldn’t opt in and now I cannot block Google tracking at the DNS level thanks to this.
We are, unfortunately, a long way from this being normal. Even as third parties doing things like running CDNs or doing TLS termination for other reasons has been pretty thoroughly normalized. Though offering it as a Firefox extension could be an interesting exercise.
I think publishers view AMP as a question of their sovereignty and choice. Since it's their website that's being potentially served by Google, it's their choice to make. There's absolutely a lot of room to dispute if this is the morally correct stance, but I also think it's not wildly out of line with other questions publishers weigh in choosing what they serve and how.
How do signed exchanges break blocking Google tracking at the DNS level? You already need to have google.com unblocked in order to get a results page that serves an exchange from Google.
> cryptographically verified to come from the original page
Elaborate.
There will be no obvious distinction between a search result and google's own website, even though the "portals" will be showing cryptographically signed content (which will almost certainly be in a super restricted AMP-esque format that denies sites much control besides what the text says)
If google swaps one result for another, 95% of users wont even notice.
Right so exactly the same way the search results page works today?
> The page results will be a tightly restricted iframe-esque window inside of google results
This is completely independent of AMP. Portals work for non-AMP content too.
> which will almost certainly be in a super restricted AMP-esque format that denies sites much control besides what the text says
So you're suggesting that Google will create a new, even more restricted than AMP protocol to be viewed on the search page?
Will Google allow for example, Taiwan content in mainland China?
Is it like VPN/Proxy or has more knobs?
Google doesn't run in mainland china, so this is a bit of a strange question. But let's assume that Google did. How would AMP or signed exchanges change the accessibility of Taiwan related content on Google in mainland china? Are you saying that the current Google results page would show Taiwan related content, but signed exchanges wouldn't, or what?
> Is it like VPN/Proxy or has more knobs?
Neither. It's literally a way to say "a site had this html, css, and js, and cryptographically signed the blob so that we can re-host it and you can be certain that the person re-hosting hasn't modified it in any way."
My question is will signed exchanges serve content but where google search results are censored.
That said, Google already has control of every AMP page because the spec REQUIRES you to load a piece of Google controlled/hosted JS onto your page. That JS can change at any time without "signed exchanges" being aware.
Ok why is this an issue? Note that HN is a bad place for this kind of socratic method discussion, we'll both quickly run out of the ability to post replies. Assume I'm someone who doesn't share whatever values you share about the purity of the url bar or whatever. Why is you being unable to know whether or not the content came from Google's IP or mysite's IP relevant to anyone as long as it's the same content (which signed exchanges ensure)?
How is this different than today, where many sites use js from google, either as a cdn or part of the ads infrastructure? I guess you can block some of those, but blocking the jquery provided by google's CDN isn't going to work too well.
(And further, what kind of nefarious thing do you fear Google will do? How likely is it that they will do so, in your opinion?)
Well, the headline is one good example. That google controlled JS is EXACTLY how they removed access to the original URL...on somebody else's page that isn't theirs. "Signed exchanges" doesn't fix that either. It's also how they hijack the back button and swipe events for carousel navigated pages.
No, the Google AMP cache adds the header bar. That isn't added by the Google controlled AMP js. Let me repeat this: The AMP js didn't change. Google's AMP cache implementation changed. (if you disagree with this, please post the diff of the AMP js that removed the url bar, the js is opensource at [0])
> "Signed exchanges" doesn't fix that either.
Yes it does, in two ways:
1. It would prevent Google from mucking with the embedded page at all, like they do now.
2. It would remove the need for me to have the url redirect, since the url bar would point to the original site.
It's different because it's a requirement. nytimes.com is moving to phase out all third-party advertising data, so presumably they could design their page such that it only accesses their resources.
With a signed exchange, that would allow them to nicely compartmentalize and contain privacy to their site, if they aren't required to load and run some Google supplied JavaScript. The argument that Google already knows that someone visited the page so it's no big deal is not compelling, since there is a big different in knowing someone clicked to visit a page, and having carte blanche over loading your own code on the page in question.
Can you include the AMP rquiers JS inline such that it implement an AMP spec version, or do you need to load it externally? If you can supply it inline, that's great, and what people would want (as long as it doesn't load additional third party resources). If you can't then you're providing Google with an extra level of control that's not really needed, and that's what people are against.
> (And further, what kind of nefarious thing do you fear Google will do? How likely is it that they will do so, in your opinion?)
If we go forth only considering what we think people will do, and not limiting what they can do, we're destined to be upset with the outcome. If not from Google itself, then in twenty years when someone buys Google, or Google sells off a division that houses information, or there's a breach and it's exposed, or some other company rides on Google's coattails and uses the same precedence to get data but is less trustworthy.
The point is that some people don't want to share this information, and would choose not to do so if there was an easy way to tell when it was being gathered. Fighting against new methods that seek to make it implicit instead of explicit is the only real way to do that.
1: https://www.axios.com/new-york-times-advertising-792b3cd6-4b...
Then I'd direct you to Gregable's comment (who is a person who actually works on AMP) that
> the AMP project is actively working to move the origin (control/host) of the AMP Javascript to the publisher's own domain, as well as allow a version served on an origin owned by the OpenJS Foundation, rather than Google.
So while this isn't supported yet, the people working on it do ant that.
> If we go forth only considering what we think people will do, and not limiting what they can do, we're destined to be upset with the outcome. If not from Google itself, then in twenty years when someone buys Google, or Google sells off a division that houses information, or there's a breach and it's exposed, or some other company rides on Google's coattails and uses the same precedence to get data but is less trustworthy.
I'm unconvinced by such slippery slope arguments, given that the pushback were Google to do something like inject nefarious js would be swift. They've had the ability to do so for, well, 20 years now. They haven't yet.
as we don’t have proof that google did not do nefarious things, we don’t have proof that they haven’t. with such monopoly and power distrust is useful thing.
We do have proof that they don't do the specific nefarious things being discussed here: injecting nefarious js into otherwise useful things. That's easy to determine.
It's about power dynamics. If you get a consolidation of power, that's going to be open to abuse. Maybe not now, maybe in the future, who knows. Democratic systems have checks and balances in the public domain. Google doesn't have this.
Good! For what it's worth, I'm slightly pro AMP based on the idea, I'm just not entirely happy with the current implementation. Fixing it to be less dependent on a Google resource is a good change, IMO.
I use copious Google services, such as Gmail and Drive, and Hangouts (or whatever it's called this week), and Android, but I'm leery of becoming more dependent on Google. It's to everyone's benefit if there's healthy competition between all parties, and to my personal benefit if I don't find that someone's gotten access to my google account and literally everything is open to them (which is why I always use a username/password combination for sites I create accounts for instead of linking my Google account... even if I know my email is @gmail.com so it's of limited use, for now. Baby steps).
> I'm unconvinced by such slippery slope arguments, given that the pushback were Google to do something like inject nefarious js would be swift. They've had the ability to do so for, well, 20 years now. They haven't yet.
First, it doesn't have to be nefarious. The bar for Google deciding they deserve analytics for content they "serve" is much lower than the bar for actually doing something illegal. I prefer not to place options to do what I consider the wrong thing for business gain in front of companies when it can be helped. Hope for the best, plan for the worst, and all that.
Second, that was a single one of the scenarios I listed. The others notably did nt rely on Google doing or not doing the right thing, because the decision is no longer in their hands. If Google is no longer the authority deciding (because they are gone, or have a new parent, or the data was taken), what Google would choose to do is irrelevant. That's why it's important to some people to reduce the information being collected. It's impossible to know what it will eventually be used for in the long term, so the prudent thing is to limit it, and/or compartmentalize it (that is, maybe I'm happy with nytimes.com knowing where else I clicked in their article, but I would prefer Google only know I loaded that first article).
PS: You work for Google. Do you work on this project?
You'll only ever retrieve Google AMP cache results from the Google search page, where they were already able to track if you made such a request, since the link you clicked has trackers in it.
So from that perspective, nothing changes.
> PS: You work for Google. Do you work on this project?
No, I work on mostly internal infrastructure. My interest in AMP is simply that I don't dislike the AMP "experience", it's fine. But more importantly, I legitimately don't get the HN hysteria around AMP. Returning to your concern, literally nothing changes with AMP vs non-AMP.
I don't get it. The most compelling concern I've heard is that it's annoying to have to couple parts of your infra to AMP-standard stuff. And I sort of understand that. But even that isn't different than previous SEO/ranking changes that required changes to the page.
I am not affected, I don’t use Google search. The problem is for individuals who use Google search and now don’t have an option to avoid in deep tracking. The difference between regular pixel trackers and multiple data points associated with every resource a site serves is immense. I work in ad-tech, not particularly in the identification side, but I started multiple projects in that end. From experience, a regular tracker can be fooled, but you cannot fool every resource request. One of the things I did to identify ad fraud bots was actually drive them to a site in which I controlled every resource. The resource request fingerprint for bots was easily distinguishable from real people. Moreover, some humans exhibited navigation patterns that were distinguishable from other humans. I remember I caught a QA person doing a shoddy job of testing the front end once due to it. That is the kind of power that Google is acquiring as more and more sites choose to use AMPs. It is scary to think that a single identity has that power.
I'm confused.
What they're pushing with Amp and the related technologies grants them a near-unavoidable man-in-the-middle position.
(FWIW I am careful to avoid Google properties at a pretty high cost.)
Not anymore than I already do bat an eye at cloudflare.
(It's probably worth noting here specifically that I do work at Google, so my risk profile is probably different than yours, for me personally and speaking solely from a trust perspective, I'd probably prefer it if Google acquired CloudFlare since I would get a net increase in transparency, but I can understand why that isn't a general position, and there are other reasons I don't think Google acquiring cloudflare would be good).
I share these fears to a lesser degree with Microsoft and of course Facebook. Apple seems to do a great job of safeguarding, but they could become sour if they don't remain careful. Stuff like Clearview crosses the line into directly-dangerous. CloudFlare is currently innocent in my eyes, but they've managed to centralize a lot more channels than I'd like to think about.
Uh, I keep seeing Google AMP URLs shared on social media, emails, etc etc. Which is quite annoying :(
If you click the browser share icon, or trigger the browser native share intent, the origin URL will be shared, not the AMP Cache URL. Only if you explicitly copy the URL bar will the AMP Cache URL be shared.
The Signed Exchange spec that AMP has offered sites for a year now allows them to have their own URLs displayed in browsers that support it. In that case, the google.com URL will never be displayed and thus can't be accidentally shared.
All AMP documents on the AMP Cache contain `<link rel=canonical href={origin url}>` and Google recommends that social media prefers the canonical URL. This is useful outside of AMP as there are often multiple URL variants for any article. The sharer and sharee may not ideally get the same version. As an example, a mobile vs. desktop article.
An AMP page can be identified by examining only the first few bytes of the HTML. The `<html>` tag will contain either the `amp` or lighting-bolt emoji attribute, ie: `<html amp>`.
Technically an AMP document must pass AMP Validation to be truly AMP, so there are documents that match the above condition which aren't valid AMP. There are multiple ways to validate. A starting place is https://validator.amp.dev/
Also, "the google.com URL will never be displayed" is a world with an internet I don't want to be a part of.
Also, others might share an amp link from their mobile devices, which I then end up clicking in a desktop slack/mail/messages app, and there we go again with the amp virus even on desktops.
I see quite a few AMP cache results being shared on twitter (for example).
>where they were already able to track if you made such a request..
It's still possible to get raw Google results (with the right extensions/browsers), though I wonder for how long.
From then on, every asset it loaded via Google servers. Google now controls the entire internet. Google does this so it can serve its ads and track all users. It's as if I would only use Google for my internet surfing.
I don't use Google because I strongly believe it is an evil company, but if websites use AMP, then I am forced to hand over my data to Google even though I don't want to. Right now, I can block Google servers entirely. But if the entire web is served via AMP, I can't do it. And that's the whole reason AMP exists. So everything I do (or at least as much as possible) goes through Google servers.
You really do not see our concern? Really?
I’m curious, what do you value about the services you consume? I like transactions where I know what I am giving to the service provider. Do you really want to push away from this reality for the benefit of a few MS load time leaving a search page? That’s essentially what you’re arguing for.
I don't think you may realize how much of your online activity is already tracked by google / facebook / instagram.
Google's javascript is everywhere, including explicit tracking with analytics, and lots of CDN loads for endless lists of things (js libraries, fonts etc).
Their properties also track you, google search, youtube, email. They also make software you might use (chome / android / google maps / google play store).
If you think something about signed exchanges let's google track you, and they can't now... please examine these assumptions.
Folks who come up with these super complex schemes (google will use javascript loaded into AMP to take over and track you) ignore that google ALREADY tracks them.
And folks who say they don't use any google products (no android / google maps/ play services / chrome etc etc) are often either lying or don't understand how many third parties load google analytics into websites, or load recaptcha bot protection etc.
I wrote a reply to joshuamorton were I expressed my concerns.
If google said, we want to track people, and brings android, chrome, dns resolvers, network infrastructure, google cloud compute, AI systems, google analytics which these media sites voluntarily, google play services etc to target and track you - they probably could.
EVERY single person (including you) who claim they don't use google, if you dig down, they often are lying and do. And if you don't, some of the people you email or interact with do, so indirect profiles can be built.
AMP solved a need for a lot of users, which is the janky, slow ad filled websites that media sites in particular had become. So there is an actual end user reason people like AMP - it's a better user experience in many cases. This is where AMP is ruining the web gets hard to support. For most folks they don't perceive they are giving up a lot more in terms of privacy, and they are getting a lot.
Their data governance team wouldn’t allow it. You are basically describing a system they could only introduce with the permission of the government. I don’t care if the government is tracking me honestly, I can’t fight that. I just don’t want Google tracking me for the purpose of influencing my spending habits, emotional state, or perception of the world. That is my main beef with their advertising capabilities.
At the same time, the AMP project is actively working to move the origin (control/host) of the AMP Javascript to the publisher's own domain, as well as allow a version served on an origin owned by the OpenJS Foundation, rather than Google.
On publisher origin, the plan-of-record does not involve any validation of the contents of the AMP javascript files. When an AMP Cache (eg: Google) crawls one of these AMP documents, the same is true - the contents of the javascript files will not be relevant to the decision of whether or not the document is considered valid AMP. The files will likely not even be crawled by the Cache.
However, when the AMP Cache serves one of these files, it will rewrite them to the latest* version for serving to users. This is necessary since the javascript runs in a somewhat privileged context in search results.
https://github.com/ampproject/amphtml/issues/25873
* There is also a mechanism for publishers to opt-in documents to a "Long-Term Stable" release, rather than the latest evergreen version: https://amp.dev/documentation/guides-and-tutorials/learn/spe...
Lastly, and there is still some discussion around this, it is likely that Signed Exchanges may be able to load the publisher's own version of the javascript in the future, even in search results. This is because the execution context of the javascript is different for Signed Exchanges.
Third parties like Google, right?
Signed Exchanges mean the publisher signs the content using their private key. A third party can provide delivery like a CDN, but they cannot modify the content, or the signature would no longer match. The useragent (browser) enforces this. This gives the secure control of the content back to the publisher, unlike the trust model of CDNs or the AMP Cache.
This assumes the user agent is actually an agent of the user, and not the AMP provider, which is demonstrably [1] not the case.
[1] https://github.com/w3ctag/design-reviews/issues/467#issuecom...
If a signed exchange includes a URL, that URL must be signed for the browser to respect the field.
[1] Which is unverifiable, we just have to take your word for it.
To make sure I understand, does this mean that in principle a third party other than Google can deliver the AMP pages? Is google working to facilitate that AMP hosting is open to everyone and calibrating their searches point to any and all alternative AMP hosters?
Also how would you reconcile your comment with that of madeofpalk who appears to be treating that possibility as a hypothetical idea that hasn't happened, and which would be unpraticable due to needing to trust third parties?
All AMP pages exist at non-Google URLs. They are just cached by the link aggregator (typically a search engine), so the link aggregator can prerender them without deanonymizing the user to the publisher until the user clicks the link.
AMP served by CNN: https://amp.cnn.com/cnn/2020/05/27/world/france-shooting-sai...
The same page served out of Bing's AMP cache: https://www.bing.com/amp/s/amp.cnn.com/cnn/2020/05/27/world/...
> Do you have a ballpark estimate of what percentage of total amps are delivered by non Google domains?
All of them (100%) are delivered by non-Google domains to Google, Bing, and other caches.
> Also how would you reconcile your comment with that of madeofpalk who appears to be treating that possibility as a hypothetical idea that hasn't happened, and which would be unpraticable due to needing to trust third parties?
madeofpalk's comment makes perfect sense if you understood what I wrote above. Why should CNN or Bing be told that you have searched for a particular news article on Google before you have clicked it? The page has to be served from the link aggregator the user is browsing to maintain the user's privacy when prerendering results.
I don't intend to ask whether AMPs (hard to resist calling them 'AMP pages') exist somewhere on non Google servers. Obviously third party content that Google is presenting exists somewhere off Google. And obviously it has to be formatted in a way that's compatible with AMP, and it makes sense that that is going to be done off Google domains. I at least knew the gist of that already, and I regard the detour into that explanation to have been a non sequitur. The point is that Google presents AMPs and it serves it's cached version of them from Google servers, on a Google domain. The beginning, middle, and end of the experience of searching for finding and consuming that news never has to involve leaving a Google domain. It's not open in the sense of involving interaction between servers that aren't controlled by Google, until you make that extra click to go from a cached Google version of an AMP to the version that sits on the domain controlled by a third party, at which point going to the third party has been rendered optional and largely unnecessary from the point of view of the user.
This next part is super important: the fact that I'm asking about openness and interoperability, or the lack thereof, in this sense doesn't mean that I'm failing understand the technical advantages with caching and optimization. I regard those as derails that don't wrestle with the issue of openness that's being raised. The point is that the connection between consumers of content who start on Google, and the third party content provider, increasingly depends on Google in a way that shifts nearly the entire experience of consuming content onto Google's infrastructure.
>All of them (100%) are delivered by non-Google domains to Google, Bing, and other caches.
This is the starkest example of a question not being answered but replaced with a different question. I asked 'what percentage of total amps are delivered by non Google domains' and you replied by answering a different question, what percent of non-Google amps were delivered TO Google and other caches, noting that it was 100%. Which of course it is, but that's because that's a tautology.
By contrast, it is helpful to note that there are caches other than Google, like Bing and 'others', which, in contrast to much of the rest of your comment, I feel actually is a pertinent and fair response to the question I'm actually asking. But those aren't content providers, so unless Bing or Google are content creators that were delivering content to themselves, it's tautologically true that 100% of that is going to be delivered to them by third parties, which has absolutely nothing to do with openness. If I'm using magic words correctly, I guess what I want to ask is what percentage of AMP traffic to cached pages is served to users by Bing and others that aren't Google.
> If I'm using magic words correctly, I guess what I want to ask is what percentage of AMP traffic to cached pages is served to users by Bing and others that aren't Google.
If I search on Bing, the results will be prerendered from Bing's AMP cache. Reread the GP comment, and see if you can understand why that is so.
> Can a third-party other than Google deliver an AMP page?
Yes. Examples: Bing runs their own AMP cache and also delivers AMP pages. LinkedIn and Twitter also link to AMP pages, but they don't currently run a cache. IIRC, Twitter links to the Google AMP cache and LinkedIn links directly to the AMP variant on the publisher origin. They could run an AMP Cache. Cloudflare ran one for some time, but shut theirs down recently.
The AMP Project maintains a list of known AMP Caches here: https://github.com/ampproject/amphtml/blob/master/build-syst...
And provides some guidelines for running one here: https://github.com/ampproject/amphtml/blob/master/spec/amp-c...
It's non-trivial, but absolutely supported.
> Can a third-party other than Google deliver a Signed-Exchange?
Yes. Cloudflare generates them for their customers who opt-in via their "AMP Real URL" product. "Generates" in this context implies delivering them. To date, I'm unaware of any large scale implementation that is delivering Signed Exchanges for third-party origins other than the Google Cache though this may change. The tech stack absolutely supports this.
Fifteen years ago, if you asked me how google search would look, I would have responded “mostly the same, maybe they’ll have cool features like asking me which meaning of ‘converse’ i wanted: the shoe brand or the logical relation.”
Instead, they’ve only subtracted functionality from the query engine (no more domain blocking), discouraged you from clicking through to sites by automatically scraping and rehosting them as “semantic” results, and now they’re trying to actively acquire 100% of the outbound traffic. Fuck google.
It blows my mind that anyone thinks that’s an acceptable idea.
What’s shown in the URL bar has long been divorced from the HTTP request(s) that are made.
> It blows my mind that anyone thinks that’s an acceptable idea
It blows your mind that different people have difference opinions and values than you?
Also, a provider uses a CDN at their discretion. Giving them the ability to invalidate or update cached records at times of their choosing. Or remove the CDN entirely if they choose to.
This is Google using their weight to be anti-competitive and fall further down the anti-trust rabbit hole.
I know it seems impossible but nobody has to use Google.
Are there any copyright implications of amp? They're essentially republishing your property.
Does the original publisher get their ad revenue?
Given context and full knowledge of the issues involved? Yes, absolutely. For this particular issue anyway.
> Or maybe it’ll come from a CDN rather than origin.
That’s not a problem, since the URL and where it points to is still decided by the content owners.
>Or is it that you don't want snippets to appear in the search results and just want a list of links without any evidence for why they might be good matches for your query?
Is that how you feel about regular search results?
> Is that how you feel about regular search results?
Regular search results have snippets.
>Regular search results have snippets.
Right, and I was asking about the search results, not the snippets that accompany them. That is to say, the part with the blue title, green link, and the few lines in black displayed from the page that are displayed ten at a time, not the snippets that accompany them at the top of the page. Unless you were just using 'snippets' as a general term to mean the same thing that I mean by search results, in which case you were just repeating the content of my own question back to me.
They still know when their content is being consumed. They just don't know when their content is being searched for until the user clicks their link, exactly like a snippet. Does that make sense now? My point was that search engines already show cached portions of the page. Read the parent comment of my first "snippet" comment to understand why I was making that point.
If I click one of the links, then yes, I absolutely expect the publisher to know I did.
[0]: https://addons.mozilla.org/en-US/firefox/addon/amp2html/
https://chrome.google.com/webstore/detail/redirect-amp-to-ht...
Note to others: this is about the upcoming rewrite, available as Firefox Preview and Firefox Beta.
I got:
Don't f* with paste, Disable WebRTC, Dark Mode, a couple of image savers, NoScript, AdBlock Plus, Privacy Badger.
I recommend https://filterlists.com/ if you use any blockers, it's an easy way to subscribe to lists.
There's a big rewrite being done and the current stable Firefox for Android which supports basically all addons that the desktop version does, will be deprecated soon-ish. Preview has a broader support.
Beta and Nightly only support uBlock Origin, literally.
Preview supports six addons in all, but Preview isn't a promise of whats to come as they consider it a pilot.
Exactly. Search your hearts and use the net with your values as though they’ve become a force to be feared by the swill that is invading our liberties (google).
The annoying thing is, average user will not notice and/or care.
[1] https://webmasters.googleblog.com/2019/04/instant-loading-am...
That's a bit of an exaggeration. Mozilla's position statement on web packaging[1] says:
> As a whole, and for origin substitution in particular, until more information is available on the effect on the web ecosystem, Mozilla concludes that it would not be good for the web to deploy web packaging.
Personally I'd like to see web packaging adopted without the origin substitution capability (at least to start with), as it would still allow sites to offer web apps comprised of a fixed bundle of code (signed with an offline key), rather than potentially different code each time you visited. That would reduce some of the concerns around serving "secure" apps on the web, as long as browsers had a way of preventing the server from silently updating the web package (perhaps using short-lived unique subdomains/certs).
[1] https://docs.google.com/document/d/1ha00dSGKmjoEh2mRiG8FIA5s...
People have been saying this for years, and it never happens.
Until Google is fined to a degree that it impacts its share price, nothing will change.
So IMHO "nothing will change" does not seem right.
Which is to say, I don't disagree with the momentum toward anti-trust measures being brought against Google, but I want them systematically brought against the entire Big Five, or else the effects may just be further consolidation.
This reminds me of the EU Internet Explorer lawsuit, which was peanuts compared to what Google is doing right now. Between Google Search, Chrome, Android, Youtube, Gmail, Google Maps, Google Docs, AMP and likely 5 more things I forgot, they've stealth-grabbed so much of the internet, it's not even funny. At least force them to split off their ad/datahoarding businesses.
A while back on one of the AMP discussions here, someone from Google weighed in. They said the data was clear: users not only accept it, they love AMP.
I asked how they knew that, because if it was, say, just tracking how many people tried the 2-3 tap process to get to the original URL compared to how many people just engaged whatever you showed them, then the data might be showing you something else (and in fact, I wasn't clear how you'd get from accept to love in any other way than a focus group or survey).
No response. Not clear if that's because revealing data would run afoul of internal confidential disclosure, or because this basically hadn't been thought through.
> Apple for refusing to change the URL bar like Google does on Android.
Apple has its own problems with the URL bar -- they keep the domain but drop the rest of the URL. Not as bad as replacing the domain, but not great.
If anyone's word should NOT be taken as gospel for UI or branding, it's Google's.
Thank goodness menus for Office still existed on the Mac.
You can view the full URL in safari for iOS by tapping the URL bar. In Safari for Mac, you can modify your preferences to always show the full URL. Definitely not ideal, but also not anticompetitive in the same vein as AMP
As a user, I will absolutely say I love AMP. AMP pages load incredibly fast with much less bullshit.
The real problem is that AMP isn't necessary. Google created AMP and is encouraging (nearly forcing it) it in a very hamfisted way because web developers couldn't figure out how to make responsive, fast-loading web pages without a huge company like Google spelling it out for them with a framework.
Now, obviously to power users like the typical HN user, AMP is evil because it's just Google taking over more of the web.
But understand that to your typical mobile user, AMP is a godsend because of how fast it is. They don't care that the URL shows Google instead of whatever page they think they're on.
With AMP, the little badge (the verification), serves as a constraint for developers, but mostly for business stakeholders. The conversation of "I can't do that, because it's simply not compatible with AMP" is way easier than "I can't do that, because it will make the page slow".
So I guess worse is better we are supposed to accept it or else they'll police us into accepting it.
To be clear, they use amp to serve pages in the protected area, but the protected content is served in the body of the page, inside an AMP-APP tag, but simply hidden.
The code is few lines long, it could have been one line, but it has to unwrap the shadow dom.
I made it for myself, but then friends started asking for it so I published it on Firefox's extension store and later on on the Chrome's one.
It's been there for a couple of years, nobody complained, I even emailed the newspaper several times to warn them about the "bug" but they never replied back.
It has never been very popular, especially outside Italy, it had around a thousand of installations and about 900 daily users, but on March this year I received a copyright infringement notice from Google, even though Google has no rights on the newspaper's content.
They removed the extension right away and banned me from re-uploading it.
I tried to reach their support many times, never heard back from them.
A few days later Firefox removed the extension as well saying Google contacted them about the copyright infringement.
As of today after at least a dozen emails I haven't been able to speak to a human being.
I don't mind much, I still use it on my systems and it still works even on Firefox mobile (for now)
I tried to upload it under a different name, but apparently I'm forbidden from publishing it again.
Weird detail: the day after Firefox removed it I've been contacted on the email I used to register on Firefox dev website asking me if I wanted to sell the extension.
The newspaper website is https://www.repubblica.it
It makes everything harder and confuses deeplinking, sharing, identifying sites and general navigation between pages.
Sure, amp sites from the feed appear to "work" instantly but they fetch all the content in the background so that's not fair (on chrome at least).
I am no fan of AMP, but this criticism is not particularly valid.
I wonder if the outcome of the lawsuit will be a grab bag of concessions, such as abandoning AMP, and, say, adding the ability to fully delete Google Apps from Android rather than doing a mere factory reset, making opt-out of interest based ads easier, and things of that nature.
They don't.
> Just heard from the Image Search team that this is an oversight and they'll add the feature! Sorry about that and thanks for the report!
Isn't Malte Ubl one of the developer/architect behind it? I could be wrong about this but I remember reading his notes/thoughts on AMP last year.
I really hope this AMP thing never becomes anything mainstream, it's an atrocious attempt at monopolizing the internet as a whole.
I feel like when a company grows to a certain size, we have to drop the “assume good faith” outlook we give to small businesses and individuals and take on “assume bad faith” instead.
So: the committee only wants what the papers say. In this case: benefits.
> Some of the owner men were kind because they hated what they had to do, and some of them were angry because they hated to be cruel, and some of them were cold because they had long ago found that one could not be an owner unless one were cold. And all of them were caught in something larger than themselves. Some of them hated the mathematics that drove them, and some were afraid, and some worshiped the mathematics because it provided a refuge from thought and from feeling. If a bank or a finance company owned the land, the owner man said, The Bank- or the Company- needs- wants- insists- must have- as though the Bank or the Company were a monster, with thought and feeling, which had ensnared them. These last would take no responsibility for the banks or the companies because they were men and slaves, while the banks were machines and masters all at the same time. Some of the owner men were a little proud to be slaves to such cold and powerful masters. The owner men sat in the cars and explained. You know the land is poor. You've scrabbled at it long enough, God knows.
http://www.polkagris.nu/wiki/Steinbeck,_John:_Grapes_of_Wrat...
To me, this rationale looks an awful lot like a moat to stifle Google's competition. If collecting "the urls you're browsing" is wrong, why is it ok for Google to do it? And if it's not wrong, why is it somehow better that only Google gets to do it?
Depending on what you're doing, one-time collection may be enough.
Also, many captive portals are provided to businesses by companies whose own business interest is in tracking people, and they'll absolutely correlate the data.
Rather than having to worry about whether the service you're getting internet access from will track you, make it impossible for them to do so.
I think you've still failed to answer my basic point - how is this not just a competitive moat that benefits Google? If we care about privacy and data collection, legislation is required because Google and Facebook have no reservations about sucking up everything they can. If it's ok for them to do it, why not $RANDOM_CANADIAN_ISP?
If you use HTTPS, you know you're talking to the site you think you're talking to. If that site itself is sharing data in a way you don't want, including by pulling in third-party scripts, you have a problem with the site. That's not an argument against HTTPS; communicating in cleartext doesn't solve that problem, it just means that other people the site doesn't trust can also access that data.
Let's not let the perfect be the enemy of the good here. Universal HTTPS is an improvement.
Pornhub should offer https if it doesn't already. A good example of a site where this would be a feature. Local recipe blog.. maybe
Btw.. Pornhub has it's own google version of ad tracking they sell/share espically when you login.
If you are not then sure browsing in an internet cafe or an unsafe network will allow rogue entities to see your interest in parts.
Your browser is fingerprinting you on chrome with an id. You are being fingerprinted with your unique fonts on other browsers. If you have javascript on that opens the floodgates. Logged into facebook still? Browser extension gone rogue? Andriod OS?
Granted, you then have to trust cloudflare; but it seems like they have been good actors so far considering their privileged position delivering tons of content across the web.
You do get the benefit of https even on static sites though. Do you want every network you join to be able to inject any JS they want into pages you're viewing? Https solves that.
[1] Via things like taking over swipe motions and the back button on carousel launched pages, for example.
They will also be able to release "unblockable" advertising to amp pages eventually.
The long term solution is stigmatizing ads—you can never ad block someone in the ear of a newspaper editor.
How can I see this very specific example ? I would like to understand exactly what this looks like ...
I am not a reddit user and I don't consume much web content on a phone, which is using Safari on an iPhone ...
Would I need to download google chrome onto my iphone, then do a google search for a reddit thread, then click on that search result ? Or would I see this result in Safari as well ?
Genuinely curious as I would like to recreate this specific result ...
The madenning part is you will see these links when using Firefox or Safari and you'll see them on a desktop. It is of course, not just Reddit thing. I've seen LinkedIn shares look like this.
https://www.google.com/amp/s/amp.reddit.com/r/gadgets/commen...
This page is simultaneously encased by AMP, has multiple ways reddit is trying to get me to install an app that isn't going to help me right now as I am hopping between websites--I am going to glance at reddit for ten seconds and then a stackoverflow question and then a bugzilla issue and then a quora thread... the last thing I want right now is to end up in some app--but it also doesn't show me all the comments and is asking me to click through to get them... it used to be I clicked a search result and it showed me the reddit thread, with all the comments and without an app: I liked that :(.
http://old.reddit.com still works, though
Hope they are sane enough to keep it forever
So none of the "nice" Reddit mobile site features actually work, and supposed "one-time" annoyances like the "Download the App" pop-up don't get cookied under AMP and continue to annoy on every google search. Insane!
best and most succinct description that I've heard.
Because Google only discontinues useful services, and AMP is actively harmful (aka of negative usefulness)?
> Just heard from the Image Search team that this is an oversight and they'll add the feature! Sorry about that and thanks for the report!
[0]: https://twitter.com/cramforce/status/1265688067706245120
Me: When can we expect to see a fix? As of right now, there’s no easy way to visit the original URL.
Malte Ubl: I don't have a timeline. The share menu should help getting the underlying URL!
Me: I’m sure I don’t need to explain how this looks; regardless of your intentions, it comes across as a fairly hollow response. The issue gets a lot of negative attention on HN, someone from Google responds that it was just an accident and will be fixed, but there’s no fix.
Malte Ubl: Sorry, no way to do it in fewer than a couple days.
Me: That sounds like a timeline to me. :)
That said, it seems likely to me that if this somehow stopped advertising revenue, it would have been fixed before HN even noticed. "No way to fix it for at least a few days" seems very untrue, that department just isn't lead by someone who cares enough about this issue to make it happen. It's not the tweeter's fault, though.
I’m well aware. But this is a pretty serious problem, and we, as Google’s users, have very few options for effecting change. If I’m given an opportunity to make a point, I’m going to seize it.
He thinks it can be done in a couple days. Does the rest of the company care enough to make that happen? Let’s find out.
Next up, I need to change my default search engine to DDG.
What’s a good privacy-oriented, web-based email service? I’ve heard of ProtonMail but haven’t used it.
At work we use Runbox (Norwegian if I'm not mistaken), works well and iirc the pricing is affordable also for individuals.
A new ISP in the Netherlands, set up in response to XS4ALL being killed by the parent company, offers email hosting with a custom domain for 50 euros a year (domain included I think). I personally have high expectations there. For more context on what XS4ALL did and stood for aside from privacy, see https://hn.algolia.com/?q=XS4ALL
Self hosting is also pretty easy if you don't mind getting your hands dirty for an evening or two to set it up. (For me it has been hands-off most of the time, aside from upgrading to new hardware every few years.)
Been Firefox user out of conviction for 10+ years, made the switch to DuckDuckGo as my main search engine with about a year ago, no regrets. But Gmail? It's sticky.
I have so much stuff tied to my email account and it just sucks looking for alternatives. I'd even happily pay. The main difficulty is finding a service that's as mature, feature-wise, as Gmail and a sensible way to migrate all my stuff (email-logins for major websites, informing clients of the new address, etc).
I think the best compromise is using two accounts for a couple of years, heavily focusing on the non-Gmail one and dropping Gmail once you had no interaction with it for a while. But all the obvious alternatives people post don't quite cut it for me, I've been searching for ages.
Finally, a week ago, I switched my email to fastmail. Bought a new domain for 10 years explicitly for that purpose.
I'm slowly migrating everything to them... Every day or two I think of something else that needs to be migrated, and do it. I don't feel a need to rush because I just have them both simultaneously.
I have to say though, Fastmail feels better than Gmail in every way. The UI is fast and snappy, looks clean (with a few themes), includes a calendar and notes. The first month is free, so I figured I'd try it before I decided to go all in. After about 20 minutes I was sold and bought a year subscription...
They have this really cool feature with subdomain forwarding so you can organize things into folders automatically. As I've been migrating emails, I've been giving each service it's own unique email address. Eg `amazon@stores.domain.com` will automatically add the email to my "stores" folder, and I'll see it came from Amazon. I can put unlimited anything before the @ sign, which will be really nice for signing up for one-off forums. If they sell my email address or send spam, I'll know exactly who did it and can just block that address.
They also have a bunch of other features for organization like the "+ addressing" that Gmail has. I definitely recommend checking them out though. I feel so good having an email that won't get shut down
i setup a gmail redirect when i switched to fastmail, that was more than a decade ago. it may or may not still be an option.
Though it irks me that Google can still rummage through so many of my conversations because my contacts still use Gmail.
Blocking third party cookies by default and requiring requests for storage access all sounds great.
window.onmessage = function(e) {
if (
/^https?:\/\/((subdomain)\.)?mysite.com/.test(e.origin) === false
) {
console.error("Access: No auth");
return;
}
}
If you could specify what the benefit over this approach is, I'd appreciate knowing.Search engines are too important to leave in the hands of one company. Especially a company that, though it was founded as a search engine company, has that search engine as only a tiny part of its people-tracking machine.
On the right is "Show Bookmarklet & Settings", click to open and you'll see your URL to bookmark. As I use standard Firefox/Chrome sync for bookmarks, I just had to save it once in either browser and it shows up on all devices exactly how I like/want.
Example: https://wccftech-com.cdn.ampproject.org/v/s/wccftech.com/int...
"3. Extension-ready
This update will initially include support for one of the most popular extensions on Android, uBlock Origin. Additional extensions will be supported in subsequent releases so you can customize and expand your mobile browsing experience even more."
Why has Moz turned in to this almost fascist company all of a sudden. Like, what? Kill all but whitelisted extensions, which users asked for that?
Let me guess, there'll be an accidental reset of people's config to enable them to be auto-updated and then there extensions will stop working ... I wouldn't put it passed then to then have already secured control over uBlock and we'll have unlockable ads before you know it.
Hope I'm wrong.
A statement along the lines of "We're working with the most popular Extension creators to get up to speed on the mobile extension API" (which could mean anything) would have been better.
Every site in Germany is 10 X bigger in normal browsing compared to AMP.
For all the intelligence and engineering prowess of Germans, their Internet infrastructure is severely lacking. Most places I'm aware of have poor connections to begin with but also still meter every kilobyte that you download, so Germans are really far more conscious of payload sizes than most Westerners are, where internet service is just a flat fee.
It's really strange when so-called "second-world" countries like Bulgaria and Romania have far better Internet than Germany
I'll take +250 ms load time over fiddling with the page for 5 seconds and then having to reload it anyway.
> The Pixel 4 is $799 and the Pixel 3a is $399 (although it may be on sale right now depending on your region). The iPhone 11 is $699 and the iPhone SE (2nd generation) is $399. Both provide additional discounts if you trade in your current phone (and since iPhones have a lot more resale value, you can get much more for your trade-in). Google provides three years of security updates, starting from the time that the phone is released. Apple provides four or five years of security (and feature!) updates. You can get the same amount of usable life out of a brand-new Pixel as a one- or two-year-old iPhone, which puts the per-year price strongly in Apple's favor. Other Android devices, like those made by Samsung, are usually even more expensive and have fewer years of guaranteed security updates. Apple even backports extremely high-severity security patches and major bug fixes (like the GPS rollover patch) to devices that would be considered "obsolete" by Android manufacturers.
So the iPhone might be a higher upfront cost, but it's a significantly lower per-year cost, especially if you get last year's model or the SE.
That doesn't seem accurate. I'm using a Samsung, 3.5 years old, and it works fine; was still getting security updates until April of this year, over 4 years after release.
Example, https://www.tescomobile.com/shop/pay-as-you-go/motorola/moto... £90.
Low end is c.£50.
For example, I get hit with this one pretty often (blank page in Safari): https://discussions.apple.com/thread/250740002, Going to reader view and back sometimes fixes it. Force quitting Safari always fixes it.
Fairly often Safari will stop accepting input. Force quitting fixes it. Also often after a pinch zoom, it snaps right back to 100%. This happens on Reddit and HN very often.
Airdrop works maybe ... 5% of the time? Just now I tried to airdrop an image to my wife. My phone said "waiting...", and nothing happened on her phone at all. Tried several times. Nothing. Airdropping to a Mac I think I've gotten to work once or twice.
I get keyboard rotation issues often, like this: https://twitter.com/mattegreer/status/1205698892555120640 (that is my tweet).
I email myself URLs from Safari. But about half the time I have to email myself, wait a few seconds, go into Mail's outbox, and then send the email from there. Otherwise it will just sit in the outbox indefinitely. This is actually true of all emails, but I use the Gmail app now for normal emailing. Added fun, sometimes the outbox doesn't show up until you force quit Mail.
Lots of annoying lack of polish issues. For example, expand an image in messages to be full screen, then return to the thread. Often you get a blank screen, because it has scrolled itself down beyond the messages by about a screen's worth. Sure, just scroll back up to fix it, but I expect a better experience from such an expensive phone.
My previous address (I just moved a week ago) has not been added to Apple maps despite the complex existing for about 2 years now. When you enter the address you get a different address about 10 miles away. Sure, not a bug but a data issue, but all the same from the user's perspective. This caused all kinds of pain. So many people use Apple Maps because they just use the maps app that came with their phone. I got situations like this, https://i.imgur.com/v13VYZM.png, all the time. Package deliveries, appointments at my house, you name it, it was such a mess. I contacted Apple support, they assigned me a support representative. Over Facetime I showed him my address not being in Apple maps and how it is in Google maps. After 2 phone calls with him and many emails, I finally just gave up and accepted it.
These are the ones I can think of quickly. I've also had tons of issues with carplay and many, many third party apps. But it's hard to know who is to blame for these issues.
Over on Android, the only real issue I've encountered is part of the phone understands I have work and personal profiles, and other parts think I don't have a work profile and want me to set one up. Admittedly, this is a pretty annoying bug that does cause some headaches, but it's really the only thing I've hit. Chrome, Gmail, pretty much everything else has been just fine for me.
But if that's what it takes to get the real web, so be it.
The dark scheme is also quite good.
I mainly use it for '*.countrydomain' to get results for a specific country.
sadly, it doesn't work with .something, so 'inurl:.co.uk' doesn't seem to work. Works with 'co.uk' but that's only valuable with longer suffixes. something like 'uk' is a bit too common.
Appears to work?
DDG is mostly Bing under the covers for organic results, so most of Bing's advanced [0] searches will work in DDG.
Edit: Interestingly enough I can't get the 'IP:' operator to work in either Bing or DDG.
But Google search is noticeably much, much better. They've got us over a barrel.
For stuff that doesn't matter too much, or is an easy search, i use DDG, then fall back to Google if i don't find what i need. For anything serious, i just open up a Google tab :(
Every time I search anything in someone else's computer (with google) I find it much harder to find what I'm looking for, sometimes I can't find and just go to DDG.
The only times I use !g is when I find some pretty obscure programming errors and no (useful) results on DDG, and only once in a while google is able to find anything better, usually the results are the same.
I wonder if the difference has to do with variations in search strategy or interests, or a combination of both. In any case, DDG does seem to have been improving, and I don't see any reason to believe that the trend won't continue. Particularly since Google seems hell-bent on making their search useless.
YMMV though, maybe I need to step up my searching game to obtain better results using DDG. That's definitely something I should work on.
Yeah, I had the same exact feeling a couple of month ago and created this [0].
Searching for my username on DDG returns an entire page of results on "glanders", a "contagious zoonotic infectious disease that occurs primarily in horses, mules, and donkeys". I don't find anything related to my name until page 2.
Runnaroo, however, has my GitHub profile as the first hit and my person website as the second. I like those results!
"I'm surprised I've never heard of this."
It is only a couple months old, so not many people have heard of it yet, but I have been trying to make an effort to share it more vs. just staying behind the computer and adding features. It did get a nice bump recently when Brendan Eich tweeted out a link to it. That was a really cool surprise.
"Runnaroo, however, has my GitHub profile as the first hit..."
I'm also working on adding Github right now as a Deep Search source, so the below results will soon be integrated into the SERP for that query.
My boss tried to warn VPs of AMP being a nuclear option. Instead of fixing the website they rather put a bandaid over it.
Isn't that part of the point though? 3rd party marketing and tracking pixels are NOT things that improve the experience or performance for the visitor.
But neither is AMP. This seems like a pure land grab to send more info to Google and less to other adtech companies.
The main issue here is executives believed the hype that an AMP website would result in higher revenue and that is not the case. The money spent on making our website AMP'd could have been spent fixing the current system.
Please read this book. The future internet will thank you.
Is there a way AMP could have an opt-out option? (maybe a permanent setting, maybe a per-search trigger) Ideally at user discretion, but I suppose it must be enabled by the first-party content provider (the website).
That would make everyone happier I think. I don't mind AMP some of the time, but sometimes it's undesirable for security concerns notably.
Does Chrome mobile’s “articles for you” section prioritize AMP content along with Google news?
From my experience this seems to be the case. I find it alarming as the only sites that support AMP are often the big clickbait news fear factories. Meanwhile the little sites who never bloated their pages with tracking scripts in the first place end up getting screwed.
How do they perceive the work that they're doing?
Do they see the harm it causes, or do they only believe in the promise of the good it gives?
I note that Terrence Eden did excellent work getting the concept of "how do users opt out of AMP results" on to the steering group, but it is notable that no work appears to have happened on it for more than a year now.
Obviously, the AMP team does not, in any way, believe the web needs to be saved from Google.
I've stopped using Google Chrome and Google Search. The only time I use Google Search now is when DuckDuckGo doesn't quite deliver and then I do so using an incognito window. Next step will be to ditch Gmail, and then Google Cloud & Firebase.
This might sound silly coming from a lone developer in South Africa, but my experience is that we live in the future, and developers with a mass intuition is rarely wrong. If the trend continues, then in 10 years' time this will be the popular view.
Which is 90% of the time when you are looking for IT questions. Unfortunately. I am hoping they are going to get better, it would be so good to finally stop google search.
I'm not suggesting that it never happens, but it's certainly not anywhere close to 90%, or even 9%.
I've generally found what I wanted via the DDG news search, but I haven't used it enough to seriously evaluate its quality, unlike the main search engine. I've also had reasonably good luck with "past week" or "past month" searches on DDG, but those aren't news-specific.
Google must index SO better or something because there's always so many more useful results (particularly in the little "sub-results" below any SO result) than what DDG gives. E.g., compare:
DDG: https://duckduckgo.com/?t=ffab&q=bash+pass+argument+to+anoth...
Google: https://www.google.com/search?hl=en&q=bash%20pass%20argument...
Or, you know, ask the site to stop using Google.
[0] https://nakedsecurity.sophos.com/2020/03/27/firefox-76-will-...
Then you have chosen to exclude yourself from knowing a large chunk of interesting information that was posted on web sites before the web went fully corporate.
Firefox focus is a very good browser for opening links on WiFi or unlimited data when using another app. It's not very good at all at being a primary browser.
How to fight back against Google AMP https://markosaric.com/google-amp/
And the original thread https://news.ycombinator.com/item?id=21712733
Surely a terrible idea though. AMP already has a PR problem.
My opinion might be because I don't have much understanding of it as a framework, but from a non power user perspective, I've found the UX to be amazing.
The reason is that, like AMP, Apple News only supports a subset of HTML. It's up to the publishers to adhere to those limitations. Some choose not to make a special Apple version or change their main content to be Apple-friendly, so Apple News does what it can to show what it can.
It's not ideal, but it's better than being reliant on Google.
Also, if you see an article that doesn't look right, there's an option to report that article to Apple. One of the options is "Content missing."
I mean if AMP effectively disguises the original URL could it not be used for phishing?
To be clear I know very little about AMP and if this is the case
Regardless it just adds complexity and makes it that much harder to teach people what is an acceptable URL when it comes to email links etc...
https://blog.amp.dev/2018/05/08/a-first-look-at-using-web-pa...
DDG has improved a lot with time, so I almost never fall back to Google anymore.
For some technical searches that DDG can't find, I find codeseek.com is better than both Google and DDG
Source - https://gist.github.com/m-thomson/611d8a91dcc27008dd4fc404d5...
Screenshot - https://imgur.com/a/qoJ6xuc
Tested in Firefox but should work in Chrome (why are you using Chrome!?).
For some reason on my iPhone AMP pages just don't fit on the screen. Maybe it's because I have a large default zoom/font. But this actually makes them unreadable because pinch-to-zoom is almost always disabled. I have a bookmark workaround for that but honestly I don't think it's ever worked.
Only recently did I discover a workaround for this: on Safari you can force touch to bring up a preview of the original site then click on it to bring that up.
If this change breaks that functionality then something has to change. That could be by using a browser to pretend to be a desktop browser or it could be DDG. I'm not sure yet.
Why do I, as a user, not have the ability to opt out of this horrible broken mess?
I'm all for having Web pages that render fast. I really hope for Google's sake that rendering speed alone is what affects ranking and there isn't some boost for AMP directly because that has anticompetitive written all over it. It would be forcing sites to adopt AMP or suffer downranking (to be fair, companies are typically terrible at designing fast-rendering websites).
So if if DDG gets me out of AMP and I can somehow set it so I get Google search results by default (instead of Bing) without using !g on every search then honestly at this point, I'm in.
>"Late last year [2016], Google said that it’s working to let users disable AMP in Google search, but there doesn’t seem to be any official kill switch yet. Meanwhile, you can use any of the above workarounds to get around Google AMP pages."
Can any Googler chime in on why it would take more than 4 years to figure out the code to turn off a feature like AMP for signed-in users who don't want it? I would have thought that this is something anyone could do in 20 minutes, but I do realize that Google has thousands of highly paid and experienced engineers so maybe there is something that takes a lot longer, that I didn't realize. Could you shed some insight on what makes this difficult?
[1] https://www.makeuseof.com/tag/disable-google-amp-google-sear...
[0] https://addons.mozilla.org/en-US/firefox/addon/amp2html/
1: https://arstechnica.com/gadgets/2018/02/internet-rages-after...
if anyone else prefers to share the original link, you can probably find the article by searching on duckduckgo. Using their search more often now these days.
What I can't understand is why it has to be managed so badly. Just put the damn URL there for people who want it. Allow opt out for people who want that. Super easy.
Even if the plan is to cynically use leverage to railroad through adoption of AMP, you're not going to win over the people who despise AMP. There's nothing to be be gained by twisting arms like this. You're only making enemies. Just throw a bone to the people don't like AMP, and the rest of the people will go along with AMP anyway because they don't care.
The original URL is provided by the Share button on the right. But it's not a link. (To visit it, you'd have to copy and paste back into the browser. You can't share a link to the app you are shared from )
So the URL is available as always, but the link is not.
Google wants to be the gatekeeper of the internet. It wants to be the middleman between everything you do online. Might you be using Google Chrome right now? Or Android? ;0
Or when you click in on some mobile and the whole url disappears and you just wanted to change part of the url.
Yes Google there are still people that want hackable urls, I remember when that was something they pushed, clean urls that make sense so you can type in where you are going.
AMP might be the thing that actually brings anti-trust, so not needed and very anti-competitive using their monopoly position to stifle competition and innovation rather than extend innovation and compete on product. Google should reward fast sites not band-aid it with an anti-competitive AMP. AMP also creates lots more work for content companies and it is only useful for Google. Essentially content companies are doing Google's work for them.
McKinsey and the management consultants have taken over large swaths of Google with stuff like this and AMP.
Here's hoping some pirate product people/engineers put up a flag and start returning to product over management metrics.
1. Enable chrome://flags/#omnibox-context-menu-show-full-urls
2. Right click the address bar
3. Select 'Always show full URLs'
Instead of seeing: news.ycombinator.com You'll now see: https://news.ycombinator.com
I made a Tell HN post about it: https://news.ycombinator.com/item?id=23322705
The long dark days of url shrouding and obscuring are over. We won the battle.
Overwhelmingly that's the main user request for AMP. The lack of progress and the fact that it disappeared from the 2020 priorities with no progress speaks volumes.
How about rewriting any AMP urls in the browser location bar to redirect to the canonical location as an end-user extension, or as an in-content script?
They already have a "good" mobile site. The AMP pages break reddit results and result in the constant annoyance of having to dismiss "Open in App?" banners both in the AMP view and on the mobile site. Everyone hates the AMP page. Why keep it? You already invested a ton of resources in the fast/nice mobile app...
I feel like we need a solution that works for everyone, not just news companies and search giants, but users as well!
When it first came out you couldn't get the URL either and they added it after people complained.
The removal seems to make it clear that it's really about control and keeping things within the confines of their own system.
As far as I know I have never seen an AMP website. I use DDG as search engine but !g a lot, so I assume I should have stumbled upon an AMP site at least once.
But maybe it is also browser related? When I go to amp.cnn.com I get redirected to editions.cnn.com in Firefox.
This Twitter post costs me 1.6MB of bandwidth and it keeps pinging for more stuff, and that's with an ad blocker enabled. While we're talking just bytes in terms of the main message.
Google is selling it as an improvement to the web, but that also says a lot about websites.
But this has been Google's strategy for a while now; they push technology that make the web faster and accessible to more people (like Chrome, HTTP/2 and 3, webp/webm, google DNS, google fiber (discontinued), Android, etc) and score goodwill, but at the same time they know if people can browse faster they will run into Google ads more often, earning them more money.
AMP is no different; if a site that doesn't even have google ads takes 10 seconds to load, they earn nothing. If the same content takes <1 second to load, WITH google ads, they earn money. And they earn money more often because people can consume more content instead of wait for things to load.
I'd love for sites to adopt AMP, as a standard for web design which leads to very lean sites without content pop-in. That'd be awesome! Give me a little icon next to the search result that says "this site is AMP certified" so I know it'll be fast.
But what I don't love, is that Google uses AMP as a trojan horse to keep me inside the google search results as I browse the internet, by:
- Rehosting the amp sites on their CDN
- Pre-rendering sites I haven't clicked yet to make them load faster
- Putting the site in some pop-over div which makes me feel like I'm still in the google results (so I can pop right back quickly and spend more time on google!)
- Breaking the swipe gesture
- Breaking the URL bar
- Breaking my phone's auto-hide for the URL bar
- etc etc
- Install an Ad Blocker, so Google will not be able to make money on your visits and chances you'll get a malware from ads will decrease - If you use Android, you can install Firefox and add uBlock Origin as extension, because Google abuse their power and prevent people from installing Ad blocker on Android. - Stop paying money for Google Ads - Stop using Gmail. There are plenty of alternatives (ex. outlook.com) - Use other search engines (bing.com and yandex.com). I noticed they work in many cases better than Google. For example, yandex.com is much better for semi-legal content which is blocked on Google and not available at all. - Stop using GCP. AWS and Azure are the better cloud providers. - Stop supporting AMP on your website - Don't pay money for integrating Google Maps into your website. There are much cheaper alternatives. - Office 365 is years ahead of Google Docs.
Has anybody actually seen the behavior described in this tweet by some anonymous guy? Because I can't confirm it so far.
Generally Google Images are the worst.
I searched 'google amp', and I can't really understand what it's supposed to do?
Can anyone explain what problem AMP is supposed solve, or what features it brings to the table?
It's supposedly a component framework. supposedly you can build web stuff faster and easier using it. In reality it looks like Google is using it a Trojan horse
>Google then cached entire amp versions of articles on their servers
That's the Amp Cache. The cache allows vendors like Google, Microsoft, and Cloudflare (who each run their own caches) to automatically preload these pages in search results without there being any risk to the user. Yes, Bing runs a copy too.
Also, I did mention scripts but left it short and sweet with the limited support of scripting that AMP has to explain AMP in more simple terms.
Yes, in this sense they are acting as a CDN. The original website is still authoring the content however.
> The internet may as well be considered broken and useless if you can't trust your web browser to at least minimally protect you from scripts automatically hijacking your computer with an "unsafe script".
It's not just about malware. I'm sure most users would not be comfortable with websites being able to track them after simply performing search results. Actually going to a website is an action with more intent behind it.
As long as Google is "only" a search engine, referencing other websites, it can get away with copyright laws by stating that he's not infringing, only showing infringing website...
But if Google serve the image by itself, with its own domain, doesn't it make him responsible for its own copyright infringement ? Maybe that we be a way to kill the behemoth... or at least this stupid "feature"...
- Changed my browser for Kiwi browser : very close to Chrome but with some neat features, one of them being to automatically redirect AMP links to original links
- deAMPify is a way to redirect AMP links from any other app than the browser
I really wish there was a way to opt-out of AMP as on iOS you're definitely SOL
AMP should die.
Critical info that's missing.
Some website: "I did this"
*walks away as Google approaches*
Google: ... "I did this"
Seriously, though. I understand why the general public isn't pushing back against this, but why don't I see more push back from websites? Websites support AMP for SEO, but at this point they should be trying to redirect users away from AMP and social media sites should be trying to automatically strip AMP from links.And why does the "Redirect AMP to HTML" extension on Firefox have so few users?
I suppose I'm happy the google crawler is still banned from my domains. People should use something else if they want good results now.
Does uBlock or privacy badger block it? It seems out of scope for those projects so I expect I should see amp links just like anyone else. Or did they kill it in the EU or something? I saw someone from NL wondering the same elsewhere in the thread.
As a user, AMP is great. AMP is a better implementation of the open web than HTML is. It's a (usually) self-contained document that isn't tightly coupled to the server it came from. You can download an AMP document, render it, attach it to an email to a friend, etc., without having to log in or get tracked. Unfortunately AMP is adding ad capabilities, but at least AMP allows you to strip those out fairly trivially.
As a website, if you want your users tightly coupled to your server, just don't implement AMP? You literally went through non-negligible effort to implement a feature and now you're surprised and angry that it works the way you implemented it. AMP was always a bad idea if you wanted users to be dependent on your website for your content--this has only made it a slightly worse idea. And by the way, if all you want is credit for your content, it's trivial to add a linked byline to the top of your AMP.
I'm not defending Google here. They're an amoral corporation with too much power and shouldn't be used, period. But AMP is fine.
EDIT: I can only assume the silent down-voters are people who implemented AMP and are whining that what they implemented works. ;P
(For what it's worth, I up-voted you).
Except the results of AMP can be done without AMP. It just requires site owners to not put a bunch of crap on the site. Something that AMP requires you to do.
> You can download an AMP document, render it, etc., without having to log in or get tracked
Except for the fact that now only Google tracks you. Also, doable without AMP.
The hate from many isn't about being a website owner. It's about being a website user. When I click on a link of a website, I expect to go to that website. Not stay on Google's site.
Sure, you can build self-contained HTML pages, but you don't have any way of indicating to browsers or search engines that what you've created can be consumed in that way.
> The hate from many isn't about being a website owner. It's about being a website user. When I click on a link of a website, I expect to go to that website. Not stay on Google's site.
That's a great objection to Google not linking to the original site.
It's not an objection to AMP. Nothing about AMP prevents Google from linking to the original site.