Firefox 85 cracks down on supercookies
blog.mozilla.org
blog.mozilla.org
Clever. And so frustrating that optimisations need to be turned off due to bad actors.
For cross-origin, you'd add CORS.
If you generate a random URL, you'll always get a cache miss.
If you use a static URL, you'll know if you have a new session or not, but that doesn't tell you what the tracking ID was.
The only thing I can imagine is the server serve several images /byte1.png /byte2.png etc. and make them all X by 1 pixels, encoding a random value in the dimensions, assuming that's available to Javascript.
But if you encode the tracking ID in the image somehow, you don't care much whether it was cached or not, it's inherently persistent. It'd mainly be useful if you're trying to reconstruct a super cookie.
As Mozilla have said:
> "In the case of Firefox’s image cache, a tracker can create a supercookie by “encoding” an identifier for the user in a cached image on one website, and then “retrieving” that identifier on a different website by embedding the same image."
The identifier is encoded into the image itself on a fresh fetch of the static URL, which can then be extracted by JS (which can access pixel data, and their RGBA channel values).
When a cache-hit is detected, you know you have an identifier that correlates to user history.
If you have to hit the server on that static URL, you write a request handler that will always give you back a new image with a new ID encoded in the pixels. Think of it like dynamic page generation on the server side, but for an image instead. Every time you hit the same URL you get a different image.
On the client you can decode that ID and use it throughout your code, in network requests, etc., to track user activity.
If the image is already cached you just decode the ID and use it as described above. All the browser cares about is associating a URL with a resource: it doesn't know or care that the resource in question changes every time it's asked for.
Also, the client code literally doesn't need to care whether the ID is from an image in cache or an image returned from the server.
The server can simply tie all activity for a given ID together on the back end.
This is one way of doing it: there are probably others. I'm certainly no expert.
When image loaded, js read the identifier, if the image loaded from cache, the identifer still same
Edit: typo
1. On site A, make a request to eviltracker (e.g. load an image); eviltracker returns an image encoding some unique identifier. Maybe the image request contained some cookie data which the server includes as part of the image.
2. On site B, make another request to evil tracker with the same URL. Browser helpfully notices that the image has been cached, and so site B can access the information contained within that information. In such a manner, information has been transferred from site A to B. You could theoretically repeat this process again: make another non-caching request to eviltracker (maybe with some cookie set to the combined A+B info)
[1] https://developer.mozilla.org/en-US/docs/Web/HTML/CORS_enabl...
I suspect you'll find this is _way_ more common than you expect.
(Also, if you thing Goog aren't doing this with their font CDN or various javascript library coaches, even (or especially) for sites without Google Analytics... I've got a bridge to sell you...)
Letting any website and their friends (and the friends of their friends) run turing complete code on the client PC probably sounded reasonable when the web was created but it seems incredibly naive in hindsight. It's not as bad as ActiveX and other plugins, but it's pretty close.
Hopefully both, someday :)
Also, good regulation is important to keep the big dogs on a leash and to have something to go after them when they don't behave.
Technological solutions will of course come, but you also need regulation, especially until the technological solutions come.
No, this is really out of touch with how crime online works. People that want to hammer a bank rent botnets, use tor, vpns, etc.
Banks get absolutely zero protection from the law in that regard. It’s “illegal” but completely unenforceable to the point of being useless.
Yes there is. A mugging is still a mugging even if the victim is "free" to give their wallet.
> websites are free to not abuse cookies to track their users.
You're free to not use such websites.
I dislike tracking and avoid being tracked myself. But this absolutely is a regulation and it's immensely disingenuous to pretend otherwise.
On the other hand, many sites work better with JS disabled: they load much faster, don't slow down scrolling, don't break copy & paste, and so on.
edit: I should probably make clear that I'm not the same user you responded to
I'm not a promiscuous browser, if I click on an interesting link and I get an empty page because it insists on javascript I close that tab and figure I saved myself from wasting my time on a crappy ad-tracking-infested website, so many of which are lame anyways.
That being said I do sometimes enable javascript temporarily on sites when I am desperately looking for some specific bit of info, then I reset back to my default-off when finished.
I've been doing this for a couple/few years, and it doesn't seem like a big deal to me. I'm happy to have that reminder that a site is irritating me insisting on javascript for no good reason, more often I go elsewhere and that suits me fine. It saves me from having to worry about so many nefarious things that go on in this space.
Why not give it a try? Ublock lets you default disable all javascript and enable it on the page you are looking at with a couple clicks, and edit/revert your list of rules whenever you want. You might be pleasantly surprised at how few times you need to fiddle with it after you set it up for your important sites.
What frustrates me the most is that we can't individually disable web api's that provide no value to us. Yeah, that would give greater entropy to fingerprinting, but I'm willing to take that tradeoff if I could prevent webrtc, motion sensing, screen size detection, or web assembly e.g. except on selected whitelisted websites.
"No no no. The problem isn't unencrypted network connections, it's companies and people who use them in evil ways. I would rather handle that even if it's much harder."
Should we not have introduced HTTPS? Permission models on modern operating systems? 2-factor authentication?
What about Javascript makes it different to the problems solved by these other features?
[0] https://addons.mozilla.org/en-US/firefox/addon/disable-javas...
---
[1] https://github.com/gorhill/uBlock/wiki/Per-site-switches#no-...
Obfuscated to resist ad-blockers and anti-tracking features.
At least that's how I understand it, care to give ideas why it's not a positive change? :)
What I wrote above: it's going to encourages 10x more bloated and obfuscated websites.
Apart from the security and privacy issues, it will make the web even less accessible to users with slower Internet connections (some 2bln people) and visually-impaired users.
Not exactly.
The root of all evil here is HTTP. You don’t need any JavaScript to plant cookies or other tracking assets. As a proof this technique is used to track users in email, such as embedding a 1 pixel image in an email retrieved via HTTP.
I guess it's probably a bad idea to let the browser send this type of potentially unique info to the server by default, but I understand how it makes sense from a performance perspective.
As far as I'm concerned privacy should always trump performance, but I realize that not everybody shares this point of view.
Suppose, that you are visiting a web site with Evil Embedding (an iframe tag or script, that loads Evil Resource on behalf of advertiser). If your browser requests Evil Resource without telling advertiser the name of top-level site, the advertiser gets little. They get to know, that user 9062342154 is online and they are asking for Evil Resource X, but that's all. They can't even tell, which specific website is being visited!
The real problems start, when the top level web site cooperates with advertiser by running a Javascript "bridge", that acts both as an arbiter and a communication channel for siphoning your information. In addition to transferring information, the bridge acts as anti-fraud measure to confirm, that there is no foul play on the part of web site operator. Since the script is Turing-complete and can be updated anytime, there is no way to restrict it's actions.
But the advertiser will get the referrer so will know the domain name?
(And if they didn't, they could require the site operator to include the site name in the resource URL.)
Oh stop with the dramatics, please. JS has brought us an immense amount of innovation on the web. It has lowered the barrier of entry to programming and introduced tens of millions of people to the world of development.
If you're on HN the odds are that directly or indirectly, JS is one of the reasons you have a job today, and that you can execute it remotely. And today specifically, it's the only reason many kids can do remote learning as efficiently as they can.
Dude/dudette, I'm not a big fan of JS but let's recognize the good it has brought on the world, instead of complaining in the likes of what amounts to "if only we still lived in caves, we wouldn't have those pesky problems with online advertising" or something.
Technically, the detail of super-cookies is inventive and surprising. The general trend for how capitalism inevitably both uses and abuses advertising was predictable.
What does JS have to do with my VPN? What was wrong with Skype? Still beats the pants off others for quality.
I cannot think of much good agressive whitespace, hamburger menus, infinite scrolling, HID hijacking, copy-paste preventing, trackers etc, etc etc, has brought us, besides into the world of Aggressive Ad Arbitrage.
Need https://motherfuckingwebsite.com/ be mentioned?
The real powerhouse was Flash, then HTML5, and now WebAssembly, or as I like to call it, reinventing the wheel while simultaneously and conveniently blocking ad-blockers.
This has shades of "What have the Romans ever done for us".
That's like saying wool is useless because you don't like modern fashion.
This meme needs to die.
WebAssembly doesn't prevent ad blocking at all. Ad blocking relies on blocking network requests for the most part, which can still absolutely be blocked when done by WASM.
Some ad blockers also optionally relies on removing DOM nodes for greater coverage. It's important to note that this technique is used to reduce visual clutter, but doesn't prevent tracking, and doesn't increase browsing performance as the ad still gets downloaded before being removed.
Yes, a purely canvas-based app could work around DOM blocking, but WASM has nothing to do with it: you can do pure canvas-based UIs in javascript too, that's what all the modern web games do.
Skype is superceeded by a half dozen more targetted classroom video chats - none of which need installing or require the kids to have accounts.
From the perspective of more easily deployable apps that are more useful to end users, WebAsm > HTML5 > Flash. The fact the ad monopolies run our major web developments is convenient for them to piggyback these changes, but isn't the drive for them.
The sad part is we're probably just one decent privacy bill away from making almost all of this go away. JS + an anti-regulatory political climate is the larger problem. The EU has tackled this heads on recently with its privacy laws. At a certain point, technical work-arounds just don't work and the bad commercial actors will always win unless there's regulation stop them.
JS has dumb flaws. It doesn't mean anything is happening "in spite" of it. If anything, innovation is happening thanks to JS AND in spite of its flaws. But don't think for a second we would have even one tenth of the developers we have at our disposal today if JS and the internet didn't massively lower that barrier of entry. And less developers means less progress overall in the entire industry, not just less left-hand libraries.
It has a type system. "Excellent" feels a bit strong.
https://blog.asana.com/2020/01/typescript-quirks/
https://www.executeprogram.com/courses/typescript/lessons/ty...
That second article is legitimately cool though.
I think Basic, Pascal or Python achieved more at that.
> it's the only reason many kids can do remote learning as efficiently as they can.
The main reason is internets and TCP/IP, that’s essential and irreplaceable. Another important reason is h.264, equivalents do exist, but given the state of hardware acceleration it’s irreplaceable, at least not on mobile devices.
JavaScript ain’t an essential tech, as it’s replaceable on both clients and servers. Your kids would learn equally efficiently using a native app instead of these JS-rich web sites.
And TCPIP may have helped but just because it's essential part of the stack doesn't mean the remote learning could have happened without JS existing (in the time it did). The web would be a glorified FTP server if some people here had their way.
Javascript is one of the, if not the, most influential technologies of the past 100 years. It changed the course of history. Can you say the same of, like, wxWidgets or whatever UI toolkit you'd be using for your native app?
That's... one hell of a claim.
A sandboxed environment was a huge idea and the browser has been the primary example of how great it can be. The app model in mobile with permission isolated access is more or less the proprietary re-implementations of the browser sandbox.
To apply the common construction analogy to JavaScript: no one would call a quick sketch on a napkin a valid blueprint for a building.
what problems? Yeah, stuff like left-pad happened with NPM, but that has nothing to do with sandboxed scripting in browser. Also within my already-depressingly-long career, I had more problems with deploying "robust" .NET desktop apps (WPF & Forms) and even Qt based supposedly "cross-platform" apps than web apps. Web is the most robust platform I've ever worked with, and that's by a huge margin.
JS as a language has problems[1] but the idea behind it proved itself to be great.
[1]: and with the latest additions it's one of the better programming languages to work with, although the standard library sucks (or more like, nearly non-existent). But that's totally another topic.
The browser runtime is what enabled us to use software provided by a huge number of developers of varying aptitude and motivation without putting in place some centralised gatekeeper with its own vested interests.
It would be naive to download and run native code for every website you visiti, yes. A few that you trust and where you think that is warranted is a different matter.
Running javascript in a sandbox provides the illusion of safety so it gets enabled by default while still creating tons of problems.
We tried that, and the security issues it caused were orders of magnitude more severe than any of the problems caused by defects in an up-to-date browser sandbox. Basically all consumer PCs used to be infested with viruses all the time. It sparked an entire virus scanning industry.
It takes far too much discipline and diligence to make sure that you can trust the motivations and security capabilties of all your software providers. Sandboxing is good. It's the only thing short of the most heavy handed, restrictive and centralised control that has ever worked.
The security issues we have on today's Web are overwhelmingly unrelated to client-side security. The problem is protecting the data that is stored on servers and the incentives created by ad based business models. All of that is equally problematic regardless of whether you run native code or sandboxed JavaScript.
I think we could have done better if we knew what we were doing.
And wasted zillions of man hours to relearn the latest web framework every 2 years. Good job JS. We all love you.
JS didn't lower the barrier to programming at all. On the contrary, programming with VisualBasic and SQL was 10 times more accessible and productive than web development. What enabled millions to write software was the availability of computers in every household.
What the Web did was revolutionise software distribution. After making a change to my 1990s style VB program I had to pack a stack of floppy disks and travel to my customer to install the new version on their PCs, migrate the data, make sure everything still worked in spite of other programs installing an overlapping set of DLLs, etc.
With the Web, we took a massive hit in terms of developer productivity and complexity, but the distribution model trumped absolutely everything. It also made things possible that would have been completely unthinkable, such as running software made by a large number of developers you don't know and don't necessarily trust with all your data.
To this day, the Web is the only reasonably secure runtime environment that isn't centrally controlled by some gatekeeper with its own agenda.
So I actually agree with most of what you have said elsewhere in this thread. But I disagree about lowering the barrier for developers.
I think OP meant it as browsers that run JS. The built in console is so useful for testing/practice. You can run JS without any setup on most popular OS - Win/Linux/Mac.
You can practice JS in console while viewing YouTube tutorial or following a JS blog/ Mozilla dev page.
Everyone who had MS Office installed back in the 1990s (which was basically everyone) could easily run some quick VB code to try things.
But the difference was that you could also create proper applications with a UI, a database and (optionally!) some glue code.
We just had no good way of distributing our apps. Creating anything collaborative that wasn't restricted to a local network was exceedingly difficult as well.
The Web fixed all that, albeit at the cost of cratering developer productivity, a massive increase in complexity and higher barriers to entry for new devs.
And if you're asking me why the number of developers exploded while the barriers to entry supposedly went up, my answer is that the new opportunities that came with unrestricted worldwide distribution of software trumped the narrower issue of writing that software in the first place.
Can't be everyone, how do you know the numbers? How many Office users actually used VB? MS famously stifled competition in internet browsers. 1990s numbers still won't give a fair picture.
>The Web fixed all that, albeit at the cost of cratering developer productivity, a massive increase in complexity and higher barriers to entry for new devs.
Why blame the web for higher barrier to entry. JS is doing fine. See a few surveys for popular languages: https://insights.stackoverflow.com/survey/2020#most-popular-...
You don't acknowledge the need to sandbox code, regardless of language.
No, it was already very unreasonable, especially as the browsers of the time had even worse sandboxing than now.
But even if you turn off Javascript, you are not invisible or untraceable, you are just getting a little harder to be tracked. I don't wanna name anyone, but there are tons of famous websites that tracks by including <img> tags and referencing pixel trackers.
I usually browse with JS turned off, it's blazingly fast, and, well most websites work without any significant drawbacks.
Gmail no longer loads them. Thunderbird no longer loads them. Most providers, offering online email, have already caught on.
> Trust me, people will find ways around it without JS. Reinventing Flash, for a start.
There is no need for that. Why bother, when you can write a mobile app in proper computer language and eliminate the middleman (browser)?
"Personalized" ads are partly a scam to devalue publishers: set a tracking cookie when a user is on an expensive-to-advertise-on website, and then serve ads to the very same user when they visit cheap sites. I'm dumbfounded why reputable publishers put up with this.
Definitely this. Reminds me of the whole Spectre/Meltdown debacle.
The likes of Amazon, Google, and Facebook are the envy of the Government, if anything.
Of course publishers don’t follow it and do the exact opposite: default allow everything, click every single one to say no.
It also means that I can remove fonts.google.com from the uBlock blacklist. Yay.
Decentraleyes hasn't been updated in ages, has few assets and its assets are massively out of date.
https://git.synz.io/Synzvato/decentraleyes/-/tree/master/res...
vs
https://codeberg.org/nobody/LocalCDN/src/branch/main/resourc...
https://codeberg.org/nobody/LocalCDN/commits/branch/main vs https://git.synz.io/Synzvato/decentraleyes/-/commits/v2.0.15
I'd imagine if LocalCDN got more popular than Decentraleyes, it would probably get Mozilla's seal of approval as a "recommended" extension. Then again I'm not entirely sure what their approval process for that looks like. Currently Decentraleyes has about 100x the userbase.
Nobody seemed to think it was hard to host a file before this came along, just as nobody thought it was hard to have a blog before Medium.
Of course this creates the apocalyptic possibility that one of these servers could get hacked (later addressed with some signing) but it's also not easy to say you're really improving the performance of something if there is any possibility you'll need to do an additional DNS lookup -- one of the greatest "long tails" in performance. You might improve median performance, but people don't 'experience' median performance in most cases (it goes by too fast for them to actually experience it), they 'experience' the 5% of requests that are the 95% worst, and if they make 100 requests to do a task, 5 of them will go bad.
People are miseducated to think caching is always a slam dunk and sometimes it is but often it is more nuanced, something you see in CPU design where you might "build the best system you can that doesn't cache" (and doesn't have the complexity, power and transistor count from the cache -- like Atmel AVR8) to quite a bit of tradeoff when it comes to 'computing power' vs 'electrical power' and also multiple cores that see a consistent or not view of memory.
https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
Every byte sent will cost the business. If you can save that 2MB per user per cache life, you pay that much less on the internet bill for your hosting.
Every byte sent uses up some of your limited bandwidth while it is being sent. If your site is 10KB and you rely on 2MB of javascript libraries and fonts, offloading that 2MB is quite a significant reduction is resource usage.
These above two views seem vastly more important than terminal laziness, up-time management, etc.
... then you're doin' it wrong.
100%. Its mind blowing that this could possibly be considered without batting an eyelid.
Ah yes - I remember those _dark days_ of being a shared webhosting customer over a decade ago and stressing about breaking my 500GB/mo data transfer limit.
Today, Azure's outbound data costs on the order of $0.08/GB, so 1MB is $0.000078125, so the cost of 2MB of JS is $0.00015625.
Supposing you have one million new visitors every month (i.e. nothing's cached at their end so they'll download the full 2MB) - those one million visitors will cost you $156.25 in data-transfer.
Compare that to the immediate cost to the business of paying their SWEs and SREs to trim down the site's resources to a more realistic few-hundred-KB, supposing that's a good 2-3 week project for 3-4 people - assuming a W/Best Coast company, that's ( $250k / 52 ) * 3 * 4 == $57,000.
From looking at those numbers, there is absolutely no business case in optimizing web content - it's now significantly cheaper (on paper) to have a crappy UX and slow load-times than it is to fix it.
Huh? Who ever said the main point of a CDN is to make things easier? It's always been in order to provide a faster end-user experience.
> ...but it's also not easy to say you're really improving the performance of something if there is any possibility you'll need to do an additional DNS lookup -- one of the greatest "long tails" in performance.
But common CDN's will virtually already have their IP address cached while you're browsing anyways.
Caching certainly has nuance to it as you say, but I think you're being particularly ungenerous in claiming that CDN's are a scam and that you're representing "reality".
Businesses measure these things in reality with analytics, and they also almost always analyze the worst 5% or 1% of requests as well, not just the "median".
CDN's are a big boost to performance in many cases. Or at least, until now (for shared files). You shouldn't be so dismissive.
On top of that a lot of the modern frontend tools and best practices are pushing in the other direction. Out of the box, tools like webpack will bundle up all your dependecies with your app code. The lack of JS namespacing and desire to avoid globals (which is pretty well-intentioned, and generally good advice) means that your linter complains when you just drop in a script tag to pull a library from a cdn instead of using an es6 import and letting your bundler handle it. Typescript won't work out of the box I don't think. Your integration tests will fail if the cdn is down or you have a network hiccup, as opposed to serving files locally in your test suite. And on and on. This is just anecdotal, but I haven't seen most teams I've worked with value the idea of centrally-hosted JS enough to work around all these obstacles.
If you are downloading fonts from Google, Google harvests your IP and likely the referring site from the request. Even if your browser doesn't sent the referrer, many sites have a unique enough font-fingerprint that Google can figure out where you are.
FWIW, I'm not sure how much of an issue this even is. My comment was a hypothetical. Sadly the way Google/ Facebook/ etc operate, I just assume that whatever I think of, they've already done it plus 1000s of other things which would never occur to me.
It doesn't or more correctly the benefit wasn't really a think in most cases.
I will not start the discussion her again but on previous hacker news articles about this topic you will find very extensive discussions about how in practice the caches often didn't work out well for all kinds of reasons and how you still have a per-domain cache so it anyway mainly matters the first time you visit a domain but not later times and how the JS ecosystem is super fragmented even if it's about the same library etc. etc.
> cause it reduces the value that unscrupulous free CDN providers can derive from their "properties".
Not really, the value of a CDN is to serve content to the user from a "close by" node in a reliable way allowing you to focus on the non static parts of your site (wrt. to traffic balancing and similar).
Shared caches technically never did matter that much wrt. CDN's (but people used it IMHO wrongly as selling point).
That negates the super cookie use case, but still lets you eg. load Jquery from a shared CDN.
You get a free security upgrade to go with it.
This does not work as you still can have the same timing attacks the hash only helps wrt. source integrity from CDN's but not with chach based time attacks.
Still what should be possible without timing attack channels is to de-duplicate the storage of resources (through not easy and likely not worth it for most use-cases). So you will only lose the most times small speed post on the load time when you open a domain the first time.
Firefox also has an active fingerprinting protection mode that spoofs the unique values returned from some JavaScript APIs (such as locale, time zone, screen dimensions, WebGL), but this feature flash is currently buried in about:config because it can break websites. How to enable fingerprinting protection anyway:
https://support.mozilla.org/kb/firefox-protection-against-fi...
eg. I'd like use temp containers all the time, except for some sites like YouTube where I'd like it to always open in a YouTube container
https://addons.mozilla.org/en-US/firefox/addon/multi-account...
uBlock Origin with privacy lists negates the need for Privacy Badger.
Decentraleyes is neat but I've found multiple sites it breaks.
A better way to protect yourself is to use a browser with tracking protections on by default, and leave the settings alone. You may see a few more ads but you’ll be a lot less tracked as a result.
If personal convenience is the priority, then of course Adblock and so on to your heart’s content, but if not being tracked is the priority, reset your browser settings to default and remove weird addons that your neighbors don’t use.
None of the cache deletion/isolation addons should inject any Javascript into the page or alter headers in any way, so they shouldn't be detectable to sites you visit. So in terms of unique behavior, all that site isolation means is that you're going to hit caches more often and be missing cookies.
I mean, sure, a website can recognize that you don't have any unique cross-site cookies to send them and make some inferences based on that, but the alternative is... having a unique cross-site cookie. So it's not like you're doing any better in that scenario.
I can see an argument against a few of these like DecentralEyes, since they change which resources you fetch at a more micro-level. But uBlock Origin and Multi Account Containers seem like strict privacy/security improvements to me.
UBlock Origin especially -- if you care about privacy, you should have that installed, because outside of very specific scenarios your biggest threat model should be 3rd-party ad-networks, not serverside 1st-party timing attacks/fingerprinting. No one should be running Chrome or Firefox without Ublock Origin installed.
Websites can only make inferences based on the absence of unique cross-site cookies if you are configuring your browser in non-default ways. If all Firefox 85+ users are partitioning, then any inferences drawn from that behavior do not increase your trackability — and it could well decrease it, as those Firefox 85+ users will be joining the swarm of Safari users whose browser has already done the same sort of partitioning for a couple years.
Multi Account Containers are an oddity, and alone they would not be particularly distinguishable from a multi-user computer (which, at a home residence, could be unusual; many people don't have User Accounts on a shared device). However, when combined with cross-container tracking infection (such as URL parameter tags designed to survive a transition to another container, e.g. fbclid or utm_*), it's possible to identify that a user is using containers, which is a very rare thing and not available by default, thus increasing risk of being tracked.
UBlock Origin allows far too much customization for me to prepare any clear reply there. I imagine it is possible to run UBO with a ruleset that only interferes with requests to third-party adservers, without letting the first-party know that this is occurring. I doubt, however, that a majority of UBO users are running in such a circumspect mode. Adblocking often requires interfering with JavaScript in ways that are easily visible to the first-party (who has a vested interest in preventing ad fraud).
Fingerprinting is a known defense against fraudulent clicks, so there's a lot to puzzle over there. But I definitely don't like to take active steps to make myself stand out from others. I'm annoyed that I'm tracked a little on the web, but I'm indistinguishable from the general pool of "users with default browser settings" today. That's a type of protection that addons can't provide. I'm not wholly certain what I think yet, but happily the browsers continue advancing the front of protection forward, so maybe by the time I decide it won't matter anymore. YMMV.
ps. I'm glad to see your much more nuanced consideration of this balance, and I wish that more took your careful approach here when recommending "privacy" setups to others.
But if the defaults don't block those cookies, then the alternative is that you have unique cross-site cookies, which are an instant game over. Having a site make inferences about you is preferable to having a unique cross-site cookie set that can perfectly identify you across multiple websites.
> [...] and I wish that more took your careful approach here when recommending "privacy" setups to others.
Similarly, I appreciate your approach and concerns, and you are correct that browser uniqueness is a valid concern, one that many people don't consider. But I fully stand by my advice. Your first priority as a user who cares about privacy needs to be blocking unique cross-site cookies. If you have them set, it's just game over, it doesn't matter whether or not someone is fingerprinting you somewhere else.
Your priority list should be:
A) block cookies and persistent storage that can track you across sites.
B) block tracking scripts from ever executing at all.
C) keep your browser from standing out.
D) etc...
uBlock Origin is the easiest, simplest way that you can make progress towards addressing A and B. To your overall points about stuff like advertising networks looking to prevent fraud, this is exactly why it's important to block advertising networks; they're the low hanging fruit that's most likely to be trying to fingerprint you at any given moment. To your point about it standing out that you don't have certain query params set, those query params are unique identifiers and referrers. If you don't delete them it's game over, you have been identified. You can't blend into the crowd if you have a tracker attached to you.
There are very few one-size-fits-all approaches to security/privacy, but I fully stand by the belief that virtually every single person running Chrome or Firefox should have uBlock Origin installed. I don't have much nuance or any caveats to add to that statement: block unique identifiers first, worry about fingerprinting second. You don't need to worry as much about your browser standing out if you block the majority of tracking scripts from reaching your browser in the first place, and in most (not all, but most) cases you should be more worried about 3rd-party tracking on the web than 1st-party tracking. That's just where the current incentives are right now, and it's important that we calibrate our threat models accordingly.
What these plugins do is make the tracking job more difficult for the adtech guys, and the more complex these systems become, the higher the costs to the tracker and the higher the likelihood they screw up. It's defense in depth.
[1]: https://support.mozilla.org/en-US/kb/how-clear-firefox-cache...
https://addons.mozilla.org/en-US/firefox/addon/temporary-con...
[1]: https://medium.com/@stoically/enhance-your-privacy-in-firefo...
> These impacts are similar to those reported by the Chrome team for similar cache protections they are planning to roll out.
"The feature is being rolled out through late 2020. To check whether your Chrome instance already supports it: ..."
Safari has been doing this since 2013 https://bugs.webkit.org/show_bug.cgi?id=110269
Tweeted about in 2017 https://twitter.com/cramforce/status/849621456111624192
https://developers.google.com/web/updates/2020/10/http-cache...
Does anyone know if these protections go further or differ significantly?
Crazy and sad to see where we've come :\
Only people from places where it's too late to go back (like China) are aware of the dangers of these systems, but they can hardly warn the rest of us and when they do, we generally don't listen as "something like that surely wouldn't happen in my free country".
It would seem that people only get slightly spooked when a government does something that could impact their privacy (even when it actually doesn't - see the recent covid tracking app backlash in basically every country) but when private companies do it, they eat it up hapily.
If there were an opt-in way of doing this, it wouldn't bother me. Similarly with online tracking, if it were opt in only, it wouldn't bother me.
What is frustrating is the lack of transparency or ability to control who and where my data is collected.
There's not much risk to 'pay with your face' for Apple/Google/Samsung pay given it's all on-device biometrics that never leave the phone, but a similar situation is when Google paid $5 to people willing to submit their face to help with facial recognition training in the then-upcoming Pixel 4 phone.
https://gadgets.ndtv.com/mobiles/news/google-pixel-4-usd-5-f...
There are cars with license plate scanners that wardrive the world. They scan plates in shopping centers, businesses, and even apartment buildings so on the off chance law enforcement, repo businesses, or anyone who wants to know where your car is parked can track you.
People accept that. Or rather, most are blissfully unaware that it happens.
If your grocery store added face tracking to their existing security cameras, would you even know it? Would you know if they sold that data?
The Wild West mentality in the US kind of sucks when technology allows even small businesses the ability to screw over large numbers of people.
That is the problem.
Private exercise of the same technology is merely deterred, but not stopped by GDPR (especially now that UK is "happily gone" from "EU overregulation"...).
And of course that ignores China which has cities that have both more total(Beijing, Shanghai) and more per-kilopop (Taiyuan, Wuxi) cameras than London.
[0] https://www.cctv.co.uk/how-many-cctv-cameras-are-there-in-lo... [1] https://www.nytimes.com/2020/01/24/business/london-police-fa...
Or remember adware on windows XP and how many antivirus tools advertised to eradicate that.
* they're hilarious comparison but I found it amusing.
I'm definitely of the opinion that our web browsing devices are marketing tools that we are allowed to use for media consumption.
I blame shitty sites more than Apples architecture :(
In fact, there are many different caches trackers can abuse to build supercookies. Firefox 85 partitions all of the following caches by the top-level site being visited: HTTP cache, image cache, favicon cache, HSTS cache, OCSP cache, style sheet cache, font cache, DNS cache, HTTP Authentication cache, Alt-Svc cache, and TLS certificate cache."
Clever !
(emphasis mine)
This has negative effects on security, as has been pointed out previously by others: https://nakedsecurity.sophos.com/2015/02/02/anatomy-of-a-bro...
Imagine a widely used legitimate non-tracking resource, say, a shared JS or CSS library on a CDN. Currently, if that CDN uses HSTS, no matter how many independent websites incorrectly include said resource using an http:// URL, only the first request is MITMable, as every subsequent request will use the HSTS cache.
However, now, every single site will have its own separate HSTS cache, so every single first request from each site will independently be MITMable. Not good. This makes HSTS preloading even more important: https://hstspreload.org/
(Good news, if you have a .app or .dev domain, you're already preloaded.)
I'd like to see a point where browsing on two different websites are treated as a completely different user. Embeds, cookies, cookies in embeds, etc.
I use it to automatically open every new tab in its own temporary container.
[0] https://addons.mozilla.org/en-US/firefox/addon/temporary-con...
[0] https://addons.mozilla.org/en-US/firefox/addon/multi-account...
I run that on my personal devices.
At work, there is so much in terms of SSO the amount of redirects that happen mean that temp-container-per-domain breaks all sorts of workflows, so I go without on the work machine.
I notice no major difference between these two configurations, although I'm sure that there would be things that are measurable, though imperceptible.
[1] https://addons.mozilla.org/en-US/firefox/addon/temporary-con...
edit: I'm trying this out, seems to work nicely - but assigning all the sites that i want permanent state on to different account containers is a bit of a chore. Feel like i'm doing something wrong there.
But the temporary containers are working great
I don't recall the last time I had to temporarily disable it to allow something to work.
No good comes from downloading random, untrusted native applications from the net, installing them locally, and trusting these not to infect your system with malware. No good comes from loading random, untrusted applications into your browser either, and trusting these not to infect your browser, either.
Basically everything on the web should not only be sandboxed with regard to local system (this is mostly established) but also be sandboxed per site by default. Hidden data, or anything that's not encoded in the URI, should only move between sites at the user's discretion and approval.
I've had personal plans to ditch my complex adblocking, multi-account/temporary container and privacy setup in favour of a clean-state browser that I launch in a file-system sandbox such as firejail for each logical browsing session (like going shopping for X, going online banking, general browsing). Basically an incognito session but with full capabilities as sites can refuse serving incognito browsers. Normal browser setup with everything wiped off when the browser exists.
I have some dedicated browsers for things like Facebook where I whitelist a handful of necessary cookies and forget the rest on exit. This, however, won't clear data other than cookies. I think that per-site sandboxing would mostly solve this problem. I don't particularly care what data each site wants to store on my browser as long as it won't be shared with any other site.
Is there a way to disable it? Or should I better think about installing a caching proxy to avoid the redundant traffic?
I think turning `privacy.partition.network_state` off in about:config should do allow reverting the change at least.
It’s only if a.com and b.com have (for example) the exact same image URL (c.com/img123.jpg) embedded, and you visit both sites, that this cache partitioning will make a difference.
In essence, there’s very little legitimate Internet traffic that would be effected by this change, but lots and lots of creepy spyware behaviour will be prevented.
If you’re a Mac user with more than one of any kind of Apple device on your network (like, two Macs), you can install their Server app on any macOS and enable software update caching as well.
It is incredibly difficult to make a browser fingerprint non-unique. Only the Tor browser has strict enough settings with a large enough user base to overcome fingerprinting.
If you don’t want to use Tor, try these:
- uBlock Origin (which has a larger blacklist of fingerprinting scripts)
- Enable the privacy.resistFingerprinting setting in about:config to make your browser more similar to other users with that setting enabled (but not entirely non-unique)
- The nuclear option: arkenfox user.js [1]. It’s github repo also contains a lot of further information about fingerprinting.
It's a continual source of amazement for me that a majority of HNers are using a browser made by the largest data gobbler in the world, instead of one that actually tries to prevent spying on users.
So, I’ve trained my brain to use chrome as an app only for google websites. When I need to check gmail or YouTube or google calendar, I use chrome. Otherwise I’m on Firefox or safari.
It’s worked pretty well. I found I was only really unhappy with Firefox when using google websites. No longer a problem.
Edit: I am a diehard Firefox user and fall back to Chrome only when I have to because of some weird breakage. One of those is editing within Atlassian's Confluence: find within a Confluence page doesn't work right in FF, and I've often had @name references messed up too upon saving. Chrome works fine.
There’s a good chance my MacBook is not supported properly for Firefox as I’ve run into some internet threads about. But at this point, I’ve settled on this solution. It also makes me spend less time on YouTube once chrome is closed down and I’m solely on Firefox.
For a number of sites like YouTube and GMail, it's because of Google. If you change your useragent to look like Chrome, you get served a JS payload that Firefox is fine with, and it is faster.
If your useragent isn't Chrome, they'll serve you a less optimised payload, but which tends to have wider support.
They seem to have made a tradeoff - one that generally isn't necessary under Firefox.
Chrome had SPDY support not just before any other web browser did, but before any open web server did—because Chrome had SPDY support before Google ever documented that there was such as thing as “SPDY.” It was, at first, just turned on as a special Chrome-to-Google.com accelerator, spoken only between that browser and that server, because only they knew it.
I don’t fault Google for this: they’re doing “internal” R&D with protocols, and then RFCing them if-and-when they turn out to have been a good design for at least their use-case with plenty of experimental data to confirm that. Which is exactly how the RFC process is intended to be used: spreading things that are known to work.
It’s just kind of surprising that “internal” R&D, in their case, means “billions of devices running their software are all auto-updated to speak the protocol, and start speaking it—at least to Google’s own servers—making it immediately become a non-negligible percentage of Internet packet throughput.” (Which is a troubling thing to have happen, if you’re a network equipment mfgr, and you expected to have some time while new protocols are still “nascent” to tune your switches for them.)
Would you be able to tell the difference between stock firefox and stock chrome if all you saw was the fiddler session? I don't know, I haven't tried. I did look at a firefox session in fiddler and I was not impressed.
Pick your poison. If you configure all the settings in firefox properly it might be acceptable. But can you just do the same in chrome? If not, you can use the privacy friendly chromium browser of your choice. Most firefox users wont take the time to configure it properly and the data will still reach the data gobbler.
Edit: an interesting comment from the other firefox thread https://news.ycombinator.com/reply?id=25916762
On a much less niche side of things, a lot of web apps like Teams, Zoom, and probably many others are only fully functional on Chromium, thanks to WebRTC specifics and some video encoding stuff that's only on Chromium. Don't know the details, but things like video and desktop streaming are limited to Chromium.
That could very well be an artificially enforced restriction, but I don't think it is. I think firefox is moving towards feature parity with Chrome on this one, I hope so anyway.
Hmm, come to think of it, does anybody know an easy Chrome-blocking trick for displaying "this page is best viewed using FF"? Might be an effective deterrent for non-"hackers" and the start of forking the web for good.
https://addons.mozilla.org/en-US/firefox/addon/temporary-con...
Firefox built the core container technology, which drives their built in Facebook container (isolating Facebook from everything else). But isolating everything has a lot of weird edge cases, and I can't blame them for not supporting it out of the box.
How do you know what browser the majority of HNers are using?
Searching for "ARPU" news will give articles with new takes every time anyone publishes new quarterly numbers, but those are roughly accurate. Obviously, they can be distorted to tell whatever story you want by messing with market segmentation, time period, and what kind of revenue/profit/margin/expenses/capital you want to invoke, but those are rough numbers.
To be clear, those are first-party advertising companies, this isn't the value of a page view to a random blog with side-roll ads from some third-party advertisers/trackers. I have no idea what Taboola/Outbrain chumboxes generate other than that they both have $1B revenue and there are about 5B Internet users worldwide, which means the average user is worth $0.20 per year to them. And it's reasonable to assume the majority of their revenue comes from wealthy English speaking adults, so maybe your demographic is worth $5 or something like that.
I max out free tiers of OneDrive/DropBox etc, use my free minutes of build time at the dev sites, I use some social media features but I browse Twitter and reddit on custom apps that don't show any ads. I never ever click an ad in an article or search no matter how interesting or relevant.
So if since I'm a net loss, that means that for everyone who is like me, there has to be someone who is an even larger gain for these companies. I have all of those services (Google, fb, twitter) and I'm still pretty sure I provide a negative revenue for all of them. So Someone needs to provide the revenue I don't. It's a scary amount. My internet activity is subsidized by someone who must be doing a scary amount of clicking on the sponsored google results, or something.
1. It seems like client web pages cannot directly view the DNS information for a given domain name. So I would think embedding identifying information in something like a CNAME or TXT record directly wouldn't work. 2. I suppose a tracker could try to create unique records for a given domain name and then use request/responses to/from that domain to get identifying information. But this seems highly dependent on being able to control the DNS propagation. Short of my ISP trying this trick on me, I'm not really sure who else could manage.
I'm sure I am missing things in this brief analysis. I'd love to hear what others think about this cache.
There's a PDF here: https://www.ndss-symposium.org/wp-content/uploads/2019/02/nd...
Basically timing based. See https://www.audero.it/demo/resource-timing-api-demo.html for a demo of what's available in the browser's navigation and resource timing API. For example, I get this on a cached reload:
domainLookupStart: 52.090000128373504
domainLookupEnd: 52.090000128373504
The PDF explains some enhancements that make it more reliable, like publishing multiple A records and watching order, etc. Also, the demo link isn't really showing what you would do...the resource being downloaded would be marked as non-cacheable so that you would be measuring "DNS lookup was cached or not" instead of "Entire Asset was cached, therefore no DNS lookup happened".
But it's more likely they just use a large set of (sub)domains and measure timing.
Wait, so one form of "supercookie" is basically the same as the transparent gif in an email?
Therefore, I believe, browsers have to provide a volunteer "tracking" functionality - when a web page reqests 3rd party cookies, a popup is shown to the user with the cookie values, description (as set by the owning domain), the list of domains already permitted to access the cookies and their privacy policy links, and options Allow Once, Allow, Deny Once, Deny.
So instead of fighting each other, service and the user had a chance to cooperate. Service only needs to describe the need clear enough.
https://developer.mozilla.org/en-US/docs/Web/API/Document/re...
https://developer.mozilla.org/en-US/docs/Web/API/Storage_Acc...
on safari, it's basically the only way to get access to third party cookies in an iframe since safari 13. I wish other browsers (chrome) would also enable this when third party cookies are disabled. On FF I think the rule is that you have to interact with the site beforehands and you get access automatically, failing that you can use this API. No idea how it works in edge
So, to access 3rd party cookies I need to access a document DOM object that has that 3rd party origin? But such a document is not always available, is it...
Looks like the use cases targeted by that proposal are limited to an embedded iframe that wants to access its own domain cookies. I was thinking also about arbitrary doman.
Like requestStorageAccess(targetOrigin, keys...)
Personally I don't think this is a problem, and people should be allowed to make that choice. But most of HN seems to disagree with me there, and feels that users need to be protected from making choices that could allow them to be tracked
Websites force you to accept tracking in the same way the store forces you to pay for your groceries
All I'm doing is highlighting is that it's not as simple as some of these jUsT bAN cOoKIes folks would have you believe.
Blocking technologies that are used for invidious ad-tech will make it more difficult to support legitimate use-cases. Sleazy ad-merchants like Google will move on to something else built into the browser https://blog.google/products/ads-commerce/2021-01-privacy-sa... and normal site developers will be left in the lurch.
IMHO there isn't a technological solution to this problem, the only effective answer is regulation & hefty fines that make unethical tracking also unprofitable.
An example that I can imagine is a big onlite shopping company that has several domains, and they want a shopping cart that that works across all their domains.
Besides, since they control all the domains, they can do redirects to associate your session across them easily enough. It's basically oauth at that point, which works just fine without 3rd party cookies.
I suppose coordinated action by citizens would have the same effect, but online privacy is such a complicated obfuscated issue that will never happen.
Or am I off in the weed here about how this will play out?
Is this a confesion.
Browsers, including Mozilla, have continually designed and kept those features enabled by default, even when they are aware of the abuse.[1]
Mozilla is nearly 100% funded by a deal with Google.
I try to forget these facts every time I read some public communication coming from Mozilla, but they just keep coming back.
1. Mozilla, or any of us (yeah, right), could rip out some of the fetaures that advertisers abuse and create a more "advertising-proof" version of Firefox. Heck, we could create much smaller and faster Firefoxes. But no, there can be only one. Because reasons.
Take out that search bar and they would probably have to kiss the money from Google goodbye.
Getting rid of ads and tracking is not Mozilla's highest priority. Keeping online advertising alive is the highest priority because obvious reasons.
There is nothing in the contract we have with our ISP that says we must support online ads. That is the benefit of paying for something. There are actually terms and the possibility for enforcement.
Mozilla's ad-supported web has no terms. None that web users can enforce. Internet subscribers using "the web" have no power. Advertisers call the shots.
Browsers are essentially entire operating systems at this point. Ad companies hire engineers. It's inevitable that this engineers will find exploits. Your stance seems to completely ignore this fact. If it would be so easy to create your perfect, user centric, privacy first browser, why haven't you made it yourself?
I mean this one, not the Chrome extension of the same name. https://oblador.github.io/hush/
That seems like it would make tls stripping attacks a lot easier.
I'm not saying any of those approaches is bulletproof, just that maybe they have a more complex strategy in mind to mitigate risk.
> Or to randomly respect the cache
If the goal is to manipulate a single request to insert malicious js that gets cached, you only need a single non tls request. If you're an on path attacker, you can probably get the user to request things multiple times (e.g. randomly break and unvlbreak internet connectivity) until you get lucky with an unencrypted connection. If you're trying to make a super cookie you can just repeat and average out the random failures (random pertubation almost never prevents a side channel leak, at most it makes it more expensive)
>Or to simply make every request to both the TLS and non-TLS port but do so in parallel and discard the non-TLS response if the domain was in the HSTS cache.
Fails at confidentiality 100% of the time
"I have no doubt that someone will succeed under these new rules to come. You're just upset that it isn't you any more."
The test at amiunique.org tells me my User Agent string is unique.
So, can we now fix the User Agent strings, please?
All this does is create a separate cache for each site, so that they can't infer that a user has already been to another site. It makes no changes to POST/PUT/PATCH requests to an endpoint. They will still be going there.
More seriously, what happens with images loaded from a CDN? Or with a site behind Cloudflare.
Using uBlock, Privacy Badger, Decentraleyes currently.
Ad company databases map 95% of IP addresses to individuals. You can buy the names, addresses, phone numbers, and email addresses of your website's visitors.
So I rolled my own DDNS solution, and have it send me a text every time my IP changes. I have only seen one change in the last six months, and that was when the neighbourhood’s power was cut for two hours for maintenance. Rebooting or temporarily powering off my router doesn’t seem to be enough to force a change on it’s own, I believe it’s only when larger equipment upstream from me powercycles that my IP changes.
So (at least in my experience) the “dynamic-ness” of my home IP is relatively small.
https://webkit.org/blog/8146/protecting-against-hsts-abuse/
"An attacker seeking to track site visitors can take advantage of the user’s HSTS cache to store one bit of information on that user’s device. For example, “load this domain with HTTPS” could represent a 1, while no entry in the HSTS cache would represent a 0. By registering some large number of domains (e.g., 32 or more), and forcing resource loads from a controlled subset of those domains, they can create a large enough vector of bits to uniquely represent each site visitor."
And FF and Safari should continue their work to close any fingerprinting opportunities Fingerprinting is becoming less effective over time - for example fingerprinting on iOS is pretty unsuccessful.
Do you have more information about how iOS is blocking fingerprinting?
https://9to5mac.com/2020/09/04/ad-industry-tracking/
"my iPhone 11 Pro was also unique among the more than 2.5 million devices they have tested."
Time zone is one possible fingerprint data point.
Totally forget that. Oops.
Now for the meat of your comment ...and how many have tested their protections so that their testing site recognize that your device is not unique?
A very good counterclaim was posted in the comments:
I strongly disagree with your findings, Ben. Namely, you list fingerprinting techniques available to browsers, and fail to mention how Safari (and Firefox to some extent) make those methods less precise. Instead, you say
Note that this isn’t a comprehensive list, it’s just examples. When a website analyses all of the data available to it, things get very specific, very fast.
So let me point out where you were wrong about Safari in particular:
• Fonts installed. Safari reports very limited subset of fonts, which does not vary. it is the same for every Safari users.
• Plugins installed. Unsurprisingly, Safari lists just one: PDF reader. Native plugins are not reported.
• Codecs supported for video. The uniqueness checking site reported just H.264 and FLAC. Audio format are not reported at all. There's no mention of H.265 and VP9 which work in my Safari beta version, and no mention of the whole plethora of audio formats which are supported.
• Screen resolution is not the real screen resolution. I'm on 27'' 5K iMac and the screen is reported as 2048 x 1152.
• Media devices attached reported as "audioinput" and "videoinput". It has nothing to do with the actual available media devices.
And incorrect reporting goes on.
As you can see, fingerprinting through browser leaves Safari users very poorly segregated. As long as you running latest OS with latest version of Safari, you are a part of a very broad chunk. You can't be identified through browser fingerprinting along.
This means that the only unique data that you can get are: a) Language settings. There is no way to work-around this (unless you consistently lie that you solely use English) b) Time zone. There is no way to work-around this (unless you consistently lie that you solely use UTC)
These things can be predicted anyway with IP address, so it is not perceptibly meaningful in any way. In other words, advertisers can literally give up on detecting when Safari are the browser and rely instead on IP addresses (which can tie into a family (or in some IPv6 cases) a device.
Disclaimer: This is a genuine question. I'm a hardware guy and I don't know how web works nowadays.
"Firefox 85 Cracks Down on Fingerprinting"
"Is this really important given that supercookies can almost always persist between sessions and across domains?"
----
If you want to fix a problem, there are going to be points during that process where the problem is partially fixed. This only becomes an issue if we're headed in the wrong direction, or focusing on a sub-problem that would be better addressed in a different way, or if we have no plans to fix the other attack vectors.
But the steps we'll take to attack fingerprinting are very similar to the steps we'll take to attack supercookies, so there's no harm in grabbing the low-hanging fruit first.
Supercookies clearly have some value to advertisers and other bad actors or else they wouldn't be used. There's value in closing off that specific tracking method while we continue to try and figure out the harder problem of how to standardize headers, resource loading, etc...
But yeah, we still have a ways to go. Small steps.
Of course we'll have the inevitable guy pop in here and talk up how awesome web tracking is because it helps sites monetize better, but that's all bullshit. At this point, all the advertising profits are sucked out of the web by Facebook and Google. The rest of the industry, including publishers are just struggling to get by while two trillion dollar behemoths throw them scraps.
It's almost impressive how they manage to load so much crap. Just visit a site like mediaite.com, the list of trackers is damn long.
The really frustrating thing about this bit is that because it disables optimizations, it potentially impacts sites where they don't actually use tracking.
I have a community site I want to build. If it stays small I can probably run it for $20 a month all in and not pester anyone. But I’m still keeping my eye on some of the saner ad networks that use subject matter instead of user tracking to target ads. That might be an option.
Linus tech tips has a video where he gives us a peek into their finances. Among other things the merchandizing arm makes them about a third of their revenue, and no one advertiser is allowed to pay more than that, so they can maintain a degree of objectivity. I think a lot of us don’t want to approach sponsors so we feel sort of stuck with ad networks.
And I’m not much of a materialist but I’m a tool nerd (you possibly don’t need it, but if you’re gonna buy it, get a really good one) so I’m not sure how I’d do merchandizing, since I’m more likely to recommend a brand than have something made for us. That leaves what? Amazon’s “influencer” BS, which is more money for Amazon? Discount codes, which are untargeted consumerism?
For every site I've developed and have been tasked with adding adverts, and every colleague that I have worked with that has done the same:
- Yes, we are aware.
- Yes, we doth protest.
- No, we were not successful.
You load one ad and they want their own analytics or they try to stuff multiple ads into the same slot so you get multiple analytics.
We clocked one ad at 800Mb loaded once.
How demotivating. It was time to start thinking about moving on anyway, but I basically stopped trying to pursue contract renewal at that point. All that work (and uncomfortable meetings) so Google could triple our load time.
Normal display ads all being blocked is generally fine 99% of the time, but if you care about not being permanently tracked across the internet then there are a couple more domains you have to add - except some sites make it mandatory that those invasive fingerprinting scripts and port scanners run and report back a session, otherwise you're refused login or banned.
Is it their content to do what they want with? Sure.
Does the same logic apply to the $9 I used to give them each month? You're damn right.
Yes you have to log in to the interface unless you engineer a way around it
Can be nice to use to quickly disable pihole to get through to a particular website.
I can't effectively keep a mental black list of all the sites which I don't want to click on.
Best part? Trying to convince the operators of such sites that users they cannot see in their "analytics solution" are worth fixing their site for is not exactly a straightfoward job - from their narrow view, these users simply do not exist, because the tracking does not show them!
An no, there isn't "tons of alternatives". In theory there is. But in practice, they can really make your life harder. Some may say that Signal is an alternative for WhatsApp, but if people you communicate with don't want to use anything but WhatsApp, then Signal is useless. I hate Facebook but when I want to plan an event, I found nothing better, simply because that's the platform that reaches the most people. Network effects... But also, your favorite show may not be on "alternative" streaming platforms, sometimes your job, or worse, the government may require a specific website.
There are extremists who are ready to find alternative friends, shows or jobs just to avoid using some website. It is a good thing these people exist, that's how progress is made. But for most people you have to make compromises.
Ah! That's why I haven't missed Facebook. I am old enough that I don't plan events any longer.
(Or maybe I have no social life. Actually, that's right, I don't. ;-))
When I need to access ads.google.com or analytics.google.com for my company, I turn on Cloudflare, and pihole is bypassed.
wget --quiet "http://PIHOLE_IP/admin/api.php?disable=60&auth=YOUR_API_TOKE..."
You can find the token in the pihole Web GUI at, Settings > API/Web Interface > Show API token
I'm all for news sites, for example, hoisting ads if I knew they were getting the money from those ads, knew the ads were actually coming from their site.
I wonder if you could hijack those requests at your router and send them back to your Pi-Hole? But then they just switch to DNS over TLS...
In the corporate world, I think the future is managing your network by managing every single device on your network. Only let authorized/corp devices in and all those devices must be enrolled in an MDM solution that enforces all sorts of policy and includes monitoring traffic/DNS queries. Of course that's a lot more work than just monitoring things at the network level.
Your computer sends the raw domain name to pi-hole (e.g. ads.google.com), and pi-hole returns 0.0.0.0 if it's on the block list.
There's nothing Google or anyone can do to make pi-hole stop working.
For now, I've configured my router to force all UDP port 53 traffic to my Pi-Hole which overrides what I mentioned above.
But, in the future we may start to see IoT Devices hard-code DoH servers which will be harder to force over to the Pi-Hole.
Oh wow, how do you do that?
Because I wonder what percentage of bandwidth (in terms of bytes) trackers/banners/ads account for.
Need to set up a pi-hole ... just too many other projects....
My pihole is showing 18.7%-23% of requests blocked :)
It would be nice to know how much we're wasting.
They focus not only on tracking but also malware prevention, where possible via dns filtering.
Pi-Hole still does not properly support wildcard filtering, only via regex but that is not really efficient (requires tons of resources).
https://github.com/StevenBlack/hosts
What is the advantage of having DNS on a separate device other than that it provides ad blocking for multiple devices?
But also you can have more flexible block patterns. I run DNSCrypt-Proxy and my block lists can have wildcards. With /etc/hosts you have to enumerate each origin. It can also do things like IP blocking where if any domain resolves to a known ad network IP, then that request is blocked.
But mainly, DNSCrypt-proxy encrypts all my outgoing queries and round robins them across resolvers. (Also hi dheera!)
Obviously not a NextDNS specific issue, it’d happen with anything that blocks the call, but just putting it out there for the next sucker that tries to google why their IKEA gateway suddenly stops responding.
[i] Target: https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts
[] Status: Retrieval successful
[i] Received 59896 domains
[i] Target: https://mirror1.malwaredomains.com/files/justdomains
[] Status: Not found
[] List download failed: using previously cached list
[i] Received 26854 domains
[i] Target: https://s3.amazonaws.com/lists.disconnect.me/simple_tracking.txt
[] Status: No changes detected
[i] Received 34 domains
[i] Target: https://s3.amazonaws.com/lists.disconnect.me/simple_ad.txt
[] Status: No changes detected
[i] Received 2701 domains
[i] Target: https://dbl.oisd.nl/
[] Status: Retrieval successful
[i] Received 1167690 domains
[i] Target: https://phishing.army/download/phishing_army_blocklist_extended.txt
[] Status: Retrieval successful
[i] Received 21379 domains
[i] Target: https://raw.githubusercontent.com/deathbybandaid/piholeparser/master/Subscribable-Lists/ParsedBlacklists/AakList.txt
[] Status: Retrieval successful
[i] Received 5 domains
[i] Target: https://raw.githubusercontent.com/deathbybandaid/piholeparser/master/Subscribable-Lists/ParsedBlacklists/Prebake-Obtrusive.txt
[] Status: Retrieval successful
[i] Received 3 domains
[i] Target: https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-blocklist.txt
[] Status: Retrieval successful
[i] Received 14724 domains
[i] Target: https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-malware.txt
[] Status: Retrieval successful
[i] Received 412 domains
[i] Target: https://raw.githubusercontent.com/hectorm/hmirror/master/data/adaway.org/list.txt
[] Status: Retrieval successful
[i] Received 9182 domains
[i] Target: https://raw.githubusercontent.com/hectorm/hmirror/master/data/disconnect.me-ad/list.txt
[] Status: Retrieval successful
[i] Received 2701 domains
[i] Target: https://raw.githubusercontent.com/notracking/hosts-blocklists/master/hostnames.txt
[] Status: Retrieval successful
[i] Received 209608 domainsKid's computer has dnsmasq as a similar solution.
It's spooky, I tell ya!
50% of adverts are a waste of money, the problem for people wanting to advertise is nobody knows which 50%
I wish that were true. Although uBlock Origin does a good job, some ads definitely still make it through. There are also some sites that detect ad blockers and refuse to let you in unless you disable it. There are workarounds for some of these, but it's still a bit of a mess.
I have yet to come across a site that offered something so unique or compelling that I decided to turn off my ad blocker to use it.
That, and when there's an email subscription popup, is when the one-click JS toggle extension comes out. Can't detect anything if it can't run any code in your browser.
You can object to being targeted based on your browsing habits, but don't stop ads altogether.
There is no level these people will not stoop to, and we're sick of their shit. They brought this on themselves.
Overall FF has been incredibly user friendly making all sort of plugins that focus on privacy possible, while Chrome has been as hostile to it as possible.
Along with some marketing drivel about how its important advertisers get their ad revenue.
Each tab group then has its own cookie container, so I can have multiple groups open and they don't share anything - I can login to different google (or any other service) accounts in different contains and it works like I want it to.
For the sites that I want to use logged in, I either create a special container for that site only, or I just use a password manager to log me in each time I need to visit it.
The added privacy is great, the peace of mind in just clicking I agree is great.
I really feel today having different devices with different browsers, connected to different providers is only working solution.
document.querySelectorAll('input[type=checkbox]').forEach(el => el.removeAttribute('checked'))
This app hides the popup :)
I like the analogy, but I wonder how effective it is on anyone under the age of what, 35?
There was a single telephone company (or it was shortly after there were plural "baby-bells") and the telephone network was a completely private, isolated, network that only the phone company (or baby-bells) even had access to. It was also a network that was heavily regulated such that the possibility of a random attacker from half a world away being able to tap into a phone call as it happened simply did not exist.
In that environment, placing a phone call was considered "secure" (or at least as secure as network isolation and regulation could cause it to become [I'm ignoring NSA style 'state secret' taps, those have likely always been available to NSA style agencies]). So it would have been seen, at that time, as reasonable to use fax machines for document exchange, because the "phone network" was considered to be secure against having a man-in-the-middle tapping off one's communications.
Wind the clock forward thirty years, and have the once isolated and highly regulated telephone network more or less become just another packet protocol on the general Internet, and the choice of using "fax" for secure document exchange sounds ludicrous.
The issue is that the regulations those environments operate under have not been updated in the ensuing thirty years to account for the fact that "phone network" is no longer the once isolated, mostly secure, network it once was. And if the regulations don't get updated, no lowly clerk at the front lines is going to lose their job by _not_ using the comm. system called for by the regulations.
This is such a meaningless statement.
Better?
On linux you can use [efax](https://linux.die.net/man/1/efax) and a modem and... ooops, good luck finding a modem.
I did this for real ~10 years ago when a stupid company didn't accept a scanned PDF by email and required a fax of the actual document "because security". The difference is that I had a modem in an old laptop at that time, so I just send them the same scanned PDF.
Now I'm wondering if there is a provision for sending faxes somewhere in the GSM/3G/4G rabbit hole of standards.
I have bookmarked them from long ago.
Every other credit agency had no problem with my SSN + address then Equifax throws a flag, locks my account and says I have to validate my identity by faxing them identity documents.
Fat chance, idiots.
I should also point to non-Unitedstatians that checks (that physical paper worth as much money as you write and sign on it) are still in use in the USA.
That's leaving out the "automatic bill pay" function of my bank's web site, which, for most payees, at the end of the day results in physical paper checks being printed and sent in envelopes.
That varies a lot by jurisdiction. I'm 50 and I haven't written a single check in my entire life. (Sweden.)
I pay contractors with checks because almost none accept credit cards and cash gets cumbersome once you start getting into 4 and 5 digits.
My local utilities all charge a "convenience fee" of a few dollars when paying online or with a credit card. Sending a check in the mail costs me only $0.50. (Even though it costs them some employee's wages to handle my envelope and cash the check. Go figure.)
Checks are also convenient for transferring small amounts of money to friends and family. Yes, there is Paypal and the like and some of them don't even charge fees but I trust my bank way more than I trust a random company with direct access to my bank account. (Paypal in particular have proven over and over again to be untrustworthy in this regard, which is why not only do I have two Paypal accounts--one for buying and one for selling--but I also have a special "firewall" account between PayPal and my main checking account. This is so that the most they can grab is a couple hundred dollars on average, rather than some arbitrary fraction of my life's savings.)
Checks are sometimes the easiest (or only) way to move large amounts of money between my own accounts. There was a time where most online bank accounts would let you make ACH ("electronic checks") transfers to any other account, but they seem to be moving away from this, I presume due to its high use in fraud.
Writing a check is the fastest way for me to transfer between two accounts. :(
Wire transfers are expensive here; my credit union which doesn't generally have high fees, charges $29 to send a wire (they don't charge for incomming wires, but some banks do). I've had some brokerages with free wires, but usually that's tied to a balance requirement or in connection with a company sponsored account (for stock based compensation or retirement accounts).
The US does have some electronic networks for instant, no-cost p2p payments. https://www.zellepay.com/ has a large number of participating major banks with some major exceptions. A lot of people use https://venmo.com/ or https://cash.app/ which are not directly integrated with banks but then offer electronic transfer of funds to bank accounts.
I'm guessing this is why several US payment companys and start-ups just don't make any sense to me: "make payments easier!"
but it's hard for me to understand how to make it easier than just typing in someone's phone number or email and sending them money, or purchasing via tap and go with your card/ phone. Don't you at least have electronic transfers if not those other newfangled technologies? are you (seriously) suggesting you can't transfer money between your accounts?
Because of how and when it got computerized, it's hard to move it forward again. There's no desire for sweeping changes, everything has to move slowly now.
There are several personal transfer services (PayPal is ancient and fits the mold), but none have a lot of penetration. I think Zelle? is deployed through bank integration, and may end up with a lot of users as a result; possibly critical mass.
There was a lot of backlash on rf payments the first go round, a few issuers gave me cards with it, but then they removed it. Then they started issuing cards with chips, and now most of them are putting rf payments back in. A lot of payment terminals have the hardware for it, but a lot of them also have signs that say don't tap to pay.
I can easily do electronic (ACH) between my accounts, as long as I've gone through setup, which takes days for test deposits to show up. But to transfer to a friend or a relative is tricky.
US banks suck for a lot of reasons but part of it is that culturally and regulatorily the entire financial/banking/commercial environment in the US is very conservative. And there's not much in the way of pressure to make changes either - whether internally from competition and regulation or externally from the need to interact with other countries. Like broadband, consumer banking is basically an oligopoly that will quite happily plod along providing the same service as long as it can.
Many shops don’t accept them, some banks have already stopped using them altogether, and the rest of the major banks are phasing them out this year.
A cheque is a rare thing to see (I haven’t handled one for a decade or so?)
At least for those of us that were late adopters of text messages.
I still laugh about how he got several cease and desist letters and still continued sending the same businesses stuff.
Ahhhhhhh yeah, the good old days.
It’s more like complaining that your sole of your shoes is being worn out more because grocery stores put the milk in the back forcing you to walk past items you don’t intend to buy. You can always go to a different store just like you no one is forcing you to browse websites that are ad supported.
It's profitable because a few people want to influence and spy on a lot of people.
Most people don't want ads they just tolerate them for getting actual services. Most these people don't even know how much tracking is involved and how nefarious this industry really is.
Perhaps you’re invested in the ad industry. No one else wants ads buddy.
Most of that VC cash startups raise is spent on marketing. I don’t understand why people have such negative perception of ads especially on a VC run news site. All the ycomb companies drops tens of millions on digital advertising.
Even if you did share a URL with another site, the benefit is low compared to what you can do with same-domain requests. Most sites should be served with HTTP 2 already, which means even unoptimized sites should still load decently fast as requests aren't as expensive as they used to. You can get almost all of the same bandwidth benefits from a cross-domain cache by just making sure your own resources are being cached for a long time.
It's just frustrating that it's one more optimization that is getting turned off. And makes the internet just a tiny bit worse as a result. It's like death by a thousand cuts.
We talked a little bit about how these ads still work, even without tracking you. You might be losing 10-15% of revenue, but if you never had that revenue to start with, you don't miss it: https://www.ethicalads.io/blog/2018/04/ethical-advertising-w...
I think the real secret is just to not become dependent on the additive revenue. All businesses forgo additional revenue based on ethics and regulation, and I don't understand why that's such a odd thing to do with advertising.
Fundamentally serving an advert should be a light process adding only a tiny amount of overhead to the site.
I use Firefox with Strict Enhanced Tracking Protection [0] and Privacy Badger [1] as an extra layer of protection. Some sites, mostly news orgs, complain that I'm blocking ads, but inevitably these are the sites Privacy Badger reports 20+ trackers blocked. I'm happy to see ads online, I'm just not willing to sacrifice my privacy for them.
[0] https://support.mozilla.org/en-US/kb/enhanced-tracking-prote... [1] https://privacybadger.org/
I don't love advertising in many of it's forms, but taken from the viewpoint of those who make money from ads (i.e. content creators), it is one of the best ways out there for them to make a living. Platforms like Patreon are great for some folks, but not everyone can make a living off of sponsorship from their viewers. But, I am not willing to sacrifice my own privacy to allow someone else to make money, especially given that we have tonnes of examples of non-privacy-invading advertising that works.
I listen to 8-10 hours of podcasts a week and I generally find the ads on them, usually where the host does an ad read and includes a discount code, to be far more useful and relevant to me than the hyper-targeted ads backed by 20 tracking scripts I see on news sites. Another example, many of the indie tech news sites I read (e.g. Daring Fireball or Six Colors) will have a weekly sponsor that will have an advertising post or two interspersed with their regular content. I'm happy to take 2-3 minutes out of a 30 minute podcast episode to listen to a couple ad reads or see a brief write-up of a sponsor's product as I'm scrolling through the week's tech news. What I'm not happy to do is have my web browser load a dozen tracking scripts in the background when I open a news article and have flashing pictures deliberately trying to distract me from what I'm reading.
The problem with charging per click or impression is that you're vulnerable to fraud which means you either lose money/trust or you have to do invasive tracking to detect & prevent fraud (which you'll be unlikely to achieve as well as the big players - Google & Facebook - do). Charging per amount of time (regardless of actual impressions or clicks) doesn't have that problem.
Do you have a good example of how this is priced, and how it would work in practice?
Determining the price will be a bit tricky (and I would expect that you'd have to lowball yourself until your platform builds credibility in terms of good ROI) but in the long run it should mean your advertisers pay a flat price to be included per week/month regardless of actual impressions or clicks (thus there's no fraud potential as only the raw profit from the ads will matter - the only "fraud" potential would be to literally buy the advertised product en masse).
Thanks for following up.
Advertising is a cynical deployment of our knowledge of crowd wisdom, media manipulation, and statistics to make people part with their money for things they wouldn't think they needed. Our economy can't handle this kind of reckless consumerism anymore.
Worse yet, we don't need advertising to bolster our media. Unfortunately, the media execs don't realize this yet.
All your metrics are fuzzy, your standards ridiculous. We have far better practices we can deploy than the ones the advertisers use.
Please, stop advertising to us. If that's all you plan to do with this new company, can you please kindly go away?
A bit more color here: https://www.ericholscher.com/blog/2016/aug/31/funding-oss-ma...
We could use help, particularly from anyone who's good with css.
However, that does not mean I have to agree to advertising -- whether it is labeled ethical, green, sustainable, cage-free or whatever. If you're lucky, you won't have a lot of extremists like myself visiting your site; i.e. the advertising will be successful.
Comments are a cynical deployment of our knowledge of crowd wisdom, media manipulation, and statistics to make people part with their opinions for others they wouldn't think they agree with.
--
Sorry, there is such a think as "more" ethical ads. If you want to be pedantic and argue they should use "more" suit yourself. But things are not black and white, your comment is in itself "manipulating" the reader trying to convince them that ads are all the same and that they cannot be put on an ehtical spectrum which is not true: tracking ads vs billboard, I'd much rather a billboard (which I hate in and on itself as they are usually just making the place they are in uglier).
And while you are not "trying" to manipulate anyone (maybe), I also disagree that you are not effectively influencing your reader thoughts to some degree.
The analogy I made is: even an internet comment does, on a smaller scale, less maliciously, use persuasion techniques: should we get rid of discussion forums too? I don't think so, and while an ad-less world seems like a nice experiment, sounds pretty unrealistic, regulating (outlawing would be nice) tracking in ads? More realistic and fixing 80% of what's wrong with 20% of the effort if you ask me
But that does not mean I have to partake in them, watch them, or allow them to consume my attention and time. I also don't need to spend my limited time on this planet trying to "fix advertising". I can simply block them and ignore the ones that slip through, and get on with my life. If this is an issue that is dear to your heart, that sentiment undoubtedly feels dismissive. I'm sorry about that.
How do you propose that companies should promote their products and services, if not through advertising?
Are you somehow suggesting that they should just sit there and hope that people who have never heard of their product independently decide they happen to want or need that product and seek it out, unprompted?
You say "people part with their money for things they wouldn't think they needed, Our economy can't handle this kind of reckless consumerism anymore": Surely you don't think you speak for everyone?
You certainly don't speak for me.
I am not some blind sheep who is suckered into buying things I don't need. I am a grown adult who can make informed decisions with my money, including sometimes buying frivolous or unnecessary things.
I hate these arguments that assume everyone is stupid except for the person making the argument. It feels like there's some weird savior complex at work.
People have free will and are allowed to spend their money as they wish, and I think YOU are the cynical one if you think otherwise..
Yeah, it's even got a name: shopping.
Or do you have infinite time to go browse every single store in your city on the odd chance that you'll see something you want?
I get the point you're making, but I hope you realize you're just backpedaling from your original "no advertisements ever!" statement.
I believe in giving people better control over how they receive ads (I personally run an ad blocker in my browsers and a Pi Hole on my network), but you position that there should be no advertising at all, and that all ads are unethical is just silly, and you're proving that point yourself here..
So, for direct to consumer companies who only ship online, SEO?
Here's the thing: ads can be useful.
Awhile back I got a, highly targeted, ad for high protein sugar free cereal. That's awesome! I am 100% the target audience for that product, and until I saw that ad I had no clue it existed! To find a product like that I'd have to search for it, but I would never search for an entire new category of product that I didn't know about.
Same thing for the fitness app I am using (BodBot, it is amazing!). I am quite literally healthier right now because of a targeted advertisement.
Was I aware of fitness apps before then? Sure. But the ad for BodBot was informative about what features differentiated it from the literally hundreds, if not thousands, of other competing apps.
Do most ads suck? Sure. Should ads be highly invasive? Nope. But interest tracking and basic targeting actually help me find products and services that I want to buy!
Facebook in particular, for all the things wrong with it (long list!) has some amazingly relevant ads that inform me of products that I never knew about.
Those who want to shop know where to go. Those who don't, know where to avoid.
Perhaps there is a way we can both enjoy the internet in our preferred ways. Perhaps not, I don't know.
The false dichotomy you pose is ridiculous. People seek out information on what to buy all the time. But when I am listening to music, watching television or film, or reading a fucking news article, that is not the time I want to be given that information. It is unsolicited and I don't care about it.
People seek out information on what to buy because at some point they found out about it via (perhaps indirectly) the provider's promotional efforts (i.e. advertising).
We can certainly talk about the appropriateness of when an where to advertise, but that's a very different topic than your ALL ADS ARE UNETHICAL screeds that you've posted in like a dozen threads on this topic from 2 different accounts..
Never mind continuing to believe that somehow those of us who engage with advertising are lying to ourselves or somehow less in control of things than you?
Now who's spinning a web..
If I want to buy something, I seek it out. Anything else is a waste of my time and a waste of the advertisers money.
I long ago decided to throw out every piece of physical ad mail I receive without even glancing at it more than long enough to recognize it as an advertisement.
I don’t know why you expect me to treat your digital ads any differently?
You can call my perspective extremist, but is it any more extreme than the methods used by advertising networks to steal my attention?
I think a service that allows for website usage based payments, a Spotify/Apple News for websites would be interesting. I can see a decentralized crypto application evolving around this usecase
Payment from one user produces more revenue than showing ads to hundreds of users. That should be multiplied in to any analysis of friction.
> I think a service that allows for website usage based payments, a Spotify/Apple News for websites would be interesting.
There have been many attempts to do that, none of which have succeeded. One major problem: they tend to track all your web activity, and the kinds of people interested in services like this are very much the kinds of people who don't want to be tracked. Another problem: it's easier to convince people to pay for a specific source of content than to amorphously pay for "various content".
I'm curious, how many services do you subscribe to and pay for content? I pay for a few ad free resources, but certainly a lot of the sites I enjoy don't get my $$.
This isn't "ad free" but it's close enough in my opinion. There's a huge gulf between contextually relevant content curated by the creators and the kind of shite that ad networks push.
> All businesses forgo additional revenue based on ethics and regulation, and I don't understand why that's such a odd thing to do with advertising.
The great bulk of advertising is built upon a conflict of interest and is essentially manipulative. Consider, for example, an article. Both the writer and the reader want the reader's maximum attention on the article for as long as the reader cares to give it. The goal of advertising is to distract from that in hopes of extracting money from the reader. Generally, ads are constructed without much regard to whether the reader was intending to buy or would really benefit from the product. The goal is to make a sale. (If you doubt me, look at how many people who create or show ads, say, test a product before putting the ad in front of people. Or just look at tobacco advertising, a product that has killed hundreds of millions.)
So I think there's an inherent lack of ethics to ads as an industry. It could be that you'll find enough people who are worried about privacy but not about the other stuff to build a business. But I wouldn't bet on it. It's no accident that this security hole is being closed not because of random miscreants but because of industrial-scale exploitation.
Indeed. The brave move would be to firefox to include built-in adblock, but I don't think Mozilla has the cojones.
>Of course we'll have the inevitable guy pop in here and talk up how awesome web tracking is because it helps sites monetize better, but that's all bullshit.
I think if adblocker usage became widespread we would in fact see the death of a lot of websites, but to be perfectly honest I kinda want that to happen because advertising is cancer.
What I’m saying is that a lot of applications have many attackers in their threat models, but advertisers have so far been out of scope.
I don't object to (silent, low resource, banner) ads, even targeted ones, as long as the targeted ads aren't building a comprehensive profile of me.
I think my ideal would be telling my browser a list of a couple interest areas (prosumer tech, sci-fi, dog peripherals) that the website could target on to serve ads. They'd get targeted ads, I'd get privacy, and I'd get ads that actually match things I care about.
Anyway one more thing that I can observe on Ubuntu 20.04. Firefox has become noticeably faster. I dont know if this is due to the fact that is not from ubuntu repositories or some serious optimizations were made.
"On Linux, the WebRender compositing engine is enabled by default for the GNOME desktop environment session with Wayland. In the previous release, WebRender support was activated for GNOME in the X11 environment. The use of WebRender on Linux is still limited to AMD and Intel graphics cards, as there are unresolved problems when working on systems with the proprietary NVIDIA driver and the free Noveau driver."
(Fax machine enthusiasts, please stop abusing the thread and move to Ask HN or something)
The latest casualty was podcasts. It's revolting.
Ad-based businesses need to be boycotted until this disease is in lasting remission.
Hmm?
Yes, there are adverts on all the podcasts I listen to. Many of my favorites offer members only ad-free versions. Usually I suffer through the ad supported versions because the adverts are easy enough to skip.
Some podcasts have too many adverts or annoyingly inserted advertising. Those are pretty 1 and done. No point listening to them.
IMO the (current) podcast market is a good example of how we can enjoy content and know the producers are compensated without having to deal with obtrusive marketing crap.
It is getting clear some podcasting is getting sucked into things like Spotify, but there is still enough good content I don't think it's a problem.
Do you feel people should volunteer their time gratis to entertain you?
What Hacker News does with adverts slipped into the newsfeed is essentially the same as what podcasters do.
> Do you feel people should volunteer their time gratis to entertain you?
No. They can do as they please. I'd prefer them to do it for the sake of it, or charge in a direct matter like a subscription model. However they should not, never, try to manipulate me for their profit.
I merely said the scene dominated by enthusiasts/hobbyists changed to a predominantly revenue-focused environment. You see the same dynamic at play, which made youtube the signal:noise hell it is today.
Mind you, the German and American podcast scene were very different in that regard, as in America monetization of every possible creation seems to be much more common. I assume this is down to a different set of factual constraints and values.
Sarcasm aside, not all natural sciences are treated equally. There are differing attitudes towards astronomy, oceanography, and climatology, for example.
If I formed my opinion only from HN, I'd think most engineers love: big-tech, advertising, electric cars, Apple, tech-enabled tracking (autos, web, cell-phone, watches, exercise machines, music players - it's ok if business profits!), and tend toward self-righteousness, narcissism, and virtue-signalling.
Of course, most of us are just living our lives and trying to get by. I don't know where this self-important insufferable attitude comes from, but I suspect it's a few folks who are very noisy. Most 'normal' people don't spend much time posting to sites like these, so there is a selection bias. Sadly, I also suspect that this attitude is an advantage in today's environment. It is a mirage of self-confidence, and telling the two apart can be very hard (especially for a potential employer).
Personally I'm not even convinced your claim is effective as a prejudice. What I'll concede is many engineers I've met seem to be harsher than average on pseudoscience och some varieties of manipulative lies, but that's to be expected as they have distinguishing knowledge for such things to clash with.
Like if I were to be caught doing this to a random woman it would be appropriately labelled 'stalking' yet when a company does it they potentially have a patentable marketing technique on their hands or something.
Sarcasm was already dead before “spam” meant ads instead of scrolling a forum or chat window by repeating yourself (exactly like the Monty Python sketch it alluded to).
If the priors were the other way then people would complain that nobody takes anyone seriously.
That sounds like a legitimate interest to me.
https://gs.statcounter.com/browser-market-share/desktop/worl...
Safari and Firefox also are up since October, but I'm not sure why that is. For Safari I suspect new Apple devices being purchased around the holidays, but that's just a guess.
As a backend dev and security focused eng I have little reason to test drive changes in all browsers.
FF has been smooth and stable for me across desktop OSs. Having no reason to alternate between that and Chrome, I’ve been confused by people saying it’s slow.
It’s been, to my memory, a flawless experience for 3+ years.
On the flip side, Chrome is a spy app, and a cognitive perception of web devs it’s faster does little to move me to use it.
That being said I use 90% FF, 9% safari and 0.999...% Chrome, because FF handling of tabs/containers/add-ons offers superior UX despite the performance annoyances. IMO, obviously.
I've noticed reddit is rather slow in ff but other than that not really nocoed anything massively slow or broken.
May be try on new profile to isolate the issue.
Just like IE was.
And just like in the IE days some of us are cheering enthusiastically for every better alternative while others are defend the incumbent alternative :-)
It will take time but if we all do something sooner or lesser the old "best viewed in IE6/Chrome" websites become an embarrassment to management and then it will get fixed ;-)
Edit: Same will probably (IMO) happen with WhatsApp now and possible (again IMO) even Facebook and Google if they don't catch the drift soon. I can sense a massive discontent with them everywhere and for at least a 3 different reasons: spying, ux and functionality regressions and also because of their stance on politics (ironically I think large groups on all sides of politics want to bludgeon those companies over various issues and few except investors really love them).
https://github.com/samyk/evercookie
It's quite dead now, stopped working around 2017: https://github.com/samyk/evercookie/issues/125
I imagine they could still choose to hide the blue button when you're on Firefox, but that wouldn't save you any vertical space, since the topnav menu of links and logo would remain.
On a sidenote, I might now re-enable cache that I kept disabled (well - cleared on exit) because of supercookies. I don't care that much if a single page tracks me, but I _really_ don't want Google to track me across sites. If Firefox protected me against that.. they would have one very grateful user. :)
EDIT: this also highlights why Google is so invested in Chrome - they can make sure that privacy doesn't interfere with their money-making machine. They really are brilliant. Brilliantly evil.